Compare commits

..

1 Commits

Author SHA1 Message Date
forust 1dec4de708 nya~ 2025-12-09 21:56:13 +01:00
29 changed files with 170 additions and 513 deletions
+7 -18
View File
@@ -2,8 +2,12 @@
sync.ffs_lock sync.ffs_lock
.sync.ffs_db .sync.ffs_db
# Copyparty # Environment
*.hist/ .env
.env.anna
.env.forust
.env.*
!.env.*example
# Volumes and data directories # Volumes and data directories
gitea/gitea-db/ gitea/gitea-db/
@@ -18,9 +22,6 @@ uptime-kuma/data/
termix/termix-data/* termix/termix-data/*
cfddns/config.json cfddns/config.json
checkmk/checkmk/* checkmk/checkmk/*
downtify/Downtify_downloads
headscale/config/*
headscale/data/*
# Steaming services files # Steaming services files
streaming/jellyfin/* streaming/jellyfin/*
@@ -33,15 +34,11 @@ streaming/prowlarr/*
# Homepage # Homepage
homepages/forust_files/assets/images/team/* homepages/forust_files/assets/images/team/*
homepages/forust_files/.well-known/*
# Traefik files # Traefik files
traefik/letsencrypt/acme.json traefik/letsencrypt/acme.json
traefik/dynamic/fileservers.yml
traefik/logs/* traefik/logs/*
# SSL Certificates
adguardhome/certs/*
traefik/certs/* traefik/certs/*
# Monitoring # Monitoring
@@ -84,11 +81,3 @@ replacements.txt
# Temp files # Temp files
edu_master/temp/ edu_master/temp/
temp/*
# Environment
.env
.env.anna
.env.forust
.env.*
!*example
+10 -16
View File
@@ -3,54 +3,48 @@ services:
image: adguard/adguardhome:latest image: adguard/adguardhome:latest
container_name: adguardhome container_name: adguardhome
restart: unless-stopped restart: unless-stopped
environment:
- TZ=${TZ}
ports: ports:
- "53:53/tcp" - "53:53/tcp"
- "53:53/udp" - "53:53/udp"
- "853:853/tcp" # DNS over TLS
# - "67:67/udp" # DHCP # - "67:67/udp" # DHCP
# - "68:68/tcp" # DHCP # - "68:68/tcp" # DHCP
# - "3000:3000/tcp" - "3000:3000/tcp"
volumes: volumes:
- ./data/work:/opt/adguardhome/work - ./data/work:/opt/adguardhome/work
- ./data/conf:/opt/adguardhome/conf - ./data/conf:/opt/adguardhome/conf
- ./certs:/certs:ro
networks: networks:
- proxy - traefik-proxy
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
- "traefik.docker.network=proxy" - "traefik.docker.network=traefik-proxy"
- "traefik.http.services.adguard.loadbalancer.server.port=3000"
# Prod Router # Prod Router
- "traefik.http.routers.adguard.rule=Host(`dns.forust.xyz`) || Host(`adguard.forust.xyz`)" - "traefik.http.routers.adguard.rule=Host(`adguard.forust.xyz`)"
- "traefik.http.routers.adguard.entrypoints=websecure" - "traefik.http.routers.adguard.entrypoints=websecure"
- "traefik.http.routers.adguard.middlewares=security-headers@file" - "traefik.http.routers.adguard.middlewares=security-headers@file"
- "traefik.http.routers.adguard.service=adguard" - "traefik.http.routers.adguard.service=adguard"
- "traefik.http.routers.adguard.tls=true" - "traefik.http.routers.adguard.tls=true"
- "traefik.http.services.adguard.loadbalancer.server.port=3000"
# Local Router # Local Router
- "traefik.http.routers.adguard-local.rule=Host(`dns.workstation.internal`) || Host(`adguard.internal`) || Host(`adguard.workstation.internal`)" - "traefik.http.routers.adguard-local.rule=Host(`adguard.workstation.internal`) || Host(`adguard.internal`)"
- "traefik.http.routers.adguard-local.entrypoints=websecure" - "traefik.http.routers.adguard-local.entrypoints=websecure"
- "traefik.http.routers.adguard-local.middlewares=security-headers@file" - "traefik.http.routers.adguard-local.middlewares=security-headers@file"
- "traefik.http.routers.adguard-local.service=adguard" - "traefik.http.routers.adguard-local.service=adguard"
- "traefik.http.routers.adguard-local.tls=true" - "traefik.http.routers.adguard-local.tls=true"
# Dev Router # Dev Router
- "traefik.http.routers.adguard-dev.rule=Host(`dns.gigaforust.internal`) || Host(`adguard.gigaforust.internal`)" - "traefik.http.routers.adguard-dev.rule=Host(`adguard.gigaforust.internal`)"
- "traefik.http.routers.adguard-dev.entrypoints=websecure" - "traefik.http.routers.adguard-dev.entrypoints=websecure"
- "traefik.http.routers.adguard-dev.middlewares=security-headers@file" - "traefik.http.routers.adguard-dev.middlewares=security-headers@file"
- "traefik.http.routers.adguard-dev.service=adguard" - "traefik.http.routers.adguard-dev.service=adguard"
- "traefik.http.routers.adguard-dev.tls=true" - "traefik.http.routers.adguard-dev.tls=true"
# DoH
- "traefik.http.routers.dns.rule=(Host(`dns.forust.xyz`) && PathPrefix(`/dns-query`))"
- "traefik.http.routers.dns.entrypoints=websecure"
- "traefik.http.routers.dns.service=adguard"
- "traefik.http.routers.dns.tls.certresolver=letsencrypt"
- glance.name=adguard - glance.name=adguard
- glance.url=https://adguard.forust.xyz/ - glance.url=https://adguard.forust.xyz/
- glance.description=AdGuard Home is a network-wide software for blocking ads. - glance.description=AdGuard Home is a network-wide software for blocking ads.
networks: networks:
proxy: traefik-proxy:
external: true external: true
+6 -6
View File
@@ -26,9 +26,9 @@ services:
command: server command: server
container_name: authentik-server container_name: authentik-server
restart: unless-stopped restart: unless-stopped
# ports: ports:
# - ${PORT_HTTP:-9000}:9000 - ${PORT_HTTP:-9000}:9000
# - ${PORT_HTTPS:-9443}:9443 - ${PORT_HTTPS:-9443}:9443
env_file: env_file:
- .env - .env
environment: environment:
@@ -40,7 +40,7 @@ services:
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
- "traefik.docker.network=proxy" - "traefik.docker.network=traefik-proxy"
# Services # Services
# - "traefik.http.services.authentik-server.loadbalancer.server.port=9443" # - "traefik.http.services.authentik-server.loadbalancer.server.port=9443"
- "traefik.http.services.authentik-server.loadbalancer.server.port=9000" - "traefik.http.services.authentik-server.loadbalancer.server.port=9000"
@@ -69,7 +69,7 @@ services:
- ./media:/media - ./media:/media
- ./custom-templates:/templates - ./custom-templates:/templates
networks: networks:
- proxy - traefik-proxy
- authentik - authentik
depends_on: depends_on:
postgresql: postgresql:
@@ -102,5 +102,5 @@ volumes:
driver: local driver: local
networks: networks:
authentik: authentik:
proxy: traefik-proxy:
external: true external: true
-2
View File
@@ -1,2 +0,0 @@
CMK_PASSWORD=password
TZ=Europe/Berlin
-50
View File
@@ -1,50 +0,0 @@
services:
checkmk:
image: "checkmk/check-mk-raw:2.4.0-latest"
container_name: "checkmk"
environment:
- CMK_PASSWORD=${CMK_PASSWORD:-password}
- CMK_SITE_ID=cmk
volumes:
- sites:/omd/sites
tmpfs:
- /opt/omd/sites/cmk/tmp:uid=1000,gid=1000
ports:
- 5000:5000
- 6776:8000
restart: unless-stopped
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.http.services.checkmk.loadbalancer.server.port=5000"
# Prod Router
- "traefik.http.routers.checkmk.rule=Host(`cmk.forust.xyz`)"
- "traefik.http.routers.checkmk.entrypoints=websecure"
- "traefik.http.routers.checkmk.service=checkmk"
- "traefik.http.routers.checkmk.middlewares=security-headers@file"
- "traefik.http.routers.checkmk.tls=true"
# Local Router
- "traefik.http.routers.checkmk-local.rule=Host(`cmk.workstation.internal`) || Host(`cmk.internal`)"
- "traefik.http.routers.checkmk-local.entrypoints=websecure"
- "traefik.http.routers.checkmk-local.service=checkmk"
- "traefik.http.routers.checkmk-local.middlewares=security-headers@file"
- "traefik.http.routers.checkmk-local.tls=true"
# Dev Router
- "traefik.http.routers.checkmk-dev.rule=Host(`cmk.gigaforust.internal`)"
- "traefik.http.routers.checkmk-dev.middlewares=security-headers@file"
- "traefik.http.routers.checkmk-dev.service=checkmk"
- "traefik.http.routers.checkmk-dev.entrypoints=websecure"
- "traefik.http.routers.checkmk-dev.tls=true"
networks:
- proxy
networks:
proxy:
external: true
volumes:
sites:
+3 -3
View File
@@ -16,10 +16,10 @@ services:
timeout: 10s timeout: 10s
retries: 3 retries: 3
networks: networks:
- proxy - traefik-proxy
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
- "traefik.docker.network=proxy" - "traefik.docker.network=traefik-proxy"
# Prod Router # Prod Router
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)" - "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
@@ -50,5 +50,5 @@ services:
- glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface. - glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface.
networks: networks:
proxy: traefik-proxy:
external: true external: true
-39
View File
@@ -1,39 +0,0 @@
services:
downtify:
container_name: downtify
image: ghcr.io/henriquesebastiao/downtify:latest
# ports:
# - '7077:8000'
labels:
- traefik.enable=true
- traefik.http.services.downtify.loadbalancer.server.port=8000
# Prod Router
- traefik.http.routers.downtify.rule=Host(`downtify.forust.xyz`)
- traefik.http.routers.downtify.entrypoints=websecure
- traefik.http.routers.downtify.middlewares=security-chain@file
- traefik.http.routers.downtify.service=downtify
- traefik.http.routers.downtify.tls=true
# Local Router
- traefik.http.routers.downtify-local.rule=Host(`downtify.workstation.internal`) || Host(`downtify.internal`)
- traefik.http.routers.downtify-local.entrypoints=websecure
- traefik.http.routers.downtify-local.middlewares=security-headers@file
- traefik.http.routers.downtify-local.service=downtify
- traefik.http.routers.downtify-local.tls=true
# Dev Router
- traefik.http.routers.downtify-dev.rule=Host(`downtify.gigaforust.internal`)
- traefik.http.routers.downtify-dev.entrypoints=websecure
- traefik.http.routers.downtify-dev.middlewares=security-chain@file
- traefik.http.routers.downtify-dev.service=downtify
- traefik.http.routers.downtify-dev.tls=true
networks:
- proxy
volumes:
- ./Downtify_downloads:/downloads
networks:
proxy:
external: true
+9 -20
View File
@@ -12,26 +12,15 @@ logging.basicConfig(
) )
logger = logging.getLogger(__name__) logger = logging.getLogger(__name__)
# Load configuration (adapted to .env keys) # Load configuration
def _env(key, default=None): LOGIN = os.getenv('EDU_LOGIN')
v = os.getenv(key, default) PASSWORD = os.getenv('EDU_PASSWORD')
if isinstance(v, str) and len(v) >= 2 and ((v[0] == '"' and v[-1] == '"') or (v[0] == "'" and v[-1] == "'")): URL_LOGIN = os.getenv('EDU_URL_LOGIN', 'https://edu.edu.vn.ua/user/login')
return v[1:-1] URL_VERIFY = os.getenv('EDU_URL_VERIFY', 'https://edu.edu.vn.ua/course/userlist')
return v INTERVAL = int(os.getenv('PHPSESSID_INTERVAL', 10))
USER_AGENT = os.getenv('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
LOGIN = _env('KEEPER_LOGIN') REDIS_HOST = os.getenv('REDIS_HOST', 'redis')
PASSWORD = _env('KEEPER_PASSWORD') REDIS_PORT = int(os.getenv('REDIS_PORT', 6379))
EDU_BASE = _env('EDU_URL_BASE', 'https://edu.edu.vn.ua')
EDU_LOGIN_PATH = _env('EDU_URL_LOGIN', '/user/login')
EDU_COURSES_PATH = _env('EDU_URL_COURSES', '/course/userlist')
URL_LOGIN = f"{EDU_BASE.rstrip('/')}/{EDU_LOGIN_PATH.lstrip('/')}"
URL_VERIFY = f"{EDU_BASE.rstrip('/')}/{EDU_COURSES_PATH.lstrip('/')}"
INTERVAL = int(_env('KEEPER_INTERVAL', 10))
USER_AGENT = _env('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
REDIS_HOST = _env('REDIS_HOST', 'redis')
REDIS_PORT = int(_env('REDIS_PORT', 6379))
SUCCESS_FILE = '/tmp/last_success' SUCCESS_FILE = '/tmp/last_success'
+23 -72
View File
@@ -3,8 +3,7 @@ import logging
import redis import redis
import json import json
from telegram import Update, InlineKeyboardButton, InlineKeyboardMarkup, ChatMember from telegram import Update, InlineKeyboardButton, InlineKeyboardMarkup
from telegram.constants import ChatType
from telegram.ext import Application, CommandHandler, CallbackQueryHandler, ContextTypes from telegram.ext import Application, CommandHandler, CallbackQueryHandler, ContextTypes
from playwright.async_api import async_playwright from playwright.async_api import async_playwright
@@ -16,23 +15,14 @@ logging.basicConfig(
logger = logging.getLogger(__name__) logger = logging.getLogger(__name__)
# Load environment variables # Load environment variables
def _env(key, default=None): WEBINAR_URL = os.getenv('WEBINAR_URL', 'https://edu.edu.vn.ua/webinar/useractive')
v = os.getenv(key, default) WEBINAR_CHECK_INTERVAL = int(os.getenv('WEBINAR_CHECK_INTERVAL', 60))
if isinstance(v, str) and len(v) >= 2 and ((v[0] == '"' and v[-1] == '"') or (v[0] == "'" and v[-1] == "'")): REDIS_HOST = os.getenv('REDIS_HOST', 'redis')
return v[1:-1] REDIS_PORT = int(os.getenv('REDIS_PORT', 6379))
return v PLAYWRIGHT_WS = os.getenv('PLAYWRIGHT_WS', 'ws://playwright-service:3000/ws')
USER_AGENT = os.getenv('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
EDU_BASE = _env('EDU_URL_BASE', 'https://edu.edu.vn.ua') WEBINAR_TELEGRAM_TOKEN = os.getenv('WEBINAR_TELEGRAM_TOKEN')
EDU_WEBINAR_PATH = _env('EDU_URL_WEBINAR', '/webinar/useractive') ADMIN_ID = int(os.getenv('WEBINAR_ADMIN_ID', '0'))
WEBINAR_URL = f"{EDU_BASE.rstrip('/')}/{EDU_WEBINAR_PATH.lstrip('/')}"
WEBINAR_CHECK_INTERVAL = int(_env('WEBINAR_CHECK_INTERVAL', 60))
REDIS_HOST = _env('REDIS_HOST', 'redis')
REDIS_PORT = int(_env('REDIS_PORT', 6379))
PLAYWRIGHT_WS = _env('PLAYWRIGHT_WS', 'ws://playwright-service:3000/ws')
USER_AGENT = _env('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
WEBINAR_TELEGRAM_TOKEN = _env('WEBINAR_TELEGRAM_TOKEN')
ADMIN_ID = int(_env('WEBINAR_ADMIN_ID', '0'))
# Redis Keys # Redis Keys
KEY_WHITELIST = "bot:whitelist" KEY_WHITELIST = "bot:whitelist"
@@ -58,7 +48,7 @@ TRANSLATIONS = {
'welcome_admin': "\n\n👑 <b>Режим администратора активен</b>", 'welcome_admin': "\n\n👑 <b>Режим администратора активен</b>",
'access_denied': "⛔ Доступ запрещен. Вас нет в белом списке.", 'access_denied': "⛔ Доступ запрещен. Вас нет в белом списке.",
'help_title': "🤖 <b>Помощь по боту</b>\n\n", 'help_title': "🤖 <b>Помощь по боту</b>\n\n",
'help_commands': "/start - Подписаться на уведомления\n/stop - Отписаться от уведомлений\n/help - Показать это сообщение\n/language - Сменить язык", 'help_commands': "/start - Подписаться на уведомления\n/help - Показать это сообщение\n/language - Сменить язык",
'help_admin': "\n<b>Команды администратора:</b>\n/adduser [user_id] - Добавить пользователя в белый список\n/removeuser [user_id] - Удалить пользователя из белого списка\nИли используйте панель ниже для управления настройками.", 'help_admin': "\n<b>Команды администратора:</b>\n/adduser [user_id] - Добавить пользователя в белый список\n/removeuser [user_id] - Удалить пользователя из белого списка\nИли используйте панель ниже для управления настройками.",
'admin_only': "⛔ Только для администратора!", 'admin_only': "⛔ Только для администратора!",
'user_added': "✅ Пользователь {user_id} добавлен в белый список", 'user_added': "✅ Пользователь {user_id} добавлен в белый список",
@@ -95,7 +85,7 @@ TRANSLATIONS = {
'welcome_admin': "\n\n👑 <b>Режим адміністратора активний</b>", 'welcome_admin': "\n\n👑 <b>Режим адміністратора активний</b>",
'access_denied': "⛔ Доступ заборонено. Вас немає в білому списку.", 'access_denied': "⛔ Доступ заборонено. Вас немає в білому списку.",
'help_title': "🤖 <b>Довідка по боту</b>\n\n", 'help_title': "🤖 <b>Довідка по боту</b>\n\n",
'help_commands': "/start - Підписатися на сповіщення\n/stop - Відписатися від сповіщень\n/help - Показати це повідомлення\n/language - Змінити мову", 'help_commands': "/start - Підписатися на сповіщення\n/help - Показати це повідомлення\n/language - Змінити мову",
'help_admin': "\n<b>Команди адміністратора:</b>\n/adduser [user_id] - Додати користувача до білого списку\n/removeuser [user_id] - Видалити користувача з білого списку\nАбо використовуйте панель нижче для керування налаштуваннями.", 'help_admin': "\n<b>Команди адміністратора:</b>\n/adduser [user_id] - Додати користувача до білого списку\n/removeuser [user_id] - Видалити користувача з білого списку\nАбо використовуйте панель нижче для керування налаштуваннями.",
'admin_only': "⛔ Тільки для адміністратора!", 'admin_only': "⛔ Тільки для адміністратора!",
'user_added': "✅ Користувач {user_id} доданий до білого списку", 'user_added': "✅ Користувач {user_id} доданий до білого списку",
@@ -132,7 +122,7 @@ TRANSLATIONS = {
'welcome_admin': "\n\n👑 <b>Admin Mode Active</b>", 'welcome_admin': "\n\n👑 <b>Admin Mode Active</b>",
'access_denied': "⛔ Access denied. You are not on the whitelist.", 'access_denied': "⛔ Access denied. You are not on the whitelist.",
'help_title': "🤖 <b>Bot Help</b>\n\n", 'help_title': "🤖 <b>Bot Help</b>\n\n",
'help_commands': "/start - Subscribe to notifications\n/stop - Unsubscribe from notifications\n/help - Show this message\n/language - Change language", 'help_commands': "/start - Subscribe to notifications\n/help - Show this message\n/language - Change language",
'help_admin': "\n<b>Admin Commands:</b>\n/adduser [user_id] - Add user to whitelist\n/removeuser [user_id] - Remove user from whitelist\nOr use the panel below to manage settings.", 'help_admin': "\n<b>Admin Commands:</b>\n/adduser [user_id] - Add user to whitelist\n/removeuser [user_id] - Remove user from whitelist\nOr use the panel below to manage settings.",
'admin_only': "⛔ Admin only!", 'admin_only': "⛔ Admin only!",
'user_added': "✅ User {user_id} added to whitelist", 'user_added': "✅ User {user_id} added to whitelist",
@@ -213,21 +203,6 @@ def is_whitelisted(user_id: int) -> bool:
return redis_client.sismember(KEY_WHITELIST, str(user_id)) return redis_client.sismember(KEY_WHITELIST, str(user_id))
async def is_group_admin(update: Update, context: ContextTypes.DEFAULT_TYPE) -> bool:
"""Check if the user is an administrator in the group."""
user = update.effective_user
chat = update.effective_chat
if chat.type in [ChatType.PRIVATE, "private"]:
return True
try:
member = await context.bot.get_chat_member(chat.id, user.id)
return member.status in [ChatMember.OWNER, ChatMember.ADMINISTRATOR]
except Exception as e:
logger.error(f"Failed to check admin status: {e}")
return False
def get_admin_keyboard(user_id: int): def get_admin_keyboard(user_id: int):
"""Generate admin panel keyboard.""" """Generate admin panel keyboard."""
whitelist_enabled = redis_client.get(KEY_WHITELIST_ENABLED) != "0" whitelist_enabled = redis_client.get(KEY_WHITELIST_ENABLED) != "0"
@@ -246,21 +221,19 @@ def get_admin_keyboard(user_id: int):
async def start(update: Update, context: ContextTypes.DEFAULT_TYPE): async def start(update: Update, context: ContextTypes.DEFAULT_TYPE):
"""Handle /start command.""" """Handle /start command."""
user = update.effective_user user = update.effective_user
chat = update.effective_chat logger.info(f"User {user.id} ({user.username}) started the bot.")
logger.info(f"User {user.id} ({user.username}) started the bot in chat {chat.id} ({chat.type}).")
# Check whitelist - MUST be the user executing the command
if not is_whitelisted(user.id): if not is_whitelisted(user.id):
await update.message.reply_text(t(user.id, 'access_denied')) await update.message.reply_text(t(user.id, 'access_denied'))
return return
# Add to subscribers (Chat ID!) # Add to subscribers
redis_client.sadd(KEY_SUBSCRIBERS, chat.id) redis_client.sadd(KEY_SUBSCRIBERS, user.id)
msg = t(chat.id, 'welcome', name=user.first_name) msg = t(user.id, 'welcome', name=user.first_name)
if user.id == ADMIN_ID and chat.type == "private": if user.id == ADMIN_ID:
msg += t(chat.id, 'welcome_admin') msg += t(user.id, 'welcome_admin')
await update.message.reply_text(msg, parse_mode='HTML', reply_markup=get_admin_keyboard(user.id)) await update.message.reply_text(msg, parse_mode='HTML', reply_markup=get_admin_keyboard(user.id))
else: else:
await update.message.reply_text(msg, parse_mode='HTML') await update.message.reply_text(msg, parse_mode='HTML')
@@ -268,39 +241,19 @@ async def start(update: Update, context: ContextTypes.DEFAULT_TYPE):
async def help_command(update: Update, context: ContextTypes.DEFAULT_TYPE): async def help_command(update: Update, context: ContextTypes.DEFAULT_TYPE):
"""Handle /help command.""" """Handle /help command."""
user_id = update.effective_user.id user_id = update.effective_user.id
chat_id = update.effective_chat.id msg = t(user_id, 'help_title') + t(user_id, 'help_commands')
msg = t(chat_id, 'help_title') + t(chat_id, 'help_commands')
if user_id == ADMIN_ID and update.effective_chat.type == "private": if user_id == ADMIN_ID:
msg += t(chat_id, 'help_admin') msg += t(user_id, 'help_admin')
await update.message.reply_text(msg, parse_mode='HTML', reply_markup=get_admin_keyboard(user_id)) await update.message.reply_text(msg, parse_mode='HTML', reply_markup=get_admin_keyboard(user_id))
else: else:
await update.message.reply_text(msg, parse_mode='HTML') await update.message.reply_text(msg, parse_mode='HTML')
async def stop_command(update: Update, context: ContextTypes.DEFAULT_TYPE):
"""Handle /stop command (unsubscribe)."""
user = update.effective_user
chat = update.effective_chat
# Permission check: Whitelisted user OR Group Admin
if not (is_whitelisted(user.id) or await is_group_admin(update, context)):
await update.message.reply_text(t(chat.id, 'access_denied')) # Or specific "admin only" message
return
redis_client.srem(KEY_SUBSCRIBERS, chat.id)
await update.message.reply_text(t(chat.id, 'whitelist_disabled').replace(" whitelist", " notifications").replace("Білий список", "Сповіщення").replace("Белый список", "Уведомления") if chat.id else "Unsubscribed")
async def language_command(update: Update, context: ContextTypes.DEFAULT_TYPE): async def language_command(update: Update, context: ContextTypes.DEFAULT_TYPE):
"""Handle /language command.""" """Handle /language command."""
user = update.effective_user user_id = update.effective_user.id
chat = update.effective_chat
# Permission check for groups
if not (is_whitelisted(user.id) or await is_group_admin(update, context)):
return
await update.message.reply_text( await update.message.reply_text(
t(chat.id, 'select_language'), t(user_id, 'select_language'),
parse_mode='HTML', parse_mode='HTML',
reply_markup=get_language_keyboard() reply_markup=get_language_keyboard()
) )
@@ -582,7 +535,6 @@ async def check_webinars_job(context: ContextTypes.DEFAULT_TYPE):
for sub_id in subscribers: for sub_id in subscribers:
try: try:
# Build message in user's language # Build message in user's language
# sub_id comes from redis set as string, convert to int for translation lookup
webinar_items = "\n\n".join([ webinar_items = "\n\n".join([
t(int(sub_id), 'webinar_item', name=w['name'], url=w['url']) t(int(sub_id), 'webinar_item', name=w['name'], url=w['url'])
for w in new_webinars for w in new_webinars
@@ -617,7 +569,6 @@ def main():
# Handlers # Handlers
app.add_handler(CommandHandler("start", start)) app.add_handler(CommandHandler("start", start))
app.add_handler(CommandHandler("stop", stop_command))
app.add_handler(CommandHandler("help", help_command)) app.add_handler(CommandHandler("help", help_command))
app.add_handler(CommandHandler("language", language_command)) app.add_handler(CommandHandler("language", language_command))
app.add_handler(CommandHandler("adduser", add_user)) app.add_handler(CommandHandler("adduser", add_user))
-3
View File
@@ -1,6 +1,3 @@
GITEA_POSTGRES_USER= GITEA_POSTGRES_USER=
GITEA_POSTGRES_PASSWORD= GITEA_POSTGRES_PASSWORD=
GITEA_POSTGRES_DB=gitea GITEA_POSTGRES_DB=gitea
GITEA_SMTP_PASS=
MAILER_ADDR=
SERVICE_EMAIL=email.used.by.services@domain.tld
+3 -16
View File
@@ -13,28 +13,18 @@ services:
- GITEA__database__NAME=gitea - GITEA__database__NAME=gitea
#Server #Server
- GITEA__server__ROOT_URL=https://gitea.forust.xyz - GITEA__server__ROOT_URL=https://gitea.forust.xyz
- GITEA__server__SSH_DOMAIN=gitssh.forust.xyz
- GITEA__server__SSH_PORT=2221 - GITEA__server__SSH_PORT=2221
# Mailer
- GITEA__mailer__ENABLED=true
- GITEA__mailer__FROM=${SERVICE_EMAIL}
- GITEA__mailer__SMTP_ADDR=${MAILER_ADDR}:465
- GITEA__mailer__USER=${SERVICE_EMAIL}
- GITEA__mailer__PASSWD=${GITEA_SMTP_PASS}
- GITEA__mailer__PROTOCOL=SMTP
- GITEA__service__REGISTER_EMAIL_CONFIRM=true
- GITEA__service__ENABLE_NOTIFY_MAIL=true
restart: always restart: always
networks: networks:
- gitea-db - gitea-db
- proxy - traefik-proxy
volumes: volumes:
- ./gitea-data:/data - ./gitea-data:/data
- /etc/timezone:/etc/timezone:ro - /etc/timezone:/etc/timezone:ro
- /etc/localtime:/etc/localtime:ro - /etc/localtime:/etc/localtime:ro
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
- "traefik.docker.network=proxy" - "traefik.docker.network=traefik-proxy"
# Prod Router # Prod Router
- "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)" - "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)"
@@ -57,9 +47,6 @@ services:
- "traefik.http.routers.gitea-dev.middlewares=security-headers@file" - "traefik.http.routers.gitea-dev.middlewares=security-headers@file"
- "traefik.http.routers.gitea-dev.service=gitea" - "traefik.http.routers.gitea-dev.service=gitea"
- "traefik.http.routers.gitea-dev.tls=true" - "traefik.http.routers.gitea-dev.tls=true"
- "traefik.tcp.routers.gitea.entrypoints=ssh"
- "traefik.tcp.routers.gitea.rule=HostSNI(`*`)"
- "traefik.tcp.services.gitea.loadbalancer.server.port=22"
ports: ports:
- "2221:22" - "2221:22"
depends_on: depends_on:
@@ -80,5 +67,5 @@ services:
networks: networks:
gitea-db: gitea-db:
external: false external: false
proxy: traefik-proxy:
external: true external: true
+5 -5
View File
@@ -11,12 +11,12 @@ services:
env_file: .env env_file: .env
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
- "traefik.docker.network=proxy" - "traefik.docker.network=traefik-proxy"
# Prod Router # Prod Router
- "traefik.http.routers.glance.rule=Host(`glance.forust.xyz`)" - "traefik.http.routers.glance.rule=Host(`glance.forust.xyz`)"
- "traefik.http.routers.glance.entrypoints=websecure" - "traefik.http.routers.glance.entrypoints=websecure"
- "traefik.http.routers.glance.middlewares=security-headers@file" - "traefik.http.routers.glance.middlewares=security-chain@file"
- "traefik.http.routers.glance.tls=true" - "traefik.http.routers.glance.tls=true"
# Local Router # Local Router
@@ -28,13 +28,13 @@ services:
# Dev Router # Dev Router
- "traefik.http.routers.glance-dev.rule=Host(`glance.gigaforust.internal`)" - "traefik.http.routers.glance-dev.rule=Host(`glance.gigaforust.internal`)"
- "traefik.http.routers.glance-dev.entrypoints=websecure" - "traefik.http.routers.glance-dev.entrypoints=websecure"
- "traefik.http.routers.glance-dev.middlewares=security-headers@file" - "traefik.http.routers.glance-dev.middlewares=security-chain@file"
- "traefik.http.routers.glance-dev.tls=true" - "traefik.http.routers.glance-dev.tls=true"
networks: networks:
- proxy - traefik-proxy
dns: dns:
- 1.1.1.1 - 1.1.1.1
- 8.8.8.8 - 8.8.8.8
networks: networks:
proxy: traefik-proxy:
external: true external: true
-84
View File
@@ -1,84 +0,0 @@
services:
server:
image: headscale/headscale:latest
restart: unless-stopped
command: serve
networks:
- proxy
volumes:
- ./config:/etc/headscale
- ./data:/var/lib/headscale
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.http.services.headscale.loadbalancer.server.port=8080"
- "traefik.http.services.headscale-metrics.loadbalancer.server.port=9090"
## SERVICE
# Prod Router
- "traefik.http.routers.headscale.rule=Host(`hs.forust.xyz`)"
- "traefik.http.routers.headscale.entrypoints=websecure"
- "traefik.http.routers.headscale.service=headscale"
- "traefik.http.routers.headscale.tls=true"
# Local Router
- "traefik.http.routers.headscale-local.rule=Host(`hs.workstation.internal`)"
- "traefik.http.routers.headscale-local.entrypoints=websecure"
- "traefik.http.routers.headscale-local.service=headscale"
- "traefik.http.routers.headscale-local.tls=true"
# Dev Router
- "traefik.http.routers.headscale-dev.rule=Host(`hs.gigaforust.internal`)"
- "traefik.http.routers.headscale-dev.entrypoints=websecure"
- "traefik.http.routers.headscale-dev.service=headscale"
- "traefik.http.routers.headscale-dev.tls=true"
## METRICS
# Prod Router
- "traefik.http.routers.headscale-metrics.rule=Host(`hs.forust.xyz`) && PathPrefix(`/metrics`)"
- "traefik.http.routers.headscale-metrics.entrypoints=websecure"
- "traefik.http.routers.headscale-metrics.service=headscale-metrics"
- "traefik.http.routers.headscale-metrics.tls=true"
# Local Router
- "traefik.http.routers.headscale-metrics-local.rule=Host(`hs.workstation.internal`) && PathPrefix(`/metrics`)"
- "traefik.http.routers.headscale-metrics-local.entrypoints=websecure"
- "traefik.http.routers.headscale-metrics-local.service=headscale-metrics"
- "traefik.http.routers.headscale-metrics-local.tls=true"
# Dev Router
- "traefik.http.routers.headscale-metrics-dev.rule=Host(`hs.gigaforust.internal`) && PathPrefix(`/metrics`)"
- "traefik.http.routers.headscale-metrics-dev.entrypoints=websecure"
- "traefik.http.routers.headscale-metrics-dev.service=headscale-metrics"
- "traefik.http.routers.headscale-metrics-dev.tls=true"
dns:
- 1.1.1.1
- 1.0.0.1
web:
image: goodieshq/headscale-admin:latest
restart: unless-stopped
networks:
- proxy
labels:
- "traefik.enable=true"
- "treafik.docker.network=proxy"
- "traefik.http.services.headscale-ui.loadbalancer.server.port=80"
# Prod Router
- "traefik.http.routers.headscale-ui.rule=Host(`hs.forust.xyz`) && PathPrefix(`/admin`)"
- "traefik.http.routers.headscale-ui.entrypoints=websecure"
- "traefik.http.routers.headscale-ui.middlewares=security-chain@file"
- "traefik.http.routers.headscale-ui.service=headscale-ui"
- "traefik.http.routers.headscale-ui.tls=true"
# Local Router
- "traefik.http.routers.headscale-ui-local.rule=Host(`hs.workstation.internal`) && PathPrefix(`/admin`)"
- "traefik.http.routers.headscale-ui-local.entrypoints=websecure"
- "traefik.http.routers.headscale-ui-local.middlewares=security-chain@file"
- "traefik.http.routers.headscale-ui-local.service=headscale-ui"
- "traefik.http.routers.headscale-ui-local.tls=true"
# Dev Router
- "traefik.http.routers.headscale-ui-dev.rule=Host(`hs.gigaforust.internal`) && PathPrefix(`/admin`)"
- "traefik.http.routers.headscale-ui-dev.entrypoints=websecure"
- "traefik.http.routers.headscale-ui-dev.middlewares=security-chain@file"
- "traefik.http.routers.headscale-ui-dev.service=headscale-ui"
- "traefik.http.routers.headscale-ui-dev.tls=true"
networks:
proxy:
external: true
-79
View File
@@ -1,79 +0,0 @@
# https://wiki.serversatho.me/en/headscale
# # Prod server_url
# server_url: https://hs.example.com
# # Local server_url
# server_url: https://hs.internal_domain.internal
# # Dev server_url
# server_url: https://hs.dev_internal_domain.internal
listen_addr: 0.0.0.0:8080
metrics_listen_addr: 127.0.0.1:9090
grpc_listen_addr: 127.0.0.1:50443
grpc_allow_insecure: false
noise:
private_key_path: /var/lib/headscale/noise_private.key
prefixes:
v4: 100.64.0.0/10
v6: fd7a:115c:a1e0::/48
allocation: sequential
derp:
server:
enabled: true
region_id: 999
region_code: "headscale"
region_name: "Headscale Embedded DERP"
stun_listen_addr: "0.0.0.0:3478"
private_key_path: /var/lib/headscale/derp_server_private.key
automatically_add_embedded_derp_region: true
ipv4: 1.2.3.4
ipv6: 2001:db8::1
urls:
- https://controlplane.tailscale.com/derpmap/default
paths: []
auto_update_enabled: true
update_frequency: 24h
disable_check_updates: false
ephemeral_node_inactivity_timeout: 30m
database:
type: sqlite
debug: false
gorm:
prepare_stmt: true
parameterized_queries: true
skip_err_record_not_found: true
slow_threshold: 1000
sqlite:
path: /var/lib/headscale/db.sqlite
write_ahead_log: true
wal_autocheckpoint: 1000
acme_url: https://acme-v02.api.letsencrypt.org/directory
acme_email: ""
tls_letsencrypt_hostname: ""
tls_letsencrypt_cache_dir: /var/lib/headscale/cache
tls_letsencrypt_challenge_type: HTTP-01
tls_letsencrypt_listen: ":http"
tls_cert_path: ""
tls_key_path: ""
log:
format: text
level: info
policy:
mode: database
path: ""
dns:
magic_dns: true
base_domain: example.com
nameservers:
global:
- 1.1.1.1
- 1.0.0.1
- 2606:4700:4700::1111
- 2606:4700:4700::1001
split: {}
search_domains: []
extra_records: []
unix_socket: /var/run/headscale/headscale.sock
unix_socket_permission: "0770"
logtail:
enabled: false
randomize_client_port: false
+10 -9
View File
@@ -3,16 +3,16 @@ services:
build: build:
context: . context: .
dockerfile: Dockerfile.forust dockerfile: Dockerfile.forust
# ports: ports:
# - "8085:80" - "8085:80"
restart: unless-stopped restart: unless-stopped
volumes: volumes:
- ./forust_files:/usr/share/nginx/html - ./forust_files:/usr/share/nginx/html
networks: networks:
- proxy - traefik-proxy
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
- "traefik.docker.network=proxy" - "traefik.docker.network=traefik-proxy"
# Services # Services
- "traefik.http.services.forust-homepage.loadbalancer.server.port=80" - "traefik.http.services.forust-homepage.loadbalancer.server.port=80"
@@ -42,16 +42,16 @@ services:
build: build:
context: . context: .
dockerfile: Dockerfile.xdfnx dockerfile: Dockerfile.xdfnx
# ports: ports:
# - "8086:80" - "8086:80"
restart: unless-stopped restart: unless-stopped
volumes: volumes:
- ./xdfnx_files:/usr/share/nginx/html - ./xdfnx_files:/usr/share/nginx/html
networks: networks:
- proxy - traefik-proxy
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
- "traefik.docker.network=proxy" - "traefik.docker.network=traefik-proxy"
# Services # Services
- "traefik.http.services.xdfnx-homepage.loadbalancer.server.port=80" - "traefik.http.services.xdfnx-homepage.loadbalancer.server.port=80"
@@ -77,6 +77,7 @@ services:
- "traefik.http.routers.xdfnx-dev.service=xdfnx-homepage" - "traefik.http.routers.xdfnx-dev.service=xdfnx-homepage"
- "traefik.http.routers.xdfnx-dev.tls=true" - "traefik.http.routers.xdfnx-dev.tls=true"
networks: networks:
proxy: traefik-proxy:
external: true external: true
+11 -1
View File
@@ -134,6 +134,7 @@ ul {
background-size: cover; background-size: cover;
} }
/* if no avatar added: */ /* if no avatar added: */
.placeholder::before { .placeholder::before {
content: "?"; content: "?";
@@ -155,9 +156,10 @@ footer {
text-align: center; text-align: center;
color: var(--dim); color: var(--dim);
font-size: 0.8rem; font-size: 0.8rem;
/* flag{why-are-you-here?} */ /* flag{why-are-you-here?} */
margin-top: 4rem; margin-top: 4rem;
} }
/* SMTH RESPONSIVE */ /* SMTH RESPONSIVE */
@media (max-width: 600px) { @media (max-width: 600px) {
.grid-2 { .grid-2 {
@@ -165,3 +167,11 @@ footer {
gap: 0; gap: 0;
} }
} }
/* nya~ */
.birthday {
color: var(--dim);
font-size: 0.75rem;
margin-top: 4px;
opacity: 0.75;
}
+9 -8
View File
@@ -41,14 +41,7 @@
</li> </li>
<li> <li>
<i class="fas fa-envelope"></i> <i class="fas fa-envelope"></i>
<a href="mailto:forust@forust.xyz">mail/contact@forust.xyz</a> <a href="mailto:forust@forust.xyz">forust@forust.xyz</a>
</li>
<li>
<i class="fa-solid fa-key"></i>
<a href=".well-known/pgp-key.asc">security/PGP Key</a>
</li>
<li>
<p class="comment"># PGP Key Fingerprint: A777 7CB7 D9C4 0A97 443D CCF0 7A3D A455 F820 5B82</p>
</li> </li>
</ul> </ul>
</section> </section>
@@ -126,6 +119,14 @@
<a href="https://chernuha.space" target="_blank">Chernuha</a> <a href="https://chernuha.space" target="_blank">Chernuha</a>
</div> </div>
<div class="member">
<div class="avatar"
style="background-image: url('assets/images/team/vv.jpg'); background-size: cover; background-position: center;">
</div>
<a href="./miku.html" target="_blank">vv</a>
<p class="birthday">Happy Birthday, darling ♡</p>
</div>
<div class="member"> <div class="member">
<div class="avatar" <div class="avatar"
style="background-image: url('assets/images/team/hudan.jpg'); background-size: cover; background-position: center;"> style="background-image: url('assets/images/team/hudan.jpg'); background-size: cover; background-position: center;">
Binary file not shown.

Before

Width:  |  Height:  |  Size: 42 KiB

+3 -3
View File
@@ -14,7 +14,7 @@ services:
- ./MeTube_downloads:/downloads - ./MeTube_downloads:/downloads
labels: labels:
- traefik.enable=true - traefik.enable=true
- "traefik.docker.network=proxy" - "traefik.docker.network=traefik-proxy"
# Prod Router # Prod Router
- "traefik.http.routers.metube.rule=Host(`metube.forust.xyz`)" - "traefik.http.routers.metube.rule=Host(`metube.forust.xyz`)"
@@ -39,7 +39,7 @@ services:
- "traefik.http.routers.metube-dev.tls=true" - "traefik.http.routers.metube-dev.tls=true"
networks: networks:
- proxy - traefik-proxy
networks: networks:
proxy: traefik-proxy:
external: true external: true
+3 -3
View File
@@ -23,11 +23,11 @@ services:
- 1.1.1.1 - 1.1.1.1
- 8.8.8.8 - 8.8.8.8
networks: networks:
- proxy - traefik-proxy
- n8n - n8n
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
- "traefik.docker.network=proxy" - "traefik.docker.network=traefik-proxy"
# Prod Router # Prod Router
- "traefik.http.routers.n8n.rule=Host(`n8n.forust.xyz`)" - "traefik.http.routers.n8n.rule=Host(`n8n.forust.xyz`)"
@@ -58,5 +58,5 @@ services:
networks: networks:
n8n: n8n:
external: false external: false
proxy: traefik-proxy:
external: true external: true
+9 -9
View File
@@ -9,7 +9,7 @@ services:
- /var/run/docker.sock:/var/run/docker.sock:ro - /var/run/docker.sock:/var/run/docker.sock:ro
networks: networks:
- nextcloud-aio - nextcloud-aio
- proxy # Optional: Connects the mastercontainer to the proxy network in order to make the built-in reverse proxy detection work. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md - traefik-proxy # Optional: Connects the mastercontainer to the traefik-proxy network in order to make the built-in reverse proxy detection work. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
# ports: # ports:
# - 8081:80 # may be removed if under reverse-proxy # - 8081:80 # may be removed if under reverse-proxy
# - 8443:8443 # - 8443:8443
@@ -17,7 +17,7 @@ services:
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
- "traefik.docker.network=proxy" - "traefik.docker.network=traefik-proxy"
# AIO Services configuration # AIO Services configuration
- "traefik.http.services.nextcloud-aio.loadbalancer.server.port=8080" - "traefik.http.services.nextcloud-aio.loadbalancer.server.port=8080"
@@ -25,21 +25,21 @@ services:
- "traefik.http.services.nextcloud-aio.loadbalancer.serverstransport=insecureTransport@file" - "traefik.http.services.nextcloud-aio.loadbalancer.serverstransport=insecureTransport@file"
# Prod Router # Prod Router
# - "traefik.http.routers.nextcloud-aio.rule=Host(`naio.forust.xyz`)" # - "traefik.http.routers.nextcloud-aio.rule=Host(`nextcloud-aio.forust.xyz`)"
# - "traefik.http.routers.nextcloud-aio.entrypoints=websecure" # - "traefik.http.routers.nextcloud-aio.entrypoints=websecure"
# - "traefik.http.routers.nextcloud-aio.middlewares=security-chain@file" # - "traefik.http.routers.nextcloud-aio.middlewares=security-headers"
# - "traefik.http.routers.nextcloud-aio.service=nextcloud-aio" # - "traefik.http.routers.nextcloud-aio.service=nextcloud-aio"
# - "traefik.http.routers.nextcloud-aio.tls=true" # - "traefik.http.routers.nextcloud-aio.tls=true"
# Local Router # Local Router
- "traefik.http.routers.nextcloud-aio-local.rule=Host(`naio.workstation.internal`) || Host(`nextcloud-aio.internal`)" - "traefik.http.routers.nextcloud-aio-local.rule=Host(`nextcloud-aio.workstation.internal`) || Host(`nextcloud-aio.internal`)"
- "traefik.http.routers.nextcloud-aio-local.entrypoints=websecure" - "traefik.http.routers.nextcloud-aio-local.entrypoints=websecure"
- "traefik.http.routers.nextcloud-aio-local.middlewares=security-headers@file" - "traefik.http.routers.nextcloud-aio-local.middlewares=security-headers@file"
- "traefik.http.routers.nextcloud-aio-local.service=nextcloud-aio" - "traefik.http.routers.nextcloud-aio-local.service=nextcloud-aio"
- "traefik.http.routers.nextcloud-aio-local.tls=true" - "traefik.http.routers.nextcloud-aio-local.tls=true"
# Dev Router # Dev Router
- "traefik.http.routers.nextcloud-aio-dev.rule=Host(`naio.gigaforust.internal`)" - "traefik.http.routers.nextcloud-aio-dev.rule=Host(`nextcloud-aio.gigaforust.internal`)"
- "traefik.http.routers.nextcloud-aio-dev.entrypoints=websecure" - "traefik.http.routers.nextcloud-aio-dev.entrypoints=websecure"
- "traefik.http.routers.nextcloud-aio-dev.middlewares=security-headers@file" - "traefik.http.routers.nextcloud-aio-dev.middlewares=security-headers@file"
- "traefik.http.routers.nextcloud-aio-dev.service=nextcloud-aio" - "traefik.http.routers.nextcloud-aio-dev.service=nextcloud-aio"
@@ -55,11 +55,11 @@ services:
AIO_DISABLE_BACKUP_SECTION: false AIO_DISABLE_BACKUP_SECTION: false
APACHE_PORT: 11000 # Is needed when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else). See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md APACHE_PORT: 11000 # Is needed when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else). See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
APACHE_IP_BINDING: 0.0.0.0 # Configure when going with reverse-proxy https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md APACHE_IP_BINDING: 0.0.0.0 # Configure when going with reverse-proxy https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
APACHE_ADDITIONAL_NETWORK: proxy # (Optional) Connect the apache container to an additional docker network. When going with reverse-proxy. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md APACHE_ADDITIONAL_NETWORK: traefik-proxy # (Optional) Connect the apache container to an additional docker network. When going with reverse-proxy. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
BORG_RETENTION_POLICY: --keep-within=7d --keep-weekly=4 --keep-monthly=6 # Backup retention See https://github.com/nextcloud/all-in-one#how-to-adjust-borgs-retention-policy BORG_RETENTION_POLICY: --keep-within=7d --keep-weekly=4 --keep-monthly=6 # Backup retention See https://github.com/nextcloud/all-in-one#how-to-adjust-borgs-retention-policy
COLLABORA_SECCOMP_DISABLED: false # Setting this to true allows to disable Collabora's Seccomp feature. See https://github.com/nextcloud/all-in-one#how-to-disable-collaboras-seccomp-feature COLLABORA_SECCOMP_DISABLED: false # Setting this to true allows to disable Collabora's Seccomp feature. See https://github.com/nextcloud/all-in-one#how-to-disable-collaboras-seccomp-feature
FULLTEXTSEARCH_JAVA_OPTIONS: "-Xms1024M -Xmx1024M" # adjust fulltextsearch java options. https://github.com/nextcloud/all-in-one#how-to-adjust-the-fulltextsearch-java-options FULLTEXTSEARCH_JAVA_OPTIONS: "-Xms1024M -Xmx1024M" # adjust fulltextsearch java options. https://github.com/nextcloud/all-in-one#how-to-adjust-the-fulltextsearch-java-options
NEXTCLOUD_DATADIR: /mnt/nextcloud/ncdata # Allows to set the host directory for Nextcloud's datadir. ⚠️⚠️⚠️ Warning: do not set or adjust this value after the initial Nextcloud installation is done! See https://github.com/nextcloud/all-in-one#how-to-change-the-default-location-of-nextclouds-datadir NEXTCLOUD_DATADIR: /media/forust/nextcloud/ncdata # Allows to set the host directory for Nextcloud's datadir. ⚠️⚠️⚠️ Warning: do not set or adjust this value after the initial Nextcloud installation is done! See https://github.com/nextcloud/all-in-one#how-to-change-the-default-location-of-nextclouds-datadir
NEXTCLOUD_MOUNT: /mnt/ # Allows the Nextcloud container to access the chosen directory on the host. See https://github.com/nextcloud/all-in-one#how-to-allow-the-nextcloud-container-to-access-directories-on-the-host NEXTCLOUD_MOUNT: /mnt/ # Allows the Nextcloud container to access the chosen directory on the host. See https://github.com/nextcloud/all-in-one#how-to-allow-the-nextcloud-container-to-access-directories-on-the-host
NEXTCLOUD_UPLOAD_LIMIT: 16G # https://github.com/nextcloud/all-in-one#how-to-adjust-the-upload-limit-for-nextcloud NEXTCLOUD_UPLOAD_LIMIT: 16G # https://github.com/nextcloud/all-in-one#how-to-adjust-the-upload-limit-for-nextcloud
NEXTCLOUD_MAX_TIME: 7200 # Max uploading time See https://github.com/nextcloud/all-in-one#how-to-adjust-the-max-execution-time-for-nextcloud NEXTCLOUD_MAX_TIME: 7200 # Max uploading time See https://github.com/nextcloud/all-in-one#how-to-adjust-the-max-execution-time-for-nextcloud
@@ -75,7 +75,7 @@ services:
# WATCHTOWER_DOCKER_SOCKET_PATH: /var/run/docker.sock # Needs to be specified if the docker socket on the host is not located in the default '/var/run/docker.sock'. For macos it needs to be '/var/run/docker.sock' # WATCHTOWER_DOCKER_SOCKET_PATH: /var/run/docker.sock # Needs to be specified if the docker socket on the host is not located in the default '/var/run/docker.sock'. For macos it needs to be '/var/run/docker.sock'
networks: networks:
proxy: traefik-proxy:
external: true external: true
nextcloud-aio: nextcloud-aio:
driver: bridge driver: bridge
+5 -5
View File
@@ -50,7 +50,7 @@ x-secret-key: &penpot-secret-key
networks: networks:
penpot: penpot:
proxy: traefik-proxy:
external: true external: true
volumes: volumes:
@@ -86,8 +86,8 @@ services:
penpot-frontend: penpot-frontend:
image: "penpotapp/frontend:${PENPOT_VERSION:-latest}" image: "penpotapp/frontend:${PENPOT_VERSION:-latest}"
restart: always restart: always
# ports: ports:
# - 9001:8080 - 9001:8080
volumes: volumes:
- penpot_assets:/opt/data/assets - penpot_assets:/opt/data/assets
@@ -98,11 +98,11 @@ services:
networks: networks:
- penpot - penpot
- proxy - traefik-proxy
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
- "traefik.docker.network=proxy" - "traefik.docker.network=traefik-proxy"
# Prod Router # Prod Router
- "traefik.http.routers.penpot.rule=Host(`penpot.forust.xyz`)" - "traefik.http.routers.penpot.rule=Host(`penpot.forust.xyz`)"
+3 -3
View File
@@ -10,10 +10,10 @@ services:
- 9443:9443 - 9443:9443
# - 8000:8000 # Remove if you do not intend to use Edge Agents # - 8000:8000 # Remove if you do not intend to use Edge Agents
networks: networks:
- proxy - traefik-proxy
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
- "traefik.docker.network=proxy" - "traefik.docker.network=traefik-proxy"
# Prod Router # Prod Router
- "traefik.http.routers.portainer.rule=Host(`portainer.forust.xyz`)" - "traefik.http.routers.portainer.rule=Host(`portainer.forust.xyz`)"
@@ -50,5 +50,5 @@ volumes:
networks: networks:
default: default:
name: portainer_network name: portainer_network
proxy: traefik-proxy:
external: true external: true
+5 -5
View File
@@ -3,15 +3,15 @@ services:
image: ghcr.io/lukegus/termix:latest image: ghcr.io/lukegus/termix:latest
container_name: termix container_name: termix
restart: unless-stopped restart: unless-stopped
# ports: ports:
# - "3331:8080" - "3331:8080"
volumes: volumes:
- ./termix-data:/app/data - ./termix-data:/app/data
environment: environment:
PORT: "8080" PORT: "8080"
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
- "traefik.docker.network=proxy" - "traefik.docker.network=traefik-proxy"
# Prod Router # Prod Router
- "traefik.http.routers.termix.rule=Host(`termix.forust.xyz`)" - "traefik.http.routers.termix.rule=Host(`termix.forust.xyz`)"
@@ -35,10 +35,10 @@ services:
- "traefik.http.routers.termix-dev.service=termix" - "traefik.http.routers.termix-dev.service=termix"
- "traefik.http.routers.termix-dev.tls=true" - "traefik.http.routers.termix-dev.tls=true"
networks: networks:
- proxy - traefik-proxy
networks: networks:
proxy: traefik-proxy:
external: true external: true
volumes: volumes:
+16 -16
View File
@@ -11,7 +11,7 @@ services:
# Providers # Providers
- "--providers.docker=true" - "--providers.docker=true"
- "--providers.docker.exposedbydefault=false" - "--providers.docker.exposedbydefault=false"
- "--providers.docker.network=proxy" - "--providers.docker.network=traefik-proxy"
- "--providers.file.directory=/etc/traefik/dynamic" - "--providers.file.directory=/etc/traefik/dynamic"
- "--providers.file.watch=true" - "--providers.file.watch=true"
@@ -23,26 +23,26 @@ services:
- "--entryPoints.web.http.redirections.entryPoint.scheme=https" - "--entryPoints.web.http.redirections.entryPoint.scheme=https"
- "--entryPoints.ssh.address=:2221" - "--entryPoints.ssh.address=:2221"
# Let's Encrypt # Let's Encrypt STAGING. CURRENTLY USING CF ORIGIN CA INSTEAD
- "--certificatesresolvers.letsencrypt.acme.email=${EMAIL}" # - "--certificatesresolvers.letsencrypt.acme.email=${EMAIL}"
- "--certificatesresolvers.letsencrypt.acme.storage=/letsencrypt/acme.json" # - "--certificatesresolvers.letsencrypt.acme.storage=/letsencrypt/acme.json"
- "--certificatesresolvers.letsencrypt.acme.httpchallenge=true"
- "--certificatesresolvers.letsencrypt.acme.httpchallenge.entrypoint=web"
# # STAGING
# - "--certificatesresolvers.letsencrypt.acme.caserver=https://acme-staging-v02.api.letsencrypt.org/directory" # - "--certificatesresolvers.letsencrypt.acme.caserver=https://acme-staging-v02.api.letsencrypt.org/directory"
# - "--certificatesresolvers.letsencrypt.acme.httpchallenge=true"
# - "--certificatesresolvers.letsencrypt.acme.httpchallenge.entrypoint=web"
# Cloudflare # Cloudflare
- "--entryPoints.web.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22" - "--entryPoints.web.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
- "--entryPoints.websecure.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22" - "--entryPoints.websecure.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
# # Logging
# - "--log.level=INFO" # Logging
# - "--log.filePath=/var/log/traefik/traefik.log" - "--log.level=INFO"
# - "--accesslog=true" - "--log.filePath=/var/log/traefik/traefik.log"
# - "--accesslog.filepath=/var/log/traefik/access.log" - "--accesslog=true"
- "--accesslog.filepath=/var/log/traefik/access.log"
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
- "traefik.docker.network=proxy" - "traefik.docker.network=traefik-proxy"
# Prod Router (Dash) # Prod Router (Dash)
- "traefik.http.routers.traefik-dashboard.rule=Host(`traefik.forust.xyz`)" - "traefik.http.routers.traefik-dashboard.rule=Host(`traefik.forust.xyz`)"
@@ -78,14 +78,14 @@ services:
- ./dynamic:/etc/traefik/dynamic:ro - ./dynamic:/etc/traefik/dynamic:ro
- ./certs:/certs:ro - ./certs:/certs:ro
- ./logs:/var/log/traefik - ./logs:/var/log/traefik
- ./letsencrypt:/letsencrypt # - ./traefik/letsencrypt:/letsencrypt
networks: networks:
- proxy - traefik-proxy
environment: environment:
- TZ=Europe/Bratislava - TZ=Europe/Bratislava
networks: networks:
proxy: traefik-proxy:
external: true external: true
-23
View File
@@ -1,23 +0,0 @@
http:
routers:
fs1-public:
rule: "Host(`fs1.domain.xyz`)"
entrypoints:
- websecure
service: fs1
middlewares:
- security-chain@file
tls: {}
fs1-workstation:
rule: "Host(`fs1.workstation.internal`)"
entrypoints:
- websecure
service: fs1
tls: {}
services:
fs1:
loadBalancer:
servers:
- url: "http://127.0.0.1:3923" # Copyparty port example
+23
View File
@@ -5,6 +5,29 @@ http:
redirectScheme: redirectScheme:
scheme: https scheme: https
permanent: true permanent: true
# Metube Basic Auth
metube-auth:
basicAuth:
users:
- "vv:$2y$05$JdT8AGUO9bd.E/PiCmKaoOJS1RFlXkrrmZ5mJ4f8/a1bEW39L3FbS"
realm: "MeTube Access"
# Basic Auth Traefik Dashboard
auth:
basicAuth:
users:
- "admin:$2y$05$.CKDD82sNUxcpaRrLbHuK.dopqt1fgurc2yfTKAT5OFzT7RvPrJHK"
realm: "Traefik Dashboard"
# Basic Auth Dockmon
dockmon-auth:
basicAuth:
users:
- "admin:$2y$05$.CKDD82sNUxcpaRrLbHuK.dopqt1fgurc2yfTKAT5OFzT7RvPrJHK"
realm: "Dockmon Access"
# Cloudflare IP Whitelist # Cloudflare IP Whitelist
cloudflare-ipwhitelist: cloudflare-ipwhitelist:
ipWhiteList: ipWhiteList:
-8
View File
@@ -1,8 +0,0 @@
http:
routers:
acme-challenge-exempt:
rule: "PathPrefix(`/.well-known/acme-challenge`)"
entryPoints:
- web
service: noop@internal
priority: 100
+5 -5
View File
@@ -5,12 +5,12 @@ services:
container_name: uptime-kuma container_name: uptime-kuma
volumes: volumes:
- ./data:/app/data - ./data:/app/data
# ports: ports:
# <Host Port>:<Container Port> # <Host Port>:<Container Port>
# - "3001:3001" - "3001:3001"
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
- "traefik.docker.network=proxy" - "traefik.docker.network=traefik-proxy"
# Prod Router # Prod Router
- "traefik.http.routers.uptime-kuma.rule=Host(`uptime.forust.xyz`)" - "traefik.http.routers.uptime-kuma.rule=Host(`uptime.forust.xyz`)"
@@ -28,7 +28,7 @@ services:
- "traefik.http.routers.uptime-kuma-dev.entrypoints=websecure" - "traefik.http.routers.uptime-kuma-dev.entrypoints=websecure"
- "traefik.http.routers.uptime-kuma-dev.tls=true" - "traefik.http.routers.uptime-kuma-dev.tls=true"
networks: networks:
- proxy - traefik-proxy
networks: networks:
proxy: traefik-proxy:
external: true external: true