# GlobalArt on-premises installation

Run GlobalArt products — OwnLate today, more later — in your own Kubernetes.
One script installs everything: the licence agent, the notification service and
the products you choose. Running it again upgrades the installation and keeps
its data.

## What you need

- A Kubernetes cluster (k3s is enough) and `kubectl` pointing at it.
- [Helm](https://helm.sh) 3.
- An ingress controller (nginx, Traefik on k3s, or another) and DNS for the
  hostnames you will use.
- The licence GlobalArt gave you.

The container images and charts are public — you do not sign in to download
them. The licence is what lets the services start: it is checked inside each
service, so without a licence in force nothing runs.

## Install

1. Download the installer and the configuration template:

   ```bash
   curl -fsSLO https://selfhosted.globalart.dev/install.sh
   curl -fsSLO https://selfhosted.globalart.dev/install.env.example
   chmod +x install.sh
   cp install.env.example install.env
   ```

2. Open `install.env` and fill it in — the licence, the hostnames, the mail
   server and the first administrator. Every setting is explained in the file.

3. Run it:

   ```bash
   ./install.sh install.env
   ```

   It installs the licence agent, waits for the licence, installs the
   notification service with your mail settings, and then each product. When it
   finishes it prints how to read the first administrator's password.

## After it finishes

- Open the app host from `install.env` (for OwnLate, `OWNLATE_APP_HOST`) and
  sign in as the first administrator. Read the password with the command the
  installer printed:

  ```bash
  kubectl -n ownlate get secret ownlate-env -o jsonpath='{.data.BOOTSTRAP_ADMIN_PASSWORD}' | base64 -d; echo
  ```

- Add the rest of your people on the admin screen. Each gets a letter with a
  link to set their own password, so the mail server must work.

- Point the command-line client at your installation once:

  ```bash
  ownlate login --api-url https://api.ownlate.example.com
  ```

## Sign-in with your identity provider

Passwords work out of the box. To let people sign in with your company's
identity provider instead (or as well), set `OWNLATE_OIDC_*` in `install.env`
and register this redirect URI with the provider:

```
https://<OWNLATE_API_HOST>/public/v1/auth/callback
```

With `OWNLATE_OIDC_AUTO_PROVISION=true` anyone the provider lets in gets an
account; otherwise an administrator adds people first and they are matched by
their verified email.

## A closed network

If the cluster has no way out to the internet:

1. Install without a licence key — the agent starts and shows the installation
   id:

   ```bash
   kubectl -n globalart-licensing get secret licence-installation \
     -o jsonpath='{.data.id}' | base64 -d; echo
   ```

2. Send the id to GlobalArt and get a licence file for it.

3. Set `LICENCE_FILE` (instead of `LICENCE_KEY`) in `install.env` and run the
   installer again.

The container images and charts still have to reach the cluster. In a closed
network, mirror them from `selfhosted.globalart.dev` into a registry the
cluster can read and set `REGISTRY_HOST`, `REGISTRY_USER`, `REGISTRY_PASSWORD`
and `CHART_REPO` in `install.env`.

## Upgrading

Download the newest `install.sh`, keep your `install.env`, and run it again.
Pin a version with `CHART_VERSION` in `install.env` if you want a specific
release rather than the newest. Databases, uploaded files and generated
secrets survive upgrades.

## Removing

```bash
helm uninstall ownlate -n ownlate
helm uninstall herald -n herald
helm uninstall licence -n globalart-licensing
```

Persistent volumes are kept on purpose. Delete them by hand if you want the
data gone.
