No description
| Filename | Latest commit message | Latest commit date |
|---|---|---|
| defaults | ||
| meta | ||
| tasks | ||
| .gitignore | ||
| LICENSE | ||
| README.md | ||
kitchenowl
Deploy KitchenOwl as a rootless Podman service.
This role defaults to the official all-in-one image. It creates a pod named
kitchenowl by default, with the app container named kitchenowl-server.
Example
kitchenowl_listen: 127.0.0.1:8081
kitchenowl_front_url: https://meals.example.net
# Store in vault.
kitchenowl_jwt_secret_key: "{{ vault_kitchenowl_jwt_secret_key }}"
Use a sufficiently random JWT secret:
openssl rand -base64 48
Auth / OIDC
Keep identity-provider integration at the playbook/inventory layer with
kitchenowl_deploy_env:
kitchenowl_front_url: https://meals.example.net
kitchenowl_deploy_env:
OIDC_ISSUER: https://auth.example.net/application/o/kitchenowl/
OIDC_CLIENT_ID: kitchenowl
OIDC_CLIENT_SECRET: "{{ vault_kitchenowl_oidc_client_secret }}"
KitchenOwl expects these redirect URIs in the provider:
https://meals.example.net/signin/redirectkitchenowl:/signin/redirect
Storage
The role persists data at /data, which contains the SQLite database and
uploaded images for the all-in-one container.
Reverse Proxy
The default listener is 127.0.0.1:8081, suitable for a local reverse proxy.
KitchenOwl recommends HTTPS, HSTS/security headers, and websocket support.
References: