Compare commits

..

1 Commits

Author SHA1 Message Date
forust 1dec4de708 nya~ 2025-12-09 21:56:13 +01:00
32 changed files with 329 additions and 838 deletions
+7 -18
View File
@@ -2,8 +2,12 @@
sync.ffs_lock
.sync.ffs_db
# Copyparty
*.hist/
# Environment
.env
.env.anna
.env.forust
.env.*
!.env.*example
# Volumes and data directories
gitea/gitea-db/
@@ -18,9 +22,6 @@ uptime-kuma/data/
termix/termix-data/*
cfddns/config.json
checkmk/checkmk/*
downtify/Downtify_downloads
headscale/config/*
headscale/data/*
# Steaming services files
streaming/jellyfin/*
@@ -33,15 +34,11 @@ streaming/prowlarr/*
# Homepage
homepages/forust_files/assets/images/team/*
homepages/forust_files/.well-known/*
# Traefik files
traefik/letsencrypt/acme.json
traefik/dynamic/fileservers.yml
traefik/logs/*
# SSL Certificates
adguardhome/certs/*
traefik/certs/*
# Monitoring
@@ -84,11 +81,3 @@ replacements.txt
# Temp files
edu_master/temp/
temp/*
# Environment
.env
.env.anna
.env.forust
.env.*
!*example
+16 -16
View File
@@ -3,48 +3,48 @@ services:
image: adguard/adguardhome:latest
container_name: adguardhome
restart: unless-stopped
environment:
- TZ=${TZ}
ports:
- "53:53/tcp"
- "53:53/udp"
- "853:853/tcp" # DNS over TLS
# - "67:67/udp" # DHCP
# - "68:68/tcp" # DHCP
# - "3000:3000/tcp"
- "3000:3000/tcp"
volumes:
- ./data/work:/opt/adguardhome/work
- ./data/conf:/opt/adguardhome/conf
- ./certs:/certs:ro
networks:
- traefik-proxy
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.http.services.adguard.loadbalancer.server.port=3000"
- "traefik.docker.network=traefik-proxy"
# Prod Router
- "traefik.http.routers.adguard.rule=Host(`dns.forust.xyz`) || Host(`adguard.forust.xyz`)"
- "traefik.http.routers.adguard.rule=Host(`adguard.forust.xyz`)"
- "traefik.http.routers.adguard.entrypoints=websecure"
- "traefik.http.routers.adguard.middlewares=security-headers@file"
- "traefik.http.routers.adguard.service=adguard"
- "traefik.http.routers.adguard.tls=true"
- "traefik.http.services.adguard.loadbalancer.server.port=3000"
# Local Router
- "traefik.http.routers.adguard-local.rule=Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`)"
- "traefik.http.routers.adguard-local.rule=Host(`adguard.workstation.internal`) || Host(`adguard.internal`)"
- "traefik.http.routers.adguard-local.entrypoints=websecure"
- "traefik.http.routers.adguard-local.middlewares=security-headers@file"
- "traefik.http.routers.adguard-local.service=adguard"
- "traefik.http.routers.adguard-local.tls=true"
# Dev Router
- "traefik.http.routers.adguard-dev.rule=Host(`adguard.gigaforust.internal`) Host(`dns.gigaforust.internal`)"
- "traefik.http.routers.adguard-dev.rule=Host(`adguard.gigaforust.internal`)"
- "traefik.http.routers.adguard-dev.entrypoints=websecure"
- "traefik.http.routers.adguard-dev.middlewares=security-headers@file"
- "traefik.http.routers.adguard-dev.service=adguard"
- "traefik.http.routers.adguard-dev.tls=true"
# DoH Router
- "traefik.http.routers.dns.rule=(Host(`dns.forust.xyz`) && PathPrefix(`/dns-query`))"
- "traefik.http.routers.dns.entrypoints=websecure"
- "traefik.http.routers.dns.tls.certresolver=letsencrypt"
# Glance Metadata
- glance.name=adguard
- glance.url=https://adguard.forust.xyz/
- glance.description=AdGuard Home is a network-wide software for blocking ads.
networks:
- proxy
networks:
proxy:
traefik-proxy:
external: true
+14 -9
View File
@@ -26,9 +26,9 @@ services:
command: server
container_name: authentik-server
restart: unless-stopped
# ports:
# - ${PORT_HTTP:-9000}:9000
# - ${PORT_HTTPS:-9443}:9443
ports:
- ${PORT_HTTP:-9000}:9000
- ${PORT_HTTPS:-9443}:9443
env_file:
- .env
environment:
@@ -37,12 +37,12 @@ services:
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
volumes:
- ./media:/media
- ./custom-templates:/templates
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.docker.network=traefik-proxy"
# Services
# - "traefik.http.services.authentik-server.loadbalancer.server.port=9443"
- "traefik.http.services.authentik-server.loadbalancer.server.port=9000"
# Prod Router
@@ -51,20 +51,25 @@ services:
- "traefik.http.routers.authentik-server.middlewares=security-headers@file"
- "traefik.http.routers.authentik-server.service=authentik-server"
- "traefik.http.routers.authentik-server.tls=true"
# Local Router
- "traefik.http.routers.authentik-server-local.rule=Host(`auth.workstation.internal`) || Host(`auth-dashboard.internal`)"
- "traefik.http.routers.authentik-server-local.entrypoints=websecure"
- "traefik.http.routers.authentik-server-local.middlewares=security-headers@file"
- "traefik.http.routers.authentik-server-local.service=authentik-server"
- "traefik.http.routers.authentik-server-local.tls=true"
# Dev Router
- "traefik.http.routers.authentik-server-dev.rule=Host(`auth.gigaforust.internal`)"
- "traefik.http.routers.authentik-server-dev.entrypoints=websecure"
- "traefik.http.routers.authentik-server-dev.middlewares=security-headers@file"
- "traefik.http.routers.authentik-server-dev.service=authentik-server"
- "traefik.http.routers.authentik-server-dev.tls=true"
volumes:
- ./media:/media
- ./custom-templates:/templates
networks:
- proxy
- traefik-proxy
- authentik
depends_on:
postgresql:
@@ -97,5 +102,5 @@ volumes:
driver: local
networks:
authentik:
proxy:
traefik-proxy:
external: true
+1 -1
View File
@@ -2,7 +2,6 @@ services:
cloudflare-ddns:
image: timothyjmiller/cloudflare-ddns:latest
container_name: cloudflare-ddns
restart: unless-stopped
security_opt:
- no-new-privileges:true
network_mode: 'host'
@@ -11,3 +10,4 @@ services:
- PGID=1000
volumes:
- ./config.json:/config.json
restart: unless-stopped
-2
View File
@@ -1,2 +0,0 @@
CMK_PASSWORD=password
TZ=Europe/Berlin
-42
View File
@@ -1,42 +0,0 @@
services:
checkmk:
image: "checkmk/check-mk-raw:2.4.0-latest"
container_name: "checkmk"
restart: unless-stopped
# ports:
# - 5000:5000
# - 6776:8000
volumes:
- sites:/omd/sites
tmpfs:
- /opt/omd/sites/cmk/tmp:uid=1000,gid=1000
environment:
- CMK_PASSWORD=${CMK_PASSWORD:-password}
- CMK_SITE_ID=cmk
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.http.services.checkmk.loadbalancer.server.port=5000"
# Prod Router
- "traefik.http.routers.checkmk.rule=Host(`cmk.forust.xyz`)"
- "traefik.http.routers.checkmk.entrypoints=websecure"
- "traefik.http.routers.checkmk.middlewares=security-headers@file"
- "traefik.http.routers.checkmk.tls=true"
# Local Router
- "traefik.http.routers.checkmk-local.rule=Host(`cmk.workstation.internal`)"
- "traefik.http.routers.checkmk-local.entrypoints=websecure"
- "traefik.http.routers.checkmk-local.middlewares=security-headers@file"
- "traefik.http.routers.checkmk-local.tls=true"
# Dev Router
- "traefik.http.routers.checkmk-dev.rule=Host(`cmk.gigaforust.internal`)"
- "traefik.http.routers.checkmk-dev.middlewares=security-headers@file"
- "traefik.http.routers.checkmk-dev.entrypoints=websecure"
- "traefik.http.routers.checkmk-dev.tls=true"
networks:
- proxy
networks:
proxy:
external: true
volumes:
sites:
+18 -14
View File
@@ -3,22 +3,23 @@ services:
image: darthnorse/dockmon:latest
container_name: dockmon
restart: unless-stopped
# ports:
# - 8000:443
ports:
- 8000:443
environment:
- TZ=Europe/Bratislava
volumes:
- data:/app/data
- ./data:/app/data
- /var/run/docker.sock:/var/run/docker.sock
healthcheck:
test: [ "CMD", "curl", "-k", "-f", "https://localhost:443/health" ]
interval: 30s
timeout: 10s
retries: 3
networks:
- traefik-proxy
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.http.services.dockmon.loadbalancer.server.port=443"
- "traefik.http.services.dockmon.loadbalancer.server.scheme=https"
- "traefik.http.services.dockmon.loadbalancer.serverstransport=insecureTransport@file"
- "traefik.docker.network=traefik-proxy"
# Prod Router
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
@@ -26,25 +27,28 @@ services:
- "traefik.http.routers.dockmon.middlewares=security-chain@file"
- "traefik.http.routers.dockmon.service=dockmon"
- "traefik.http.routers.dockmon.tls=true"
- "traefik.http.services.dockmon.loadbalancer.server.port=443"
- "traefik.http.services.dockmon.loadbalancer.server.scheme=https"
- "traefik.http.services.dockmon.loadbalancer.serverstransport=insecureTransport@file"
# Local Router
- "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`)"
- "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`) || Host(`dockmon.internal`)"
- "traefik.http.routers.dockmon-local.entrypoints=websecure"
- "traefik.http.routers.dockmon-local.middlewares=security-headers@file"
- "traefik.http.routers.dockmon-local.service=dockmon"
- "traefik.http.routers.dockmon-local.tls=true"
# Dev Router
- "traefik.http.routers.dockmon-dev.rule=Host(`dockmon.gigaforust.internal`)"
- "traefik.http.routers.dockmon-dev.entrypoints=websecure"
- "traefik.http.routers.dockmon-dev.middlewares=security-chain@file"
- "traefik.http.routers.dockmon-dev.service=dockmon"
- "traefik.http.routers.dockmon-dev.tls=true"
# Glance Metadata
- glance.name=dockmon
- glance.url=https://dockmon.forust.xyz/
- glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface.
networks:
- proxy
volumes:
data:
networks:
proxy:
traefik-proxy:
external: true
-33
View File
@@ -1,33 +0,0 @@
services:
downtify:
container_name: downtify
image: ghcr.io/henriquesebastiao/downtify:latest
# ports:
# - '7077:8000'
volumes:
- ./Downtify_downloads:/downloads
labels:
- traefik.enable=true
- traefik.docker.network=proxy
- traefik.http.services.downtify.loadbalancer.server.port=8000
# Prod Router
- traefik.http.routers.downtify.rule=Host(`downtify.forust.xyz`)
- traefik.http.routers.downtify.entrypoints=websecure
- traefik.http.routers.downtify.middlewares=security-chain@file
- traefik.http.routers.downtify.tls=true
# Local Router
- traefik.http.routers.downtify-local.rule=Host(`downtify.workstation.internal`) || Host(`downtify.internal`)
- traefik.http.routers.downtify-local.entrypoints=websecure
- traefik.http.routers.downtify-local.middlewares=security-headers@file
- traefik.http.routers.downtify-local.tls=true
# Dev Router
- traefik.http.routers.downtify-dev.rule=Host(`downtify.gigaforust.internal`)
- traefik.http.routers.downtify-dev.entrypoints=websecure
- traefik.http.routers.downtify-dev.middlewares=security-chain@file
- traefik.http.routers.downtify-dev.tls=true
networks:
- proxy
networks:
proxy:
external: true
+9 -20
View File
@@ -12,26 +12,15 @@ logging.basicConfig(
)
logger = logging.getLogger(__name__)
# Load configuration (adapted to .env keys)
def _env(key, default=None):
v = os.getenv(key, default)
if isinstance(v, str) and len(v) >= 2 and ((v[0] == '"' and v[-1] == '"') or (v[0] == "'" and v[-1] == "'")):
return v[1:-1]
return v
LOGIN = _env('KEEPER_LOGIN')
PASSWORD = _env('KEEPER_PASSWORD')
EDU_BASE = _env('EDU_URL_BASE', 'https://edu.edu.vn.ua')
EDU_LOGIN_PATH = _env('EDU_URL_LOGIN', '/user/login')
EDU_COURSES_PATH = _env('EDU_URL_COURSES', '/course/userlist')
URL_LOGIN = f"{EDU_BASE.rstrip('/')}/{EDU_LOGIN_PATH.lstrip('/')}"
URL_VERIFY = f"{EDU_BASE.rstrip('/')}/{EDU_COURSES_PATH.lstrip('/')}"
INTERVAL = int(_env('KEEPER_INTERVAL', 10))
USER_AGENT = _env('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
REDIS_HOST = _env('REDIS_HOST', 'redis')
REDIS_PORT = int(_env('REDIS_PORT', 6379))
# Load configuration
LOGIN = os.getenv('EDU_LOGIN')
PASSWORD = os.getenv('EDU_PASSWORD')
URL_LOGIN = os.getenv('EDU_URL_LOGIN', 'https://edu.edu.vn.ua/user/login')
URL_VERIFY = os.getenv('EDU_URL_VERIFY', 'https://edu.edu.vn.ua/course/userlist')
INTERVAL = int(os.getenv('PHPSESSID_INTERVAL', 10))
USER_AGENT = os.getenv('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
REDIS_HOST = os.getenv('REDIS_HOST', 'redis')
REDIS_PORT = int(os.getenv('REDIS_PORT', 6379))
SUCCESS_FILE = '/tmp/last_success'
+31 -107
View File
@@ -3,8 +3,7 @@ import logging
import redis
import json
from telegram import Update, InlineKeyboardButton, InlineKeyboardMarkup, ChatMember
from telegram.constants import ChatType
from telegram import Update, InlineKeyboardButton, InlineKeyboardMarkup
from telegram.ext import Application, CommandHandler, CallbackQueryHandler, ContextTypes
from playwright.async_api import async_playwright
@@ -15,36 +14,22 @@ logging.basicConfig(
)
logger = logging.getLogger(__name__)
# Suppress HTTP request logs
logging.getLogger('urllib3').setLevel(logging.WARNING)
logging.getLogger('httpx').setLevel(logging.WARNING)
logging.getLogger('telegram.ext._application').setLevel(logging.WARNING)
# Load environment variables
def _env(key, default=None):
v = os.getenv(key, default)
if isinstance(v, str) and len(v) >= 2 and ((v[0] == '"' and v[-1] == '"') or (v[0] == "'" and v[-1] == "'")):
return v[1:-1]
return v
EDU_BASE = _env('EDU_URL_BASE', 'https://edu.edu.vn.ua')
EDU_WEBINAR_PATH = _env('EDU_URL_WEBINAR', '/webinar/useractive')
WEBINAR_URL = f"{EDU_BASE.rstrip('/')}/{EDU_WEBINAR_PATH.lstrip('/')}"
WEBINAR_CHECK_INTERVAL = int(_env('WEBINAR_CHECK_INTERVAL', 60))
REDIS_HOST = _env('REDIS_HOST', 'redis')
REDIS_PORT = int(_env('REDIS_PORT', 6379))
PLAYWRIGHT_WS = _env('PLAYWRIGHT_WS', 'ws://playwright-service:3000/ws')
USER_AGENT = _env('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
WEBINAR_TELEGRAM_TOKEN = _env('WEBINAR_TELEGRAM_TOKEN')
ADMIN_ID = int(_env('WEBINAR_ADMIN_ID', '0'))
WEBINAR_URL = os.getenv('WEBINAR_URL', 'https://edu.edu.vn.ua/webinar/useractive')
WEBINAR_CHECK_INTERVAL = int(os.getenv('WEBINAR_CHECK_INTERVAL', 60))
REDIS_HOST = os.getenv('REDIS_HOST', 'redis')
REDIS_PORT = int(os.getenv('REDIS_PORT', 6379))
PLAYWRIGHT_WS = os.getenv('PLAYWRIGHT_WS', 'ws://playwright-service:3000/ws')
USER_AGENT = os.getenv('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
WEBINAR_TELEGRAM_TOKEN = os.getenv('WEBINAR_TELEGRAM_TOKEN')
ADMIN_ID = int(os.getenv('WEBINAR_ADMIN_ID', '0'))
# Redis Keys
KEY_WHITELIST = "bot:whitelist"
KEY_WHITELIST_ENABLED = "bot:whitelist_enabled"
KEY_SUBSCRIBERS = "bot:subscribers"
KEY_PHPSESSID = "EDU_PHPSESSID"
KEY_WEBINAR_HISTORY = "bot:webinar_history" # Stores last 3 webinars
KEY_WEBINAR_HISTORY = "bot:webinar_history" # Stores last 5 webinars
# Initialize Redis
try:
@@ -63,7 +48,7 @@ TRANSLATIONS = {
'welcome_admin': "\n\n👑 <b>Режим администратора активен</b>",
'access_denied': "⛔ Доступ запрещен. Вас нет в белом списке.",
'help_title': "🤖 <b>Помощь по боту</b>\n\n",
'help_commands': "/start - Подписаться на уведомления\n/stop - Отписаться от уведомлений\n/help - Показать это сообщение\n/language - Сменить язык",
'help_commands': "/start - Подписаться на уведомления\n/help - Показать это сообщение\n/language - Сменить язык",
'help_admin': "\n<b>Команды администратора:</b>\n/adduser [user_id] - Добавить пользователя в белый список\n/removeuser [user_id] - Удалить пользователя из белого списка\nИли используйте панель ниже для управления настройками.",
'admin_only': "⛔ Только для администратора!",
'user_added': "✅ Пользователь {user_id} добавлен в белый список",
@@ -94,15 +79,13 @@ TRANSLATIONS = {
'flag_ru': "🇷🇺 Русский",
'flag_uk': "🇺🇦 Українська",
'flag_en': "🇬🇧 English",
'history_cleared': "✅ История вебинаров очищена",
'history_clear_failed': "❌ Ошибка при очистке истории",
},
'uk': {
'welcome': "👋 Привіт, {name}!\n\nЯ бот-сповіщувач про вебінари. Я повідомлятиму вас, коли з'явиться новий вебінар.\nВи підписані на сповіщення.",
'welcome_admin': "\n\n👑 <b>Режим адміністратора активний</b>",
'access_denied': "⛔ Доступ заборонено. Вас немає в білому списку.",
'help_title': "🤖 <b>Довідка по боту</b>\n\n",
'help_commands': "/start - Підписатися на сповіщення\n/stop - Відписатися від сповіщень\n/help - Показати це повідомлення\n/language - Змінити мову",
'help_commands': "/start - Підписатися на сповіщення\n/help - Показати це повідомлення\n/language - Змінити мову",
'help_admin': "\n<b>Команди адміністратора:</b>\n/adduser [user_id] - Додати користувача до білого списку\n/removeuser [user_id] - Видалити користувача з білого списку\nАбо використовуйте панель нижче для керування налаштуваннями.",
'admin_only': "⛔ Тільки для адміністратора!",
'user_added': "✅ Користувач {user_id} доданий до білого списку",
@@ -133,15 +116,13 @@ TRANSLATIONS = {
'flag_ru': "🇷🇺 Русский",
'flag_uk': "🇺🇦 Українська",
'flag_en': "🇬🇧 English",
'history_cleared': "✅ Історія вебінарів очищена",
'history_clear_failed': "❌ Помилка при очищенні історії",
},
'en': {
'welcome': "👋 Hello, {name}!\n\nI am the Webinar Checker Bot. I will notify you when a new webinar appears.\nYou have been subscribed to notifications.",
'welcome_admin': "\n\n👑 <b>Admin Mode Active</b>",
'access_denied': "⛔ Access denied. You are not on the whitelist.",
'help_title': "🤖 <b>Bot Help</b>\n\n",
'help_commands': "/start - Subscribe to notifications\n/stop - Unsubscribe from notifications\n/help - Show this message\n/language - Change language",
'help_commands': "/start - Subscribe to notifications\n/help - Show this message\n/language - Change language",
'help_admin': "\n<b>Admin Commands:</b>\n/adduser [user_id] - Add user to whitelist\n/removeuser [user_id] - Remove user from whitelist\nOr use the panel below to manage settings.",
'admin_only': "⛔ Admin only!",
'user_added': "✅ User {user_id} added to whitelist",
@@ -172,8 +153,6 @@ TRANSLATIONS = {
'flag_ru': "🇷🇺 Русский",
'flag_uk': "🇺🇦 Українська",
'flag_en': "🇬🇧 English",
'history_cleared': "✅ Webinar history cleared",
'history_clear_failed': "❌ Error clearing history",
}
}
@@ -224,21 +203,6 @@ def is_whitelisted(user_id: int) -> bool:
return redis_client.sismember(KEY_WHITELIST, str(user_id))
async def is_group_admin(update: Update, context: ContextTypes.DEFAULT_TYPE) -> bool:
"""Check if the user is an administrator in the group."""
user = update.effective_user
chat = update.effective_chat
if chat.type in [ChatType.PRIVATE, "private"]:
return True
try:
member = await context.bot.get_chat_member(chat.id, user.id)
return member.status in [ChatMember.OWNER, ChatMember.ADMINISTRATOR]
except Exception as e:
logger.error(f"Failed to check admin status: {e}")
return False
def get_admin_keyboard(user_id: int):
"""Generate admin panel keyboard."""
whitelist_enabled = redis_client.get(KEY_WHITELIST_ENABLED) != "0"
@@ -257,21 +221,19 @@ def get_admin_keyboard(user_id: int):
async def start(update: Update, context: ContextTypes.DEFAULT_TYPE):
"""Handle /start command."""
user = update.effective_user
chat = update.effective_chat
logger.info(f"User {user.id} ({user.username}) started the bot in chat {chat.id} ({chat.type}).")
logger.info(f"User {user.id} ({user.username}) started the bot.")
# Check whitelist - MUST be the user executing the command
if not is_whitelisted(user.id):
await update.message.reply_text(t(user.id, 'access_denied'))
return
# Add to subscribers (Chat ID!)
redis_client.sadd(KEY_SUBSCRIBERS, chat.id)
# Add to subscribers
redis_client.sadd(KEY_SUBSCRIBERS, user.id)
msg = t(chat.id, 'welcome', name=user.first_name)
msg = t(user.id, 'welcome', name=user.first_name)
if user.id == ADMIN_ID and chat.type == "private":
msg += t(chat.id, 'welcome_admin')
if user.id == ADMIN_ID:
msg += t(user.id, 'welcome_admin')
await update.message.reply_text(msg, parse_mode='HTML', reply_markup=get_admin_keyboard(user.id))
else:
await update.message.reply_text(msg, parse_mode='HTML')
@@ -279,39 +241,19 @@ async def start(update: Update, context: ContextTypes.DEFAULT_TYPE):
async def help_command(update: Update, context: ContextTypes.DEFAULT_TYPE):
"""Handle /help command."""
user_id = update.effective_user.id
chat_id = update.effective_chat.id
msg = t(chat_id, 'help_title') + t(chat_id, 'help_commands')
msg = t(user_id, 'help_title') + t(user_id, 'help_commands')
if user_id == ADMIN_ID and update.effective_chat.type == "private":
msg += t(chat_id, 'help_admin')
if user_id == ADMIN_ID:
msg += t(user_id, 'help_admin')
await update.message.reply_text(msg, parse_mode='HTML', reply_markup=get_admin_keyboard(user_id))
else:
await update.message.reply_text(msg, parse_mode='HTML')
async def stop_command(update: Update, context: ContextTypes.DEFAULT_TYPE):
"""Handle /stop command (unsubscribe)."""
user = update.effective_user
chat = update.effective_chat
# Permission check: Whitelisted user OR Group Admin
if not (is_whitelisted(user.id) or await is_group_admin(update, context)):
await update.message.reply_text(t(chat.id, 'access_denied')) # Or specific "admin only" message
return
redis_client.srem(KEY_SUBSCRIBERS, chat.id)
await update.message.reply_text(t(chat.id, 'whitelist_disabled').replace(" whitelist", " notifications").replace("Білий список", "Сповіщення").replace("Белый список", "Уведомления") if chat.id else "Unsubscribed")
async def language_command(update: Update, context: ContextTypes.DEFAULT_TYPE):
"""Handle /language command."""
user = update.effective_user
chat = update.effective_chat
# Permission check for groups
if not (is_whitelisted(user.id) or await is_group_admin(update, context)):
return
user_id = update.effective_user.id
await update.message.reply_text(
t(chat.id, 'select_language'),
t(user_id, 'select_language'),
parse_mode='HTML',
reply_markup=get_language_keyboard()
)
@@ -361,21 +303,6 @@ async def remove_user(update: Update, context: ContextTypes.DEFAULT_TYPE):
except ValueError:
await update.message.reply_text(t(admin_id, 'invalid_user_id'))
async def clear_history(update: Update, context: ContextTypes.DEFAULT_TYPE):
"""Clear webinar history (admin only)."""
admin_id = update.effective_user.id
if admin_id != ADMIN_ID:
await update.message.reply_text(t(admin_id, 'admin_only'))
return
try:
redis_client.delete(KEY_WEBINAR_HISTORY)
await update.message.reply_text(t(admin_id, 'history_cleared'))
logger.info("Admin cleared webinar history")
except Exception as e:
logger.error(f"Failed to clear history: {e}")
await update.message.reply_text(t(admin_id, 'history_clear_failed'))
# --- Admin Callbacks ---
async def admin_callback(update: Update, context: ContextTypes.DEFAULT_TYPE):
@@ -436,9 +363,9 @@ async def language_callback(update: Update, context: ContextTypes.DEFAULT_TYPE):
# --- Webinar Checking Job ---
def get_webinar_key(url: str) -> str:
"""Generate unique key for a webinar based on URL."""
return url
def get_webinar_key(name: str, url: str) -> str:
"""Generate unique key for a webinar based on name and URL."""
return f"{name}|{url}"
def get_stored_webinars() -> list:
"""Get list of stored webinar keys from Redis."""
@@ -451,9 +378,9 @@ def get_stored_webinars() -> list:
return []
def store_webinars(webinar_keys: list):
"""Store up to 3 most recent webinar keys in Redis."""
# Keep only last 3
webinar_keys = webinar_keys[-3:]
"""Store up to 5 most recent webinar keys in Redis."""
# Keep only last 5
webinar_keys = webinar_keys[-5:]
try:
redis_client.set(KEY_WEBINAR_HISTORY, json.dumps(webinar_keys))
logger.info(f"Stored {len(webinar_keys)} webinar(s) in history")
@@ -588,7 +515,7 @@ async def check_webinars_job(context: ContextTypes.DEFAULT_TYPE):
current_keys = []
for webinar in current_webinars:
key = get_webinar_key(webinar['url'])
key = get_webinar_key(webinar['name'], webinar['url'])
current_keys.append(key)
if key not in stored_keys:
@@ -608,7 +535,6 @@ async def check_webinars_job(context: ContextTypes.DEFAULT_TYPE):
for sub_id in subscribers:
try:
# Build message in user's language
# sub_id comes from redis set as string, convert to int for translation lookup
webinar_items = "\n\n".join([
t(int(sub_id), 'webinar_item', name=w['name'], url=w['url'])
for w in new_webinars
@@ -643,12 +569,10 @@ def main():
# Handlers
app.add_handler(CommandHandler("start", start))
app.add_handler(CommandHandler("stop", stop_command))
app.add_handler(CommandHandler("help", help_command))
app.add_handler(CommandHandler("language", language_command))
app.add_handler(CommandHandler("adduser", add_user))
app.add_handler(CommandHandler("removeuser", remove_user))
app.add_handler(CommandHandler("clearhistory", clear_history))
# Callback handlers - language selection first, then admin panel
app.add_handler(CallbackQueryHandler(language_callback, pattern="^lang_"))
-3
View File
@@ -1,6 +1,3 @@
GITEA_POSTGRES_USER=
GITEA_POSTGRES_PASSWORD=
GITEA_POSTGRES_DB=gitea
GITEA_SMTP_PASS=
MAILER_ADDR=
SERVICE_EMAIL=email.used.by.services@domain.tld
+17 -24
View File
@@ -2,7 +2,6 @@ services:
server:
image: docker.gitea.com/gitea:1.25.1
container_name: gitea
restart: always
environment:
- USER_UID=1000
- USER_GID=1000
@@ -14,52 +13,45 @@ services:
- GITEA__database__NAME=gitea
#Server
- GITEA__server__ROOT_URL=https://gitea.forust.xyz
- GITEA__server__SSH_DOMAIN=gitssh.forust.xyz
- GITEA__server__SSH_PORT=2221
# Mailer
- GITEA__mailer__ENABLED=true
- GITEA__mailer__FROM=${SERVICE_EMAIL}
- GITEA__mailer__SMTP_ADDR=${MAILER_ADDR}:465
- GITEA__mailer__USER=${SERVICE_EMAIL}
- GITEA__mailer__PASSWD=${GITEA_SMTP_PASS}
- GITEA__mailer__PROTOCOL=SMTP
- GITEA__service__REGISTER_EMAIL_CONFIRM=true
- GITEA__service__ENABLE_NOTIFY_MAIL=true
restart: always
networks:
- gitea-db
- traefik-proxy
volumes:
- ./gitea-data:/data
- /etc/timezone:/etc/timezone:ro
- /etc/localtime:/etc/localtime:ro
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.http.services.gitea.loadbalancer.server.port=3000"
- "traefik.docker.network=traefik-proxy"
# Prod Router
- "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)"
- "traefik.http.routers.gitea.entrypoints=websecure"
- "traefik.http.routers.gitea.middlewares=security-headers@file"
- "traefik.http.routers.gitea.service=gitea"
- "traefik.http.routers.gitea.tls=true"
- "traefik.http.services.gitea.loadbalancer.server.port=3000"
# Local Router
- "traefik.http.routers.gitea-local.rule=Host(`gitea.workstation.internal`)"
- "traefik.http.routers.gitea-local.rule=Host(`gitea.workstation.internal`) || Host(`gitea.internal`)"
- "traefik.http.routers.gitea-local.entrypoints=websecure"
- "traefik.http.routers.gitea-local.middlewares=security-headers@file"
- "traefik.http.routers.gitea-local.service=gitea"
- "traefik.http.routers.gitea-local.tls=true"
# Dev Router
- "traefik.http.routers.gitea-dev.rule=Host(`gitea.gigaforust.internal`)"
- "traefik.http.routers.gitea-dev.entrypoints=websecure"
- "traefik.http.routers.gitea-dev.middlewares=security-headers@file"
- "traefik.http.routers.gitea-dev.service=gitea"
- "traefik.http.routers.gitea-dev.tls=true"
# SSH Router
- "traefik.tcp.services.gitea.loadbalancer.server.port=22"
- "traefik.tcp.routers.gitea.entrypoints=ssh"
- "traefik.tcp.routers.gitea.rule=HostSNI(`*`)"
ports:
- "2221:22"
networks:
- gitea-db
- proxy
depends_on:
- db
db:
image: docker.io/library/postgres:14
restart: always
@@ -67,12 +59,13 @@ services:
- POSTGRES_USER=gitea
- POSTGRES_PASSWORD=gitea
- POSTGRES_DB=gitea
volumes:
- ./gitea-db/:/var/lib/postgresql/data
networks:
- gitea-db
volumes:
- ./gitea-db/:/var/lib/postgresql/data
networks:
gitea-db:
external: false
proxy:
traefik-proxy:
external: true
+11 -7
View File
@@ -11,26 +11,30 @@ services:
env_file: .env
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
# FIXME: traefik.services.glance.loadbalancer.server.port ??
- "traefik.docker.network=traefik-proxy"
# Prod Router
- "traefik.http.routers.glance.rule=Host(`glance.forust.xyz`)"
- "traefik.http.routers.glance.entrypoints=websecure"
- "traefik.http.routers.glance.middlewares=security-headers@file"
- "traefik.http.routers.glance.middlewares=security-chain@file"
- "traefik.http.routers.glance.tls=true"
# Local Router
- "traefik.http.routers.glance-local.rule=Host(`glance.workstation.internal`)"
- "traefik.http.routers.glance-local.rule=Host(`glance.workstation.internal`) || Host(`glance.internal`)"
- "traefik.http.routers.glance-local.entrypoints=websecure"
- "traefik.http.routers.glance-local.middlewares=security-headers@file"
- "traefik.http.routers.glance-local.tls=true"
# Dev Router
- "traefik.http.routers.glance-dev.rule=Host(`glance.gigaforust.internal`)"
- "traefik.http.routers.glance-dev.entrypoints=websecure"
- "traefik.http.routers.glance-dev.middlewares=security-headers@file"
- "traefik.http.routers.glance-dev.middlewares=security-chain@file"
- "traefik.http.routers.glance-dev.tls=true"
networks:
- proxy
- traefik-proxy
dns:
- 1.1.1.1
- 8.8.8.8
networks:
proxy:
traefik-proxy:
external: true
-77
View File
@@ -1,77 +0,0 @@
services:
headscale:
image: headscale/headscale:latest
restart: unless-stopped
container_name: headscale-server
command: serve
networks:
- proxy
volumes:
- ./config/headscale.yaml:/etc/headscale/config.yaml
- data:/var/lib/headscale
labels:
- "me.tale.headplane.target: headscale"
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.http.services.headscale.loadbalancer.server.port=8080"
- "traefik.http.services.headscale-metrics.loadbalancer.server.port=9090"
## SERVICE
# Prod Router
- "traefik.http.routers.headscale.rule=Host(`hs.forust.xyz`)"
- "traefik.http.routers.headscale.entrypoints=websecure"
- "traefik.http.routers.headscale.service=headscale"
- "traefik.http.routers.headscale.tls=true"
# Local Router
- "traefik.http.routers.headscale-local.rule=Host(`hs.workstation.internal`)"
- "traefik.http.routers.headscale-local.entrypoints=websecure"
- "traefik.http.routers.headscale-local.service=headscale"
- "traefik.http.routers.headscale-local.tls=true"
# Dev Router
- "traefik.http.routers.headscale-dev.rule=Host(`hs.gigaforust.internal`)"
- "traefik.http.routers.headscale-dev.entrypoints=websecure"
- "traefik.http.routers.headscale-dev.service=headscale"
- "traefik.http.routers.headscale-dev.tls=true"
## METRICS
# Prod Router
- "traefik.http.routers.headscale-metrics.rule=Host(`hs.forust.xyz`) && PathPrefix(`/metrics`)"
- "traefik.http.routers.headscale-metrics.entrypoints=websecure"
- "traefik.http.routers.headscale-metrics.service=headscale-metrics"
- "traefik.http.routers.headscale-metrics.tls=true"
# Local Router
- "traefik.http.routers.headscale-metrics-local.rule=Host(`hs.workstation.internal`) && PathPrefix(`/metrics`)"
- "traefik.http.routers.headscale-metrics-local.entrypoints=websecure"
- "traefik.http.routers.headscale-metrics-local.service=headscale-metrics"
- "traefik.http.routers.headscale-metrics-local.tls=true"
# Dev Router
- "traefik.http.routers.headscale-metrics-dev.rule=Host(`hs.gigaforust.internal`) && PathPrefix(`/metrics`)"
- "traefik.http.routers.headscale-metrics-dev.entrypoints=websecure"
- "traefik.http.routers.headscale-metrics-dev.service=headscale-metrics"
- "traefik.http.routers.headscale-metrics-dev.tls=true"
headplane:
image: ghcr.io/tale/headplane:latest
container_name: headplane
restart: unless-stopped
ports:
- '3000:3000'
volumes:
- ./config/headplane.yaml:/etc/headplane/config.yaml
- ./config/headscale.yaml:/etc/headscale/config.yaml
- headplane-data:/var/lib/headplane
- /var/run/docker.sock:/var/run/docker.sock:ro
networks:
- proxy
healthcheck:
test: [ "CMD", "/bin/hp_healthcheck" ]
interval: 30s
timeout: 5s
start_period: 5s
retries: 3
volumes:
data:
headplane-data:
name: headplane_data
networks:
proxy:
external: true
-221
View File
@@ -1,221 +0,0 @@
# Configuration for the Headplane server and web application
server:
# These are the default values, change them as needed
host: "0.0.0.0"
port: 3000
# Should not include the dashboard prefix (/admin) portion.
# # Prod server_url
# base_url: https://hs.forust.xyz
# # Local base_url
# base_url: https://hs.workstation.internal
# # Dev base_url
# base_url: https://hs.gigaforust.internal
# You may provide `cookie_secret_path` instead to read a value from disk.
# See https://headplane.net/configuration/#sensitive-values
cookie_secret: "<change_me_to_something_secure!>"
# Whether cookies should be marked as Secure
# * Should be false if running without HTTPs
# * Should be true if running behind a reverse proxy with HTTPs
cookie_secure: true
# The maximum age of the session cookie in seconds
cookie_max_age: 86400 # 1 day in seconds
# This is not required, but if you want to restrict the cookie
# to a specific domain, set it here. Otherwise leave it commented out.
# This may not work as expected if not using a reverse proxy.
# cookie_domain: ""
# The path to persist Headplane specific data. All data going forward
# is stored in this directory, including the internal database and
# any cache related files.
data_path: "/var/lib/headplane"
# The info secret is optional and allows access to certain debug endpoints
# that may expose sensitive information about your Headplane instance.
#
# As of now, this protects the /api/info endpoint which exposes details about
# the Headplane and Headscale versions in use. In the future, more endpoints
# may be protected by this secret.
#
# If not set, these endpoints will be disabled.
# info_secret: "<change_me_to_something_secure!>"
# Headscale specific settings to allow Headplane to talk
# to Headscale and access deep integration features
headscale:
# The URL to your Headscale instance
# (All API requests are routed through this URL)
# (THIS IS NOT the gRPC endpoint, but the HTTP endpoint)
#
# IMPORTANT: If you are using TLS this MUST be set to `https://`
url: "http://headscale-server:8080"
# If you use the TLS configuration in Headscale, and you are not using
# Let's Encrypt for your certificate, pass in the path to the certificate.
# (This has no effect if `url` does not start with `https://`)
# tls_cert_path: "/var/lib/headplane/tls.crt"
# Optional, public URL if its different from the `headscale.url`
# This affects certain parts of the web UI which shows Headscale's URL
public_url: "https://headscale.example.com"
# Path to the Headscale configuration file
# This is optional, but HIGHLY recommended for the best experience
# If this is read only, Headplane will show your configuration settings
# in the Web UI, but they cannot be changed.
config_path: "/etc/headscale/config.yaml"
# Whether the Headscale configuration should be strictly validated
# when reading from `config_path`. If true, Headplane will not interact
# with Headscale if there are any issues with the configuration file.
#
# This is recommended to be true for production deployments to, however it
# may not work if you are using a version of Headscale that has configuration
# options unknown to Headplane.
config_strict: true
# If you are using `dns.extra_records_path` in your Headscale
# configuration, you need to set this to the path for Headplane
# to be able to read the DNS records.
#
# Pass it in if using Docker and ensure that the file is both
# readable and writable to the Headplane process.
# When using this, Headplane will no longer need to automatically
# restart Headscale for DNS record changes.
# dns_records_path: "/var/lib/headscale/extra_records.json"
# Integration configurations for Headplane to interact with Headscale
integration:
# The Headplane agent allows retrieving information about nodes
# This allows the UI to display version, OS, and connectivity data
# You will see the Headplane agent in your Tailnet as a node when
# it connects.
agent:
enabled: false
# To connect to your Tailnet, you need to generate a pre-auth key
# This can be done via the web UI or through the `headscale` CLI.
pre_authkey: "<your-preauth-key>"
# Optionally change the name of the agent in the Tailnet.
# host_name: "headplane-agent"
# Configure different caching settings. By default, the agent will store
# caches in the path below for a maximum of 1 minute. If you want data
# to update faster, reduce the TTL, but this will increase the frequency
# of requests to Headscale.
# cache_ttl: 60
# cache_path: /var/lib/headplane/agent_cache.json
# The work_dir represents where the agent will store its data to be able
# to automatically reauthenticate with your Tailnet. It needs to be
# writable by the user running the Headplane process.
#
# If using Docker, it is best to leave this as the default.
# work_dir: "/var/lib/headplane/agent"
# Only one of these should be enabled at a time or you will get errors
# This does not include the agent integration (above), which can be enabled
# at the same time as any of these and is recommended for the best experience.
docker:
enabled: true
# By default we check for the presence of a container label (see the docs)
# to determine the container to signal when changes are made to DNS settings.
container_label: "me.tale.headplane.target=headscale"
# HOWEVER, you can fallback to a container name if you desire, but this is
# not recommended as its brittle and doesn't work with orchestrators that
# automatically assign container names.
#
# If `container_name` is set, it will override any label checks.
# container_name: "headscale-server"
# The path to the Docker socket (do not change this if you are unsure)
# Docker socket paths must start with unix:// or tcp:// and at the moment
# https connections are not supported.
socket: "unix:///var/run/docker.sock"
# Please refer to docs/integration/Kubernetes.md for more information
# on how to configure the Kubernetes integration. There are requirements in
# order to allow Headscale to be controlled by Headplane in a cluster.
kubernetes:
enabled: false
# Validates the manifest for the Pod to ensure all of the criteria
# are set correctly. Turn this off if you are having issues with
# shareProcessNamespace not being validated correctly.
validate_manifest: true
# This should be the name of the Pod running Headscale and Headplane.
# If this isn't static you should be using the Kubernetes Downward API
# to set this value (refer to docs/Integrated-Mode.md for more info).
pod_name: "headscale"
# Proc is the "Native" integration that only works when Headscale and
# Headplane are running outside of a container. There is no configuration,
# but you need to ensure that the Headplane process can terminate the
# Headscale process.
#
# (If they are both running under systemd as sudo, this will work).
proc:
enabled: false
# OIDC Configuration for simpler authentication
# (This is optional, but recommended for the best experience)
# oidc:
# The OIDC issuer URL
# issuer: "https://accounts.google.com"
# If you are using OIDC, you need to generate an API key
# that can be used to authenticate other sessions when signing in.
#
# This can be done with `headscale apikeys create --expiration 999d`
# headscale_api_key: "<your-headscale-api-key>"
# If your OIDC provider does not support discovery (does not have the URL at
# `/.well-known/openid-configuration`), you need to manually set endpoints.
# This also works to override endpoints if you so desire or if your OIDC
# discovery is missing certain endpoints (ie GitHub).
# For some typical providers, see https://headplane.net/features/sso.
# authorization_endpoint: ""
# token_endpoint: ""
# userinfo_endpoint: ""
# The authentication method to use when communicating with the token endpoint.
# This is fully optional and Headplane will attempt to auto-detect the best
# method and fall back to `client_secret_basic` if unsure.
# token_endpoint_auth_method: "client_secret_post"
# The client ID for the OIDC client
# For the best experience please ensure this is *identical* to the client_id
# you are using for Headscale. because
# client_id: "your-client-id"
# The client secret for the OIDC client
# You may also provide `client_secret_path` instead to read a value from disk.
# See https://headplane.net/configuration/#sensitive-values
# client_secret: "<your-client-secret>"
# Whether to use PKCE when authenticating users. This is recommended as it
# adds an extra layer of security to the authentication process. Enabling this
# means your OIDC provider must support PKCE and it must be enabled on the
# client.
# use_pkce: true
# If you want to disable traditional login via Headscale API keys
# disable_api_key_login: false
# By default profile pictures are pulled from the OIDC provider when
# we go to fetch the userinfo endpoint. Optionally, this can be set to
# "oidc" or "gravatar" as of 0.6.1.
# profile_picture_source: "gravatar"
# The scopes to request when authenticating users. The default is below.
# scope: "openid email profile"
# Extra query parameters can be passed to the authorization endpoint
# by setting them here. This is useful for providers that require any kind
# of custom hinting.
# extra_params:
# prompt: "select_account" # Example: force account selection on Google
-79
View File
@@ -1,79 +0,0 @@
# https://wiki.serversatho.me/en/headscale
# # Prod server_url
# server_url: https://hs.example.com
# # Local server_url
# server_url: https://hs.internal_domain.internal
# # Dev server_url
# server_url: https://hs.dev_internal_domain.internal
listen_addr: 0.0.0.0:8080
metrics_listen_addr: 127.0.0.1:9090
grpc_listen_addr: 127.0.0.1:50443
grpc_allow_insecure: false
noise:
private_key_path: /var/lib/headscale/noise_private.key
prefixes:
v4: 100.64.0.0/10
v6: fd7a:115c:a1e0::/48
allocation: sequential
derp:
server:
enabled: true
region_id: 999
region_code: "headscale"
region_name: "Headscale Embedded DERP"
stun_listen_addr: "0.0.0.0:3478"
private_key_path: /var/lib/headscale/derp_server_private.key
automatically_add_embedded_derp_region: true
ipv4: 1.2.3.4
ipv6: 2001:db8::1
urls:
- https://controlplane.tailscale.com/derpmap/default
paths: []
auto_update_enabled: true
update_frequency: 24h
disable_check_updates: false
ephemeral_node_inactivity_timeout: 30m
database:
type: sqlite
debug: false
gorm:
prepare_stmt: true
parameterized_queries: true
skip_err_record_not_found: true
slow_threshold: 1000
sqlite:
path: /var/lib/headscale/db.sqlite
write_ahead_log: true
wal_autocheckpoint: 1000
acme_url: https://acme-v02.api.letsencrypt.org/directory
acme_email: ""
tls_letsencrypt_hostname: ""
tls_letsencrypt_cache_dir: /var/lib/headscale/cache
tls_letsencrypt_challenge_type: HTTP-01
tls_letsencrypt_listen: ":http"
tls_cert_path: ""
tls_key_path: ""
log:
format: text
level: info
policy:
mode: database
path: ""
dns:
magic_dns: true
base_domain: example.com
nameservers:
global:
- 1.1.1.1
- 1.0.0.1
- 2606:4700:4700::1111
- 2606:4700:4700::1001
split: {}
search_domains: []
extra_records: []
unix_socket: /var/run/headscale/headscale.sock
unix_socket_permission: "0770"
logtail:
enabled: false
randomize_client_port: false
+29 -12
View File
@@ -3,64 +3,81 @@ services:
build:
context: .
dockerfile: Dockerfile.forust
# ports:
# - "8085:80"
ports:
- "8085:80"
restart: unless-stopped
volumes:
- ./forust_files:/usr/share/nginx/html
networks:
- proxy
- traefik-proxy
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.docker.network=traefik-proxy"
# Services
- "traefik.http.services.forust-homepage.loadbalancer.server.port=80"
# Prod Router
- "traefik.http.routers.forust-homepage.rule=Host(`forust.xyz`)"
- "traefik.http.routers.forust-homepage.entrypoints=websecure"
- "traefik.http.routers.forust-homepage.middlewares=security-headers@file"
- "traefik.http.routers.forust-homepage.service=forust-homepage"
- "traefik.http.routers.forust-homepage.tls=true"
# Local Router
- "traefik.http.routers.forust-homepage-local.rule=Host(`landing.workstation.internal`)"
- "traefik.http.routers.forust-homepage-local.rule=Host(`landing.workstation.internal`) || Host(`landing.internal`)"
- "traefik.http.routers.forust-homepage-local.entrypoints=websecure"
- "traefik.http.routers.forust-homepage-local.middlewares=security-headers@file"
- "traefik.http.routers.forust-homepage-local.service=forust-homepage"
- "traefik.http.routers.forust-homepage-local.tls=true"
# Dev Router
- "traefik.http.routers.forust-homepage-dev.rule=Host(`landing.gigaforust.internal`)"
- "traefik.http.routers.forust-homepage-dev.entrypoints=websecure"
- "traefik.http.routers.forust-homepage-dev.middlewares=security-headers@file"
- "traefik.http.routers.forust-homepage-dev.service=forust-homepage"
- "traefik.http.routers.forust-homepage-dev.tls=true"
xdfnx:
build:
context: .
dockerfile: Dockerfile.xdfnx
ports:
- "8086:80"
restart: unless-stopped
# ports:
# - "8086:80"
volumes:
- ./xdfnx_files:/usr/share/nginx/html
networks:
- traefik-proxy
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.docker.network=traefik-proxy"
# Services
- "traefik.http.services.xdfnx-homepage.loadbalancer.server.port=80"
# Prod Router
- "traefik.http.routers.xdfnx.rule=Host(`xdfnx.cfd`)"
- "traefik.http.routers.xdfnx.entrypoints=websecure"
- "traefik.http.routers.xdfnx.middlewares=security-headers@file"
- "traefik.http.routers.xdfnx.service=xdfnx-homepage"
- "traefik.http.routers.xdfnx.tls=true"
# Local Router
- "traefik.http.routers.xdfnx-local.rule=Host(`xdfnx.workstation.internal`)"
- "traefik.http.routers.xdfnx-local.rule=Host(`xdfnx.workstation.internal`) || Host(`xdfnx.internal`)"
- "traefik.http.routers.xdfnx-local.entrypoints=websecure"
- "traefik.http.routers.xdfnx-local.middlewares=security-headers@file"
- "traefik.http.routers.xdfnx-local.service=xdfnx-homepage"
- "traefik.http.routers.xdfnx-local.tls=true"
# Dev Router
- "traefik.http.routers.xdfnx-dev.rule=Host(`xdfnx.gigaforust.internal`)"
- "traefik.http.routers.xdfnx-dev.entrypoints=websecure"
- "traefik.http.routers.xdfnx-dev.middlewares=security-headers@file"
- "traefik.http.routers.xdfnx-dev.service=xdfnx-homepage"
- "traefik.http.routers.xdfnx-dev.tls=true"
networks:
- proxy
networks:
proxy:
traefik-proxy:
external: true
+11 -1
View File
@@ -134,6 +134,7 @@ ul {
background-size: cover;
}
/* if no avatar added: */
.placeholder::before {
content: "?";
@@ -155,9 +156,10 @@ footer {
text-align: center;
color: var(--dim);
font-size: 0.8rem;
/* flag{why-are-you-here?} */
/* flag{why-are-you-here?} */
margin-top: 4rem;
}
/* SMTH RESPONSIVE */
@media (max-width: 600px) {
.grid-2 {
@@ -165,3 +167,11 @@ footer {
gap: 0;
}
}
/* nya~ */
.birthday {
color: var(--dim);
font-size: 0.75rem;
margin-top: 4px;
opacity: 0.75;
}
+9 -8
View File
@@ -41,14 +41,7 @@
</li>
<li>
<i class="fas fa-envelope"></i>
<a href="mailto:forust@forust.xyz">mail/contact@forust.xyz</a>
</li>
<li>
<i class="fa-solid fa-key"></i>
<a href=".well-known/pgp-key.asc">security/PGP Key</a>
</li>
<li>
<p class="comment"># PGP Key Fingerprint: A777 7CB7 D9C4 0A97 443D CCF0 7A3D A455 F820 5B82</p>
<a href="mailto:forust@forust.xyz">forust@forust.xyz</a>
</li>
</ul>
</section>
@@ -126,6 +119,14 @@
<a href="https://chernuha.space" target="_blank">Chernuha</a>
</div>
<div class="member">
<div class="avatar"
style="background-image: url('assets/images/team/vv.jpg'); background-size: cover; background-position: center;">
</div>
<a href="./miku.html" target="_blank">vv</a>
<p class="birthday">Happy Birthday, darling ♡</p>
</div>
<div class="member">
<div class="avatar"
style="background-image: url('assets/images/team/hudan.jpg'); background-size: cover; background-position: center;">
Binary file not shown.

Before

Width:  |  Height:  |  Size: 42 KiB

+13 -7
View File
@@ -1,7 +1,7 @@
services:
metube:
image: ghcr.io/alexta69/metube
container_name: metube
# container_name: metube
restart: unless-stopped
# ports:
# - "8081:8081"
@@ -13,27 +13,33 @@ services:
volumes:
- ./MeTube_downloads:/downloads
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.http.services.metube.loadbalancer.server.port=8081"
- traefik.enable=true
- "traefik.docker.network=traefik-proxy"
# Prod Router
- "traefik.http.routers.metube.rule=Host(`metube.forust.xyz`)"
- "traefik.http.routers.metube.entrypoints=websecure"
- "traefik.http.routers.metube.middlewares=security-chain@file"
- "traefik.http.routers.metube.service=metube"
- "traefik.http.routers.metube.tls=true"
- "traefik.http.services.metube.loadbalancer.server.port=8081"
# Local Router
- "traefik.http.routers.metube-local.rule=Host(`metube.workstation.internal`))"
- "traefik.http.routers.metube-local.rule=Host(`metube.workstation.internal`) || Host(`metube.internal`)"
- "traefik.http.routers.metube-local.entrypoints=websecure"
- "traefik.http.routers.metube-local.middlewares=security-headers@file"
- "traefik.http.routers.metube-local.service=metube"
- "traefik.http.routers.metube-local.tls=true"
# Dev Router
- "traefik.http.routers.metube-dev.rule=Host(`metube.gigaforust.internal`)"
- "traefik.http.routers.metube-dev.entrypoints=websecure"
- "traefik.http.routers.metube-dev.middlewares=security-chain@file"
- "traefik.http.routers.metube-dev.service=metube"
- "traefik.http.routers.metube-dev.tls=true"
networks:
- proxy
- traefik-proxy
networks:
proxy:
traefik-proxy:
external: true
+3 -3
View File
@@ -23,11 +23,11 @@ services:
- 1.1.1.1
- 8.8.8.8
networks:
- proxy
- traefik-proxy
- n8n
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.docker.network=traefik-proxy"
# Prod Router
- "traefik.http.routers.n8n.rule=Host(`n8n.forust.xyz`)"
@@ -58,5 +58,5 @@ services:
networks:
n8n:
external: false
proxy:
traefik-proxy:
external: true
+17 -10
View File
@@ -9,7 +9,7 @@ services:
- /var/run/docker.sock:/var/run/docker.sock:ro
networks:
- nextcloud-aio
- proxy # Optional: Connects the mastercontainer to the proxy network in order to make the built-in reverse proxy detection work. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
- traefik-proxy # Optional: Connects the mastercontainer to the traefik-proxy network in order to make the built-in reverse proxy detection work. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
# ports:
# - 8081:80 # may be removed if under reverse-proxy
# - 8443:8443
@@ -17,42 +17,49 @@ services:
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.docker.network=traefik-proxy"
# AIO Services configuration
- "traefik.http.services.nextcloud-aio.loadbalancer.server.port=8080"
- "traefik.http.services.nextcloud-aio.loadbalancer.server.scheme=https"
- "traefik.http.services.nextcloud-aio.loadbalancer.serverstransport=insecureTransport@file"
# Prod Router
# - "traefik.http.routers.nextcloud-aio.rule=Host(`naio.forust.xyz`)"
# - "traefik.http.routers.nextcloud-aio.rule=Host(`nextcloud-aio.forust.xyz`)"
# - "traefik.http.routers.nextcloud-aio.entrypoints=websecure"
# - "traefik.http.routers.nextcloud-aio.middlewares=security-chain@file"
# - "traefik.http.routers.nextcloud-aio.middlewares=security-headers"
# - "traefik.http.routers.nextcloud-aio.service=nextcloud-aio"
# - "traefik.http.routers.nextcloud-aio.tls=true"
# Local Router
- "traefik.http.routers.nextcloud-aio-local.rule=Host(`naio.workstation.internal`)"
- "traefik.http.routers.nextcloud-aio-local.rule=Host(`nextcloud-aio.workstation.internal`) || Host(`nextcloud-aio.internal`)"
- "traefik.http.routers.nextcloud-aio-local.entrypoints=websecure"
- "traefik.http.routers.nextcloud-aio-local.middlewares=security-headers@file"
- "traefik.http.routers.nextcloud-aio-local.service=nextcloud-aio"
- "traefik.http.routers.nextcloud-aio-local.tls=true"
# Dev Router
- "traefik.http.routers.nextcloud-aio-dev.rule=Host(`naio.gigaforust.internal`)"
- "traefik.http.routers.nextcloud-aio-dev.rule=Host(`nextcloud-aio.gigaforust.internal`)"
- "traefik.http.routers.nextcloud-aio-dev.entrypoints=websecure"
- "traefik.http.routers.nextcloud-aio-dev.middlewares=security-headers@file"
- "traefik.http.routers.nextcloud-aio-dev.service=nextcloud-aio"
- "traefik.http.routers.nextcloud-aio-dev.tls=true"
# Glance Metadata
# Glanceapp/glance config
- glance.name=Nextcloud
# - glance.icon=si:nextcloud
- glance.url=https://nextcloud.forust.xyz/
- glance.description=Nextcloud is a suite of client-server software for creating and using file hosting services.
environment:
AIO_DISABLE_BACKUP_SECTION: false
APACHE_PORT: 11000 # Is needed when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else). See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
APACHE_IP_BINDING: 0.0.0.0 # Configure when going with reverse-proxy https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
APACHE_ADDITIONAL_NETWORK: proxy # (Optional) Connect the apache container to an additional docker network. When going with reverse-proxy. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
APACHE_ADDITIONAL_NETWORK: traefik-proxy # (Optional) Connect the apache container to an additional docker network. When going with reverse-proxy. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
BORG_RETENTION_POLICY: --keep-within=7d --keep-weekly=4 --keep-monthly=6 # Backup retention See https://github.com/nextcloud/all-in-one#how-to-adjust-borgs-retention-policy
COLLABORA_SECCOMP_DISABLED: false # Setting this to true allows to disable Collabora's Seccomp feature. See https://github.com/nextcloud/all-in-one#how-to-disable-collaboras-seccomp-feature
FULLTEXTSEARCH_JAVA_OPTIONS: "-Xms1024M -Xmx1024M" # adjust fulltextsearch java options. https://github.com/nextcloud/all-in-one#how-to-adjust-the-fulltextsearch-java-options
NEXTCLOUD_DATADIR: /mnt/nextcloud/ncdata # Allows to set the host directory for Nextcloud's datadir. ⚠️⚠️⚠️ Warning: do not set or adjust this value after the initial Nextcloud installation is done! See https://github.com/nextcloud/all-in-one#how-to-change-the-default-location-of-nextclouds-datadir
NEXTCLOUD_DATADIR: /media/forust/nextcloud/ncdata # Allows to set the host directory for Nextcloud's datadir. ⚠️⚠️⚠️ Warning: do not set or adjust this value after the initial Nextcloud installation is done! See https://github.com/nextcloud/all-in-one#how-to-change-the-default-location-of-nextclouds-datadir
NEXTCLOUD_MOUNT: /mnt/ # Allows the Nextcloud container to access the chosen directory on the host. See https://github.com/nextcloud/all-in-one#how-to-allow-the-nextcloud-container-to-access-directories-on-the-host
NEXTCLOUD_UPLOAD_LIMIT: 16G # https://github.com/nextcloud/all-in-one#how-to-adjust-the-upload-limit-for-nextcloud
NEXTCLOUD_MAX_TIME: 7200 # Max uploading time See https://github.com/nextcloud/all-in-one#how-to-adjust-the-max-execution-time-for-nextcloud
@@ -68,7 +75,7 @@ services:
# WATCHTOWER_DOCKER_SOCKET_PATH: /var/run/docker.sock # Needs to be specified if the docker socket on the host is not located in the default '/var/run/docker.sock'. For macos it needs to be '/var/run/docker.sock'
networks:
proxy:
traefik-proxy:
external: true
nextcloud-aio:
driver: bridge
+14 -7
View File
@@ -50,7 +50,7 @@ x-secret-key: &penpot-secret-key
networks:
penpot:
proxy:
traefik-proxy:
external: true
volumes:
@@ -86,8 +86,8 @@ services:
penpot-frontend:
image: "penpotapp/frontend:${PENPOT_VERSION:-latest}"
restart: always
# ports:
# - 9001:8080
ports:
- 9001:8080
volumes:
- penpot_assets:/opt/data/assets
@@ -98,30 +98,37 @@ services:
networks:
- penpot
- proxy
- traefik-proxy
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.http.services.penpot.loadbalancer.server.port=8080"
- "traefik.docker.network=traefik-proxy"
# Prod Router
- "traefik.http.routers.penpot.rule=Host(`penpot.forust.xyz`)"
- "traefik.http.routers.penpot.entrypoints=websecure"
- "traefik.http.routers.penpot.middlewares=security-headers@file"
- "traefik.http.routers.penpot.service=penpot"
- "traefik.http.routers.penpot.tls=true"
- "traefik.http.services.penpot.loadbalancer.server.port=8080"
# Local Router
- "traefik.http.routers.penpot-local.rule=Host(`penpot.workstation.internal`)"
- "traefik.http.routers.penpot-local.rule=Host(`penpot.workstation.internal`) || Host(`penpot.internal`)"
- "traefik.http.routers.penpot-local.entrypoints=websecure"
- "traefik.http.routers.penpot-local.middlewares=security-headers@file"
- "traefik.http.routers.penpot-local.service=penpot"
- "traefik.http.routers.penpot-local.tls=true"
# Dev Router
- "traefik.http.routers.penpot-dev.rule=Host(`penpot.gigaforust.internal`)"
- "traefik.http.routers.penpot-dev.entrypoints=websecure"
- "traefik.http.routers.penpot-dev.middlewares=security-headers@file"
- "traefik.http.routers.penpot-dev.service=penpot"
- "traefik.http.routers.penpot-dev.tls=true"
environment:
<<: [ *penpot-flags, *penpot-http-body-size ]
penpot-backend:
image: "penpotapp/backend:${PENPOT_VERSION:-latest}"
restart: always
+21 -12
View File
@@ -1,45 +1,54 @@
services:
portainer:
image: portainer/portainer-ce:latest
container_name: portainer
image: portainer/portainer-ce:latest
restart: always
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- data:/data
- ./portainer_data:/data
ports:
- 9443:9443
# - 8000:8000 # Remove if you do not intend to use Edge Agents
networks:
- traefik-proxy
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.http.services.portainer.loadbalancer.server.port=9443"
- "traefik.http.services.portainer.loadbalancer.server.scheme=https"
- "traefik.http.services.portainer.loadbalancer.serverstransport=insecureTransport@file"
- "traefik.docker.network=traefik-proxy"
# Prod Router
- "traefik.http.routers.portainer.rule=Host(`portainer.forust.xyz`)"
- "traefik.http.routers.portainer.entrypoints=websecure"
- "traefik.http.routers.portainer.middlewares=security-headers@file"
- "traefik.http.routers.portainer.service=portainer"
- "traefik.http.routers.portainer.tls=true"
- "traefik.http.services.portainer.loadbalancer.server.port=9443"
- "traefik.http.services.portainer.loadbalancer.server.scheme=https"
- "traefik.http.services.portainer.loadbalancer.serverstransport=insecureTransport@file"
# Local Router
- "traefik.http.routers.portainer-local.rule=Host(`portainer.workstation.internal`)"
- "traefik.http.routers.portainer-local.rule=Host(`portainer.workstation.internal`) || Host(`portainer.internal`)"
- "traefik.http.routers.portainer-local.entrypoints=websecure"
- "traefik.http.routers.portainer-local.middlewares=security-headers@file"
- "traefik.http.routers.portainer-local.service=portainer"
- "traefik.http.routers.portainer-local.tls=true"
# Dev Router
- "traefik.http.routers.portainer-dev.rule=Host(`portainer.gigaforust.internal`)"
- "traefik.http.routers.portainer-dev.entrypoints=websecure"
- "traefik.http.routers.portainer-dev.middlewares=security-headers@file"
- "traefik.http.routers.portainer-dev.service=portainer"
- "traefik.http.routers.portainer-dev.tls=true"
# Glance Metadata
- glance.name=Portainer
- glance.url=https://portainer.forust.xyz/
- glance.description=Portainer is a lightweight management UI which allows you to easily manage your Docker environments.
networks:
- proxy
volumes:
data:
portainer_data:
name: portainer_data
networks:
proxy:
default:
name: portainer_network
traefik-proxy:
external: true
-26
View File
@@ -1,26 +0,0 @@
# sudo mount /dev/sdc5 /mnt/mediaserver
# volumes:
# - /mnt/mediaserver:/<somepath>
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.http.services.lampa.loadbalancer.server.port=<container port>"
# Prod Router
- "traefik.http.routers.lampa.rule=Host(`media.forust.xyz`)"
- "traefik.http.routers.lampa.entrypoints=websecure"
- "traefik.http.routers.lampa.tls=true"
# Local Router
- "traefik.http.routers.lampa-local.rule=Host(`media.workstation.internal`)"
- "traefik.http.routers.lampa-local.entrypoints=websecure"
- "traefik.http.routers.lampa-local.tls=true"
# Dev Router
- "traefik.http.routers.lampa-dev.rule=Host(`media.gigaforust.internal`)"
- "traefik.http.routers.jellyfin-dev.entrypoints=websecure"
- "traefik.http.routers.jellyfin-dev.tls=true"
networks:
- proxy
networks:
proxy:
external: true
+17 -9
View File
@@ -3,36 +3,44 @@ services:
image: ghcr.io/lukegus/termix:latest
container_name: termix
restart: unless-stopped
# ports:
# - "3331:8080"
ports:
- "3331:8080"
volumes:
- data:/app/data
- ./termix-data:/app/data
environment:
PORT: "8080"
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.http.services.termix.loadbalancer.server.port=8080"
- "traefik.docker.network=traefik-proxy"
# Prod Router
- "traefik.http.routers.termix.rule=Host(`termix.forust.xyz`)"
- "traefik.http.routers.termix.entrypoints=websecure"
- "traefik.http.routers.termix.middlewares=security-headers@file"
- "traefik.http.routers.termix.service=termix"
- "traefik.http.routers.termix.tls=true"
- "traefik.http.services.termix.loadbalancer.server.port=8080"
# Local Router
- "traefik.http.routers.termix-local.rule=Host(`termix.workstation.internal`)"
- "traefik.http.routers.termix-local.rule=Host(`termix.workstation.internal`) || Host(`termix.internal`)"
- "traefik.http.routers.termix-local.entrypoints=websecure"
- "traefik.http.routers.termix-local.middlewares=security-headers@file"
- "traefik.http.routers.termix-local.service=termix"
- "traefik.http.routers.termix-local.tls=true"
# Dev Router
- "traefik.http.routers.termix-dev.rule=Host(`termix.gigaforust.internal`)"
- "traefik.http.routers.termix-dev.entrypoints=websecure"
- "traefik.http.routers.termix-dev.middlewares=security-headers@file"
- "traefik.http.routers.termix-dev.service=termix"
- "traefik.http.routers.termix-dev.tls=true"
networks:
- proxy
- traefik-proxy
networks:
proxy:
traefik-proxy:
external: true
volumes:
data:
termix-data:
driver: local
+29 -21
View File
@@ -11,7 +11,7 @@ services:
# Providers
- "--providers.docker=true"
- "--providers.docker.exposedbydefault=false"
- "--providers.docker.network=proxy"
- "--providers.docker.network=traefik-proxy"
- "--providers.file.directory=/etc/traefik/dynamic"
- "--providers.file.watch=true"
@@ -23,26 +23,26 @@ services:
- "--entryPoints.web.http.redirections.entryPoint.scheme=https"
- "--entryPoints.ssh.address=:2221"
# Let's Encrypt
- "--certificatesresolvers.letsencrypt.acme.email=${EMAIL}"
- "--certificatesresolvers.letsencrypt.acme.storage=/letsencrypt/acme.json"
- "--certificatesresolvers.letsencrypt.acme.httpchallenge=true"
- "--certificatesresolvers.letsencrypt.acme.httpchallenge.entrypoint=web"
# # STAGING
# Let's Encrypt STAGING. CURRENTLY USING CF ORIGIN CA INSTEAD
# - "--certificatesresolvers.letsencrypt.acme.email=${EMAIL}"
# - "--certificatesresolvers.letsencrypt.acme.storage=/letsencrypt/acme.json"
# - "--certificatesresolvers.letsencrypt.acme.caserver=https://acme-staging-v02.api.letsencrypt.org/directory"
# - "--certificatesresolvers.letsencrypt.acme.httpchallenge=true"
# - "--certificatesresolvers.letsencrypt.acme.httpchallenge.entrypoint=web"
# Cloudflare
- "--entryPoints.web.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
- "--entryPoints.websecure.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
# # Logging
# - "--log.level=INFO"
# - "--log.filePath=/var/log/traefik/traefik.log"
# - "--accesslog=true"
# - "--accesslog.filepath=/var/log/traefik/access.log"
# Logging
- "--log.level=INFO"
- "--log.filePath=/var/log/traefik/traefik.log"
- "--accesslog=true"
- "--accesslog.filepath=/var/log/traefik/access.log"
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.docker.network=traefik-proxy"
# Prod Router (Dash)
- "traefik.http.routers.traefik-dashboard.rule=Host(`traefik.forust.xyz`)"
@@ -50,12 +50,14 @@ services:
- "traefik.http.routers.traefik-dashboard.middlewares=security-chain@file"
- "traefik.http.routers.traefik-dashboard.service=api@internal"
- "traefik.http.routers.traefik-dashboard.tls=true"
# Local Router
- "traefik.http.routers.traefik-dashboard-local.rule=Host(`traefik.workstation.internal`)"
- "traefik.http.routers.traefik-dashboard-local.rule=Host(`traefik.workstation.internal`) || Host(`traefik.internal`)"
- "traefik.http.routers.traefik-dashboard-local.entrypoints=websecure"
- "traefik.http.routers.traefik-dashboard-local.middlewares=security-headers@file"
- "traefik.http.routers.traefik-dashboard-local.service=api@internal"
- "traefik.http.routers.traefik-dashboard-local.tls=true"
# Dev Router
- "traefik.http.routers.traefik-dashboard-dev.rule=Host(`traefik.gigaforust.internal`)"
- "traefik.http.routers.traefik-dashboard-dev.entrypoints=websecure"
@@ -63,21 +65,27 @@ services:
- "traefik.http.routers.traefik-dashboard-dev.service=api@internal"
- "traefik.http.routers.traefik-dashboard-dev.tls=true"
# Glance Metadata
- glance.name=Traefik
- glance.url=https://traefik.forust.xyz/
- glance.description=Traefik is a modern reverse proxy and load balancer
ports:
- "80:80"
- "443:443"
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
- ./dynamic:/etc/traefik/dynamic:ro
- ./certs:/certs:ro
- ./logs:/var/log/traefik
- ./letsencrypt:/letsencrypt
ports:
- "80:80"
- "443:443"
# - ./traefik/letsencrypt:/letsencrypt
networks:
- proxy
- traefik-proxy
environment:
- TZ=Europe/Bratislava
networks:
proxy:
traefik-proxy:
external: true
-23
View File
@@ -1,23 +0,0 @@
http:
routers:
fs1-public:
rule: "Host(`fs1.domain.xyz`)"
entrypoints:
- websecure
service: fs1
middlewares:
- security-chain@file
tls: {}
fs1-workstation:
rule: "Host(`fs1.workstation.internal`)"
entrypoints:
- websecure
service: fs1
tls: {}
services:
fs1:
loadBalancer:
servers:
- url: "http://127.0.0.1:3923" # Copyparty port example
+23
View File
@@ -5,6 +5,29 @@ http:
redirectScheme:
scheme: https
permanent: true
# Metube Basic Auth
metube-auth:
basicAuth:
users:
- "vv:$2y$05$JdT8AGUO9bd.E/PiCmKaoOJS1RFlXkrrmZ5mJ4f8/a1bEW39L3FbS"
realm: "MeTube Access"
# Basic Auth Traefik Dashboard
auth:
basicAuth:
users:
- "admin:$2y$05$.CKDD82sNUxcpaRrLbHuK.dopqt1fgurc2yfTKAT5OFzT7RvPrJHK"
realm: "Traefik Dashboard"
# Basic Auth Dockmon
dockmon-auth:
basicAuth:
users:
- "admin:$2y$05$.CKDD82sNUxcpaRrLbHuK.dopqt1fgurc2yfTKAT5OFzT7RvPrJHK"
realm: "Dockmon Access"
# Cloudflare IP Whitelist
cloudflare-ipwhitelist:
ipWhiteList:
-8
View File
@@ -1,8 +0,0 @@
http:
routers:
acme-challenge-exempt:
rule: "PathPrefix(`/.well-known/acme-challenge`)"
entryPoints:
- web
service: noop@internal
priority: 100
+12 -11
View File
@@ -1,33 +1,34 @@
services:
uptime-kuma:
image: louislam/uptime-kuma:2
container_name: uptime-kuma
restart: unless-stopped
container_name: uptime-kuma
volumes:
- data:/app/data
# ports:
# - "3001:3001"
- ./data:/app/data
ports:
# <Host Port>:<Container Port>
- "3001:3001"
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.http.services.uptime-kuma.loadbalancer.server.port=3001"
- "traefik.docker.network=traefik-proxy"
# Prod Router
- "traefik.http.routers.uptime-kuma.rule=Host(`uptime.forust.xyz`)"
- "traefik.http.routers.uptime-kuma.entrypoints=websecure"
- "traefik.http.routers.uptime-kuma.tls=true"
- "traefik.http.services.uptime-kuma.loadbalancer.server.port=3001"
# Local Router
- "traefik.http.routers.uptime-kuma-local.rule=Host(`uptime.workstation.internal`)"
- "traefik.http.routers.uptime-kuma-local.rule=Host(`uptime.workstation.internal`) || Host(`uptime.internal`)"
- "traefik.http.routers.uptime-kuma-local.entrypoints=websecure"
- "traefik.http.routers.uptime-kuma-local.tls=true"
# Dev Router
- "traefik.http.routers.uptime-kuma-dev.rule=Host(`uptime.gigaforust.internal`)"
- "traefik.http.routers.uptime-kuma-dev.entrypoints=websecure"
- "traefik.http.routers.uptime-kuma-dev.tls=true"
networks:
- proxy
volumes:
data:
- traefik-proxy
networks:
proxy:
traefik-proxy:
external: true