b7d296f6e9
The bootstrap hook created `admin` with no password, so the account could only use its API key and could not sign in on the web UI or the TUI. It also won the one-shot /api/bootstrap against whoever ran it by hand, and failed with exit 1 when the Secret already existed, which fails the Helm release. The hook now generates a 32-character password, stores username, password and api-key in the <release>-admin-key Secret, and reuses the stored password on later runs, so recreating the database brings the same account back. The password is written before the account is created, so a crash in between cannot leave an administrator nobody has the password for. When the server was bootstrapped by something else, it checks the stored password against /api/login and removes only the password it generated if that does not sign in, then exits cleanly. bootstrap.enabled: false still removes the hook and its role. Claude-Session: https://claude.ai/code/session_016mBLURvJoMuUEr9cB2RpUN
Terminal Duty documentation
The README is the short tour. These pages hold the detail.
Running it
- Deployment: Docker, the Helm chart, the database, backups, and the operator.
- Configuration: environment variables and settings.
- Single sign-on: OIDC, group mapping, the terminal device flow.
Using it
- The web UI: sessions, the Team and Admin tabs.
- Alertmanager configuration: routes, integration keys and webhooks.
- Alerts and incidents: correlation, lifecycle, on-call assignment, stale-alert expiry.
- Push notifications: ntfy pages and acknowledging from them.
- Escalation: ladders, repeats and the fallback topic.
- Dead man's switches: noticing that alerts stopped arriving.
Integrating and contributing
- API reference: every endpoint, authentication and error shape.
- Service accounts: non-human credentials for automation.
- Development and releasing: tests, the CI gate, the release pipeline.