Jake Howard
|
c6bae0f797
|
Do simple endsWith matching for docker view
This saves the need for a regex
|
2024-01-14 22:27:02 +00:00 |
|
Jake Howard
|
4c5936b2aa
|
Disable Grafana analytics
|
2024-01-14 15:30:12 +00:00 |
|
Jake Howard
|
9d685d85aa
|
Update website deployment to unify containers
|
2024-01-14 14:22:19 +00:00 |
|
Jake Howard
|
ac166c3874
|
Start resolved to support mDNS
|
2024-01-10 13:28:45 +00:00 |
|
Jake Howard
|
06b9197c5b
|
Sync terraform state to restic
This allows it to be backed up easily
|
2024-01-09 19:56:06 +00:00 |
|
Jake Howard
|
4a69df1d6c
|
Ignore ansible-lint for nebula install block
I'm smarter than it is
|
2024-01-08 21:49:38 +00:00 |
|
Jake Howard
|
f33d19e156
|
Move AdGuardHome configuration to Terraform
https://git.theorangeone.net/systems/adguardhome
|
2024-01-08 21:45:28 +00:00 |
|
Jake Howard
|
ed59458f39
|
Add backups to tang
|
2024-01-08 19:20:55 +00:00 |
|
Jake Howard
|
616d20e23b
|
Tweak some AGH settings
|
2024-01-08 19:01:46 +00:00 |
|
Jake Howard
|
383a57d1f2
|
Use DoH endpoint fot quad9
Seems latency is much lower
|
2024-01-08 18:21:03 +00:00 |
|
Jake Howard
|
9f13ace88c
|
Use newer S3 configuration resources
|
2024-01-07 13:49:35 +00:00 |
|
Jake Howard
|
094091dd21
|
Add role for minio state management
|
2024-01-07 13:06:37 +00:00 |
|
Jake Howard
|
9ac9380387
|
Restructure state IAM to use separate role
|
2024-01-07 12:58:16 +00:00 |
|
Jake Howard
|
1555803d25
|
Move terraform state file
This lets me use the bucket for other states too
|
2024-01-06 21:28:57 +00:00 |
|
Jake Howard
|
c8211d4756
|
Use Debian repo version of nginx
It's older, and doesn't have `stream` compiled in, but the repo one can't link to any of the installed modules, which is a non-starter.
|
2024-01-04 14:17:36 +00:00 |
|
Jake Howard
|
57ad143268
|
Set password for homeassistant SMB mount
It had an IP restriction, but still
|
2024-01-03 21:23:49 +00:00 |
|
Jake Howard
|
16e9952b2f
|
Replace custom restic logs with runitor
|
2024-01-03 21:09:07 +00:00 |
|
Jake Howard
|
f5154d1683
|
Use CoreDNS to do recursive CNAME aliasing for AGH
|
2024-01-02 17:48:47 +00:00 |
|
Jake Howard
|
3ed7074af6
|
Rename coredns role
|
2024-01-02 17:02:34 +00:00 |
|
Jake Howard
|
5581bbc01a
|
Replace pihole with adguardhome
AGH is much simpler to install and manage, and does DoH natively.
|
2024-01-01 15:48:14 +00:00 |
|
Jake Howard
|
6a14679edf
|
Only add IPv4 address for PVE sys domain
For some reason, ipv6 doesn't really work with my current setup. It'll change at another time, so it's future me's problem
|
2023-12-31 23:01:53 +00:00 |
|
Jake Howard
|
56bfe544e4
|
nginx HTTPS redirect on ipv6
|
2023-12-31 22:49:11 +00:00 |
|
Jake Howard
|
e03cc40bf3
|
Update DNS records to alias sys records
|
2023-12-31 21:10:55 +00:00 |
|
Jake Howard
|
6a23d8cab5
|
Use sys domain resource for reverse DNS
|
2023-12-31 18:22:21 +00:00 |
|
Jake Howard
|
8b21c7d64c
|
Add record for PVE
|
2023-12-31 16:46:45 +00:00 |
|
Jake Howard
|
0e0d0c9b82
|
walker doesn't have a traefik anymore
|
2023-12-26 22:31:12 +00:00 |
|
Jake Howard
|
026d8db13e
|
Be root when generating dhparams
This is needed to write to the destination
|
2023-12-24 19:44:30 +00:00 |
|
Jake Howard
|
593a945c5c
|
Install nginx from package manager if available
|
2023-12-24 19:44:30 +00:00 |
|
Jake Howard
|
bd15946f3b
|
Update Nebula
|
2023-12-24 19:44:30 +00:00 |
|
Jake Howard
|
f4b96afcfa
|
Deploy ntfy
|
2023-12-23 16:40:53 +00:00 |
|
Jake Howard
|
c0c7f393e3
|
Only pin to minor versions of gitea
|
2023-12-21 16:43:18 +00:00 |
|
Jake Howard
|
5fd952be4c
|
Only pin to minor version of Authentik
|
2023-12-21 16:42:02 +00:00 |
|
Jake Howard
|
1e798ac5ce
|
Don't require role variables to be prefixed
|
2023-12-21 16:38:24 +00:00 |
|
Jake Howard
|
39899cd1e0
|
Use certbot to issue certificates
|
2023-12-21 16:38:07 +00:00 |
|
Jake Howard
|
8e1a203df2
|
Add helper map for better websocket support
|
2023-12-21 16:38:07 +00:00 |
|
Jake Howard
|
a3baf8be1e
|
Use nginx as reverse proxy on walker, removing traefik
SSL coming soon
|
2023-12-21 16:38:07 +00:00 |
|
Jake Howard
|
a7eb372899
|
Fix HTTPS redirect hostname
|
2023-12-21 14:58:19 +00:00 |
|
Jake Howard
|
80a770f399
|
Add include files before main nginx config
|
2023-12-21 14:58:04 +00:00 |
|
Jake Howard
|
ef432642dd
|
Unify nginx module tasks
|
2023-12-20 22:35:11 +00:00 |
|
Jake Howard
|
b32a63bd72
|
Add helpful includes
Along with ensuring there are dhparams
|
2023-12-20 22:29:42 +00:00 |
|
Jake Howard
|
2336e4dd5b
|
Add brotli
|
2023-12-17 18:12:33 +00:00 |
|
Jake Howard
|
46eda36515
|
Fully block Server header
|
2023-12-16 21:57:19 +00:00 |
|
Jake Howard
|
cfb498d7c6
|
Only add HTTPS redirect when it's needed
|
2023-12-16 18:13:49 +00:00 |
|
Jake Howard
|
48efcf4d91
|
Use mainline nginx release on Arch
|
2023-12-16 18:03:01 +00:00 |
|
Jake Howard
|
930cf87084
|
gzip as much as makes sense
|
2023-12-16 17:58:15 +00:00 |
|
Jake Howard
|
92052a3d0a
|
Unify nginx configuration
This creates a simple base configuration skeleton, that other configuration can be easily loaded into.
|
2023-12-16 17:47:04 +00:00 |
|
Jake Howard
|
943c141d59
|
Ensure ingress proxy doesn't terminate connections
This mostly works around a weird issues with Jellyfin
|
2023-12-14 22:08:02 +00:00 |
|
Jake Howard
|
2ff2128330
|
Set pihole temp unit
|
2023-12-14 22:04:14 +00:00 |
|
Jake Howard
|
b33e19e152
|
Remove unnecessary extra variable definitions
The world could do with a bit less YAML!
|
2023-12-14 22:03:23 +00:00 |
|
Jake Howard
|
7ad5d6e51e
|
Deploy coredns as a proxy to Docker's internal DNS
|
2023-12-14 21:04:26 +00:00 |
|
Jake Howard
|
7381c1f10a
|
Update nextcloud version in config.php
|
2023-12-13 17:48:46 +00:00 |
|
Jake Howard
|
c0df505f70
|
Disable browser updates for nextcloud
|
2023-12-04 09:39:14 +00:00 |
|
Jake Howard
|
aecd7c0a18
|
Upgrade nextcloud version in config
|
2023-12-04 09:38:43 +00:00 |
|
Jake Howard
|
e815fcb2be
|
Pin all redis versions to 7
Keeps them all in sync
|
2023-12-04 09:22:51 +00:00 |
|
Jake Howard
|
461ec71b12
|
Update gitea branding path
|
2023-11-27 19:19:58 +00:00 |
|
Jake Howard
|
8666933bfb
|
Revert "Use OIDC to log in to tt-rss"
OIDC breaks any kind of API integration, which is very annoying
This reverts commit 66ddef96e2.
|
2023-11-18 21:57:16 +00:00 |
|
Jake Howard
|
3df1e1d46b
|
Update Nextcloud version in config.php
|
2023-11-13 18:22:42 +00:00 |
|
Jake Howard
|
e4b2318c82
|
Monitor authentik
|
2023-11-12 21:25:02 +00:00 |
|
Jake Howard
|
dfef31cbfa
|
Deploy minio
My own S3, for various things
|
2023-11-12 21:23:54 +00:00 |
|
Jake Howard
|
38840402b9
|
Disable repo units I don't use by default
|
2023-11-12 18:28:01 +00:00 |
|
Jake Howard
|
5f31a39804
|
Ensure Nextcloud can talk to local servers
Needed for Authentik
|
2023-11-08 19:51:16 +00:00 |
|
Jake Howard
|
6b1f5343f9
|
Always use diff when running deploys
|
2023-11-08 19:46:28 +00:00 |
|
Jake Howard
|
66ddef96e2
|
Use OIDC to log in to tt-rss
|
2023-11-08 19:46:16 +00:00 |
|
Jake Howard
|
935b099c4f
|
Decommission upload
It was never really used for anything, and I want to replace it with something better eventually
|
2023-11-07 21:17:21 +00:00 |
|
Jake Howard
|
dbbfe55975
|
Deploy authentik
_again_.
|
2023-11-07 21:17:21 +00:00 |
|
Jake Howard
|
48dbaeed99
|
Deploy remark42
To soon replace Commento
|
2023-11-06 21:29:28 +00:00 |
|
Jake Howard
|
5fb605231d
|
Allow pings to ingress
This makes testing connections much simpler
|
2023-11-05 21:48:25 +00:00 |
|
Jake Howard
|
dd1558bafa
|
Set sensible permissions on nftables config
|
2023-11-05 21:43:16 +00:00 |
|
Jake Howard
|
b0347fc037
|
Remove redundant quotes
|
2023-11-05 21:43:02 +00:00 |
|
Jake Howard
|
64f5763571
|
Ensure nginx role is actually installed
|
2023-11-05 21:37:33 +00:00 |
|
Jake Howard
|
f1ac40f432
|
Reduce pihole cache size
This is still a lot of records, and pihole complains with values any larger
|
2023-11-05 13:22:05 +00:00 |
|
Jake Howard
|
850278ab19
|
Allow nebula through firewall
|
2023-11-03 18:06:36 +00:00 |
|
Jake Howard
|
b1284877a3
|
Update blackbox configuration for not following redirects
|
2023-11-01 22:14:35 +00:00 |
|
Jake Howard
|
6b4285a264
|
Let alertmanager run as its own user
It's already not-root, and can't access the filesystem anyway
|
2023-11-01 22:13:37 +00:00 |
|
Jake Howard
|
3ed786336e
|
Remove wireguard_53
I never used it - no reason to maintain it
|
2023-10-26 21:50:22 +01:00 |
|
Jake Howard
|
9f83efa53b
|
Use nftables for firewall on ingress
See ya never, iptables!
|
2023-10-26 21:34:06 +01:00 |
|
Jake Howard
|
54e2205e48
|
Don't bother renaming speedtest metrics
|
2023-10-23 22:09:25 +01:00 |
|
Jake Howard
|
c29dfb5ad2
|
Add hostname label for blackbox
|
2023-10-23 21:06:43 +01:00 |
|
Jake Howard
|
4950082c28
|
Remove deprecated gitea config settings
|
2023-10-15 21:27:23 +01:00 |
|
Jake Howard
|
ad867f9654
|
Add JWT secret for gitea
This appeared in my config - it's probably important
|
2023-10-15 18:55:24 +01:00 |
|
Jake Howard
|
ad3b5bc42d
|
Move repo archive to "files" subvolume
It's better suited for this kind of file storage
|
2023-10-15 18:53:30 +01:00 |
|
Jake Howard
|
0780d255ed
|
Remove grafana-cloud
I've migrated back to Uptime Robot, for simplicity. Sadly their API limits make it almost impossible to properly Terraform.
|
2023-10-09 19:48:39 +01:00 |
|
Jake Howard
|
37b8c48a77
|
Remove legacy short domains
I never used them, and the certificate renewal didn't work anyway.
|
2023-10-02 09:37:05 +01:00 |
|
Jake Howard
|
54c88d4253
|
Fix lint issues
|
2023-10-01 17:10:37 +01:00 |
|
Jake Howard
|
5770ab4a59
|
Sync dokku data to tank
This is much easier than mounting the files themselves
|
2023-10-01 17:06:09 +01:00 |
|
Jake Howard
|
3b303e4940
|
Deploy db-auto-backup to dokku
It might have DBs somewhen
|
2023-10-01 16:47:06 +01:00 |
|
Jake Howard
|
a54a91ea44
|
Deploy a dokku
|
2023-10-01 16:34:01 +01:00 |
|
Jake Howard
|
b02be4e77a
|
Add email to Vikunja
|
2023-10-01 14:08:25 +01:00 |
|
Jake Howard
|
28a5089190
|
Bootstrap a new dokku machine on PVE
|
2023-09-29 22:03:23 +01:00 |
|
Jake Howard
|
12c46e50b5
|
Decommission grimes
Dokku will return, soon...
|
2023-09-29 21:42:05 +01:00 |
|
Jake Howard
|
a1285612f1
|
Increase pihole cache
|
2023-09-24 13:45:40 +01:00 |
|
Jake Howard
|
1801a21e5d
|
Update nextcloud config to 27.1.1
|
2023-09-23 21:51:15 +01:00 |
|
Jake Howard
|
7de73287fd
|
Move spotify proxy alongside website
That's all it's really used for right now.
|
2023-09-21 14:20:54 +01:00 |
|
Jake Howard
|
27da7a7494
|
Fix occ command
|
2023-09-18 19:21:42 +01:00 |
|
Jake Howard
|
0789abaa0b
|
Update nextcloud config version
|
2023-09-18 18:49:04 +01:00 |
|
Jake Howard
|
d3c6e65053
|
Change sensitivity to medium for all alerts
It's a bit too flaky for 95%
|
2023-09-18 18:36:06 +01:00 |
|
Jake Howard
|
e56ffa576f
|
Deploy vikunja
|
2023-09-07 20:18:32 +01:00 |
|
Jake Howard
|
d16feb2f89
|
Override DNS for vaultwarden
Make sure it finds icons for local applications
|
2023-09-07 18:04:03 +01:00 |
|
Jake Howard
|
4aa4ac24d4
|
The partial probe map is enough for global coverage
|
2023-09-06 19:30:12 +01:00 |
|
Jake Howard
|
a1bed2ca9f
|
Reduce frequency on some monitoring probes
The frequency is per-region, so it's still quite regular
|
2023-09-06 19:22:02 +01:00 |
|