Compare commits
348 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| ace23ad1f9 | |||
| 92aa731e44 | |||
|
87ca3fd40c
|
|||
|
82bcd30ed8
|
|||
| 620262d98c | |||
| 831f3a46b0 | |||
|
f7902e74e8
|
|||
|
eb8d1b361e
|
|||
|
6e2cafb206
|
|||
|
67b0c0824f
|
|||
|
8e72e0a920
|
|||
| 73a1132beb | |||
| a128523c24 | |||
| ee881acd0e | |||
| bacb2f4b9f | |||
| 91211e7b78 | |||
|
9b3a7aadb4
|
|||
|
b123621ead
|
|||
|
a2df8504f5
|
|||
|
fb43306571
|
|||
|
f424d91405
|
|||
|
88a8f2987f
|
|||
|
17027b232b
|
|||
|
6ecbbb39b4
|
|||
|
175cbc8860
|
|||
|
6363d050b0
|
|||
|
c855764bc6
|
|||
|
7d92b85e21
|
|||
| 9364392bc0 | |||
| 4355f451d4 | |||
| 3eaef5dc90 | |||
| 69ffd3682e | |||
| 1930600c40 | |||
|
d74a705d53
|
|||
|
3c383db9a7
|
|||
| 7fb0a0e179 | |||
|
227e5fda27
|
|||
| 20bce5b31c | |||
|
70d7855f06
|
|||
| c905bbd039 | |||
|
fc83176522
|
|||
| 7ba6bc44f2 | |||
|
0506aaaac8
|
|||
|
bd9724da69
|
|||
|
3bad433f1a
|
|||
|
2bd7a5176f
|
|||
|
a9ff01261b
|
|||
| 95cec59263 | |||
|
1362ebc3c2
|
|||
|
2de6131ba7
|
|||
|
1762962f32
|
|||
|
7fb9e46c05
|
|||
|
b33488342a
|
|||
|
d53b14b1de
|
|||
|
a6a6d933da
|
|||
| 0803f3efff | |||
| ec0420962b | |||
| b407202e53 | |||
| b9b8474455 | |||
| 76853637bc | |||
| dac3777fc4 | |||
| bb5a3697f2 | |||
| e73aacb900 | |||
| ea483da645 | |||
| 85d35f86a7 | |||
| 3d03ab1ea4 | |||
| 4ca3ccdad3 | |||
| 10e26cda72 | |||
| c648dfd147 | |||
| 2f97821dc6 | |||
| 3d78b90f3a | |||
| 3dc8228e22 | |||
| 93171ad8e6 | |||
| dca7ad0902 | |||
| 26d10f4e71 | |||
| 68c5eac164 | |||
| 30f0f05150 | |||
| a97560eaf3 | |||
| 2dce972be2 | |||
| c2ad1122e5 | |||
| 4c356924e7 | |||
| 51777f904f | |||
| 37550da086 | |||
| 12d59cb6f9 | |||
| 714d4896c6 | |||
| e369875117 | |||
| 31e61a9513 | |||
| 9b21f8056c | |||
| 4623fbd8bd | |||
| 18d1e21690 | |||
| 20b8c93275 | |||
| 5f88ecf02b | |||
| 0093e5ac52 | |||
| bb821e138a | |||
| 1ea669220b | |||
| f068a3e6a0 | |||
| b7854447af | |||
| 7a3708f70c | |||
| 01ae2dd5cf | |||
| 82595804bf | |||
| 31b3c5bc31 | |||
| 1cdbfb2d7b | |||
| 6232b77026 | |||
| 22ffd779cc | |||
| d85b3f02f5 | |||
| 17b2dfdc2e | |||
| b641e3bd94 | |||
| e19660fdf4 | |||
|
36922a177c
|
|||
|
f3d04e935c
|
|||
| e5797e60b7 | |||
| 444bb97f8e | |||
|
0c5cf29f83
|
|||
| 4f01cdac31 | |||
|
43c38767a1
|
|||
| cb40b10ecf | |||
| a68c01a68f | |||
| bdcdb1cb3d | |||
| fe2b80b51f | |||
| b8d5bc747d | |||
|
6f77b7d845
|
|||
| ea286e117d | |||
| 6a050669e8 | |||
| b9c11b8eab | |||
| 6dac841b2c | |||
| bed58c84ef | |||
| 526a2b617a | |||
| 56e5d79e3e | |||
| 1e08391e0e | |||
| cd0ce06246 | |||
| 0a31601b77 | |||
| e9a9271d2f | |||
| 25eb89c902 | |||
| d988b0f7db | |||
| e873f37159 | |||
| 8362f45bdc | |||
| fd5ea6cadd | |||
| aa3598ee3d | |||
|
c0205fa49b
|
|||
|
a22707770f
|
|||
|
646f988a86
|
|||
|
414d17d839
|
|||
|
812e4eb87a
|
|||
| 70b3b203fb | |||
| d857f3838d | |||
| f8620349a9 | |||
| b1acff5c85 | |||
| beb6dca6a2 | |||
| aed6ff31f7 | |||
| 73684af21b | |||
| cd5c90adcc | |||
| 578a1ca544 | |||
| 12ed20a306 | |||
|
400e7b6595
|
|||
| f58e96a25d | |||
| a3e5f5a78b | |||
|
1a09a62a4c
|
|||
|
2593b54402
|
|||
|
42826a037c
|
|||
|
d7a68237e5
|
|||
| bbb8bdf0a7 | |||
| f4d3bd9c6d | |||
|
6b919df7c6
|
|||
| 3ee0b96ed5 | |||
| d25d213d9b | |||
|
a3b7c4c889
|
|||
| 3dbb50c924 | |||
| 54da82432b | |||
| e5eb234c41 | |||
| 721348e67f | |||
|
d58ae2a5e7
|
|||
| aa516c3445 | |||
|
b5cc7d9a0d
|
|||
|
5dfa9c879b
|
|||
| 3c5702a0fb | |||
| dd0ca27f4f | |||
| 7f7d0de090 | |||
| bee3f16cb2 | |||
|
303d23968d
|
|||
|
b7ecf88052
|
|||
|
5068591b8b
|
|||
|
8e57f21e44
|
|||
|
073d9ff569
|
|||
| c6d00e525b | |||
|
539994a145
|
|||
|
95f0afbbee
|
|||
|
9f86bd1142
|
|||
| af9668e8e6 | |||
|
53b71a33ad
|
|||
|
bf72007b14
|
|||
|
0bad0a817e
|
|||
| 525fed3b92 | |||
|
fe5e5c5e35
|
|||
|
72aa022048
|
|||
|
f18d4d9be4
|
|||
|
45ce789f58
|
|||
|
d7c05fd058
|
|||
| c13056fba1 | |||
|
5fe8af82d5
|
|||
| 6d97246997 | |||
| 6970279311 | |||
|
02f4e0ab42
|
|||
|
4a25622552
|
|||
|
0138fbd276
|
|||
|
94b5f39207
|
|||
| 403e88d548 | |||
| d03a4844fb | |||
| 48ff08529e | |||
|
81592b6142
|
|||
| 9480576966 | |||
| 9b43a9bef4 | |||
| 2b03335af5 | |||
| ea738ec14c | |||
|
e4e9d96a0b
|
|||
| 89576032b9 | |||
| a9edfc0a25 | |||
| acb8009307 | |||
| 21f4e46028 | |||
| 0234524635 | |||
| 26f5fb2fb9 | |||
| 122e6f6986 | |||
| ce0bc4613a | |||
| 8f4f460ff3 | |||
| c048efd569 | |||
| 1f1e13ff39 | |||
| c80a6c5351 | |||
| 4fe3d660f1 | |||
| 9675eac2bf | |||
| dc7fe64fbc | |||
| 502810a12e | |||
| c047cc291d | |||
| f2b951673c | |||
| 6b7c0df586 | |||
| fb2f420520 | |||
| 60c7d4ff17 | |||
| d20ec696a3 | |||
| c030b4cffa | |||
| e0f7ab6561 | |||
| f0682319a7 | |||
| dbd3f36f76 | |||
| 4471da827c | |||
| 163ea867ce | |||
| dc75dbaf7c | |||
| db0f0f7bb6 | |||
| 5e4c60bb30 | |||
| a699ceb935 | |||
| 17cae71952 | |||
| f4c695f95e | |||
| 6bdb16ad21 | |||
| 6eb62f41cc | |||
| 586f0e3f7d | |||
| 0e46193f53 | |||
| aed28ed15c | |||
| f3b73bae11 | |||
| be049cfa0d | |||
| bfb21adff7 | |||
| 1c75382a6e | |||
| 9c5e037567 | |||
| 4f9e7ea990 | |||
| 9f784d2c31 | |||
| a07e27bff6 | |||
| c31369f2b7 | |||
| 3bfcd6edf4 | |||
| 504cbc81a0 | |||
| aa7239ee83 | |||
| 6d9427cf2a | |||
| 70d60ed40a | |||
| aca6824309 | |||
| d48a01775d | |||
| 99d50b43fe | |||
| 23e955bde7 | |||
| 7d7a0e5c8a | |||
| a767107277 | |||
| e68e37c285 | |||
| fc6a11397b | |||
| d776124f26 | |||
| 8a0ed85e7c | |||
| 15f0f35ce4 | |||
| 1ec145d4cf | |||
| 8b6815f314 | |||
| 2d05a1911c | |||
| 6f2f70ad09 | |||
| ce66a546f1 | |||
| 6cb49be951 | |||
| 3bcabcce4b | |||
| a54b7b000f | |||
| 5b1fa11b5e | |||
| 380288d103 | |||
| 8fae8bf75d | |||
| d4e0e7f37a | |||
| cb92bff0c5 | |||
| bfbe841154 | |||
| 7cbc5bf4f3 | |||
| 258ed04f98 | |||
| 7ee0a1e7a2 | |||
| 739915c451 | |||
| 68b5467a37 | |||
| 61e6b2b5c7 | |||
| 272666d2fd | |||
| aca485836b | |||
| 02671b9117 | |||
| 1c1170ca96 | |||
| 3eab3b254a | |||
| 5d9fc18ba5 | |||
| 03d39f8a32 | |||
| 7b60630d76 | |||
| cc20d848f8 | |||
| 1040e4fdf7 | |||
| 7af5af0630 | |||
| 8f9be8a478 | |||
| d1adaa54b1 | |||
| b3b0d5b553 | |||
| d22ef0cb44 | |||
| 7c29d74c72 | |||
| b2ae170ea0 | |||
| 2c2474165b | |||
| 155bb8d02b | |||
| ed1b41ca1d | |||
| 9bb5f070e3 | |||
| b238e9ccf2 | |||
| 09a05a5ad5 | |||
| 5b05207985 | |||
| 319cf0ea1f | |||
| 53a0460476 | |||
| 13340b6ddc | |||
| ed20fb6e2a | |||
| 4fe36be5ea | |||
| 6f8b780906 | |||
| 1f9a1c2c62 | |||
| b20c012268 | |||
| b4bce72611 | |||
| e7d21bfe90 | |||
| 0f75fe02c2 | |||
| 2d895fe2bd | |||
| 45b0859ab5 | |||
| 45021933a6 | |||
| d25570e293 | |||
| 6843befac3 | |||
| 0dfb09590d | |||
| 625eb9561b | |||
| b367b64879 | |||
| a30bda4940 | |||
| b722467991 | |||
| 5f8fd05266 | |||
| 1c7afe5bb3 | |||
| 4ff80c07b0 | |||
| 3a5652daa7 | |||
| 4e18cd0eb3 |
@@ -0,0 +1,191 @@
|
|||||||
|
# Инструкция: Анализ хранилища Kubernetes и настройка NFS
|
||||||
|
|
||||||
|
## Цель
|
||||||
|
Проанализировать текущую конфигурацию хранилища Kubernetes и подготовить план внедрения NFS StorageClass для сохранения данных при удалении namespace.
|
||||||
|
|
||||||
|
## 1. Собрать информацию о кластере
|
||||||
|
|
||||||
|
### 1.1. Версия Kubernetes и тип дистрибутива
|
||||||
|
```bash
|
||||||
|
kubectl version --short
|
||||||
|
# или
|
||||||
|
kubectl version
|
||||||
|
```
|
||||||
|
|
||||||
|
Определить, используется ли k3s, k8s, microk8s и т.д.:
|
||||||
|
```bash
|
||||||
|
# Проверить наличие k3s
|
||||||
|
which k3s
|
||||||
|
# Проверить процесс
|
||||||
|
ps aux | grep -E 'kube|k3s'
|
||||||
|
```
|
||||||
|
|
||||||
|
### 1.2. StorageClass
|
||||||
|
```bash
|
||||||
|
kubectl get storageclass -o wide
|
||||||
|
```
|
||||||
|
|
||||||
|
Запомнить:
|
||||||
|
- `PROVISIONER` — какой драйвер используется
|
||||||
|
- `RECLAIMPOLICY` — Delete или Retain
|
||||||
|
- Какой StorageClass помечен как `(default)`
|
||||||
|
|
||||||
|
### 1.3. Существующие PV и PVC
|
||||||
|
```bash
|
||||||
|
kubectl get pv -o wide
|
||||||
|
kubectl get pvc --all-namespaces
|
||||||
|
```
|
||||||
|
|
||||||
|
Посмотреть, какие PVC привязаны к каким PV, и какой reclaimPolicy у PV.
|
||||||
|
|
||||||
|
### 1.4. Нода и диски
|
||||||
|
```bash
|
||||||
|
# Список нод
|
||||||
|
kubectl get nodes -o wide
|
||||||
|
|
||||||
|
# На каждой ноде (через ssh или локально):
|
||||||
|
lsblk
|
||||||
|
df -h
|
||||||
|
cat /etc/fstab
|
||||||
|
```
|
||||||
|
|
||||||
|
Определить:
|
||||||
|
- Есть ли отдельный раздел/диск для данных
|
||||||
|
- Куда смонтированы разделы
|
||||||
|
- Сколько свободного места
|
||||||
|
- Есть ли монтирование NTFS-разделов (как `/media/forust/Programs`)
|
||||||
|
|
||||||
|
### 1.5. Где local-path хранит данные (для k3s)
|
||||||
|
```bash
|
||||||
|
ls -la /var/lib/rancher/k3s/storage/ 2>/dev/null
|
||||||
|
# или для microk8s
|
||||||
|
ls -la /var/snap/microk8s/common/ 2>/dev/null
|
||||||
|
```
|
||||||
|
|
||||||
|
## 2. Анализ: сохраняются ли данные при удалении namespace?
|
||||||
|
|
||||||
|
| Сценарий | Результат |
|
||||||
|
|---|---|
|
||||||
|
| `kubectl delete ns <ns>` | Все PVC в namespace удаляются |
|
||||||
|
| PVC → PV c `reclaimPolicy: Delete` | PV и данные удалены |
|
||||||
|
| PVC → PV c `reclaimPolicy: Retain` | PV остаётся (статус Released), данные целы |
|
||||||
|
|
||||||
|
**Вывод:** Если reclaimPolicy в StorageClass = `Delete`, то данные **пропадут**. Если `Retain` — сохранятся.
|
||||||
|
|
||||||
|
## 3. План внедрения NFS
|
||||||
|
|
||||||
|
### 3.1. Проверить, установлен ли NFS
|
||||||
|
```bash
|
||||||
|
which nfsstat exportfs mount.nfs
|
||||||
|
systemctl status nfs-server 2>/dev/null || systemctl status nfs-kernel-server 2>/dev/null
|
||||||
|
```
|
||||||
|
|
||||||
|
### 3.2. Выбрать директорию для NFS-экспорта
|
||||||
|
|
||||||
|
Варианты (выбрать подходящий):
|
||||||
|
- `/var/lib/k8s-nfs/` — на корневом разделе
|
||||||
|
- `<путь к отдельному разделу>/k8s-nfs/` — если есть отдельный диск/раздел
|
||||||
|
- Не рекомендуется использовать NTFS-раздел (проблемы с правами и производительностью)
|
||||||
|
|
||||||
|
Требования:
|
||||||
|
- Файловая система: ext4 или xfs (не ntfs!)
|
||||||
|
- Достаточно свободного места
|
||||||
|
- Права: `755`, владелец root
|
||||||
|
|
||||||
|
### 3.3. Установить NFS-сервер
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Debian/Ubuntu
|
||||||
|
apt update && apt install -y nfs-kernel-server
|
||||||
|
|
||||||
|
# RHEL/Fedora
|
||||||
|
dnf install -y nfs-utils
|
||||||
|
```
|
||||||
|
|
||||||
|
### 3.4. Настроить экспорт
|
||||||
|
|
||||||
|
Создать директорию:
|
||||||
|
```bash
|
||||||
|
mkdir -p /var/lib/k8s-nfs
|
||||||
|
chmod 755 /var/lib/k8s-nfs
|
||||||
|
```
|
||||||
|
|
||||||
|
Добавить в `/etc/exports`:
|
||||||
|
```
|
||||||
|
/var/lib/k8s-nfs *(rw,sync,no_subtree_check,no_root_squash)
|
||||||
|
```
|
||||||
|
|
||||||
|
Применить:
|
||||||
|
```bash
|
||||||
|
exportfs -rav
|
||||||
|
```
|
||||||
|
|
||||||
|
Проверить:
|
||||||
|
```bash
|
||||||
|
showmount -e localhost
|
||||||
|
```
|
||||||
|
|
||||||
|
### 3.5. Выбрать способ интеграции с Kubernetes
|
||||||
|
|
||||||
|
#### Вариант A: nfs-subdir-external-provisioner (проще)
|
||||||
|
```bash
|
||||||
|
helm repo add nfs-subdir-external-provisioner https://kubernetes-sigs.github.io/nfs-subdir-external-provisioner/
|
||||||
|
helm install nfs-provisioner nfs-subdir-external-provisioner/nfs-subdir-external-provisioner \
|
||||||
|
--namespace kube-system \
|
||||||
|
--set nfs.server=127.0.0.1 \
|
||||||
|
--set nfs.path=/var/lib/k8s-nfs \
|
||||||
|
--set storageClass.name=nfs \
|
||||||
|
--set storageClass.defaultClass=false \
|
||||||
|
--set storageClass.reclaimPolicy=Retain
|
||||||
|
```
|
||||||
|
|
||||||
|
#### Вариант B: NFS CSI Driver
|
||||||
|
```bash
|
||||||
|
helm repo add csi-driver-nfs https://raw.githubusercontent.com/kubernetes-csi/csi-driver-nfs/master/charts
|
||||||
|
helm install csi-driver-nfs csi-driver-nfs/csi-driver-nfs --namespace kube-system
|
||||||
|
```
|
||||||
|
|
||||||
|
После установки CSI драйвера создать StorageClass:
|
||||||
|
```yaml
|
||||||
|
apiVersion: storage.k8s.io/v1
|
||||||
|
kind: StorageClass
|
||||||
|
metadata:
|
||||||
|
name: nfs
|
||||||
|
provisioner: nfs.csi.k8s.io
|
||||||
|
parameters:
|
||||||
|
server: 127.0.0.1
|
||||||
|
share: /var/lib/k8s-nfs
|
||||||
|
reclaimPolicy: Retain
|
||||||
|
volumeBindingMode: Immediate
|
||||||
|
```
|
||||||
|
|
||||||
|
### 3.6. Проверить результат
|
||||||
|
```bash
|
||||||
|
kubectl get storageclass
|
||||||
|
kubectl get pods -n kube-system | grep -E 'nfs|provisioner'
|
||||||
|
```
|
||||||
|
|
||||||
|
## 4. Итоговая конфигурация
|
||||||
|
|
||||||
|
После внедрения в кластере будет два StorageClass:
|
||||||
|
|
||||||
|
| Имя | Provisioner | ReclaimPolicy | Назначение |
|
||||||
|
|---|---|---|---|
|
||||||
|
| `local-path` (default) | rancher.io/local-path | Delete | Временные данные, stateless |
|
||||||
|
| `nfs` | nfs-subdir-external-provisioner или nfs.csi.k8s.io | Retain | Данные, которые нужно сохранять |
|
||||||
|
|
||||||
|
**Главное преимущество:** PVC c `storageClassName: nfs` при удалении namespace сохраняют данные на диске, так как NFS-провизор использует `reclaimPolicy: Retain` или файлы физически остаются в NFS-экспорте.
|
||||||
|
|
||||||
|
## 5. Ответы на частые вопросы
|
||||||
|
|
||||||
|
**В:** Не упадёт ли local-path при установке NFS?
|
||||||
|
**О:** Нет, они независимы. local-path продолжает работать как обычно.
|
||||||
|
|
||||||
|
**В:** Данные NFS и local-path будут на одном диске?
|
||||||
|
**О:** Да, можно настроить оба на одном разделе, в разных каталогах.
|
||||||
|
|
||||||
|
**В:** Что если у меня несколько нод?
|
||||||
|
**О:** NFS сервер нужно поднять на одной ноде, а с других нод должна быть доступна шари. Для multi-node лучше использовать отдельный сервер или distributed storage (Longhorn, Rook/Ceph).
|
||||||
|
|
||||||
|
**В:** Можно ли использовать существующий NTFS-раздел для NFS?
|
||||||
|
**О:** Не рекомендуется — NTFS не поддерживает права Linux (no_root_squash не сработает корректно), возможны проблемы с блокировками и производительностью.
|
||||||
@@ -0,0 +1,24 @@
|
|||||||
|
root = true
|
||||||
|
|
||||||
|
[*]
|
||||||
|
indent_style = space
|
||||||
|
indent_size = 2
|
||||||
|
end_of_line = lf
|
||||||
|
charset = utf-8
|
||||||
|
trim_trailing_whitespace = true
|
||||||
|
insert_final_newline = true
|
||||||
|
|
||||||
|
[*.{yml,yaml}]
|
||||||
|
indent_size = 2
|
||||||
|
|
||||||
|
[*.{json,jsonc}]
|
||||||
|
indent_size = 2
|
||||||
|
|
||||||
|
[*.md]
|
||||||
|
trim_trailing_whitespace = false
|
||||||
|
|
||||||
|
[*.py]
|
||||||
|
indent_size = 4
|
||||||
|
|
||||||
|
[{Makefile,makefile}]
|
||||||
|
indent_style = tab
|
||||||
@@ -0,0 +1,70 @@
|
|||||||
|
|
||||||
|
|
||||||
|
#===============================
|
||||||
|
# Basic auth credentials
|
||||||
|
#===============================
|
||||||
|
#
|
||||||
|
#
|
||||||
|
#
|
||||||
|
#===============================
|
||||||
|
|
||||||
|
#===============================================
|
||||||
|
#BEGIN TRAEFIK ENVIRONMENT VARIABLES ===========
|
||||||
|
#===============================================
|
||||||
|
|
||||||
|
#===============================================
|
||||||
|
# General Traefik Environment Variables
|
||||||
|
#===============================================
|
||||||
|
HOST=hostname
|
||||||
|
EMAIL=your@email.here
|
||||||
|
CF_DNS_API_TOKEN=API_TOKEN_HERE
|
||||||
|
CF_EMAIL=your_cloudflare@email.here
|
||||||
|
TZ=Europe/Berlin
|
||||||
|
|
||||||
|
#===============================================
|
||||||
|
# Dockmon Traefik Configuration File
|
||||||
|
#===============================================
|
||||||
|
DOCKMON_APPNAME=dockmon
|
||||||
|
DOCKMON_SUBDOMEN=dockmon
|
||||||
|
#===============================================
|
||||||
|
# Dashboard Traefik Environment Variables
|
||||||
|
#===============================================
|
||||||
|
DASHBOARD_APPNAME=traefik
|
||||||
|
DASHBOARD_SUBDOMEN=traefik
|
||||||
|
#===============================================
|
||||||
|
# Watercrawl Traefik Environment Variables
|
||||||
|
#===============================================
|
||||||
|
WATERCRAWL_APPNAME=watercrawl
|
||||||
|
WATERCRAWL_SUBDOMEN=watercrawl
|
||||||
|
#===============================================
|
||||||
|
# n8n Traefik Environment Variables
|
||||||
|
#===============================================
|
||||||
|
N8N_APPNAME=n8n
|
||||||
|
N8N_SUBDOMEN=n8n
|
||||||
|
#===============================================
|
||||||
|
# Glance Traefik Environment Variables
|
||||||
|
#===============================================
|
||||||
|
GLANCE_APPNAME=glance
|
||||||
|
GLANCE_SUBDOMEN=glance
|
||||||
|
#===============================================
|
||||||
|
# AdGuard Traefik Environment Variables
|
||||||
|
#===============================================
|
||||||
|
ADGUARD_APPNAME=adguard
|
||||||
|
ADGUARD_SUBDOMEN=adguard
|
||||||
|
#===============================================
|
||||||
|
# Portainer Traefik Environment Variables
|
||||||
|
#===============================================
|
||||||
|
PORTAINER_APPNAME=portainer
|
||||||
|
PORTAINER_SUBDOMEN=portainer
|
||||||
|
#===============================================
|
||||||
|
# Nextcloud Traefik Environment Variables
|
||||||
|
#===============================================
|
||||||
|
NEXTCLOUD_APPNAME=nextcloud
|
||||||
|
NEXTCLOUD_SUBDOMEN=nextcloud
|
||||||
|
#===============================================
|
||||||
|
# Aio Traefik Environment Variables
|
||||||
|
#===============================================
|
||||||
|
NEXTCLOUD_AIO_APPNAME=nextcloud-aio
|
||||||
|
NEXTCLOUD_AIO_SUBDOMEN=nextcloud-aio
|
||||||
|
# END OF TRAEFIK ENVIRONMENT VARIABLES
|
||||||
|
#===============================================
|
||||||
@@ -0,0 +1,326 @@
|
|||||||
|
name: ci
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- "**"
|
||||||
|
pull_request:
|
||||||
|
workflow_dispatch:
|
||||||
|
|
||||||
|
env:
|
||||||
|
REGISTRY: gcr.forust.xyz
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
lint-prettier:
|
||||||
|
runs-on: [self-hosted, linux, arch, homelab]
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Check formatting with Prettier
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
mapfile -t prettier_files < <(
|
||||||
|
git ls-files \
|
||||||
|
| grep -E '\.(md|json|ya?ml|html|css)$' \
|
||||||
|
| grep -Ev '^(\.docs/|\.zed/|errorpages/html/|homepages/(forust_files|xdfnx_files)/)'
|
||||||
|
)
|
||||||
|
|
||||||
|
if [ "${#prettier_files[@]}" -eq 0 ]; then
|
||||||
|
echo "No Prettier-managed files found."
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
docker run --rm \
|
||||||
|
-v "$PWD:/work" \
|
||||||
|
-w /work \
|
||||||
|
node:22-alpine \
|
||||||
|
sh -lc 'npx --yes prettier@3 --check --ignore-unknown "$@"' sh "${prettier_files[@]}"
|
||||||
|
|
||||||
|
lint-ruff:
|
||||||
|
runs-on: [self-hosted, linux, arch, homelab]
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Lint Python with Ruff
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
docker run --rm \
|
||||||
|
-v "$PWD:/work" \
|
||||||
|
-w /work \
|
||||||
|
ghcr.io/astral-sh/ruff:latest \
|
||||||
|
check .
|
||||||
|
|
||||||
|
lint-yaml:
|
||||||
|
runs-on: [self-hosted, linux, arch, homelab]
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Lint YAML syntax
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
docker run --rm \
|
||||||
|
-v "$PWD:/work" \
|
||||||
|
-w /work \
|
||||||
|
cytopia/yamllint:latest \
|
||||||
|
-c .yamllint .
|
||||||
|
|
||||||
|
lint-dockerfiles:
|
||||||
|
runs-on: [self-hosted, linux, arch, homelab]
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Lint Dockerfiles
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
mapfile -t dockerfiles < <(
|
||||||
|
git ls-files ':(glob)**/Dockerfile' ':(glob)**/Dockerfile.*'
|
||||||
|
)
|
||||||
|
|
||||||
|
if [ "${#dockerfiles[@]}" -eq 0 ]; then
|
||||||
|
echo "No Dockerfiles found."
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
docker run --rm \
|
||||||
|
-v "$PWD:/work" \
|
||||||
|
-w /work \
|
||||||
|
--entrypoint hadolint \
|
||||||
|
hadolint/hadolint:latest-debian \
|
||||||
|
-c .hadolint.yaml "${dockerfiles[@]}"
|
||||||
|
|
||||||
|
validate:
|
||||||
|
runs-on: [self-hosted, linux, arch, homelab]
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Validate Kubernetes manifests
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
mapfile -t manifests < <(
|
||||||
|
git ls-files ':(glob)**/k8s/**/*.yaml' ':(glob)**/k8s/**/*.yml' \
|
||||||
|
| grep -Ev '(^|/)(kustomization\.ya?ml|.*\.example\.ya?ml|.*values\.ya?ml|patch-.*\.ya?ml)$'
|
||||||
|
)
|
||||||
|
|
||||||
|
if [ "${#manifests[@]}" -eq 0 ]; then
|
||||||
|
echo "No Kubernetes manifests found."
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
docker run --rm \
|
||||||
|
-v "$PWD:/work" \
|
||||||
|
-w /work \
|
||||||
|
ghcr.io/yannh/kubeconform:latest \
|
||||||
|
-strict \
|
||||||
|
-ignore-missing-schemas \
|
||||||
|
-summary \
|
||||||
|
"${manifests[@]}"
|
||||||
|
|
||||||
|
build:
|
||||||
|
needs: [lint-prettier, lint-ruff, lint-yaml, lint-dockerfiles, validate]
|
||||||
|
if: github.event_name != 'pull_request' && (github.ref_name == 'main' || github.ref_name == 'dev')
|
||||||
|
runs-on: [self-hosted, linux, arch, homelab]
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
|
||||||
|
- name: Detect changed docker-built services
|
||||||
|
id: services
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
base="${{ github.event.before }}"
|
||||||
|
if [ -z "$base" ] || [ "$base" = "0000000000000000000000000000000000000000" ]; then
|
||||||
|
base="$(git rev-list --max-parents=0 HEAD)"
|
||||||
|
fi
|
||||||
|
|
||||||
|
mapfile -t changed_files < <(git diff --name-only "$base" "${GITHUB_SHA}")
|
||||||
|
|
||||||
|
services=()
|
||||||
|
|
||||||
|
add_service() {
|
||||||
|
local name="$1"
|
||||||
|
local seen=0
|
||||||
|
for existing in "${services[@]}"; do
|
||||||
|
if [ "$existing" = "$name" ]; then
|
||||||
|
seen=1
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
if [ "$seen" -eq 0 ]; then
|
||||||
|
services+=("$name")
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
for file in "${changed_files[@]}"; do
|
||||||
|
case "$file" in
|
||||||
|
dtek_notif/*)
|
||||||
|
add_service dtek_notif
|
||||||
|
;;
|
||||||
|
errorpages/*)
|
||||||
|
add_service errorpages
|
||||||
|
;;
|
||||||
|
userbot/*)
|
||||||
|
add_service userbot
|
||||||
|
;;
|
||||||
|
homepages/*)
|
||||||
|
add_service homepages
|
||||||
|
;;
|
||||||
|
edu_master/phpsessid-bot/*|edu_master/webinar-checker/*|edu_master/compose.yaml)
|
||||||
|
add_service edu_master
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
|
|
||||||
|
if [ "${#services[@]}" -eq 0 ]; then
|
||||||
|
echo "No docker-built services changed."
|
||||||
|
echo "services=" >> "$GITHUB_OUTPUT"
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
printf '%s\n' "${services[@]}" | tee /tmp/services.txt
|
||||||
|
echo "services=$(paste -sd, /tmp/services.txt)" >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
|
- name: Log in to registry
|
||||||
|
if: steps.services.outputs.services != ''
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login "${REGISTRY}" \
|
||||||
|
-u "${{ secrets.REGISTRY_USERNAME }}" \
|
||||||
|
--password-stdin
|
||||||
|
|
||||||
|
- name: Build and push changed images
|
||||||
|
if: steps.services.outputs.services != ''
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
IFS=, read -r -a services <<< "${{ steps.services.outputs.services }}"
|
||||||
|
|
||||||
|
for service in "${services[@]}"; do
|
||||||
|
case "$service" in
|
||||||
|
dtek_notif)
|
||||||
|
image="${REGISTRY}/forust/dtek-notif"
|
||||||
|
tags=("latest")
|
||||||
|
case "${GITHUB_REF_NAME}" in
|
||||||
|
main)
|
||||||
|
tags+=("main" "prod")
|
||||||
|
;;
|
||||||
|
dev)
|
||||||
|
tags+=("dev")
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
build_args=()
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
build_args+=(-t "${image}:${tag}")
|
||||||
|
done
|
||||||
|
docker build "${build_args[@]}" dtek_notif
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
docker push "${image}:${tag}"
|
||||||
|
done
|
||||||
|
;;
|
||||||
|
errorpages)
|
||||||
|
image="${REGISTRY}/forust/error-pages"
|
||||||
|
tags=("latest")
|
||||||
|
case "${GITHUB_REF_NAME}" in
|
||||||
|
main)
|
||||||
|
tags+=("main" "prod")
|
||||||
|
;;
|
||||||
|
dev)
|
||||||
|
tags+=("dev")
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
build_args=()
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
build_args+=(-t "${image}:${tag}")
|
||||||
|
done
|
||||||
|
docker build "${build_args[@]}" errorpages
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
docker push "${image}:${tag}"
|
||||||
|
done
|
||||||
|
;;
|
||||||
|
userbot)
|
||||||
|
image="${REGISTRY}/forust/userbot"
|
||||||
|
tags=("latest")
|
||||||
|
case "${GITHUB_REF_NAME}" in
|
||||||
|
main)
|
||||||
|
tags+=("main" "prod")
|
||||||
|
;;
|
||||||
|
dev)
|
||||||
|
tags+=("dev")
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
build_args=()
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
build_args+=(-t "${image}:${tag}")
|
||||||
|
done
|
||||||
|
docker build "${build_args[@]}" userbot
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
docker push "${image}:${tag}"
|
||||||
|
done
|
||||||
|
;;
|
||||||
|
homepages)
|
||||||
|
for service in forust xdfnx; do
|
||||||
|
case "$service" in
|
||||||
|
forust)
|
||||||
|
image="${REGISTRY}/forust/forust-homepage"
|
||||||
|
;;
|
||||||
|
xdfnx)
|
||||||
|
image="${REGISTRY}/forust/xdfnx-homepage"
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
tags=("latest")
|
||||||
|
case "${GITHUB_REF_NAME}" in
|
||||||
|
main)
|
||||||
|
tags+=("main" "prod")
|
||||||
|
;;
|
||||||
|
dev)
|
||||||
|
tags+=("dev")
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
build_args=()
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
build_args+=(-t "${image}:${tag}")
|
||||||
|
done
|
||||||
|
docker build "${build_args[@]}" -f "homepages/Dockerfile.${service}" homepages
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
docker push "${image}:${tag}"
|
||||||
|
done
|
||||||
|
done
|
||||||
|
;;
|
||||||
|
edu_master)
|
||||||
|
for service in session-keeper webinar-checker; do
|
||||||
|
case "$service" in
|
||||||
|
session-keeper)
|
||||||
|
context="edu_master/phpsessid-bot"
|
||||||
|
image="${REGISTRY}/forust/session-keeper"
|
||||||
|
;;
|
||||||
|
webinar-checker)
|
||||||
|
context="edu_master/webinar-checker"
|
||||||
|
image="${REGISTRY}/forust/webinar-checker"
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
tags=("latest")
|
||||||
|
case "${GITHUB_REF_NAME}" in
|
||||||
|
main)
|
||||||
|
tags+=("main" "prod")
|
||||||
|
;;
|
||||||
|
dev)
|
||||||
|
tags+=("dev")
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
build_args=()
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
build_args+=(-t "${image}:${tag}")
|
||||||
|
done
|
||||||
|
docker build "${build_args[@]}" "$context"
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
docker push "${image}:${tag}"
|
||||||
|
done
|
||||||
|
done
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
@@ -0,0 +1,326 @@
|
|||||||
|
name: ci
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- "**"
|
||||||
|
pull_request:
|
||||||
|
workflow_dispatch:
|
||||||
|
|
||||||
|
env:
|
||||||
|
REGISTRY: gcr.forust.xyz
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
lint-prettier:
|
||||||
|
runs-on: [self-hosted, linux, arch, homelab]
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Check formatting with Prettier
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
mapfile -t prettier_files < <(
|
||||||
|
git ls-files \
|
||||||
|
| grep -E '\.(md|json|ya?ml|html|css)$' \
|
||||||
|
| grep -Ev '^(\.docs/|\.zed/|errorpages/html/|homepages/(forust_files|xdfnx_files)/)'
|
||||||
|
)
|
||||||
|
|
||||||
|
if [ "${#prettier_files[@]}" -eq 0 ]; then
|
||||||
|
echo "No Prettier-managed files found."
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
docker run --rm \
|
||||||
|
-v "$PWD:/work" \
|
||||||
|
-w /work \
|
||||||
|
node:22-alpine \
|
||||||
|
sh -lc 'npx --yes prettier@3 --check --ignore-unknown "$@"' sh "${prettier_files[@]}"
|
||||||
|
|
||||||
|
lint-ruff:
|
||||||
|
runs-on: [self-hosted, linux, arch, homelab]
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Lint Python with Ruff
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
docker run --rm \
|
||||||
|
-v "$PWD:/work" \
|
||||||
|
-w /work \
|
||||||
|
ghcr.io/astral-sh/ruff:latest \
|
||||||
|
check .
|
||||||
|
|
||||||
|
lint-yaml:
|
||||||
|
runs-on: [self-hosted, linux, arch, homelab]
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Lint YAML syntax
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
docker run --rm \
|
||||||
|
-v "$PWD:/work" \
|
||||||
|
-w /work \
|
||||||
|
cytopia/yamllint:latest \
|
||||||
|
-c .yamllint .
|
||||||
|
|
||||||
|
lint-dockerfiles:
|
||||||
|
runs-on: [self-hosted, linux, arch, homelab]
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Lint Dockerfiles
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
mapfile -t dockerfiles < <(
|
||||||
|
git ls-files ':(glob)**/Dockerfile' ':(glob)**/Dockerfile.*'
|
||||||
|
)
|
||||||
|
|
||||||
|
if [ "${#dockerfiles[@]}" -eq 0 ]; then
|
||||||
|
echo "No Dockerfiles found."
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
docker run --rm \
|
||||||
|
-v "$PWD:/work" \
|
||||||
|
-w /work \
|
||||||
|
--entrypoint hadolint \
|
||||||
|
hadolint/hadolint:latest-debian \
|
||||||
|
-c .hadolint.yaml "${dockerfiles[@]}"
|
||||||
|
|
||||||
|
validate:
|
||||||
|
runs-on: [self-hosted, linux, arch, homelab]
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Validate Kubernetes manifests
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
mapfile -t manifests < <(
|
||||||
|
git ls-files ':(glob)**/k8s/**/*.yaml' ':(glob)**/k8s/**/*.yml' \
|
||||||
|
| grep -Ev '(^|/)(kustomization\.ya?ml|.*\.example\.ya?ml|.*values\.ya?ml|patch-.*\.ya?ml)$'
|
||||||
|
)
|
||||||
|
|
||||||
|
if [ "${#manifests[@]}" -eq 0 ]; then
|
||||||
|
echo "No Kubernetes manifests found."
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
docker run --rm \
|
||||||
|
-v "$PWD:/work" \
|
||||||
|
-w /work \
|
||||||
|
ghcr.io/yannh/kubeconform:latest \
|
||||||
|
-strict \
|
||||||
|
-ignore-missing-schemas \
|
||||||
|
-summary \
|
||||||
|
"${manifests[@]}"
|
||||||
|
|
||||||
|
build:
|
||||||
|
needs: [lint-prettier, lint-ruff, lint-yaml, lint-dockerfiles, validate]
|
||||||
|
if: github.event_name != 'pull_request' && (github.ref_name == 'main' || github.ref_name == 'dev')
|
||||||
|
runs-on: [self-hosted, linux, arch, homelab]
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
|
||||||
|
- name: Detect changed docker-built services
|
||||||
|
id: services
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
base="${{ github.event.before }}"
|
||||||
|
if [ -z "$base" ] || [ "$base" = "0000000000000000000000000000000000000000" ]; then
|
||||||
|
base="$(git rev-list --max-parents=0 HEAD)"
|
||||||
|
fi
|
||||||
|
|
||||||
|
mapfile -t changed_files < <(git diff --name-only "$base" "${GITHUB_SHA}")
|
||||||
|
|
||||||
|
services=()
|
||||||
|
|
||||||
|
add_service() {
|
||||||
|
local name="$1"
|
||||||
|
local seen=0
|
||||||
|
for existing in "${services[@]}"; do
|
||||||
|
if [ "$existing" = "$name" ]; then
|
||||||
|
seen=1
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
if [ "$seen" -eq 0 ]; then
|
||||||
|
services+=("$name")
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
for file in "${changed_files[@]}"; do
|
||||||
|
case "$file" in
|
||||||
|
dtek_notif/*)
|
||||||
|
add_service dtek_notif
|
||||||
|
;;
|
||||||
|
errorpages/*)
|
||||||
|
add_service errorpages
|
||||||
|
;;
|
||||||
|
userbot/*)
|
||||||
|
add_service userbot
|
||||||
|
;;
|
||||||
|
homepages/*)
|
||||||
|
add_service homepages
|
||||||
|
;;
|
||||||
|
edu_master/phpsessid-bot/*|edu_master/webinar-checker/*|edu_master/compose.yaml)
|
||||||
|
add_service edu_master
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
|
|
||||||
|
if [ "${#services[@]}" -eq 0 ]; then
|
||||||
|
echo "No docker-built services changed."
|
||||||
|
echo "services=" >> "$GITHUB_OUTPUT"
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
printf '%s\n' "${services[@]}" | tee /tmp/services.txt
|
||||||
|
echo "services=$(paste -sd, /tmp/services.txt)" >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
|
- name: Log in to registry
|
||||||
|
if: steps.services.outputs.services != ''
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
echo "${{ secrets.REGISTRY_PASSWORD }}" | docker login "${REGISTRY}" \
|
||||||
|
-u "${{ secrets.REGISTRY_USERNAME }}" \
|
||||||
|
--password-stdin
|
||||||
|
|
||||||
|
- name: Build and push changed images
|
||||||
|
if: steps.services.outputs.services != ''
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
IFS=, read -r -a services <<< "${{ steps.services.outputs.services }}"
|
||||||
|
|
||||||
|
for service in "${services[@]}"; do
|
||||||
|
case "$service" in
|
||||||
|
dtek_notif)
|
||||||
|
image="${REGISTRY}/forust/dtek-notif"
|
||||||
|
tags=("latest")
|
||||||
|
case "${GITHUB_REF_NAME}" in
|
||||||
|
main)
|
||||||
|
tags+=("main" "prod")
|
||||||
|
;;
|
||||||
|
dev)
|
||||||
|
tags+=("dev")
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
build_args=()
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
build_args+=(-t "${image}:${tag}")
|
||||||
|
done
|
||||||
|
docker build "${build_args[@]}" dtek_notif
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
docker push "${image}:${tag}"
|
||||||
|
done
|
||||||
|
;;
|
||||||
|
errorpages)
|
||||||
|
image="${REGISTRY}/forust/error-pages"
|
||||||
|
tags=("latest")
|
||||||
|
case "${GITHUB_REF_NAME}" in
|
||||||
|
main)
|
||||||
|
tags+=("main" "prod")
|
||||||
|
;;
|
||||||
|
dev)
|
||||||
|
tags+=("dev")
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
build_args=()
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
build_args+=(-t "${image}:${tag}")
|
||||||
|
done
|
||||||
|
docker build "${build_args[@]}" errorpages
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
docker push "${image}:${tag}"
|
||||||
|
done
|
||||||
|
;;
|
||||||
|
userbot)
|
||||||
|
image="${REGISTRY}/forust/userbot"
|
||||||
|
tags=("latest")
|
||||||
|
case "${GITHUB_REF_NAME}" in
|
||||||
|
main)
|
||||||
|
tags+=("main" "prod")
|
||||||
|
;;
|
||||||
|
dev)
|
||||||
|
tags+=("dev")
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
build_args=()
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
build_args+=(-t "${image}:${tag}")
|
||||||
|
done
|
||||||
|
docker build "${build_args[@]}" userbot
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
docker push "${image}:${tag}"
|
||||||
|
done
|
||||||
|
;;
|
||||||
|
homepages)
|
||||||
|
for service in forust xdfnx; do
|
||||||
|
case "$service" in
|
||||||
|
forust)
|
||||||
|
image="${REGISTRY}/forust/forust-homepage"
|
||||||
|
;;
|
||||||
|
xdfnx)
|
||||||
|
image="${REGISTRY}/forust/xdfnx-homepage"
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
tags=("latest")
|
||||||
|
case "${GITHUB_REF_NAME}" in
|
||||||
|
main)
|
||||||
|
tags+=("main" "prod")
|
||||||
|
;;
|
||||||
|
dev)
|
||||||
|
tags+=("dev")
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
build_args=()
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
build_args+=(-t "${image}:${tag}")
|
||||||
|
done
|
||||||
|
docker build "${build_args[@]}" -f "homepages/Dockerfile.${service}" homepages
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
docker push "${image}:${tag}"
|
||||||
|
done
|
||||||
|
done
|
||||||
|
;;
|
||||||
|
edu_master)
|
||||||
|
for service in session-keeper webinar-checker; do
|
||||||
|
case "$service" in
|
||||||
|
session-keeper)
|
||||||
|
context="edu_master/phpsessid-bot"
|
||||||
|
image="${REGISTRY}/forust/session-keeper"
|
||||||
|
;;
|
||||||
|
webinar-checker)
|
||||||
|
context="edu_master/webinar-checker"
|
||||||
|
image="${REGISTRY}/forust/webinar-checker"
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
tags=("latest")
|
||||||
|
case "${GITHUB_REF_NAME}" in
|
||||||
|
main)
|
||||||
|
tags+=("main" "prod")
|
||||||
|
;;
|
||||||
|
dev)
|
||||||
|
tags+=("dev")
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
build_args=()
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
build_args+=(-t "${image}:${tag}")
|
||||||
|
done
|
||||||
|
docker build "${build_args[@]}" "$context"
|
||||||
|
for tag in "${tags[@]}"; do
|
||||||
|
docker push "${image}:${tag}"
|
||||||
|
done
|
||||||
|
done
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
+91
-11
@@ -2,27 +2,107 @@
|
|||||||
sync.ffs_lock
|
sync.ffs_lock
|
||||||
.sync.ffs_db
|
.sync.ffs_db
|
||||||
|
|
||||||
# Environment
|
# Copyparty
|
||||||
.env
|
*.hist/
|
||||||
.env.anna
|
|
||||||
.env.forust
|
|
||||||
|
|
||||||
# Volumes and data directories
|
# Volumes, configs and data directories
|
||||||
gitea/gitea-db/*
|
gitea/gitea-db/
|
||||||
gitea/gitea-data/*
|
gitea/gitea-data/*
|
||||||
n8n/n8n-data/*
|
n8n/n8n-data/*
|
||||||
n8n/n8n-node-data/*
|
n8n/n8n-node-data/*
|
||||||
adguardhome/data/*
|
adguardhome/conf/*
|
||||||
dockmon/data/*
|
dockmon/data/*
|
||||||
portainer/portainer_data/*
|
portainer/portainer_data/*
|
||||||
metube/MeTube_downloads
|
metube/MeTube_downloads
|
||||||
|
uptime-kuma/data/
|
||||||
|
termix/termix-data/*
|
||||||
|
cfddns/config.json
|
||||||
|
checkmk/checkmk/*
|
||||||
|
downtify/Downtify_downloads
|
||||||
|
headscale/config/*
|
||||||
|
headscale/data/*
|
||||||
|
searxng/core-config/*
|
||||||
|
|
||||||
|
# Steaming services files
|
||||||
|
streaming/jellyfin/*
|
||||||
|
streaming/jellyseerr/*
|
||||||
|
streaming/sonarr/*
|
||||||
|
streaming/radarr/*
|
||||||
|
streaming/data/*
|
||||||
|
streaming/qbittorrent/*
|
||||||
|
streaming/prowlarr/*
|
||||||
|
|
||||||
|
# Homepage
|
||||||
|
homepages/forust_files/.well-known/*
|
||||||
|
|
||||||
# Traefik files
|
# Traefik files
|
||||||
traefik/letsencrypt/acme.json
|
traefik/letsencrypt/acme.json
|
||||||
traefik/logs/*
|
traefik/dynamic/fileservers.yml
|
||||||
traefik/certs/*
|
traefik/dynamic/*.local.y*ml.*
|
||||||
|
traefik/dynamic/*.external.y*ml
|
||||||
|
traefik/k8s/fileservers.y*ml
|
||||||
|
|
||||||
# Python
|
traefik/logs/*
|
||||||
|
|
||||||
|
# SSL Certificates
|
||||||
|
adguardhome/certs/*
|
||||||
|
traefik/certs/*
|
||||||
|
certs/
|
||||||
|
|
||||||
|
# Monitoring
|
||||||
|
monitoring/prometheus.yml
|
||||||
|
|
||||||
|
# Python
|
||||||
.python-version
|
.python-version
|
||||||
.venv/
|
|
||||||
venv/
|
venv/
|
||||||
|
pyc
|
||||||
|
unknown_errors.txt
|
||||||
|
moonlogs.txt
|
||||||
|
thumb.jpg
|
||||||
|
antipm_pic.jpg
|
||||||
|
musicbot/
|
||||||
|
.trunk/
|
||||||
|
previous_profiles/
|
||||||
|
.python-version
|
||||||
|
/modules/__pycache__/
|
||||||
|
__pycache__/
|
||||||
|
*.session
|
||||||
|
*.session-old
|
||||||
|
*.db
|
||||||
|
*.sqlite3
|
||||||
|
*-journal
|
||||||
|
/venv/
|
||||||
|
.venv/
|
||||||
|
|
||||||
|
# DataSecurity
|
||||||
|
replacements.txt
|
||||||
|
|
||||||
|
# Vscode
|
||||||
|
.vscode
|
||||||
|
|
||||||
|
# Git
|
||||||
|
.gitattributes
|
||||||
|
# Gitea/github Runners
|
||||||
|
.runner
|
||||||
|
|
||||||
|
# Misc
|
||||||
|
.DS_Store
|
||||||
|
.idea
|
||||||
|
|
||||||
|
# Temp files
|
||||||
|
edu_master/temp/
|
||||||
|
temp/*
|
||||||
|
|
||||||
|
# Environment
|
||||||
|
.env
|
||||||
|
.env.anna
|
||||||
|
.env.forust
|
||||||
|
.env.*
|
||||||
|
!*example
|
||||||
|
|
||||||
|
# kubernetes
|
||||||
|
*/k8s/*secret*
|
||||||
|
!*/k8s/*secret*.example
|
||||||
|
traefik/k8s/local-tls.yaml
|
||||||
|
converters/k8s/config.yaml
|
||||||
|
convertx/k8s/config.yaml
|
||||||
|
|||||||
@@ -0,0 +1,10 @@
|
|||||||
|
ignored:
|
||||||
|
- DL3008
|
||||||
|
- DL3042
|
||||||
|
- DL3018
|
||||||
|
- DL3059
|
||||||
|
trustedRegistries:
|
||||||
|
- docker.io
|
||||||
|
- ghcr.io
|
||||||
|
- quay.io
|
||||||
|
- gcr.forust.xyz
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
{
|
||||||
|
"default": true,
|
||||||
|
"MD013": false,
|
||||||
|
"MD024": false,
|
||||||
|
"MD033": false,
|
||||||
|
"MD041": false,
|
||||||
|
"MD046": false
|
||||||
|
}
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
bracketSameLine: true
|
||||||
|
htmlWhitespaceSensitivity: css
|
||||||
|
printWidth: 120
|
||||||
|
tabWidth: 2
|
||||||
|
trailingComma: all
|
||||||
|
proseWrap: preserve
|
||||||
|
endOfLine: lf
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
extends: default
|
||||||
|
|
||||||
|
rules:
|
||||||
|
comments:
|
||||||
|
min-spaces-from-content: 1
|
||||||
|
comments-indentation: false
|
||||||
|
document-start: disable
|
||||||
|
line-length: disable
|
||||||
|
braces:
|
||||||
|
min-spaces-inside: 0
|
||||||
|
max-spaces-inside: 1
|
||||||
|
brackets:
|
||||||
|
min-spaces-inside: 0
|
||||||
|
max-spaces-inside: 1
|
||||||
|
indentation:
|
||||||
|
spaces: 2
|
||||||
|
indent-sequences: consistent
|
||||||
|
truthy:
|
||||||
|
allowed-values:
|
||||||
|
- "true"
|
||||||
|
- "false"
|
||||||
|
- "on"
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
{
|
||||||
|
"tab_size": 2,
|
||||||
|
"soft_wrap": "prefer_line",
|
||||||
|
"preferred_line_length": 120,
|
||||||
|
"format_on_save": "on",
|
||||||
|
"languages": {
|
||||||
|
"YAML": {
|
||||||
|
"tab_size": 2,
|
||||||
|
"hard_tabs": false,
|
||||||
|
"format_on_save": "on",
|
||||||
|
"formatter": {
|
||||||
|
"language_server": { "name": "yaml-language-server" },
|
||||||
|
},
|
||||||
|
},
|
||||||
|
"Python": {
|
||||||
|
"tab_size": 4,
|
||||||
|
"format_on_save": "on",
|
||||||
|
"language_servers": ["pyright", "ruff"],
|
||||||
|
"formatter": {
|
||||||
|
"language_server": { "name": "ruff" },
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
"lsp": {
|
||||||
|
"yaml-language-server": {
|
||||||
|
"settings": {
|
||||||
|
"yaml": {
|
||||||
|
"schemas": {
|
||||||
|
"kubernetes": ["**/k8s/*.yaml", "**/k8s/*.yml"],
|
||||||
|
},
|
||||||
|
"validate": true,
|
||||||
|
"completion": true,
|
||||||
|
"format": {
|
||||||
|
"enable": true,
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
}
|
||||||
+31
-11
@@ -3,26 +3,46 @@ services:
|
|||||||
image: adguard/adguardhome:latest
|
image: adguard/adguardhome:latest
|
||||||
container_name: adguardhome
|
container_name: adguardhome
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
environment:
|
|
||||||
- TZ=${TZ}
|
|
||||||
ports:
|
ports:
|
||||||
- "53:53/tcp"
|
- "53:53/tcp"
|
||||||
- "53:53/udp"
|
- "53:53/udp"
|
||||||
|
- "853:853/tcp" # DNS over TLS
|
||||||
# - "67:67/udp" # DHCP
|
# - "67:67/udp" # DHCP
|
||||||
# - "68:68/tcp" # DHCP
|
# - "68:68/tcp" # DHCP
|
||||||
- "3000:3000/tcp"
|
# - "3000:3000/tcp"
|
||||||
volumes:
|
volumes:
|
||||||
- ./data/work:/opt/adguardhome/work
|
- data:/opt/adguardhome/work
|
||||||
- ./data/conf:/opt/adguardhome/conf
|
- ./conf:/opt/adguardhome/conf
|
||||||
networks:
|
- ./certs:/certs:ro
|
||||||
- traefik-proxy
|
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=traefik-proxy"
|
- "traefik.http.services.adguard.loadbalancer.server.port=3000"
|
||||||
|
|
||||||
|
# Prod Router
|
||||||
|
- "traefik.http.routers.adguard.rule=Host(`dns.forust.xyz`) || Host(`adguard.forust.xyz`)"
|
||||||
|
- "traefik.http.routers.adguard.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.adguard.tls.certresolver=letsencrypt"
|
||||||
|
# Local Router
|
||||||
|
- "traefik.http.routers.adguard-local.rule=Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`)"
|
||||||
|
- "traefik.http.routers.adguard-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.adguard-local.tls=true"
|
||||||
|
# Dev Router
|
||||||
|
- "traefik.http.routers.adguard-dev.rule=Host(`adguard.gigaforust.internal`) || Host(`dns.gigaforust.internal`)"
|
||||||
|
- "traefik.http.routers.adguard-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.adguard-dev.tls=true"
|
||||||
|
# DoH Router
|
||||||
|
- "traefik.http.routers.dns-over-https.rule=(Host(`dns.forust.xyz` || Host(`adguard.forust.xyz`)) && PathPrefix(`/dns-query`))"
|
||||||
|
- "traefik.http.routers.dns-over-https.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.dns-over-https.tls.certresolver=letsencrypt"
|
||||||
|
|
||||||
|
# Glance Metadata
|
||||||
- glance.name=adguard
|
- glance.name=adguard
|
||||||
# - glance.icon=si:adguard
|
|
||||||
- glance.url=https://adguard.forust.xyz/
|
- glance.url=https://adguard.forust.xyz/
|
||||||
- glance.description=AdGuard Home is a network-wide software for blocking ads.
|
- glance.description=AdGuard Home is a network-wide software for blocking ads.
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
|
volumes:
|
||||||
|
data:
|
||||||
networks:
|
networks:
|
||||||
traefik-proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -0,0 +1,116 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: adguard-lb-service
|
||||||
|
namespace: adguard
|
||||||
|
annotations:
|
||||||
|
metallb.io/loadBalancerIPs: "192.168.80.3"
|
||||||
|
spec:
|
||||||
|
type: LoadBalancer
|
||||||
|
externalTrafficPolicy: Local
|
||||||
|
selector:
|
||||||
|
app: adguard
|
||||||
|
ports:
|
||||||
|
- name: dns-udp
|
||||||
|
port: 53
|
||||||
|
targetPort: 53
|
||||||
|
protocol: UDP
|
||||||
|
- name: dns-tcp
|
||||||
|
port: 53
|
||||||
|
targetPort: 53
|
||||||
|
protocol: TCP
|
||||||
|
- name: dot
|
||||||
|
port: 853
|
||||||
|
targetPort: 853
|
||||||
|
protocol: TCP
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: adguard-service
|
||||||
|
namespace: adguard
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: adguard
|
||||||
|
ports:
|
||||||
|
- port: 3000
|
||||||
|
name: webui
|
||||||
|
targetPort: 3000
|
||||||
|
- port: 53
|
||||||
|
name: dns
|
||||||
|
targetPort: 53
|
||||||
|
protocol: UDP
|
||||||
|
- port: 53
|
||||||
|
name: dns-tcp
|
||||||
|
targetPort: 53
|
||||||
|
protocol: TCP
|
||||||
|
- port: 853
|
||||||
|
name: dot
|
||||||
|
targetPort: 853
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: adguard-deployment
|
||||||
|
namespace: adguard
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: adguard
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: adguard
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: adguard
|
||||||
|
image: adguard/adguardhome:latest
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
memory: "1.5Gi"
|
||||||
|
cpu: "300m"
|
||||||
|
requests:
|
||||||
|
memory: "500Mi"
|
||||||
|
cpu: "50m"
|
||||||
|
ports:
|
||||||
|
- containerPort: 3000
|
||||||
|
name: webui
|
||||||
|
- containerPort: 53
|
||||||
|
name: dns
|
||||||
|
- containerPort: 853
|
||||||
|
name: dot
|
||||||
|
volumeMounts:
|
||||||
|
- name: adguard-data
|
||||||
|
mountPath: /opt/adguardhome/work
|
||||||
|
subPath: work
|
||||||
|
- name: adguard-data
|
||||||
|
mountPath: /opt/adguardhome/conf
|
||||||
|
subPath: conf
|
||||||
|
- name: adguard-certs
|
||||||
|
mountPath: /certs
|
||||||
|
readOnly: true
|
||||||
|
volumes:
|
||||||
|
- name: adguard-data
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: adguard-pvc
|
||||||
|
- name: adguard-certs
|
||||||
|
secret:
|
||||||
|
secretName: adguard-certs
|
||||||
|
items:
|
||||||
|
- key: tls.crt
|
||||||
|
path: fullchain.pem
|
||||||
|
- key: tls.key
|
||||||
|
path: privkey.pem
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
metadata:
|
||||||
|
name: adguard-pvc
|
||||||
|
namespace: adguard
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 2Gi
|
||||||
@@ -0,0 +1,43 @@
|
|||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: adguard-prod
|
||||||
|
namespace: adguard
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: Host(`adguard.forust.xyz`) || Host(`dns.forust.xyz`)
|
||||||
|
kind: Rule
|
||||||
|
middlewares:
|
||||||
|
services:
|
||||||
|
- name: adguard-service
|
||||||
|
port: 3000
|
||||||
|
- match: (Host(`adguard.forust.xyz`) || Host(`dns.forust.xyz`)) && PathPrefix(`/dns-query`)
|
||||||
|
kind: Rule
|
||||||
|
middlewares:
|
||||||
|
services:
|
||||||
|
- name: adguard-service
|
||||||
|
port: 3000
|
||||||
|
tls:
|
||||||
|
certResolver: letsencrypt
|
||||||
|
---
|
||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: adguard-local
|
||||||
|
namespace: adguard
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`) || Host(`adguard.gigaforust.internal`) || Host(`dns.gigaforust.internal`)
|
||||||
|
kind: Rule
|
||||||
|
services:
|
||||||
|
- name: adguard-service
|
||||||
|
port: 3000
|
||||||
|
- match: (Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`) || Host(`adguard.gigaforust.internal`) || Host(`dns.gigaforust.internal`)) && PathPrefix(`/dns-query`)
|
||||||
|
kind: Rule
|
||||||
|
services:
|
||||||
|
- name: adguard-service
|
||||||
|
port: 3000
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: adguard
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
kubectl apply -f k8s/namespace.yaml && \
|
||||||
|
kubectl create secret tls adguard-certs -n adguard \
|
||||||
|
--cert=certs/fullchain.pem \
|
||||||
|
--key=certs/privkey.pem --dry-run=client -o yaml > \
|
||||||
|
k8s/secrets.yaml
|
||||||
|
|
||||||
|
# OR WITH NO FILE CREATION:
|
||||||
|
kubectl create secret tls adguard-certs -n adguard \
|
||||||
|
--cert=certs/fullchain.pem --key=certs/privkey.pem \
|
||||||
|
--save-config
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
# ===================================
|
||||||
|
# Authentification app (authentik)
|
||||||
|
|
||||||
|
# PostgresQL conf
|
||||||
|
PG_PASS=change_this_cuz_its_ur_db_pass
|
||||||
|
PG_USER=authentik # it's okay
|
||||||
|
|
||||||
|
# Image Settings
|
||||||
|
AUTHENTIK_IMAGE=ghcr.io/goauthentik/server
|
||||||
|
AUTHENTIK_TAG=2025.10.2
|
||||||
|
|
||||||
|
# Networking
|
||||||
|
PORT_HTTP=9000
|
||||||
|
PORT_HTTPS=9443 # btw likely already used by portainer
|
||||||
|
|
||||||
|
AUTHENTIK_SECRET_KEY=super_secret_super_scary_authenik_key
|
||||||
|
|
||||||
|
AUTHENTIK_BOOTSTRAP_PASSWORD=pls_change_this
|
||||||
|
|
||||||
|
AUTHENTIK_ERROR_REPORTING__ENABLED=true # Or false to turn off
|
||||||
@@ -0,0 +1,95 @@
|
|||||||
|
services:
|
||||||
|
postgresql:
|
||||||
|
image: docker.io/library/postgres:15-alpine
|
||||||
|
restart: unless-stopped
|
||||||
|
env_file:
|
||||||
|
- .env
|
||||||
|
environment:
|
||||||
|
POSTGRES_DB: ${PG_DB:-authentik}
|
||||||
|
POSTGRES_PASSWORD: ${PG_PASS:?database password required}
|
||||||
|
POSTGRES_USER: ${PG_USER:-authentik}
|
||||||
|
healthcheck:
|
||||||
|
interval: 30s
|
||||||
|
retries: 5
|
||||||
|
start_period: 20s
|
||||||
|
test:
|
||||||
|
- CMD-SHELL
|
||||||
|
- pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}
|
||||||
|
timeout: 5s
|
||||||
|
volumes:
|
||||||
|
- database:/var/lib/postgresql/data
|
||||||
|
networks:
|
||||||
|
- authentik
|
||||||
|
|
||||||
|
server:
|
||||||
|
image: ${AUTHENTIK_IMAGE:-ghcr.io/goauthentik/server}:${AUTHENTIK_TAG:-2025.10.2}
|
||||||
|
command: server
|
||||||
|
container_name: authentik-server
|
||||||
|
restart: unless-stopped
|
||||||
|
# ports:
|
||||||
|
# - ${PORT_HTTP:-9000}:9000
|
||||||
|
# - ${PORT_HTTPS:-9443}:9443
|
||||||
|
env_file:
|
||||||
|
- .env
|
||||||
|
environment:
|
||||||
|
AUTHENTIK_POSTGRESQL__HOST: postgresql
|
||||||
|
AUTHENTIK_POSTGRESQL__NAME: ${PG_DB:-authentik}
|
||||||
|
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
|
||||||
|
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
|
||||||
|
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
||||||
|
volumes:
|
||||||
|
- ./media:/media
|
||||||
|
- ./custom-templates:/templates
|
||||||
|
labels:
|
||||||
|
- "traefik.enable=true"
|
||||||
|
- "traefik.http.services.authentik-server.loadbalancer.server.port=9000"
|
||||||
|
|
||||||
|
# Prod Router
|
||||||
|
- "traefik.http.routers.authentik-server.rule=Host(`auth.forust.xyz`)"
|
||||||
|
- "traefik.http.routers.authentik-server.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.authentik-server.tls.certresolver=letsencrypt"
|
||||||
|
# Local Router
|
||||||
|
- "traefik.http.routers.authentik-server-local.rule=Host(`auth.workstation.internal`)"
|
||||||
|
- "traefik.http.routers.authentik-server-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.authentik-server-local.tls=true"
|
||||||
|
# Dev Router
|
||||||
|
- "traefik.http.routers.authentik-server-dev.rule=Host(`auth.gigaforust.internal`)"
|
||||||
|
- "traefik.http.routers.authentik-server-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.authentik-server-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.authentik-server-dev.tls=true"
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
|
- authentik
|
||||||
|
depends_on:
|
||||||
|
postgresql:
|
||||||
|
condition: service_healthy
|
||||||
|
worker:
|
||||||
|
image: ${AUTHENTIK_IMAGE:-ghcr.io/goauthentik/server}:${AUTHENTIK_TAG:-2025.10.2}
|
||||||
|
restart: unless-stopped
|
||||||
|
user: root
|
||||||
|
command: worker
|
||||||
|
env_file:
|
||||||
|
- .env
|
||||||
|
environment:
|
||||||
|
AUTHENTIK_POSTGRESQL__HOST: postgresql
|
||||||
|
AUTHENTIK_POSTGRESQL__NAME: ${PG_DB:-authentik}
|
||||||
|
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
|
||||||
|
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
|
||||||
|
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
||||||
|
volumes:
|
||||||
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
|
- ./media:/media
|
||||||
|
- ./certs:/certs
|
||||||
|
- ./custom-templates:/templates
|
||||||
|
networks:
|
||||||
|
- authentik
|
||||||
|
depends_on:
|
||||||
|
postgresql:
|
||||||
|
condition: service_healthy
|
||||||
|
volumes:
|
||||||
|
database:
|
||||||
|
driver: local
|
||||||
|
networks:
|
||||||
|
authentik:
|
||||||
|
proxy:
|
||||||
|
external: true
|
||||||
@@ -0,0 +1,93 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: authentik-server-service
|
||||||
|
namespace: authentik
|
||||||
|
spec:
|
||||||
|
type: ClusterIP
|
||||||
|
selector:
|
||||||
|
app: authentik-server
|
||||||
|
ports:
|
||||||
|
- port: 9000
|
||||||
|
targetPort: 9000
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: authentik-worker-service
|
||||||
|
namespace: authentik
|
||||||
|
spec:
|
||||||
|
type: ClusterIP
|
||||||
|
selector:
|
||||||
|
app: authentik-worker
|
||||||
|
ports:
|
||||||
|
- port: 9000
|
||||||
|
targetPort: 9000
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: authentik-server-deployment
|
||||||
|
namespace: authentik
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: authentik-server
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: authentik-server
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: authentik-server
|
||||||
|
image: ghcr.io/goauthentik/server:2025.10.2
|
||||||
|
args: ["server"]
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: authentik-config
|
||||||
|
- secretRef:
|
||||||
|
name: authentik-secrets
|
||||||
|
ports:
|
||||||
|
- containerPort: 9000
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "700Mi"
|
||||||
|
cpu: "300m"
|
||||||
|
limits:
|
||||||
|
memory: "1.5Gi"
|
||||||
|
cpu: "1000m"
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: authentik-worker-deployment
|
||||||
|
namespace: authentik
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: authentik-worker
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: authentik-worker
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: authentik-worker
|
||||||
|
image: ghcr.io/goauthentik/server:2025.10.2
|
||||||
|
args: ["worker"]
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 0
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: authentik-config
|
||||||
|
- secretRef:
|
||||||
|
name: authentik-secrets
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "512Mi"
|
||||||
|
cpu: "300m"
|
||||||
|
limits:
|
||||||
|
memory: "1Gi"
|
||||||
|
cpu: "700m"
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: authentik-config
|
||||||
|
namespace: authentik
|
||||||
|
data:
|
||||||
|
AUTHENTIK_IMAGE: ghcr.io/goauthentik/server
|
||||||
|
AUTHENTIK_TAG: "2025.10.2"
|
||||||
|
AUTHENTIK_POSTGRESQL__HOST: authentik-postgres-service
|
||||||
|
AUTHENTIK_POSTGRESQL__NAME: authentik
|
||||||
|
AUTHENTIK_ERROR_REPORTING__ENABLED: "true"
|
||||||
@@ -0,0 +1,32 @@
|
|||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: authentik-prod
|
||||||
|
namespace: authentik
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: Host(`auth.forust.xyz`)
|
||||||
|
kind: Rule
|
||||||
|
middlewares:
|
||||||
|
services:
|
||||||
|
- name: authentik-server-service
|
||||||
|
port: 9000
|
||||||
|
tls:
|
||||||
|
certResolver: letsencrypt
|
||||||
|
---
|
||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: authentik-local
|
||||||
|
namespace: authentik
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: Host(`auth.workstation.internal`) || Host(`auth.gigaforust.internal`)
|
||||||
|
kind: Rule
|
||||||
|
services:
|
||||||
|
- name: authentik-server-service
|
||||||
|
port: 9000
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: authentik
|
||||||
@@ -0,0 +1,66 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: authentik-postgres-service
|
||||||
|
namespace: authentik
|
||||||
|
spec:
|
||||||
|
clusterIP: None
|
||||||
|
selector:
|
||||||
|
app: authentik-postgres
|
||||||
|
ports:
|
||||||
|
- port: 5432
|
||||||
|
targetPort: 5432
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: StatefulSet
|
||||||
|
metadata:
|
||||||
|
name: authentik-postgres-statefulset
|
||||||
|
namespace: authentik
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: authentik-postgres
|
||||||
|
serviceName: authentik-postgres-service
|
||||||
|
replicas: 1
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: authentik-postgres
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: postgres
|
||||||
|
image: docker.io/library/postgres:15-alpine
|
||||||
|
env:
|
||||||
|
- name: POSTGRES_DB
|
||||||
|
value: authentik
|
||||||
|
- name: POSTGRES_USER
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: authentik-secrets
|
||||||
|
key: AUTHENTIK_POSTGRESQL__USER
|
||||||
|
- name: POSTGRES_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: authentik-secrets
|
||||||
|
key: AUTHENTIK_POSTGRESQL__PASSWORD
|
||||||
|
ports:
|
||||||
|
- containerPort: 5432
|
||||||
|
name: postgres
|
||||||
|
volumeMounts:
|
||||||
|
- name: postgres-data
|
||||||
|
mountPath: /var/lib/postgresql/data
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "256Mi"
|
||||||
|
cpu: "200m"
|
||||||
|
limits:
|
||||||
|
memory: "1Gi"
|
||||||
|
cpu: "500m"
|
||||||
|
volumeClaimTemplates:
|
||||||
|
- metadata:
|
||||||
|
name: postgres-data
|
||||||
|
spec:
|
||||||
|
accessModes: ["ReadWriteOnce"]
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 5Gi
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: authentik-secrets
|
||||||
|
namespace: authentik
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
AUTHENTIK_SECRET_KEY: ""
|
||||||
|
AUTHENTIK_POSTGRESQL__PASSWORD: ""
|
||||||
|
AUTHENTIK_POSTGRESQL__USER: authentik
|
||||||
|
AUTHENTIK_BOOTSTRAP_PASSWORD: authentik
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
CLOUDFLARE_API_TOKEN=YOUR_CLOUDFLARE_API_TOKEN
|
||||||
|
DOMAINS=example.com,dns.example.com,mc.example.com,auth.example.com,ssh.example.com
|
||||||
|
IP4_DOMAINS=
|
||||||
|
IP6_DOMAINS=
|
||||||
|
IP4_PROVIDER=cloudflare.trace
|
||||||
|
IP6_PROVIDER=none # change if you want to update AAAA
|
||||||
|
UPDATE_CRON=@every 5m
|
||||||
|
UPDATE_ON_START=true
|
||||||
|
DELETE_ON_STOP=false
|
||||||
|
DELETE_ON_FAILURE=true
|
||||||
|
TTL=1
|
||||||
|
PROXIED=!is(dns.example.com) && !is(mc.example.com) && !is(ssh.example.com)
|
||||||
|
EMOJI=true
|
||||||
|
UPTIMEKUMA=https://uptime-kuma.example.com/api/push/AsaSDFGFkfklaFALSKffkfFKfkfkfkFK?status=up&msg=OK&ping=
|
||||||
|
REJECT_CLOUDFLARE_IPS=true
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
services:
|
||||||
|
cloudflare-ddns:
|
||||||
|
image: timothyjmiller/cloudflare-ddns:latest
|
||||||
|
container_name: cloudflare-ddns
|
||||||
|
restart: unless-stopped
|
||||||
|
security_opt:
|
||||||
|
- no-new-privileges:true
|
||||||
|
network_mode: "host"
|
||||||
|
# https://github.com/timothymiller/cloudflare-ddns#-quick-start
|
||||||
|
environment:
|
||||||
|
- CLOUDFLARE_API_TOKEN=${CLOUDFLARE_API_TOKEN:?Cloudflare API token is required}
|
||||||
|
- DOMAINS=${DOMAINS:-}
|
||||||
|
- IP4_DOMAINS=${IP4_DOMAINS:-}
|
||||||
|
- IP6_DOMAINS=${IP6_DOMAINS:-}
|
||||||
|
- IP4_PROVIDER=${IP4_PROVIDER:-cloudflare.trace}
|
||||||
|
- IP6_PROVIDER=${IP6_PROVIDER:-none}
|
||||||
|
- UPDATE_CRON=${UPDATE_CRON:-@every 5m}
|
||||||
|
- UPDATE_ON_START=${UPDATE_ON_START:-true}
|
||||||
|
- DELETE_ON_STOP=${DELETE_ON_STOP:-false}
|
||||||
|
- DELETE_ON_FAILURE=${DELETE_ON_FAILURE:-true}
|
||||||
|
- TTL=${TTL:-1} # 1=auto
|
||||||
|
# to proxy only "dns.example.com" and "wfs.example.com" use "!is(dns.domain.com) && !is (wfs.domain.com)"
|
||||||
|
- PROXIED=${PROXIED:-true}
|
||||||
|
- EMOJI=${EMOJI:-true}
|
||||||
|
- UPTIMEKUMA=${UPTIMEKUMA:-}
|
||||||
|
- HEALTHCHECKS=${HEALTHCHECKS:-}
|
||||||
|
- REJECT_CLOUDFLARE_IPS=${REJECT_CLOUDFLARE_IPS:-true}
|
||||||
|
# volumes:
|
||||||
|
# Prefer using environment variables for configuration, config.json legacy support
|
||||||
|
# - ./config.json:/config.json
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
{
|
||||||
|
"cloudflare": [
|
||||||
|
{
|
||||||
|
"authentication": {
|
||||||
|
"api_token": "API_TOKEN"
|
||||||
|
},
|
||||||
|
"api_key": {
|
||||||
|
"api_key": "api_key_here",
|
||||||
|
"account_email": "your_email_here"
|
||||||
|
},
|
||||||
|
"zone_id": "your_zone-id",
|
||||||
|
"subdomains": [
|
||||||
|
{ "name": "", "proxied": true },
|
||||||
|
{ "name": "www", "proxied": true }
|
||||||
|
]
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"a": true,
|
||||||
|
"aaaa": false,
|
||||||
|
"purgeUnknownRecords": false,
|
||||||
|
"ttl": 300
|
||||||
|
}
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
secret.yaml
|
||||||
@@ -0,0 +1,32 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: cfddns
|
||||||
|
labels:
|
||||||
|
app: cfddns
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: cfddns
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: cfddns
|
||||||
|
spec:
|
||||||
|
hostNetwork: true
|
||||||
|
dnsPolicy: ClusterFirstWithHostNet
|
||||||
|
containers:
|
||||||
|
- name: cloudflare-ddns
|
||||||
|
image: timothyjmiller/cloudflare-ddns:latest
|
||||||
|
imagePullPolicy: Always
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "20Mi"
|
||||||
|
cpu: "30m"
|
||||||
|
limits:
|
||||||
|
memory: "64Mi"
|
||||||
|
cpu: "50m"
|
||||||
|
envFrom:
|
||||||
|
- secretRef:
|
||||||
|
name: cfddns-secrets
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: cfddns-secrets
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
CLOUDFLARE_API_TOKEN: your_token
|
||||||
|
DOMAINS: "example.com,www.example.com"
|
||||||
|
IP4_PROVIDER: cloudflare.trace
|
||||||
|
IP6_PROVIDER: none
|
||||||
|
UPDATE_CRON: "@every 5m"
|
||||||
|
UPDATE_ON_START: "true"
|
||||||
|
DELETE_ON_STOP: "false"
|
||||||
|
DELETE_ON_FAILURE: "true"
|
||||||
|
TTL: "1"
|
||||||
|
PROXIED: "true"
|
||||||
|
EMOJI: "true"
|
||||||
|
REJECT_CLOUDFLARE_IPS: "true"
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
CMK_PASSWORD=password
|
||||||
|
TZ=Europe/Berlin
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
services:
|
||||||
|
checkmk:
|
||||||
|
image: "checkmk/check-mk-raw:2.4.0-latest"
|
||||||
|
container_name: "checkmk"
|
||||||
|
restart: unless-stopped
|
||||||
|
# ports:
|
||||||
|
# - 5000:5000
|
||||||
|
# - 6776:8000
|
||||||
|
volumes:
|
||||||
|
- sites:/omd/sites
|
||||||
|
tmpfs:
|
||||||
|
- /opt/omd/sites/cmk/tmp:uid=1000,gid=1000
|
||||||
|
environment:
|
||||||
|
- CMK_PASSWORD=${CMK_PASSWORD:-password}
|
||||||
|
- CMK_SITE_ID=cmk
|
||||||
|
- TZ=${TZ:-Etc/UTC}
|
||||||
|
labels:
|
||||||
|
- "traefik.enable=true"
|
||||||
|
- "traefik.http.services.checkmk.loadbalancer.server.port=5000"
|
||||||
|
|
||||||
|
# Prod Router
|
||||||
|
- "traefik.http.routers.checkmk.rule=Host(`cmk.forust.xyz`)"
|
||||||
|
- "traefik.http.routers.checkmk.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.checkmk.tls.certresolver=letsencrypt"
|
||||||
|
# Local Router
|
||||||
|
- "traefik.http.routers.checkmk-local.rule=Host(`cmk.workstation.internal`)"
|
||||||
|
- "traefik.http.routers.checkmk-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.checkmk-local.tls=true"
|
||||||
|
# Dev Router
|
||||||
|
- "traefik.http.routers.checkmk-dev.rule=Host(`cmk.gigaforust.internal`)"
|
||||||
|
- "traefik.http.routers.checkmk-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.checkmk-dev.tls=true"
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
|
networks:
|
||||||
|
proxy:
|
||||||
|
external: true
|
||||||
|
volumes:
|
||||||
|
sites:
|
||||||
@@ -0,0 +1,68 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: checkmk-service
|
||||||
|
namespace: checkmk
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: checkmk
|
||||||
|
ports:
|
||||||
|
- port: 5000
|
||||||
|
targetPort: 5000
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: checkmk-deployment
|
||||||
|
namespace: checkmk
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: checkmk
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: checkmk
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: checkmk
|
||||||
|
image: checkmk/check-mk-raw:2.4.0-latest
|
||||||
|
envFrom:
|
||||||
|
- secretRef:
|
||||||
|
name: checkmk-secrets
|
||||||
|
- configMapRef:
|
||||||
|
name: checkmk-config
|
||||||
|
ports:
|
||||||
|
- containerPort: 5000
|
||||||
|
volumeMounts:
|
||||||
|
- name: sites
|
||||||
|
mountPath: /omd/sites
|
||||||
|
- name: tmp
|
||||||
|
mountPath: /opt/omd/sites/cmk/tmp
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "2Gi"
|
||||||
|
cpu: "600m"
|
||||||
|
limits:
|
||||||
|
memory: "5Gi"
|
||||||
|
cpu: "4"
|
||||||
|
volumes:
|
||||||
|
- name: sites
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: checkmk-sites-pvc
|
||||||
|
- name: tmp
|
||||||
|
emptyDir:
|
||||||
|
medium: Memory
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
metadata:
|
||||||
|
name: checkmk-sites-pvc
|
||||||
|
namespace: checkmk
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 5Gi
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: checkmk-config
|
||||||
|
namespace: checkmk
|
||||||
|
data:
|
||||||
|
TZ: Europe/Bratislava
|
||||||
|
CMK_SITE_ID: cmk
|
||||||
@@ -0,0 +1,32 @@
|
|||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: checkmk-prod
|
||||||
|
namespace: checkmk
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: Host(`cmk.forust.xyz`)
|
||||||
|
kind: Rule
|
||||||
|
middlewares:
|
||||||
|
services:
|
||||||
|
- name: checkmk-service
|
||||||
|
port: 5000
|
||||||
|
tls:
|
||||||
|
certResolver: letsencrypt
|
||||||
|
---
|
||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: checkmk-local
|
||||||
|
namespace: checkmk
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: Host(`cmk.workstation.internal`) || Host(`cmk.gigaforust.internal`)
|
||||||
|
kind: Rule
|
||||||
|
services:
|
||||||
|
- name: checkmk-service
|
||||||
|
port: 5000
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: checkmk
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: checkmk-secrets
|
||||||
|
namespace: checkmk
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
CMK_PASSWORD: "password"
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
ACCOUNT_REGISTRATION=false
|
||||||
|
HTTP_ALLOWED=false
|
||||||
|
ALLOW_UNAUTHENTICAED=false
|
||||||
|
AUTO_DELETE_EVERY_N_HOURS=24
|
||||||
|
WEBROOT=/convert
|
||||||
|
HIDE_HISTORY=false
|
||||||
|
LANGUAGE=en
|
||||||
|
UNAUTHED_USER_SHARING=false
|
||||||
|
MAX_CONVERT_PROCESS=0
|
||||||
@@ -0,0 +1,70 @@
|
|||||||
|
services:
|
||||||
|
convertx:
|
||||||
|
container_name: convertx
|
||||||
|
image: ghcr.io/c4illin/convertx:latest
|
||||||
|
restart: unless-stopped
|
||||||
|
ports:
|
||||||
|
- "9992:3000"
|
||||||
|
# https://github.com/C4illin/ConvertX#environment-variables
|
||||||
|
environment:
|
||||||
|
- JWT_SECRET=$(JWT_SECRET)
|
||||||
|
- ACCOUNT_REGISTRATION=$(ACCOUNT_REGISTRATION:-false)
|
||||||
|
- HTTP_ALLOWED=$(HTTP_ALLOWED:-false)
|
||||||
|
- ALLOW_UNAUTHENTICATED=$(ALLOW_UNAUTHENTICATED:-false)
|
||||||
|
- AUTO_DELETE_EVERY_N_HOURS=$(AUTO_DELETE_EVERY_N_HOURS:-24)
|
||||||
|
- WEBROOT=$(WEBROOT)
|
||||||
|
- HIDE_HISTORY=$(HIDE_HISTORY:-false)
|
||||||
|
- LANGUAGE=$(LANGUAGE:-en)
|
||||||
|
- UNAUTHENTICATED_USER_SHARING=$(UNAUTHENTICATED_USER_SHARING:-false)
|
||||||
|
- MAX_CONVERT_PROCESS=$(MAX_CONVERT_PROCESS:-0)
|
||||||
|
labels:
|
||||||
|
- "traefik.enable=true"
|
||||||
|
- "traefik.http.services.convertx.loadbalancer.server.port=3000"
|
||||||
|
# Prod Router
|
||||||
|
- "traefik.http.routers.convertx.rule=(Host(`forust.xyz`) || Host(`www.forust.xyz`)) && PathPrefix(`/convert`)"
|
||||||
|
- "traefik.http.routers.convertx.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.convertx.priority=50"
|
||||||
|
- "traefik.http.routers.convertx.tls.certresolver=letsencrypt"
|
||||||
|
# Local Router
|
||||||
|
- "traefik.http.routers.convertx-local.rule=Host(`workstation.internal`) && PathPrefix(`/convert`)"
|
||||||
|
- "traefik.http.routers.convertx-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.convertx-local.priority=50"
|
||||||
|
- "traefik.http.routers.convertx-local.tls=true"
|
||||||
|
# Dev Router
|
||||||
|
- "traefik.http.routers.convertx-dev.rule=Host(`gigaforust.internal`) && PathPrefix(`/convert`)"
|
||||||
|
- "traefik.http.routers.convertx-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.convertx-dev.priority=50"
|
||||||
|
- "traefik.http.routers.convertx-dev.tls=true"
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
|
volumes:
|
||||||
|
- data:/app/data
|
||||||
|
|
||||||
|
bentopdf:
|
||||||
|
container_name: bentopdf
|
||||||
|
image: bentopdf/bentopdf:latest
|
||||||
|
restart: unless-stopped
|
||||||
|
labels:
|
||||||
|
- "traefik.enable=true"
|
||||||
|
- "traefik.http.services.bentopdf.loadbalancer.server.port=8080"
|
||||||
|
|
||||||
|
# Prod router
|
||||||
|
- "traefik.http.routers.bentopdf.rule=Host(`pdf.forust.xyz`)"
|
||||||
|
- "traefik.http.routers.bentopdf.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.bentopdf.tls.certresolver=letsencrypt"
|
||||||
|
- "traefik.http.routers.bentopdf.tls=true"
|
||||||
|
# Local router
|
||||||
|
- "traefik.http.routers.bentopdf-local.rule=Host(`pdf.wokstation.internal`)"
|
||||||
|
- "traefik.http.routers.bentopdf-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.bentopdf-local.tls=true"
|
||||||
|
# Dev router
|
||||||
|
- "traefik.http.routers.bentopdf-dev.rule=Host(`pdf.gigaforust.internal`)"
|
||||||
|
- "traefik.http.routers.bentopdf-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.bentopdf-dev.tls=true"
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
|
networks:
|
||||||
|
proxy:
|
||||||
|
external: true
|
||||||
|
volumes:
|
||||||
|
data:
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
kind: Service
|
||||||
|
apiVersion: v1
|
||||||
|
metadata:
|
||||||
|
name: bentopdf-service
|
||||||
|
namespace: converters
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: bentopdf
|
||||||
|
ports:
|
||||||
|
- port: 8080
|
||||||
|
targetPort: 8080
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: bentopdf-deployment
|
||||||
|
namespace: converters
|
||||||
|
spec:
|
||||||
|
replicas: 2
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: bentopdf
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: bentopdf
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- image: bentopdf/bentopdf:latest
|
||||||
|
imagePullPolicy: Always
|
||||||
|
name: bentopdf
|
||||||
|
ports:
|
||||||
|
- containerPort: 8080
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "50Mi"
|
||||||
|
cpu: "50m"
|
||||||
|
ephemeral-storage: "100Mi"
|
||||||
|
limits:
|
||||||
|
memory: "700Mi"
|
||||||
|
cpu: "700m"
|
||||||
|
ephemeral-storage: "5Gi"
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
# test manifest with docker and k8s config keys mismatch
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: convertx-config
|
||||||
|
namespace: converters
|
||||||
|
data:
|
||||||
|
ACCOUNT_REGISTRATION: "false"
|
||||||
|
HTTP_ALLOWED: "false"
|
||||||
|
ALLOW_UNAUTHENTICAED: "false"
|
||||||
|
AUTO_DELETE_EVERY_N_HOURS: "24"
|
||||||
|
WEBROOT: "/convert"
|
||||||
|
HIDE_HISTORY: "false"
|
||||||
|
LANGUAGE: "en"
|
||||||
|
UNAUTHED_USER_SHARING: "false"
|
||||||
|
MAX_CONVERT_PROCESS: "0"
|
||||||
@@ -0,0 +1,63 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: convertx-service
|
||||||
|
namespace: converters
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: convertx
|
||||||
|
ports:
|
||||||
|
- port: 3000
|
||||||
|
targetPort: 3000
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: convertx-deployment
|
||||||
|
namespace: converters
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: convertx
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: convertx
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- image: ghcr.io/c4illin/convertx:latest
|
||||||
|
name: convertx
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: convertx-config
|
||||||
|
- secretRef:
|
||||||
|
name: convertx-secrets
|
||||||
|
ports:
|
||||||
|
- containerPort: 3000
|
||||||
|
volumeMounts:
|
||||||
|
- mountPath: /data
|
||||||
|
name: data
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "250Mi"
|
||||||
|
cpu: "100m"
|
||||||
|
limits:
|
||||||
|
cpu: "1500m"
|
||||||
|
memory: "1.5Gi"
|
||||||
|
volumes:
|
||||||
|
- name: data
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: convertx-pvc
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
metadata:
|
||||||
|
name: convertx-pvc
|
||||||
|
namespace: converters
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 2Gi
|
||||||
@@ -0,0 +1,65 @@
|
|||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: convertx-prod
|
||||||
|
namespace: converters
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: (Host(`forust.xyz`) || Host(`www.forust.xyz`)) && PathPrefix(`/convert`)
|
||||||
|
kind: Rule
|
||||||
|
priority: 50
|
||||||
|
services:
|
||||||
|
- name: convertx-service
|
||||||
|
port: 3000
|
||||||
|
tls:
|
||||||
|
certResolver: letsencrypt
|
||||||
|
---
|
||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: convertx-local
|
||||||
|
namespace: converters
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: (Host(`workstation.internal`) || Host(`gigaforust.internal`)) && PathPrefix(`/convert`)
|
||||||
|
kind: Rule
|
||||||
|
priority: 50
|
||||||
|
services:
|
||||||
|
- name: convertx-service
|
||||||
|
port: 3000
|
||||||
|
---
|
||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: bentopdf-prod
|
||||||
|
namespace: converters
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: Host(`pdf.forust.xyz`)
|
||||||
|
kind: Rule
|
||||||
|
services:
|
||||||
|
- name: bentopdf-service
|
||||||
|
port: 8080
|
||||||
|
tls:
|
||||||
|
certResolver: letsencrypt
|
||||||
|
---
|
||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: bentopdf-local
|
||||||
|
namespace: converters
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: Host(`pdf.workstation.internal`) || Host(`pdf.gigaforust.internal`)
|
||||||
|
kind: Rule
|
||||||
|
services:
|
||||||
|
- name: bentopdf-service
|
||||||
|
port: 8080
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: converters
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: convertx-secrets
|
||||||
|
namespace: converters
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
jwt-secret: ""
|
||||||
+39
-23
@@ -1,30 +1,46 @@
|
|||||||
services:
|
services:
|
||||||
dockmon:
|
dockmon:
|
||||||
image: darthnorse/dockmon:latest
|
image: darthnorse/dockmon:latest
|
||||||
container_name: dockmon
|
container_name: dockmon
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
ports:
|
# ports:
|
||||||
- 8000:443
|
# - 8000:443
|
||||||
environment:
|
volumes:
|
||||||
- TZ=Europe/Bratislava
|
- data:/app/data
|
||||||
volumes:
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
- ./data:/app/data
|
healthcheck:
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
test: ["CMD", "curl", "-k", "-f", "https://localhost:443/health"]
|
||||||
healthcheck:
|
interval: 30s
|
||||||
test: ["CMD", "curl", "-k", "-f", "https://localhost:443/health"]
|
timeout: 10s
|
||||||
interval: 30s
|
retries: 3
|
||||||
timeout: 10s
|
labels:
|
||||||
retries: 3
|
|
||||||
networks:
|
|
||||||
- traefik-proxy
|
|
||||||
labels:
|
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=traefik-proxy"
|
- "traefik.http.services.dockmon.loadbalancer.server.port=443"
|
||||||
|
- "traefik.http.services.dockmon.loadbalancer.server.scheme=https"
|
||||||
|
- "traefik.http.services.dockmon.loadbalancer.serverstransport=insecureTransport@file"
|
||||||
|
|
||||||
|
# Prod Router
|
||||||
|
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
|
||||||
|
- "traefik.http.routers.dockmon.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.dockmon.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.dockmon.tls.certresolver=letsencrypt"
|
||||||
|
# Local Router
|
||||||
|
- "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`)"
|
||||||
|
- "traefik.http.routers.dockmon-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.dockmon-local.tls=true"
|
||||||
|
# Dev Router
|
||||||
|
- "traefik.http.routers.dockmon-dev.rule=Host(`dockmon.gigaforust.internal`)"
|
||||||
|
- "traefik.http.routers.dockmon-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.dockmon-dev.tls=true"
|
||||||
|
|
||||||
|
# Glance Metadata
|
||||||
- glance.name=dockmon
|
- glance.name=dockmon
|
||||||
# - glance.icon=sh:dockmon
|
|
||||||
- glance.url=https://dockmon.forust.xyz/
|
- glance.url=https://dockmon.forust.xyz/
|
||||||
- glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface.
|
- glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface.
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
|
volumes:
|
||||||
|
data:
|
||||||
networks:
|
networks:
|
||||||
traefik-proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -0,0 +1,68 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: dockmon-service
|
||||||
|
namespace: dockmon
|
||||||
|
spec:
|
||||||
|
clusterIP: None
|
||||||
|
selector:
|
||||||
|
app: dockmon
|
||||||
|
ports:
|
||||||
|
- port: 443
|
||||||
|
targetPort: 443
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: StatefulSet
|
||||||
|
metadata:
|
||||||
|
name: dockmon-statefulset
|
||||||
|
namespace: dockmon
|
||||||
|
spec:
|
||||||
|
serviceName: dockmon-service
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: dockmon
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: dockmon
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: dockmon
|
||||||
|
image: darthnorse/dockmon:latest
|
||||||
|
ports:
|
||||||
|
- containerPort: 443
|
||||||
|
volumeMounts:
|
||||||
|
- name: data
|
||||||
|
mountPath: /app/data
|
||||||
|
- name: docker-sock
|
||||||
|
mountPath: /var/run/docker.sock
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /health
|
||||||
|
port: 443
|
||||||
|
scheme: HTTPS
|
||||||
|
initialDelaySeconds: 30
|
||||||
|
periodSeconds: 30
|
||||||
|
timeoutSeconds: 10
|
||||||
|
failureThreshold: 3
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "512Mi"
|
||||||
|
cpu: "200m"
|
||||||
|
limits:
|
||||||
|
memory: "1.5Gi"
|
||||||
|
cpu: "700m "
|
||||||
|
volumes:
|
||||||
|
- name: docker-sock
|
||||||
|
hostPath:
|
||||||
|
path: /var/run/docker.sock
|
||||||
|
type: Socket
|
||||||
|
volumeClaimTemplates:
|
||||||
|
- metadata:
|
||||||
|
name: data
|
||||||
|
spec:
|
||||||
|
accessModes: ["ReadWriteOnce"]
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 1Gi
|
||||||
@@ -0,0 +1,43 @@
|
|||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: ServersTransport
|
||||||
|
metadata:
|
||||||
|
name: dockmon-transport
|
||||||
|
namespace: dockmon
|
||||||
|
spec:
|
||||||
|
insecureSkipVerify: true
|
||||||
|
---
|
||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: dockmon-prod
|
||||||
|
namespace: dockmon
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: Host(`dockmon.forust.xyz`)
|
||||||
|
kind: Rule
|
||||||
|
middlewares:
|
||||||
|
- name: security-headers@file
|
||||||
|
services:
|
||||||
|
- name: dockmon-service
|
||||||
|
port: 443
|
||||||
|
serversTransport: dockmon-transport
|
||||||
|
tls:
|
||||||
|
certResolver: letsencrypt
|
||||||
|
---
|
||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: dockmon-local
|
||||||
|
namespace: dockmon
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: Host(`dockmon.workstation.internal`) || Host(`dockmon.gigaforust.internal`)
|
||||||
|
kind: Rule
|
||||||
|
services:
|
||||||
|
- name: dockmon-service
|
||||||
|
port: 443
|
||||||
|
serversTransport: dockmon-transport
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: dockmon
|
||||||
@@ -0,0 +1,31 @@
|
|||||||
|
services:
|
||||||
|
downtify:
|
||||||
|
container_name: downtify
|
||||||
|
image: ghcr.io/henriquesebastiao/downtify:latest
|
||||||
|
restart: unless-stopped
|
||||||
|
# ports:
|
||||||
|
# - '7077:8000'
|
||||||
|
volumes:
|
||||||
|
- ./Downtify_downloads:/downloads
|
||||||
|
labels:
|
||||||
|
- "traefik.enable=true"
|
||||||
|
- "traefik.http.services.downtify.loadbalancer.server.port=8000"
|
||||||
|
|
||||||
|
# Prod Router
|
||||||
|
- "traefik.http.routers.downtify.rule=Host(`downtify.forust.xyz`)"
|
||||||
|
- "traefik.http.routers.downtify.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.downtify.middlewares=security-chain@file"
|
||||||
|
- "traefik.http.routers.downtify.tls.certresolver=letsencrypt"
|
||||||
|
# Local Router
|
||||||
|
- "traefik.http.routers.downtify-local.rule=Host(`downtify.workstation.internal`)"
|
||||||
|
- "traefik.http.routers.downtify-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.downtify-local.tls=true"
|
||||||
|
# Dev Router
|
||||||
|
- "traefik.http.routers.downtify-dev.rule=Host(`downtify.gigaforust.internal`)"
|
||||||
|
- "traefik.http.routers.downtify-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.downtify-dev.tls=true"
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
|
networks:
|
||||||
|
proxy:
|
||||||
|
external: true
|
||||||
@@ -0,0 +1,58 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: downtify-service
|
||||||
|
namespace: downtify
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: downtify
|
||||||
|
ports:
|
||||||
|
- port: 8000
|
||||||
|
targetPort: 8000
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: downtify-deployment
|
||||||
|
namespace: downtify
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: downtify
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: downtify
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: downtify
|
||||||
|
image: ghcr.io/henriquesebastiao/downtify:latest
|
||||||
|
ports:
|
||||||
|
- containerPort: 8000
|
||||||
|
volumeMounts:
|
||||||
|
- name: downloads
|
||||||
|
mountPath: /downloads
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "128Mi"
|
||||||
|
cpu: "200m"
|
||||||
|
limits:
|
||||||
|
memory: "1Gi"
|
||||||
|
cpu: "1"
|
||||||
|
volumes:
|
||||||
|
- name: downloads
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: downtify-downloads-pvc
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
metadata:
|
||||||
|
name: downtify-downloads-pvc
|
||||||
|
namespace: downtify
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 10Gi
|
||||||
@@ -0,0 +1,33 @@
|
|||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: downtify-prod
|
||||||
|
namespace: downtify
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: Host(`downtify.forust.xyz`)
|
||||||
|
kind: Rule
|
||||||
|
middlewares:
|
||||||
|
- name: security-chain@file
|
||||||
|
services:
|
||||||
|
- name: downtify-service
|
||||||
|
port: 8000
|
||||||
|
tls:
|
||||||
|
certResolver: letsencrypt
|
||||||
|
---
|
||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: downtify-local
|
||||||
|
namespace: downtify
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: Host(`downtify.workstation.internal`) || Host(`downtify.gigaforust.internal`)
|
||||||
|
kind: Rule
|
||||||
|
services:
|
||||||
|
- name: downtify-service
|
||||||
|
port: 8000
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: downtify
|
||||||
@@ -0,0 +1,373 @@
|
|||||||
|
Mozilla Public License Version 2.0
|
||||||
|
==================================
|
||||||
|
|
||||||
|
1. Definitions
|
||||||
|
--------------
|
||||||
|
|
||||||
|
1.1. "Contributor"
|
||||||
|
means each individual or legal entity that creates, contributes to
|
||||||
|
the creation of, or owns Covered Software.
|
||||||
|
|
||||||
|
1.2. "Contributor Version"
|
||||||
|
means the combination of the Contributions of others (if any) used
|
||||||
|
by a Contributor and that particular Contributor's Contribution.
|
||||||
|
|
||||||
|
1.3. "Contribution"
|
||||||
|
means Covered Software of a particular Contributor.
|
||||||
|
|
||||||
|
1.4. "Covered Software"
|
||||||
|
means Source Code Form to which the initial Contributor has attached
|
||||||
|
the notice in Exhibit A, the Executable Form of such Source Code
|
||||||
|
Form, and Modifications of such Source Code Form, in each case
|
||||||
|
including portions thereof.
|
||||||
|
|
||||||
|
1.5. "Incompatible With Secondary Licenses"
|
||||||
|
means
|
||||||
|
|
||||||
|
(a) that the initial Contributor has attached the notice described
|
||||||
|
in Exhibit B to the Covered Software; or
|
||||||
|
|
||||||
|
(b) that the Covered Software was made available under the terms of
|
||||||
|
version 1.1 or earlier of the License, but not also under the
|
||||||
|
terms of a Secondary License.
|
||||||
|
|
||||||
|
1.6. "Executable Form"
|
||||||
|
means any form of the work other than Source Code Form.
|
||||||
|
|
||||||
|
1.7. "Larger Work"
|
||||||
|
means a work that combines Covered Software with other material, in
|
||||||
|
a separate file or files, that is not Covered Software.
|
||||||
|
|
||||||
|
1.8. "License"
|
||||||
|
means this document.
|
||||||
|
|
||||||
|
1.9. "Licensable"
|
||||||
|
means having the right to grant, to the maximum extent possible,
|
||||||
|
whether at the time of the initial grant or subsequently, any and
|
||||||
|
all of the rights conveyed by this License.
|
||||||
|
|
||||||
|
1.10. "Modifications"
|
||||||
|
means any of the following:
|
||||||
|
|
||||||
|
(a) any file in Source Code Form that results from an addition to,
|
||||||
|
deletion from, or modification of the contents of Covered
|
||||||
|
Software; or
|
||||||
|
|
||||||
|
(b) any new file in Source Code Form that contains any Covered
|
||||||
|
Software.
|
||||||
|
|
||||||
|
1.11. "Patent Claims" of a Contributor
|
||||||
|
means any patent claim(s), including without limitation, method,
|
||||||
|
process, and apparatus claims, in any patent Licensable by such
|
||||||
|
Contributor that would be infringed, but for the grant of the
|
||||||
|
License, by the making, using, selling, offering for sale, having
|
||||||
|
made, import, or transfer of either its Contributions or its
|
||||||
|
Contributor Version.
|
||||||
|
|
||||||
|
1.12. "Secondary License"
|
||||||
|
means either the GNU General Public License, Version 2.0, the GNU
|
||||||
|
Lesser General Public License, Version 2.1, the GNU Affero General
|
||||||
|
Public License, Version 3.0, or any later versions of those
|
||||||
|
licenses.
|
||||||
|
|
||||||
|
1.13. "Source Code Form"
|
||||||
|
means the form of the work preferred for making modifications.
|
||||||
|
|
||||||
|
1.14. "You" (or "Your")
|
||||||
|
means an individual or a legal entity exercising rights under this
|
||||||
|
License. For legal entities, "You" includes any entity that
|
||||||
|
controls, is controlled by, or is under common control with You. For
|
||||||
|
purposes of this definition, "control" means (a) the power, direct
|
||||||
|
or indirect, to cause the direction or management of such entity,
|
||||||
|
whether by contract or otherwise, or (b) ownership of more than
|
||||||
|
fifty percent (50%) of the outstanding shares or beneficial
|
||||||
|
ownership of such entity.
|
||||||
|
|
||||||
|
2. License Grants and Conditions
|
||||||
|
--------------------------------
|
||||||
|
|
||||||
|
2.1. Grants
|
||||||
|
|
||||||
|
Each Contributor hereby grants You a world-wide, royalty-free,
|
||||||
|
non-exclusive license:
|
||||||
|
|
||||||
|
(a) under intellectual property rights (other than patent or trademark)
|
||||||
|
Licensable by such Contributor to use, reproduce, make available,
|
||||||
|
modify, display, perform, distribute, and otherwise exploit its
|
||||||
|
Contributions, either on an unmodified basis, with Modifications, or
|
||||||
|
as part of a Larger Work; and
|
||||||
|
|
||||||
|
(b) under Patent Claims of such Contributor to make, use, sell, offer
|
||||||
|
for sale, have made, import, and otherwise transfer either its
|
||||||
|
Contributions or its Contributor Version.
|
||||||
|
|
||||||
|
2.2. Effective Date
|
||||||
|
|
||||||
|
The licenses granted in Section 2.1 with respect to any Contribution
|
||||||
|
become effective for each Contribution on the date the Contributor first
|
||||||
|
distributes such Contribution.
|
||||||
|
|
||||||
|
2.3. Limitations on Grant Scope
|
||||||
|
|
||||||
|
The licenses granted in this Section 2 are the only rights granted under
|
||||||
|
this License. No additional rights or licenses will be implied from the
|
||||||
|
distribution or licensing of Covered Software under this License.
|
||||||
|
Notwithstanding Section 2.1(b) above, no patent license is granted by a
|
||||||
|
Contributor:
|
||||||
|
|
||||||
|
(a) for any code that a Contributor has removed from Covered Software;
|
||||||
|
or
|
||||||
|
|
||||||
|
(b) for infringements caused by: (i) Your and any other third party's
|
||||||
|
modifications of Covered Software, or (ii) the combination of its
|
||||||
|
Contributions with other software (except as part of its Contributor
|
||||||
|
Version); or
|
||||||
|
|
||||||
|
(c) under Patent Claims infringed by Covered Software in the absence of
|
||||||
|
its Contributions.
|
||||||
|
|
||||||
|
This License does not grant any rights in the trademarks, service marks,
|
||||||
|
or logos of any Contributor (except as may be necessary to comply with
|
||||||
|
the notice requirements in Section 3.4).
|
||||||
|
|
||||||
|
2.4. Subsequent Licenses
|
||||||
|
|
||||||
|
No Contributor makes additional grants as a result of Your choice to
|
||||||
|
distribute the Covered Software under a subsequent version of this
|
||||||
|
License (see Section 10.2) or under the terms of a Secondary License (if
|
||||||
|
permitted under the terms of Section 3.3).
|
||||||
|
|
||||||
|
2.5. Representation
|
||||||
|
|
||||||
|
Each Contributor represents that the Contributor believes its
|
||||||
|
Contributions are its original creation(s) or it has sufficient rights
|
||||||
|
to grant the rights to its Contributions conveyed by this License.
|
||||||
|
|
||||||
|
2.6. Fair Use
|
||||||
|
|
||||||
|
This License is not intended to limit any rights You have under
|
||||||
|
applicable copyright doctrines of fair use, fair dealing, or other
|
||||||
|
equivalents.
|
||||||
|
|
||||||
|
2.7. Conditions
|
||||||
|
|
||||||
|
Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses granted
|
||||||
|
in Section 2.1.
|
||||||
|
|
||||||
|
3. Responsibilities
|
||||||
|
-------------------
|
||||||
|
|
||||||
|
3.1. Distribution of Source Form
|
||||||
|
|
||||||
|
All distribution of Covered Software in Source Code Form, including any
|
||||||
|
Modifications that You create or to which You contribute, must be under
|
||||||
|
the terms of this License. You must inform recipients that the Source
|
||||||
|
Code Form of the Covered Software is governed by the terms of this
|
||||||
|
License, and how they can obtain a copy of this License. You may not
|
||||||
|
attempt to alter or restrict the recipients' rights in the Source Code
|
||||||
|
Form.
|
||||||
|
|
||||||
|
3.2. Distribution of Executable Form
|
||||||
|
|
||||||
|
If You distribute Covered Software in Executable Form then:
|
||||||
|
|
||||||
|
(a) such Covered Software must also be made available in Source Code
|
||||||
|
Form, as described in Section 3.1, and You must inform recipients of
|
||||||
|
the Executable Form how they can obtain a copy of such Source Code
|
||||||
|
Form by reasonable means in a timely manner, at a charge no more
|
||||||
|
than the cost of distribution to the recipient; and
|
||||||
|
|
||||||
|
(b) You may distribute such Executable Form under the terms of this
|
||||||
|
License, or sublicense it under different terms, provided that the
|
||||||
|
license for the Executable Form does not attempt to limit or alter
|
||||||
|
the recipients' rights in the Source Code Form under this License.
|
||||||
|
|
||||||
|
3.3. Distribution of a Larger Work
|
||||||
|
|
||||||
|
You may create and distribute a Larger Work under terms of Your choice,
|
||||||
|
provided that You also comply with the requirements of this License for
|
||||||
|
the Covered Software. If the Larger Work is a combination of Covered
|
||||||
|
Software with a work governed by one or more Secondary Licenses, and the
|
||||||
|
Covered Software is not Incompatible With Secondary Licenses, this
|
||||||
|
License permits You to additionally distribute such Covered Software
|
||||||
|
under the terms of such Secondary License(s), so that the recipient of
|
||||||
|
the Larger Work may, at their option, further distribute the Covered
|
||||||
|
Software under the terms of either this License or such Secondary
|
||||||
|
License(s).
|
||||||
|
|
||||||
|
3.4. Notices
|
||||||
|
|
||||||
|
You may not remove or alter the substance of any license notices
|
||||||
|
(including copyright notices, patent notices, disclaimers of warranty,
|
||||||
|
or limitations of liability) contained within the Source Code Form of
|
||||||
|
the Covered Software, except that You may alter any license notices to
|
||||||
|
the extent required to remedy known factual inaccuracies.
|
||||||
|
|
||||||
|
3.5. Application of Additional Terms
|
||||||
|
|
||||||
|
You may choose to offer, and to charge a fee for, warranty, support,
|
||||||
|
indemnity or liability obligations to one or more recipients of Covered
|
||||||
|
Software. However, You may do so only on Your own behalf, and not on
|
||||||
|
behalf of any Contributor. You must make it absolutely clear that any
|
||||||
|
such warranty, support, indemnity, or liability obligation is offered by
|
||||||
|
You alone, and You hereby agree to indemnify every Contributor for any
|
||||||
|
liability incurred by such Contributor as a result of warranty, support,
|
||||||
|
indemnity or liability terms You offer. You may include additional
|
||||||
|
disclaimers of warranty and limitations of liability specific to any
|
||||||
|
jurisdiction.
|
||||||
|
|
||||||
|
4. Inability to Comply Due to Statute or Regulation
|
||||||
|
---------------------------------------------------
|
||||||
|
|
||||||
|
If it is impossible for You to comply with any of the terms of this
|
||||||
|
License with respect to some or all of the Covered Software due to
|
||||||
|
statute, judicial order, or regulation then You must: (a) comply with
|
||||||
|
the terms of this License to the maximum extent possible; and (b)
|
||||||
|
describe the limitations and the code they affect. Such description must
|
||||||
|
be placed in a text file included with all distributions of the Covered
|
||||||
|
Software under this License. Except to the extent prohibited by statute
|
||||||
|
or regulation, such description must be sufficiently detailed for a
|
||||||
|
recipient of ordinary skill to be able to understand it.
|
||||||
|
|
||||||
|
5. Termination
|
||||||
|
--------------
|
||||||
|
|
||||||
|
5.1. The rights granted under this License will terminate automatically
|
||||||
|
if You fail to comply with any of its terms. However, if You become
|
||||||
|
compliant, then the rights granted under this License from a particular
|
||||||
|
Contributor are reinstated (a) provisionally, unless and until such
|
||||||
|
Contributor explicitly and finally terminates Your grants, and (b) on an
|
||||||
|
ongoing basis, if such Contributor fails to notify You of the
|
||||||
|
non-compliance by some reasonable means prior to 60 days after You have
|
||||||
|
come back into compliance. Moreover, Your grants from a particular
|
||||||
|
Contributor are reinstated on an ongoing basis if such Contributor
|
||||||
|
notifies You of the non-compliance by some reasonable means, this is the
|
||||||
|
first time You have received notice of non-compliance with this License
|
||||||
|
from such Contributor, and You become compliant prior to 30 days after
|
||||||
|
Your receipt of the notice.
|
||||||
|
|
||||||
|
5.2. If You initiate litigation against any entity by asserting a patent
|
||||||
|
infringement claim (excluding declaratory judgment actions,
|
||||||
|
counter-claims, and cross-claims) alleging that a Contributor Version
|
||||||
|
directly or indirectly infringes any patent, then the rights granted to
|
||||||
|
You by any and all Contributors for the Covered Software under Section
|
||||||
|
2.1 of this License shall terminate.
|
||||||
|
|
||||||
|
5.3. In the event of termination under Sections 5.1 or 5.2 above, all
|
||||||
|
end user license agreements (excluding distributors and resellers) which
|
||||||
|
have been validly granted by You or Your distributors under this License
|
||||||
|
prior to termination shall survive termination.
|
||||||
|
|
||||||
|
************************************************************************
|
||||||
|
* *
|
||||||
|
* 6. Disclaimer of Warranty *
|
||||||
|
* ------------------------- *
|
||||||
|
* *
|
||||||
|
* Covered Software is provided under this License on an "as is" *
|
||||||
|
* basis, without warranty of any kind, either expressed, implied, or *
|
||||||
|
* statutory, including, without limitation, warranties that the *
|
||||||
|
* Covered Software is free of defects, merchantable, fit for a *
|
||||||
|
* particular purpose or non-infringing. The entire risk as to the *
|
||||||
|
* quality and performance of the Covered Software is with You. *
|
||||||
|
* Should any Covered Software prove defective in any respect, You *
|
||||||
|
* (not any Contributor) assume the cost of any necessary servicing, *
|
||||||
|
* repair, or correction. This disclaimer of warranty constitutes an *
|
||||||
|
* essential part of this License. No use of any Covered Software is *
|
||||||
|
* authorized under this License except under this disclaimer. *
|
||||||
|
* *
|
||||||
|
************************************************************************
|
||||||
|
|
||||||
|
************************************************************************
|
||||||
|
* *
|
||||||
|
* 7. Limitation of Liability *
|
||||||
|
* -------------------------- *
|
||||||
|
* *
|
||||||
|
* Under no circumstances and under no legal theory, whether tort *
|
||||||
|
* (including negligence), contract, or otherwise, shall any *
|
||||||
|
* Contributor, or anyone who distributes Covered Software as *
|
||||||
|
* permitted above, be liable to You for any direct, indirect, *
|
||||||
|
* special, incidental, or consequential damages of any character *
|
||||||
|
* including, without limitation, damages for lost profits, loss of *
|
||||||
|
* goodwill, work stoppage, computer failure or malfunction, or any *
|
||||||
|
* and all other commercial damages or losses, even if such party *
|
||||||
|
* shall have been informed of the possibility of such damages. This *
|
||||||
|
* limitation of liability shall not apply to liability for death or *
|
||||||
|
* personal injury resulting from such party's negligence to the *
|
||||||
|
* extent applicable law prohibits such limitation. Some *
|
||||||
|
* jurisdictions do not allow the exclusion or limitation of *
|
||||||
|
* incidental or consequential damages, so this exclusion and *
|
||||||
|
* limitation may not apply to You. *
|
||||||
|
* *
|
||||||
|
************************************************************************
|
||||||
|
|
||||||
|
8. Litigation
|
||||||
|
-------------
|
||||||
|
|
||||||
|
Any litigation relating to this License may be brought only in the
|
||||||
|
courts of a jurisdiction where the defendant maintains its principal
|
||||||
|
place of business and such litigation shall be governed by laws of that
|
||||||
|
jurisdiction, without reference to its conflict-of-law provisions.
|
||||||
|
Nothing in this Section shall prevent a party's ability to bring
|
||||||
|
cross-claims or counter-claims.
|
||||||
|
|
||||||
|
9. Miscellaneous
|
||||||
|
----------------
|
||||||
|
|
||||||
|
This License represents the complete agreement concerning the subject
|
||||||
|
matter hereof. If any provision of this License is held to be
|
||||||
|
unenforceable, such provision shall be reformed only to the extent
|
||||||
|
necessary to make it enforceable. Any law or regulation which provides
|
||||||
|
that the language of a contract shall be construed against the drafter
|
||||||
|
shall not be used to construe this License against a Contributor.
|
||||||
|
|
||||||
|
10. Versions of the License
|
||||||
|
---------------------------
|
||||||
|
|
||||||
|
10.1. New Versions
|
||||||
|
|
||||||
|
Mozilla Foundation is the license steward. Except as provided in Section
|
||||||
|
10.3, no one other than the license steward has the right to modify or
|
||||||
|
publish new versions of this License. Each version will be given a
|
||||||
|
distinguishing version number.
|
||||||
|
|
||||||
|
10.2. Effect of New Versions
|
||||||
|
|
||||||
|
You may distribute the Covered Software under the terms of the version
|
||||||
|
of the License under which You originally received the Covered Software,
|
||||||
|
or under the terms of any subsequent version published by the license
|
||||||
|
steward.
|
||||||
|
|
||||||
|
10.3. Modified Versions
|
||||||
|
|
||||||
|
If you create software not governed by this License, and you want to
|
||||||
|
create a new license for such software, you may create and use a
|
||||||
|
modified version of this License if you rename the license and remove
|
||||||
|
any references to the name of the license steward (except to note that
|
||||||
|
such modified license differs from this License).
|
||||||
|
|
||||||
|
10.4. Distributing Source Code Form that is Incompatible With Secondary
|
||||||
|
Licenses
|
||||||
|
|
||||||
|
If You choose to distribute Source Code Form that is Incompatible With
|
||||||
|
Secondary Licenses under the terms of this version of the License, the
|
||||||
|
notice described in Exhibit B of this License must be attached.
|
||||||
|
|
||||||
|
Exhibit A - Source Code Form License Notice
|
||||||
|
-------------------------------------------
|
||||||
|
|
||||||
|
This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
file, You can obtain one at https://mozilla.org/MPL/2.0/.
|
||||||
|
|
||||||
|
If it is not possible or desirable to put the notice in a particular
|
||||||
|
file, then You may include the notice in a location (such as a LICENSE
|
||||||
|
file in a relevant directory) where a recipient would be likely to look
|
||||||
|
for such a notice.
|
||||||
|
|
||||||
|
You may add additional accurate notices of copyright ownership.
|
||||||
|
|
||||||
|
Exhibit B - "Incompatible With Secondary Licenses" Notice
|
||||||
|
---------------------------------------------------------
|
||||||
|
|
||||||
|
This Source Code Form is "Incompatible With Secondary Licenses", as
|
||||||
|
defined by the Mozilla Public License, v. 2.0.
|
||||||
@@ -3,12 +3,13 @@ services:
|
|||||||
build:
|
build:
|
||||||
context: .
|
context: .
|
||||||
dockerfile: Dockerfile
|
dockerfile: Dockerfile
|
||||||
|
image: gcr.forust.xyz/forust/dtek-notif:latest
|
||||||
|
pull_policy: build
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
- TZ=Europe/Kyiv
|
- TZ=Europe/Kyiv
|
||||||
|
|
||||||
dns:
|
dns:
|
||||||
- 1.1.1.1
|
- 1.1.1.1
|
||||||
- 8.8.8.8
|
- 8.8.8.8
|
||||||
networks:
|
networks:
|
||||||
- default
|
- default
|
||||||
|
|||||||
+388
-418
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,13 @@
|
|||||||
|
EDU_LOGIN=your_edu_login_here
|
||||||
|
EDU_PASSWORD=your_edu_password_here
|
||||||
|
EDU_URL_LOGIN=https://edu.edu.vn.ua/user/login
|
||||||
|
EDU_URL_VERIFY=https://edu.edu.vn.ua/course/userlist
|
||||||
|
PHPSESSID_INTERVAL=10
|
||||||
|
USER_AGENT="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36"
|
||||||
|
WEBINAR_URL=https://edu.edu.vn.ua/webinar/useractive
|
||||||
|
WEBINAR_CHECK_INTERVAL=60
|
||||||
|
REDIS_HOST=redis
|
||||||
|
REDIS_PORT=6379
|
||||||
|
PLAYWRIGHT_WS=ws://playwright-service:3000/ws
|
||||||
|
WEBINAR_TELEGRAM_TOKEN=your_telegram_bot_token_here
|
||||||
|
WEBINAR_ADMIN_ID=123456789
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
ARG VERSION
|
|
||||||
# Use the official WaterCrawl image as the base image
|
|
||||||
FROM watercrawl/watercrawl:${VERSION:-v0.10.2}
|
|
||||||
|
|
||||||
# Set working directory
|
|
||||||
WORKDIR /var/www
|
|
||||||
|
|
||||||
# Copy the extra requirements file
|
|
||||||
COPY extra_requirements.txt /var/www/extra_requirements.txt
|
|
||||||
|
|
||||||
# Install any additional packages
|
|
||||||
RUN poetry run pip install -r /var/www/extra_requirements.txt
|
|
||||||
|
|
||||||
# The rest of the configuration is inherited from the base image
|
|
||||||
# The entrypoint and command should be defined in docker-compose.yml
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
# Add your additional Python packages here, one per line
|
|
||||||
+36
-249
@@ -1,262 +1,49 @@
|
|||||||
x-app: &app
|
|
||||||
build:
|
|
||||||
context: ./backend/
|
|
||||||
dockerfile: Dockerfile
|
|
||||||
args:
|
|
||||||
- VERSION=${VERSION:-v0.10.2}
|
|
||||||
depends_on:
|
|
||||||
db:
|
|
||||||
condition: service_healthy
|
|
||||||
dns:
|
|
||||||
- 8.8.8.8
|
|
||||||
- 1.1.1.1
|
|
||||||
environment:
|
|
||||||
- SECRET_KEY=${SECRET_KEY:-django-insecure-el4wo4a4--=f0+ag#omp@^w4eq^8v4(scda&1a(td_y2@=sh6&}
|
|
||||||
- API_ENCRYPTION_KEY=${API_ENCRYPTION_KEY:-8zSd6JIuC7ovfZ4AoxG_XmhubW6CPnQWW7Qe_4TD1TQ=}
|
|
||||||
- DEBUG=${DEBUG:-True}
|
|
||||||
- ALLOWED_HOSTS=${ALLOWED_HOSTS:-*}
|
|
||||||
- LANGUAGE_CODE=${LANGUAGE_CODE:-en-us}
|
|
||||||
- TIME_ZONE=${TIME_ZONE:-UTC}
|
|
||||||
- USE_I18N=${USE_I18N:-True}
|
|
||||||
- USE_TZ=${USE_TZ:-True}
|
|
||||||
- STATIC_ROOT=${STATIC_ROOT:-storage/static/}
|
|
||||||
- MEDIA_ROOT=${MEDIA_ROOT:-storage/media/}
|
|
||||||
- LOG_LEVEL=${LOG_LEVEL:-INFO}
|
|
||||||
- REDIS_URL=${REDIS_URL:-redis://redis:6379/1}
|
|
||||||
- DATABASE_URL=postgres://${POSTGRES_USER:-postgres}:${POSTGRES_PASSWORD:-postgres}@${POSTGRES_HOST:-db}:${POSTGRES_PORT:-5432}/${POSTGRES_DB:-postgres}
|
|
||||||
- CELERY_BROKER_URL=${CELERY_BROKER_URL:-redis://redis:6379/0}
|
|
||||||
- CELERY_RESULT_BACKEND=${CELERY_RESULT_BACKEND:-django-db}
|
|
||||||
- REDIS_LOCKER_URL=${REDIS_LOCKER_URL:-redis://redis:6379/3}
|
|
||||||
- MINIO_ENDPOINT=minio:9000
|
|
||||||
- MINIO_EXTERNAL_ENDPOINT=nginx
|
|
||||||
- MINIO_REGION=us-east-1
|
|
||||||
- MINIO_ACCESS_KEY=minio
|
|
||||||
- MINIO_SECRET_KEY=minio123
|
|
||||||
- MINIO_USE_HTTPS=False
|
|
||||||
- MINIO_EXTERNAL_ENDPOINT_USE_HTTPS=False
|
|
||||||
- MINIO_URL_EXPIRY_HOURS=7
|
|
||||||
- MINIO_PRIVATE_BUCKET=private
|
|
||||||
- MINIO_PUBLIC_BUCKET=public
|
|
||||||
- CSRF_TRUSTED_ORIGINS=${CSRF_TRUSTED_ORIGINS:-}
|
|
||||||
- CORS_ALLOWED_ORIGINS=${CORS_ALLOWED_ORIGINS:-}
|
|
||||||
- CORS_ALLOWED_ORIGIN_REGEXES=${CORS_ALLOWED_ORIGIN_REGEXES:-}
|
|
||||||
- CORS_ALLOW_ALL_ORIGINS=${CORS_ALLOW_ALL_ORIGINS:-False}
|
|
||||||
- FRONTEND_URL=${FRONTEND_URL:-http://localhost}
|
|
||||||
- IS_LOGIN_ACTIVE=${IS_LOGIN_ACTIVE:-True}
|
|
||||||
- IS_SIGNUP_ACTIVE=${IS_SIGNUP_ACTIVE:-True}
|
|
||||||
- IS_GITHUB_LOGIN_ACTIVE=${IS_GITHUB_LOGIN_ACTIVE:-True}
|
|
||||||
- IS_GOOGLE_LOGIN_ACTIVE=${IS_GOOGLE_LOGIN_ACTIVE:-True}
|
|
||||||
- GITHUB_CLIENT_ID=${GITHUB_CLIENT_ID:-}
|
|
||||||
- GITHUB_CLIENT_SECRET=${GITHUB_CLIENT_SECRET:-}
|
|
||||||
- GOOGLE_CLIENT_ID=${GOOGLE_CLIENT_ID:-}
|
|
||||||
- GOOGLE_CLIENT_SECRET=${GOOGLE_CLIENT_SECRET:-}
|
|
||||||
- ACCESS_TOKEN_LIFETIME_MINUTES=${ACCESS_TOKEN_LIFETIME_MINUTES:-5}
|
|
||||||
- REFRESH_TOKEN_LIFETIME_DAYS=${REFRESH_TOKEN_LIFETIME_DAYS:-30}
|
|
||||||
- EMAIL_BACKEND=${EMAIL_BACKEND:-django.core.mail.backends.smtp.EmailBackend}
|
|
||||||
- EMAIL_HOST=${EMAIL_HOST:-}
|
|
||||||
- EMAIL_PORT=${EMAIL_PORT:-587}
|
|
||||||
- EMAIL_USE_TLS=${EMAIL_USE_TLS:-True}
|
|
||||||
- EMAIL_HOST_USER=${EMAIL_HOST_USER:-}
|
|
||||||
- EMAIL_HOST_PASSWORD=${EMAIL_HOST_PASSWORD:-}
|
|
||||||
- DEFAULT_FROM_EMAIL=${DEFAULT_FROM_EMAIL:-}
|
|
||||||
- SCRAPY_USER_AGENT=${SCRAPY_USER_AGENT:-WaterCrawl/0.1 (+https://github.com/watercrawl/watercrawl)}
|
|
||||||
- SCRAPY_ROBOTSTXT_OBEY=${SCRAPY_ROBOTSTXT_OBEY:-True}
|
|
||||||
- SCRAPY_CONCURRENT_REQUESTS=${SCRAPY_CONCURRENT_REQUESTS:-16}
|
|
||||||
- SCRAPY_DOWNLOAD_DELAY=${SCRAPY_DOWNLOAD_DELAY:-0}
|
|
||||||
- SCRAPY_CONCURRENT_REQUESTS_PER_DOMAIN=${SCRAPY_CONCURRENT_REQUESTS_PER_DOMAIN:-4}
|
|
||||||
- SCRAPY_CONCURRENT_REQUESTS_PER_IP=${SCRAPY_CONCURRENT_REQUESTS_PER_IP:-4}
|
|
||||||
- SCRAPY_COOKIES_ENABLED=${SCRAPY_COOKIES_ENABLED:-False}
|
|
||||||
- SCRAPY_HTTPCACHE_ENABLED=${SCRAPY_HTTPCACHE_ENABLED:-True}
|
|
||||||
- SCRAPY_HTTPCACHE_EXPIRATION_SECS=${SCRAPY_HTTPCACHE_EXPIRATION_SECS:-3600}
|
|
||||||
- SCRAPY_HTTPCACHE_DIR=${SCRAPY_HTTPCACHE_DIR:-httpcache}
|
|
||||||
- SCRAPY_LOG_LEVEL=${SCRAPY_LOG_LEVEL:-ERROR}
|
|
||||||
- SCRAPY_GOOGLE_API_KEY=${SCRAPY_GOOGLE_API_KEY:-}
|
|
||||||
- SCRAPY_GOOGLE_CSE_ID=${SCRAPY_GOOGLE_CSE_ID:-}
|
|
||||||
- SCRAPY_MAX_NUMBER_OF_SITEMAP_URLS=${SCRAPY_MAX_NUMBER_OF_SITEMAP_URLS:-20000}
|
|
||||||
- SCRAPY_SITEMAP_CRAWL_PAGE_LIMIT=${SCRAPY_SITEMAP_CRAWL_PAGE_LIMIT:-100}
|
|
||||||
- PLAYWRIGHT_SERVER=${PLAYWRIGHT_SERVER:-http://playwright:8000}
|
|
||||||
- PLAYWRIGHT_API_KEY=${PLAYWRIGHT_API_KEY:-your-secret-api-key}
|
|
||||||
- OPENAI_API_KEY=${OPENAI_API_KEY:-}
|
|
||||||
- STRIPE_SECRET_KEY=${STRIPE_SECRET_KEY:-}
|
|
||||||
- STRIPE_WEBHOOK_SECRET=${STRIPE_WEBHOOK_SECRET:-}
|
|
||||||
- GOOGLE_ANALYTICS_ID=${GOOGLE_ANALYTICS_ID:-}
|
|
||||||
- IS_ENTERPRISE_MODE_ACTIVE=${IS_ENTERPRISE_MODE_ACTIVE:-False}
|
|
||||||
- MAX_CRAWL_DEPTH=${MAX_CRAWL_DEPTH:--1}
|
|
||||||
- CAPTURE_USAGE_HISTORY=${CAPTURE_USAGE_HISTORY:-True}
|
|
||||||
- MCP_SERVER=${MCP_SERVER:-http://localhost/sse}
|
|
||||||
networks:
|
|
||||||
- traefik-proxy
|
|
||||||
- default
|
|
||||||
- n8n
|
|
||||||
|
|
||||||
x-frontend: &frontend
|
|
||||||
image: watercrawl/frontend:${VERSION:-v0.10.2}
|
|
||||||
environment:
|
|
||||||
- VITE_API_BASE_URL=${API_BASE_URL:-http://localhost/api}
|
|
||||||
depends_on:
|
|
||||||
- app
|
|
||||||
|
|
||||||
services:
|
services:
|
||||||
nginx:
|
redis:
|
||||||
image: nginx:alpine
|
image: redis:alpine
|
||||||
volumes:
|
|
||||||
- ./nginx/nginx.conf:/etc/nginx/conf.d/default.conf.template
|
|
||||||
- ./nginx/entrypoint.sh:/entrypoint.sh
|
|
||||||
environment:
|
|
||||||
- MINIO_PRIVATE_BUCKET=${MINIO_PRIVATE_BUCKET:-private}
|
|
||||||
- MINIO_PUBLIC_BUCKET=${MINIO_PUBLIC_BUCKET:-public}
|
|
||||||
command: ["/bin/sh", "/entrypoint.sh"]
|
|
||||||
depends_on:
|
|
||||||
- app
|
|
||||||
- frontend
|
|
||||||
- minio
|
|
||||||
restart: unless-stopped
|
|
||||||
networks:
|
|
||||||
- traefik-proxy
|
|
||||||
- n8n
|
|
||||||
|
|
||||||
labels:
|
|
||||||
- "traefik.enable=true"
|
|
||||||
- "traefik.docker.network=traefik-proxy"
|
|
||||||
|
|
||||||
app:
|
|
||||||
<<: *app
|
|
||||||
command: [ "gunicorn", "-b", "0.0.0.0:9000", "-w", "2", "watercrawl.wsgi:application", "--access-logfile", "-", "--error-logfile", "-", "--timeout", "60" ]
|
|
||||||
|
|
||||||
celery:
|
|
||||||
<<: *app
|
|
||||||
command: [ "celery", "-A", "watercrawl", "worker", "-l", "info", "-S", "django" ]
|
|
||||||
dns:
|
|
||||||
- 1.1.1.1
|
|
||||||
- 8.8.8.8
|
|
||||||
|
|
||||||
celery-beat:
|
|
||||||
<<: *app
|
|
||||||
command: [ "celery", "-A", "watercrawl", "beat", "-l", "info", "-S", "django" ]
|
|
||||||
|
|
||||||
frontend:
|
|
||||||
<<: *frontend
|
|
||||||
command: [ "npm", "run", "serve" ]
|
|
||||||
|
|
||||||
minio:
|
|
||||||
image: minio/minio:RELEASE.2024-11-07T00-52-20Z
|
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
volumes:
|
volumes:
|
||||||
- ./volumes/minio-data:/data
|
- redis-data:/data
|
||||||
command: server /data --console-address ":9001"
|
|
||||||
environment:
|
|
||||||
- MINIO_BROWSER_REDIRECT_URL=${MINIO_BROWSER_REDIRECT_URL:-http://localhost/minio-console/}
|
|
||||||
- MINIO_SERVER_URL=${MINIO_SERVER_URL:-http://localhost/}
|
|
||||||
- MINIO_ROOT_USER=${MINIO_ACCESS_KEY:-minio}
|
|
||||||
- MINIO_ROOT_PASSWORD=${MINIO_SECRET_KEY:-minio123}
|
|
||||||
|
|
||||||
playwright:
|
|
||||||
image: watercrawl/playwright:1.1
|
|
||||||
restart: unless-stopped
|
|
||||||
user: root
|
|
||||||
environment:
|
|
||||||
- AUTH_API_KEY=${PLAYWRIGHT_API_KEY:-your-secret-api-key}
|
|
||||||
- PORT=${PLAYWRIGHT_PORT:-8000}
|
|
||||||
- HOST=${PLAYWRIGHT_HOST:-0.0.0.0}
|
|
||||||
dns:
|
|
||||||
- 8.8.8.8
|
|
||||||
- 1.1.1.1
|
|
||||||
networks:
|
|
||||||
- traefik-proxy
|
|
||||||
- n8n
|
|
||||||
|
|
||||||
db:
|
|
||||||
image: postgres:17.2-alpine3.21
|
|
||||||
restart: unless-stopped
|
|
||||||
environment:
|
|
||||||
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD:-postgres}
|
|
||||||
- POSTGRES_USER=${POSTGRES_USER:-postgres}
|
|
||||||
- POSTGRES_DB=${POSTGRES_DB:-postgres}
|
|
||||||
volumes:
|
|
||||||
- ./volumes/postgres-db:/var/lib/postgresql/data
|
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: [ "CMD-SHELL", "pg_isready" ]
|
test: ["CMD", "redis-cli", "ping"]
|
||||||
interval: 10s
|
interval: 5s
|
||||||
timeout: 5s
|
timeout: 3s
|
||||||
retries: 5
|
retries: 5
|
||||||
|
|
||||||
mcp:
|
playwright-service:
|
||||||
image: watercrawl/mcp:v1.2.0
|
image: mcr.microsoft.com/playwright:v1.56.0-jammy
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
command: [ "sse", "--base-url", "http://app:9000", '--port', '3000', '--endpoint', '/sse' ]
|
command: npx -y playwright@1.56.0 run-server --port 3000 --path /ws
|
||||||
networks:
|
|
||||||
- n8n
|
|
||||||
|
|
||||||
redis:
|
session-keeper:
|
||||||
image: redis:latest
|
build: ./phpsessid-bot
|
||||||
|
image: gcr.forust.xyz/forust/session-keeper:latest
|
||||||
|
pull_policy: build
|
||||||
|
env_file: .env
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
|
depends_on:
|
||||||
|
redis:
|
||||||
|
condition: service_healthy
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD-SHELL", "redis-cli -h redis EXISTS EDU_PHPSESSID | grep -q 1"]
|
||||||
|
interval: 30s
|
||||||
|
timeout: 5s
|
||||||
|
retries: 10
|
||||||
|
start_period: 60s
|
||||||
|
|
||||||
llm:
|
webinar-checker:
|
||||||
image: ollama/ollama:latest
|
build: ./webinar-checker
|
||||||
|
image: gcr.forust.xyz/forust/webinar-checker:latest
|
||||||
|
pull_policy: build
|
||||||
|
env_file: .env
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
volumes:
|
depends_on:
|
||||||
- ./volumes/ollama-models:/root/.ollama
|
redis:
|
||||||
environment:
|
condition: service_healthy
|
||||||
- OLLAMA_DISABLE_TELEMETRY=true
|
session-keeper:
|
||||||
- OLLAMA_KEEP_ALIVE=5m
|
condition: service_healthy
|
||||||
- OLLAMA_HOST=0.0.0.0:11434
|
playwright-service:
|
||||||
- OLLAMA_NUM_PARALLEL=1
|
condition: service_started
|
||||||
- OLLAMA_MAX_LOADED_MODELS=1
|
|
||||||
dns:
|
|
||||||
- 1.1.1.1
|
|
||||||
- 8.8.8.8
|
|
||||||
networks:
|
|
||||||
- n8n
|
|
||||||
|
|
||||||
# docker exec -it edu_master-llm-1 ollama pull neural-chat:7b-q4
|
|
||||||
# docker exec -it edu_master-llm-1 ollama pull mistral:7b-q4
|
|
||||||
|
|
||||||
# lessons-bot:
|
|
||||||
# build:
|
|
||||||
# context: edu_master/lessons_bot/
|
|
||||||
# dockerfile: Dockerfile
|
|
||||||
# restart: unless-stopped
|
|
||||||
# environment:
|
|
||||||
# - LESSONS_BOT_TOKEN=${LESSONS_BOT_TOKEN}
|
|
||||||
# - N8N_WEBHOOK_URL=${N8N_WEBHOOK_URL:-http://n8n:5678/webhook-test/get-lessons}
|
|
||||||
# - N8N_SECRET=${N8N_SECRET:-your-secret-token-here}
|
|
||||||
# - WATERCRAWL_API_URL=${WATERCRAWL_API_URL:-http://app:9000/api}
|
|
||||||
# - PHPSESSID_BOT_URL=${PHPSESSID_BOT_URL:-http://phpsessid-bot:5000}
|
|
||||||
# - EDU_HOST=${EDU_HOST:-edu.edu.vn.ua}
|
|
||||||
# depends_on:
|
|
||||||
# - n8n
|
|
||||||
# - app
|
|
||||||
# - phpsessid-bot
|
|
||||||
# dns:
|
|
||||||
# - 1.1.1.1
|
|
||||||
# - 8.8.8.8
|
|
||||||
# networks:
|
|
||||||
# - default
|
|
||||||
|
|
||||||
phpsessid-bot:
|
|
||||||
build:
|
|
||||||
context: ./phpsessid_bot/
|
|
||||||
dockerfile: Dockerfile
|
|
||||||
restart: unless-stopped
|
|
||||||
environment:
|
|
||||||
- EDU_HOST=${EDU_HOST:-edu.edu.vn.ua}
|
|
||||||
- EDU_LOGIN=${EDU_LOGIN}
|
|
||||||
- EDU_PASSWORD=${EDU_PASSWORD}
|
|
||||||
- BOT_PORT=${PHPSESSID_BOT_PORT:-5000}
|
|
||||||
- BOT_HOST=${PHPSESSID_BOT_HOST:-0.0.0.0}
|
|
||||||
dns:
|
|
||||||
- 1.1.1.1
|
|
||||||
- 8.8.8.8
|
|
||||||
networks:
|
|
||||||
- default
|
|
||||||
|
|
||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
n8n_data:
|
redis-data:
|
||||||
postgres-db:
|
|
||||||
minio-data:
|
|
||||||
ollama-models:
|
|
||||||
lmstudio_data:
|
|
||||||
networks:
|
|
||||||
traefik-proxy:
|
|
||||||
external: true
|
|
||||||
|
|||||||
@@ -1,16 +0,0 @@
|
|||||||
FROM python:3.11-slim
|
|
||||||
|
|
||||||
WORKDIR /app
|
|
||||||
|
|
||||||
# Установка зависимостей
|
|
||||||
COPY requirements.txt .
|
|
||||||
RUN pip install --no-cache-dir -r requirements.txt
|
|
||||||
|
|
||||||
# Копирование кода
|
|
||||||
COPY config.py .
|
|
||||||
COPY utils.py .
|
|
||||||
COPY handlers.py .
|
|
||||||
COPY main.py .
|
|
||||||
|
|
||||||
# Запуск бота
|
|
||||||
CMD ["python", "-u", "main.py"]
|
|
||||||
@@ -1,26 +0,0 @@
|
|||||||
import os
|
|
||||||
from dotenv import load_dotenv
|
|
||||||
|
|
||||||
load_dotenv()
|
|
||||||
|
|
||||||
# Telegram
|
|
||||||
BOT_TOKEN = os.getenv('LESSONS_BOT_TOKEN')
|
|
||||||
|
|
||||||
# n8n
|
|
||||||
N8N_WEBHOOK_URL = os.getenv('N8N_WEBHOOK_URL', 'http://n8n:5678/webhook/homework-check')
|
|
||||||
N8N_SECRET = os.getenv('N8N_SECRET', 'your-secret-token-here')
|
|
||||||
|
|
||||||
# WaterCrawl API
|
|
||||||
WATERCRAWL_API_URL = os.getenv('WATERCRAWL_API_URL', 'http://app:9000/api')
|
|
||||||
|
|
||||||
# PHPSESSID Bot
|
|
||||||
PHPSESSID_BOT_URL = os.getenv('PHPSESSID_BOT_URL', 'http://phpsessid-bot:5000')
|
|
||||||
|
|
||||||
# EDU site
|
|
||||||
EDU_HOST = os.getenv('EDU_HOST', 'edu.edu.vn.ua')
|
|
||||||
EDU_WEBINAR_URL = f'https://{EDU_HOST}/webinar/useractive'
|
|
||||||
|
|
||||||
# Playwright
|
|
||||||
PLAYWRIGHT_SERVER = os.getenv('PLAYWRIGHT_SERVER', 'http://playwright:8000')
|
|
||||||
PLAYWRIGHT_API_KEY = os.getenv('PLAYWRIGHT_API_KEY', 'your-secret-api-key')
|
|
||||||
WEBINAR_WAIT_TIME = int(os.getenv('WEBINAR_WAIT_TIME', '3')) # Секунды ожидания загрузки
|
|
||||||
@@ -1,131 +0,0 @@
|
|||||||
import logging
|
|
||||||
import requests
|
|
||||||
from telegram import Update
|
|
||||||
from telegram.ext import ContextTypes
|
|
||||||
import config
|
|
||||||
from utils import fetch_webinars, format_webinar_message
|
|
||||||
|
|
||||||
logger = logging.getLogger(__name__)
|
|
||||||
|
|
||||||
|
|
||||||
async def start(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
|
||||||
"""Команда /start"""
|
|
||||||
welcome_message = """
|
|
||||||
Привет! Я бот для проверки домашних заданий и вебинаров.
|
|
||||||
|
|
||||||
<b>Команды:</b>
|
|
||||||
/check - Проверить несделанные уроки
|
|
||||||
/webinar - Проверить активные онлайн уроки
|
|
||||||
/help - Помощь
|
|
||||||
"""
|
|
||||||
await update.message.reply_text(welcome_message, parse_mode='HTML')
|
|
||||||
|
|
||||||
|
|
||||||
async def help_command(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
|
||||||
"""Команда /help"""
|
|
||||||
help_text = """
|
|
||||||
<b>Как пользоваться ботом:</b>
|
|
||||||
|
|
||||||
<b>/check</b> - Проверка домашних заданий
|
|
||||||
- Поиск несделанных уроков
|
|
||||||
|
|
||||||
⏱ Проверка занимает 10-30 секунд
|
|
||||||
|
|
||||||
<b>/webinar</b> - Активные онлайн уроки
|
|
||||||
- Проверка активных вебинаровв
|
|
||||||
⏱ Проверка занимает 3-5 секунд
|
|
||||||
"""
|
|
||||||
await update.message.reply_text(help_text, parse_mode='HTML')
|
|
||||||
|
|
||||||
|
|
||||||
async def check_homework(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
|
||||||
"""Команда /check - запускает проверку уроков"""
|
|
||||||
chat_id = update.effective_chat.id
|
|
||||||
user_id = update.effective_user.id
|
|
||||||
username = update.effective_user.username or "unknown"
|
|
||||||
|
|
||||||
# Отправляем уведомление что начали работу
|
|
||||||
status_message = await update.message.reply_text("Запускаю проверку уроков...")
|
|
||||||
|
|
||||||
# Формируем данные для n8n
|
|
||||||
payload = {
|
|
||||||
"chat_id": chat_id,
|
|
||||||
"user_id": user_id,
|
|
||||||
"username": username,
|
|
||||||
"timestamp": update.message.date.isoformat()
|
|
||||||
}
|
|
||||||
|
|
||||||
headers = {
|
|
||||||
"Authorization": f"Bearer {config.N8N_SECRET}",
|
|
||||||
"Content-Type": "application/json"
|
|
||||||
}
|
|
||||||
|
|
||||||
try:
|
|
||||||
logger.info(f"Sending request to n8n for user {user_id}")
|
|
||||||
|
|
||||||
# Отправляем запрос в n8n
|
|
||||||
response = requests.post(
|
|
||||||
config.N8N_WEBHOOK_URL,
|
|
||||||
json=payload,
|
|
||||||
headers=headers,
|
|
||||||
timeout=5 # Короткий таймаут т.к. это асинхронный запрос
|
|
||||||
)
|
|
||||||
|
|
||||||
if response.status_code == 200:
|
|
||||||
await status_message.edit_text(
|
|
||||||
"✅ Запрос принят!\n"
|
|
||||||
"🔄 Парсинг сайта и анализ данных...\n"
|
|
||||||
"⏱ Это займет 10-30 секунд"
|
|
||||||
)
|
|
||||||
logger.info(f"Request accepted for user {user_id}")
|
|
||||||
else:
|
|
||||||
await status_message.edit_text(
|
|
||||||
f"Ошибка при отправке запроса. Функция в разработке\n"
|
|
||||||
f"Код: {response.status_code}"
|
|
||||||
)
|
|
||||||
logger.error(f"n8n returned status {response.status_code}")
|
|
||||||
|
|
||||||
except requests.Timeout:
|
|
||||||
await status_message.edit_text("⏱ Запрос обрабатывается (таймаут соединения)")
|
|
||||||
logger.warning(f"Timeout for user {user_id}")
|
|
||||||
except Exception as e:
|
|
||||||
await status_message.edit_text(f"❌ Ошибка: {str(e)}")
|
|
||||||
logger.error(f"Error for user {user_id}: {e}", exc_info=True)
|
|
||||||
|
|
||||||
|
|
||||||
async def check_webinar(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
|
||||||
"""Команда /webinar - проверяет активные онлайн уроки"""
|
|
||||||
user_id = update.effective_user.id
|
|
||||||
|
|
||||||
# Отправляем уведомление что начали работу
|
|
||||||
status_message = await update.message.reply_text("Проверяю активные вебинары...")
|
|
||||||
|
|
||||||
try:
|
|
||||||
logger.info(f"Checking webinars for user {user_id}")
|
|
||||||
|
|
||||||
# Получаем список вебинаров
|
|
||||||
webinars = fetch_webinars()
|
|
||||||
|
|
||||||
if webinars is None:
|
|
||||||
await status_message.edit_text(
|
|
||||||
"❌ Не удалось получить информацию о вебинарах\n"
|
|
||||||
"Попробуйте позже или обратитесь к администратору\n"
|
|
||||||
"|@MrForust|mr.forust| Либо же прямо сюда."
|
|
||||||
)
|
|
||||||
logger.error(f"Failed to fetch webinars for user {user_id}")
|
|
||||||
return
|
|
||||||
|
|
||||||
# Форматируем и отправляем результат
|
|
||||||
message = format_webinar_message(webinars)
|
|
||||||
await status_message.edit_text(message, parse_mode='HTML', disable_web_page_preview=True)
|
|
||||||
|
|
||||||
logger.info(f"Webinar check completed for user {user_id}: found {len(webinars)} webinars")
|
|
||||||
|
|
||||||
except Exception as e:
|
|
||||||
await status_message.edit_text(f"❌ Ошибка: {str(e)}")
|
|
||||||
logger.error(f"Error checking webinars for user {user_id}: {e}", exc_info=True)
|
|
||||||
|
|
||||||
|
|
||||||
async def error_handler(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
|
||||||
"""Обработчик ошибок"""
|
|
||||||
logger.error(f"Update {update} caused error {context.error}", exc_info=context.error)
|
|
||||||
@@ -1,42 +0,0 @@
|
|||||||
import logging
|
|
||||||
from telegram import Update
|
|
||||||
from telegram.ext import Application, CommandHandler
|
|
||||||
import config
|
|
||||||
from handlers import start, help_command, check_homework, check_webinar, error_handler
|
|
||||||
|
|
||||||
# Настройка логирования
|
|
||||||
logging.basicConfig(
|
|
||||||
format='%(asctime)s - %(name)s - %(levelname)s - %(message)s',
|
|
||||||
level=logging.INFO
|
|
||||||
)
|
|
||||||
logger = logging.getLogger(__name__)
|
|
||||||
|
|
||||||
|
|
||||||
def main():
|
|
||||||
"""Запуск бота"""
|
|
||||||
if not config.BOT_TOKEN:
|
|
||||||
logger.error("LESSONS_BOT_TOKEN not set!")
|
|
||||||
return
|
|
||||||
|
|
||||||
# Создаем приложение
|
|
||||||
application = Application.builder().token(config.BOT_TOKEN).build()
|
|
||||||
|
|
||||||
# Регистрируем обработчики команд
|
|
||||||
application.add_handler(CommandHandler("start", start))
|
|
||||||
application.add_handler(CommandHandler("help", help_command))
|
|
||||||
application.add_handler(CommandHandler("check", check_homework))
|
|
||||||
application.add_handler(CommandHandler("webinar", check_webinar))
|
|
||||||
|
|
||||||
# Регистрируем обработчик ошибок
|
|
||||||
application.add_error_handler(error_handler)
|
|
||||||
|
|
||||||
# Запускаем бота
|
|
||||||
logger.info("Lessons Bot started!")
|
|
||||||
logger.info(f"PHPSESSID Bot URL: {config.PHPSESSID_BOT_URL}")
|
|
||||||
logger.info(f"n8n Webhook URL: {config.N8N_WEBHOOK_URL}")
|
|
||||||
|
|
||||||
application.run_polling(allowed_updates=Update.ALL_TYPES)
|
|
||||||
|
|
||||||
|
|
||||||
if __name__ == '__main__':
|
|
||||||
main()
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
python-telegram-bot==20.7
|
|
||||||
requests==2.31.0
|
|
||||||
beautifulsoup4==4.12.2
|
|
||||||
python-dotenv==1.0.0
|
|
||||||
lxml==4.9.3
|
|
||||||
@@ -1,258 +0,0 @@
|
|||||||
import logging
|
|
||||||
import requests
|
|
||||||
from bs4 import BeautifulSoup
|
|
||||||
from typing import Optional, Dict, List
|
|
||||||
import config
|
|
||||||
|
|
||||||
logger = logging.getLogger(__name__)
|
|
||||||
|
|
||||||
|
|
||||||
def get_phpsessid() -> Optional[str]:
|
|
||||||
"""
|
|
||||||
Получает валидный PHPSESSID через phpsessid-bot
|
|
||||||
|
|
||||||
Returns:
|
|
||||||
str: PHPSESSID или None в случае ошибки
|
|
||||||
"""
|
|
||||||
try:
|
|
||||||
url = f"{config.PHPSESSID_BOT_URL}/get-session"
|
|
||||||
logger.info(f"Requesting PHPSESSID from {url}")
|
|
||||||
|
|
||||||
response = requests.post(url, timeout=10)
|
|
||||||
|
|
||||||
if response.status_code == 200:
|
|
||||||
data = response.json()
|
|
||||||
if data.get('success'):
|
|
||||||
phpsessid = data.get('phpsessid')
|
|
||||||
logger.info(f"Got PHPSESSID: {phpsessid[:10]}...")
|
|
||||||
return phpsessid
|
|
||||||
else:
|
|
||||||
logger.error(f"Failed to get PHPSESSID: {data.get('error')}")
|
|
||||||
return None
|
|
||||||
else:
|
|
||||||
logger.error(f"PHPSESSID bot returned status {response.status_code}")
|
|
||||||
return None
|
|
||||||
|
|
||||||
except Exception as e:
|
|
||||||
logger.error(f"Error getting PHPSESSID: {e}", exc_info=True)
|
|
||||||
return None
|
|
||||||
|
|
||||||
|
|
||||||
def parse_webinar_table(html_content: str) -> List[Dict[str, str]]:
|
|
||||||
"""
|
|
||||||
Парсит таблицу с вебинарами
|
|
||||||
|
|
||||||
Args:
|
|
||||||
html_content: HTML контент страницы
|
|
||||||
|
|
||||||
Returns:
|
|
||||||
List[Dict]: Список вебинаров или пустой список
|
|
||||||
"""
|
|
||||||
try:
|
|
||||||
soup = BeautifulSoup(html_content, 'html.parser')
|
|
||||||
|
|
||||||
# Находим таблицу с вебинарами
|
|
||||||
meetings_div = soup.find('div', {'id': 'meetings'})
|
|
||||||
if not meetings_div:
|
|
||||||
logger.warning("meetings div not found")
|
|
||||||
return []
|
|
||||||
|
|
||||||
table = meetings_div.find('table', {'class': 'table table-zebra'})
|
|
||||||
if not table:
|
|
||||||
logger.warning("table not found")
|
|
||||||
return []
|
|
||||||
|
|
||||||
tbody = table.find('tbody')
|
|
||||||
if not tbody:
|
|
||||||
logger.warning("tbody not found")
|
|
||||||
return []
|
|
||||||
|
|
||||||
rows = tbody.find_all('tr')
|
|
||||||
if not rows:
|
|
||||||
return []
|
|
||||||
|
|
||||||
# Проверяем на сообщение "Жодного онлайн уроку зараз"
|
|
||||||
first_row = rows[0]
|
|
||||||
td = first_row.find('td')
|
|
||||||
if td and 'Жодного онлайн уроку зараз' in td.get_text(strip=True):
|
|
||||||
logger.info("No webinars available")
|
|
||||||
return []
|
|
||||||
|
|
||||||
# Парсим активные вебинары
|
|
||||||
webinars = []
|
|
||||||
for row in rows:
|
|
||||||
tds = row.find_all('td')
|
|
||||||
if len(tds) >= 4:
|
|
||||||
webinar = {
|
|
||||||
'topic': tds[0].get_text(strip=True),
|
|
||||||
'course': tds[1].get_text(strip=True),
|
|
||||||
'teacher': tds[2].get_text(strip=True),
|
|
||||||
'join_link': tds[3].find('a')['href'] if tds[3].find('a') else ''
|
|
||||||
}
|
|
||||||
webinars.append(webinar)
|
|
||||||
|
|
||||||
logger.info(f"Parsed {len(webinars)} webinars")
|
|
||||||
return webinars
|
|
||||||
|
|
||||||
except Exception as e:
|
|
||||||
logger.error(f"Error parsing webinar table: {e}", exc_info=True)
|
|
||||||
return []
|
|
||||||
|
|
||||||
|
|
||||||
def fetch_webinars_with_playwright() -> Optional[List[Dict[str, str]]]:
|
|
||||||
"""
|
|
||||||
Получает список активных вебинаров используя Playwright для динамического контента
|
|
||||||
|
|
||||||
Returns:
|
|
||||||
List[Dict]: Список вебинаров или None в случае ошибки
|
|
||||||
"""
|
|
||||||
# Получаем PHPSESSID
|
|
||||||
phpsessid = get_phpsessid()
|
|
||||||
if not phpsessid:
|
|
||||||
logger.error("Failed to get PHPSESSID")
|
|
||||||
return None
|
|
||||||
|
|
||||||
try:
|
|
||||||
# Подготавливаем cookies для Playwright
|
|
||||||
cookies = [
|
|
||||||
{
|
|
||||||
'name': 'PHPSESSID',
|
|
||||||
'value': phpsessid,
|
|
||||||
'domain': config.EDU_HOST,
|
|
||||||
'path': '/'
|
|
||||||
}
|
|
||||||
]
|
|
||||||
|
|
||||||
# Запрос к Playwright серверу
|
|
||||||
playwright_request = {
|
|
||||||
'url': config.EDU_WEBINAR_URL,
|
|
||||||
'cookies': cookies,
|
|
||||||
'wait_until': 'networkidle', # Ждем пока сеть успокоится
|
|
||||||
'wait_time': config.WEBINAR_WAIT_TIME * 1000, # Дополнительное ожидание в миллисекундах
|
|
||||||
'user_agent': 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36'
|
|
||||||
}
|
|
||||||
|
|
||||||
headers = {
|
|
||||||
'Authorization': f'Bearer {config.PLAYWRIGHT_API_KEY}',
|
|
||||||
'Content-Type': 'application/json'
|
|
||||||
}
|
|
||||||
|
|
||||||
logger.info(f"Fetching webinars via Playwright from {config.EDU_WEBINAR_URL}")
|
|
||||||
logger.info(f"Will wait {config.WEBINAR_WAIT_TIME} seconds for dynamic content")
|
|
||||||
|
|
||||||
response = requests.post(
|
|
||||||
f"{config.PLAYWRIGHT_SERVER}/render",
|
|
||||||
json=playwright_request,
|
|
||||||
headers=headers,
|
|
||||||
timeout=30
|
|
||||||
)
|
|
||||||
|
|
||||||
if response.status_code != 200:
|
|
||||||
logger.error(f"Playwright server returned status {response.status_code}")
|
|
||||||
logger.error(f"Response: {response.text}")
|
|
||||||
return None
|
|
||||||
|
|
||||||
result = response.json()
|
|
||||||
html_content = result.get('html', '')
|
|
||||||
|
|
||||||
if not html_content:
|
|
||||||
logger.error("No HTML content in Playwright response")
|
|
||||||
return None
|
|
||||||
|
|
||||||
# Парсим таблицу
|
|
||||||
webinars = parse_webinar_table(html_content)
|
|
||||||
return webinars
|
|
||||||
|
|
||||||
except Exception as e:
|
|
||||||
logger.error(f"Error fetching webinars via Playwright: {e}", exc_info=True)
|
|
||||||
return None
|
|
||||||
|
|
||||||
|
|
||||||
def fetch_webinars() -> Optional[List[Dict[str, str]]]:
|
|
||||||
"""
|
|
||||||
Получает список активных вебинаров
|
|
||||||
Сначала пробует через Playwright (для динамического контента),
|
|
||||||
при неудаче - через обычный requests
|
|
||||||
|
|
||||||
Returns:
|
|
||||||
List[Dict]: Список вебинаров или None в случае ошибки
|
|
||||||
"""
|
|
||||||
# Пробуем через Playwright
|
|
||||||
logger.info("Attempting to fetch via Playwright for dynamic content")
|
|
||||||
webinars = fetch_webinars_with_playwright()
|
|
||||||
|
|
||||||
if webinars is not None:
|
|
||||||
return webinars
|
|
||||||
|
|
||||||
# Fallback на обычный requests
|
|
||||||
logger.warning("Playwright fetch failed, falling back to simple requests")
|
|
||||||
|
|
||||||
# Получаем PHPSESSID
|
|
||||||
phpsessid = get_phpsessid()
|
|
||||||
if not phpsessid:
|
|
||||||
logger.error("Failed to get PHPSESSID")
|
|
||||||
return None
|
|
||||||
|
|
||||||
# Запрашиваем страницу с вебинарами
|
|
||||||
try:
|
|
||||||
headers = {
|
|
||||||
'User-Agent': 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36',
|
|
||||||
'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8',
|
|
||||||
'Accept-Language': 'ru-RU,ru;q=0.9,uk;q=0.8',
|
|
||||||
'Referer': f'https://{config.EDU_HOST}/'
|
|
||||||
}
|
|
||||||
|
|
||||||
cookies = {
|
|
||||||
'PHPSESSID': phpsessid
|
|
||||||
}
|
|
||||||
|
|
||||||
logger.info(f"Fetching webinars from {config.EDU_WEBINAR_URL}")
|
|
||||||
response = requests.get(
|
|
||||||
config.EDU_WEBINAR_URL,
|
|
||||||
headers=headers,
|
|
||||||
cookies=cookies,
|
|
||||||
timeout=15
|
|
||||||
)
|
|
||||||
|
|
||||||
if response.status_code != 200:
|
|
||||||
logger.error(f"Failed to fetch webinars page: {response.status_code}")
|
|
||||||
return None
|
|
||||||
|
|
||||||
# Парсим таблицу
|
|
||||||
webinars = parse_webinar_table(response.text)
|
|
||||||
return webinars
|
|
||||||
|
|
||||||
except Exception as e:
|
|
||||||
logger.error(f"Error fetching webinars: {e}", exc_info=True)
|
|
||||||
return None
|
|
||||||
|
|
||||||
|
|
||||||
def format_webinar_message(webinars: List[Dict[str, str]]) -> str:
|
|
||||||
"""
|
|
||||||
Форматирует список вебинаров для отправки в Telegram
|
|
||||||
|
|
||||||
Args:
|
|
||||||
webinars: Список вебинаров
|
|
||||||
|
|
||||||
Returns:
|
|
||||||
str: Отформатированное сообщение
|
|
||||||
"""
|
|
||||||
if not webinars:
|
|
||||||
return "📭 Жодного онлайн уроку зараз"
|
|
||||||
|
|
||||||
message = "🎓 <b>Активні онлайн уроки:</b>\n\n"
|
|
||||||
|
|
||||||
for i, webinar in enumerate(webinars, 1):
|
|
||||||
message += f"<b>{i}. {webinar['topic']}</b>\n"
|
|
||||||
message += f"📚 Курс: {webinar['course']}\n"
|
|
||||||
message += f"👨🏫 Вчитель: {webinar['teacher']}\n"
|
|
||||||
|
|
||||||
if webinar['join_link']:
|
|
||||||
full_link = webinar['join_link']
|
|
||||||
if not full_link.startswith('http'):
|
|
||||||
full_link = f"https://{config.EDU_HOST}{webinar['join_link']}"
|
|
||||||
message += f"🔗 <a href='{full_link}'>Увійти до уроку</a>\n"
|
|
||||||
|
|
||||||
message += "\n"
|
|
||||||
|
|
||||||
return message
|
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
#!/bin/sh
|
|
||||||
set -e
|
|
||||||
|
|
||||||
# Replace environment variables in the Nginx configuration template
|
|
||||||
envsubst '${MINIO_PRIVATE_BUCKET} ${MINIO_PUBLIC_BUCKET}' < /etc/nginx/conf.d/default.conf.template > /etc/nginx/conf.d/default.conf
|
|
||||||
|
|
||||||
# Start Nginx
|
|
||||||
exec nginx -g 'daemon off;'
|
|
||||||
@@ -1,87 +0,0 @@
|
|||||||
server {
|
|
||||||
listen 80;
|
|
||||||
server_name localhost;
|
|
||||||
client_max_body_size 100M;
|
|
||||||
|
|
||||||
# Frontend
|
|
||||||
location / {
|
|
||||||
proxy_pass http://frontend:80;
|
|
||||||
proxy_set_header Host $host;
|
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
||||||
proxy_set_header X-Forwarded-Proto $scheme;
|
|
||||||
}
|
|
||||||
|
|
||||||
# API
|
|
||||||
location /api/ {
|
|
||||||
proxy_pass http://app:9000;
|
|
||||||
proxy_set_header Host $host;
|
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
||||||
proxy_set_header X-Forwarded-Proto $scheme;
|
|
||||||
}
|
|
||||||
|
|
||||||
# MCP
|
|
||||||
location ~ ^/(sse|messages) {
|
|
||||||
proxy_pass http://mcp:3000;
|
|
||||||
proxy_set_header Host $host;
|
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
||||||
proxy_set_header X-Forwarded-Proto $scheme;
|
|
||||||
|
|
||||||
|
|
||||||
# Important SSE settings
|
|
||||||
proxy_http_version 1.1;
|
|
||||||
proxy_set_header Connection "";
|
|
||||||
|
|
||||||
# Disable buffering so events are sent immediately
|
|
||||||
proxy_buffering off;
|
|
||||||
proxy_cache off;
|
|
||||||
|
|
||||||
# Increase timeouts so connection stays open
|
|
||||||
proxy_read_timeout 3600s;
|
|
||||||
proxy_send_timeout 3600s;
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
# MinIO private bucket
|
|
||||||
location /${MINIO_PRIVATE_BUCKET}/ {
|
|
||||||
proxy_pass http://minio:9000/${MINIO_PRIVATE_BUCKET}/;
|
|
||||||
proxy_set_header Host $host;
|
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
||||||
proxy_set_header X-Forwarded-Proto $scheme;
|
|
||||||
proxy_buffering off;
|
|
||||||
}
|
|
||||||
|
|
||||||
# MinIO public bucket
|
|
||||||
location /${MINIO_PUBLIC_BUCKET}/ {
|
|
||||||
proxy_pass http://minio:9000/${MINIO_PUBLIC_BUCKET}/;
|
|
||||||
proxy_set_header Host $host;
|
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
||||||
proxy_set_header X-Forwarded-Proto $scheme;
|
|
||||||
proxy_buffering off;
|
|
||||||
}
|
|
||||||
|
|
||||||
# MinIO API - for direct S3 operations
|
|
||||||
# location /minio/api/ {
|
|
||||||
# proxy_pass http://minio:9000/;
|
|
||||||
# proxy_set_header Host $host;
|
|
||||||
# proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
||||||
# proxy_set_header X-Forwarded-Proto $scheme;
|
|
||||||
# proxy_buffering off;
|
|
||||||
# }
|
|
||||||
|
|
||||||
# MinIO Console
|
|
||||||
location /minio-console/ {
|
|
||||||
proxy_pass http://minio:9001/;
|
|
||||||
proxy_set_header Host $host;
|
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
||||||
proxy_set_header X-Forwarded-Proto $scheme;
|
|
||||||
# Rewrite location headers
|
|
||||||
proxy_redirect / /minio-console/;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
FROM python:3.11-slim
|
||||||
|
|
||||||
|
WORKDIR /app
|
||||||
|
|
||||||
|
# Install system dependencies
|
||||||
|
RUN apt-get update && apt-get install -y --no-install-recommends redis-tools && rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
|
# Install dependencies
|
||||||
|
RUN pip install --no-cache-dir requests==2.32.3 redis==5.2.1
|
||||||
|
|
||||||
|
# Copy application code
|
||||||
|
COPY . .
|
||||||
|
|
||||||
|
# Run the bot
|
||||||
|
CMD ["python", "bot.py"]
|
||||||
@@ -0,0 +1,132 @@
|
|||||||
|
import logging
|
||||||
|
import os
|
||||||
|
import time
|
||||||
|
from datetime import datetime
|
||||||
|
|
||||||
|
import redis
|
||||||
|
import requests
|
||||||
|
|
||||||
|
# Configure logging
|
||||||
|
logging.basicConfig(level=logging.INFO, format='%(asctime)s - %(levelname)s - %(message)s')
|
||||||
|
logger = logging.getLogger(__name__)
|
||||||
|
|
||||||
|
|
||||||
|
# Load configuration (adapted to .env keys)
|
||||||
|
def _env(key, default=None):
|
||||||
|
v = os.getenv(key, default)
|
||||||
|
if isinstance(v, str) and len(v) >= 2 and ((v[0] == '"' and v[-1] == '"') or (v[0] == "'" and v[-1] == "'")):
|
||||||
|
return v[1:-1]
|
||||||
|
return v
|
||||||
|
|
||||||
|
|
||||||
|
LOGIN = _env('KEEPER_LOGIN')
|
||||||
|
PASSWORD = _env('KEEPER_PASSWORD')
|
||||||
|
|
||||||
|
EDU_BASE = _env('EDU_URL_BASE', 'https://edu.edu.vn.ua')
|
||||||
|
EDU_LOGIN_PATH = _env('EDU_URL_LOGIN', '/user/login')
|
||||||
|
EDU_COURSES_PATH = _env('EDU_URL_COURSES', '/course/userlist')
|
||||||
|
URL_LOGIN = f'{EDU_BASE.rstrip("/")}/{EDU_LOGIN_PATH.lstrip("/")}'
|
||||||
|
URL_VERIFY = f'{EDU_BASE.rstrip("/")}/{EDU_COURSES_PATH.lstrip("/")}'
|
||||||
|
|
||||||
|
INTERVAL = int(_env('KEEPER_INTERVAL', 10))
|
||||||
|
USER_AGENT = _env(
|
||||||
|
'USER_AGENT',
|
||||||
|
'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36',
|
||||||
|
)
|
||||||
|
REDIS_HOST = _env('REDIS_HOST', 'redis')
|
||||||
|
REDIS_PORT = int(_env('REDIS_PORT', 6379))
|
||||||
|
|
||||||
|
SUCCESS_FILE = '/tmp/last_success' # noqa: S108
|
||||||
|
|
||||||
|
|
||||||
|
def touch_success_file():
|
||||||
|
"""Updates the timestamp of the success file for healthchecks."""
|
||||||
|
try:
|
||||||
|
with open(SUCCESS_FILE, 'w') as f:
|
||||||
|
f.write(str(datetime.now().timestamp()))
|
||||||
|
except Exception as e:
|
||||||
|
logger.error(f'Failed to touch success file: {e}')
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
logger.info('Starting Session Keeper Bot')
|
||||||
|
|
||||||
|
# Connect to Redis
|
||||||
|
try:
|
||||||
|
redis_client = redis.Redis(host=REDIS_HOST, port=REDIS_PORT, decode_responses=True)
|
||||||
|
redis_client.ping()
|
||||||
|
logger.info(f'Connected to Redis at {REDIS_HOST}:{REDIS_PORT}')
|
||||||
|
except Exception as e:
|
||||||
|
logger.error(f'Failed to connect to Redis: {e}')
|
||||||
|
return
|
||||||
|
|
||||||
|
session = requests.Session()
|
||||||
|
|
||||||
|
# Set headers
|
||||||
|
headers = {
|
||||||
|
'User-Agent': USER_AGENT,
|
||||||
|
'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7',
|
||||||
|
'Accept-Language': 'en-US,en;q=0.9',
|
||||||
|
'Cache-Control': 'max-age=0',
|
||||||
|
'Upgrade-Insecure-Requests': '1',
|
||||||
|
'Sec-Fetch-Site': 'same-origin',
|
||||||
|
'Sec-Fetch-Mode': 'navigate',
|
||||||
|
'Sec-Fetch-User': '?1',
|
||||||
|
'Sec-Fetch-Dest': 'document',
|
||||||
|
'Sec-Ch-Ua': '"Not_A Brand";v="99", "Chromium";v="142"',
|
||||||
|
'Sec-Ch-Ua-Mobile': '?0',
|
||||||
|
'Sec-Ch-Ua-Platform': '"Linux"',
|
||||||
|
'Accept-Encoding': 'gzip, deflate, br',
|
||||||
|
'Priority': 'u=0, i',
|
||||||
|
}
|
||||||
|
session.headers.update(headers)
|
||||||
|
|
||||||
|
while True:
|
||||||
|
try:
|
||||||
|
logger.info('Attempting login...')
|
||||||
|
|
||||||
|
# Login payload
|
||||||
|
payload = {'login': LOGIN, 'password': PASSWORD}
|
||||||
|
|
||||||
|
# Perform Login
|
||||||
|
# Note: The user request shows a POST to /user/login with form data
|
||||||
|
# We need to make sure we handle the PHPSESSID correctly.
|
||||||
|
# If we already have a PHPSESSID, requests will send it.
|
||||||
|
|
||||||
|
login_response = session.post(URL_LOGIN, data=payload, allow_redirects=True)
|
||||||
|
|
||||||
|
logger.info(f'Login Response Status: {login_response.status_code}')
|
||||||
|
logger.info(f'Cookies after login: {session.cookies.get_dict()}')
|
||||||
|
|
||||||
|
# Verify Session
|
||||||
|
logger.info('Verifying session...')
|
||||||
|
verify_response = session.get(URL_VERIFY, allow_redirects=False)
|
||||||
|
|
||||||
|
logger.info(f'Verify Response Status: {verify_response.status_code}')
|
||||||
|
|
||||||
|
if verify_response.status_code == 200:
|
||||||
|
logger.info('Session verification SUCCESS (200 OK).')
|
||||||
|
touch_success_file()
|
||||||
|
|
||||||
|
# Save PHPSESSID to Redis
|
||||||
|
phpsessid = session.cookies.get('PHPSESSID')
|
||||||
|
if phpsessid:
|
||||||
|
try:
|
||||||
|
redis_client.set('EDU_PHPSESSID', phpsessid)
|
||||||
|
logger.info(f'Saved PHPSESSID to Redis: {phpsessid}')
|
||||||
|
except Exception as e:
|
||||||
|
logger.error(f'Failed to save PHPSESSID to Redis: {e}')
|
||||||
|
elif verify_response.status_code == 302:
|
||||||
|
logger.warning('Session verification FAILED (302 Redirect). Session might be invalid.')
|
||||||
|
else:
|
||||||
|
logger.warning(f'Session verification returned unexpected status: {verify_response.status_code}')
|
||||||
|
|
||||||
|
except Exception as e:
|
||||||
|
logger.error(f'An error occurred: {e}')
|
||||||
|
|
||||||
|
logger.info(f'Sleeping for {INTERVAL} minutes...')
|
||||||
|
time.sleep(INTERVAL * 60)
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == '__main__':
|
||||||
|
main()
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
FROM python:3.11-slim
|
|
||||||
|
|
||||||
WORKDIR /app
|
|
||||||
|
|
||||||
# Устанавливаем зависимости
|
|
||||||
RUN pip install --no-cache-dir flask requests
|
|
||||||
|
|
||||||
# Копируем код бота
|
|
||||||
COPY main.py .
|
|
||||||
|
|
||||||
# Открываем порт
|
|
||||||
EXPOSE 5000
|
|
||||||
|
|
||||||
# Запускаем бот
|
|
||||||
CMD ["python", "-u", "main.py"]
|
|
||||||
@@ -1,216 +0,0 @@
|
|||||||
import os
|
|
||||||
import logging
|
|
||||||
from flask import Flask, request, jsonify
|
|
||||||
import requests
|
|
||||||
from datetime import datetime
|
|
||||||
|
|
||||||
# Настройка логирования
|
|
||||||
logging.basicConfig(
|
|
||||||
level=logging.INFO,
|
|
||||||
format='%(asctime)s - %(name)s - %(levelname)s - %(message)s'
|
|
||||||
)
|
|
||||||
logger = logging.getLogger(__name__)
|
|
||||||
|
|
||||||
app = Flask(__name__)
|
|
||||||
|
|
||||||
# Конфигурация из переменных окружения
|
|
||||||
EDU_HOST = os.getenv('EDU_HOST', 'edu.edu.vn.ua')
|
|
||||||
EDU_LOGIN = os.getenv('EDU_LOGIN', '')
|
|
||||||
EDU_PASSWORD = os.getenv('EDU_PASSWORD', '')
|
|
||||||
BOT_PORT = int(os.getenv('BOT_PORT', '5000'))
|
|
||||||
BOT_HOST = os.getenv('BOT_HOST', '0.0.0.0')
|
|
||||||
|
|
||||||
# Кэш для хранения актуальной сессии
|
|
||||||
session_cache = {
|
|
||||||
'phpsessid': None,
|
|
||||||
'expires_at': None
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
def login_and_get_session():
|
|
||||||
"""
|
|
||||||
Выполняет логин и возвращает новый PHPSESSID
|
|
||||||
"""
|
|
||||||
url = f"https://{EDU_HOST}/user/login"
|
|
||||||
|
|
||||||
headers = {
|
|
||||||
'Cache-Control': 'max-age=0',
|
|
||||||
'Sec-Ch-Ua': '"Chromium";v="141", "Not?A_Brand";v="8"',
|
|
||||||
'Sec-Ch-Ua-Mobile': '?0',
|
|
||||||
'Sec-Ch-Ua-Platform': '"Linux"',
|
|
||||||
'Accept-Language': 'ru-RU,ru;q=0.9',
|
|
||||||
'Origin': f'https://{EDU_HOST}',
|
|
||||||
'Content-Type': 'application/x-www-form-urlencoded',
|
|
||||||
'Upgrade-Insecure-Requests': '1',
|
|
||||||
'User-Agent': 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36',
|
|
||||||
'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7',
|
|
||||||
'Sec-Fetch-Site': 'same-origin',
|
|
||||||
'Sec-Fetch-Mode': 'navigate',
|
|
||||||
'Sec-Fetch-User': '?1',
|
|
||||||
'Sec-Fetch-Dest': 'document',
|
|
||||||
'Referer': f'https://{EDU_HOST}/',
|
|
||||||
'Accept-Encoding': 'gzip, deflate, br',
|
|
||||||
'Priority': 'u=0, i'
|
|
||||||
}
|
|
||||||
|
|
||||||
data = {
|
|
||||||
'login': EDU_LOGIN,
|
|
||||||
'password': EDU_PASSWORD
|
|
||||||
}
|
|
||||||
|
|
||||||
try:
|
|
||||||
logger.info(f"Attempting login to {url}")
|
|
||||||
response = requests.post(
|
|
||||||
url,
|
|
||||||
data=data,
|
|
||||||
headers=headers,
|
|
||||||
allow_redirects=False,
|
|
||||||
timeout=10
|
|
||||||
)
|
|
||||||
|
|
||||||
# Получаем PHPSESSID из cookies
|
|
||||||
phpsessid = response.cookies.get('PHPSESSID')
|
|
||||||
|
|
||||||
if phpsessid:
|
|
||||||
logger.info(f"Login successful, got PHPSESSID: {phpsessid[:10]}...")
|
|
||||||
return {
|
|
||||||
'success': True,
|
|
||||||
'phpsessid': phpsessid,
|
|
||||||
'status_code': response.status_code
|
|
||||||
}
|
|
||||||
else:
|
|
||||||
logger.warning(f"Login failed: no PHPSESSID in response. Status: {response.status_code}")
|
|
||||||
return {
|
|
||||||
'success': False,
|
|
||||||
'error': 'No PHPSESSID in response',
|
|
||||||
'status_code': response.status_code
|
|
||||||
}
|
|
||||||
|
|
||||||
except requests.exceptions.RequestException as e:
|
|
||||||
logger.error(f"Login request failed: {str(e)}")
|
|
||||||
return {
|
|
||||||
'success': False,
|
|
||||||
'error': str(e)
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
def validate_phpsessid(phpsessid):
|
|
||||||
"""
|
|
||||||
Проверяет валидность существующего PHPSESSID
|
|
||||||
"""
|
|
||||||
url = f"https://{EDU_HOST}/"
|
|
||||||
|
|
||||||
headers = {
|
|
||||||
'User-Agent': 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36',
|
|
||||||
'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8'
|
|
||||||
}
|
|
||||||
|
|
||||||
cookies = {
|
|
||||||
'PHPSESSID': phpsessid
|
|
||||||
}
|
|
||||||
|
|
||||||
try:
|
|
||||||
response = requests.get(url, headers=headers, cookies=cookies, timeout=10)
|
|
||||||
|
|
||||||
# Проверяем, не редиректит ли на страницу логина
|
|
||||||
is_valid = response.status_code == 200 and '/user/login' not in response.url
|
|
||||||
|
|
||||||
return {
|
|
||||||
'valid': is_valid,
|
|
||||||
'status_code': response.status_code,
|
|
||||||
'url': response.url
|
|
||||||
}
|
|
||||||
except requests.exceptions.RequestException as e:
|
|
||||||
logger.error(f"Validation request failed: {str(e)}")
|
|
||||||
return {
|
|
||||||
'valid': False,
|
|
||||||
'error': str(e)
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
@app.route('/health', methods=['GET'])
|
|
||||||
def health():
|
|
||||||
"""Health check endpoint"""
|
|
||||||
return jsonify({'status': 'ok', 'timestamp': datetime.now().isoformat()})
|
|
||||||
|
|
||||||
|
|
||||||
@app.route('/get-session', methods=['POST', 'GET'])
|
|
||||||
def get_session():
|
|
||||||
"""
|
|
||||||
Основной endpoint для получения валидного PHPSESSID
|
|
||||||
Возвращает кэшированную сессию или создает новую
|
|
||||||
"""
|
|
||||||
result = login_and_get_session()
|
|
||||||
|
|
||||||
if result['success']:
|
|
||||||
session_cache['phpsessid'] = result['phpsessid']
|
|
||||||
session_cache['last_updated'] = datetime.now().isoformat()
|
|
||||||
|
|
||||||
return jsonify({
|
|
||||||
'success': True,
|
|
||||||
'phpsessid': result['phpsessid'],
|
|
||||||
'timestamp': datetime.now().isoformat()
|
|
||||||
})
|
|
||||||
else:
|
|
||||||
return jsonify({
|
|
||||||
'success': False,
|
|
||||||
'error': result.get('error', 'Login failed'),
|
|
||||||
'timestamp': datetime.now().isoformat()
|
|
||||||
}), 400
|
|
||||||
|
|
||||||
|
|
||||||
@app.route('/validate-session', methods=['POST'])
|
|
||||||
def validate_session():
|
|
||||||
"""
|
|
||||||
Проверяет валидность переданного PHPSESSID
|
|
||||||
"""
|
|
||||||
data = request.get_json() or {}
|
|
||||||
phpsessid = data.get('phpsessid') or request.args.get('phpsessid')
|
|
||||||
|
|
||||||
if not phpsessid:
|
|
||||||
return jsonify({
|
|
||||||
'success': False,
|
|
||||||
'error': 'PHPSESSID not provided'
|
|
||||||
}), 400
|
|
||||||
|
|
||||||
validation_result = validate_phpsessid(phpsessid)
|
|
||||||
|
|
||||||
return jsonify({
|
|
||||||
'success': True,
|
|
||||||
'valid': validation_result.get('valid', False),
|
|
||||||
'details': validation_result,
|
|
||||||
'timestamp': datetime.now().isoformat()
|
|
||||||
})
|
|
||||||
|
|
||||||
|
|
||||||
@app.route('/refresh-session', methods=['POST', 'GET'])
|
|
||||||
def refresh_session():
|
|
||||||
"""
|
|
||||||
Принудительно обновляет сессию
|
|
||||||
"""
|
|
||||||
result = login_and_get_session()
|
|
||||||
|
|
||||||
if result['success']:
|
|
||||||
return jsonify({
|
|
||||||
'success': True,
|
|
||||||
'phpsessid': result['phpsessid'],
|
|
||||||
'message': 'Session refreshed successfully',
|
|
||||||
'timestamp': datetime.now().isoformat()
|
|
||||||
})
|
|
||||||
else:
|
|
||||||
return jsonify({
|
|
||||||
'success': False,
|
|
||||||
'error': result.get('error', 'Failed to refresh session'),
|
|
||||||
'timestamp': datetime.now().isoformat()
|
|
||||||
}), 400
|
|
||||||
|
|
||||||
|
|
||||||
if __name__ == '__main__':
|
|
||||||
if not EDU_LOGIN or not EDU_PASSWORD:
|
|
||||||
logger.error("EDU_LOGIN and EDU_PASSWORD must be set!")
|
|
||||||
exit(1)
|
|
||||||
|
|
||||||
logger.info(f"Starting PHPSESSID validator bot on {BOT_HOST}:{BOT_PORT}")
|
|
||||||
logger.info(f"Target host: {EDU_HOST}")
|
|
||||||
|
|
||||||
app.run(host=BOT_HOST, port=BOT_PORT, debug=False)
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
flask==3.0.0
|
|
||||||
requests==2.31.0
|
|
||||||
Werkzeug==3.0.1
|
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
FROM python:3.11-slim
|
||||||
|
|
||||||
|
WORKDIR /app
|
||||||
|
|
||||||
|
# Install dependencies
|
||||||
|
RUN pip install --no-cache-dir pip==25.0.1 && pip install --no-cache-dir playwright==1.56.0 redis==5.2.1 requests==2.32.3 "python-telegram-bot[job-queue]==21.10"
|
||||||
|
|
||||||
|
COPY checker.py .
|
||||||
|
|
||||||
|
CMD ["python", "checker.py"]
|
||||||
@@ -0,0 +1,965 @@
|
|||||||
|
import contextlib
|
||||||
|
import json
|
||||||
|
import logging
|
||||||
|
import os
|
||||||
|
import re
|
||||||
|
import time
|
||||||
|
from datetime import datetime, timedelta
|
||||||
|
|
||||||
|
import redis
|
||||||
|
from playwright.async_api import async_playwright
|
||||||
|
from telegram import ChatMember, InlineKeyboardButton, InlineKeyboardMarkup, Update
|
||||||
|
from telegram.constants import ChatType
|
||||||
|
from telegram.ext import Application, CallbackQueryHandler, CommandHandler, ContextTypes
|
||||||
|
|
||||||
|
# Logger
|
||||||
|
logging.basicConfig(level=logging.INFO, format='%(asctime)s - %(levelname)s - %(message)s')
|
||||||
|
logger = logging.getLogger(__name__)
|
||||||
|
|
||||||
|
# Suppress HTTP request logs
|
||||||
|
logging.getLogger('urllib3').setLevel(logging.WARNING)
|
||||||
|
logging.getLogger('httpx').setLevel(logging.WARNING)
|
||||||
|
logging.getLogger('telegram.ext._application').setLevel(logging.WARNING)
|
||||||
|
|
||||||
|
|
||||||
|
# Load environment variables
|
||||||
|
def _env(key, default=None):
|
||||||
|
v = os.getenv(key, default)
|
||||||
|
if isinstance(v, str) and len(v) >= 2 and ((v[0] == '"' and v[-1] == '"') or (v[0] == "'" and v[-1] == "'")):
|
||||||
|
return v[1:-1]
|
||||||
|
return v
|
||||||
|
|
||||||
|
|
||||||
|
EDU_BASE = _env('EDU_URL_BASE', 'https://edu.edu.vn.ua')
|
||||||
|
EDU_WEBINAR_PATH = _env('EDU_URL_WEBINAR', '/webinar/useractive')
|
||||||
|
WEBINAR_URL = f'{EDU_BASE.rstrip("/")}/{EDU_WEBINAR_PATH.lstrip("/")}'
|
||||||
|
DIARY_URL = f'{EDU_BASE.rstrip("/")}/user/diary'
|
||||||
|
|
||||||
|
WEBINAR_CHECK_INTERVAL = int(_env('WEBINAR_CHECK_INTERVAL', 60))
|
||||||
|
REDIS_HOST = _env('REDIS_HOST', 'redis')
|
||||||
|
REDIS_PORT = int(_env('REDIS_PORT', 6379))
|
||||||
|
PLAYWRIGHT_WS = _env('PLAYWRIGHT_WS', 'ws://playwright-service:3000/ws')
|
||||||
|
USER_AGENT = _env(
|
||||||
|
'USER_AGENT',
|
||||||
|
'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36',
|
||||||
|
)
|
||||||
|
WEBINAR_TELEGRAM_TOKEN = _env('WEBINAR_TELEGRAM_TOKEN')
|
||||||
|
ADMIN_ID = int(_env('WEBINAR_ADMIN_ID', '0'))
|
||||||
|
|
||||||
|
# Redis Keys
|
||||||
|
KEY_WHITELIST = 'bot:whitelist'
|
||||||
|
KEY_WHITELIST_ENABLED = 'bot:whitelist_enabled'
|
||||||
|
KEY_SUBSCRIBERS = 'bot:subscribers'
|
||||||
|
KEY_PHPSESSID = 'EDU_PHPSESSID'
|
||||||
|
KEY_WEBINAR_HISTORY = 'bot:webinar_history' # Stores last 3 webinars
|
||||||
|
|
||||||
|
# Initialize Redis
|
||||||
|
try:
|
||||||
|
redis_client = redis.Redis(host=REDIS_HOST, port=REDIS_PORT, decode_responses=True)
|
||||||
|
redis_client.ping()
|
||||||
|
logger.info(f'Connected to Redis at {REDIS_HOST}:{REDIS_PORT}')
|
||||||
|
except Exception as e:
|
||||||
|
logger.error(f'Failed to connect to Redis: {e}')
|
||||||
|
exit(1)
|
||||||
|
|
||||||
|
# --- Translations ---
|
||||||
|
|
||||||
|
TRANSLATIONS = {
|
||||||
|
'ru': {
|
||||||
|
'welcome': '👋 Привет, {name}!\n\nЯ бот-уведомитель о вебинарах. Я буду сообщать вам, когда появится новый вебинар.\nВы подписаны на уведомления.',
|
||||||
|
'welcome_admin': '\n\n👑 <b>Режим администратора активен</b>',
|
||||||
|
'access_denied': '⛔ Доступ запрещен. Вас нет в белом списке.',
|
||||||
|
'help_title': '🤖 <b>Помощь по боту</b>\n\n',
|
||||||
|
'help_commands': '/start - Подписаться на уведомления\n/stop - Отписаться от уведомлений\n/help - Показать это сообщение\n/language - Сменить язык',
|
||||||
|
'help_admin': '\n<b>Команды администратора:</b>\n/adduser [user_id] - Добавить пользователя в белый список\n/removeuser [user_id] - Удалить пользователя из белого списка\nИли используйте панель ниже для управления настройками.',
|
||||||
|
'admin_only': '⛔ Только для администратора!',
|
||||||
|
'user_added': '✅ Пользователь {user_id} добавлен в белый список',
|
||||||
|
'user_removed': '✅ Пользователь {user_id} удален из белого списка',
|
||||||
|
'user_not_in_whitelist': '⚠️ Пользователь {user_id} не был в белом списке',
|
||||||
|
'cannot_remove_admin': '❌ Невозможно удалить администратора из белого списка',
|
||||||
|
'invalid_user_id': '❌ Неверный ID пользователя. Должно быть число.',
|
||||||
|
'usage_adduser': 'Использование: /adduser [user_id]',
|
||||||
|
'usage_removeuser': 'Использование: /removeuser [user_id]',
|
||||||
|
'whitelist_enabled': '✅ Белый список включен',
|
||||||
|
'whitelist_disabled': '✅ Белый список отключен',
|
||||||
|
'whitelist_title': '📋 <b>Белый список:</b>\n',
|
||||||
|
'subscribers_title': '👥 <b>Подписчики:</b>\n',
|
||||||
|
'empty': 'Пусто',
|
||||||
|
'force_check_running': '🔄 Запускаю проверку...',
|
||||||
|
'check_failed': '❌ Проверка не удалась. Смотрите логи.',
|
||||||
|
'check_completed_none': '✅ Проверка завершена. Вебинаров не найдено.',
|
||||||
|
'check_completed': '✅ Проверка завершена. Найдено {count} вебинар(ов)!',
|
||||||
|
'toggle_whitelist_disable': '🔒 Отключить белый список',
|
||||||
|
'toggle_whitelist_enable': '🔓 Включить белый список',
|
||||||
|
'view_whitelist': '📋 Посмотреть белый список',
|
||||||
|
'view_subscribers': '👥 Посмотреть подписчиков',
|
||||||
|
'force_check': '🔄 Принудительная проверка',
|
||||||
|
'webinar_found': '🎓 <b>Новый вебинар!</b>\n\n',
|
||||||
|
'webinar_item': '📌 <b>{name}</b>\n🔗 https://edu.edu.vn.ua{url}',
|
||||||
|
'select_language': '🌐 <b>Выберите язык / Оберіть мову / Select language:</b>',
|
||||||
|
'language_changed': '✅ Язык изменен на русский',
|
||||||
|
'flag_ru': '🇷🇺 Русский',
|
||||||
|
'flag_uk': '🇺🇦 Українська',
|
||||||
|
'flag_en': '🇬🇧 English',
|
||||||
|
'history_cleared': '✅ История вебинаров очищена',
|
||||||
|
'history_clear_failed': '❌ Ошибка при очистке истории',
|
||||||
|
},
|
||||||
|
'uk': {
|
||||||
|
'welcome': "👋 Привіт, {name}!\n\nЯ бот-сповіщувач про вебінари. Я повідомлятиму вас, коли з'явиться новий вебінар.\nВи підписані на сповіщення.",
|
||||||
|
'welcome_admin': '\n\n👑 <b>Режим адміністратора активний</b>',
|
||||||
|
'access_denied': '⛔ Доступ заборонено. Вас немає в білому списку.',
|
||||||
|
'help_title': '🤖 <b>Довідка по боту</b>\n\n',
|
||||||
|
'help_commands': '/start - Підписатися на сповіщення\n/stop - Відписатися від сповіщень\n/help - Показати це повідомлення\n/language - Змінити мову',
|
||||||
|
'help_admin': '\n<b>Команди адміністратора:</b>\n/adduser [user_id] - Додати користувача до білого списку\n/removeuser [user_id] - Видалити користувача з білого списку\nАбо використовуйте панель нижче для керування налаштуваннями.',
|
||||||
|
'admin_only': '⛔ Тільки для адміністратора!',
|
||||||
|
'user_added': '✅ Користувач {user_id} доданий до білого списку',
|
||||||
|
'user_removed': '✅ Користувач {user_id} видалений з білого списку',
|
||||||
|
'user_not_in_whitelist': '⚠️ Користувач {user_id} не був у білому списку',
|
||||||
|
'cannot_remove_admin': '❌ Неможливо видалити адміністратора з білого списку',
|
||||||
|
'invalid_user_id': '❌ Невірний ID користувача. Має бути число.',
|
||||||
|
'usage_adduser': 'Використання: /adduser [user_id]',
|
||||||
|
'usage_removeuser': 'Використання: /removeuser [user_id]',
|
||||||
|
'whitelist_enabled': '✅ Білий список увімкнено',
|
||||||
|
'whitelist_disabled': '✅ Білий список вимкнено',
|
||||||
|
'whitelist_title': '📋 <b>Білий список:</b>\n',
|
||||||
|
'subscribers_title': '👥 <b>Підписники:</b>\n',
|
||||||
|
'empty': 'Порожньо',
|
||||||
|
'force_check_running': '🔄 Запускаю перевірку...',
|
||||||
|
'check_failed': '❌ Перевірка не вдалася. Дивіться логи.',
|
||||||
|
'check_completed_none': '✅ Перевірка завершена. Вебінарів не знайдено.',
|
||||||
|
'check_completed': '✅ Перевірка завершена. Знайдено {count} вебінар(ів)!',
|
||||||
|
'toggle_whitelist_disable': '🔒 Вимкнути білий список',
|
||||||
|
'toggle_whitelist_enable': '🔓 Увімкнути білий список',
|
||||||
|
'view_whitelist': '📋 Переглянути білий список',
|
||||||
|
'view_subscribers': '👥 Переглянути підписників',
|
||||||
|
'force_check': '🔄 Примусова перевірка',
|
||||||
|
'webinar_found': '🎓 <b>Новий вебінар!</b>\n\n',
|
||||||
|
'webinar_item': '📌 <b>{name}</b>\n🔗 https://edu.edu.vn.ua{url}',
|
||||||
|
'select_language': '🌐 <b>Виберіть мову / Выберите язык / Select language:</b>',
|
||||||
|
'language_changed': '✅ Мову змінено на українську',
|
||||||
|
'flag_ru': '🇷🇺 Русский',
|
||||||
|
'flag_uk': '🇺🇦 Українська',
|
||||||
|
'flag_en': '🇬🇧 English',
|
||||||
|
'history_cleared': '✅ Історія вебінарів очищена',
|
||||||
|
'history_clear_failed': '❌ Помилка при очищенні історії',
|
||||||
|
},
|
||||||
|
'en': {
|
||||||
|
'welcome': '👋 Hello, {name}!\n\nI am the Webinar Checker Bot. I will notify you when a new webinar appears.\nYou have been subscribed to notifications.',
|
||||||
|
'welcome_admin': '\n\n👑 <b>Admin Mode Active</b>',
|
||||||
|
'access_denied': '⛔ Access denied. You are not on the whitelist.',
|
||||||
|
'help_title': '🤖 <b>Bot Help</b>\n\n',
|
||||||
|
'help_commands': '/start - Subscribe to notifications\n/stop - Unsubscribe from notifications\n/help - Show this message\n/language - Change language',
|
||||||
|
'help_admin': '\n<b>Admin Commands:</b>\n/adduser [user_id] - Add user to whitelist\n/removeuser [user_id] - Remove user from whitelist\nOr use the panel below to manage settings.',
|
||||||
|
'admin_only': '⛔ Admin only!',
|
||||||
|
'user_added': '✅ User {user_id} added to whitelist',
|
||||||
|
'user_removed': '✅ User {user_id} removed from whitelist',
|
||||||
|
'user_not_in_whitelist': '⚠️ User {user_id} was not in whitelist',
|
||||||
|
'cannot_remove_admin': '❌ Cannot remove admin from whitelist',
|
||||||
|
'invalid_user_id': '❌ Invalid user ID. Must be a number.',
|
||||||
|
'usage_adduser': 'Usage: /adduser [user_id]',
|
||||||
|
'usage_removeuser': 'Usage: /removeuser [user_id]',
|
||||||
|
'whitelist_enabled': '✅ Whitelist Enabled',
|
||||||
|
'whitelist_disabled': '✅ Whitelist Disabled',
|
||||||
|
'whitelist_title': '📋 <b>Whitelist:</b>\n',
|
||||||
|
'subscribers_title': '👥 <b>Subscribers:</b>\n',
|
||||||
|
'empty': 'Empty',
|
||||||
|
'force_check_running': '🔄 Running immediate check...',
|
||||||
|
'check_failed': '❌ Check failed. See logs for details.',
|
||||||
|
'check_completed_none': '✅ Check completed. No webinars found.',
|
||||||
|
'check_completed': '✅ Check completed. Found {count} webinar(s)!',
|
||||||
|
'toggle_whitelist_disable': '🔒 Disable Whitelist',
|
||||||
|
'toggle_whitelist_enable': '🔓 Enable Whitelist',
|
||||||
|
'view_whitelist': '📋 View Whitelist',
|
||||||
|
'view_subscribers': '👥 View Subscribers',
|
||||||
|
'force_check': '🔄 Force Check',
|
||||||
|
'webinar_found': '🎓 <b>New webinar found!</b>\n\n',
|
||||||
|
'webinar_item': '📌 <b>{name}</b>\n🔗 https://edu.edu.vn.ua{url}',
|
||||||
|
'select_language': '🌐 <b>Select language / Виберіть мову / Выберите язык:</b>',
|
||||||
|
'language_changed': '✅ Language changed to English',
|
||||||
|
'flag_ru': '🇷🇺 Русский',
|
||||||
|
'flag_uk': '🇺🇦 Українська',
|
||||||
|
'flag_en': '🇬🇧 English',
|
||||||
|
'history_cleared': '✅ Webinar history cleared',
|
||||||
|
'history_clear_failed': '❌ Error clearing history',
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
# --- Language Helper Functions ---
|
||||||
|
|
||||||
|
|
||||||
|
def get_user_language(user_id: int) -> str:
|
||||||
|
"""Get user's preferred language from Redis. Default: Ukrainian."""
|
||||||
|
lang = redis_client.get(f'user:{user_id}:language')
|
||||||
|
return lang if lang in ['ru', 'uk', 'en'] else 'uk'
|
||||||
|
|
||||||
|
|
||||||
|
def set_user_language(user_id: int, lang: str):
|
||||||
|
"""Save user's language preference to Redis."""
|
||||||
|
if lang in ['ru', 'uk', 'en']:
|
||||||
|
redis_client.set(f'user:{user_id}:language', lang)
|
||||||
|
logger.info(f'User {user_id} language set to {lang}')
|
||||||
|
|
||||||
|
|
||||||
|
def t(user_id: int, key: str, **kwargs) -> str:
|
||||||
|
"""Translate message for user with optional formatting."""
|
||||||
|
lang = get_user_language(user_id)
|
||||||
|
message = TRANSLATIONS.get(lang, TRANSLATIONS['uk']).get(key, key)
|
||||||
|
if kwargs:
|
||||||
|
return message.format(**kwargs)
|
||||||
|
return message
|
||||||
|
|
||||||
|
|
||||||
|
def get_language_keyboard():
|
||||||
|
"""Generate language selection keyboard."""
|
||||||
|
keyboard = [
|
||||||
|
[
|
||||||
|
InlineKeyboardButton('🇷🇺 Русский', callback_data='lang_ru'),
|
||||||
|
InlineKeyboardButton('🇺🇦 Українська', callback_data='lang_uk'),
|
||||||
|
],
|
||||||
|
[
|
||||||
|
InlineKeyboardButton('🇬🇧 English', callback_data='lang_en'),
|
||||||
|
],
|
||||||
|
]
|
||||||
|
return InlineKeyboardMarkup(keyboard)
|
||||||
|
|
||||||
|
|
||||||
|
# --- Helper Functions ---
|
||||||
|
|
||||||
|
|
||||||
|
def is_whitelisted(user_id: int) -> bool:
|
||||||
|
"""Check if user is allowed to use the bot."""
|
||||||
|
if user_id == ADMIN_ID:
|
||||||
|
return True
|
||||||
|
|
||||||
|
enabled = redis_client.get(KEY_WHITELIST_ENABLED)
|
||||||
|
if enabled == '0': # Whitelist disabled
|
||||||
|
return True
|
||||||
|
|
||||||
|
return redis_client.sismember(KEY_WHITELIST, str(user_id))
|
||||||
|
|
||||||
|
|
||||||
|
async def is_group_admin(update: Update, context: ContextTypes.DEFAULT_TYPE) -> bool:
|
||||||
|
"""Check if the user is an administrator in the group."""
|
||||||
|
user = update.effective_user
|
||||||
|
chat = update.effective_chat
|
||||||
|
|
||||||
|
if chat.type in [ChatType.PRIVATE, 'private']:
|
||||||
|
return True
|
||||||
|
|
||||||
|
try:
|
||||||
|
member = await context.bot.get_chat_member(chat.id, user.id)
|
||||||
|
return member.status in [ChatMember.OWNER, ChatMember.ADMINISTRATOR]
|
||||||
|
except Exception as e:
|
||||||
|
logger.error(f'Failed to check admin status: {e}')
|
||||||
|
return False
|
||||||
|
|
||||||
|
|
||||||
|
def get_admin_keyboard(user_id: int):
|
||||||
|
"""Generate admin panel keyboard."""
|
||||||
|
whitelist_enabled = redis_client.get(KEY_WHITELIST_ENABLED) != '0'
|
||||||
|
toggle_text = t(user_id, 'toggle_whitelist_disable') if whitelist_enabled else t(user_id, 'toggle_whitelist_enable')
|
||||||
|
|
||||||
|
keyboard = [
|
||||||
|
[InlineKeyboardButton(toggle_text, callback_data='toggle_whitelist')],
|
||||||
|
[InlineKeyboardButton(t(user_id, 'view_whitelist'), callback_data='view_whitelist')],
|
||||||
|
[InlineKeyboardButton(t(user_id, 'view_subscribers'), callback_data='view_subscribers')],
|
||||||
|
[InlineKeyboardButton(t(user_id, 'force_check'), callback_data='force_check')],
|
||||||
|
]
|
||||||
|
return InlineKeyboardMarkup(keyboard)
|
||||||
|
|
||||||
|
|
||||||
|
# --- Diary Functions ---
|
||||||
|
|
||||||
|
DIARY_MONTH_NAMES = [
|
||||||
|
'',
|
||||||
|
'Січня',
|
||||||
|
'Лютого',
|
||||||
|
'Березня',
|
||||||
|
'Квітня',
|
||||||
|
'Травня',
|
||||||
|
'Червня',
|
||||||
|
'Липня',
|
||||||
|
'Серпня',
|
||||||
|
'Вересня',
|
||||||
|
'Жовтня',
|
||||||
|
'Листопада',
|
||||||
|
'Грудня',
|
||||||
|
]
|
||||||
|
|
||||||
|
DIARY_WEEKDAYS_SHORT = ['Пн', 'Вт', 'Ср', 'Чт', 'Пт', 'Сб', 'Нд']
|
||||||
|
|
||||||
|
|
||||||
|
def get_diary_keyboard():
|
||||||
|
today = datetime.now()
|
||||||
|
keyboard = [
|
||||||
|
[
|
||||||
|
InlineKeyboardButton(f'📌 Сьогодні ({today.day}.{today.month:02d})', callback_data='diary_today'),
|
||||||
|
InlineKeyboardButton('📌 Завтра', callback_data='diary_tomorrow'),
|
||||||
|
],
|
||||||
|
[
|
||||||
|
InlineKeyboardButton('📅 Цей тиждень', callback_data='diary_week'),
|
||||||
|
InlineKeyboardButton('📅 Весь місяць', callback_data='diary_month'),
|
||||||
|
],
|
||||||
|
]
|
||||||
|
return InlineKeyboardMarkup(keyboard)
|
||||||
|
|
||||||
|
|
||||||
|
def _parse_calendar_html(table_html: str) -> tuple:
|
||||||
|
"""Parse calendar HTML table into (month_text, {day_num: {weekday, events}})."""
|
||||||
|
days = {}
|
||||||
|
weekdays = []
|
||||||
|
rows = re.findall(r'<tr[^>]*>(.*?)</tr>', table_html, re.DOTALL)
|
||||||
|
|
||||||
|
month_text = ''
|
||||||
|
for r_idx, row in enumerate(rows):
|
||||||
|
cells = re.findall(r'<t[dh][^>]*>(.*?)</t[dh]>', row, re.DOTALL)
|
||||||
|
|
||||||
|
if r_idx == 0:
|
||||||
|
# Month navigation row: extract "Травень 2026" from nav text
|
||||||
|
raw = re.sub(r'<[^>]+>', ' ', row).strip()
|
||||||
|
raw = re.sub(r'\s+', ' ', raw)
|
||||||
|
m = re.search(r'([А-Яа-яіїєґ\']+\s*:?\s*\d{4})', raw)
|
||||||
|
month_text = m.group(1).replace(' : ', ' ').strip() if m else raw
|
||||||
|
elif r_idx == 1:
|
||||||
|
# Day names row
|
||||||
|
for cell in cells:
|
||||||
|
name = re.sub(r'<[^>]+>', '', cell).strip()
|
||||||
|
if name:
|
||||||
|
weekdays.append(name)
|
||||||
|
else:
|
||||||
|
# Data rows: each cell = a day
|
||||||
|
for col_idx, cell in enumerate(cells):
|
||||||
|
# Extract day number — first number in the cell text
|
||||||
|
text = re.sub(r'<[^>]+>', ' ', cell).strip()
|
||||||
|
text = re.sub(r'\s+', ' ', text)
|
||||||
|
dm = re.match(r'(\d+)', text)
|
||||||
|
if not dm:
|
||||||
|
continue
|
||||||
|
day_num = dm.group(1)
|
||||||
|
|
||||||
|
# Extract events: title attribute (full name) of ALL <a> tags inside the cell
|
||||||
|
events = []
|
||||||
|
for a_match in re.finditer(r'<a[^>]*>(.*?)</a>', cell, re.DOTALL):
|
||||||
|
a_tag = a_match.group(0)
|
||||||
|
# Prefer the title attribute (contains full name, not truncated)
|
||||||
|
title_m = re.search(r'title\s*=\s*"([^"]*)"', a_tag)
|
||||||
|
et = title_m.group(1).strip() if title_m else re.sub(r'<[^>]+>', '', a_match.group(1)).strip()
|
||||||
|
if et:
|
||||||
|
events.append(et)
|
||||||
|
|
||||||
|
weekday = weekdays[col_idx] if col_idx < len(weekdays) else ''
|
||||||
|
days[day_num] = {'weekday': weekday, 'events': events}
|
||||||
|
|
||||||
|
return month_text, days
|
||||||
|
|
||||||
|
|
||||||
|
async def fetch_diary_data(phpsessid: str) -> dict | None:
|
||||||
|
logger.info('Fetching diary data via Playwright...')
|
||||||
|
try:
|
||||||
|
async with async_playwright() as p:
|
||||||
|
browser = await p.chromium.connect(PLAYWRIGHT_WS)
|
||||||
|
try:
|
||||||
|
context_browser = await browser.new_context(user_agent=USER_AGENT)
|
||||||
|
await context_browser.add_cookies(
|
||||||
|
[{'name': 'PHPSESSID', 'value': phpsessid, 'domain': 'edu.edu.vn.ua', 'path': '/'}]
|
||||||
|
)
|
||||||
|
page = await context_browser.new_page()
|
||||||
|
|
||||||
|
try:
|
||||||
|
await page.goto(DIARY_URL, wait_until='domcontentloaded')
|
||||||
|
await page.wait_for_selector('table.calendar', timeout=10000)
|
||||||
|
await page.wait_for_timeout(1500)
|
||||||
|
|
||||||
|
table_html = await page.evaluate("""
|
||||||
|
() => {
|
||||||
|
const t = document.querySelector('table.calendar');
|
||||||
|
return t ? t.outerHTML : null;
|
||||||
|
}
|
||||||
|
""")
|
||||||
|
if not table_html:
|
||||||
|
logger.error('table.calendar not found in DOM')
|
||||||
|
return None
|
||||||
|
|
||||||
|
# Debug: save HTML for troubleshooting
|
||||||
|
with contextlib.suppress(Exception), open('/tmp/diary_debug.html', 'w', encoding='utf-8') as f: # noqa: S108
|
||||||
|
f.write(table_html)
|
||||||
|
|
||||||
|
month_text, days = _parse_calendar_html(table_html)
|
||||||
|
logger.info(
|
||||||
|
f'Diary parsed: month={month_text!r}, days_with_events={sum(1 for d in days.values() if d["events"])}/{len(days)}'
|
||||||
|
)
|
||||||
|
|
||||||
|
return {'monthFullText': month_text, 'days': days}
|
||||||
|
|
||||||
|
except Exception as e:
|
||||||
|
logger.error(f'Error parsing diary: {e}')
|
||||||
|
return None
|
||||||
|
finally:
|
||||||
|
await page.close()
|
||||||
|
await context_browser.close()
|
||||||
|
finally:
|
||||||
|
await browser.close()
|
||||||
|
except Exception as e:
|
||||||
|
logger.error(f'Playwright error in diary fetch: {e}')
|
||||||
|
return None
|
||||||
|
|
||||||
|
|
||||||
|
def _parse_diary_month(text: str) -> str:
|
||||||
|
match = re.search(r'([А-Яа-яіїєґ\']+\s*:\s*\d{4})', text)
|
||||||
|
if match:
|
||||||
|
return match.group(1).replace(' : ', ' ').strip()
|
||||||
|
return text.strip()
|
||||||
|
|
||||||
|
|
||||||
|
def format_diary_day(data: dict, day_num: int) -> str:
|
||||||
|
days = data.get('days', {})
|
||||||
|
month_str = _parse_diary_month(data.get('monthFullText', ''))
|
||||||
|
day_data = days.get(str(day_num))
|
||||||
|
lines = [f'📅 <b>{day_num} {month_str}</b>', '─' * 18]
|
||||||
|
if not day_data or not day_data.get('events'):
|
||||||
|
lines.append('Немає подій')
|
||||||
|
else:
|
||||||
|
for e in day_data['events']:
|
||||||
|
lines.append(f'📌 {e}')
|
||||||
|
lines.append(f'\n🔗 {DIARY_URL}')
|
||||||
|
return '\n'.join(lines)
|
||||||
|
|
||||||
|
|
||||||
|
def format_diary_week(data: dict, today: datetime) -> str:
|
||||||
|
days = data.get('days', {})
|
||||||
|
_parse_diary_month(data.get('monthFullText', ''))
|
||||||
|
monday = today - timedelta(days=today.weekday())
|
||||||
|
sunday = monday + timedelta(days=6)
|
||||||
|
lines = [f'📅 <b>Тиждень {monday.day}.{monday.month} – {sunday.day}.{sunday.month}</b>\n']
|
||||||
|
for i in range(7):
|
||||||
|
d = monday + timedelta(days=i)
|
||||||
|
day_data = days.get(str(d.day))
|
||||||
|
lines.append(f'─ <b>{DIARY_WEEKDAYS_SHORT[i]} {d.day}.{d.month}</b> ─')
|
||||||
|
if not day_data or not day_data.get('events'):
|
||||||
|
lines.append('Немає подій\n')
|
||||||
|
else:
|
||||||
|
for e in day_data['events']:
|
||||||
|
lines.append(f'📌 {e}')
|
||||||
|
lines.append('')
|
||||||
|
lines.append(f'🔗 {DIARY_URL}')
|
||||||
|
return '\n'.join(lines)
|
||||||
|
|
||||||
|
|
||||||
|
def format_diary_month(data: dict) -> str:
|
||||||
|
days = data.get('days', {})
|
||||||
|
month_str = _parse_diary_month(data.get('monthFullText', ''))
|
||||||
|
lines = [f'📅 <b>{month_str}</b>\n']
|
||||||
|
for day_num in sorted(days.keys(), key=int):
|
||||||
|
day_data = days[day_num]
|
||||||
|
events = day_data.get('events', [])
|
||||||
|
weekday = day_data.get('weekday', '')
|
||||||
|
lines.append(f'─ <b>{weekday} {day_num}</b> ─')
|
||||||
|
if not events:
|
||||||
|
lines.append('Немає подій\n')
|
||||||
|
else:
|
||||||
|
for e in events:
|
||||||
|
lines.append(f'📌 {e}')
|
||||||
|
lines.append('')
|
||||||
|
lines.append(f'🔗 {DIARY_URL}')
|
||||||
|
return '\n'.join(lines)
|
||||||
|
|
||||||
|
|
||||||
|
async def _get_diary_data(context: ContextTypes.DEFAULT_TYPE) -> dict | None:
|
||||||
|
cached = context.user_data.get('diary_cache')
|
||||||
|
now_ts = time.time()
|
||||||
|
if cached and (now_ts - cached.get('timestamp', 0)) < 300:
|
||||||
|
return cached['data']
|
||||||
|
phpsessid = redis_client.get(KEY_PHPSESSID)
|
||||||
|
if not phpsessid:
|
||||||
|
return None
|
||||||
|
data = await fetch_diary_data(phpsessid)
|
||||||
|
if data:
|
||||||
|
context.user_data['diary_cache'] = {'data': data, 'timestamp': now_ts}
|
||||||
|
return data
|
||||||
|
|
||||||
|
|
||||||
|
# --- Command Handlers ---
|
||||||
|
|
||||||
|
|
||||||
|
async def start(update: Update, _context: ContextTypes.DEFAULT_TYPE):
|
||||||
|
"""Handle /start command."""
|
||||||
|
user = update.effective_user
|
||||||
|
chat = update.effective_chat
|
||||||
|
logger.info(f'User {user.id} ({user.username}) started the bot in chat {chat.id} ({chat.type}).')
|
||||||
|
|
||||||
|
# Check whitelist - MUST be the user executing the command
|
||||||
|
if not is_whitelisted(user.id):
|
||||||
|
await update.message.reply_text(t(user.id, 'access_denied'))
|
||||||
|
return
|
||||||
|
|
||||||
|
# Add to subscribers (Chat ID!)
|
||||||
|
redis_client.sadd(KEY_SUBSCRIBERS, chat.id)
|
||||||
|
|
||||||
|
msg = t(chat.id, 'welcome', name=user.first_name)
|
||||||
|
|
||||||
|
if user.id == ADMIN_ID and chat.type == 'private':
|
||||||
|
msg += t(chat.id, 'welcome_admin')
|
||||||
|
await update.message.reply_text(msg, parse_mode='HTML', reply_markup=get_admin_keyboard(user.id))
|
||||||
|
else:
|
||||||
|
await update.message.reply_text(msg, parse_mode='HTML')
|
||||||
|
|
||||||
|
|
||||||
|
async def help_command(update: Update, _context: ContextTypes.DEFAULT_TYPE):
|
||||||
|
"""Handle /help command."""
|
||||||
|
user_id = update.effective_user.id
|
||||||
|
chat_id = update.effective_chat.id
|
||||||
|
msg = t(chat_id, 'help_title') + t(chat_id, 'help_commands')
|
||||||
|
|
||||||
|
if user_id == ADMIN_ID and update.effective_chat.type == 'private':
|
||||||
|
msg += t(chat_id, 'help_admin')
|
||||||
|
await update.message.reply_text(msg, parse_mode='HTML', reply_markup=get_admin_keyboard(user_id))
|
||||||
|
else:
|
||||||
|
await update.message.reply_text(msg, parse_mode='HTML')
|
||||||
|
|
||||||
|
|
||||||
|
async def stop_command(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||||
|
"""Handle /stop command (unsubscribe)."""
|
||||||
|
user = update.effective_user
|
||||||
|
chat = update.effective_chat
|
||||||
|
|
||||||
|
# Permission check: Whitelisted user OR Group Admin
|
||||||
|
if not (is_whitelisted(user.id) or await is_group_admin(update, context)):
|
||||||
|
await update.message.reply_text(t(chat.id, 'access_denied')) # Or specific "admin only" message
|
||||||
|
return
|
||||||
|
|
||||||
|
redis_client.srem(KEY_SUBSCRIBERS, chat.id)
|
||||||
|
await update.message.reply_text(
|
||||||
|
t(chat.id, 'whitelist_disabled')
|
||||||
|
.replace(' whitelist', ' notifications')
|
||||||
|
.replace('Білий список', 'Сповіщення')
|
||||||
|
.replace('Белый список', 'Уведомления')
|
||||||
|
if chat.id
|
||||||
|
else 'Unsubscribed'
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
|
async def language_command(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||||
|
"""Handle /language command."""
|
||||||
|
user = update.effective_user
|
||||||
|
chat = update.effective_chat
|
||||||
|
|
||||||
|
# Permission check for groups
|
||||||
|
if not (is_whitelisted(user.id) or await is_group_admin(update, context)):
|
||||||
|
return
|
||||||
|
|
||||||
|
await update.message.reply_text(
|
||||||
|
t(chat.id, 'select_language'), parse_mode='HTML', reply_markup=get_language_keyboard()
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
|
async def add_user(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||||
|
"""Add user to whitelist (admin only)."""
|
||||||
|
admin_id = update.effective_user.id
|
||||||
|
if admin_id != ADMIN_ID:
|
||||||
|
await update.message.reply_text(t(admin_id, 'admin_only'))
|
||||||
|
return
|
||||||
|
|
||||||
|
if not context.args:
|
||||||
|
await update.message.reply_text(t(admin_id, 'usage_adduser'))
|
||||||
|
return
|
||||||
|
|
||||||
|
try:
|
||||||
|
user_id = int(context.args[0])
|
||||||
|
redis_client.sadd(KEY_WHITELIST, str(user_id))
|
||||||
|
await update.message.reply_text(t(admin_id, 'user_added', user_id=user_id))
|
||||||
|
logger.info(f'Admin added user {user_id} to whitelist')
|
||||||
|
except ValueError:
|
||||||
|
await update.message.reply_text(t(admin_id, 'invalid_user_id'))
|
||||||
|
|
||||||
|
|
||||||
|
async def remove_user(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||||
|
"""Remove user from whitelist (admin only)."""
|
||||||
|
admin_id = update.effective_user.id
|
||||||
|
if admin_id != ADMIN_ID:
|
||||||
|
await update.message.reply_text(t(admin_id, 'admin_only'))
|
||||||
|
return
|
||||||
|
|
||||||
|
if not context.args:
|
||||||
|
await update.message.reply_text(t(admin_id, 'usage_removeuser'))
|
||||||
|
return
|
||||||
|
|
||||||
|
try:
|
||||||
|
user_id = int(context.args[0])
|
||||||
|
if str(user_id) == str(ADMIN_ID):
|
||||||
|
await update.message.reply_text(t(admin_id, 'cannot_remove_admin'))
|
||||||
|
return
|
||||||
|
|
||||||
|
removed = redis_client.srem(KEY_WHITELIST, str(user_id))
|
||||||
|
if removed:
|
||||||
|
await update.message.reply_text(t(admin_id, 'user_removed', user_id=user_id))
|
||||||
|
logger.info(f'Admin removed user {user_id} from whitelist')
|
||||||
|
else:
|
||||||
|
await update.message.reply_text(t(admin_id, 'user_not_in_whitelist', user_id=user_id))
|
||||||
|
except ValueError:
|
||||||
|
await update.message.reply_text(t(admin_id, 'invalid_user_id'))
|
||||||
|
|
||||||
|
|
||||||
|
async def clear_history(update: Update, _context: ContextTypes.DEFAULT_TYPE):
|
||||||
|
"""Clear webinar history (admin only)."""
|
||||||
|
admin_id = update.effective_user.id
|
||||||
|
if admin_id != ADMIN_ID:
|
||||||
|
await update.message.reply_text(t(admin_id, 'admin_only'))
|
||||||
|
return
|
||||||
|
|
||||||
|
try:
|
||||||
|
redis_client.delete(KEY_WEBINAR_HISTORY)
|
||||||
|
await update.message.reply_text(t(admin_id, 'history_cleared'))
|
||||||
|
logger.info('Admin cleared webinar history')
|
||||||
|
except Exception as e:
|
||||||
|
logger.error(f'Failed to clear history: {e}')
|
||||||
|
await update.message.reply_text(t(admin_id, 'history_clear_failed'))
|
||||||
|
|
||||||
|
|
||||||
|
async def diary_command(update: Update, _context: ContextTypes.DEFAULT_TYPE):
|
||||||
|
user = update.effective_user
|
||||||
|
if not is_whitelisted(user.id):
|
||||||
|
await update.message.reply_text(t(user.id, 'access_denied'))
|
||||||
|
return
|
||||||
|
await update.message.reply_text(
|
||||||
|
'📅 <b>Щоденник</b> — виберіть період:', parse_mode='HTML', reply_markup=get_diary_keyboard()
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
|
async def diary_callback(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||||
|
query = update.callback_query
|
||||||
|
user_id = query.from_user.id
|
||||||
|
await query.answer()
|
||||||
|
|
||||||
|
if user_id != ADMIN_ID and not is_whitelisted(user_id):
|
||||||
|
await query.edit_message_text('⛔ Доступ заборонено.')
|
||||||
|
return
|
||||||
|
|
||||||
|
data = query.data
|
||||||
|
if data == 'diary_refresh':
|
||||||
|
context.user_data.pop('diary_cache', None)
|
||||||
|
await query.edit_message_text('🔄 Завантажую щоденник...')
|
||||||
|
diary_data = await _get_diary_data(context)
|
||||||
|
if not diary_data:
|
||||||
|
await query.edit_message_text('❌ Не вдалося завантажити щоденник. Немає сесії або помилка.')
|
||||||
|
return
|
||||||
|
await query.edit_message_text(
|
||||||
|
'📅 <b>Щоденник</b> — виберіть період:', parse_mode='HTML', reply_markup=get_diary_keyboard()
|
||||||
|
)
|
||||||
|
return
|
||||||
|
|
||||||
|
await query.edit_message_text('🔄 Завантажую щоденник...')
|
||||||
|
diary_data = await _get_diary_data(context)
|
||||||
|
if not diary_data:
|
||||||
|
await query.edit_message_text('❌ Не вдалося завантажити щоденник.')
|
||||||
|
return
|
||||||
|
|
||||||
|
today = datetime.now()
|
||||||
|
if data == 'diary_today':
|
||||||
|
text = format_diary_day(diary_data, today.day)
|
||||||
|
elif data == 'diary_tomorrow':
|
||||||
|
tomorrow = today + timedelta(days=1)
|
||||||
|
if tomorrow.day < today.day:
|
||||||
|
text = '❌ Дані за наступний місяць недоступні. Перейдіть на сайт.'
|
||||||
|
else:
|
||||||
|
text = format_diary_day(diary_data, tomorrow.day)
|
||||||
|
elif data == 'diary_week':
|
||||||
|
text = format_diary_week(diary_data, today)
|
||||||
|
elif data == 'diary_month':
|
||||||
|
text = format_diary_month(diary_data)
|
||||||
|
else:
|
||||||
|
return
|
||||||
|
|
||||||
|
if len(text) > 4096:
|
||||||
|
text = text[:4090] + '\n\n✂️ ...(обрізано)'
|
||||||
|
|
||||||
|
await query.edit_message_text(text, parse_mode='HTML', reply_markup=get_diary_keyboard())
|
||||||
|
|
||||||
|
|
||||||
|
# --- Admin Callbacks ---
|
||||||
|
|
||||||
|
|
||||||
|
async def admin_callback(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||||
|
"""Handle admin panel button clicks."""
|
||||||
|
query = update.callback_query
|
||||||
|
user_id = query.from_user.id
|
||||||
|
|
||||||
|
if user_id != ADMIN_ID:
|
||||||
|
await query.answer(t(user_id, 'admin_only'), show_alert=True)
|
||||||
|
return
|
||||||
|
|
||||||
|
await query.answer()
|
||||||
|
data = query.data
|
||||||
|
|
||||||
|
if data == 'toggle_whitelist':
|
||||||
|
current = redis_client.get(KEY_WHITELIST_ENABLED)
|
||||||
|
new_state = '0' if current != '0' else '1'
|
||||||
|
redis_client.set(KEY_WHITELIST_ENABLED, new_state)
|
||||||
|
state_text = t(user_id, 'whitelist_disabled') if new_state == '0' else t(user_id, 'whitelist_enabled')
|
||||||
|
await query.edit_message_reply_markup(reply_markup=get_admin_keyboard(user_id))
|
||||||
|
await query.message.reply_text(state_text)
|
||||||
|
|
||||||
|
elif data == 'view_whitelist':
|
||||||
|
members = redis_client.smembers(KEY_WHITELIST)
|
||||||
|
msg = t(user_id, 'whitelist_title') + ('\n'.join(members) if members else t(user_id, 'empty'))
|
||||||
|
await query.message.reply_text(msg, parse_mode='HTML')
|
||||||
|
|
||||||
|
elif data == 'view_subscribers':
|
||||||
|
subs = redis_client.smembers(KEY_SUBSCRIBERS)
|
||||||
|
msg = t(user_id, 'subscribers_title') + ('\n'.join(subs) if subs else t(user_id, 'empty'))
|
||||||
|
await query.message.reply_text(msg, parse_mode='HTML')
|
||||||
|
|
||||||
|
elif data == 'force_check':
|
||||||
|
await query.message.reply_text(t(user_id, 'force_check_running'))
|
||||||
|
result = await check_webinars_job(context)
|
||||||
|
|
||||||
|
if result is None:
|
||||||
|
await query.message.reply_text(t(user_id, 'check_failed'))
|
||||||
|
elif result == 0:
|
||||||
|
await query.message.reply_text(t(user_id, 'check_completed_none'))
|
||||||
|
else:
|
||||||
|
await query.message.reply_text(t(user_id, 'check_completed', count=result))
|
||||||
|
|
||||||
|
|
||||||
|
async def language_callback(update: Update, _context: ContextTypes.DEFAULT_TYPE):
|
||||||
|
"""Handle language selection button clicks."""
|
||||||
|
query = update.callback_query
|
||||||
|
user_id = query.from_user.id
|
||||||
|
data = query.data
|
||||||
|
|
||||||
|
if data.startswith('lang_'):
|
||||||
|
lang = data.split('_')[1]
|
||||||
|
set_user_language(user_id, lang)
|
||||||
|
await query.answer()
|
||||||
|
await query.edit_message_text(t(user_id, 'language_changed'), parse_mode='HTML')
|
||||||
|
|
||||||
|
|
||||||
|
# --- Webinar Checking Job ---
|
||||||
|
|
||||||
|
|
||||||
|
def get_webinar_key(url: str) -> str:
|
||||||
|
"""Generate unique key for a webinar based on URL."""
|
||||||
|
return url
|
||||||
|
|
||||||
|
|
||||||
|
def get_stored_webinars() -> list:
|
||||||
|
"""Get list of stored webinar keys from Redis."""
|
||||||
|
data = redis_client.get(KEY_WEBINAR_HISTORY)
|
||||||
|
if data:
|
||||||
|
try:
|
||||||
|
return json.loads(data)
|
||||||
|
except Exception as e:
|
||||||
|
logger.error(f'Failed to parse webinar history: {e}')
|
||||||
|
return []
|
||||||
|
|
||||||
|
|
||||||
|
def store_webinars(webinar_keys: list):
|
||||||
|
"""Store up to 3 most recent webinar keys in Redis."""
|
||||||
|
# Keep only last 3
|
||||||
|
webinar_keys = webinar_keys[-3:]
|
||||||
|
try:
|
||||||
|
redis_client.set(KEY_WEBINAR_HISTORY, json.dumps(webinar_keys))
|
||||||
|
logger.info(f'Stored {len(webinar_keys)} webinar(s) in history')
|
||||||
|
except Exception as e:
|
||||||
|
logger.error(f'Failed to store webinar history: {e}')
|
||||||
|
|
||||||
|
|
||||||
|
async def check_webinars_job(context: ContextTypes.DEFAULT_TYPE):
|
||||||
|
"""Background job to check for webinars using Async Playwright.
|
||||||
|
|
||||||
|
Returns:
|
||||||
|
int: Number of webinars found, or None if check failed
|
||||||
|
"""
|
||||||
|
logger.info('Running webinar check...')
|
||||||
|
|
||||||
|
phpsessid = redis_client.get(KEY_PHPSESSID)
|
||||||
|
if not phpsessid:
|
||||||
|
logger.warning('PHPSESSID missing. Skipping check.')
|
||||||
|
# --- DEBUG LOGGING ---
|
||||||
|
try:
|
||||||
|
with open('phpsessid_missing.log', 'a') as f:
|
||||||
|
f.write(f'[{os.getcwd()}] PHPSESSID missing at {context.job.last_run: %Y-%m-%d %H:%M:%S}\n')
|
||||||
|
except Exception as e:
|
||||||
|
logger.error(f'Failed to write PHPSESSID debug log: {e}')
|
||||||
|
# ---------------------
|
||||||
|
return None
|
||||||
|
|
||||||
|
current_webinars = [] # List of dicts with name, url, and formatted text
|
||||||
|
content = ''
|
||||||
|
|
||||||
|
try:
|
||||||
|
async with async_playwright() as p:
|
||||||
|
# Connect to remote Playwright service
|
||||||
|
browser = await p.chromium.connect(PLAYWRIGHT_WS)
|
||||||
|
|
||||||
|
try:
|
||||||
|
# Create browser context with user agent
|
||||||
|
context_browser = await browser.new_context(user_agent=USER_AGENT)
|
||||||
|
|
||||||
|
# Add PHPSESSID cookie
|
||||||
|
await context_browser.add_cookies(
|
||||||
|
[{'name': 'PHPSESSID', 'value': phpsessid, 'domain': 'edu.edu.vn.ua', 'path': '/'}]
|
||||||
|
)
|
||||||
|
|
||||||
|
# Create new page
|
||||||
|
page = await context_browser.new_page()
|
||||||
|
|
||||||
|
try:
|
||||||
|
# Navigate to webinar page
|
||||||
|
await page.goto(WEBINAR_URL, wait_until='domcontentloaded')
|
||||||
|
|
||||||
|
# Wait for the table to load
|
||||||
|
await page.wait_for_selector('#meetings table', timeout=10000)
|
||||||
|
await page.wait_for_timeout(2000)
|
||||||
|
|
||||||
|
# Get page content
|
||||||
|
content = await page.content()
|
||||||
|
|
||||||
|
# Check if "no webinar" message is present
|
||||||
|
if 'Жодного онлайн уроку зараз' not in content:
|
||||||
|
logger.info('!!! WEBINAR FOUND !!!')
|
||||||
|
|
||||||
|
# Extract webinar details from table rows
|
||||||
|
rows = page.locator('#meetings table tbody tr')
|
||||||
|
count = await rows.count()
|
||||||
|
|
||||||
|
for i in range(count):
|
||||||
|
row = rows.nth(i)
|
||||||
|
text = await row.inner_text()
|
||||||
|
|
||||||
|
if 'Жодного онлайн уроку зараз' not in text:
|
||||||
|
# Extract name (topic) from first column
|
||||||
|
name_elem = row.locator('td').nth(0)
|
||||||
|
name = await name_elem.inner_text()
|
||||||
|
name = name.strip()
|
||||||
|
|
||||||
|
# Extract join URL from fourth column
|
||||||
|
url_elem = row.locator('td').nth(3).locator('a[href*="/webinar/join/"]').first
|
||||||
|
url = await url_elem.get_attribute('href')
|
||||||
|
|
||||||
|
if name and url:
|
||||||
|
current_webinars.append({'name': name, 'url': url, 'text': text.strip()})
|
||||||
|
logger.info(f'Found webinar: {name} -> {url}')
|
||||||
|
else:
|
||||||
|
logger.info('No webinars found (expected message present)')
|
||||||
|
|
||||||
|
except Exception as e:
|
||||||
|
logger.error(f'Error checking page: {e}. Saving content for debug.')
|
||||||
|
# If page content is available, save it on error
|
||||||
|
with contextlib.suppress(Exception):
|
||||||
|
if page and not content:
|
||||||
|
content = await page.content()
|
||||||
|
|
||||||
|
return None
|
||||||
|
finally:
|
||||||
|
await page.close()
|
||||||
|
await context_browser.close()
|
||||||
|
|
||||||
|
finally:
|
||||||
|
await browser.close()
|
||||||
|
|
||||||
|
except Exception as e:
|
||||||
|
logger.error(f'Playwright error: {e}')
|
||||||
|
return None
|
||||||
|
|
||||||
|
# --- DEBUG LOGGING (Saving last response content) ---
|
||||||
|
if not current_webinars and content: # if no webinars found, save the page content
|
||||||
|
try:
|
||||||
|
with open('response.html', 'w', encoding='utf-8') as f:
|
||||||
|
f.write(content)
|
||||||
|
logger.info('Saved page content to response.html for debug.')
|
||||||
|
except Exception as e:
|
||||||
|
logger.error(f'Failed to write debug HTML: {e}')
|
||||||
|
# -----------------------------------------------------
|
||||||
|
|
||||||
|
# Check for NEW webinars and notify
|
||||||
|
if current_webinars:
|
||||||
|
# Get stored webinar history
|
||||||
|
stored_keys = get_stored_webinars()
|
||||||
|
logger.info(f'Stored webinar keys: {stored_keys}')
|
||||||
|
|
||||||
|
# Find new webinars (not in history)
|
||||||
|
new_webinars = []
|
||||||
|
current_keys = []
|
||||||
|
|
||||||
|
for webinar in current_webinars:
|
||||||
|
key = get_webinar_key(webinar['url'])
|
||||||
|
current_keys.append(key)
|
||||||
|
|
||||||
|
if key not in stored_keys:
|
||||||
|
new_webinars.append(webinar)
|
||||||
|
logger.info(f'NEW webinar detected: {webinar["name"]}')
|
||||||
|
|
||||||
|
# Update stored history with current webinars
|
||||||
|
# Merge old and new, keeping only last 5
|
||||||
|
updated_keys = stored_keys + [k for k in current_keys if k not in stored_keys]
|
||||||
|
store_webinars(updated_keys)
|
||||||
|
|
||||||
|
# Notify subscribers ONLY about NEW webinars
|
||||||
|
if new_webinars:
|
||||||
|
subscribers = redis_client.smembers(KEY_SUBSCRIBERS)
|
||||||
|
logger.info(
|
||||||
|
f'Sending notification about {len(new_webinars)} new webinar(s) to {len(subscribers)} subscriber(s)'
|
||||||
|
)
|
||||||
|
|
||||||
|
for sub_id in subscribers:
|
||||||
|
try:
|
||||||
|
# Build message in user's language
|
||||||
|
# sub_id comes from redis set as string, convert to int for translation lookup
|
||||||
|
webinar_items = '\n\n'.join(
|
||||||
|
[t(int(sub_id), 'webinar_item', name=w['name'], url=w['url']) for w in new_webinars]
|
||||||
|
)
|
||||||
|
message = t(int(sub_id), 'webinar_found') + webinar_items
|
||||||
|
|
||||||
|
await context.bot.send_message(chat_id=sub_id, text=message, parse_mode='HTML')
|
||||||
|
logger.info(f'Notification sent to {sub_id}')
|
||||||
|
except Exception as e:
|
||||||
|
logger.error(f'Failed to send to {sub_id}: {e}')
|
||||||
|
else:
|
||||||
|
logger.info(f'Found {len(current_webinars)} webinar(s), but all are already known')
|
||||||
|
|
||||||
|
return len(current_webinars)
|
||||||
|
|
||||||
|
|
||||||
|
# --- Main ---
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
if not WEBINAR_TELEGRAM_TOKEN:
|
||||||
|
logger.error('WEBINAR_TELEGRAM_TOKEN is missing!')
|
||||||
|
return
|
||||||
|
|
||||||
|
# Set default whitelist state if not set
|
||||||
|
if not redis_client.exists(KEY_WHITELIST_ENABLED):
|
||||||
|
redis_client.set(KEY_WHITELIST_ENABLED, '1') # Enabled by default
|
||||||
|
|
||||||
|
# Add admin to whitelist
|
||||||
|
if ADMIN_ID:
|
||||||
|
redis_client.sadd(KEY_WHITELIST, str(ADMIN_ID))
|
||||||
|
|
||||||
|
app = Application.builder().token(WEBINAR_TELEGRAM_TOKEN).build()
|
||||||
|
|
||||||
|
# Handlers
|
||||||
|
app.add_handler(CommandHandler('start', start))
|
||||||
|
app.add_handler(CommandHandler('stop', stop_command))
|
||||||
|
app.add_handler(CommandHandler('help', help_command))
|
||||||
|
app.add_handler(CommandHandler('language', language_command))
|
||||||
|
app.add_handler(CommandHandler('adduser', add_user))
|
||||||
|
app.add_handler(CommandHandler('removeuser', remove_user))
|
||||||
|
app.add_handler(CommandHandler('clearhistory', clear_history))
|
||||||
|
app.add_handler(CommandHandler('diary', diary_command))
|
||||||
|
|
||||||
|
# Callback handlers - diary first, then language selection, then admin panel
|
||||||
|
app.add_handler(CallbackQueryHandler(diary_callback, pattern='^diary_'))
|
||||||
|
app.add_handler(CallbackQueryHandler(language_callback, pattern='^lang_'))
|
||||||
|
app.add_handler(CallbackQueryHandler(admin_callback))
|
||||||
|
|
||||||
|
# Job Queue
|
||||||
|
job_queue = app.job_queue
|
||||||
|
job_queue.run_repeating(check_webinars_job, interval=WEBINAR_CHECK_INTERVAL, first=10)
|
||||||
|
|
||||||
|
logger.info('Bot started polling...')
|
||||||
|
app.run_polling()
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == '__main__':
|
||||||
|
main()
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
FROM nginx:alpine
|
||||||
|
RUN rm -rf /usr/share/nginx/html/*
|
||||||
|
COPY html /usr/share/nginx/html
|
||||||
|
EXPOSE 80
|
||||||
|
CMD ["nginx", "-g", "daemon off;"]
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
services:
|
||||||
|
errorpage:
|
||||||
|
build: .
|
||||||
|
image: gcr.forust.xyz/forust/error-pages:latest
|
||||||
|
pull_policy: build
|
||||||
|
container_name: error-pages
|
||||||
|
restart: unless-stopped
|
||||||
|
# ports:
|
||||||
|
# - 1234:80
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
|
labels:
|
||||||
|
- "traefik.enable=true"
|
||||||
|
- "traefik.http.services.error-pages.loadbalancer.server.port=80"
|
||||||
|
# Error handler middleware
|
||||||
|
- "traefik.http.middlewares.error-pages.errors.status=400,402-599"
|
||||||
|
- "traefik.http.middlewares.error-pages.errors.service=error-pages"
|
||||||
|
- "traefik.http.middlewares.error-pages.errors.query=/{status}.html"
|
||||||
|
networks:
|
||||||
|
proxy:
|
||||||
|
external: true
|
||||||
@@ -0,0 +1,208 @@
|
|||||||
|
<!DOCTYPE html>
|
||||||
|
<html lang="en">
|
||||||
|
|
||||||
|
<head>
|
||||||
|
<meta charset="UTF-8">
|
||||||
|
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||||
|
<title>403 // Forbidden</title>
|
||||||
|
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||||
|
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||||
|
<style>
|
||||||
|
/* hidden in a plain sight? */
|
||||||
|
:root {
|
||||||
|
--bg-color: #050505;
|
||||||
|
--text-color: #e0e0e0;
|
||||||
|
--accent: #ffffff;
|
||||||
|
--dim: #666666;
|
||||||
|
--font-mono: 'Courier New', Courier, monospace;
|
||||||
|
}
|
||||||
|
|
||||||
|
* {
|
||||||
|
box-sizing: border-box;
|
||||||
|
margin: 0;
|
||||||
|
padding: 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
body {
|
||||||
|
background-color: var(--bg-color);
|
||||||
|
color: var(--text-color);
|
||||||
|
font-family: var(--font-mono);
|
||||||
|
line-height: 1.6;
|
||||||
|
font-size: 16px;
|
||||||
|
padding: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
a {
|
||||||
|
color: var(--text-color);
|
||||||
|
text-decoration: none;
|
||||||
|
border-bottom: 1px solid var(--dim);
|
||||||
|
transition: all 0.2s;
|
||||||
|
}
|
||||||
|
|
||||||
|
a:hover {
|
||||||
|
background-color: var(--text-color);
|
||||||
|
color: var(--bg-color);
|
||||||
|
border-color: var(--text-color);
|
||||||
|
}
|
||||||
|
|
||||||
|
.container {
|
||||||
|
max-width: 800px;
|
||||||
|
margin: 0 auto;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* TEXT */
|
||||||
|
h1 {
|
||||||
|
font-size: 2.5rem;
|
||||||
|
text-transform: uppercase;
|
||||||
|
letter-spacing: -2px;
|
||||||
|
margin-bottom: 0.5rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
h2 {
|
||||||
|
font-size: 1.2rem;
|
||||||
|
margin-bottom: 1.5rem;
|
||||||
|
border-bottom: 1px solid var(--dim);
|
||||||
|
display: inline-block;
|
||||||
|
padding-right: 20px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.subtitle {
|
||||||
|
color: var(--dim);
|
||||||
|
margin-bottom: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
hr {
|
||||||
|
border: 0;
|
||||||
|
border-top: 1px dashed var(--dim);
|
||||||
|
margin: 2rem 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
.comment {
|
||||||
|
color: var(--dim);
|
||||||
|
font-size: 0.9rem;
|
||||||
|
margin-left: 10px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* SECTIONS */
|
||||||
|
section {
|
||||||
|
margin-bottom: 3rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* LISTS */
|
||||||
|
ul {
|
||||||
|
list-style: none;
|
||||||
|
}
|
||||||
|
|
||||||
|
.link-list li {
|
||||||
|
margin-bottom: 0.8rem;
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 15px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* STACK GRID */
|
||||||
|
.grid-2 {
|
||||||
|
display: grid;
|
||||||
|
grid-template-columns: 1fr 1fr;
|
||||||
|
gap: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.skill-item {
|
||||||
|
display: flex;
|
||||||
|
justify-content: space-between;
|
||||||
|
margin-bottom: 0.5rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.level {
|
||||||
|
font-weight: bold;
|
||||||
|
}
|
||||||
|
|
||||||
|
.special .level {
|
||||||
|
color: var(--text-color);
|
||||||
|
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* my dudes */
|
||||||
|
.team-grid {
|
||||||
|
display: flex;
|
||||||
|
gap: 2rem;
|
||||||
|
flex-wrap: wrap;
|
||||||
|
margin-top: 1rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.member {
|
||||||
|
text-align: center;
|
||||||
|
width: 100px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.avatar {
|
||||||
|
width: 80px;
|
||||||
|
height: 80px;
|
||||||
|
background-color: #222;
|
||||||
|
border: 2px solid var(--text-color);
|
||||||
|
margin: 0 auto 10px auto;
|
||||||
|
background-size: cover;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* if no avatar added: */
|
||||||
|
.placeholder::before {
|
||||||
|
content: "?";
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
justify-content: center;
|
||||||
|
height: 100%;
|
||||||
|
font-size: 2rem;
|
||||||
|
color: var(--dim);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* REPOS */
|
||||||
|
.repo-list li {
|
||||||
|
margin-bottom: 1rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* FOOTER */
|
||||||
|
footer {
|
||||||
|
text-align: center;
|
||||||
|
color: var(--dim);
|
||||||
|
font-size: 0.8rem;
|
||||||
|
/* flag{why-are-you-here?} */
|
||||||
|
margin-top: 4rem;
|
||||||
|
}
|
||||||
|
/* SMTH RESPONSIVE */
|
||||||
|
@media (max-width: 600px) {
|
||||||
|
.grid-2 {
|
||||||
|
grid-template-columns: 1fr;
|
||||||
|
gap: 0;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
</style>
|
||||||
|
</head>
|
||||||
|
|
||||||
|
<body>
|
||||||
|
|
||||||
|
<div class="container">
|
||||||
|
<header>
|
||||||
|
<h1 class="glitch" data-text="403">403</h1>
|
||||||
|
<p class="subtitle">> Forbidden / Access Denied.</p>
|
||||||
|
</header>
|
||||||
|
|
||||||
|
<hr>
|
||||||
|
|
||||||
|
<section id="message">
|
||||||
|
<h2>./error_message</h2>
|
||||||
|
<p>You do not have permission to access this resource.</p>
|
||||||
|
<br>
|
||||||
|
<p>Check the <a href="https://status.forust.xyz">System Status</a> if you believe this is an
|
||||||
|
error.</p>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
<footer>
|
||||||
|
<p>root@error:~$ sudo access_resource</p>
|
||||||
|
<p>User is not in the sudoers file. This incident will be reported.</p>
|
||||||
|
<p>© XRock - Just Signal.</p>
|
||||||
|
</footer>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
</body>
|
||||||
|
|
||||||
|
</html>
|
||||||
@@ -0,0 +1,207 @@
|
|||||||
|
<!DOCTYPE html>
|
||||||
|
<html lang="en">
|
||||||
|
|
||||||
|
<head>
|
||||||
|
<meta charset="UTF-8">
|
||||||
|
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||||
|
<title>404 // Not Found</title>
|
||||||
|
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||||
|
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||||
|
<style>
|
||||||
|
/* hidden in a plain sight? */
|
||||||
|
:root {
|
||||||
|
--bg-color: #050505;
|
||||||
|
--text-color: #e0e0e0;
|
||||||
|
--accent: #ffffff;
|
||||||
|
--dim: #666666;
|
||||||
|
--font-mono: 'Courier New', Courier, monospace;
|
||||||
|
}
|
||||||
|
|
||||||
|
* {
|
||||||
|
box-sizing: border-box;
|
||||||
|
margin: 0;
|
||||||
|
padding: 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
body {
|
||||||
|
background-color: var(--bg-color);
|
||||||
|
color: var(--text-color);
|
||||||
|
font-family: var(--font-mono);
|
||||||
|
line-height: 1.6;
|
||||||
|
font-size: 16px;
|
||||||
|
padding: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
a {
|
||||||
|
color: var(--text-color);
|
||||||
|
text-decoration: none;
|
||||||
|
border-bottom: 1px solid var(--dim);
|
||||||
|
transition: all 0.2s;
|
||||||
|
}
|
||||||
|
|
||||||
|
a:hover {
|
||||||
|
background-color: var(--text-color);
|
||||||
|
color: var(--bg-color);
|
||||||
|
border-color: var(--text-color);
|
||||||
|
}
|
||||||
|
|
||||||
|
.container {
|
||||||
|
max-width: 800px;
|
||||||
|
margin: 0 auto;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* TEXT */
|
||||||
|
h1 {
|
||||||
|
font-size: 2.5rem;
|
||||||
|
text-transform: uppercase;
|
||||||
|
letter-spacing: -2px;
|
||||||
|
margin-bottom: 0.5rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
h2 {
|
||||||
|
font-size: 1.2rem;
|
||||||
|
margin-bottom: 1.5rem;
|
||||||
|
border-bottom: 1px solid var(--dim);
|
||||||
|
display: inline-block;
|
||||||
|
padding-right: 20px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.subtitle {
|
||||||
|
color: var(--dim);
|
||||||
|
margin-bottom: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
hr {
|
||||||
|
border: 0;
|
||||||
|
border-top: 1px dashed var(--dim);
|
||||||
|
margin: 2rem 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
.comment {
|
||||||
|
color: var(--dim);
|
||||||
|
font-size: 0.9rem;
|
||||||
|
margin-left: 10px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* SECTIONS */
|
||||||
|
section {
|
||||||
|
margin-bottom: 3rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* LISTS */
|
||||||
|
ul {
|
||||||
|
list-style: none;
|
||||||
|
}
|
||||||
|
|
||||||
|
.link-list li {
|
||||||
|
margin-bottom: 0.8rem;
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 15px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* STACK GRID */
|
||||||
|
.grid-2 {
|
||||||
|
display: grid;
|
||||||
|
grid-template-columns: 1fr 1fr;
|
||||||
|
gap: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.skill-item {
|
||||||
|
display: flex;
|
||||||
|
justify-content: space-between;
|
||||||
|
margin-bottom: 0.5rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.level {
|
||||||
|
font-weight: bold;
|
||||||
|
}
|
||||||
|
|
||||||
|
.special .level {
|
||||||
|
color: var(--text-color);
|
||||||
|
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* my dudes */
|
||||||
|
.team-grid {
|
||||||
|
display: flex;
|
||||||
|
gap: 2rem;
|
||||||
|
flex-wrap: wrap;
|
||||||
|
margin-top: 1rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.member {
|
||||||
|
text-align: center;
|
||||||
|
width: 100px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.avatar {
|
||||||
|
width: 80px;
|
||||||
|
height: 80px;
|
||||||
|
background-color: #222;
|
||||||
|
border: 2px solid var(--text-color);
|
||||||
|
margin: 0 auto 10px auto;
|
||||||
|
background-size: cover;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* if no avatar added: */
|
||||||
|
.placeholder::before {
|
||||||
|
content: "?";
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
justify-content: center;
|
||||||
|
height: 100%;
|
||||||
|
font-size: 2rem;
|
||||||
|
color: var(--dim);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* REPOS */
|
||||||
|
.repo-list li {
|
||||||
|
margin-bottom: 1rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* FOOTER */
|
||||||
|
footer {
|
||||||
|
text-align: center;
|
||||||
|
color: var(--dim);
|
||||||
|
font-size: 0.8rem;
|
||||||
|
/* flag{why-are-you-here?} */
|
||||||
|
margin-top: 4rem;
|
||||||
|
}
|
||||||
|
/* SMTH RESPONSIVE */
|
||||||
|
@media (max-width: 600px) {
|
||||||
|
.grid-2 {
|
||||||
|
grid-template-columns: 1fr;
|
||||||
|
gap: 0;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
</style>
|
||||||
|
</head>
|
||||||
|
|
||||||
|
<body>
|
||||||
|
|
||||||
|
<div class="container">
|
||||||
|
<header>
|
||||||
|
<h1 class="glitch" data-text="404">404</h1>
|
||||||
|
<p class="subtitle">> Page Not Found / Lost in the Void.</p>
|
||||||
|
</header>
|
||||||
|
|
||||||
|
<hr>
|
||||||
|
|
||||||
|
<section id="message">
|
||||||
|
<h2>./error_message</h2>
|
||||||
|
<p>The page you are looking for does not exist or has been moved.</p>
|
||||||
|
<br>
|
||||||
|
<p>Check the <a href="https://status.forust.xyz">System Status</a> if you believe this is an error.</p>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
<footer>
|
||||||
|
<p>root@error:~$ ping target</p>
|
||||||
|
<p>Destination Host Unreachable</p>
|
||||||
|
<p>© XRock - Just Signal.</p>
|
||||||
|
</footer>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
</body>
|
||||||
|
|
||||||
|
</html>
|
||||||
@@ -0,0 +1,207 @@
|
|||||||
|
<!DOCTYPE html>
|
||||||
|
<html lang="en">
|
||||||
|
|
||||||
|
<head>
|
||||||
|
<meta charset="UTF-8">
|
||||||
|
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||||
|
<title>500 // Server Error</title>
|
||||||
|
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||||
|
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||||
|
<style>
|
||||||
|
/* hidden in a plain sight? */
|
||||||
|
:root {
|
||||||
|
--bg-color: #050505;
|
||||||
|
--text-color: #e0e0e0;
|
||||||
|
--accent: #ffffff;
|
||||||
|
--dim: #666666;
|
||||||
|
--font-mono: 'Courier New', Courier, monospace;
|
||||||
|
}
|
||||||
|
|
||||||
|
* {
|
||||||
|
box-sizing: border-box;
|
||||||
|
margin: 0;
|
||||||
|
padding: 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
body {
|
||||||
|
background-color: var(--bg-color);
|
||||||
|
color: var(--text-color);
|
||||||
|
font-family: var(--font-mono);
|
||||||
|
line-height: 1.6;
|
||||||
|
font-size: 16px;
|
||||||
|
padding: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
a {
|
||||||
|
color: var(--text-color);
|
||||||
|
text-decoration: none;
|
||||||
|
border-bottom: 1px solid var(--dim);
|
||||||
|
transition: all 0.2s;
|
||||||
|
}
|
||||||
|
|
||||||
|
a:hover {
|
||||||
|
background-color: var(--text-color);
|
||||||
|
color: var(--bg-color);
|
||||||
|
border-color: var(--text-color);
|
||||||
|
}
|
||||||
|
|
||||||
|
.container {
|
||||||
|
max-width: 800px;
|
||||||
|
margin: 0 auto;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* TEXT */
|
||||||
|
h1 {
|
||||||
|
font-size: 2.5rem;
|
||||||
|
text-transform: uppercase;
|
||||||
|
letter-spacing: -2px;
|
||||||
|
margin-bottom: 0.5rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
h2 {
|
||||||
|
font-size: 1.2rem;
|
||||||
|
margin-bottom: 1.5rem;
|
||||||
|
border-bottom: 1px solid var(--dim);
|
||||||
|
display: inline-block;
|
||||||
|
padding-right: 20px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.subtitle {
|
||||||
|
color: var(--dim);
|
||||||
|
margin-bottom: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
hr {
|
||||||
|
border: 0;
|
||||||
|
border-top: 1px dashed var(--dim);
|
||||||
|
margin: 2rem 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
.comment {
|
||||||
|
color: var(--dim);
|
||||||
|
font-size: 0.9rem;
|
||||||
|
margin-left: 10px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* SECTIONS */
|
||||||
|
section {
|
||||||
|
margin-bottom: 3rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* LISTS */
|
||||||
|
ul {
|
||||||
|
list-style: none;
|
||||||
|
}
|
||||||
|
|
||||||
|
.link-list li {
|
||||||
|
margin-bottom: 0.8rem;
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 15px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* STACK GRID */
|
||||||
|
.grid-2 {
|
||||||
|
display: grid;
|
||||||
|
grid-template-columns: 1fr 1fr;
|
||||||
|
gap: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.skill-item {
|
||||||
|
display: flex;
|
||||||
|
justify-content: space-between;
|
||||||
|
margin-bottom: 0.5rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.level {
|
||||||
|
font-weight: bold;
|
||||||
|
}
|
||||||
|
|
||||||
|
.special .level {
|
||||||
|
color: var(--text-color);
|
||||||
|
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* my dudes */
|
||||||
|
.team-grid {
|
||||||
|
display: flex;
|
||||||
|
gap: 2rem;
|
||||||
|
flex-wrap: wrap;
|
||||||
|
margin-top: 1rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.member {
|
||||||
|
text-align: center;
|
||||||
|
width: 100px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.avatar {
|
||||||
|
width: 80px;
|
||||||
|
height: 80px;
|
||||||
|
background-color: #222;
|
||||||
|
border: 2px solid var(--text-color);
|
||||||
|
margin: 0 auto 10px auto;
|
||||||
|
background-size: cover;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* if no avatar added: */
|
||||||
|
.placeholder::before {
|
||||||
|
content: "?";
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
justify-content: center;
|
||||||
|
height: 100%;
|
||||||
|
font-size: 2rem;
|
||||||
|
color: var(--dim);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* REPOS */
|
||||||
|
.repo-list li {
|
||||||
|
margin-bottom: 1rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* FOOTER */
|
||||||
|
footer {
|
||||||
|
text-align: center;
|
||||||
|
color: var(--dim);
|
||||||
|
font-size: 0.8rem;
|
||||||
|
/* flag{why-are-you-here?} */
|
||||||
|
margin-top: 4rem;
|
||||||
|
}
|
||||||
|
/* SMTH RESPONSIVE */
|
||||||
|
@media (max-width: 600px) {
|
||||||
|
.grid-2 {
|
||||||
|
grid-template-columns: 1fr;
|
||||||
|
gap: 0;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
</style>
|
||||||
|
</head>
|
||||||
|
|
||||||
|
<body>
|
||||||
|
|
||||||
|
<div class="container">
|
||||||
|
<header>
|
||||||
|
<h1 class="glitch" data-text="500">500</h1>
|
||||||
|
<p class="subtitle">> Internal Server Error / System Failure.</p>
|
||||||
|
</header>
|
||||||
|
|
||||||
|
<hr>
|
||||||
|
|
||||||
|
<section id="message">
|
||||||
|
<h2>./error_message</h2>
|
||||||
|
<p>Something went wrong on our end. We are working to fix it.</p>
|
||||||
|
<br>
|
||||||
|
<p>Check the <a href="https://status.forust.xyz">System Status</a> for more information.</p>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
<footer>
|
||||||
|
<p>root@error:~$ systemctl status service</p>
|
||||||
|
<p>Active: failed (Result: core-dump)</p>
|
||||||
|
<p>© XRock - Just Signal.</p>
|
||||||
|
</footer>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
</body>
|
||||||
|
|
||||||
|
</html>
|
||||||
@@ -0,0 +1,207 @@
|
|||||||
|
<!DOCTYPE html>
|
||||||
|
<html lang="en">
|
||||||
|
|
||||||
|
<head>
|
||||||
|
<meta charset="UTF-8">
|
||||||
|
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||||
|
<title>502 // Bad Gateway</title>
|
||||||
|
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||||
|
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||||
|
<style>
|
||||||
|
/* hidden in a plain sight? */
|
||||||
|
:root {
|
||||||
|
--bg-color: #050505;
|
||||||
|
--text-color: #e0e0e0;
|
||||||
|
--accent: #ffffff;
|
||||||
|
--dim: #666666;
|
||||||
|
--font-mono: 'Courier New', Courier, monospace;
|
||||||
|
}
|
||||||
|
|
||||||
|
* {
|
||||||
|
box-sizing: border-box;
|
||||||
|
margin: 0;
|
||||||
|
padding: 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
body {
|
||||||
|
background-color: var(--bg-color);
|
||||||
|
color: var(--text-color);
|
||||||
|
font-family: var(--font-mono);
|
||||||
|
line-height: 1.6;
|
||||||
|
font-size: 16px;
|
||||||
|
padding: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
a {
|
||||||
|
color: var(--text-color);
|
||||||
|
text-decoration: none;
|
||||||
|
border-bottom: 1px solid var(--dim);
|
||||||
|
transition: all 0.2s;
|
||||||
|
}
|
||||||
|
|
||||||
|
a:hover {
|
||||||
|
background-color: var(--text-color);
|
||||||
|
color: var(--bg-color);
|
||||||
|
border-color: var(--text-color);
|
||||||
|
}
|
||||||
|
|
||||||
|
.container {
|
||||||
|
max-width: 800px;
|
||||||
|
margin: 0 auto;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* TEXT */
|
||||||
|
h1 {
|
||||||
|
font-size: 2.5rem;
|
||||||
|
text-transform: uppercase;
|
||||||
|
letter-spacing: -2px;
|
||||||
|
margin-bottom: 0.5rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
h2 {
|
||||||
|
font-size: 1.2rem;
|
||||||
|
margin-bottom: 1.5rem;
|
||||||
|
border-bottom: 1px solid var(--dim);
|
||||||
|
display: inline-block;
|
||||||
|
padding-right: 20px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.subtitle {
|
||||||
|
color: var(--dim);
|
||||||
|
margin-bottom: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
hr {
|
||||||
|
border: 0;
|
||||||
|
border-top: 1px dashed var(--dim);
|
||||||
|
margin: 2rem 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
.comment {
|
||||||
|
color: var(--dim);
|
||||||
|
font-size: 0.9rem;
|
||||||
|
margin-left: 10px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* SECTIONS */
|
||||||
|
section {
|
||||||
|
margin-bottom: 3rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* LISTS */
|
||||||
|
ul {
|
||||||
|
list-style: none;
|
||||||
|
}
|
||||||
|
|
||||||
|
.link-list li {
|
||||||
|
margin-bottom: 0.8rem;
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 15px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* STACK GRID */
|
||||||
|
.grid-2 {
|
||||||
|
display: grid;
|
||||||
|
grid-template-columns: 1fr 1fr;
|
||||||
|
gap: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.skill-item {
|
||||||
|
display: flex;
|
||||||
|
justify-content: space-between;
|
||||||
|
margin-bottom: 0.5rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.level {
|
||||||
|
font-weight: bold;
|
||||||
|
}
|
||||||
|
|
||||||
|
.special .level {
|
||||||
|
color: var(--text-color);
|
||||||
|
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* my dudes */
|
||||||
|
.team-grid {
|
||||||
|
display: flex;
|
||||||
|
gap: 2rem;
|
||||||
|
flex-wrap: wrap;
|
||||||
|
margin-top: 1rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.member {
|
||||||
|
text-align: center;
|
||||||
|
width: 100px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.avatar {
|
||||||
|
width: 80px;
|
||||||
|
height: 80px;
|
||||||
|
background-color: #222;
|
||||||
|
border: 2px solid var(--text-color);
|
||||||
|
margin: 0 auto 10px auto;
|
||||||
|
background-size: cover;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* if no avatar added: */
|
||||||
|
.placeholder::before {
|
||||||
|
content: "?";
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
justify-content: center;
|
||||||
|
height: 100%;
|
||||||
|
font-size: 2rem;
|
||||||
|
color: var(--dim);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* REPOS */
|
||||||
|
.repo-list li {
|
||||||
|
margin-bottom: 1rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* FOOTER */
|
||||||
|
footer {
|
||||||
|
text-align: center;
|
||||||
|
color: var(--dim);
|
||||||
|
font-size: 0.8rem;
|
||||||
|
/* flag{why-are-you-here?} */
|
||||||
|
margin-top: 4rem;
|
||||||
|
}
|
||||||
|
/* SMTH RESPONSIVE */
|
||||||
|
@media (max-width: 600px) {
|
||||||
|
.grid-2 {
|
||||||
|
grid-template-columns: 1fr;
|
||||||
|
gap: 0;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
</style>
|
||||||
|
</head>
|
||||||
|
|
||||||
|
<body>
|
||||||
|
|
||||||
|
<div class="container">
|
||||||
|
<header>
|
||||||
|
<h1 class="glitch" data-text="502">502</h1>
|
||||||
|
<p class="subtitle">> Bad Gateway / System Failure.</p>
|
||||||
|
</header>
|
||||||
|
|
||||||
|
<hr>
|
||||||
|
|
||||||
|
<section id="message">
|
||||||
|
<h2>./error_message</h2>
|
||||||
|
<p>The server received an invalid response from the upstream server.</p>
|
||||||
|
<br>
|
||||||
|
<p>Check the <a href="https://status.forust.xyz">System Status</a> for more information.</p>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
<footer>
|
||||||
|
<p>root@error:~$ curl -I upstream_host</p>
|
||||||
|
<p>HTTP/1.1 502 Bad Gateway</p>
|
||||||
|
<p>© XRock - Just Signal.</p>
|
||||||
|
</footer>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
</body>
|
||||||
|
|
||||||
|
</html>
|
||||||
@@ -0,0 +1,207 @@
|
|||||||
|
<!DOCTYPE html>
|
||||||
|
<html lang="en">
|
||||||
|
|
||||||
|
<head>
|
||||||
|
<meta charset="UTF-8">
|
||||||
|
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||||
|
<title>503 // Service Unavailable</title>
|
||||||
|
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||||
|
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||||
|
<style>
|
||||||
|
/* hidden in a plain sight? */
|
||||||
|
:root {
|
||||||
|
--bg-color: #050505;
|
||||||
|
--text-color: #e0e0e0;
|
||||||
|
--accent: #ffffff;
|
||||||
|
--dim: #666666;
|
||||||
|
--font-mono: 'Courier New', Courier, monospace;
|
||||||
|
}
|
||||||
|
|
||||||
|
* {
|
||||||
|
box-sizing: border-box;
|
||||||
|
margin: 0;
|
||||||
|
padding: 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
body {
|
||||||
|
background-color: var(--bg-color);
|
||||||
|
color: var(--text-color);
|
||||||
|
font-family: var(--font-mono);
|
||||||
|
line-height: 1.6;
|
||||||
|
font-size: 16px;
|
||||||
|
padding: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
a {
|
||||||
|
color: var(--text-color);
|
||||||
|
text-decoration: none;
|
||||||
|
border-bottom: 1px solid var(--dim);
|
||||||
|
transition: all 0.2s;
|
||||||
|
}
|
||||||
|
|
||||||
|
a:hover {
|
||||||
|
background-color: var(--text-color);
|
||||||
|
color: var(--bg-color);
|
||||||
|
border-color: var(--text-color);
|
||||||
|
}
|
||||||
|
|
||||||
|
.container {
|
||||||
|
max-width: 800px;
|
||||||
|
margin: 0 auto;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* TEXT */
|
||||||
|
h1 {
|
||||||
|
font-size: 2.5rem;
|
||||||
|
text-transform: uppercase;
|
||||||
|
letter-spacing: -2px;
|
||||||
|
margin-bottom: 0.5rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
h2 {
|
||||||
|
font-size: 1.2rem;
|
||||||
|
margin-bottom: 1.5rem;
|
||||||
|
border-bottom: 1px solid var(--dim);
|
||||||
|
display: inline-block;
|
||||||
|
padding-right: 20px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.subtitle {
|
||||||
|
color: var(--dim);
|
||||||
|
margin-bottom: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
hr {
|
||||||
|
border: 0;
|
||||||
|
border-top: 1px dashed var(--dim);
|
||||||
|
margin: 2rem 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
.comment {
|
||||||
|
color: var(--dim);
|
||||||
|
font-size: 0.9rem;
|
||||||
|
margin-left: 10px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* SECTIONS */
|
||||||
|
section {
|
||||||
|
margin-bottom: 3rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* LISTS */
|
||||||
|
ul {
|
||||||
|
list-style: none;
|
||||||
|
}
|
||||||
|
|
||||||
|
.link-list li {
|
||||||
|
margin-bottom: 0.8rem;
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 15px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* STACK GRID */
|
||||||
|
.grid-2 {
|
||||||
|
display: grid;
|
||||||
|
grid-template-columns: 1fr 1fr;
|
||||||
|
gap: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.skill-item {
|
||||||
|
display: flex;
|
||||||
|
justify-content: space-between;
|
||||||
|
margin-bottom: 0.5rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.level {
|
||||||
|
font-weight: bold;
|
||||||
|
}
|
||||||
|
|
||||||
|
.special .level {
|
||||||
|
color: var(--text-color);
|
||||||
|
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* my dudes */
|
||||||
|
.team-grid {
|
||||||
|
display: flex;
|
||||||
|
gap: 2rem;
|
||||||
|
flex-wrap: wrap;
|
||||||
|
margin-top: 1rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.member {
|
||||||
|
text-align: center;
|
||||||
|
width: 100px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.avatar {
|
||||||
|
width: 80px;
|
||||||
|
height: 80px;
|
||||||
|
background-color: #222;
|
||||||
|
border: 2px solid var(--text-color);
|
||||||
|
margin: 0 auto 10px auto;
|
||||||
|
background-size: cover;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* if no avatar added: */
|
||||||
|
.placeholder::before {
|
||||||
|
content: "?";
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
justify-content: center;
|
||||||
|
height: 100%;
|
||||||
|
font-size: 2rem;
|
||||||
|
color: var(--dim);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* REPOS */
|
||||||
|
.repo-list li {
|
||||||
|
margin-bottom: 1rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* FOOTER */
|
||||||
|
footer {
|
||||||
|
text-align: center;
|
||||||
|
color: var(--dim);
|
||||||
|
font-size: 0.8rem;
|
||||||
|
/* flag{why-are-you-here?} */
|
||||||
|
margin-top: 4rem;
|
||||||
|
}
|
||||||
|
/* SMTH RESPONSIVE */
|
||||||
|
@media (max-width: 600px) {
|
||||||
|
.grid-2 {
|
||||||
|
grid-template-columns: 1fr;
|
||||||
|
gap: 0;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
</style>
|
||||||
|
</head>
|
||||||
|
|
||||||
|
<body>
|
||||||
|
|
||||||
|
<div class="container">
|
||||||
|
<header>
|
||||||
|
<h1 class="glitch" data-text="503">503</h1>
|
||||||
|
<p class="subtitle">> Service Unavailable / System Failure.</p>
|
||||||
|
</header>
|
||||||
|
|
||||||
|
<hr>
|
||||||
|
|
||||||
|
<section id="message">
|
||||||
|
<h2>./error_message</h2>
|
||||||
|
<p>The server is currently unable to handle the request due to maintenance or overload.</p>
|
||||||
|
<br>
|
||||||
|
<p>Check the <a href="https://status.forust.xyz">System Status</a> for more information.</p>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
<footer>
|
||||||
|
<p>root@error:~$ systemctl start service</p>
|
||||||
|
<p>Job for service failed because the control process exited with error code.</p>
|
||||||
|
<p>© XRock - Just Signal.</p>
|
||||||
|
</footer>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
</body>
|
||||||
|
|
||||||
|
</html>
|
||||||
@@ -0,0 +1,207 @@
|
|||||||
|
<!DOCTYPE html>
|
||||||
|
<html lang="en">
|
||||||
|
|
||||||
|
<head>
|
||||||
|
<meta charset="UTF-8">
|
||||||
|
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||||
|
<title>504 // Gateway Timeout</title>
|
||||||
|
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||||
|
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||||
|
<style>
|
||||||
|
/* hidden in a plain sight? */
|
||||||
|
:root {
|
||||||
|
--bg-color: #050505;
|
||||||
|
--text-color: #e0e0e0;
|
||||||
|
--accent: #ffffff;
|
||||||
|
--dim: #666666;
|
||||||
|
--font-mono: 'Courier New', Courier, monospace;
|
||||||
|
}
|
||||||
|
|
||||||
|
* {
|
||||||
|
box-sizing: border-box;
|
||||||
|
margin: 0;
|
||||||
|
padding: 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
body {
|
||||||
|
background-color: var(--bg-color);
|
||||||
|
color: var(--text-color);
|
||||||
|
font-family: var(--font-mono);
|
||||||
|
line-height: 1.6;
|
||||||
|
font-size: 16px;
|
||||||
|
padding: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
a {
|
||||||
|
color: var(--text-color);
|
||||||
|
text-decoration: none;
|
||||||
|
border-bottom: 1px solid var(--dim);
|
||||||
|
transition: all 0.2s;
|
||||||
|
}
|
||||||
|
|
||||||
|
a:hover {
|
||||||
|
background-color: var(--text-color);
|
||||||
|
color: var(--bg-color);
|
||||||
|
border-color: var(--text-color);
|
||||||
|
}
|
||||||
|
|
||||||
|
.container {
|
||||||
|
max-width: 800px;
|
||||||
|
margin: 0 auto;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* TEXT */
|
||||||
|
h1 {
|
||||||
|
font-size: 2.5rem;
|
||||||
|
text-transform: uppercase;
|
||||||
|
letter-spacing: -2px;
|
||||||
|
margin-bottom: 0.5rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
h2 {
|
||||||
|
font-size: 1.2rem;
|
||||||
|
margin-bottom: 1.5rem;
|
||||||
|
border-bottom: 1px solid var(--dim);
|
||||||
|
display: inline-block;
|
||||||
|
padding-right: 20px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.subtitle {
|
||||||
|
color: var(--dim);
|
||||||
|
margin-bottom: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
hr {
|
||||||
|
border: 0;
|
||||||
|
border-top: 1px dashed var(--dim);
|
||||||
|
margin: 2rem 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
.comment {
|
||||||
|
color: var(--dim);
|
||||||
|
font-size: 0.9rem;
|
||||||
|
margin-left: 10px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* SECTIONS */
|
||||||
|
section {
|
||||||
|
margin-bottom: 3rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* LISTS */
|
||||||
|
ul {
|
||||||
|
list-style: none;
|
||||||
|
}
|
||||||
|
|
||||||
|
.link-list li {
|
||||||
|
margin-bottom: 0.8rem;
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 15px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* STACK GRID */
|
||||||
|
.grid-2 {
|
||||||
|
display: grid;
|
||||||
|
grid-template-columns: 1fr 1fr;
|
||||||
|
gap: 2rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.skill-item {
|
||||||
|
display: flex;
|
||||||
|
justify-content: space-between;
|
||||||
|
margin-bottom: 0.5rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.level {
|
||||||
|
font-weight: bold;
|
||||||
|
}
|
||||||
|
|
||||||
|
.special .level {
|
||||||
|
color: var(--text-color);
|
||||||
|
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* my dudes */
|
||||||
|
.team-grid {
|
||||||
|
display: flex;
|
||||||
|
gap: 2rem;
|
||||||
|
flex-wrap: wrap;
|
||||||
|
margin-top: 1rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.member {
|
||||||
|
text-align: center;
|
||||||
|
width: 100px;
|
||||||
|
}
|
||||||
|
|
||||||
|
.avatar {
|
||||||
|
width: 80px;
|
||||||
|
height: 80px;
|
||||||
|
background-color: #222;
|
||||||
|
border: 2px solid var(--text-color);
|
||||||
|
margin: 0 auto 10px auto;
|
||||||
|
background-size: cover;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* if no avatar added: */
|
||||||
|
.placeholder::before {
|
||||||
|
content: "?";
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
justify-content: center;
|
||||||
|
height: 100%;
|
||||||
|
font-size: 2rem;
|
||||||
|
color: var(--dim);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* REPOS */
|
||||||
|
.repo-list li {
|
||||||
|
margin-bottom: 1rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* FOOTER */
|
||||||
|
footer {
|
||||||
|
text-align: center;
|
||||||
|
color: var(--dim);
|
||||||
|
font-size: 0.8rem;
|
||||||
|
/* flag{why-are-you-here?} */
|
||||||
|
margin-top: 4rem;
|
||||||
|
}
|
||||||
|
/* SMTH RESPONSIVE */
|
||||||
|
@media (max-width: 600px) {
|
||||||
|
.grid-2 {
|
||||||
|
grid-template-columns: 1fr;
|
||||||
|
gap: 0;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
</style>
|
||||||
|
</head>
|
||||||
|
|
||||||
|
<body>
|
||||||
|
|
||||||
|
<div class="container">
|
||||||
|
<header>
|
||||||
|
<h1 class="glitch" data-text="504">504</h1>
|
||||||
|
<p class="subtitle">> Gateway Timeout / System Failure.</p>
|
||||||
|
</header>
|
||||||
|
|
||||||
|
<hr>
|
||||||
|
|
||||||
|
<section id="message">
|
||||||
|
<h2>./error_message</h2>
|
||||||
|
<p>The server did not receive a timely response from the upstream server.</p>
|
||||||
|
<br>
|
||||||
|
<p>Check the <a href="https://status.forust.xyz">System Status</a> for more information.</p>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
<footer>
|
||||||
|
<p>root@error:~$ timeout 30s curl upstream</p>
|
||||||
|
<p>curl: (28) Operation timed out after 30001 milliseconds with 0 bytes received</p>
|
||||||
|
<p>© XRock - Just Signal.</p>
|
||||||
|
</footer>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
</body>
|
||||||
|
|
||||||
|
</html>
|
||||||
@@ -0,0 +1,33 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: error-pages-service
|
||||||
|
namespace: error-pages
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: error-pages
|
||||||
|
ports:
|
||||||
|
- port: 80
|
||||||
|
targetPort: 80
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: error-pages-deployment
|
||||||
|
namespace: error-pages
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: error-pages
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: error-pages
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: error-pages
|
||||||
|
image: gcr.forust.xyz/forust/error-pages:latest
|
||||||
|
ports:
|
||||||
|
- containerPort: 80
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: error-pages
|
||||||
+4
-1
@@ -1,3 +1,6 @@
|
|||||||
GITEA_POSTGRES_USER=
|
GITEA_POSTGRES_USER=
|
||||||
GITEA_POSTGRES_PASSWORD=
|
GITEA_POSTGRES_PASSWORD=
|
||||||
GITEA_POSTGRES_DB=gitea
|
GITEA_POSTGRES_DB=gitea
|
||||||
|
GITEA_SMTP_PASS=
|
||||||
|
MAILER_ADDR=
|
||||||
|
SERVICE_EMAIL=email.used.by.services@domain.tld
|
||||||
+41
-12
@@ -1,7 +1,8 @@
|
|||||||
services:
|
services:
|
||||||
server:
|
server:
|
||||||
image: docker.gitea.com/gitea:1.25.1
|
image: docker.gitea.com/gitea:1.26
|
||||||
container_name: gitea
|
container_name: gitea
|
||||||
|
restart: always
|
||||||
environment:
|
environment:
|
||||||
- USER_UID=1000
|
- USER_UID=1000
|
||||||
- USER_GID=1000
|
- USER_GID=1000
|
||||||
@@ -11,25 +12,54 @@ services:
|
|||||||
- GITEA__database__USER=gitea
|
- GITEA__database__USER=gitea
|
||||||
- GITEA__database__PASSWD=gitea
|
- GITEA__database__PASSWD=gitea
|
||||||
- GITEA__database__NAME=gitea
|
- GITEA__database__NAME=gitea
|
||||||
#Server
|
# Server
|
||||||
- GITEA__server__ROOT_URL=https://gitea.forust.xyz
|
- GITEA__server__ROOT_URL=https://gitea.forust.xyz
|
||||||
|
- GITEA__server__SSH_DOMAIN=gitssh.forust.xyz
|
||||||
- GITEA__server__SSH_PORT=2221
|
- GITEA__server__SSH_PORT=2221
|
||||||
restart: always
|
# Mailer
|
||||||
networks:
|
- GITEA__mailer__ENABLED=true
|
||||||
- gitea-db
|
- GITEA__mailer__FROM=${SERVICE_EMAIL}
|
||||||
- traefik-proxy
|
- GITEA__mailer__SMTP_ADDR=${MAILER_ADDR}:465
|
||||||
|
- GITEA__mailer__USER=${SERVICE_EMAIL}
|
||||||
|
- GITEA__mailer__PASSWD=${GITEA_SMTP_PASS}
|
||||||
|
- GITEA__mailer__PROTOCOL=SMTP
|
||||||
|
- GITEA__service__REGISTER_EMAIL_CONFIRM=true
|
||||||
|
- GITEA__service__ENABLE_NOTIFY_MAIL=true
|
||||||
volumes:
|
volumes:
|
||||||
- ./gitea-data:/data
|
- ./gitea-data:/data
|
||||||
- /etc/timezone:/etc/timezone:ro
|
- /etc/timezone:/etc/timezone:ro
|
||||||
- /etc/localtime:/etc/localtime:ro
|
- /etc/localtime:/etc/localtime:ro
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=traefik-proxy"
|
- "traefik.http.services.gitea.loadbalancer.server.port=3000"
|
||||||
|
|
||||||
|
# Prod Router
|
||||||
|
- "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)"
|
||||||
|
- "traefik.http.routers.gitea.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.gitea.tls.certresolver"
|
||||||
|
# Local Router
|
||||||
|
- "traefik.http.routers.gitea-local.rule=Host(`gitea.workstation.internal`)"
|
||||||
|
- "traefik.http.routers.gitea-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.gitea-local.tls=true"
|
||||||
|
# Dev Router
|
||||||
|
- "traefik.http.routers.gitea-dev.rule=Host(`gitea.gigaforust.internal`)"
|
||||||
|
- "traefik.http.routers.gitea-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.gitea-dev.tls=true"
|
||||||
|
# SSH Router
|
||||||
|
- "traefik.tcp.services.gitea.loadbalancer.server.port=22"
|
||||||
|
- "traefik.tcp.routers.gitea.entrypoints=ssh"
|
||||||
|
- "traefik.tcp.routers.gitea.rule=HostSNI(`*`)"
|
||||||
|
# Gitea container registry Router
|
||||||
|
- "traefik.http.routers.gitea-registry.rule=Host(`gcr.forust.xyz`) && PathPrefix(`/v2`)"
|
||||||
|
- "traefik.http.routers.gitea-registry.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.gitea-registry.tls.certresolver=letsencrypt"
|
||||||
ports:
|
ports:
|
||||||
- "2221:22"
|
- "2221:22"
|
||||||
|
networks:
|
||||||
|
- gitea-db
|
||||||
|
- proxy
|
||||||
depends_on:
|
depends_on:
|
||||||
- db
|
- db
|
||||||
|
|
||||||
db:
|
db:
|
||||||
image: docker.io/library/postgres:14
|
image: docker.io/library/postgres:14
|
||||||
restart: always
|
restart: always
|
||||||
@@ -37,13 +67,12 @@ services:
|
|||||||
- POSTGRES_USER=gitea
|
- POSTGRES_USER=gitea
|
||||||
- POSTGRES_PASSWORD=gitea
|
- POSTGRES_PASSWORD=gitea
|
||||||
- POSTGRES_DB=gitea
|
- POSTGRES_DB=gitea
|
||||||
networks:
|
|
||||||
- gitea-db
|
|
||||||
volumes:
|
volumes:
|
||||||
- ./gitea-db/:/var/lib/postgresql/data
|
- ./gitea-db/:/var/lib/postgresql/data
|
||||||
|
networks:
|
||||||
|
- gitea-db
|
||||||
networks:
|
networks:
|
||||||
gitea-db:
|
gitea-db:
|
||||||
external: false
|
external: false
|
||||||
traefik-proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -0,0 +1,22 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: gitea-config
|
||||||
|
namespace: gitea
|
||||||
|
data:
|
||||||
|
GITEA__server__DOMAIN: "gitea.forust.xyz"
|
||||||
|
GITEA__server__ROOT_URL: "https://gitea.forust.xyz"
|
||||||
|
GITEA__server__SSH_DOMAIN: "gitssh.forust.xyz"
|
||||||
|
GITEA__server__SSH_PORT: "2221"
|
||||||
|
|
||||||
|
GITEA__database__DB_TYPE: "postgres"
|
||||||
|
GITEA__database__HOST: "gitea-postgres-service:5432"
|
||||||
|
GITEA__database__NAME: "gitea"
|
||||||
|
GITEA__security__REVERSE_PROXY_LIMIT: "1"
|
||||||
|
GITEA__security__REVERSE_PROXY_TRUSTED_PROXIES: "*"
|
||||||
|
|
||||||
|
GITEA__mailer__ENABLED: "false"
|
||||||
|
|
||||||
|
GITEA__log__logger__access__MODE: "console, file"
|
||||||
|
USER_UID: "1000"
|
||||||
|
USER_GID: "1000"
|
||||||
@@ -0,0 +1,71 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: gitea-service
|
||||||
|
namespace: gitea
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: gitea
|
||||||
|
ports:
|
||||||
|
- port: 3000
|
||||||
|
name: http
|
||||||
|
targetPort: 3000
|
||||||
|
- port: 2221
|
||||||
|
name: ssh
|
||||||
|
targetPort: 22
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: gitea-deployment
|
||||||
|
namespace: gitea
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: gitea
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: gitea
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: gitea
|
||||||
|
image: docker.gitea.com/gitea:1.26
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: gitea-config
|
||||||
|
- secretRef:
|
||||||
|
name: gitea-secrets
|
||||||
|
ports:
|
||||||
|
- containerPort: 3000
|
||||||
|
name: http
|
||||||
|
- containerPort: 2221
|
||||||
|
name: ssh
|
||||||
|
volumeMounts:
|
||||||
|
- name: gitea-data
|
||||||
|
mountPath: /data
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "512Mi"
|
||||||
|
cpu: "300m"
|
||||||
|
limits:
|
||||||
|
memory: "1.5Gi"
|
||||||
|
cpu: "1300m"
|
||||||
|
volumes:
|
||||||
|
- name: gitea-data
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: gitea-pvc
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: PersistentVolumeClaim
|
||||||
|
metadata:
|
||||||
|
name: gitea-pvc
|
||||||
|
namespace: gitea
|
||||||
|
spec:
|
||||||
|
accessModes:
|
||||||
|
- ReadWriteOnce
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 5Gi
|
||||||
|
---
|
||||||
@@ -0,0 +1,57 @@
|
|||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: gitea-prod
|
||||||
|
namespace: gitea
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: Host(`gitea.forust.xyz`)
|
||||||
|
kind: Rule
|
||||||
|
middlewares:
|
||||||
|
services:
|
||||||
|
- name: gitea-service
|
||||||
|
port: 3000
|
||||||
|
- match: Host(`gcr.forust.xyz`) && PathPrefix(`/v2`)
|
||||||
|
kind: Rule
|
||||||
|
middlewares:
|
||||||
|
services:
|
||||||
|
- name: gitea-service
|
||||||
|
port: 3000
|
||||||
|
tls:
|
||||||
|
certResolver: letsencrypt
|
||||||
|
---
|
||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: gitea-local
|
||||||
|
namespace: gitea
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: Host(`gitea.workstation.internal`) || Host(`gitea.gigaforust.internal`)
|
||||||
|
kind: Rule
|
||||||
|
services:
|
||||||
|
- name: gitea-service
|
||||||
|
port: 3000
|
||||||
|
- match: (Host(`gcr.workstation.internal`) || Host(`gcr.gigaforust.internal`)) && PathPrefix(`/v2`)
|
||||||
|
kind: Rule
|
||||||
|
services:
|
||||||
|
- name: gitea-service
|
||||||
|
port: 3000
|
||||||
|
---
|
||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRouteTCP
|
||||||
|
metadata:
|
||||||
|
name: gitea-ssh
|
||||||
|
namespace: gitea
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- ssh
|
||||||
|
routes:
|
||||||
|
- match: HostSNI(`*`)
|
||||||
|
services:
|
||||||
|
- name: gitea-service
|
||||||
|
port: 2221
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: gitea
|
||||||
@@ -0,0 +1,62 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: gitea-postgres-service
|
||||||
|
namespace: gitea
|
||||||
|
spec:
|
||||||
|
clusterIP: None
|
||||||
|
selector:
|
||||||
|
app: gitea-postgres
|
||||||
|
ports:
|
||||||
|
- port: 5432
|
||||||
|
targetPort: 5432
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: StatefulSet
|
||||||
|
metadata:
|
||||||
|
name: gitea-postgres-statefulset
|
||||||
|
namespace: gitea
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: gitea-postgres
|
||||||
|
serviceName: gitea-postgres-service
|
||||||
|
replicas: 1
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: gitea-postgres
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: gitea-postgres
|
||||||
|
image: postgres:14
|
||||||
|
env:
|
||||||
|
- name: POSTGRES_USER
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: gitea-secrets
|
||||||
|
key: GITEA__database__USER
|
||||||
|
- name: POSTGRES_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: gitea-secrets
|
||||||
|
key: GITEA__database__PASSWD
|
||||||
|
- name: POSTGRES_DB
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: gitea-secrets
|
||||||
|
key: GITEA__database__USER
|
||||||
|
ports:
|
||||||
|
- containerPort: 5432
|
||||||
|
name: postgres
|
||||||
|
volumeMounts:
|
||||||
|
- name: postgres-data
|
||||||
|
mountPath: /var/lib/postgresql/data
|
||||||
|
volumeClaimTemplates:
|
||||||
|
- metadata:
|
||||||
|
name: postgres-data
|
||||||
|
spec:
|
||||||
|
accessModes: ["ReadWriteOnce"]
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
storage: 1Gi
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: gitea-secrets
|
||||||
|
namespace: gitea
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
GITEA__database__USER: "gitea"
|
||||||
|
GITEA__database__PASSWD: "gitea"
|
||||||
+22
-8
@@ -10,13 +10,27 @@ services:
|
|||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
env_file: .env
|
env_file: .env
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=traefik-proxy"
|
- "traefik.docker.network=proxy"
|
||||||
|
- "traefik.services.glance.loadbalancer.server.port=8080"
|
||||||
|
|
||||||
|
# Prod Router
|
||||||
|
- "traefik.http.routers.glance.rule=(Host(`forust.xyz`) || Host(`www.forust.xyz`)) && PathPrefix(`/glance`)"
|
||||||
|
- "traefik.http.routers.glance.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.glance.priority=50"
|
||||||
|
- "traefik.http.routers.glance.tls.certresolver=letsencrypt"
|
||||||
|
# Local Router
|
||||||
|
- "traefik.http.routers.glance-local.rule=Host(`workstation.internal`) && PathPrefix(`/glance`)"
|
||||||
|
- "traefik.http.routers.glance-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.glance-local.priority=50"
|
||||||
|
- "traefik.http.routers.glance-local.tls=true"
|
||||||
|
# Dev Router
|
||||||
|
- "traefik.http.routers.glance-dev.rule=Host(`gigaforust.internal`) && PathPrefix(`/glance`)"
|
||||||
|
- "traefik.http.routers.glance-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.glance-dev.priority=50"
|
||||||
|
- "traefik.http.routers.glance-dev.tls=true"
|
||||||
networks:
|
networks:
|
||||||
- traefik-proxy
|
- proxy
|
||||||
dns:
|
|
||||||
- 1.1.1.1
|
|
||||||
- 8.8.8.8
|
|
||||||
networks:
|
networks:
|
||||||
traefik-proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -64,7 +64,6 @@
|
|||||||
name: Apple
|
name: Apple
|
||||||
- symbol: MSFT
|
- symbol: MSFT
|
||||||
name: Microsoft
|
name: Microsoft
|
||||||
|
|
||||||
|
|
||||||
- type: releases
|
- type: releases
|
||||||
cache: 1d
|
cache: 1d
|
||||||
|
|||||||
+11
-13
@@ -1,15 +1,13 @@
|
|||||||
- name: Monitoring
|
- name: Monitoring
|
||||||
columns:
|
columns:
|
||||||
- size: small
|
- size: small
|
||||||
widgets:
|
widgets:
|
||||||
- type: dns-stats
|
- type: dns-stats
|
||||||
service: adguard
|
service: adguard
|
||||||
url: http://adguardhome:3000
|
url: http://adguardhome:3000
|
||||||
username: forust
|
username: forust
|
||||||
password: ${ADGUARD_PASSWORD}
|
password: ${ADGUARD_PASSWORD}
|
||||||
- size: full
|
- size: full
|
||||||
widgets:
|
widgets:
|
||||||
- type: docker-containers
|
- type: docker-containers
|
||||||
hide-by-default: false
|
hide-by-default: false
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,211 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: glance-assets
|
||||||
|
namespace: glance
|
||||||
|
data:
|
||||||
|
# Инжектируем твой брутализм напрямую в ассеты
|
||||||
|
user.css: |
|
||||||
|
:root {
|
||||||
|
--bg-color: #050505;
|
||||||
|
--text-color: #e0e0e0;
|
||||||
|
--accent: #ffffff;
|
||||||
|
--dim: #666666;
|
||||||
|
--font-mono: 'Courier New', Courier, monospace;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Принудительно ставим моноширинный шрифт для всего дашборда */
|
||||||
|
body, id, main, div, span, p, a, h1, h2, h3 {
|
||||||
|
font-family: var(--font-mono) !important;
|
||||||
|
letter-spacing: -0.5px;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Ломаем закругления Glance и делаем жесткие рамки */
|
||||||
|
.widget, .card, main div, [class*="widget"], [class*="card"] {
|
||||||
|
border-radius: 0px !important;
|
||||||
|
border: 1px solid var(--dim) !important;
|
||||||
|
box-shadow: none !important;
|
||||||
|
background-color: var(--bg-color) !important;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Стилизация ссылок под ховер-эффект из твоего style.css */
|
||||||
|
a {
|
||||||
|
color: var(--text-color) !important;
|
||||||
|
text-decoration: none !important;
|
||||||
|
border-bottom: 1px solid var(--dim) !important;
|
||||||
|
transition: all 0.2s;
|
||||||
|
}
|
||||||
|
a:hover {
|
||||||
|
background-color: var(--text-color) !important;
|
||||||
|
color: var(--bg-color) !important;
|
||||||
|
border-color: var(--text-color) !important;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Кастомизация заголовков внутри модулей */
|
||||||
|
h2, .widget-title, [class*="title"] {
|
||||||
|
text-transform: uppercase;
|
||||||
|
font-weight: bold;
|
||||||
|
}
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: glance-config
|
||||||
|
namespace: glance
|
||||||
|
data:
|
||||||
|
glance.yml: |
|
||||||
|
server:
|
||||||
|
assets-path: /app/assets
|
||||||
|
proxied: true
|
||||||
|
base-url: /glance
|
||||||
|
theme:
|
||||||
|
# Перевели #050505 и #e0e0e0 в формат HSL для Glance
|
||||||
|
background-color: 0 0 2 # Истинно черный фон
|
||||||
|
primary-color: 0 0 88 # Светло-серый текст
|
||||||
|
contrast-multiplier: 1.4
|
||||||
|
positive-color: 140 50 50 # Зеленый для UP-сервисов (не вырвиглазный)
|
||||||
|
negative-color: 0 70 50 # Красный для упавших сайтов
|
||||||
|
custom-css-file: /assets/user.css
|
||||||
|
pages:
|
||||||
|
- $include: home.yml
|
||||||
|
- $include: docker.yml
|
||||||
|
- $include: monitor.yml
|
||||||
|
|
||||||
|
home.yml: |
|
||||||
|
- name: Home
|
||||||
|
columns:
|
||||||
|
- size: small
|
||||||
|
widgets:
|
||||||
|
- type: clock
|
||||||
|
hour-format: 24h
|
||||||
|
timezones:
|
||||||
|
- timezone: Europe/Bratislava
|
||||||
|
label: Bratislava
|
||||||
|
- timezone: Europe/Kyiv
|
||||||
|
label: Kyiv
|
||||||
|
- timezone: Europe/Moscow
|
||||||
|
label: St. Petersburg
|
||||||
|
- type: calendar
|
||||||
|
first-day-of-week: monday
|
||||||
|
- type: rss
|
||||||
|
limit: 10
|
||||||
|
collapse-after: 3
|
||||||
|
cache: 12h
|
||||||
|
feeds:
|
||||||
|
- url: https://selfh.st/rss/
|
||||||
|
title: selfh.st
|
||||||
|
- size: full
|
||||||
|
widgets:
|
||||||
|
- type: group
|
||||||
|
widgets:
|
||||||
|
- type: hacker-news
|
||||||
|
- type: lobsters
|
||||||
|
- type: videos
|
||||||
|
channels:
|
||||||
|
- UCXuqSBlHAE6Xw-yeJA0Tunw
|
||||||
|
- UCR-DXc1voovS8nhAvccRZhg
|
||||||
|
- UCsBjURrPoezykLs9EqgamOA
|
||||||
|
- UCBJycsmduvYEL83R_U4JriQ
|
||||||
|
- UCHnyfMqiRRG1u-2MsSQLbXA
|
||||||
|
- type: group
|
||||||
|
widgets:
|
||||||
|
- type: reddit
|
||||||
|
subreddit: technology
|
||||||
|
show-thumbnails: true
|
||||||
|
- type: reddit
|
||||||
|
subreddit: selfhosted
|
||||||
|
show-thumbnails: true
|
||||||
|
- size: small
|
||||||
|
widgets:
|
||||||
|
- type: weather
|
||||||
|
location: London, United Kingdom
|
||||||
|
units: metric
|
||||||
|
hour-format: 12h
|
||||||
|
hide-location: true
|
||||||
|
- type: markets
|
||||||
|
markets:
|
||||||
|
- symbol: SPY
|
||||||
|
name: S&P 500
|
||||||
|
- symbol: BTC-USD
|
||||||
|
name: Bitcoin
|
||||||
|
- symbol: NVDA
|
||||||
|
name: NVIDIA
|
||||||
|
- symbol: AAPL
|
||||||
|
name: Apple
|
||||||
|
- symbol: MSFT
|
||||||
|
name: Microsoft
|
||||||
|
- type: releases
|
||||||
|
cache: 1d
|
||||||
|
repositories:
|
||||||
|
- glanceapp/glance
|
||||||
|
- go-gitea/gitea
|
||||||
|
- nextcloud/all-in-one
|
||||||
|
|
||||||
|
docker.yml: |
|
||||||
|
- name: Docker
|
||||||
|
columns:
|
||||||
|
- size: full
|
||||||
|
widgets:
|
||||||
|
- type: docker-containers
|
||||||
|
hide-by-default: false
|
||||||
|
|
||||||
|
monitor.yml: |
|
||||||
|
- name: Monitoring
|
||||||
|
columns:
|
||||||
|
- size: small
|
||||||
|
widgets:
|
||||||
|
- type: dns-stats
|
||||||
|
service: adguard
|
||||||
|
url: http://adguard-service.adguard.svc.cluster.local:3000
|
||||||
|
username: forust
|
||||||
|
password: ${ADGUARD_PASSWORD}
|
||||||
|
- size: full
|
||||||
|
widgets:
|
||||||
|
- type: monitor
|
||||||
|
title: Services Status
|
||||||
|
cache: 1m
|
||||||
|
sites:
|
||||||
|
- title: forust.xyz
|
||||||
|
url: https://forust.xyz
|
||||||
|
- title: dns.forust.xyz
|
||||||
|
url: https://dns.forust.xyz
|
||||||
|
- title: www.lk-tour.com.ua
|
||||||
|
url: https://www.lk-tour.com.ua
|
||||||
|
- title: lk-tour.com.ua
|
||||||
|
url: https://lk-tour.com.ua
|
||||||
|
# - title: gitssh.forust.xyz
|
||||||
|
# url: https://gitssh.forust.xyz
|
||||||
|
# - title: gcr.forust.xyz
|
||||||
|
# url: https://gcr.forust.xyz/v2/
|
||||||
|
- title: gitea.forust.xyz
|
||||||
|
url: https://gitea.forust.xyz
|
||||||
|
- title: nextcloud.forust.xyz
|
||||||
|
url: https://nextcloud.forust.xyz
|
||||||
|
- title: mc.forust.xyz
|
||||||
|
url: https://mc.forust.xyz/map
|
||||||
|
- title: auth.forust.xyz
|
||||||
|
url: https://auth.forust.xyz
|
||||||
|
- title: metube.forust.xyz
|
||||||
|
url: https://metube.forust.xyz
|
||||||
|
- title: dockmon.forust.xyz
|
||||||
|
url: https://dockmon.forust.xyz
|
||||||
|
- title: portainer.forust.xyz
|
||||||
|
url: https://portainer.forust.xyz
|
||||||
|
- title: termix.forust.xyz
|
||||||
|
url: https://termix.forust.xyz
|
||||||
|
- title: uptime.forust.xyz
|
||||||
|
url: https://uptime.forust.xyz
|
||||||
|
- title: cmk.forust.xyz
|
||||||
|
url: https://cmk.forust.xyz
|
||||||
|
- title: search.forust.xyz
|
||||||
|
url: https://search.forust.xyz
|
||||||
|
- title: status.forust.xyz
|
||||||
|
url: https://status.forust.xyz
|
||||||
|
- title: traefik.forust.xyz
|
||||||
|
url: https://traefik.forust.xyz
|
||||||
|
- title: media.forust.xyz
|
||||||
|
url: https://media.forust.xyz
|
||||||
|
- title: wfs.forust.xyz
|
||||||
|
url: https://wfs.forust.xyz
|
||||||
|
- title: forust.xyz/convert
|
||||||
|
url: https://forust.xyz/convert
|
||||||
@@ -0,0 +1,78 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: glance-service
|
||||||
|
namespace: glance
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: glance
|
||||||
|
ports:
|
||||||
|
- port: 8080
|
||||||
|
targetPort: 8080
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: glance-deployment
|
||||||
|
namespace: glance
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: glance
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: glance
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: glance
|
||||||
|
image: glanceapp/glance
|
||||||
|
envFrom:
|
||||||
|
- secretRef:
|
||||||
|
name: glance-secrets
|
||||||
|
ports:
|
||||||
|
- containerPort: 8080
|
||||||
|
volumeMounts:
|
||||||
|
- name: glance-config
|
||||||
|
mountPath: /app/config/glance.yml
|
||||||
|
subPath: glance.yml
|
||||||
|
- name: glance-config
|
||||||
|
mountPath: /app/config/home.yml
|
||||||
|
subPath: home.yml
|
||||||
|
- name: glance-config
|
||||||
|
mountPath: /app/config/docker.yml
|
||||||
|
subPath: docker.yml
|
||||||
|
- name: glance-config
|
||||||
|
mountPath: /app/config/monitor.yml
|
||||||
|
subPath: monitor.yml
|
||||||
|
- name: glance-assets
|
||||||
|
mountPath: /app/assets/user.css
|
||||||
|
subPath: user.css
|
||||||
|
- name: docker-socket
|
||||||
|
mountPath: /var/run/docker.sock
|
||||||
|
- name: localtime
|
||||||
|
mountPath: /etc/localtime
|
||||||
|
readOnly: true
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "30Mi"
|
||||||
|
cpu: "20m"
|
||||||
|
limits:
|
||||||
|
memory: "100Mi"
|
||||||
|
cpu: "50m"
|
||||||
|
volumes:
|
||||||
|
- name: glance-config
|
||||||
|
configMap:
|
||||||
|
name: glance-config
|
||||||
|
- name: glance-assets
|
||||||
|
configMap:
|
||||||
|
name: glance-config
|
||||||
|
- name: docker-socket
|
||||||
|
hostPath:
|
||||||
|
path: /var/run/docker.sock
|
||||||
|
type: Socket
|
||||||
|
- name: localtime
|
||||||
|
hostPath:
|
||||||
|
path: /etc/localtime
|
||||||
|
type: File
|
||||||
@@ -0,0 +1,47 @@
|
|||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: glance-prod
|
||||||
|
namespace: glance
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: (Host(`forust.xyz`) || Host(`www.forust.xyz`)) && PathPrefix(`/glance`)
|
||||||
|
kind: Rule
|
||||||
|
priority: 50
|
||||||
|
middlewares:
|
||||||
|
- name: glance-stripprefix
|
||||||
|
services:
|
||||||
|
- name: glance-service
|
||||||
|
port: 8080
|
||||||
|
tls:
|
||||||
|
certResolver: letsencrypt
|
||||||
|
---
|
||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: IngressRoute
|
||||||
|
metadata:
|
||||||
|
name: glance-local
|
||||||
|
namespace: glance
|
||||||
|
spec:
|
||||||
|
entryPoints:
|
||||||
|
- websecure
|
||||||
|
routes:
|
||||||
|
- match: (Host(`glance.workstation.internal`) || Host(`glance.gigaforust.internal`)) && PathPrefix(`/glance`)
|
||||||
|
kind: Rule
|
||||||
|
middlewares:
|
||||||
|
- name: glance-stripprefix
|
||||||
|
priority: 50
|
||||||
|
services:
|
||||||
|
- name: glance-service
|
||||||
|
port: 8080
|
||||||
|
---
|
||||||
|
apiVersion: traefik.io/v1alpha1
|
||||||
|
kind: Middleware
|
||||||
|
metadata:
|
||||||
|
name: glance-stripprefix
|
||||||
|
namespace: glance
|
||||||
|
spec:
|
||||||
|
stripPrefix:
|
||||||
|
prefixes:
|
||||||
|
- /glance
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: glance
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user