Initial commit
This commit is contained in:
@@ -0,0 +1,27 @@
|
||||
# Pocket ID
|
||||
|
||||
Self-hosted OIDC identity provider using passkeys for authentication.
|
||||
|
||||
## Deployment layout
|
||||
|
||||
- **Compose:** `/srv/docker/pocketid/docker-compose.yml`
|
||||
- **Static configuration/source:** none
|
||||
- **Non-secret environment:** application URL, trusted-proxy policy, UID, GID, and the encryption-key file location
|
||||
are declared inline in Compose; there is no project-local `.env`
|
||||
- **Secrets:** `/srv/docker/secrets/pocketid/encryption_key`
|
||||
- **NVMe application state:** `/srv/appdata/pocketid/data`
|
||||
- **Bulk HDD data:** none
|
||||
- **Other mounts:** none
|
||||
|
||||
Secrets are never committed to this repository. The central encryption key is
|
||||
supplied to the Pocket ID service as the `pocketid_encryption_key` Docker secret
|
||||
and referenced through `ENCRYPTION_KEY_FILE`.
|
||||
|
||||
## Dependencies and recovery
|
||||
|
||||
- **Networks/dependencies:** Pocket ID uses the external `npm_proxy` network at `192.168.100.10`; no dependent
|
||||
services are declared
|
||||
- **Back up:** `/srv/appdata/pocketid/data` and the separately protected `/srv/docker/secrets/pocketid/
|
||||
encryption_key`
|
||||
- **Re-creatable:** the Pocket ID container itself; no persistent cache is declared
|
||||
|
||||
Reference in New Issue
Block a user