update
This commit is contained in:
+3
-3
@@ -1,16 +1,16 @@
|
|||||||
# stalwart
|
# stalwart
|
||||||
STALWART_PUBLIC_URL=https://m.example.org
|
STALWART_PUBLIC_URL=https://post.example.org
|
||||||
OIDC_KEY=GENERATE_STRING # openssl rand -hex 32
|
OIDC_KEY=GENERATE_STRING # openssl rand -hex 32
|
||||||
OIDC_SIGNATURE_KEY=GENERATE_PEM # openssl genpkey -algorithm EC -pkeyopt ec_paramgen_curve:secp384r1 -pkeyopt ec_param_enc:named_curve
|
OIDC_SIGNATURE_KEY=GENERATE_PEM # openssl genpkey -algorithm EC -pkeyopt ec_paramgen_curve:secp384r1 -pkeyopt ec_param_enc:named_curve
|
||||||
|
|
||||||
# bulwark
|
# bulwark
|
||||||
JMAP_SERVER_URL=https://m.example.org
|
JMAP_SERVER_URL=https://post.example.org
|
||||||
SESSION_SECRET=GENERATE_STRING # openssl rand -hex 32
|
SESSION_SECRET=GENERATE_STRING # openssl rand -hex 32
|
||||||
SETTINGS_SYNC_ENABLED=true
|
SETTINGS_SYNC_ENABLED=true
|
||||||
ADMIN_PASSWORD=GENERATE_PASSWORD # tr -dc 'A-Za-z0-9' < /dev/urandom | head -c 20; echo
|
ADMIN_PASSWORD=GENERATE_PASSWORD # tr -dc 'A-Za-z0-9' < /dev/urandom | head -c 20; echo
|
||||||
|
|
||||||
# vykar
|
# vykar
|
||||||
VYKAR_LABEL=borgbase
|
VYKAR_LABEL=borgbase
|
||||||
VYKAR_URL=https://myrepo.repo.borgbase.com
|
VYKAR_URL=https://REPO.repo.borgbase.com
|
||||||
VYKAR_ACCESS_TOKEN=ACCESS_TOKEN
|
VYKAR_ACCESS_TOKEN=ACCESS_TOKEN
|
||||||
VYKAR_ENCRYPTION_SECRET=GENERATE_STRING # openssl rand -hex 32
|
VYKAR_ENCRYPTION_SECRET=GENERATE_STRING # openssl rand -hex 32
|
||||||
|
|||||||
+1
-1
@@ -1 +1 @@
|
|||||||
.env
|
*.env
|
||||||
|
|||||||
@@ -3,14 +3,14 @@
|
|||||||
# acme_ca https://acme-staging-v02.api.letsencrypt.org/directory
|
# acme_ca https://acme-staging-v02.api.letsencrypt.org/directory
|
||||||
# }
|
# }
|
||||||
|
|
||||||
mail.yaoi.dog {
|
post.atom.town {
|
||||||
reverse_proxy stalwart:8080
|
reverse_proxy stalwart:8080
|
||||||
}
|
}
|
||||||
|
|
||||||
post.yaoi.dog {
|
mail.atom.town {
|
||||||
reverse_proxy bulwark:3000
|
reverse_proxy bulwark:3000
|
||||||
}
|
}
|
||||||
|
|
||||||
git.yaoi.dog {
|
git.atom.town {
|
||||||
reverse_proxy gitea:3000
|
reverse_proxy gitea:3000
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
# thingy!
|
# atom.town!
|
||||||
|
|
||||||
some kind of hosting setup
|
some kind of hosting setup
|
||||||
|
|
||||||
@@ -11,11 +11,11 @@ some kind of hosting setup
|
|||||||
- `sudo su - admin`
|
- `sudo su - admin`
|
||||||
3. use the system setup script, and log out
|
3. use the system setup script, and log out
|
||||||
- `sudo dnf install git -y`
|
- `sudo dnf install git -y`
|
||||||
- `git clone https://gitlab.com/futile/thingy`
|
- `git clone https://gitlab.com/futile/atom.town`
|
||||||
- `./thingy/scripts/system-setup.sh`
|
- `./atom.town/scripts/system-setup.sh`
|
||||||
- `exit`
|
- `exit`
|
||||||
4. log in again, populate the `.env` and start everything up
|
4. log in again, populate the `.env` and start everything up
|
||||||
- `cd thingy`
|
- `cd atom.town`
|
||||||
- `micro .env`
|
- `micro .env`
|
||||||
- `docker compose up`
|
- `docker compose up`
|
||||||
5. continue with service-specific setups .....
|
5. continue with service-specific setups .....
|
||||||
@@ -32,17 +32,17 @@ specifics for everything
|
|||||||
- **bulwark** – webmail
|
- **bulwark** – webmail
|
||||||
- **gitea** – git server
|
- **gitea** – git server
|
||||||
- via caddy
|
- via caddy
|
||||||
- `mail.yaoi.dog` – mail (server & admin dash)
|
- `post.atom.town` – mailserver, mail admin, and oidc
|
||||||
- `post.yaoi.dog` – mail (webmail)
|
- `mail.atom.town` – webmail
|
||||||
- `git.yaoi.dog` – git
|
- `git.atom.town` – git
|
||||||
|
|
||||||
**dns setup**
|
**dns setup**
|
||||||
|
|
||||||
| type | host | value | notes |
|
| type | host | value | notes |
|
||||||
|-------|-----------|---------------------------- |----------------------------|
|
|-------|-----------|---------------------------- |----------------------------|
|
||||||
| `A` | `@` | `<ip>` | apex domain |
|
| `A` | `@` | `<ip>` | apex domain |
|
||||||
| `A` | `mail` | `<ip>` | mailserver |
|
| `A` | `post` | `<ip>` | mailserver |
|
||||||
| `A` | `post` | `<ip>` | webmail |
|
| `A` | `mail` | `<ip>` | webmail |
|
||||||
| `A` | `git` | `<ip>` | gitea |
|
| `A` | `git` | `<ip>` | gitea |
|
||||||
| `CAA` | `@` | `0 issue "letsencrypt.org"` | allow caddy to issue certs |
|
| `CAA` | `@` | `0 issue "letsencrypt.org"` | allow caddy to issue certs |
|
||||||
|
|
||||||
@@ -57,8 +57,8 @@ specifics for everything
|
|||||||
<summary>initial setup</summary>
|
<summary>initial setup</summary>
|
||||||
|
|
||||||
1. server identity
|
1. server identity
|
||||||
- server hostname: `mail.yaoi.dog`
|
- server hostname: `mail.atom.town`
|
||||||
- default email domain: `yaoi.dog`
|
- default email domain: `atom.town`
|
||||||
- automatically obtain tls certificate: `true`
|
- automatically obtain tls certificate: `true`
|
||||||
- generate email signing keys: `true`
|
- generate email signing keys: `true`
|
||||||
2. storage
|
2. storage
|
||||||
@@ -119,15 +119,15 @@ specifics for everything
|
|||||||
- path: `/data/gitea/gitea.db`
|
- path: `/data/gitea/gitea.db`
|
||||||
- general settings
|
- general settings
|
||||||
- site title: `We cock. Dick. BALLING.`
|
- site title: `We cock. Dick. BALLING.`
|
||||||
- server domain: `git.yaoi.dog`
|
- server domain: `git.atom.town`
|
||||||
- ssh server port: `22`
|
- ssh server port: `22`
|
||||||
- gitea base url: `https://git.yaoi.dog/`
|
- gitea base url: `https://git.atom.town/`
|
||||||
- enable update checker: `true`
|
- enable update checker: `true`
|
||||||
- email settings
|
- email settings
|
||||||
- smtp host: `mail.yaoi.dog`
|
- smtp host: `mail.atom.town`
|
||||||
- smtp port: `465`
|
- smtp port: `465`
|
||||||
- send email as: `"Gitea" <system@yaoi.dog>`
|
- send email as: `"Gitea" <system@atom.town>`
|
||||||
- smtp username: `system@yaoi.dog`
|
- smtp username: `system@atom.town`
|
||||||
- smtp password: `<password>`
|
- smtp password: `<password>`
|
||||||
- enable email notifications: `true`
|
- enable email notifications: `true`
|
||||||
- server and third-party service settings
|
- server and third-party service settings
|
||||||
@@ -135,7 +135,7 @@ specifics for everything
|
|||||||
- disable self-registration: `false`
|
- disable self-registration: `false`
|
||||||
- allow registration only through external services: `true`
|
- allow registration only through external services: `true`
|
||||||
- enable openid self-registration: `true`
|
- enable openid self-registration: `true`
|
||||||
- hidden email domain: `git.yaoi.dog`
|
- hidden email domain: `git.atom.town`
|
||||||
- password hash algorithm: `argon2`
|
- password hash algorithm: `argon2`
|
||||||
</details>
|
</details>
|
||||||
|
|
||||||
@@ -152,7 +152,7 @@ always remember to `docker compose stop` before doing any of this!
|
|||||||
- to back up automatically, run `sudo EDITOR=micro crontab -e` and add the following:
|
- to back up automatically, run `sudo EDITOR=micro crontab -e` and add the following:
|
||||||
```
|
```
|
||||||
TZ=UTC
|
TZ=UTC
|
||||||
0 6 * * * /home/admin/thingy/scripts/volume-backup.sh
|
0 6 * * * /home/admin/atom.town/scripts/volume-backup.sh
|
||||||
```
|
```
|
||||||
|
|
||||||
**restoring**
|
**restoring**
|
||||||
|
|||||||
@@ -19,13 +19,11 @@ function banner() {
|
|||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
# https://patorjk.com/software/taag/#p=display&f=Small+Slant
|
|
||||||
cat << 'EOF'
|
cat << 'EOF'
|
||||||
__ __ _
|
__ __
|
||||||
/ /_/ / (_)__ ___ ___ __
|
___ _/ /____ __ _ / /____ _ _____
|
||||||
/ __/ _ \/ / _ \/ _ `/ // /
|
/ _ `/ __/ _ \/ ' \_/ __/ _ \ |/|/ / _ \
|
||||||
\__/_//_/_/_//_/\_, /\_, /
|
\_,_/\__/\___/_/_/_(_)__/\___/__,__/_//_/
|
||||||
/___//___/
|
|
||||||
..... brought to you by futile
|
..... brought to you by futile
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
#!/usr/bin/env bash
|
#!/usr/bin/env bash
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
WORKING_DIR="/home/admin/thingy" # todo: better
|
WORKING_DIR="/home/admin/atom.town" # todo: better
|
||||||
LOG_FILE="/var/log/volume-backup.log"
|
LOG_FILE="/var/log/volume-backup.log"
|
||||||
|
|
||||||
function log() {
|
function log() {
|
||||||
|
|||||||
Reference in New Issue
Block a user