Rename iPodderX to iPX (#56)
The app, the repository (rays/ipx), the image, the compose service and container, and the data folders on Tower take the new name. What stays: the 2004 iPodderX and ipodderx-core, which are history; the Postgres database and login, and ipodderx.sdf1.net with its Access and Authentik apps, which would each need moving outside this repo; and the first-start password, as ipx is shorter than the eight characters a password needs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
14
docs/sso.md
14
docs/sso.md
@@ -31,7 +31,7 @@ request it forwards through the tunnel, and ipx signs that person in.
|
||||
| Access application | Zero Trust → Access → Applications → `ipodderx` | Domain `ipodderx.sdf1.net`; identity providers: Authentik only, with instant auth; session 730h; policy *Require Login* allows a list of email addresses |
|
||||
| Tunnel route | Zero Trust → Networks → Tunnels → `rays-unraid` → Public hostnames | `ipodderx.sdf1.net` → HTTP `192.168.1.130:8099` |
|
||||
| DNS | `sdf1.net` | `ipodderx` CNAME to the tunnel, proxied |
|
||||
| ipx | `/mnt/fast/appdata/ipodderx/config.toml`, `[web]` | below |
|
||||
| ipx | `/mnt/fast/appdata/ipx/config.toml`, `[web]` | below |
|
||||
|
||||
```toml
|
||||
[web]
|
||||
@@ -51,7 +51,7 @@ on since 2026-09-19. Both can be read without the dashboard: a request to the si
|
||||
out is sent to `https://<team domain>/cdn-cgi/access/login/ipodderx.sdf1.net?kid=<AUD tag>&...`.
|
||||
|
||||
Restart ipx after editing it: `docker compose -f /mnt/fast/arcane/projects/content/compose.yaml
|
||||
restart ipodderx`.
|
||||
restart ipx`.
|
||||
|
||||
### What was missing
|
||||
|
||||
@@ -93,7 +93,7 @@ ordinary user with no feeds. An account made before the proxy can be given the n
|
||||
send:
|
||||
|
||||
```sh
|
||||
docker exec iPodderX ipx user rename <old name> <email address>
|
||||
docker exec iPX ipx user rename <old name> <email address>
|
||||
```
|
||||
|
||||
### Signing out
|
||||
@@ -109,10 +109,10 @@ feeds.
|
||||
|
||||
### The tile in Authentik's library
|
||||
|
||||
Authentik's library lists Authentik's own applications, and ipodderx signs in through the one
|
||||
called `Cloudflare Access`, so ipodderx needs a bookmark of its own to show up there. It is
|
||||
Authentik's library lists Authentik's own applications, and ipx signs in through the one
|
||||
called `Cloudflare Access`, so ipx needs a bookmark of its own to show up there. It is
|
||||
Applications → Applications → `ipodderx`: no provider, launch URL `https://ipodderx.sdf1.net`, and
|
||||
the iPodderX icon. Like Outline's, it has no policy bindings, so everyone in Authentik sees the
|
||||
the ipx logo. Like Outline's, it has no policy bindings, so everyone in Authentik sees the
|
||||
tile. Who actually gets in is still up to the Access policy.
|
||||
|
||||
### Check it
|
||||
@@ -222,7 +222,7 @@ echo -n 'newsecret' | ipx user passwd sam # change a password
|
||||
ipx user rm sam # remove the account
|
||||
```
|
||||
|
||||
In the container, put `docker exec iPodderX` in front, and `docker exec -i iPodderX` for the ones
|
||||
In the container, put `docker exec iPX` in front, and `docker exec -i iPX` for the ones
|
||||
that read a password.
|
||||
|
||||
Set `auto_create_users = false` once everyone who should have an account has one. After that the
|
||||
|
||||
Reference in New Issue
Block a user