No description
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-23 08:02:39 +00:00
defaults initial commit 2026-09-23 08:02:39 +00:00
meta initial commit 2026-09-23 08:02:39 +00:00
tasks initial commit 2026-09-23 08:02:39 +00:00
.gitignore initial commit 2026-09-23 08:02:39 +00:00
LICENSE initial commit 2026-09-23 08:02:39 +00:00
README.md initial commit 2026-09-23 08:02:39 +00:00

kitchenowl

Deploy KitchenOwl as a rootless Podman service.

This role defaults to the official all-in-one image. It creates a pod named kitchenowl by default, with the app container named kitchenowl-server.

Example

kitchenowl_listen: 127.0.0.1:8081
kitchenowl_front_url: https://meals.example.net

# Store in vault.
kitchenowl_jwt_secret_key: "{{ vault_kitchenowl_jwt_secret_key }}"

Use a sufficiently random JWT secret:

openssl rand -base64 48

Auth / OIDC

Keep identity-provider integration at the playbook/inventory layer with kitchenowl_deploy_env:

kitchenowl_front_url: https://meals.example.net
kitchenowl_deploy_env:
  OIDC_ISSUER: https://auth.example.net/application/o/kitchenowl/
  OIDC_CLIENT_ID: kitchenowl
  OIDC_CLIENT_SECRET: "{{ vault_kitchenowl_oidc_client_secret }}"

KitchenOwl expects these redirect URIs in the provider:

  • https://meals.example.net/signin/redirect
  • kitchenowl:/signin/redirect

Storage

The role persists data at /data, which contains the SQLite database and uploaded images for the all-in-one container.

Reverse Proxy

The default listener is 127.0.0.1:8081, suitable for a local reverse proxy. KitchenOwl recommends HTTPS, HSTS/security headers, and websocket support.

References: