Compare commits
69 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
5dfa9c879b
|
|||
| 3c5702a0fb | |||
| dd0ca27f4f | |||
| 7f7d0de090 | |||
| bee3f16cb2 | |||
|
303d23968d
|
|||
|
b7ecf88052
|
|||
|
5068591b8b
|
|||
|
8e57f21e44
|
|||
|
073d9ff569
|
|||
| c6d00e525b | |||
|
539994a145
|
|||
|
95f0afbbee
|
|||
|
9f86bd1142
|
|||
| af9668e8e6 | |||
|
53b71a33ad
|
|||
|
bf72007b14
|
|||
|
0bad0a817e
|
|||
| 525fed3b92 | |||
|
fe5e5c5e35
|
|||
|
72aa022048
|
|||
|
f18d4d9be4
|
|||
|
45ce789f58
|
|||
|
d7c05fd058
|
|||
| c13056fba1 | |||
|
5fe8af82d5
|
|||
| 6d97246997 | |||
| 6970279311 | |||
|
02f4e0ab42
|
|||
|
4a25622552
|
|||
|
0138fbd276
|
|||
|
94b5f39207
|
|||
| 403e88d548 | |||
| d03a4844fb | |||
| 48ff08529e | |||
|
81592b6142
|
|||
| 9480576966 | |||
| 9b43a9bef4 | |||
| 2b03335af5 | |||
| ea738ec14c | |||
|
e4e9d96a0b
|
|||
| 89576032b9 | |||
| a9edfc0a25 | |||
| acb8009307 | |||
| 21f4e46028 | |||
| 0234524635 | |||
| 26f5fb2fb9 | |||
| 122e6f6986 | |||
| ce0bc4613a | |||
| 8f4f460ff3 | |||
| c048efd569 | |||
| 1f1e13ff39 | |||
| c80a6c5351 | |||
| 4fe3d660f1 | |||
| 9675eac2bf | |||
| dc7fe64fbc | |||
| 502810a12e | |||
| c047cc291d | |||
| f2b951673c | |||
| 6b7c0df586 | |||
| fb2f420520 | |||
| 60c7d4ff17 | |||
| db0f0f7bb6 | |||
| 5e4c60bb30 | |||
| bfb21adff7 | |||
| 1c75382a6e | |||
| 9c5e037567 | |||
| 9f784d2c31 | |||
| a07e27bff6 |
+17
-8
@@ -2,17 +2,12 @@
|
||||
sync.ffs_lock
|
||||
.sync.ffs_db
|
||||
|
||||
# Environment
|
||||
.env
|
||||
.env.anna
|
||||
.env.forust
|
||||
.env.*
|
||||
!.env.*example
|
||||
# Copyparty
|
||||
*.hist/
|
||||
|
||||
# Volumes and data directories
|
||||
gitea/gitea-db/
|
||||
gitea/gitea-data/*
|
||||
gitea/*runner/*
|
||||
n8n/n8n-data/*
|
||||
n8n/n8n-node-data/*
|
||||
adguardhome/data/*
|
||||
@@ -24,6 +19,8 @@ termix/termix-data/*
|
||||
cfddns/config.json
|
||||
checkmk/checkmk/*
|
||||
downtify/Downtify_downloads
|
||||
headscale/config/*
|
||||
headscale/data/*
|
||||
|
||||
# Steaming services files
|
||||
streaming/jellyfin/*
|
||||
@@ -36,11 +33,15 @@ streaming/prowlarr/*
|
||||
|
||||
# Homepage
|
||||
homepages/forust_files/assets/images/team/*
|
||||
|
||||
homepages/forust_files/.well-known/*
|
||||
|
||||
# Traefik files
|
||||
traefik/letsencrypt/acme.json
|
||||
traefik/dynamic/fileservers.yml
|
||||
traefik/logs/*
|
||||
|
||||
# SSL Certificates
|
||||
adguardhome/certs/*
|
||||
traefik/certs/*
|
||||
|
||||
# Monitoring
|
||||
@@ -83,3 +84,11 @@ replacements.txt
|
||||
|
||||
# Temp files
|
||||
edu_master/temp/
|
||||
temp/*
|
||||
|
||||
# Environment
|
||||
.env
|
||||
.env.anna
|
||||
.env.forust
|
||||
.env.*
|
||||
!*example
|
||||
+19
-19
@@ -3,48 +3,48 @@ services:
|
||||
image: adguard/adguardhome:latest
|
||||
container_name: adguardhome
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- TZ=${TZ}
|
||||
ports:
|
||||
- "53:53/tcp"
|
||||
- "53:53/udp"
|
||||
- "853:853/tcp" # DNS over TLS
|
||||
# - "67:67/udp" # DHCP
|
||||
# - "68:68/tcp" # DHCP
|
||||
- "3000:3000/tcp"
|
||||
# - "3000:3000/tcp"
|
||||
volumes:
|
||||
- ./data/work:/opt/adguardhome/work
|
||||
- ./data/conf:/opt/adguardhome/conf
|
||||
networks:
|
||||
- traefik-proxy
|
||||
- ./certs:/certs:ro
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.adguard.rule=Host(`adguard.forust.xyz`)"
|
||||
- "traefik.http.routers.adguard.entrypoints=websecure"
|
||||
- "traefik.http.routers.adguard.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.adguard.service=adguard"
|
||||
- "traefik.http.routers.adguard.tls=true"
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.http.services.adguard.loadbalancer.server.port=3000"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.adguard.rule=Host(`dns.forust.xyz`) || Host(`adguard.forust.xyz`)"
|
||||
- "traefik.http.routers.adguard.entrypoints=websecure"
|
||||
- "traefik.http.routers.adguard.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.adguard.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.adguard-local.rule=Host(`adguard.workstation.internal`) || Host(`adguard.internal`)"
|
||||
- "traefik.http.routers.adguard-local.rule=Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`)"
|
||||
- "traefik.http.routers.adguard-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.adguard-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.adguard-local.service=adguard"
|
||||
- "traefik.http.routers.adguard-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.adguard-dev.rule=Host(`adguard.gigaforust.internal`)"
|
||||
- "traefik.http.routers.adguard-dev.rule=Host(`adguard.gigaforust.internal`) || Host(`dns.gigaforust.internal`)"
|
||||
- "traefik.http.routers.adguard-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.adguard-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.adguard-dev.service=adguard"
|
||||
- "traefik.http.routers.adguard-dev.tls=true"
|
||||
# DoH Router
|
||||
- "traefik.http.routers.dns.rule=(Host(`dns.forust.xyz`) && PathPrefix(`/dns-query`))"
|
||||
- "traefik.http.routers.dns.entrypoints=websecure"
|
||||
- "traefik.http.routers.dns.tls.certresolver=letsencrypt"
|
||||
|
||||
# Glance Metadata
|
||||
- glance.name=adguard
|
||||
- glance.url=https://adguard.forust.xyz/
|
||||
- glance.description=AdGuard Home is a network-wide software for blocking ads.
|
||||
networks:
|
||||
traefik-proxy:
|
||||
- proxy
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
+9
-14
@@ -26,9 +26,9 @@ services:
|
||||
command: server
|
||||
container_name: authentik-server
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- ${PORT_HTTP:-9000}:9000
|
||||
- ${PORT_HTTPS:-9443}:9443
|
||||
# ports:
|
||||
# - ${PORT_HTTP:-9000}:9000
|
||||
# - ${PORT_HTTPS:-9443}:9443
|
||||
env_file:
|
||||
- .env
|
||||
environment:
|
||||
@@ -37,12 +37,12 @@ services:
|
||||
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
|
||||
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
|
||||
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
||||
|
||||
volumes:
|
||||
- ./media:/media
|
||||
- ./custom-templates:/templates
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
# Services
|
||||
# - "traefik.http.services.authentik-server.loadbalancer.server.port=9443"
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.http.services.authentik-server.loadbalancer.server.port=9000"
|
||||
|
||||
# Prod Router
|
||||
@@ -51,25 +51,20 @@ services:
|
||||
- "traefik.http.routers.authentik-server.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.authentik-server.service=authentik-server"
|
||||
- "traefik.http.routers.authentik-server.tls=true"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.authentik-server-local.rule=Host(`auth.workstation.internal`) || Host(`auth-dashboard.internal`)"
|
||||
- "traefik.http.routers.authentik-server-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.authentik-server-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.authentik-server-local.service=authentik-server"
|
||||
- "traefik.http.routers.authentik-server-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.authentik-server-dev.rule=Host(`auth.gigaforust.internal`)"
|
||||
- "traefik.http.routers.authentik-server-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.authentik-server-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.authentik-server-dev.service=authentik-server"
|
||||
- "traefik.http.routers.authentik-server-dev.tls=true"
|
||||
volumes:
|
||||
- ./media:/media
|
||||
- ./custom-templates:/templates
|
||||
networks:
|
||||
- traefik-proxy
|
||||
- proxy
|
||||
- authentik
|
||||
depends_on:
|
||||
postgresql:
|
||||
@@ -102,5 +97,5 @@ volumes:
|
||||
driver: local
|
||||
networks:
|
||||
authentik:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
+1
-1
@@ -2,6 +2,7 @@ services:
|
||||
cloudflare-ddns:
|
||||
image: timothyjmiller/cloudflare-ddns:latest
|
||||
container_name: cloudflare-ddns
|
||||
restart: unless-stopped
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
network_mode: 'host'
|
||||
@@ -10,4 +11,3 @@ services:
|
||||
- PGID=1000
|
||||
volumes:
|
||||
- ./config.json:/config.json
|
||||
restart: unless-stopped
|
||||
|
||||
@@ -0,0 +1,2 @@
|
||||
CMK_PASSWORD=password
|
||||
TZ=Europe/Berlin
|
||||
@@ -0,0 +1,43 @@
|
||||
services:
|
||||
checkmk:
|
||||
image: "checkmk/check-mk-raw:2.4.0-latest"
|
||||
container_name: "checkmk"
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - 5000:5000
|
||||
# - 6776:8000
|
||||
volumes:
|
||||
- sites:/omd/sites
|
||||
tmpfs:
|
||||
- /opt/omd/sites/cmk/tmp:uid=1000,gid=1000
|
||||
environment:
|
||||
- CMK_PASSWORD=${CMK_PASSWORD:-password}
|
||||
- CMK_SITE_ID=cmk
|
||||
- TZ=${TZ:-Etc/UTC}
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.http.services.checkmk.loadbalancer.server.port=5000"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.checkmk.rule=Host(`cmk.forust.xyz`)"
|
||||
- "traefik.http.routers.checkmk.entrypoints=websecure"
|
||||
- "traefik.http.routers.checkmk.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.checkmk.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.checkmk-local.rule=Host(`cmk.workstation.internal`)"
|
||||
- "traefik.http.routers.checkmk-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.checkmk-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.checkmk-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.checkmk-dev.rule=Host(`cmk.gigaforust.internal`)"
|
||||
- "traefik.http.routers.checkmk-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.checkmk-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.checkmk-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
volumes:
|
||||
sites:
|
||||
+14
-18
@@ -3,23 +3,22 @@ services:
|
||||
image: darthnorse/dockmon:latest
|
||||
container_name: dockmon
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- 8000:443
|
||||
environment:
|
||||
- TZ=Europe/Bratislava
|
||||
# ports:
|
||||
# - 8000:443
|
||||
volumes:
|
||||
- ./data:/app/data
|
||||
- data:/app/data
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
healthcheck:
|
||||
test: [ "CMD", "curl", "-k", "-f", "https://localhost:443/health" ]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 3
|
||||
networks:
|
||||
- traefik-proxy
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.http.services.dockmon.loadbalancer.server.port=443"
|
||||
- "traefik.http.services.dockmon.loadbalancer.server.scheme=https"
|
||||
- "traefik.http.services.dockmon.loadbalancer.serverstransport=insecureTransport@file"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
|
||||
@@ -27,28 +26,25 @@ services:
|
||||
- "traefik.http.routers.dockmon.middlewares=security-chain@file"
|
||||
- "traefik.http.routers.dockmon.service=dockmon"
|
||||
- "traefik.http.routers.dockmon.tls=true"
|
||||
- "traefik.http.services.dockmon.loadbalancer.server.port=443"
|
||||
- "traefik.http.services.dockmon.loadbalancer.server.scheme=https"
|
||||
- "traefik.http.services.dockmon.loadbalancer.serverstransport=insecureTransport@file"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`) || Host(`dockmon.internal`)"
|
||||
- "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`)"
|
||||
- "traefik.http.routers.dockmon-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.dockmon-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.dockmon-local.service=dockmon"
|
||||
- "traefik.http.routers.dockmon-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.dockmon-dev.rule=Host(`dockmon.gigaforust.internal`)"
|
||||
- "traefik.http.routers.dockmon-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.dockmon-dev.middlewares=security-chain@file"
|
||||
- "traefik.http.routers.dockmon-dev.service=dockmon"
|
||||
- "traefik.http.routers.dockmon-dev.tls=true"
|
||||
|
||||
# Glance Metadata
|
||||
- glance.name=dockmon
|
||||
- glance.url=https://dockmon.forust.xyz/
|
||||
- glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface.
|
||||
|
||||
networks:
|
||||
traefik-proxy:
|
||||
- proxy
|
||||
volumes:
|
||||
data:
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
+5
-11
@@ -4,36 +4,30 @@ services:
|
||||
image: ghcr.io/henriquesebastiao/downtify:latest
|
||||
# ports:
|
||||
# - '7077:8000'
|
||||
volumes:
|
||||
- ./Downtify_downloads:/downloads
|
||||
labels:
|
||||
- traefik.enable=true
|
||||
- traefik.docker.network=proxy
|
||||
- traefik.http.services.downtify.loadbalancer.server.port=8000
|
||||
|
||||
# Prod Router
|
||||
- traefik.http.routers.downtify.rule=Host(`downtify.forust.xyz`)
|
||||
- traefik.http.routers.downtify.entrypoints=websecure
|
||||
- traefik.http.routers.downtify.middlewares=security-chain@file
|
||||
- traefik.http.routers.downtify.service=downtify
|
||||
- traefik.http.routers.downtify.tls=true
|
||||
|
||||
# Local Router
|
||||
- traefik.http.routers.downtify-local.rule=Host(`downtify.workstation.internal`) || Host(`downtify.internal`)
|
||||
- traefik.http.routers.downtify-local.entrypoints=websecure
|
||||
- traefik.http.routers.downtify-local.middlewares=security-headers@file
|
||||
- traefik.http.routers.downtify-local.service=downtify
|
||||
- traefik.http.routers.downtify-local.tls=true
|
||||
|
||||
# Dev Router
|
||||
- traefik.http.routers.downtify-dev.rule=Host(`downtify.gigaforust.internal`)
|
||||
- traefik.http.routers.downtify-dev.entrypoints=websecure
|
||||
- traefik.http.routers.downtify-dev.middlewares=security-chain@file
|
||||
- traefik.http.routers.downtify-dev.service=downtify
|
||||
- traefik.http.routers.downtify-dev.tls=true
|
||||
networks:
|
||||
- traefik-proxy
|
||||
|
||||
volumes:
|
||||
- ./Downtify_downloads:/downloads
|
||||
|
||||
- proxy
|
||||
networks:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
@@ -12,15 +12,26 @@ logging.basicConfig(
|
||||
)
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
# Load configuration
|
||||
LOGIN = os.getenv('EDU_LOGIN')
|
||||
PASSWORD = os.getenv('EDU_PASSWORD')
|
||||
URL_LOGIN = os.getenv('EDU_URL_LOGIN', 'https://edu.edu.vn.ua/user/login')
|
||||
URL_VERIFY = os.getenv('EDU_URL_VERIFY', 'https://edu.edu.vn.ua/course/userlist')
|
||||
INTERVAL = int(os.getenv('PHPSESSID_INTERVAL', 10))
|
||||
USER_AGENT = os.getenv('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
|
||||
REDIS_HOST = os.getenv('REDIS_HOST', 'redis')
|
||||
REDIS_PORT = int(os.getenv('REDIS_PORT', 6379))
|
||||
# Load configuration (adapted to .env keys)
|
||||
def _env(key, default=None):
|
||||
v = os.getenv(key, default)
|
||||
if isinstance(v, str) and len(v) >= 2 and ((v[0] == '"' and v[-1] == '"') or (v[0] == "'" and v[-1] == "'")):
|
||||
return v[1:-1]
|
||||
return v
|
||||
|
||||
LOGIN = _env('KEEPER_LOGIN')
|
||||
PASSWORD = _env('KEEPER_PASSWORD')
|
||||
|
||||
EDU_BASE = _env('EDU_URL_BASE', 'https://edu.edu.vn.ua')
|
||||
EDU_LOGIN_PATH = _env('EDU_URL_LOGIN', '/user/login')
|
||||
EDU_COURSES_PATH = _env('EDU_URL_COURSES', '/course/userlist')
|
||||
URL_LOGIN = f"{EDU_BASE.rstrip('/')}/{EDU_LOGIN_PATH.lstrip('/')}"
|
||||
URL_VERIFY = f"{EDU_BASE.rstrip('/')}/{EDU_COURSES_PATH.lstrip('/')}"
|
||||
|
||||
INTERVAL = int(_env('KEEPER_INTERVAL', 10))
|
||||
USER_AGENT = _env('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
|
||||
REDIS_HOST = _env('REDIS_HOST', 'redis')
|
||||
REDIS_PORT = int(_env('REDIS_PORT', 6379))
|
||||
|
||||
SUCCESS_FILE = '/tmp/last_success'
|
||||
|
||||
|
||||
@@ -3,7 +3,8 @@ import logging
|
||||
import redis
|
||||
import json
|
||||
|
||||
from telegram import Update, InlineKeyboardButton, InlineKeyboardMarkup
|
||||
from telegram import Update, InlineKeyboardButton, InlineKeyboardMarkup, ChatMember
|
||||
from telegram.constants import ChatType
|
||||
from telegram.ext import Application, CommandHandler, CallbackQueryHandler, ContextTypes
|
||||
from playwright.async_api import async_playwright
|
||||
|
||||
@@ -14,22 +15,36 @@ logging.basicConfig(
|
||||
)
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
# Suppress HTTP request logs
|
||||
logging.getLogger('urllib3').setLevel(logging.WARNING)
|
||||
logging.getLogger('httpx').setLevel(logging.WARNING)
|
||||
logging.getLogger('telegram.ext._application').setLevel(logging.WARNING)
|
||||
|
||||
# Load environment variables
|
||||
WEBINAR_URL = os.getenv('WEBINAR_URL', 'https://edu.edu.vn.ua/webinar/useractive')
|
||||
WEBINAR_CHECK_INTERVAL = int(os.getenv('WEBINAR_CHECK_INTERVAL', 60))
|
||||
REDIS_HOST = os.getenv('REDIS_HOST', 'redis')
|
||||
REDIS_PORT = int(os.getenv('REDIS_PORT', 6379))
|
||||
PLAYWRIGHT_WS = os.getenv('PLAYWRIGHT_WS', 'ws://playwright-service:3000/ws')
|
||||
USER_AGENT = os.getenv('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
|
||||
WEBINAR_TELEGRAM_TOKEN = os.getenv('WEBINAR_TELEGRAM_TOKEN')
|
||||
ADMIN_ID = int(os.getenv('WEBINAR_ADMIN_ID', '0'))
|
||||
def _env(key, default=None):
|
||||
v = os.getenv(key, default)
|
||||
if isinstance(v, str) and len(v) >= 2 and ((v[0] == '"' and v[-1] == '"') or (v[0] == "'" and v[-1] == "'")):
|
||||
return v[1:-1]
|
||||
return v
|
||||
|
||||
EDU_BASE = _env('EDU_URL_BASE', 'https://edu.edu.vn.ua')
|
||||
EDU_WEBINAR_PATH = _env('EDU_URL_WEBINAR', '/webinar/useractive')
|
||||
WEBINAR_URL = f"{EDU_BASE.rstrip('/')}/{EDU_WEBINAR_PATH.lstrip('/')}"
|
||||
|
||||
WEBINAR_CHECK_INTERVAL = int(_env('WEBINAR_CHECK_INTERVAL', 60))
|
||||
REDIS_HOST = _env('REDIS_HOST', 'redis')
|
||||
REDIS_PORT = int(_env('REDIS_PORT', 6379))
|
||||
PLAYWRIGHT_WS = _env('PLAYWRIGHT_WS', 'ws://playwright-service:3000/ws')
|
||||
USER_AGENT = _env('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
|
||||
WEBINAR_TELEGRAM_TOKEN = _env('WEBINAR_TELEGRAM_TOKEN')
|
||||
ADMIN_ID = int(_env('WEBINAR_ADMIN_ID', '0'))
|
||||
|
||||
# Redis Keys
|
||||
KEY_WHITELIST = "bot:whitelist"
|
||||
KEY_WHITELIST_ENABLED = "bot:whitelist_enabled"
|
||||
KEY_SUBSCRIBERS = "bot:subscribers"
|
||||
KEY_PHPSESSID = "EDU_PHPSESSID"
|
||||
KEY_WEBINAR_HISTORY = "bot:webinar_history" # Stores last 5 webinars
|
||||
KEY_WEBINAR_HISTORY = "bot:webinar_history" # Stores last 3 webinars
|
||||
|
||||
# Initialize Redis
|
||||
try:
|
||||
@@ -48,7 +63,7 @@ TRANSLATIONS = {
|
||||
'welcome_admin': "\n\n👑 <b>Режим администратора активен</b>",
|
||||
'access_denied': "⛔ Доступ запрещен. Вас нет в белом списке.",
|
||||
'help_title': "🤖 <b>Помощь по боту</b>\n\n",
|
||||
'help_commands': "/start - Подписаться на уведомления\n/help - Показать это сообщение\n/language - Сменить язык",
|
||||
'help_commands': "/start - Подписаться на уведомления\n/stop - Отписаться от уведомлений\n/help - Показать это сообщение\n/language - Сменить язык",
|
||||
'help_admin': "\n<b>Команды администратора:</b>\n/adduser [user_id] - Добавить пользователя в белый список\n/removeuser [user_id] - Удалить пользователя из белого списка\nИли используйте панель ниже для управления настройками.",
|
||||
'admin_only': "⛔ Только для администратора!",
|
||||
'user_added': "✅ Пользователь {user_id} добавлен в белый список",
|
||||
@@ -79,13 +94,15 @@ TRANSLATIONS = {
|
||||
'flag_ru': "🇷🇺 Русский",
|
||||
'flag_uk': "🇺🇦 Українська",
|
||||
'flag_en': "🇬🇧 English",
|
||||
'history_cleared': "✅ История вебинаров очищена",
|
||||
'history_clear_failed': "❌ Ошибка при очистке истории",
|
||||
},
|
||||
'uk': {
|
||||
'welcome': "👋 Привіт, {name}!\n\nЯ бот-сповіщувач про вебінари. Я повідомлятиму вас, коли з'явиться новий вебінар.\nВи підписані на сповіщення.",
|
||||
'welcome_admin': "\n\n👑 <b>Режим адміністратора активний</b>",
|
||||
'access_denied': "⛔ Доступ заборонено. Вас немає в білому списку.",
|
||||
'help_title': "🤖 <b>Довідка по боту</b>\n\n",
|
||||
'help_commands': "/start - Підписатися на сповіщення\n/help - Показати це повідомлення\n/language - Змінити мову",
|
||||
'help_commands': "/start - Підписатися на сповіщення\n/stop - Відписатися від сповіщень\n/help - Показати це повідомлення\n/language - Змінити мову",
|
||||
'help_admin': "\n<b>Команди адміністратора:</b>\n/adduser [user_id] - Додати користувача до білого списку\n/removeuser [user_id] - Видалити користувача з білого списку\nАбо використовуйте панель нижче для керування налаштуваннями.",
|
||||
'admin_only': "⛔ Тільки для адміністратора!",
|
||||
'user_added': "✅ Користувач {user_id} доданий до білого списку",
|
||||
@@ -116,13 +133,15 @@ TRANSLATIONS = {
|
||||
'flag_ru': "🇷🇺 Русский",
|
||||
'flag_uk': "🇺🇦 Українська",
|
||||
'flag_en': "🇬🇧 English",
|
||||
'history_cleared': "✅ Історія вебінарів очищена",
|
||||
'history_clear_failed': "❌ Помилка при очищенні історії",
|
||||
},
|
||||
'en': {
|
||||
'welcome': "👋 Hello, {name}!\n\nI am the Webinar Checker Bot. I will notify you when a new webinar appears.\nYou have been subscribed to notifications.",
|
||||
'welcome_admin': "\n\n👑 <b>Admin Mode Active</b>",
|
||||
'access_denied': "⛔ Access denied. You are not on the whitelist.",
|
||||
'help_title': "🤖 <b>Bot Help</b>\n\n",
|
||||
'help_commands': "/start - Subscribe to notifications\n/help - Show this message\n/language - Change language",
|
||||
'help_commands': "/start - Subscribe to notifications\n/stop - Unsubscribe from notifications\n/help - Show this message\n/language - Change language",
|
||||
'help_admin': "\n<b>Admin Commands:</b>\n/adduser [user_id] - Add user to whitelist\n/removeuser [user_id] - Remove user from whitelist\nOr use the panel below to manage settings.",
|
||||
'admin_only': "⛔ Admin only!",
|
||||
'user_added': "✅ User {user_id} added to whitelist",
|
||||
@@ -153,6 +172,8 @@ TRANSLATIONS = {
|
||||
'flag_ru': "🇷🇺 Русский",
|
||||
'flag_uk': "🇺🇦 Українська",
|
||||
'flag_en': "🇬🇧 English",
|
||||
'history_cleared': "✅ Webinar history cleared",
|
||||
'history_clear_failed': "❌ Error clearing history",
|
||||
}
|
||||
}
|
||||
|
||||
@@ -203,6 +224,21 @@ def is_whitelisted(user_id: int) -> bool:
|
||||
|
||||
return redis_client.sismember(KEY_WHITELIST, str(user_id))
|
||||
|
||||
async def is_group_admin(update: Update, context: ContextTypes.DEFAULT_TYPE) -> bool:
|
||||
"""Check if the user is an administrator in the group."""
|
||||
user = update.effective_user
|
||||
chat = update.effective_chat
|
||||
|
||||
if chat.type in [ChatType.PRIVATE, "private"]:
|
||||
return True
|
||||
|
||||
try:
|
||||
member = await context.bot.get_chat_member(chat.id, user.id)
|
||||
return member.status in [ChatMember.OWNER, ChatMember.ADMINISTRATOR]
|
||||
except Exception as e:
|
||||
logger.error(f"Failed to check admin status: {e}")
|
||||
return False
|
||||
|
||||
def get_admin_keyboard(user_id: int):
|
||||
"""Generate admin panel keyboard."""
|
||||
whitelist_enabled = redis_client.get(KEY_WHITELIST_ENABLED) != "0"
|
||||
@@ -221,19 +257,21 @@ def get_admin_keyboard(user_id: int):
|
||||
async def start(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
"""Handle /start command."""
|
||||
user = update.effective_user
|
||||
logger.info(f"User {user.id} ({user.username}) started the bot.")
|
||||
chat = update.effective_chat
|
||||
logger.info(f"User {user.id} ({user.username}) started the bot in chat {chat.id} ({chat.type}).")
|
||||
|
||||
# Check whitelist - MUST be the user executing the command
|
||||
if not is_whitelisted(user.id):
|
||||
await update.message.reply_text(t(user.id, 'access_denied'))
|
||||
return
|
||||
|
||||
# Add to subscribers
|
||||
redis_client.sadd(KEY_SUBSCRIBERS, user.id)
|
||||
# Add to subscribers (Chat ID!)
|
||||
redis_client.sadd(KEY_SUBSCRIBERS, chat.id)
|
||||
|
||||
msg = t(user.id, 'welcome', name=user.first_name)
|
||||
msg = t(chat.id, 'welcome', name=user.first_name)
|
||||
|
||||
if user.id == ADMIN_ID:
|
||||
msg += t(user.id, 'welcome_admin')
|
||||
if user.id == ADMIN_ID and chat.type == "private":
|
||||
msg += t(chat.id, 'welcome_admin')
|
||||
await update.message.reply_text(msg, parse_mode='HTML', reply_markup=get_admin_keyboard(user.id))
|
||||
else:
|
||||
await update.message.reply_text(msg, parse_mode='HTML')
|
||||
@@ -241,19 +279,39 @@ async def start(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
async def help_command(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
"""Handle /help command."""
|
||||
user_id = update.effective_user.id
|
||||
msg = t(user_id, 'help_title') + t(user_id, 'help_commands')
|
||||
chat_id = update.effective_chat.id
|
||||
msg = t(chat_id, 'help_title') + t(chat_id, 'help_commands')
|
||||
|
||||
if user_id == ADMIN_ID:
|
||||
msg += t(user_id, 'help_admin')
|
||||
if user_id == ADMIN_ID and update.effective_chat.type == "private":
|
||||
msg += t(chat_id, 'help_admin')
|
||||
await update.message.reply_text(msg, parse_mode='HTML', reply_markup=get_admin_keyboard(user_id))
|
||||
else:
|
||||
await update.message.reply_text(msg, parse_mode='HTML')
|
||||
|
||||
async def stop_command(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
"""Handle /stop command (unsubscribe)."""
|
||||
user = update.effective_user
|
||||
chat = update.effective_chat
|
||||
|
||||
# Permission check: Whitelisted user OR Group Admin
|
||||
if not (is_whitelisted(user.id) or await is_group_admin(update, context)):
|
||||
await update.message.reply_text(t(chat.id, 'access_denied')) # Or specific "admin only" message
|
||||
return
|
||||
|
||||
redis_client.srem(KEY_SUBSCRIBERS, chat.id)
|
||||
await update.message.reply_text(t(chat.id, 'whitelist_disabled').replace(" whitelist", " notifications").replace("Білий список", "Сповіщення").replace("Белый список", "Уведомления") if chat.id else "Unsubscribed")
|
||||
|
||||
async def language_command(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
"""Handle /language command."""
|
||||
user_id = update.effective_user.id
|
||||
user = update.effective_user
|
||||
chat = update.effective_chat
|
||||
|
||||
# Permission check for groups
|
||||
if not (is_whitelisted(user.id) or await is_group_admin(update, context)):
|
||||
return
|
||||
|
||||
await update.message.reply_text(
|
||||
t(user_id, 'select_language'),
|
||||
t(chat.id, 'select_language'),
|
||||
parse_mode='HTML',
|
||||
reply_markup=get_language_keyboard()
|
||||
)
|
||||
@@ -303,6 +361,21 @@ async def remove_user(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
except ValueError:
|
||||
await update.message.reply_text(t(admin_id, 'invalid_user_id'))
|
||||
|
||||
async def clear_history(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
"""Clear webinar history (admin only)."""
|
||||
admin_id = update.effective_user.id
|
||||
if admin_id != ADMIN_ID:
|
||||
await update.message.reply_text(t(admin_id, 'admin_only'))
|
||||
return
|
||||
|
||||
try:
|
||||
redis_client.delete(KEY_WEBINAR_HISTORY)
|
||||
await update.message.reply_text(t(admin_id, 'history_cleared'))
|
||||
logger.info("Admin cleared webinar history")
|
||||
except Exception as e:
|
||||
logger.error(f"Failed to clear history: {e}")
|
||||
await update.message.reply_text(t(admin_id, 'history_clear_failed'))
|
||||
|
||||
# --- Admin Callbacks ---
|
||||
|
||||
async def admin_callback(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
@@ -363,9 +436,9 @@ async def language_callback(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
|
||||
# --- Webinar Checking Job ---
|
||||
|
||||
def get_webinar_key(name: str, url: str) -> str:
|
||||
"""Generate unique key for a webinar based on name and URL."""
|
||||
return f"{name}|{url}"
|
||||
def get_webinar_key(url: str) -> str:
|
||||
"""Generate unique key for a webinar based on URL."""
|
||||
return url
|
||||
|
||||
def get_stored_webinars() -> list:
|
||||
"""Get list of stored webinar keys from Redis."""
|
||||
@@ -378,9 +451,9 @@ def get_stored_webinars() -> list:
|
||||
return []
|
||||
|
||||
def store_webinars(webinar_keys: list):
|
||||
"""Store up to 5 most recent webinar keys in Redis."""
|
||||
# Keep only last 5
|
||||
webinar_keys = webinar_keys[-5:]
|
||||
"""Store up to 3 most recent webinar keys in Redis."""
|
||||
# Keep only last 3
|
||||
webinar_keys = webinar_keys[-3:]
|
||||
try:
|
||||
redis_client.set(KEY_WEBINAR_HISTORY, json.dumps(webinar_keys))
|
||||
logger.info(f"Stored {len(webinar_keys)} webinar(s) in history")
|
||||
@@ -515,7 +588,7 @@ async def check_webinars_job(context: ContextTypes.DEFAULT_TYPE):
|
||||
current_keys = []
|
||||
|
||||
for webinar in current_webinars:
|
||||
key = get_webinar_key(webinar['name'], webinar['url'])
|
||||
key = get_webinar_key(webinar['url'])
|
||||
current_keys.append(key)
|
||||
|
||||
if key not in stored_keys:
|
||||
@@ -535,6 +608,7 @@ async def check_webinars_job(context: ContextTypes.DEFAULT_TYPE):
|
||||
for sub_id in subscribers:
|
||||
try:
|
||||
# Build message in user's language
|
||||
# sub_id comes from redis set as string, convert to int for translation lookup
|
||||
webinar_items = "\n\n".join([
|
||||
t(int(sub_id), 'webinar_item', name=w['name'], url=w['url'])
|
||||
for w in new_webinars
|
||||
@@ -569,10 +643,12 @@ def main():
|
||||
|
||||
# Handlers
|
||||
app.add_handler(CommandHandler("start", start))
|
||||
app.add_handler(CommandHandler("stop", stop_command))
|
||||
app.add_handler(CommandHandler("help", help_command))
|
||||
app.add_handler(CommandHandler("language", language_command))
|
||||
app.add_handler(CommandHandler("adduser", add_user))
|
||||
app.add_handler(CommandHandler("removeuser", remove_user))
|
||||
app.add_handler(CommandHandler("clearhistory", clear_history))
|
||||
|
||||
# Callback handlers - language selection first, then admin panel
|
||||
app.add_handler(CallbackQueryHandler(language_callback, pattern="^lang_"))
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
FROM nginx:alpine
|
||||
RUN rm -rf /usr/share/nginx/html/*
|
||||
COPY html /usr/share/nginx/html
|
||||
EXPOSE 80
|
||||
CMD ["nginx", "-g", "daemon off;"]
|
||||
@@ -0,0 +1,20 @@
|
||||
services:
|
||||
errorpage:
|
||||
build: .
|
||||
container_name: error-pages
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - 1234:80
|
||||
networks:
|
||||
- proxy
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.http.services.errorpage.loadbalancer.server.port=80"
|
||||
# Error handler middleware
|
||||
- "traefik.http.middlewares.error-pages.errors.status=400-599"
|
||||
- "traefik.http.middlewares.error-pages.errors.service=errorpage"
|
||||
- "traefik.http.middlewares.error-pages.errors.query=/{status}.html"
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
@@ -0,0 +1,40 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>403 // Forbidden</title>
|
||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||
<link rel="stylesheet" href="style.css">
|
||||
</head>
|
||||
|
||||
<body>
|
||||
|
||||
<div class="container">
|
||||
<header>
|
||||
<h1 class="glitch" data-text="403">403</h1>
|
||||
<p class="subtitle">> Forbidden / Access Denied.</p>
|
||||
</header>
|
||||
|
||||
<hr>
|
||||
|
||||
<section id="message">
|
||||
<h2>./error_message</h2>
|
||||
<p>You do not have permission to access this resource.</p>
|
||||
<br>
|
||||
<p>Check the <a href="https://uptime.forust.xyz/status/forust">System Status</a> if you believe this is an
|
||||
error.</p>
|
||||
</section>
|
||||
|
||||
<footer>
|
||||
<p>root@error:~$ sudo access_resource</p>
|
||||
<p>User is not in the sudoers file. This incident will be reported.</p>
|
||||
<p>© XRock - Just Signal.</p>
|
||||
</footer>
|
||||
</div>
|
||||
|
||||
</body>
|
||||
|
||||
</html>
|
||||
@@ -0,0 +1,39 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>404 // Not Found</title>
|
||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||
<link rel="stylesheet" href="style.css">
|
||||
</head>
|
||||
|
||||
<body>
|
||||
|
||||
<div class="container">
|
||||
<header>
|
||||
<h1 class="glitch" data-text="404">404</h1>
|
||||
<p class="subtitle">> Page Not Found / Lost in the Void.</p>
|
||||
</header>
|
||||
|
||||
<hr>
|
||||
|
||||
<section id="message">
|
||||
<h2>./error_message</h2>
|
||||
<p>The page you are looking for does not exist or has been moved.</p>
|
||||
<br>
|
||||
<p>Check the <a href="https://uptime.forust.xyz/status/forust">System Status</a> if you believe this is an error.</p>
|
||||
</section>
|
||||
|
||||
<footer>
|
||||
<p>root@error:~$ ping target</p>
|
||||
<p>Destination Host Unreachable</p>
|
||||
<p>© XRock - Just Signal.</p>
|
||||
</footer>
|
||||
</div>
|
||||
|
||||
</body>
|
||||
|
||||
</html>
|
||||
@@ -0,0 +1,39 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>500 // Server Error</title>
|
||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||
<link rel="stylesheet" href="style.css">
|
||||
</head>
|
||||
|
||||
<body>
|
||||
|
||||
<div class="container">
|
||||
<header>
|
||||
<h1 class="glitch" data-text="500">500</h1>
|
||||
<p class="subtitle">> Internal Server Error / System Failure.</p>
|
||||
</header>
|
||||
|
||||
<hr>
|
||||
|
||||
<section id="message">
|
||||
<h2>./error_message</h2>
|
||||
<p>Something went wrong on our end. We are working to fix it.</p>
|
||||
<br>
|
||||
<p>Check the <a href="https://uptime.forust.xyz/status/forust">System Status</a> for more information.</p>
|
||||
</section>
|
||||
|
||||
<footer>
|
||||
<p>root@error:~$ systemctl status service</p>
|
||||
<p>Active: failed (Result: core-dump)</p>
|
||||
<p>© XRock - Just Signal.</p>
|
||||
</footer>
|
||||
</div>
|
||||
|
||||
</body>
|
||||
|
||||
</html>
|
||||
@@ -0,0 +1,39 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>502 // Bad Gateway</title>
|
||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||
<link rel="stylesheet" href="style.css">
|
||||
</head>
|
||||
|
||||
<body>
|
||||
|
||||
<div class="container">
|
||||
<header>
|
||||
<h1 class="glitch" data-text="502">502</h1>
|
||||
<p class="subtitle">> Bad Gateway / System Failure.</p>
|
||||
</header>
|
||||
|
||||
<hr>
|
||||
|
||||
<section id="message">
|
||||
<h2>./error_message</h2>
|
||||
<p>The server received an invalid response from the upstream server.</p>
|
||||
<br>
|
||||
<p>Check the <a href="https://uptime.forust.xyz/status/forust">System Status</a> for more information.</p>
|
||||
</section>
|
||||
|
||||
<footer>
|
||||
<p>root@error:~$ curl -I upstream_host</p>
|
||||
<p>HTTP/1.1 502 Bad Gateway</p>
|
||||
<p>© XRock - Just Signal.</p>
|
||||
</footer>
|
||||
</div>
|
||||
|
||||
</body>
|
||||
|
||||
</html>
|
||||
@@ -0,0 +1,39 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>503 // Service Unavailable</title>
|
||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||
<link rel="stylesheet" href="style.css">
|
||||
</head>
|
||||
|
||||
<body>
|
||||
|
||||
<div class="container">
|
||||
<header>
|
||||
<h1 class="glitch" data-text="503">503</h1>
|
||||
<p class="subtitle">> Service Unavailable / System Failure.</p>
|
||||
</header>
|
||||
|
||||
<hr>
|
||||
|
||||
<section id="message">
|
||||
<h2>./error_message</h2>
|
||||
<p>The server is currently unable to handle the request due to maintenance or overload.</p>
|
||||
<br>
|
||||
<p>Check the <a href="https://uptime.forust.xyz/status/forust">System Status</a> for more information.</p>
|
||||
</section>
|
||||
|
||||
<footer>
|
||||
<p>root@error:~$ systemctl start service</p>
|
||||
<p>Job for service failed because the control process exited with error code.</p>
|
||||
<p>© XRock - Just Signal.</p>
|
||||
</footer>
|
||||
</div>
|
||||
|
||||
</body>
|
||||
|
||||
</html>
|
||||
@@ -0,0 +1,39 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>504 // Gateway Timeout</title>
|
||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||
<link rel="stylesheet" href="style.css">
|
||||
</head>
|
||||
|
||||
<body>
|
||||
|
||||
<div class="container">
|
||||
<header>
|
||||
<h1 class="glitch" data-text="504">504</h1>
|
||||
<p class="subtitle">> Gateway Timeout / System Failure.</p>
|
||||
</header>
|
||||
|
||||
<hr>
|
||||
|
||||
<section id="message">
|
||||
<h2>./error_message</h2>
|
||||
<p>The server did not receive a timely response from the upstream server.</p>
|
||||
<br>
|
||||
<p>Check the <a href="https://uptime.forust.xyz/status/forust">System Status</a> for more information.</p>
|
||||
</section>
|
||||
|
||||
<footer>
|
||||
<p>root@error:~$ timeout 30s curl upstream</p>
|
||||
<p>curl: (28) Operation timed out after 30001 milliseconds with 0 bytes received</p>
|
||||
<p>© XRock - Just Signal.</p>
|
||||
</footer>
|
||||
</div>
|
||||
|
||||
</body>
|
||||
|
||||
</html>
|
||||
@@ -0,0 +1,167 @@
|
||||
/* hidden in a plain sight? */
|
||||
:root {
|
||||
--bg-color: #050505;
|
||||
--text-color: #e0e0e0;
|
||||
--accent: #ffffff;
|
||||
--dim: #666666;
|
||||
--font-mono: 'Courier New', Courier, monospace;
|
||||
}
|
||||
|
||||
* {
|
||||
box-sizing: border-box;
|
||||
margin: 0;
|
||||
padding: 0;
|
||||
}
|
||||
|
||||
body {
|
||||
background-color: var(--bg-color);
|
||||
color: var(--text-color);
|
||||
font-family: var(--font-mono);
|
||||
line-height: 1.6;
|
||||
font-size: 16px;
|
||||
padding: 2rem;
|
||||
}
|
||||
|
||||
a {
|
||||
color: var(--text-color);
|
||||
text-decoration: none;
|
||||
border-bottom: 1px solid var(--dim);
|
||||
transition: all 0.2s;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
background-color: var(--text-color);
|
||||
color: var(--bg-color);
|
||||
border-color: var(--text-color);
|
||||
}
|
||||
|
||||
.container {
|
||||
max-width: 800px;
|
||||
margin: 0 auto;
|
||||
}
|
||||
|
||||
/* TEXT */
|
||||
h1 {
|
||||
font-size: 2.5rem;
|
||||
text-transform: uppercase;
|
||||
letter-spacing: -2px;
|
||||
margin-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
h2 {
|
||||
font-size: 1.2rem;
|
||||
margin-bottom: 1.5rem;
|
||||
border-bottom: 1px solid var(--dim);
|
||||
display: inline-block;
|
||||
padding-right: 20px;
|
||||
}
|
||||
|
||||
.subtitle {
|
||||
color: var(--dim);
|
||||
margin-bottom: 2rem;
|
||||
}
|
||||
|
||||
hr {
|
||||
border: 0;
|
||||
border-top: 1px dashed var(--dim);
|
||||
margin: 2rem 0;
|
||||
}
|
||||
|
||||
.comment {
|
||||
color: var(--dim);
|
||||
font-size: 0.9rem;
|
||||
margin-left: 10px;
|
||||
}
|
||||
|
||||
/* SECTIONS */
|
||||
section {
|
||||
margin-bottom: 3rem;
|
||||
}
|
||||
|
||||
/* LISTS */
|
||||
ul {
|
||||
list-style: none;
|
||||
}
|
||||
|
||||
.link-list li {
|
||||
margin-bottom: 0.8rem;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 15px;
|
||||
}
|
||||
|
||||
/* STACK GRID */
|
||||
.grid-2 {
|
||||
display: grid;
|
||||
grid-template-columns: 1fr 1fr;
|
||||
gap: 2rem;
|
||||
}
|
||||
|
||||
.skill-item {
|
||||
display: flex;
|
||||
justify-content: space-between;
|
||||
margin-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
.level {
|
||||
font-weight: bold;
|
||||
}
|
||||
|
||||
.special .level {
|
||||
color: var(--text-color);
|
||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
||||
}
|
||||
|
||||
/* my dudes */
|
||||
.team-grid {
|
||||
display: flex;
|
||||
gap: 2rem;
|
||||
flex-wrap: wrap;
|
||||
margin-top: 1rem;
|
||||
}
|
||||
|
||||
.member {
|
||||
text-align: center;
|
||||
width: 100px;
|
||||
}
|
||||
|
||||
.avatar {
|
||||
width: 80px;
|
||||
height: 80px;
|
||||
background-color: #222;
|
||||
border: 2px solid var(--text-color);
|
||||
margin: 0 auto 10px auto;
|
||||
background-size: cover;
|
||||
}
|
||||
|
||||
/* if no avatar added: */
|
||||
.placeholder::before {
|
||||
content: "?";
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
height: 100%;
|
||||
font-size: 2rem;
|
||||
color: var(--dim);
|
||||
}
|
||||
|
||||
/* REPOS */
|
||||
.repo-list li {
|
||||
margin-bottom: 1rem;
|
||||
}
|
||||
|
||||
/* FOOTER */
|
||||
footer {
|
||||
text-align: center;
|
||||
color: var(--dim);
|
||||
font-size: 0.8rem;
|
||||
/* flag{why-are-you-here?} */
|
||||
margin-top: 4rem;
|
||||
}
|
||||
/* SMTH RESPONSIVE */
|
||||
@media (max-width: 600px) {
|
||||
.grid-2 {
|
||||
grid-template-columns: 1fr;
|
||||
gap: 0;
|
||||
}
|
||||
}
|
||||
+3
-1
@@ -1,4 +1,6 @@
|
||||
GITEA_POSTGRES_USER=
|
||||
GITEA_POSTGRES_PASSWORD=
|
||||
GITEA_POSTGRES_DB=gitea
|
||||
BASIC-RUNNER_TOKEN=
|
||||
GITEA_SMTP_PASS=
|
||||
MAILER_ADDR=
|
||||
SERVICE_EMAIL=email.used.by.services@domain.tld
|
||||
+21
-37
@@ -2,6 +2,7 @@ services:
|
||||
server:
|
||||
image: docker.gitea.com/gitea:1.25.1
|
||||
container_name: gitea
|
||||
restart: always
|
||||
environment:
|
||||
- USER_UID=1000
|
||||
- USER_GID=1000
|
||||
@@ -15,66 +16,50 @@ services:
|
||||
- GITEA__server__ROOT_URL=https://gitea.forust.xyz
|
||||
- GITEA__server__SSH_DOMAIN=gitssh.forust.xyz
|
||||
- GITEA__server__SSH_PORT=2221
|
||||
restart: always
|
||||
networks:
|
||||
- gitea-db
|
||||
- traefik-proxy
|
||||
# Mailer
|
||||
- GITEA__mailer__ENABLED=true
|
||||
- GITEA__mailer__FROM=${SERVICE_EMAIL}
|
||||
- GITEA__mailer__SMTP_ADDR=${MAILER_ADDR}:465
|
||||
- GITEA__mailer__USER=${SERVICE_EMAIL}
|
||||
- GITEA__mailer__PASSWD=${GITEA_SMTP_PASS}
|
||||
- GITEA__mailer__PROTOCOL=SMTP
|
||||
- GITEA__service__REGISTER_EMAIL_CONFIRM=true
|
||||
- GITEA__service__ENABLE_NOTIFY_MAIL=true
|
||||
volumes:
|
||||
- ./gitea-data:/data
|
||||
- /etc/timezone:/etc/timezone:ro
|
||||
- /etc/localtime:/etc/localtime:ro
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.http.services.gitea.loadbalancer.server.port=3000"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)"
|
||||
- "traefik.http.routers.gitea.entrypoints=websecure"
|
||||
- "traefik.http.routers.gitea.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.gitea.service=gitea"
|
||||
- "traefik.http.routers.gitea.tls=true"
|
||||
- "traefik.http.services.gitea.loadbalancer.server.port=3000"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.gitea-local.rule=Host(`gitea.workstation.internal`) || Host(`gitea.internal`)"
|
||||
- "traefik.http.routers.gitea-local.rule=Host(`gitea.workstation.internal`)"
|
||||
- "traefik.http.routers.gitea-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.gitea-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.gitea-local.service=gitea"
|
||||
- "traefik.http.routers.gitea-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.gitea-dev.rule=Host(`gitea.gigaforust.internal`)"
|
||||
- "traefik.http.routers.gitea-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.gitea-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.gitea-dev.service=gitea"
|
||||
- "traefik.http.routers.gitea-dev.tls=true"
|
||||
# SSH Router
|
||||
- "traefik.tcp.services.gitea.loadbalancer.server.port=22"
|
||||
- "traefik.tcp.routers.gitea.entrypoints=ssh"
|
||||
- "traefik.tcp.routers.gitea.rule=HostSNI(`*`)"
|
||||
- "traefik.tcp.services.gitea.loadbalancer.server.port=22"
|
||||
ports:
|
||||
- "2221:22"
|
||||
depends_on:
|
||||
- db
|
||||
|
||||
runner:
|
||||
image: gitea/act_runner:0.2.11
|
||||
container_name: gitea-runner
|
||||
restart: always
|
||||
depends_on:
|
||||
- server
|
||||
env_file:
|
||||
- .env
|
||||
networks:
|
||||
- gitea-db
|
||||
environment:
|
||||
- GITEA_INSTANCE_URL=http://server:3000
|
||||
- GITEA_RUNNER_REGISTRATION_TOKEN=${BASIC-RUNNER_TOKEN}
|
||||
- GITEA_RUNNER_NAME=basic-runner
|
||||
- GITEA_RUNNER_LABELS=docker:docker://node:20-bookworm,ubuntu-latest:docker://node:20-bookworm
|
||||
volumes:
|
||||
- ./gitea-runner:/data
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
|
||||
- proxy
|
||||
depends_on:
|
||||
- db
|
||||
db:
|
||||
image: docker.io/library/postgres:14
|
||||
restart: always
|
||||
@@ -82,13 +67,12 @@ services:
|
||||
- POSTGRES_USER=gitea
|
||||
- POSTGRES_PASSWORD=gitea
|
||||
- POSTGRES_DB=gitea
|
||||
networks:
|
||||
- gitea-db
|
||||
volumes:
|
||||
- ./gitea-db/:/var/lib/postgresql/data
|
||||
|
||||
networks:
|
||||
- gitea-db
|
||||
networks:
|
||||
gitea-db:
|
||||
external: false
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
+7
-11
@@ -11,30 +11,26 @@ services:
|
||||
env_file: .env
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.docker.network=proxy"
|
||||
# FIXME: traefik.services.glance.loadbalancer.server.port ??
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.glance.rule=Host(`glance.forust.xyz`)"
|
||||
- "traefik.http.routers.glance.entrypoints=websecure"
|
||||
- "traefik.http.routers.glance.middlewares=security-chain@file"
|
||||
- "traefik.http.routers.glance.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.glance.tls=true"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.glance-local.rule=Host(`glance.workstation.internal`) || Host(`glance.internal`)"
|
||||
- "traefik.http.routers.glance-local.rule=Host(`glance.workstation.internal`)"
|
||||
- "traefik.http.routers.glance-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.glance-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.glance-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.glance-dev.rule=Host(`glance.gigaforust.internal`)"
|
||||
- "traefik.http.routers.glance-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.glance-dev.middlewares=security-chain@file"
|
||||
- "traefik.http.routers.glance-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.glance-dev.tls=true"
|
||||
networks:
|
||||
- traefik-proxy
|
||||
dns:
|
||||
- 1.1.1.1
|
||||
- 8.8.8.8
|
||||
- proxy
|
||||
networks:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
@@ -0,0 +1,77 @@
|
||||
services:
|
||||
headscale:
|
||||
image: headscale/headscale:latest
|
||||
restart: unless-stopped
|
||||
container_name: headscale-server
|
||||
command: serve
|
||||
networks:
|
||||
- proxy
|
||||
volumes:
|
||||
- ./config/headscale.yaml:/etc/headscale/config.yaml
|
||||
- data:/var/lib/headscale
|
||||
labels:
|
||||
- "me.tale.headplane.target: headscale"
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.http.services.headscale.loadbalancer.server.port=8080"
|
||||
- "traefik.http.services.headscale-metrics.loadbalancer.server.port=9090"
|
||||
|
||||
## SERVICE
|
||||
# Prod Router
|
||||
- "traefik.http.routers.headscale.rule=Host(`hs.forust.xyz`)"
|
||||
- "traefik.http.routers.headscale.entrypoints=websecure"
|
||||
- "traefik.http.routers.headscale.service=headscale"
|
||||
- "traefik.http.routers.headscale.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.headscale-local.rule=Host(`hs.workstation.internal`)"
|
||||
- "traefik.http.routers.headscale-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.headscale-local.service=headscale"
|
||||
- "traefik.http.routers.headscale-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.headscale-dev.rule=Host(`hs.gigaforust.internal`)"
|
||||
- "traefik.http.routers.headscale-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.headscale-dev.service=headscale"
|
||||
- "traefik.http.routers.headscale-dev.tls=true"
|
||||
|
||||
## METRICS
|
||||
# Prod Router
|
||||
- "traefik.http.routers.headscale-metrics.rule=Host(`hs.forust.xyz`) && PathPrefix(`/metrics`)"
|
||||
- "traefik.http.routers.headscale-metrics.entrypoints=websecure"
|
||||
- "traefik.http.routers.headscale-metrics.service=headscale-metrics"
|
||||
- "traefik.http.routers.headscale-metrics.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.headscale-metrics-local.rule=Host(`hs.workstation.internal`) && PathPrefix(`/metrics`)"
|
||||
- "traefik.http.routers.headscale-metrics-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.headscale-metrics-local.service=headscale-metrics"
|
||||
- "traefik.http.routers.headscale-metrics-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.headscale-metrics-dev.rule=Host(`hs.gigaforust.internal`) && PathPrefix(`/metrics`)"
|
||||
- "traefik.http.routers.headscale-metrics-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.headscale-metrics-dev.service=headscale-metrics"
|
||||
- "traefik.http.routers.headscale-metrics-dev.tls=true"
|
||||
headplane:
|
||||
image: ghcr.io/tale/headplane:latest
|
||||
container_name: headplane
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- '3000:3000'
|
||||
volumes:
|
||||
- ./config/headplane.yaml:/etc/headplane/config.yaml
|
||||
- ./config/headscale.yaml:/etc/headscale/config.yaml
|
||||
- headplane-data:/var/lib/headplane
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||
networks:
|
||||
- proxy
|
||||
healthcheck:
|
||||
test: [ "CMD", "/bin/hp_healthcheck" ]
|
||||
interval: 30s
|
||||
timeout: 5s
|
||||
start_period: 5s
|
||||
retries: 3
|
||||
volumes:
|
||||
data:
|
||||
headplane-data:
|
||||
name: headplane_data
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
@@ -0,0 +1,221 @@
|
||||
# Configuration for the Headplane server and web application
|
||||
server:
|
||||
# These are the default values, change them as needed
|
||||
host: "0.0.0.0"
|
||||
port: 3000
|
||||
# Should not include the dashboard prefix (/admin) portion.
|
||||
# # Prod server_url
|
||||
# base_url: https://hs.forust.xyz
|
||||
# # Local base_url
|
||||
# base_url: https://hs.workstation.internal
|
||||
# # Dev base_url
|
||||
# base_url: https://hs.gigaforust.internal
|
||||
|
||||
# You may provide `cookie_secret_path` instead to read a value from disk.
|
||||
# See https://headplane.net/configuration/#sensitive-values
|
||||
cookie_secret: "<change_me_to_something_secure!>"
|
||||
|
||||
# Whether cookies should be marked as Secure
|
||||
# * Should be false if running without HTTPs
|
||||
# * Should be true if running behind a reverse proxy with HTTPs
|
||||
cookie_secure: true
|
||||
# The maximum age of the session cookie in seconds
|
||||
cookie_max_age: 86400 # 1 day in seconds
|
||||
|
||||
# This is not required, but if you want to restrict the cookie
|
||||
# to a specific domain, set it here. Otherwise leave it commented out.
|
||||
# This may not work as expected if not using a reverse proxy.
|
||||
# cookie_domain: ""
|
||||
|
||||
# The path to persist Headplane specific data. All data going forward
|
||||
# is stored in this directory, including the internal database and
|
||||
# any cache related files.
|
||||
data_path: "/var/lib/headplane"
|
||||
|
||||
# The info secret is optional and allows access to certain debug endpoints
|
||||
# that may expose sensitive information about your Headplane instance.
|
||||
#
|
||||
# As of now, this protects the /api/info endpoint which exposes details about
|
||||
# the Headplane and Headscale versions in use. In the future, more endpoints
|
||||
# may be protected by this secret.
|
||||
#
|
||||
# If not set, these endpoints will be disabled.
|
||||
# info_secret: "<change_me_to_something_secure!>"
|
||||
|
||||
# Headscale specific settings to allow Headplane to talk
|
||||
# to Headscale and access deep integration features
|
||||
headscale:
|
||||
# The URL to your Headscale instance
|
||||
# (All API requests are routed through this URL)
|
||||
# (THIS IS NOT the gRPC endpoint, but the HTTP endpoint)
|
||||
#
|
||||
# IMPORTANT: If you are using TLS this MUST be set to `https://`
|
||||
url: "http://headscale-server:8080"
|
||||
|
||||
# If you use the TLS configuration in Headscale, and you are not using
|
||||
# Let's Encrypt for your certificate, pass in the path to the certificate.
|
||||
# (This has no effect if `url` does not start with `https://`)
|
||||
# tls_cert_path: "/var/lib/headplane/tls.crt"
|
||||
|
||||
# Optional, public URL if its different from the `headscale.url`
|
||||
# This affects certain parts of the web UI which shows Headscale's URL
|
||||
public_url: "https://headscale.example.com"
|
||||
|
||||
# Path to the Headscale configuration file
|
||||
# This is optional, but HIGHLY recommended for the best experience
|
||||
# If this is read only, Headplane will show your configuration settings
|
||||
# in the Web UI, but they cannot be changed.
|
||||
config_path: "/etc/headscale/config.yaml"
|
||||
|
||||
# Whether the Headscale configuration should be strictly validated
|
||||
# when reading from `config_path`. If true, Headplane will not interact
|
||||
# with Headscale if there are any issues with the configuration file.
|
||||
#
|
||||
# This is recommended to be true for production deployments to, however it
|
||||
# may not work if you are using a version of Headscale that has configuration
|
||||
# options unknown to Headplane.
|
||||
config_strict: true
|
||||
|
||||
# If you are using `dns.extra_records_path` in your Headscale
|
||||
# configuration, you need to set this to the path for Headplane
|
||||
# to be able to read the DNS records.
|
||||
#
|
||||
# Pass it in if using Docker and ensure that the file is both
|
||||
# readable and writable to the Headplane process.
|
||||
# When using this, Headplane will no longer need to automatically
|
||||
# restart Headscale for DNS record changes.
|
||||
# dns_records_path: "/var/lib/headscale/extra_records.json"
|
||||
|
||||
# Integration configurations for Headplane to interact with Headscale
|
||||
integration:
|
||||
# The Headplane agent allows retrieving information about nodes
|
||||
# This allows the UI to display version, OS, and connectivity data
|
||||
# You will see the Headplane agent in your Tailnet as a node when
|
||||
# it connects.
|
||||
agent:
|
||||
enabled: false
|
||||
|
||||
# To connect to your Tailnet, you need to generate a pre-auth key
|
||||
# This can be done via the web UI or through the `headscale` CLI.
|
||||
pre_authkey: "<your-preauth-key>"
|
||||
|
||||
# Optionally change the name of the agent in the Tailnet.
|
||||
# host_name: "headplane-agent"
|
||||
|
||||
# Configure different caching settings. By default, the agent will store
|
||||
# caches in the path below for a maximum of 1 minute. If you want data
|
||||
# to update faster, reduce the TTL, but this will increase the frequency
|
||||
# of requests to Headscale.
|
||||
# cache_ttl: 60
|
||||
# cache_path: /var/lib/headplane/agent_cache.json
|
||||
|
||||
# The work_dir represents where the agent will store its data to be able
|
||||
# to automatically reauthenticate with your Tailnet. It needs to be
|
||||
# writable by the user running the Headplane process.
|
||||
#
|
||||
# If using Docker, it is best to leave this as the default.
|
||||
# work_dir: "/var/lib/headplane/agent"
|
||||
|
||||
# Only one of these should be enabled at a time or you will get errors
|
||||
# This does not include the agent integration (above), which can be enabled
|
||||
# at the same time as any of these and is recommended for the best experience.
|
||||
docker:
|
||||
enabled: true
|
||||
|
||||
# By default we check for the presence of a container label (see the docs)
|
||||
# to determine the container to signal when changes are made to DNS settings.
|
||||
container_label: "me.tale.headplane.target=headscale"
|
||||
|
||||
# HOWEVER, you can fallback to a container name if you desire, but this is
|
||||
# not recommended as its brittle and doesn't work with orchestrators that
|
||||
# automatically assign container names.
|
||||
#
|
||||
# If `container_name` is set, it will override any label checks.
|
||||
# container_name: "headscale-server"
|
||||
|
||||
# The path to the Docker socket (do not change this if you are unsure)
|
||||
# Docker socket paths must start with unix:// or tcp:// and at the moment
|
||||
# https connections are not supported.
|
||||
socket: "unix:///var/run/docker.sock"
|
||||
|
||||
# Please refer to docs/integration/Kubernetes.md for more information
|
||||
# on how to configure the Kubernetes integration. There are requirements in
|
||||
# order to allow Headscale to be controlled by Headplane in a cluster.
|
||||
kubernetes:
|
||||
enabled: false
|
||||
# Validates the manifest for the Pod to ensure all of the criteria
|
||||
# are set correctly. Turn this off if you are having issues with
|
||||
# shareProcessNamespace not being validated correctly.
|
||||
validate_manifest: true
|
||||
# This should be the name of the Pod running Headscale and Headplane.
|
||||
# If this isn't static you should be using the Kubernetes Downward API
|
||||
# to set this value (refer to docs/Integrated-Mode.md for more info).
|
||||
pod_name: "headscale"
|
||||
|
||||
# Proc is the "Native" integration that only works when Headscale and
|
||||
# Headplane are running outside of a container. There is no configuration,
|
||||
# but you need to ensure that the Headplane process can terminate the
|
||||
# Headscale process.
|
||||
#
|
||||
# (If they are both running under systemd as sudo, this will work).
|
||||
proc:
|
||||
enabled: false
|
||||
|
||||
# OIDC Configuration for simpler authentication
|
||||
# (This is optional, but recommended for the best experience)
|
||||
# oidc:
|
||||
# The OIDC issuer URL
|
||||
# issuer: "https://accounts.google.com"
|
||||
|
||||
# If you are using OIDC, you need to generate an API key
|
||||
# that can be used to authenticate other sessions when signing in.
|
||||
#
|
||||
# This can be done with `headscale apikeys create --expiration 999d`
|
||||
# headscale_api_key: "<your-headscale-api-key>"
|
||||
|
||||
# If your OIDC provider does not support discovery (does not have the URL at
|
||||
# `/.well-known/openid-configuration`), you need to manually set endpoints.
|
||||
# This also works to override endpoints if you so desire or if your OIDC
|
||||
# discovery is missing certain endpoints (ie GitHub).
|
||||
# For some typical providers, see https://headplane.net/features/sso.
|
||||
# authorization_endpoint: ""
|
||||
# token_endpoint: ""
|
||||
# userinfo_endpoint: ""
|
||||
|
||||
# The authentication method to use when communicating with the token endpoint.
|
||||
# This is fully optional and Headplane will attempt to auto-detect the best
|
||||
# method and fall back to `client_secret_basic` if unsure.
|
||||
# token_endpoint_auth_method: "client_secret_post"
|
||||
|
||||
# The client ID for the OIDC client
|
||||
# For the best experience please ensure this is *identical* to the client_id
|
||||
# you are using for Headscale. because
|
||||
# client_id: "your-client-id"
|
||||
|
||||
# The client secret for the OIDC client
|
||||
# You may also provide `client_secret_path` instead to read a value from disk.
|
||||
# See https://headplane.net/configuration/#sensitive-values
|
||||
# client_secret: "<your-client-secret>"
|
||||
|
||||
# Whether to use PKCE when authenticating users. This is recommended as it
|
||||
# adds an extra layer of security to the authentication process. Enabling this
|
||||
# means your OIDC provider must support PKCE and it must be enabled on the
|
||||
# client.
|
||||
# use_pkce: true
|
||||
|
||||
# If you want to disable traditional login via Headscale API keys
|
||||
# disable_api_key_login: false
|
||||
|
||||
# By default profile pictures are pulled from the OIDC provider when
|
||||
# we go to fetch the userinfo endpoint. Optionally, this can be set to
|
||||
# "oidc" or "gravatar" as of 0.6.1.
|
||||
# profile_picture_source: "gravatar"
|
||||
|
||||
# The scopes to request when authenticating users. The default is below.
|
||||
# scope: "openid email profile"
|
||||
|
||||
# Extra query parameters can be passed to the authorization endpoint
|
||||
# by setting them here. This is useful for providers that require any kind
|
||||
# of custom hinting.
|
||||
# extra_params:
|
||||
# prompt: "select_account" # Example: force account selection on Google
|
||||
@@ -0,0 +1,79 @@
|
||||
# https://wiki.serversatho.me/en/headscale
|
||||
|
||||
# # Prod server_url
|
||||
# server_url: https://hs.example.com
|
||||
# # Local server_url
|
||||
# server_url: https://hs.internal_domain.internal
|
||||
# # Dev server_url
|
||||
# server_url: https://hs.dev_internal_domain.internal
|
||||
listen_addr: 0.0.0.0:8080
|
||||
metrics_listen_addr: 127.0.0.1:9090
|
||||
grpc_listen_addr: 127.0.0.1:50443
|
||||
grpc_allow_insecure: false
|
||||
noise:
|
||||
private_key_path: /var/lib/headscale/noise_private.key
|
||||
prefixes:
|
||||
v4: 100.64.0.0/10
|
||||
v6: fd7a:115c:a1e0::/48
|
||||
allocation: sequential
|
||||
derp:
|
||||
server:
|
||||
enabled: true
|
||||
region_id: 999
|
||||
region_code: "headscale"
|
||||
region_name: "Headscale Embedded DERP"
|
||||
stun_listen_addr: "0.0.0.0:3478"
|
||||
private_key_path: /var/lib/headscale/derp_server_private.key
|
||||
automatically_add_embedded_derp_region: true
|
||||
ipv4: 1.2.3.4
|
||||
ipv6: 2001:db8::1
|
||||
urls:
|
||||
- https://controlplane.tailscale.com/derpmap/default
|
||||
paths: []
|
||||
auto_update_enabled: true
|
||||
update_frequency: 24h
|
||||
disable_check_updates: false
|
||||
ephemeral_node_inactivity_timeout: 30m
|
||||
database:
|
||||
type: sqlite
|
||||
debug: false
|
||||
gorm:
|
||||
prepare_stmt: true
|
||||
parameterized_queries: true
|
||||
skip_err_record_not_found: true
|
||||
slow_threshold: 1000
|
||||
sqlite:
|
||||
path: /var/lib/headscale/db.sqlite
|
||||
write_ahead_log: true
|
||||
wal_autocheckpoint: 1000
|
||||
acme_url: https://acme-v02.api.letsencrypt.org/directory
|
||||
acme_email: ""
|
||||
tls_letsencrypt_hostname: ""
|
||||
tls_letsencrypt_cache_dir: /var/lib/headscale/cache
|
||||
tls_letsencrypt_challenge_type: HTTP-01
|
||||
tls_letsencrypt_listen: ":http"
|
||||
tls_cert_path: ""
|
||||
tls_key_path: ""
|
||||
log:
|
||||
format: text
|
||||
level: info
|
||||
policy:
|
||||
mode: database
|
||||
path: ""
|
||||
dns:
|
||||
magic_dns: true
|
||||
base_domain: example.com
|
||||
nameservers:
|
||||
global:
|
||||
- 1.1.1.1
|
||||
- 1.0.0.1
|
||||
- 2606:4700:4700::1111
|
||||
- 2606:4700:4700::1001
|
||||
split: {}
|
||||
search_domains: []
|
||||
extra_records: []
|
||||
unix_socket: /var/run/headscale/headscale.sock
|
||||
unix_socket_permission: "0770"
|
||||
logtail:
|
||||
enabled: false
|
||||
randomize_client_port: false
|
||||
+12
-29
@@ -3,81 +3,64 @@ services:
|
||||
build:
|
||||
context: .
|
||||
dockerfile: Dockerfile.forust
|
||||
ports:
|
||||
- "8085:80"
|
||||
# ports:
|
||||
# - "8085:80"
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- ./forust_files:/usr/share/nginx/html
|
||||
networks:
|
||||
- traefik-proxy
|
||||
- proxy
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
|
||||
# Services
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.http.services.forust-homepage.loadbalancer.server.port=80"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.forust-homepage.rule=Host(`forust.xyz`)"
|
||||
- "traefik.http.routers.forust-homepage.entrypoints=websecure"
|
||||
- "traefik.http.routers.forust-homepage.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.forust-homepage.service=forust-homepage"
|
||||
- "traefik.http.routers.forust-homepage.tls=true"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.forust-homepage-local.rule=Host(`landing.workstation.internal`) || Host(`landing.internal`)"
|
||||
- "traefik.http.routers.forust-homepage-local.rule=Host(`landing.workstation.internal`)"
|
||||
- "traefik.http.routers.forust-homepage-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.forust-homepage-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.forust-homepage-local.service=forust-homepage"
|
||||
- "traefik.http.routers.forust-homepage-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.forust-homepage-dev.rule=Host(`landing.gigaforust.internal`)"
|
||||
- "traefik.http.routers.forust-homepage-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.forust-homepage-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.forust-homepage-dev.service=forust-homepage"
|
||||
- "traefik.http.routers.forust-homepage-dev.tls=true"
|
||||
|
||||
xdfnx:
|
||||
build:
|
||||
context: .
|
||||
dockerfile: Dockerfile.xdfnx
|
||||
ports:
|
||||
- "8086:80"
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - "8086:80"
|
||||
volumes:
|
||||
- ./xdfnx_files:/usr/share/nginx/html
|
||||
networks:
|
||||
- traefik-proxy
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
|
||||
# Services
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.http.services.xdfnx-homepage.loadbalancer.server.port=80"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.xdfnx.rule=Host(`xdfnx.cfd`)"
|
||||
- "traefik.http.routers.xdfnx.entrypoints=websecure"
|
||||
- "traefik.http.routers.xdfnx.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.xdfnx.service=xdfnx-homepage"
|
||||
- "traefik.http.routers.xdfnx.tls=true"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.xdfnx-local.rule=Host(`xdfnx.workstation.internal`) || Host(`xdfnx.internal`)"
|
||||
- "traefik.http.routers.xdfnx-local.rule=Host(`xdfnx.workstation.internal`)"
|
||||
- "traefik.http.routers.xdfnx-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.xdfnx-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.xdfnx-local.service=xdfnx-homepage"
|
||||
- "traefik.http.routers.xdfnx-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.xdfnx-dev.rule=Host(`xdfnx.gigaforust.internal`)"
|
||||
- "traefik.http.routers.xdfnx-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.xdfnx-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.xdfnx-dev.service=xdfnx-homepage"
|
||||
- "traefik.http.routers.xdfnx-dev.tls=true"
|
||||
|
||||
|
||||
networks:
|
||||
traefik-proxy:
|
||||
- proxy
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
@@ -41,7 +41,14 @@
|
||||
</li>
|
||||
<li>
|
||||
<i class="fas fa-envelope"></i>
|
||||
<a href="mailto:forust@forust.xyz">forust@forust.xyz</a>
|
||||
<a href="mailto:forust@forust.xyz">mail/contact@forust.xyz</a>
|
||||
</li>
|
||||
<li>
|
||||
<i class="fa-solid fa-key"></i>
|
||||
<a href=".well-known/pgp-key.asc">security/PGP Key</a>
|
||||
</li>
|
||||
<li>
|
||||
<p class="comment"># PGP Key Fingerprint: A777 7CB7 D9C4 0A97 443D CCF0 7A3D A455 F820 5B82</p>
|
||||
</li>
|
||||
</ul>
|
||||
</section>
|
||||
|
||||
@@ -0,0 +1,54 @@
|
||||
# Resolved: Overlay FS failure (and so containers)
|
||||
|
||||
15-12-2025 03:02 AM EET: Degraded control panels' performances, following by full cascade docker failure
|
||||
|
||||
15-12-2025 04:36 AM EET: Identified: Services are terminated due to server software (Overlay FS) + hardware issues (HDD).
|
||||
|
||||
15-12-2025 08:45 PM EET: Restored NextCloud service with few tweaks to lower I/O
|
||||
|
||||
---
|
||||
|
||||
16-12-2025 08:34 PM EET: Ordered new HDD, ETA 22nd of December - 2nd of January
|
||||
|
||||
---
|
||||
|
||||
17-12-2025 02:47 AM EET: To avoid additional I/O into kuma's database, disabled uptime monitoring for non-critical services, such as:
|
||||
|
||||
- Game servers
|
||||
- Gitea (no public projects being hosted yet)
|
||||
- Landings
|
||||
- Cloud services
|
||||
- PenPot
|
||||
- Auth provider
|
||||
- Secondary management tools
|
||||
- Chernuha's non-important infrastructure
|
||||
|
||||
These can be identified by seeing ">2m ago" under monitor's heartbeats.
|
||||
|
||||
---
|
||||
|
||||
09-01-2026 02:32 PM EET: NextCloud's frontend files are corrupted due to the unknown issue. All user data is integrity-verified. To prevent user data corruption, NextCloud service will be restored after new hardware will be available.
|
||||
|
||||
---
|
||||
|
||||
14-01-2026 08:42 PM EET: After planned updating and restarting server, critical firmware software were corrupted because of physical degradation of the disk. Server inaccessible in any way
|
||||
|
||||
---
|
||||
|
||||
15-01-2026 11:30 AM EET: A new NAS-Grade HDD (Seagate IronWolf Pro) was ordered. ETA 16-01-2026 EET Before 12:00 PM
|
||||
|
||||
---
|
||||
|
||||
16-01-2026 12:47 AM EET: New server system is installed, data backed up. Experiencing docker memory leak.
|
||||
|
||||
---
|
||||
|
||||
17-01-2026 01:27 PM EET: All services except NextCloud and Satisfactory server are online.
|
||||
|
||||
17-01-2026 03:48 PM EET: Nextcloud is online. Satisfactory will be provided on-demand. Monitoring status
|
||||
|
||||
---
|
||||
|
||||
##### Status: All services are online
|
||||
|
||||
**Solution: moving all infrastructure onto new NAS-Grade HDD with fresh OS install**
|
||||
@@ -0,0 +1,3 @@
|
||||
KENER_SECRET_KEY=your_secret_key_here
|
||||
ORIGIN=http://localhost:3000
|
||||
TZ=Etc/UTC
|
||||
@@ -0,0 +1,39 @@
|
||||
services:
|
||||
kener:
|
||||
image: rajnandan1/kener:latest
|
||||
container_name: kener
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - 3000:3000/tcp
|
||||
environment:
|
||||
- KENER_SECRET_KEY=${KENER_SECRET_KEY?Kener requires a secret key}
|
||||
- ORIGIN=${ORIGIN:-http://localhost:3000}
|
||||
- TZ:${TZ:-Etc/UTC}
|
||||
volumes:
|
||||
- db:/app/database
|
||||
- uploads:/app/uploads
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.http.services.kener.loadbalancer.server.port=3000"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.kener.rule=Host(`status.forust.xyz`)"
|
||||
- "traefik.http.routers.kener.entrypoints=websecure"
|
||||
- "traefik.http.routers.kener.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.kener-local.rule=Host(`status.workstation.internal`)"
|
||||
- "traefik.http.routers.kener-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.kener-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.kener-dev.rule=Host(`status.gigaforust.internal`)"
|
||||
- "traefik.http.routers.kener-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.kener-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
volumes:
|
||||
db:
|
||||
uploads:
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
+7
-13
@@ -1,7 +1,7 @@
|
||||
services:
|
||||
metube:
|
||||
image: ghcr.io/alexta69/metube
|
||||
# container_name: metube
|
||||
container_name: metube
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - "8081:8081"
|
||||
@@ -13,33 +13,27 @@ services:
|
||||
volumes:
|
||||
- ./MeTube_downloads:/downloads
|
||||
labels:
|
||||
- traefik.enable=true
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.http.services.metube.loadbalancer.server.port=8081"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.metube.rule=Host(`metube.forust.xyz`)"
|
||||
- "traefik.http.routers.metube.entrypoints=websecure"
|
||||
- "traefik.http.routers.metube.middlewares=security-chain@file"
|
||||
- "traefik.http.routers.metube.service=metube"
|
||||
- "traefik.http.routers.metube.tls=true"
|
||||
- "traefik.http.services.metube.loadbalancer.server.port=8081"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.metube-local.rule=Host(`metube.workstation.internal`) || Host(`metube.internal`)"
|
||||
- "traefik.http.routers.metube-local.rule=Host(`metube.workstation.internal`)"
|
||||
- "traefik.http.routers.metube-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.metube-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.metube-local.service=metube"
|
||||
- "traefik.http.routers.metube-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.metube-dev.rule=Host(`metube.gigaforust.internal`)"
|
||||
- "traefik.http.routers.metube-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.metube-dev.middlewares=security-chain@file"
|
||||
- "traefik.http.routers.metube-dev.service=metube"
|
||||
- "traefik.http.routers.metube-dev.tls=true"
|
||||
|
||||
networks:
|
||||
- traefik-proxy
|
||||
- proxy
|
||||
networks:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
+3
-3
@@ -23,11 +23,11 @@ services:
|
||||
- 1.1.1.1
|
||||
- 8.8.8.8
|
||||
networks:
|
||||
- traefik-proxy
|
||||
- proxy
|
||||
- n8n
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.docker.network=proxy"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.n8n.rule=Host(`n8n.forust.xyz`)"
|
||||
@@ -58,5 +58,5 @@ services:
|
||||
networks:
|
||||
n8n:
|
||||
external: false
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
+10
-17
@@ -9,7 +9,7 @@ services:
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||
networks:
|
||||
- nextcloud-aio
|
||||
- traefik-proxy # Optional: Connects the mastercontainer to the traefik-proxy network in order to make the built-in reverse proxy detection work. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||
- proxy # Optional: Connects the mastercontainer to the proxy network in order to make the built-in reverse proxy detection work. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||
# ports:
|
||||
# - 8081:80 # may be removed if under reverse-proxy
|
||||
# - 8443:8443
|
||||
@@ -17,49 +17,42 @@ services:
|
||||
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
|
||||
- "traefik.docker.network=proxy"
|
||||
# AIO Services configuration
|
||||
- "traefik.http.services.nextcloud-aio.loadbalancer.server.port=8080"
|
||||
- "traefik.http.services.nextcloud-aio.loadbalancer.server.scheme=https"
|
||||
- "traefik.http.services.nextcloud-aio.loadbalancer.serverstransport=insecureTransport@file"
|
||||
|
||||
# Prod Router
|
||||
# - "traefik.http.routers.nextcloud-aio.rule=Host(`nextcloud-aio.forust.xyz`)"
|
||||
# - "traefik.http.routers.nextcloud-aio.rule=Host(`naio.forust.xyz`)"
|
||||
# - "traefik.http.routers.nextcloud-aio.entrypoints=websecure"
|
||||
# - "traefik.http.routers.nextcloud-aio.middlewares=security-headers"
|
||||
# - "traefik.http.routers.nextcloud-aio.middlewares=security-chain@file"
|
||||
# - "traefik.http.routers.nextcloud-aio.service=nextcloud-aio"
|
||||
# - "traefik.http.routers.nextcloud-aio.tls=true"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.nextcloud-aio-local.rule=Host(`nextcloud-aio.workstation.internal`) || Host(`nextcloud-aio.internal`)"
|
||||
- "traefik.http.routers.nextcloud-aio-local.rule=Host(`naio.workstation.internal`)"
|
||||
- "traefik.http.routers.nextcloud-aio-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.nextcloud-aio-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.nextcloud-aio-local.service=nextcloud-aio"
|
||||
- "traefik.http.routers.nextcloud-aio-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.nextcloud-aio-dev.rule=Host(`nextcloud-aio.gigaforust.internal`)"
|
||||
- "traefik.http.routers.nextcloud-aio-dev.rule=Host(`naio.gigaforust.internal`)"
|
||||
- "traefik.http.routers.nextcloud-aio-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.nextcloud-aio-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.nextcloud-aio-dev.service=nextcloud-aio"
|
||||
- "traefik.http.routers.nextcloud-aio-dev.tls=true"
|
||||
|
||||
# Glanceapp/glance config
|
||||
# Glance Metadata
|
||||
- glance.name=Nextcloud
|
||||
# - glance.icon=si:nextcloud
|
||||
- glance.url=https://nextcloud.forust.xyz/
|
||||
- glance.description=Nextcloud is a suite of client-server software for creating and using file hosting services.
|
||||
|
||||
environment:
|
||||
AIO_DISABLE_BACKUP_SECTION: false
|
||||
APACHE_PORT: 11000 # Is needed when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else). See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||
APACHE_IP_BINDING: 0.0.0.0 # Configure when going with reverse-proxy https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||
APACHE_ADDITIONAL_NETWORK: traefik-proxy # (Optional) Connect the apache container to an additional docker network. When going with reverse-proxy. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||
APACHE_ADDITIONAL_NETWORK: proxy # (Optional) Connect the apache container to an additional docker network. When going with reverse-proxy. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||
BORG_RETENTION_POLICY: --keep-within=7d --keep-weekly=4 --keep-monthly=6 # Backup retention See https://github.com/nextcloud/all-in-one#how-to-adjust-borgs-retention-policy
|
||||
COLLABORA_SECCOMP_DISABLED: false # Setting this to true allows to disable Collabora's Seccomp feature. See https://github.com/nextcloud/all-in-one#how-to-disable-collaboras-seccomp-feature
|
||||
FULLTEXTSEARCH_JAVA_OPTIONS: "-Xms1024M -Xmx1024M" # adjust fulltextsearch java options. https://github.com/nextcloud/all-in-one#how-to-adjust-the-fulltextsearch-java-options
|
||||
NEXTCLOUD_DATADIR: /media/forust/nextcloud/ncdata # Allows to set the host directory for Nextcloud's datadir. ⚠️⚠️⚠️ Warning: do not set or adjust this value after the initial Nextcloud installation is done! See https://github.com/nextcloud/all-in-one#how-to-change-the-default-location-of-nextclouds-datadir
|
||||
NEXTCLOUD_DATADIR: /mnt/nextcloud/ncdata # Allows to set the host directory for Nextcloud's datadir. ⚠️⚠️⚠️ Warning: do not set or adjust this value after the initial Nextcloud installation is done! See https://github.com/nextcloud/all-in-one#how-to-change-the-default-location-of-nextclouds-datadir
|
||||
NEXTCLOUD_MOUNT: /mnt/ # Allows the Nextcloud container to access the chosen directory on the host. See https://github.com/nextcloud/all-in-one#how-to-allow-the-nextcloud-container-to-access-directories-on-the-host
|
||||
NEXTCLOUD_UPLOAD_LIMIT: 16G # https://github.com/nextcloud/all-in-one#how-to-adjust-the-upload-limit-for-nextcloud
|
||||
NEXTCLOUD_MAX_TIME: 7200 # Max uploading time See https://github.com/nextcloud/all-in-one#how-to-adjust-the-max-execution-time-for-nextcloud
|
||||
@@ -75,7 +68,7 @@ services:
|
||||
# WATCHTOWER_DOCKER_SOCKET_PATH: /var/run/docker.sock # Needs to be specified if the docker socket on the host is not located in the default '/var/run/docker.sock'. For macos it needs to be '/var/run/docker.sock'
|
||||
|
||||
networks:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
nextcloud-aio:
|
||||
driver: bridge
|
||||
|
||||
+7
-14
@@ -50,7 +50,7 @@ x-secret-key: &penpot-secret-key
|
||||
|
||||
networks:
|
||||
penpot:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
volumes:
|
||||
@@ -86,8 +86,8 @@ services:
|
||||
penpot-frontend:
|
||||
image: "penpotapp/frontend:${PENPOT_VERSION:-latest}"
|
||||
restart: always
|
||||
ports:
|
||||
- 9001:8080
|
||||
# ports:
|
||||
# - 9001:8080
|
||||
|
||||
volumes:
|
||||
- penpot_assets:/opt/data/assets
|
||||
@@ -98,37 +98,30 @@ services:
|
||||
|
||||
networks:
|
||||
- penpot
|
||||
- traefik-proxy
|
||||
- proxy
|
||||
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.http.services.penpot.loadbalancer.server.port=8080"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.penpot.rule=Host(`penpot.forust.xyz`)"
|
||||
- "traefik.http.routers.penpot.entrypoints=websecure"
|
||||
- "traefik.http.routers.penpot.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.penpot.service=penpot"
|
||||
- "traefik.http.routers.penpot.tls=true"
|
||||
- "traefik.http.services.penpot.loadbalancer.server.port=8080"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.penpot-local.rule=Host(`penpot.workstation.internal`) || Host(`penpot.internal`)"
|
||||
- "traefik.http.routers.penpot-local.rule=Host(`penpot.workstation.internal`)"
|
||||
- "traefik.http.routers.penpot-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.penpot-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.penpot-local.service=penpot"
|
||||
- "traefik.http.routers.penpot-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.penpot-dev.rule=Host(`penpot.gigaforust.internal`)"
|
||||
- "traefik.http.routers.penpot-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.penpot-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.penpot-dev.service=penpot"
|
||||
- "traefik.http.routers.penpot-dev.tls=true"
|
||||
|
||||
environment:
|
||||
<<: [ *penpot-flags, *penpot-http-body-size ]
|
||||
|
||||
penpot-backend:
|
||||
image: "penpotapp/backend:${PENPOT_VERSION:-latest}"
|
||||
restart: always
|
||||
|
||||
+13
-22
@@ -1,54 +1,45 @@
|
||||
services:
|
||||
portainer:
|
||||
container_name: portainer
|
||||
image: portainer/portainer-ce:latest
|
||||
container_name: portainer
|
||||
restart: always
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- ./portainer_data:/data
|
||||
- data:/data
|
||||
ports:
|
||||
- 9443:9443
|
||||
# - 8000:8000 # Remove if you do not intend to use Edge Agents
|
||||
networks:
|
||||
- traefik-proxy
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.http.services.portainer.loadbalancer.server.port=9443"
|
||||
- "traefik.http.services.portainer.loadbalancer.server.scheme=https"
|
||||
- "traefik.http.services.portainer.loadbalancer.serverstransport=insecureTransport@file"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.portainer.rule=Host(`portainer.forust.xyz`)"
|
||||
- "traefik.http.routers.portainer.entrypoints=websecure"
|
||||
- "traefik.http.routers.portainer.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.portainer.service=portainer"
|
||||
- "traefik.http.routers.portainer.tls=true"
|
||||
- "traefik.http.services.portainer.loadbalancer.server.port=9443"
|
||||
- "traefik.http.services.portainer.loadbalancer.server.scheme=https"
|
||||
- "traefik.http.services.portainer.loadbalancer.serverstransport=insecureTransport@file"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.portainer-local.rule=Host(`portainer.workstation.internal`) || Host(`portainer.internal`)"
|
||||
- "traefik.http.routers.portainer-local.rule=Host(`portainer.workstation.internal`)"
|
||||
- "traefik.http.routers.portainer-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.portainer-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.portainer-local.service=portainer"
|
||||
- "traefik.http.routers.portainer-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.portainer-dev.rule=Host(`portainer.gigaforust.internal`)"
|
||||
- "traefik.http.routers.portainer-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.portainer-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.portainer-dev.service=portainer"
|
||||
- "traefik.http.routers.portainer-dev.tls=true"
|
||||
|
||||
# Glance Metadata
|
||||
- glance.name=Portainer
|
||||
- glance.url=https://portainer.forust.xyz/
|
||||
- glance.description=Portainer is a lightweight management UI which allows you to easily manage your Docker environments.
|
||||
|
||||
volumes:
|
||||
portainer_data:
|
||||
name: portainer_data
|
||||
|
||||
networks:
|
||||
default:
|
||||
name: portainer_network
|
||||
traefik-proxy:
|
||||
- proxy
|
||||
volumes:
|
||||
data:
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
+9
-17
@@ -3,44 +3,36 @@ services:
|
||||
image: ghcr.io/lukegus/termix:latest
|
||||
container_name: termix
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "3331:8080"
|
||||
# ports:
|
||||
# - "3331:8080"
|
||||
volumes:
|
||||
- ./termix-data:/app/data
|
||||
- data:/app/data
|
||||
environment:
|
||||
PORT: "8080"
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.http.services.termix.loadbalancer.server.port=8080"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.termix.rule=Host(`termix.forust.xyz`)"
|
||||
- "traefik.http.routers.termix.entrypoints=websecure"
|
||||
- "traefik.http.routers.termix.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.termix.service=termix"
|
||||
- "traefik.http.routers.termix.tls=true"
|
||||
- "traefik.http.services.termix.loadbalancer.server.port=8080"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.termix-local.rule=Host(`termix.workstation.internal`) || Host(`termix.internal`)"
|
||||
- "traefik.http.routers.termix-local.rule=Host(`termix.workstation.internal`)"
|
||||
- "traefik.http.routers.termix-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.termix-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.termix-local.service=termix"
|
||||
- "traefik.http.routers.termix-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.termix-dev.rule=Host(`termix.gigaforust.internal`)"
|
||||
- "traefik.http.routers.termix-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.termix-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.termix-dev.service=termix"
|
||||
- "traefik.http.routers.termix-dev.tls=true"
|
||||
networks:
|
||||
- traefik-proxy
|
||||
|
||||
- proxy
|
||||
networks:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
volumes:
|
||||
termix-data:
|
||||
driver: local
|
||||
data:
|
||||
+21
-28
@@ -11,24 +11,26 @@ services:
|
||||
# Providers
|
||||
- "--providers.docker=true"
|
||||
- "--providers.docker.exposedbydefault=false"
|
||||
- "--providers.docker.network=traefik-proxy"
|
||||
- "--providers.docker.network=proxy"
|
||||
- "--providers.file.directory=/etc/traefik/dynamic"
|
||||
- "--providers.file.watch=true"
|
||||
|
||||
# EntryPoints
|
||||
- "--entryPoints.web.address=:80"
|
||||
- "--entryPoints.websecure.address=:443"
|
||||
- "--entryPoints.websecure.http.tls=true"
|
||||
- "--entryPoints.web.http.redirections.entryPoint.to=websecure"
|
||||
# - "--entryPoints.web.http.middlewares=error-pages@docker"
|
||||
- "--entryPoints.web.http.redirections.entryPoint.scheme=https"
|
||||
- "--entryPoints.websecure.address=:443"
|
||||
- "--entryPoints.websecure.http.middlewares=error-pages@docker"
|
||||
- "--entryPoints.websecure.http.tls=true"
|
||||
- "--entryPoints.ssh.address=:2221"
|
||||
|
||||
# Let's Encrypt STAGING. CURRENTLY USING CF ORIGIN CA INSTEAD
|
||||
# - "--certificatesresolvers.letsencrypt.acme.email=${EMAIL}"
|
||||
# - "--certificatesresolvers.letsencrypt.acme.storage=/letsencrypt/acme.json"
|
||||
# Let's Encrypt
|
||||
- "--certificatesresolvers.letsencrypt.acme.email=${EMAIL}"
|
||||
- "--certificatesresolvers.letsencrypt.acme.storage=/letsencrypt/acme.json"
|
||||
- "--certificatesresolvers.letsencrypt.acme.httpchallenge=true"
|
||||
- "--certificatesresolvers.letsencrypt.acme.httpchallenge.entrypoint=web"
|
||||
# # STAGING
|
||||
# - "--certificatesresolvers.letsencrypt.acme.caserver=https://acme-staging-v02.api.letsencrypt.org/directory"
|
||||
# - "--certificatesresolvers.letsencrypt.acme.httpchallenge=true"
|
||||
# - "--certificatesresolvers.letsencrypt.acme.httpchallenge.entrypoint=web"
|
||||
|
||||
# Cloudflare
|
||||
- "--entryPoints.web.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
||||
@@ -38,10 +40,9 @@ services:
|
||||
# - "--log.filePath=/var/log/traefik/traefik.log"
|
||||
# - "--accesslog=true"
|
||||
# - "--accesslog.filepath=/var/log/traefik/access.log"
|
||||
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.docker.network=proxy"
|
||||
|
||||
# Prod Router (Dash)
|
||||
- "traefik.http.routers.traefik-dashboard.rule=Host(`traefik.forust.xyz`)"
|
||||
@@ -49,42 +50,34 @@ services:
|
||||
- "traefik.http.routers.traefik-dashboard.middlewares=security-chain@file"
|
||||
- "traefik.http.routers.traefik-dashboard.service=api@internal"
|
||||
- "traefik.http.routers.traefik-dashboard.tls=true"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.traefik-dashboard-local.rule=Host(`traefik.workstation.internal`) || Host(`traefik.internal`)"
|
||||
- "traefik.http.routers.traefik-dashboard-local.rule=Host(`traefik.workstation.internal`)"
|
||||
- "traefik.http.routers.traefik-dashboard-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.traefik-dashboard-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.traefik-dashboard-local.service=api@internal"
|
||||
- "traefik.http.routers.traefik-dashboard-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.traefik-dashboard-dev.rule=Host(`traefik.gigaforust.internal`)"
|
||||
- "traefik.http.routers.traefik-dashboard-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.traefik-dashboard-dev.middlewares=security-chain@file"
|
||||
- "traefik.http.routers.traefik-dashboard-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.traefik-dashboard-dev.service=api@internal"
|
||||
- "traefik.http.routers.traefik-dashboard-dev.tls=true"
|
||||
|
||||
# Glance Metadata
|
||||
- glance.name=Traefik
|
||||
- glance.url=https://traefik.forust.xyz/
|
||||
- glance.description=Traefik is a modern reverse proxy and load balancer
|
||||
|
||||
ports:
|
||||
- "80:80"
|
||||
- "443:443"
|
||||
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||
- ./dynamic:/etc/traefik/dynamic:ro
|
||||
- ./certs:/certs:ro
|
||||
- ./logs:/var/log/traefik
|
||||
# - ./traefik/letsencrypt:/letsencrypt
|
||||
|
||||
- ./letsencrypt:/letsencrypt
|
||||
ports:
|
||||
- "80:80"
|
||||
- "443:443"
|
||||
networks:
|
||||
- traefik-proxy
|
||||
|
||||
environment:
|
||||
- TZ=Europe/Bratislava
|
||||
|
||||
- proxy
|
||||
networks:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
@@ -0,0 +1,23 @@
|
||||
http:
|
||||
routers:
|
||||
fs1-public:
|
||||
rule: "Host(`fs1.domain.xyz`)"
|
||||
entrypoints:
|
||||
- websecure
|
||||
service: fs1
|
||||
middlewares:
|
||||
- security-chain@file
|
||||
tls: {}
|
||||
|
||||
fs1-workstation:
|
||||
rule: "Host(`fs1.workstation.internal`)"
|
||||
entrypoints:
|
||||
- websecure
|
||||
service: fs1
|
||||
tls: {}
|
||||
|
||||
services:
|
||||
fs1:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://127.0.0.1:3923" # Copyparty port example
|
||||
@@ -5,29 +5,6 @@ http:
|
||||
redirectScheme:
|
||||
scheme: https
|
||||
permanent: true
|
||||
|
||||
# Metube Basic Auth
|
||||
metube-auth:
|
||||
basicAuth:
|
||||
users:
|
||||
- "vv:$2y$05$JdT8AGUO9bd.E/PiCmKaoOJS1RFlXkrrmZ5mJ4f8/a1bEW39L3FbS"
|
||||
|
||||
realm: "MeTube Access"
|
||||
|
||||
# Basic Auth Traefik Dashboard
|
||||
auth:
|
||||
basicAuth:
|
||||
users:
|
||||
- "admin:$2y$05$.CKDD82sNUxcpaRrLbHuK.dopqt1fgurc2yfTKAT5OFzT7RvPrJHK"
|
||||
realm: "Traefik Dashboard"
|
||||
|
||||
# Basic Auth Dockmon
|
||||
dockmon-auth:
|
||||
basicAuth:
|
||||
users:
|
||||
- "admin:$2y$05$.CKDD82sNUxcpaRrLbHuK.dopqt1fgurc2yfTKAT5OFzT7RvPrJHK"
|
||||
realm: "Dockmon Access"
|
||||
|
||||
# Cloudflare IP Whitelist
|
||||
cloudflare-ipwhitelist:
|
||||
ipWhiteList:
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
http:
|
||||
routers:
|
||||
acme-challenge-exempt:
|
||||
rule: "PathPrefix(`/.well-known/acme-challenge`)"
|
||||
entryPoints:
|
||||
- web
|
||||
service: noop@internal
|
||||
priority: 100
|
||||
@@ -2,8 +2,8 @@
|
||||
tls:
|
||||
certificates:
|
||||
# Cloudflare Origin CA *.forust.xyz
|
||||
- certFile: /certs/cloudflare.pem
|
||||
keyFile: /certs/cloudflare.key
|
||||
# - certFile: /certs/cloudflare.pem
|
||||
# keyFile: /certs/cloudflare.key
|
||||
- certFile: /certs/xdfnx.pem
|
||||
keyFile: /certs/xdfnx.key
|
||||
stores:
|
||||
|
||||
+11
-12
@@ -1,34 +1,33 @@
|
||||
services:
|
||||
uptime-kuma:
|
||||
image: louislam/uptime-kuma:2
|
||||
restart: unless-stopped
|
||||
container_name: uptime-kuma
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- ./data:/app/data
|
||||
ports:
|
||||
# <Host Port>:<Container Port>
|
||||
- "3001:3001"
|
||||
- data:/app/data
|
||||
# ports:
|
||||
# - "3001:3001"
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.http.services.uptime-kuma.loadbalancer.server.port=3001"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.uptime-kuma.rule=Host(`uptime.forust.xyz`)"
|
||||
- "traefik.http.routers.uptime-kuma.entrypoints=websecure"
|
||||
- "traefik.http.routers.uptime-kuma.tls=true"
|
||||
- "traefik.http.services.uptime-kuma.loadbalancer.server.port=3001"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.uptime-kuma-local.rule=Host(`uptime.workstation.internal`) || Host(`uptime.internal`)"
|
||||
- "traefik.http.routers.uptime-kuma-local.rule=Host(`uptime.workstation.internal`)"
|
||||
- "traefik.http.routers.uptime-kuma-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.uptime-kuma-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.uptime-kuma-dev.rule=Host(`uptime.gigaforust.internal`)"
|
||||
- "traefik.http.routers.uptime-kuma-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.uptime-kuma-dev.tls=true"
|
||||
networks:
|
||||
- traefik-proxy
|
||||
- proxy
|
||||
volumes:
|
||||
data:
|
||||
networks:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
Reference in New Issue
Block a user