Commit Graph
100 Commits
Author SHA1 Message Date
Jake Howard 998d798797 Set maintenance window for nextcloud 2024-02-21 21:57:03 +00:00
Jake Howard 11a93dac55 Update nextcloud version in config 2024-02-21 21:52:58 +00:00
Jake Howard 808e72553b Add the basics of some edge caching 2024-02-21 21:42:16 +00:00
Jake Howard 58c48261e7 Consolidate vikunja container 2024-02-12 14:12:17 +00:00
Jake Howard 91a247868b Add routes from forrest to tailscale network 2024-02-07 22:12:08 +00:00
Jake Howard df43be6f9b Set private_ip for some other machines 2024-02-07 19:27:48 +00:00
Jake Howard b6eca40ae0 Allow tailscale IP in more places 2024-02-07 18:21:16 +00:00
Jake Howard 02847355a7 Install tailscale
Install, not configure
2024-02-01 19:41:47 +00:00
Jake Howard 29cac09b48 Remove explicit port for headscale 2024-02-01 18:32:53 +00:00
Jake Howard dba0262801 Remove website tmpfs
The server's disk is probably fast enough, and container restarts will nuke that storage anyway
2024-02-01 18:15:51 +00:00
Jake Howard 0c6528f9ca Restrict access to headscale OIDC and API 2024-01-31 21:40:43 +00:00
Jake Howard dfa8328e7b Move gateway logs to separate file 2024-01-31 21:06:19 +00:00
Jake Howard 53c758a781 Monitor headscale with prometheus 2024-01-27 17:40:02 +00:00
Jake Howard b51677b795 Back up headscale config 2024-01-27 15:04:53 +00:00
Jake Howard 2ceeaf091d Deploy headscale 2024-01-27 14:18:37 +00:00
Jake Howard 06784563a7 Don't resolve ipv6
Something about this setup doesn't like it, so I'll disable v6 for now
2024-01-26 21:43:04 +00:00
Jake Howard 88f0828153 Use primary Quad9 servers
DNSSEC and malware blocking is probably useful, just in case
2024-01-21 23:19:49 +00:00
Jake Howard cfc3de61b4 Add fallback quad9 address
This aids availability, along with a healthcheck
2024-01-21 23:05:25 +00:00
Jake Howard c6bae0f797 Do simple endsWith matching for docker view
This saves the need for a regex
2024-01-14 22:27:02 +00:00
Jake Howard 4c5936b2aa Disable Grafana analytics 2024-01-14 15:30:12 +00:00
Jake Howard 9d685d85aa Update website deployment to unify containers 2024-01-14 14:22:19 +00:00
Jake Howard ac166c3874 Start resolved to support mDNS 2024-01-10 13:28:45 +00:00
Jake Howard 06b9197c5b Sync terraform state to restic
This allows it to be backed up easily
2024-01-09 19:56:06 +00:00
Jake Howard 4a69df1d6c Ignore ansible-lint for nebula install block
I'm smarter than it is
2024-01-08 21:49:38 +00:00
Jake Howard f33d19e156 Move AdGuardHome configuration to Terraform
https://git.theorangeone.net/systems/adguardhome
2024-01-08 21:45:28 +00:00
Jake Howard ed59458f39 Add backups to tang 2024-01-08 19:20:55 +00:00
Jake Howard 616d20e23b Tweak some AGH settings 2024-01-08 19:01:46 +00:00
Jake Howard 383a57d1f2 Use DoH endpoint fot quad9
Seems latency is much lower
2024-01-08 18:21:03 +00:00
Jake Howard 9f13ace88c Use newer S3 configuration resources 2024-01-07 13:49:35 +00:00
Jake Howard 094091dd21 Add role for minio state management 2024-01-07 13:06:37 +00:00
Jake Howard 9ac9380387 Restructure state IAM to use separate role 2024-01-07 12:58:16 +00:00
Jake Howard 1555803d25 Move terraform state file
This lets me use the bucket for other states too
2024-01-06 21:28:57 +00:00
Jake Howard c8211d4756 Use Debian repo version of nginx
It's older, and doesn't have `stream` compiled in, but the repo one can't link to any of the installed modules, which is a non-starter.
2024-01-04 14:17:36 +00:00
Jake Howard 57ad143268 Set password for homeassistant SMB mount
It had an IP restriction, but still
2024-01-03 21:23:49 +00:00
Jake Howard 16e9952b2f Replace custom restic logs with runitor 2024-01-03 21:09:07 +00:00
Jake Howard f5154d1683 Use CoreDNS to do recursive CNAME aliasing for AGH 2024-01-02 17:48:47 +00:00
Jake Howard 3ed7074af6 Rename coredns role 2024-01-02 17:02:34 +00:00
Jake Howard 5581bbc01a Replace pihole with adguardhome
AGH is much simpler to install and manage, and does DoH natively.
2024-01-01 15:48:14 +00:00
Jake Howard 6a14679edf Only add IPv4 address for PVE sys domain
For some reason, ipv6 doesn't really work with my current setup. It'll change at another time, so it's future me's problem
2023-12-31 23:01:53 +00:00
Jake Howard 56bfe544e4 nginx HTTPS redirect on ipv6 2023-12-31 22:49:11 +00:00
Jake Howard e03cc40bf3 Update DNS records to alias sys records 2023-12-31 21:10:55 +00:00
Jake Howard 6a23d8cab5 Use sys domain resource for reverse DNS 2023-12-31 18:22:21 +00:00
Jake Howard 8b21c7d64c Add record for PVE 2023-12-31 16:46:45 +00:00
Jake Howard 0e0d0c9b82 walker doesn't have a traefik anymore 2023-12-26 22:31:12 +00:00
Jake Howard 026d8db13e Be root when generating dhparams
This is needed to write to the destination
2023-12-24 19:44:30 +00:00
Jake Howard 593a945c5c Install nginx from package manager if available 2023-12-24 19:44:30 +00:00
Jake Howard bd15946f3b Update Nebula 2023-12-24 19:44:30 +00:00
Jake Howard f4b96afcfa Deploy ntfy 2023-12-23 16:40:53 +00:00
Jake Howard c0c7f393e3 Only pin to minor versions of gitea 2023-12-21 16:43:18 +00:00
Jake Howard 5fd952be4c Only pin to minor version of Authentik 2023-12-21 16:42:02 +00:00
Jake Howard 1e798ac5ce Don't require role variables to be prefixed 2023-12-21 16:38:24 +00:00
Jake Howard 39899cd1e0 Use certbot to issue certificates 2023-12-21 16:38:07 +00:00
Jake Howard 8e1a203df2 Add helper map for better websocket support 2023-12-21 16:38:07 +00:00
Jake Howard a3baf8be1e Use nginx as reverse proxy on walker, removing traefik
SSL coming soon
2023-12-21 16:38:07 +00:00
Jake Howard a7eb372899 Fix HTTPS redirect hostname 2023-12-21 14:58:19 +00:00
Jake Howard 80a770f399 Add include files before main nginx config 2023-12-21 14:58:04 +00:00
Jake Howard ef432642dd Unify nginx module tasks 2023-12-20 22:35:11 +00:00
Jake Howard b32a63bd72 Add helpful includes
Along with ensuring there are dhparams
2023-12-20 22:29:42 +00:00
Jake Howard 2336e4dd5b Add brotli 2023-12-17 18:12:33 +00:00
Jake Howard 46eda36515 Fully block Server header 2023-12-16 21:57:19 +00:00
Jake Howard cfb498d7c6 Only add HTTPS redirect when it's needed 2023-12-16 18:13:49 +00:00
Jake Howard 48efcf4d91 Use mainline nginx release on Arch 2023-12-16 18:03:01 +00:00
Jake Howard 930cf87084 gzip as much as makes sense 2023-12-16 17:58:15 +00:00
Jake Howard 92052a3d0a Unify nginx configuration
This creates a simple base configuration skeleton, that other configuration can be easily loaded into.
2023-12-16 17:47:04 +00:00
Jake Howard 943c141d59 Ensure ingress proxy doesn't terminate connections
This mostly works around a weird issues with Jellyfin
2023-12-14 22:08:02 +00:00
Jake Howard 2ff2128330 Set pihole temp unit 2023-12-14 22:04:14 +00:00
Jake Howard b33e19e152 Remove unnecessary extra variable definitions
The world could do with a bit less YAML!
2023-12-14 22:03:23 +00:00
Jake Howard 7ad5d6e51e Deploy coredns as a proxy to Docker's internal DNS 2023-12-14 21:04:26 +00:00
Jake Howard 7381c1f10a Update nextcloud version in config.php 2023-12-13 17:48:46 +00:00
Jake Howard c0df505f70 Disable browser updates for nextcloud 2023-12-04 09:39:14 +00:00
Jake Howard aecd7c0a18 Upgrade nextcloud version in config 2023-12-04 09:38:43 +00:00
Jake Howard e815fcb2be Pin all redis versions to 7
Keeps them all in sync
2023-12-04 09:22:51 +00:00
Jake Howard 461ec71b12 Update gitea branding path 2023-11-27 19:19:58 +00:00
Jake Howard 8666933bfb Revert "Use OIDC to log in to tt-rss"
OIDC breaks any kind of API integration, which is very annoying

This reverts commit 66ddef96e2.
2023-11-18 21:57:16 +00:00
Jake Howard 3df1e1d46b Update Nextcloud version in config.php 2023-11-13 18:22:42 +00:00
Jake Howard e4b2318c82 Monitor authentik 2023-11-12 21:25:02 +00:00
Jake Howard dfef31cbfa Deploy minio
My own S3, for various things
2023-11-12 21:23:54 +00:00
Jake Howard 38840402b9 Disable repo units I don't use by default 2023-11-12 18:28:01 +00:00
Jake Howard 5f31a39804 Ensure Nextcloud can talk to local servers
Needed for Authentik
2023-11-08 19:51:16 +00:00
Jake Howard 6b1f5343f9 Always use diff when running deploys 2023-11-08 19:46:28 +00:00
Jake Howard 66ddef96e2 Use OIDC to log in to tt-rss 2023-11-08 19:46:16 +00:00
Jake Howard 935b099c4f Decommission upload
It was never really used for anything, and I want to replace it with something better eventually
2023-11-07 21:17:21 +00:00
Jake Howard dbbfe55975 Deploy authentik
_again_.
2023-11-07 21:17:21 +00:00
Jake Howard 48dbaeed99 Deploy remark42
To soon replace Commento
2023-11-06 21:29:28 +00:00
Jake Howard 5fb605231d Allow pings to ingress
This makes testing connections much simpler
2023-11-05 21:48:25 +00:00
Jake Howard dd1558bafa Set sensible permissions on nftables config 2023-11-05 21:43:16 +00:00
Jake Howard b0347fc037 Remove redundant quotes 2023-11-05 21:43:02 +00:00
Jake Howard 64f5763571 Ensure nginx role is actually installed 2023-11-05 21:37:33 +00:00
Jake Howard f1ac40f432 Reduce pihole cache size
This is still a lot of records, and pihole complains with values any larger
2023-11-05 13:22:05 +00:00
Jake Howard 850278ab19 Allow nebula through firewall 2023-11-03 18:06:36 +00:00
Jake Howard b1284877a3 Update blackbox configuration for not following redirects 2023-11-01 22:14:35 +00:00
Jake Howard 6b4285a264 Let alertmanager run as its own user
It's already not-root, and can't access the filesystem anyway
2023-11-01 22:13:37 +00:00
Jake Howard 3ed786336e Remove wireguard_53
I never used it - no reason to maintain it
2023-10-26 21:50:22 +01:00
Jake Howard 9f83efa53b Use nftables for firewall on ingress
See ya never, iptables!
2023-10-26 21:34:06 +01:00
Jake Howard 54e2205e48 Don't bother renaming speedtest metrics 2023-10-23 22:09:25 +01:00
Jake Howard c29dfb5ad2 Add hostname label for blackbox 2023-10-23 21:06:43 +01:00
Jake Howard 4950082c28 Remove deprecated gitea config settings 2023-10-15 21:27:23 +01:00
Jake Howard ad867f9654 Add JWT secret for gitea
This appeared in my config - it's probably important
2023-10-15 18:55:24 +01:00
Jake Howard ad3b5bc42d Move repo archive to "files" subvolume
It's better suited for this kind of file storage
2023-10-15 18:53:30 +01:00
Jake Howard 0780d255ed Remove grafana-cloud
I've migrated back to Uptime Robot, for simplicity. Sadly their API limits make it almost impossible to properly Terraform.
2023-10-09 19:48:39 +01:00