- TypeScript 83.4%
- PLpgSQL 10.4%
- OpenSCAD 3.1%
- CSS 1.2%
- Shell 0.8%
- Other 1%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
Moved out of the infra repo (/mnt/fastpool/git/infra/ctr/cadam): - src/: CADAM fork (upstream Adam-CAD/CADAM with the local patch) - Dockerfile, src/.env.production: image build input - entrypoint.sh, auth-entrypoint.sh, storage-entrypoint.sh, migrations/: container startup, schema migrations and OIDC/bucket bootstrap - Caddyfile: internal Supabase proxy config - deploy.sh: rebuild / deps / complete deploy - patches/cadam-local-changes.patch: recorded diff against upstream |
||
| migrations | ||
| patches | ||
| src | ||
| .dockerignore | ||
| auth-entrypoint.sh | ||
| Caddyfile | ||
| deploy.sh | ||
| Dockerfile | ||
| entrypoint.sh | ||
| README.md | ||
| storage-entrypoint.sh | ||
CADAM (self-built image)
Build repository for the CADAM app image that runs as cadam.service on
cadam.mynas-lechner.de together with the self-hosted Supabase stack. The
container definitions (quadlets) and the public Caddy config stay in the
deployment repo /mnt/fastpool/git/infra/ctr/cadam/; this repository owns the
application: source, image build and startup logic.
Layout
| Path | Purpose |
|---|---|
src/ |
CADAM fork (upstream Adam-CAD/CADAM + local patch, see patches/) |
src/.env.production |
Vite build config (Supabase URL/anon key, Kanidm SSO provider) baked into the bundle |
Dockerfile |
Multi-stage build (node:22 -> node:22-slim, Nitro output) |
entrypoint.sh |
Container startup: wait for Supabase, apply migrations/, register the Kanidm OIDC provider, create buckets, start Nitro |
migrations/ |
Idempotent CADAM schema migrations (applied by entrypoint.sh) |
auth-entrypoint.sh, storage-entrypoint.sh |
Startup glue for the GoTrue/storage-api containers (DB URL from the podman secret) |
Caddyfile |
Internal Supabase proxy (cadam-proxy): strips /auth/v1, /rest/v1, /storage/v1 |
deploy.sh |
Image build/push and rollout |
patches/cadam-local-changes.patch |
Local changes on top of the upstream clone |
The runtime mounts for entrypoint.sh, migrations/, auth-entrypoint.sh,
storage-entrypoint.sh and Caddyfile are wired in the quadlets of the
deployment repo and point back into this repository.
Deploy
./deploy.sh # complete deploy: build + push + restart the cadam stack
./deploy.sh --image-only # build + push only (rollout via the ctr_cadam auto-update window)
./deploy.sh --deps # npm update (package-lock.json) + complete deploy
./deploy.sh --skip-build # reuse the existing image (quadlet/host-only changes)
--image-only and --deps are the two modes of the automatic build service
(podman-autobuild@rebuild.service / @deps.service), configured in
podman_admin's Podman tab. The weekly rebuild runs Sunday 22:00, the monthly
deps run on the first Sunday 20:30 - both 1.5-3.5 h before the containers are
rolled over by podman-auto-update (00:00-00:15) via AutoUpdate=registry.
The push authenticates as the registry publisher; the password is read from
/etc/podman-admin/registry-password (host-wide publisher credential) and
stored in the persistent /root/.config/containers/auth.json, so the nightly
run does not depend on a login from an interactive session.
Updating CADAM
- Clone the new upstream release into a scratch directory.
- Re-apply
patches/cadam-local-changes.patch(it contains the local provider/billing adjustments plus the SSO build config). - Replace
src/with the patched tree (keepsrc/.env.production). ./deploy.sh- the entrypoint applies new migrations frommigrations/(idempotent) so the schema follows the source.
Notes / gotchas
src/.env.productionis a build input, not a secret: the Supabase anon key and the SSO provider are part of the public frontend bundle.npm update --package-lock-onlyin--depsonly moves inside the semver ranges ofpackage.json; a breaking major still needs a manual source update.- The GoTrue/storage containers translate the
cadam_db_pwdpodman secret into a database URL at startup, so their entrypoints are part of this repository. - Postgres data lives in
/mnt/fastpool/ctr/cadam/(not in git); thepostgres-datadirectory must stay owned by the postgres subuid. - Health checks inside the stack must use
127.0.0.1, notlocalhost(IPv6).