Jake Howard
ee96e6ab08
Rename forrest role to prometheus
...
Makes organising much simpler
2024-04-21 19:47:02 +01:00
Jake Howard
ffbba254fb
Remove redundant quotes
2024-04-21 18:11:57 +01:00
Jake Howard
c472411801
Deploy uptime-kuma
2024-04-21 18:11:39 +01:00
Jake Howard
7564911da3
Add IPv6 to blackbox
...
This is needed to monitor private services
2024-04-20 18:12:38 +01:00
Jake Howard
7ff44ee238
Add IPv6 to proxmox internal network
2024-04-20 18:00:08 +01:00
Jake Howard
7c8d224c4a
Add headscale ACLs
...
Tags are managed entirely server side, so there's no priv esc issues.
This lets my devices do what they want, and server style devices can't do anything.
2024-04-20 15:46:21 +01:00
Jake Howard
33f9c544fd
Remove /tt-rss/ path from URL
2024-04-15 17:33:36 +01:00
Jake Howard
b6583cc823
Update Nextcloud version in config
2024-04-15 15:28:16 +01:00
Jake Howard
9c02017fed
Unpin tandoor
2024-04-15 15:28:16 +01:00
Jake Howard
8424b3211b
Allow ingress to serve as tailscale exit node
2024-03-28 23:30:24 +00:00
Jake Howard
b83e239123
Rename private domain
2024-03-23 12:55:54 +00:00
Jake Howard
5157940f20
Stop exposing homeassistant
2024-03-23 11:54:26 +00:00
Jake Howard
eb6fe3a23b
Allow forrest to access internal services
...
This is mostly for monitoring
2024-03-22 18:13:25 +00:00
Jake Howard
b2656bdf43
Make vaultwarden VPN only
...
The first service to go dark...
2024-03-21 23:20:27 +00:00
Jake Howard
124b83526d
Fix spacing
2024-03-20 17:59:32 +00:00
Jake Howard
0295507d0b
Increase frequency of snapshots
2024-03-19 21:31:27 +00:00
Jake Howard
f88d224168
Allow only exposing services over Tailscale
...
This works using public DNS, so doesn't need Tailscale's magic DNS to override my local.
2024-03-07 22:30:10 +00:00
Jake Howard
451a114262
Add IPv6 support for internal DNS overrides
...
CoreDNS 1.11.2 finally shipped!
2024-03-07 20:02:39 +00:00
Jake Howard
119b3212a9
Remove robots.txt for gitea
2024-03-04 08:38:16 +00:00
Jake Howard
82451784a8
Deploy slides hosting
2024-03-03 21:39:22 +00:00
Jake Howard
000f3d3348
Add HSTS to all nginx requests
2024-03-03 21:37:07 +00:00
Jake Howard
0dcc3f7c30
Use regular version of nginx on Arch
...
`nginx-mainline` requires modules be recompiled each time, and isn't handled automatically. It's still a very new and maintained release.
2024-02-29 19:46:32 +00:00
Jake Howard
8a1e21c79d
Ensure headscale sees the correct IP
2024-02-29 17:41:29 +00:00
Jake Howard
998d798797
Set maintenance window for nextcloud
2024-02-21 21:57:03 +00:00
Jake Howard
11a93dac55
Update nextcloud version in config
2024-02-21 21:52:58 +00:00
Jake Howard
808e72553b
Add the basics of some edge caching
2024-02-21 21:42:16 +00:00
Jake Howard
58c48261e7
Consolidate vikunja container
2024-02-12 14:12:17 +00:00
Jake Howard
91a247868b
Add routes from forrest to tailscale network
2024-02-07 22:12:08 +00:00
Jake Howard
df43be6f9b
Set private_ip for some other machines
2024-02-07 19:27:48 +00:00
Jake Howard
b6eca40ae0
Allow tailscale IP in more places
2024-02-07 18:21:16 +00:00
Jake Howard
02847355a7
Install tailscale
...
Install, not configure
2024-02-01 19:41:47 +00:00
Jake Howard
29cac09b48
Remove explicit port for headscale
2024-02-01 18:32:53 +00:00
Jake Howard
dba0262801
Remove website tmpfs
...
The server's disk is probably fast enough, and container restarts will nuke that storage anyway
2024-02-01 18:15:51 +00:00
Jake Howard
0c6528f9ca
Restrict access to headscale OIDC and API
2024-01-31 21:40:43 +00:00
Jake Howard
dfa8328e7b
Move gateway logs to separate file
2024-01-31 21:06:19 +00:00
Jake Howard
53c758a781
Monitor headscale with prometheus
2024-01-27 17:40:02 +00:00
Jake Howard
b51677b795
Back up headscale config
2024-01-27 15:04:53 +00:00
Jake Howard
2ceeaf091d
Deploy headscale
2024-01-27 14:18:37 +00:00
Jake Howard
06784563a7
Don't resolve ipv6
...
Something about this setup doesn't like it, so I'll disable v6 for now
2024-01-26 21:43:04 +00:00
Jake Howard
88f0828153
Use primary Quad9 servers
...
DNSSEC and malware blocking is probably useful, just in case
2024-01-21 23:19:49 +00:00
Jake Howard
cfc3de61b4
Add fallback quad9 address
...
This aids availability, along with a healthcheck
2024-01-21 23:05:25 +00:00
Jake Howard
c6bae0f797
Do simple endsWith matching for docker view
...
This saves the need for a regex
2024-01-14 22:27:02 +00:00
Jake Howard
4c5936b2aa
Disable Grafana analytics
2024-01-14 15:30:12 +00:00
Jake Howard
9d685d85aa
Update website deployment to unify containers
2024-01-14 14:22:19 +00:00
Jake Howard
ac166c3874
Start resolved to support mDNS
2024-01-10 13:28:45 +00:00
Jake Howard
06b9197c5b
Sync terraform state to restic
...
This allows it to be backed up easily
2024-01-09 19:56:06 +00:00
Jake Howard
4a69df1d6c
Ignore ansible-lint for nebula install block
...
I'm smarter than it is
2024-01-08 21:49:38 +00:00
Jake Howard
f33d19e156
Move AdGuardHome configuration to Terraform
...
https://git.theorangeone.net/systems/adguardhome
2024-01-08 21:45:28 +00:00
Jake Howard
ed59458f39
Add backups to tang
2024-01-08 19:20:55 +00:00
Jake Howard
616d20e23b
Tweak some AGH settings
2024-01-08 19:01:46 +00:00
Jake Howard
383a57d1f2
Use DoH endpoint fot quad9
...
Seems latency is much lower
2024-01-08 18:21:03 +00:00
Jake Howard
9f13ace88c
Use newer S3 configuration resources
2024-01-07 13:49:35 +00:00
Jake Howard
094091dd21
Add role for minio state management
2024-01-07 13:06:37 +00:00
Jake Howard
9ac9380387
Restructure state IAM to use separate role
2024-01-07 12:58:16 +00:00
Jake Howard
1555803d25
Move terraform state file
...
This lets me use the bucket for other states too
2024-01-06 21:28:57 +00:00
Jake Howard
c8211d4756
Use Debian repo version of nginx
...
It's older, and doesn't have `stream` compiled in, but the repo one can't link to any of the installed modules, which is a non-starter.
2024-01-04 14:17:36 +00:00
Jake Howard
57ad143268
Set password for homeassistant SMB mount
...
It had an IP restriction, but still
2024-01-03 21:23:49 +00:00
Jake Howard
16e9952b2f
Replace custom restic logs with runitor
2024-01-03 21:09:07 +00:00
Jake Howard
f5154d1683
Use CoreDNS to do recursive CNAME aliasing for AGH
2024-01-02 17:48:47 +00:00
Jake Howard
3ed7074af6
Rename coredns role
2024-01-02 17:02:34 +00:00
Jake Howard
5581bbc01a
Replace pihole with adguardhome
...
AGH is much simpler to install and manage, and does DoH natively.
2024-01-01 15:48:14 +00:00
Jake Howard
6a14679edf
Only add IPv4 address for PVE sys domain
...
For some reason, ipv6 doesn't really work with my current setup. It'll change at another time, so it's future me's problem
2023-12-31 23:01:53 +00:00
Jake Howard
56bfe544e4
nginx HTTPS redirect on ipv6
2023-12-31 22:49:11 +00:00
Jake Howard
e03cc40bf3
Update DNS records to alias sys records
2023-12-31 21:10:55 +00:00
Jake Howard
6a23d8cab5
Use sys domain resource for reverse DNS
2023-12-31 18:22:21 +00:00
Jake Howard
8b21c7d64c
Add record for PVE
2023-12-31 16:46:45 +00:00
Jake Howard
0e0d0c9b82
walker doesn't have a traefik anymore
2023-12-26 22:31:12 +00:00
Jake Howard
026d8db13e
Be root when generating dhparams
...
This is needed to write to the destination
2023-12-24 19:44:30 +00:00
Jake Howard
593a945c5c
Install nginx from package manager if available
2023-12-24 19:44:30 +00:00
Jake Howard
bd15946f3b
Update Nebula
2023-12-24 19:44:30 +00:00
Jake Howard
f4b96afcfa
Deploy ntfy
2023-12-23 16:40:53 +00:00
Jake Howard
c0c7f393e3
Only pin to minor versions of gitea
2023-12-21 16:43:18 +00:00
Jake Howard
5fd952be4c
Only pin to minor version of Authentik
2023-12-21 16:42:02 +00:00
Jake Howard
1e798ac5ce
Don't require role variables to be prefixed
2023-12-21 16:38:24 +00:00
Jake Howard
39899cd1e0
Use certbot to issue certificates
2023-12-21 16:38:07 +00:00
Jake Howard
8e1a203df2
Add helper map for better websocket support
2023-12-21 16:38:07 +00:00
Jake Howard
a3baf8be1e
Use nginx as reverse proxy on walker, removing traefik
...
SSL coming soon
2023-12-21 16:38:07 +00:00
Jake Howard
a7eb372899
Fix HTTPS redirect hostname
2023-12-21 14:58:19 +00:00
Jake Howard
80a770f399
Add include files before main nginx config
2023-12-21 14:58:04 +00:00
Jake Howard
ef432642dd
Unify nginx module tasks
2023-12-20 22:35:11 +00:00
Jake Howard
b32a63bd72
Add helpful includes
...
Along with ensuring there are dhparams
2023-12-20 22:29:42 +00:00
Jake Howard
2336e4dd5b
Add brotli
2023-12-17 18:12:33 +00:00
Jake Howard
46eda36515
Fully block Server header
2023-12-16 21:57:19 +00:00
Jake Howard
cfb498d7c6
Only add HTTPS redirect when it's needed
2023-12-16 18:13:49 +00:00
Jake Howard
48efcf4d91
Use mainline nginx release on Arch
2023-12-16 18:03:01 +00:00
Jake Howard
930cf87084
gzip as much as makes sense
2023-12-16 17:58:15 +00:00
Jake Howard
92052a3d0a
Unify nginx configuration
...
This creates a simple base configuration skeleton, that other configuration can be easily loaded into.
2023-12-16 17:47:04 +00:00
Jake Howard
943c141d59
Ensure ingress proxy doesn't terminate connections
...
This mostly works around a weird issues with Jellyfin
2023-12-14 22:08:02 +00:00
Jake Howard
2ff2128330
Set pihole temp unit
2023-12-14 22:04:14 +00:00
Jake Howard
b33e19e152
Remove unnecessary extra variable definitions
...
The world could do with a bit less YAML!
2023-12-14 22:03:23 +00:00
Jake Howard
7ad5d6e51e
Deploy coredns as a proxy to Docker's internal DNS
2023-12-14 21:04:26 +00:00
Jake Howard
7381c1f10a
Update nextcloud version in config.php
2023-12-13 17:48:46 +00:00
Jake Howard
c0df505f70
Disable browser updates for nextcloud
2023-12-04 09:39:14 +00:00
Jake Howard
aecd7c0a18
Upgrade nextcloud version in config
2023-12-04 09:38:43 +00:00
Jake Howard
e815fcb2be
Pin all redis versions to 7
...
Keeps them all in sync
2023-12-04 09:22:51 +00:00
Jake Howard
461ec71b12
Update gitea branding path
2023-11-27 19:19:58 +00:00
Jake Howard
8666933bfb
Revert "Use OIDC to log in to tt-rss"
...
OIDC breaks any kind of API integration, which is very annoying
This reverts commit 66ddef96e2 .
2023-11-18 21:57:16 +00:00
Jake Howard
3df1e1d46b
Update Nextcloud version in config.php
2023-11-13 18:22:42 +00:00
Jake Howard
e4b2318c82
Monitor authentik
2023-11-12 21:25:02 +00:00
Jake Howard
dfef31cbfa
Deploy minio
...
My own S3, for various things
2023-11-12 21:23:54 +00:00