Commit Graph
100 Commits
Author SHA1 Message Date
Jake Howard 6a14679edf Only add IPv4 address for PVE sys domain
For some reason, ipv6 doesn't really work with my current setup. It'll change at another time, so it's future me's problem
2023-12-31 23:01:53 +00:00
Jake Howard 56bfe544e4 nginx HTTPS redirect on ipv6 2023-12-31 22:49:11 +00:00
Jake Howard e03cc40bf3 Update DNS records to alias sys records 2023-12-31 21:10:55 +00:00
Jake Howard 6a23d8cab5 Use sys domain resource for reverse DNS 2023-12-31 18:22:21 +00:00
Jake Howard 8b21c7d64c Add record for PVE 2023-12-31 16:46:45 +00:00
Jake Howard 0e0d0c9b82 walker doesn't have a traefik anymore 2023-12-26 22:31:12 +00:00
Jake Howard 026d8db13e Be root when generating dhparams
This is needed to write to the destination
2023-12-24 19:44:30 +00:00
Jake Howard 593a945c5c Install nginx from package manager if available 2023-12-24 19:44:30 +00:00
Jake Howard bd15946f3b Update Nebula 2023-12-24 19:44:30 +00:00
Jake Howard f4b96afcfa Deploy ntfy 2023-12-23 16:40:53 +00:00
Jake Howard c0c7f393e3 Only pin to minor versions of gitea 2023-12-21 16:43:18 +00:00
Jake Howard 5fd952be4c Only pin to minor version of Authentik 2023-12-21 16:42:02 +00:00
Jake Howard 1e798ac5ce Don't require role variables to be prefixed 2023-12-21 16:38:24 +00:00
Jake Howard 39899cd1e0 Use certbot to issue certificates 2023-12-21 16:38:07 +00:00
Jake Howard 8e1a203df2 Add helper map for better websocket support 2023-12-21 16:38:07 +00:00
Jake Howard a3baf8be1e Use nginx as reverse proxy on walker, removing traefik
SSL coming soon
2023-12-21 16:38:07 +00:00
Jake Howard a7eb372899 Fix HTTPS redirect hostname 2023-12-21 14:58:19 +00:00
Jake Howard 80a770f399 Add include files before main nginx config 2023-12-21 14:58:04 +00:00
Jake Howard ef432642dd Unify nginx module tasks 2023-12-20 22:35:11 +00:00
Jake Howard b32a63bd72 Add helpful includes
Along with ensuring there are dhparams
2023-12-20 22:29:42 +00:00
Jake Howard 2336e4dd5b Add brotli 2023-12-17 18:12:33 +00:00
Jake Howard 46eda36515 Fully block Server header 2023-12-16 21:57:19 +00:00
Jake Howard cfb498d7c6 Only add HTTPS redirect when it's needed 2023-12-16 18:13:49 +00:00
Jake Howard 48efcf4d91 Use mainline nginx release on Arch 2023-12-16 18:03:01 +00:00
Jake Howard 930cf87084 gzip as much as makes sense 2023-12-16 17:58:15 +00:00
Jake Howard 92052a3d0a Unify nginx configuration
This creates a simple base configuration skeleton, that other configuration can be easily loaded into.
2023-12-16 17:47:04 +00:00
Jake Howard 943c141d59 Ensure ingress proxy doesn't terminate connections
This mostly works around a weird issues with Jellyfin
2023-12-14 22:08:02 +00:00
Jake Howard 2ff2128330 Set pihole temp unit 2023-12-14 22:04:14 +00:00
Jake Howard b33e19e152 Remove unnecessary extra variable definitions
The world could do with a bit less YAML!
2023-12-14 22:03:23 +00:00
Jake Howard 7ad5d6e51e Deploy coredns as a proxy to Docker's internal DNS 2023-12-14 21:04:26 +00:00
Jake Howard 7381c1f10a Update nextcloud version in config.php 2023-12-13 17:48:46 +00:00
Jake Howard c0df505f70 Disable browser updates for nextcloud 2023-12-04 09:39:14 +00:00
Jake Howard aecd7c0a18 Upgrade nextcloud version in config 2023-12-04 09:38:43 +00:00
Jake Howard e815fcb2be Pin all redis versions to 7
Keeps them all in sync
2023-12-04 09:22:51 +00:00
Jake Howard 461ec71b12 Update gitea branding path 2023-11-27 19:19:58 +00:00
Jake Howard 8666933bfb Revert "Use OIDC to log in to tt-rss"
OIDC breaks any kind of API integration, which is very annoying

This reverts commit 66ddef96e2.
2023-11-18 21:57:16 +00:00
Jake Howard 3df1e1d46b Update Nextcloud version in config.php 2023-11-13 18:22:42 +00:00
Jake Howard e4b2318c82 Monitor authentik 2023-11-12 21:25:02 +00:00
Jake Howard dfef31cbfa Deploy minio
My own S3, for various things
2023-11-12 21:23:54 +00:00
Jake Howard 38840402b9 Disable repo units I don't use by default 2023-11-12 18:28:01 +00:00
Jake Howard 5f31a39804 Ensure Nextcloud can talk to local servers
Needed for Authentik
2023-11-08 19:51:16 +00:00
Jake Howard 6b1f5343f9 Always use diff when running deploys 2023-11-08 19:46:28 +00:00
Jake Howard 66ddef96e2 Use OIDC to log in to tt-rss 2023-11-08 19:46:16 +00:00
Jake Howard 935b099c4f Decommission upload
It was never really used for anything, and I want to replace it with something better eventually
2023-11-07 21:17:21 +00:00
Jake Howard dbbfe55975 Deploy authentik
_again_.
2023-11-07 21:17:21 +00:00
Jake Howard 48dbaeed99 Deploy remark42
To soon replace Commento
2023-11-06 21:29:28 +00:00
Jake Howard 5fb605231d Allow pings to ingress
This makes testing connections much simpler
2023-11-05 21:48:25 +00:00
Jake Howard dd1558bafa Set sensible permissions on nftables config 2023-11-05 21:43:16 +00:00
Jake Howard b0347fc037 Remove redundant quotes 2023-11-05 21:43:02 +00:00
Jake Howard 64f5763571 Ensure nginx role is actually installed 2023-11-05 21:37:33 +00:00
Jake Howard f1ac40f432 Reduce pihole cache size
This is still a lot of records, and pihole complains with values any larger
2023-11-05 13:22:05 +00:00
Jake Howard 850278ab19 Allow nebula through firewall 2023-11-03 18:06:36 +00:00
Jake Howard b1284877a3 Update blackbox configuration for not following redirects 2023-11-01 22:14:35 +00:00
Jake Howard 6b4285a264 Let alertmanager run as its own user
It's already not-root, and can't access the filesystem anyway
2023-11-01 22:13:37 +00:00
Jake Howard 3ed786336e Remove wireguard_53
I never used it - no reason to maintain it
2023-10-26 21:50:22 +01:00
Jake Howard 9f83efa53b Use nftables for firewall on ingress
See ya never, iptables!
2023-10-26 21:34:06 +01:00
Jake Howard 54e2205e48 Don't bother renaming speedtest metrics 2023-10-23 22:09:25 +01:00
Jake Howard c29dfb5ad2 Add hostname label for blackbox 2023-10-23 21:06:43 +01:00
Jake Howard 4950082c28 Remove deprecated gitea config settings 2023-10-15 21:27:23 +01:00
Jake Howard ad867f9654 Add JWT secret for gitea
This appeared in my config - it's probably important
2023-10-15 18:55:24 +01:00
Jake Howard ad3b5bc42d Move repo archive to "files" subvolume
It's better suited for this kind of file storage
2023-10-15 18:53:30 +01:00
Jake Howard 0780d255ed Remove grafana-cloud
I've migrated back to Uptime Robot, for simplicity. Sadly their API limits make it almost impossible to properly Terraform.
2023-10-09 19:48:39 +01:00
Jake Howard 37b8c48a77 Remove legacy short domains
I never used them, and the certificate renewal didn't work anyway.
2023-10-02 09:37:05 +01:00
Jake Howard 54c88d4253 Fix lint issues 2023-10-01 17:10:37 +01:00
Jake Howard 5770ab4a59 Sync dokku data to tank
This is much easier than mounting the files themselves
2023-10-01 17:06:09 +01:00
Jake Howard 3b303e4940 Deploy db-auto-backup to dokku
It might have DBs somewhen
2023-10-01 16:47:06 +01:00
Jake Howard a54a91ea44 Deploy a dokku 2023-10-01 16:34:01 +01:00
Jake Howard b02be4e77a Add email to Vikunja 2023-10-01 14:08:25 +01:00
Jake Howard 28a5089190 Bootstrap a new dokku machine on PVE 2023-09-29 22:03:23 +01:00
Jake Howard 12c46e50b5 Decommission grimes
Dokku will return, soon...
2023-09-29 21:42:05 +01:00
Jake Howard a1285612f1 Increase pihole cache 2023-09-24 13:45:40 +01:00
Jake Howard 1801a21e5d Update nextcloud config to 27.1.1 2023-09-23 21:51:15 +01:00
Jake Howard 7de73287fd Move spotify proxy alongside website
That's all it's really used for right now.
2023-09-21 14:20:54 +01:00
Jake Howard 27da7a7494 Fix occ command 2023-09-18 19:21:42 +01:00
Jake Howard 0789abaa0b Update nextcloud config version 2023-09-18 18:49:04 +01:00
Jake Howard d3c6e65053 Change sensitivity to medium for all alerts
It's a bit too flaky for 95%
2023-09-18 18:36:06 +01:00
Jake Howard e56ffa576f Deploy vikunja 2023-09-07 20:18:32 +01:00
Jake Howard d16feb2f89 Override DNS for vaultwarden
Make sure it finds icons for local applications
2023-09-07 18:04:03 +01:00
Jake Howard 4aa4ac24d4 The partial probe map is enough for global coverage 2023-09-06 19:30:12 +01:00
Jake Howard a1bed2ca9f Reduce frequency on some monitoring probes
The frequency is per-region, so it's still quite regular
2023-09-06 19:22:02 +01:00
Jake Howard 5a0df92a6a Disable ip_forward
I don't need P2P comms for this, so disable this for extra security.

I should add a proper firewall at some point...
2023-09-01 19:52:36 +01:00
Jake Howard 81ccfeed30 Add helper to edit ansible vault 2023-08-31 09:21:14 +01:00
Jake Howard ccadc7fbfa Migrate wallabag to postgres 2023-08-28 19:10:37 +01:00
Jake Howard 2b75b526ac Update nextcloud version in config 2023-08-28 17:53:29 +01:00
Jake Howard 16be8dd87c Disable registration on wallabag
The documented default is wrong
2023-08-28 17:51:58 +01:00
Jake Howard 266601d6f5 Vaguely harden vaultwarden config 2023-08-16 22:03:22 +01:00
Jake Howard 82281c6307 Decommission BG 2023-08-01 21:49:20 +01:00
Jake Howard ce53032819 Fix nextcloud config dir 2023-08-01 21:19:35 +01:00
Jake Howard b499882ca7 Update Nextcloud to 27.0.1 2023-08-01 21:18:50 +01:00
Jake Howard dfa6ffdcd2 Update Gitea token for renovate
It seems in a recent update, the token stopped working, possibly due to a permissions issue.
2023-08-01 14:17:16 +01:00
Jake Howard 6224b8f675 Remove aurto
I never used it, and trust chaotic-aur enough for AUR things
2023-07-30 19:09:34 +01:00
Jake Howard b2f894c5da Move notes to GitHub 2023-07-26 08:39:30 +01:00
Jake Howard f5faad1b2d Upgrade Gitea to 1.20.1 2023-07-22 14:30:49 +01:00
Jake Howard a1d8764a90 Expose tt-rss plugins to nginx container 2023-07-21 12:57:01 +01:00
Jake Howard 5aff824389 Remove feediron plugin
It causes lots of issues for GitHub feeds
2023-07-21 09:13:24 +01:00
Jake Howard 4de69e3955 Rotate Gandi API key
Had to regenerate it to debug an issue
2023-07-17 15:03:04 +01:00
Jake Howard 0e9e63d8b7 Use correct gandi API 2023-07-17 15:03:04 +01:00
Jake Howard 9a65bc74a3 Correctly format domains for Gandi
Gandi requires CNAMEs end with `.`, because it doesn't handle that magically.
2023-07-17 14:26:12 +01:00
Jake Howard 9e7ccb81ec Fix external storage for gitea packages 2023-07-17 14:26:12 +01:00
Jake Howard 2e7d60d87d Use gandi as cert resolver for 0rng.one 2023-07-17 14:26:12 +01:00