# thingy! some kind of hosting setup ## setup 1. log into the vps, make sure it's fedora (or else 🔪) 2. create a new admin user - `sudo useradd -m -G wheel admin` - `sudo passwd admin` - `sudo su - admin` 3. use the system setup script, and log out - `sudo dnf install git -y` - `git clone https://gitlab.com/futile/thingy` - `./thingy/scripts/system-setup.sh` - `exit` 4. log in again, populate the `.env` and start everything up - `cd thingy` - `micro .env` - `docker compose up` 5. continue with service-specific setups ..... ## services specifics for everything **currently serving** - via docker - **caddy** – http server & reverse proxy - **stalwart** – mailserver - **bulwark** – webmail - via caddy - `mail.yaoi.dog` – mail (server & admin dash) - `post.yaoi.dog` – mail (webmail) **dns setup** | type | host | value | notes | |-------|-----------|---------------------------- |----------------------------| | `A` | `@` | `` | apex domain | | `A` | `mail` | `` | mailserver | | `A` | `post` | `` | webmail | | `CAA` | `@` | `0 issue "letsencrypt.org"` | allow caddy to issue certs | ### stalwart **first setup** 1. server identity - server hostname: `mail.yaoi.dog` - default email domain: `yaoi.dog` - automatically obtain tls certificate: `true` - generate email signing keys: `true` 2. storage - main data storage: `rocksdb` - path: `/var/lib/stalwart/` 3. account directory - directory type: `use internal` 4. logging - log destination: `console` 5. automatic dns management - dns server type: `porkbun` - description: `porkbun` **further setup** - settings -> security -> allowed ips - added `172.18.0.0/24`; reason: `internal` - settings -> network -> http -> security - permissive cors policy: `true` **[restart needed]** **useful links** - https://stalw.art/docs - https://testconnectivity.microsoft.com/tests/Imap/input - https://mail-tester.com ### bulwark **useful links** - https://bulwarkmail.org/docs ## backups - backups are done with [vykar](https://vykar.borgbase.com) to [borgbase](https://borgbase.com) - if on a new borgbase repo, run `vykar init` first - to back up automatically, run `sudo EDITOR=micro crontab -e` and add the following: ``` TZ=UTC 0 * * * * /home/admin/thingy/scripts/volume-backup.sh ``` ## todo - further secure the server (ratelimiting, hardening...) - more services - forgejo (need to change host ssh port to 2222) - vaultwarden - tie all services together with an sso (like voidauth)