Compare commits
15 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
3be9556eb4
|
|||
|
e952c8161a
|
|||
|
8d665a7f34
|
|||
|
6e4f8c06b4
|
|||
| 8cd122d50d | |||
| f531393481 | |||
| ce43b34ce0 | |||
| ddb755e7e5 | |||
| 682a5b949f | |||
| 6c72acc59e | |||
| b381c7b012 | |||
| a3c12855fe | |||
| bbd374590e | |||
| fd72b415c5 | |||
| 97f6aeb538 |
@@ -1,39 +0,0 @@
|
|||||||
name: Deploy to Server
|
|
||||||
run-name: Deploying to ${{ runner.os}} server on ${{ gitea.ref }}
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- main
|
|
||||||
- ci/gitea-actions
|
|
||||||
jobs:
|
|
||||||
deploy:
|
|
||||||
runs-on: prod
|
|
||||||
steps:
|
|
||||||
- name: Fetch and Diff Analysis
|
|
||||||
id: diff
|
|
||||||
run: |
|
|
||||||
cd ${{ secrets.PROD_DIR }}
|
|
||||||
git fetch origin main
|
|
||||||
CHANGES=$(git diff --name-only HEAD origin/main | cut -d/ -f1 | sort -u | tr '\n' ' ')
|
|
||||||
echo "dirs=$CHANGES" >> $GITHUB_OUTPUT
|
|
||||||
echo "Changed dirs: $CHANGES"
|
|
||||||
|
|
||||||
- name: Sync Server Files
|
|
||||||
run: |
|
|
||||||
cd ${{ secrets.PROD_DIR }}
|
|
||||||
git reset --hard origin/main
|
|
||||||
echo "Server files synced with origin/main"
|
|
||||||
|
|
||||||
- name: Deploy Services
|
|
||||||
run: |
|
|
||||||
cd ${{ secrets.PROD_DIR }}
|
|
||||||
for dir in ${{ steps.diff.outputs.dirs }}; do
|
|
||||||
if [ -d "$dir" ] && ([ -f "$dir/compose.yaml" ] || [ -f "$dir/docker-compose.yaml" ]); then
|
|
||||||
echo ">>> Deploying $dir"
|
|
||||||
cd "$dir"
|
|
||||||
DOCKER_BUILDKIT=1 BUILDKIT_PROGRESS=plain docker compose up -d --build --no-color
|
|
||||||
cd ..
|
|
||||||
else
|
|
||||||
echo ">>> Skipping $dir: no compose file found"
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
@@ -1,41 +0,0 @@
|
|||||||
## BINARY MODE, USE WITH THE GITHUB RUNNER BINARY INSTALLED ON THE SERVER
|
|
||||||
|
|
||||||
name: Deploy to Server
|
|
||||||
run-name: Deploying onto server on ${{ github.ref }}
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- main
|
|
||||||
- ci/actions
|
|
||||||
jobs:
|
|
||||||
deploy:
|
|
||||||
runs-on: [prod, self-hosted]
|
|
||||||
steps:
|
|
||||||
- name: Fetch and Diff Analysis
|
|
||||||
id: diff
|
|
||||||
run: |
|
|
||||||
cd ${{ secrets.PROD_DIR }}
|
|
||||||
git fetch origin main
|
|
||||||
CHANGES=$(git diff --name-only HEAD origin/main | cut -d/ -f1 | sort -u | tr '\n' ' ')
|
|
||||||
echo "dirs=$CHANGES" >> $GITHUB_OUTPUT
|
|
||||||
echo "Changed dirs: $CHANGES"
|
|
||||||
|
|
||||||
- name: Sync Server Files
|
|
||||||
run: |
|
|
||||||
cd ${{ secrets.PROD_DIR }}
|
|
||||||
git reset --hard origin/main
|
|
||||||
echo "Server files synced with origin/main"
|
|
||||||
|
|
||||||
- name: Deploy Services
|
|
||||||
run: |
|
|
||||||
cd ${{ secrets.PROD_DIR }}
|
|
||||||
for dir in ${{ steps.diff.outputs.dirs }}; do
|
|
||||||
if [ -d "$dir" ] && ([ -f "$dir/compose.yaml" ] || [ -f "$dir/docker-compose.yaml" ]); then
|
|
||||||
echo ">>> Deploying $dir"
|
|
||||||
cd "$dir"
|
|
||||||
DOCKER_BUILDKIT=1 BUILDKIT_PROGRESS=plain docker compose up -d --build --no-color
|
|
||||||
cd ..
|
|
||||||
else
|
|
||||||
echo ">>> Skipping $dir: no compose file found"
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
@@ -5,12 +5,12 @@ sync.ffs_lock
|
|||||||
# Copyparty
|
# Copyparty
|
||||||
*.hist/
|
*.hist/
|
||||||
|
|
||||||
# Volumes, configs and data directories
|
# Volumes and data directories
|
||||||
gitea/gitea-db/
|
gitea/gitea-db/
|
||||||
gitea/gitea-data/*
|
gitea/gitea-data/*
|
||||||
n8n/n8n-data/*
|
n8n/n8n-data/*
|
||||||
n8n/n8n-node-data/*
|
n8n/n8n-node-data/*
|
||||||
adguardhome/conf/*
|
adguardhome/data/*
|
||||||
dockmon/data/*
|
dockmon/data/*
|
||||||
portainer/portainer_data/*
|
portainer/portainer_data/*
|
||||||
metube/MeTube_downloads
|
metube/MeTube_downloads
|
||||||
@@ -21,7 +21,9 @@ checkmk/checkmk/*
|
|||||||
downtify/Downtify_downloads
|
downtify/Downtify_downloads
|
||||||
headscale/config/*
|
headscale/config/*
|
||||||
headscale/data/*
|
headscale/data/*
|
||||||
searxng/core-config/settings.yml
|
|
||||||
|
# Steaming services files
|
||||||
|
streaming/config/*
|
||||||
|
|
||||||
# Steaming services files
|
# Steaming services files
|
||||||
streaming/jellyfin/*
|
streaming/jellyfin/*
|
||||||
@@ -33,15 +35,12 @@ streaming/qbittorrent/*
|
|||||||
streaming/prowlarr/*
|
streaming/prowlarr/*
|
||||||
|
|
||||||
# Homepage
|
# Homepage
|
||||||
|
homepages/forust_files/assets/images/team/*
|
||||||
homepages/forust_files/.well-known/*
|
homepages/forust_files/.well-known/*
|
||||||
|
|
||||||
# Traefik files
|
# Traefik files
|
||||||
traefik/letsencrypt/acme.json
|
traefik/letsencrypt/acme.json
|
||||||
traefik/dynamic/fileservers.yml
|
traefik/dynamic/fileservers.yml
|
||||||
traefik/dynamic/*.local.y*ml.*
|
|
||||||
traefik/dynamic/*.external.y*ml
|
|
||||||
|
|
||||||
|
|
||||||
traefik/logs/*
|
traefik/logs/*
|
||||||
|
|
||||||
# SSL Certificates
|
# SSL Certificates
|
||||||
@@ -81,8 +80,6 @@ replacements.txt
|
|||||||
|
|
||||||
# Git
|
# Git
|
||||||
.gitattributes
|
.gitattributes
|
||||||
# Gitea/github Runners
|
|
||||||
.runner
|
|
||||||
|
|
||||||
# Misc
|
# Misc
|
||||||
.DS_Store
|
.DS_Store
|
||||||
@@ -97,4 +94,4 @@ temp/*
|
|||||||
.env.anna
|
.env.anna
|
||||||
.env.forust
|
.env.forust
|
||||||
.env.*
|
.env.*
|
||||||
!*example
|
!*example
|
||||||
@@ -11,38 +11,46 @@ services:
|
|||||||
# - "68:68/tcp" # DHCP
|
# - "68:68/tcp" # DHCP
|
||||||
# - "3000:3000/tcp"
|
# - "3000:3000/tcp"
|
||||||
volumes:
|
volumes:
|
||||||
- data:/opt/adguardhome/work
|
- ./data/work:/opt/adguardhome/work
|
||||||
- ./conf:/opt/adguardhome/conf
|
- ./data/conf:/opt/adguardhome/conf
|
||||||
- ./certs:/certs:ro
|
- ./certs:/certs:ro
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
|
- "traefik.docker.network=proxy"
|
||||||
- "traefik.http.services.adguard.loadbalancer.server.port=3000"
|
- "traefik.http.services.adguard.loadbalancer.server.port=3000"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.adguard.rule=Host(`dns.forust.xyz`) || Host(`adguard.forust.xyz`)"
|
- "traefik.http.routers.adguard.rule=Host(`dns.forust.xyz`) || Host(`adguard.forust.xyz`)"
|
||||||
- "traefik.http.routers.adguard.entrypoints=websecure"
|
- "traefik.http.routers.adguard.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.adguard.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.adguard.service=adguard"
|
||||||
- "traefik.http.routers.adguard.tls=true"
|
- "traefik.http.routers.adguard.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.adguard-local.rule=Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`)"
|
- "traefik.http.routers.adguard-local.rule=Host(`dns.workstation.internal`) || Host(`adguard.internal`) || Host(`adguard.workstation.internal`)"
|
||||||
- "traefik.http.routers.adguard-local.entrypoints=websecure"
|
- "traefik.http.routers.adguard-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.adguard-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.adguard-local.service=adguard"
|
||||||
- "traefik.http.routers.adguard-local.tls=true"
|
- "traefik.http.routers.adguard-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.adguard-dev.rule=Host(`adguard.gigaforust.internal`) || Host(`dns.gigaforust.internal`)"
|
- "traefik.http.routers.adguard-dev.rule=Host(`dns.gigaforust.internal`) || Host(`adguard.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.adguard-dev.entrypoints=websecure"
|
- "traefik.http.routers.adguard-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.adguard-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.adguard-dev.service=adguard"
|
||||||
- "traefik.http.routers.adguard-dev.tls=true"
|
- "traefik.http.routers.adguard-dev.tls=true"
|
||||||
# DoH Router
|
|
||||||
|
# DoH
|
||||||
- "traefik.http.routers.dns.rule=(Host(`dns.forust.xyz`) && PathPrefix(`/dns-query`))"
|
- "traefik.http.routers.dns.rule=(Host(`dns.forust.xyz`) && PathPrefix(`/dns-query`))"
|
||||||
- "traefik.http.routers.dns.entrypoints=websecure"
|
- "traefik.http.routers.dns.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.dns.service=adguard"
|
||||||
- "traefik.http.routers.dns.tls.certresolver=letsencrypt"
|
- "traefik.http.routers.dns.tls.certresolver=letsencrypt"
|
||||||
|
|
||||||
# Glance Metadata
|
|
||||||
- glance.name=adguard
|
- glance.name=adguard
|
||||||
- glance.url=https://adguard.forust.xyz/
|
- glance.url=https://adguard.forust.xyz/
|
||||||
- glance.description=AdGuard Home is a network-wide software for blocking ads.
|
- glance.description=AdGuard Home is a network-wide software for blocking ads.
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
volumes:
|
|
||||||
data:
|
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -37,26 +37,37 @@ services:
|
|||||||
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
|
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
|
||||||
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
|
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
|
||||||
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
||||||
volumes:
|
|
||||||
- ./media:/media
|
|
||||||
- ./custom-templates:/templates
|
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
|
- "traefik.docker.network=proxy"
|
||||||
|
# Services
|
||||||
|
# - "traefik.http.services.authentik-server.loadbalancer.server.port=9443"
|
||||||
- "traefik.http.services.authentik-server.loadbalancer.server.port=9000"
|
- "traefik.http.services.authentik-server.loadbalancer.server.port=9000"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.authentik-server.rule=Host(`auth.forust.xyz`)"
|
- "traefik.http.routers.authentik-server.rule=Host(`auth.forust.xyz`)"
|
||||||
- "traefik.http.routers.authentik-server.entrypoints=websecure"
|
- "traefik.http.routers.authentik-server.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.authentik-server.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.authentik-server.service=authentik-server"
|
||||||
- "traefik.http.routers.authentik-server.tls=true"
|
- "traefik.http.routers.authentik-server.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.authentik-server-local.rule=Host(`auth.workstation.internal`)"
|
- "traefik.http.routers.authentik-server-local.rule=Host(`auth.workstation.internal`) || Host(`auth-dashboard.internal`)"
|
||||||
- "traefik.http.routers.authentik-server-local.entrypoints=websecure"
|
- "traefik.http.routers.authentik-server-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.authentik-server-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.authentik-server-local.service=authentik-server"
|
||||||
- "traefik.http.routers.authentik-server-local.tls=true"
|
- "traefik.http.routers.authentik-server-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.authentik-server-dev.rule=Host(`auth.gigaforust.internal`)"
|
- "traefik.http.routers.authentik-server-dev.rule=Host(`auth.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.authentik-server-dev.entrypoints=websecure"
|
- "traefik.http.routers.authentik-server-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.authentik-server-dev.middlewares=security-headers@file"
|
- "traefik.http.routers.authentik-server-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.authentik-server-dev.service=authentik-server"
|
||||||
- "traefik.http.routers.authentik-server-dev.tls=true"
|
- "traefik.http.routers.authentik-server-dev.tls=true"
|
||||||
|
volumes:
|
||||||
|
- ./media:/media
|
||||||
|
- ./custom-templates:/templates
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
- authentik
|
- authentik
|
||||||
|
|||||||
@@ -1,15 +0,0 @@
|
|||||||
CLOUDFLARE_API_TOKEN=YOUR_CLOUDFLARE_API_TOKEN
|
|
||||||
DOMAINS=example.com,dns.example.com,mc.example.com,auth.example.com,ssh.example.com
|
|
||||||
IP4_DOMAINS=
|
|
||||||
IP6_DOMAINS=
|
|
||||||
IP4_PROVIDER=cloudflare.trace
|
|
||||||
IP6_PROVIDER=none # change if you want to update AAAA
|
|
||||||
UPDATE_CRON=@every 5m
|
|
||||||
UPDATE_ON_START=true
|
|
||||||
DELETE_ON_STOP=false
|
|
||||||
DELETE_ON_FAILURE=true
|
|
||||||
TTL=1
|
|
||||||
PROXIED=!is(dns.example.com) && !is(mc.example.com) && !is(ssh.example.com)
|
|
||||||
EMOJI=true
|
|
||||||
UPTIMEKUMA=https://uptime-kuma.example.com/api/push/AsaSDFGFkfklaFALSKffkfFKfkfkfkFK?status=up&msg=OK&ping=
|
|
||||||
REJECT_CLOUDFLARE_IPS=true
|
|
||||||
@@ -2,29 +2,12 @@ services:
|
|||||||
cloudflare-ddns:
|
cloudflare-ddns:
|
||||||
image: timothyjmiller/cloudflare-ddns:latest
|
image: timothyjmiller/cloudflare-ddns:latest
|
||||||
container_name: cloudflare-ddns
|
container_name: cloudflare-ddns
|
||||||
restart: unless-stopped
|
|
||||||
security_opt:
|
security_opt:
|
||||||
- no-new-privileges:true
|
- no-new-privileges:true
|
||||||
network_mode: 'host'
|
network_mode: 'host'
|
||||||
# https://github.com/timothymiller/cloudflare-ddns#-quick-start
|
|
||||||
environment:
|
environment:
|
||||||
- CLOUDFLARE_API_TOKEN=${CLOUDFLARE_API_TOKEN:?Cloudflare API token is required}
|
- PUID=1000
|
||||||
- DOMAINS=${DOMAINS:-}
|
- PGID=1000
|
||||||
- IP4_DOMAINS=${IP4_DOMAINS:-}
|
volumes:
|
||||||
- IP6_DOMAINS=${IP6_DOMAINS:-}
|
- ./config.json:/config.json
|
||||||
- IP4_PROVIDER=${IP4_PROVIDER:-cloudflare.trace}
|
restart: unless-stopped
|
||||||
- IP6_PROVIDER=${IP6_PROVIDER:-none}
|
|
||||||
- UPDATE_CRON=${UPDATE_CRON:-@every 5m}
|
|
||||||
- UPDATE_ON_START=${UPDATE_ON_START:-true}
|
|
||||||
- DELETE_ON_STOP=${DELETE_ON_STOP:-false}
|
|
||||||
- DELETE_ON_FAILURE=${DELETE_ON_FAILURE:-true}
|
|
||||||
- TTL=${TTL:-1} # 1=auto
|
|
||||||
# to proxy only "dns.example.com" and "wfs.example.com" use "!is(dns.domain.com) && !is (wfs.domain.com)"
|
|
||||||
- PROXIED=${PROXIED:-true}
|
|
||||||
- EMOJI=${EMOJI:-true}
|
|
||||||
- UPTIMEKUMA=${UPTIMEKUMA:-}
|
|
||||||
- HEALTHCHECKS=${HEALTHCHECKS:-}
|
|
||||||
- REJECT_CLOUDFLARE_IPS=${REJECT_CLOUDFLARE_IPS:-true}
|
|
||||||
# volumes:
|
|
||||||
# Prefer using environment variables for configuration, config.json legacy support
|
|
||||||
# - ./config.json:/config.json
|
|
||||||
|
|||||||
@@ -2,36 +2,47 @@ services:
|
|||||||
checkmk:
|
checkmk:
|
||||||
image: "checkmk/check-mk-raw:2.4.0-latest"
|
image: "checkmk/check-mk-raw:2.4.0-latest"
|
||||||
container_name: "checkmk"
|
container_name: "checkmk"
|
||||||
restart: unless-stopped
|
environment:
|
||||||
# ports:
|
- CMK_PASSWORD=${CMK_PASSWORD:-password}
|
||||||
# - 5000:5000
|
- CMK_SITE_ID=cmk
|
||||||
# - 6776:8000
|
|
||||||
volumes:
|
volumes:
|
||||||
- sites:/omd/sites
|
- sites:/omd/sites
|
||||||
tmpfs:
|
tmpfs:
|
||||||
- /opt/omd/sites/cmk/tmp:uid=1000,gid=1000
|
- /opt/omd/sites/cmk/tmp:uid=1000,gid=1000
|
||||||
environment:
|
ports:
|
||||||
- CMK_PASSWORD=${CMK_PASSWORD:-password}
|
- 5000:5000
|
||||||
- CMK_SITE_ID=cmk
|
- 6776:8000
|
||||||
- TZ=${TZ:-Etc/UTC}
|
restart: unless-stopped
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
|
- "traefik.docker.network=proxy"
|
||||||
- "traefik.http.services.checkmk.loadbalancer.server.port=5000"
|
- "traefik.http.services.checkmk.loadbalancer.server.port=5000"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.checkmk.rule=Host(`cmk.forust.xyz`)"
|
- "traefik.http.routers.checkmk.rule=Host(`cmk.forust.xyz`)"
|
||||||
- "traefik.http.routers.checkmk.entrypoints=websecure"
|
- "traefik.http.routers.checkmk.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.checkmk.service=checkmk"
|
||||||
|
- "traefik.http.routers.checkmk.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.checkmk.tls=true"
|
- "traefik.http.routers.checkmk.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.checkmk-local.rule=Host(`cmk.workstation.internal`)"
|
- "traefik.http.routers.checkmk-local.rule=Host(`cmk.workstation.internal`) || Host(`cmk.internal`)"
|
||||||
- "traefik.http.routers.checkmk-local.entrypoints=websecure"
|
- "traefik.http.routers.checkmk-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.checkmk-local.service=checkmk"
|
||||||
|
- "traefik.http.routers.checkmk-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.checkmk-local.tls=true"
|
- "traefik.http.routers.checkmk-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.checkmk-dev.rule=Host(`cmk.gigaforust.internal`)"
|
- "traefik.http.routers.checkmk-dev.rule=Host(`cmk.gigaforust.internal`)"
|
||||||
|
- "traefik.http.routers.checkmk-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.checkmk-dev.service=checkmk"
|
||||||
- "traefik.http.routers.checkmk-dev.entrypoints=websecure"
|
- "traefik.http.routers.checkmk-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.checkmk-dev.tls=true"
|
- "traefik.http.routers.checkmk-dev.tls=true"
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -3,44 +3,52 @@ services:
|
|||||||
image: darthnorse/dockmon:latest
|
image: darthnorse/dockmon:latest
|
||||||
container_name: dockmon
|
container_name: dockmon
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
# ports:
|
ports:
|
||||||
# - 8000:443
|
- 8000:443
|
||||||
|
environment:
|
||||||
|
- TZ=Europe/Bratislava
|
||||||
volumes:
|
volumes:
|
||||||
- data:/app/data
|
- ./data:/app/data
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: [ "CMD", "curl", "-k", "-f", "https://localhost:443/health" ]
|
test: [ "CMD", "curl", "-k", "-f", "https://localhost:443/health" ]
|
||||||
interval: 30s
|
interval: 30s
|
||||||
timeout: 10s
|
timeout: 10s
|
||||||
retries: 3
|
retries: 3
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.http.services.dockmon.loadbalancer.server.port=443"
|
- "traefik.docker.network=proxy"
|
||||||
- "traefik.http.services.dockmon.loadbalancer.server.scheme=https"
|
|
||||||
- "traefik.http.services.dockmon.loadbalancer.serverstransport=insecureTransport@file"
|
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
|
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
|
||||||
- "traefik.http.routers.dockmon.entrypoints=websecure"
|
- "traefik.http.routers.dockmon.entrypoints=websecure"
|
||||||
- "traefik.http.routers.dockmon.middlewares=security-chain@file"
|
- "traefik.http.routers.dockmon.middlewares=security-chain@file"
|
||||||
|
- "traefik.http.routers.dockmon.service=dockmon"
|
||||||
- "traefik.http.routers.dockmon.tls=true"
|
- "traefik.http.routers.dockmon.tls=true"
|
||||||
|
- "traefik.http.services.dockmon.loadbalancer.server.port=443"
|
||||||
|
- "traefik.http.services.dockmon.loadbalancer.server.scheme=https"
|
||||||
|
- "traefik.http.services.dockmon.loadbalancer.serverstransport=insecureTransport@file"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`)"
|
- "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`) || Host(`dockmon.internal`)"
|
||||||
- "traefik.http.routers.dockmon-local.entrypoints=websecure"
|
- "traefik.http.routers.dockmon-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.dockmon-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.dockmon-local.service=dockmon"
|
||||||
- "traefik.http.routers.dockmon-local.tls=true"
|
- "traefik.http.routers.dockmon-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.dockmon-dev.rule=Host(`dockmon.gigaforust.internal`)"
|
- "traefik.http.routers.dockmon-dev.rule=Host(`dockmon.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.dockmon-dev.entrypoints=websecure"
|
- "traefik.http.routers.dockmon-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.dockmon-dev.middlewares=security-chain@file"
|
||||||
|
- "traefik.http.routers.dockmon-dev.service=dockmon"
|
||||||
- "traefik.http.routers.dockmon-dev.tls=true"
|
- "traefik.http.routers.dockmon-dev.tls=true"
|
||||||
|
|
||||||
# Glance Metadata
|
|
||||||
- glance.name=dockmon
|
- glance.name=dockmon
|
||||||
- glance.url=https://dockmon.forust.xyz/
|
- glance.url=https://dockmon.forust.xyz/
|
||||||
- glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface.
|
- glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface.
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
volumes:
|
|
||||||
data:
|
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -2,30 +2,38 @@ services:
|
|||||||
downtify:
|
downtify:
|
||||||
container_name: downtify
|
container_name: downtify
|
||||||
image: ghcr.io/henriquesebastiao/downtify:latest
|
image: ghcr.io/henriquesebastiao/downtify:latest
|
||||||
restart: unless-stopped
|
|
||||||
# ports:
|
# ports:
|
||||||
# - '7077:8000'
|
# - '7077:8000'
|
||||||
volumes:
|
|
||||||
- ./Downtify_downloads:/downloads
|
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- traefik.enable=true
|
||||||
- "traefik.http.services.downtify.loadbalancer.server.port=8000"
|
- traefik.http.services.downtify.loadbalancer.server.port=8000
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.downtify.rule=Host(`downtify.forust.xyz`)"
|
- traefik.http.routers.downtify.rule=Host(`downtify.forust.xyz`)
|
||||||
- "traefik.http.routers.downtify.entrypoints=websecure"
|
- traefik.http.routers.downtify.entrypoints=websecure
|
||||||
- "traefik.http.routers.downtify.middlewares=security-chain@file"
|
- traefik.http.routers.downtify.middlewares=security-chain@file
|
||||||
- "traefik.http.routers.downtify.tls=true"
|
- traefik.http.routers.downtify.service=downtify
|
||||||
|
- traefik.http.routers.downtify.tls=true
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.downtify-local.rule=Host(`downtify.workstation.internal`)"
|
- traefik.http.routers.downtify-local.rule=Host(`downtify.workstation.internal`) || Host(`downtify.internal`)
|
||||||
- "traefik.http.routers.downtify-local.entrypoints=websecure"
|
- traefik.http.routers.downtify-local.entrypoints=websecure
|
||||||
- "traefik.http.routers.downtify-local.tls=true"
|
- traefik.http.routers.downtify-local.middlewares=security-headers@file
|
||||||
|
- traefik.http.routers.downtify-local.service=downtify
|
||||||
|
- traefik.http.routers.downtify-local.tls=true
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.downtify-dev.rule=Host(`downtify.gigaforust.internal`)"
|
- traefik.http.routers.downtify-dev.rule=Host(`downtify.gigaforust.internal`)
|
||||||
- "traefik.http.routers.downtify-dev.entrypoints=websecure"
|
- traefik.http.routers.downtify-dev.entrypoints=websecure
|
||||||
- "traefik.http.routers.downtify-dev.tls=true"
|
- traefik.http.routers.downtify-dev.middlewares=security-chain@file
|
||||||
|
- traefik.http.routers.downtify-dev.service=downtify
|
||||||
|
- traefik.http.routers.downtify-dev.tls=true
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
- ./Downtify_downloads:/downloads
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -1,5 +0,0 @@
|
|||||||
FROM nginx:alpine
|
|
||||||
RUN rm -rf /usr/share/nginx/html/*
|
|
||||||
COPY html /usr/share/nginx/html
|
|
||||||
EXPOSE 80
|
|
||||||
CMD ["nginx", "-g", "daemon off;"]
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
services:
|
|
||||||
errorpage:
|
|
||||||
build: .
|
|
||||||
container_name: error-pages
|
|
||||||
restart: unless-stopped
|
|
||||||
# ports:
|
|
||||||
# - 1234:80
|
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
labels:
|
|
||||||
- "traefik.enable=true"
|
|
||||||
- "traefik.http.services.error-pages.loadbalancer.server.port=80"
|
|
||||||
# Error handler middleware
|
|
||||||
- "traefik.http.middlewares.error-pages.errors.status=400-599"
|
|
||||||
- "traefik.http.middlewares.error-pages.errors.service=error-pages"
|
|
||||||
- "traefik.http.middlewares.error-pages.errors.query=/{status}.html"
|
|
||||||
networks:
|
|
||||||
proxy:
|
|
||||||
external: true
|
|
||||||
@@ -1,208 +0,0 @@
|
|||||||
<!DOCTYPE html>
|
|
||||||
<html lang="en">
|
|
||||||
|
|
||||||
<head>
|
|
||||||
<meta charset="UTF-8">
|
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
||||||
<title>403 // Forbidden</title>
|
|
||||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
|
||||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
|
||||||
<style>
|
|
||||||
/* hidden in a plain sight? */
|
|
||||||
:root {
|
|
||||||
--bg-color: #050505;
|
|
||||||
--text-color: #e0e0e0;
|
|
||||||
--accent: #ffffff;
|
|
||||||
--dim: #666666;
|
|
||||||
--font-mono: 'Courier New', Courier, monospace;
|
|
||||||
}
|
|
||||||
|
|
||||||
* {
|
|
||||||
box-sizing: border-box;
|
|
||||||
margin: 0;
|
|
||||||
padding: 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
body {
|
|
||||||
background-color: var(--bg-color);
|
|
||||||
color: var(--text-color);
|
|
||||||
font-family: var(--font-mono);
|
|
||||||
line-height: 1.6;
|
|
||||||
font-size: 16px;
|
|
||||||
padding: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
a {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-decoration: none;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
transition: all 0.2s;
|
|
||||||
}
|
|
||||||
|
|
||||||
a:hover {
|
|
||||||
background-color: var(--text-color);
|
|
||||||
color: var(--bg-color);
|
|
||||||
border-color: var(--text-color);
|
|
||||||
}
|
|
||||||
|
|
||||||
.container {
|
|
||||||
max-width: 800px;
|
|
||||||
margin: 0 auto;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* TEXT */
|
|
||||||
h1 {
|
|
||||||
font-size: 2.5rem;
|
|
||||||
text-transform: uppercase;
|
|
||||||
letter-spacing: -2px;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
h2 {
|
|
||||||
font-size: 1.2rem;
|
|
||||||
margin-bottom: 1.5rem;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
display: inline-block;
|
|
||||||
padding-right: 20px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.subtitle {
|
|
||||||
color: var(--dim);
|
|
||||||
margin-bottom: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
hr {
|
|
||||||
border: 0;
|
|
||||||
border-top: 1px dashed var(--dim);
|
|
||||||
margin: 2rem 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
.comment {
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.9rem;
|
|
||||||
margin-left: 10px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* SECTIONS */
|
|
||||||
section {
|
|
||||||
margin-bottom: 3rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* LISTS */
|
|
||||||
ul {
|
|
||||||
list-style: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
.link-list li {
|
|
||||||
margin-bottom: 0.8rem;
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
gap: 15px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* STACK GRID */
|
|
||||||
.grid-2 {
|
|
||||||
display: grid;
|
|
||||||
grid-template-columns: 1fr 1fr;
|
|
||||||
gap: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.skill-item {
|
|
||||||
display: flex;
|
|
||||||
justify-content: space-between;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.level {
|
|
||||||
font-weight: bold;
|
|
||||||
}
|
|
||||||
|
|
||||||
.special .level {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* my dudes */
|
|
||||||
.team-grid {
|
|
||||||
display: flex;
|
|
||||||
gap: 2rem;
|
|
||||||
flex-wrap: wrap;
|
|
||||||
margin-top: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.member {
|
|
||||||
text-align: center;
|
|
||||||
width: 100px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.avatar {
|
|
||||||
width: 80px;
|
|
||||||
height: 80px;
|
|
||||||
background-color: #222;
|
|
||||||
border: 2px solid var(--text-color);
|
|
||||||
margin: 0 auto 10px auto;
|
|
||||||
background-size: cover;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* if no avatar added: */
|
|
||||||
.placeholder::before {
|
|
||||||
content: "?";
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
justify-content: center;
|
|
||||||
height: 100%;
|
|
||||||
font-size: 2rem;
|
|
||||||
color: var(--dim);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* REPOS */
|
|
||||||
.repo-list li {
|
|
||||||
margin-bottom: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* FOOTER */
|
|
||||||
footer {
|
|
||||||
text-align: center;
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.8rem;
|
|
||||||
/* flag{why-are-you-here?} */
|
|
||||||
margin-top: 4rem;
|
|
||||||
}
|
|
||||||
/* SMTH RESPONSIVE */
|
|
||||||
@media (max-width: 600px) {
|
|
||||||
.grid-2 {
|
|
||||||
grid-template-columns: 1fr;
|
|
||||||
gap: 0;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
</style>
|
|
||||||
</head>
|
|
||||||
|
|
||||||
<body>
|
|
||||||
|
|
||||||
<div class="container">
|
|
||||||
<header>
|
|
||||||
<h1 class="glitch" data-text="403">403</h1>
|
|
||||||
<p class="subtitle">> Forbidden / Access Denied.</p>
|
|
||||||
</header>
|
|
||||||
|
|
||||||
<hr>
|
|
||||||
|
|
||||||
<section id="message">
|
|
||||||
<h2>./error_message</h2>
|
|
||||||
<p>You do not have permission to access this resource.</p>
|
|
||||||
<br>
|
|
||||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> if you believe this is an
|
|
||||||
error.</p>
|
|
||||||
</section>
|
|
||||||
|
|
||||||
<footer>
|
|
||||||
<p>root@error:~$ sudo access_resource</p>
|
|
||||||
<p>User is not in the sudoers file. This incident will be reported.</p>
|
|
||||||
<p>© XRock - Just Signal.</p>
|
|
||||||
</footer>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
</body>
|
|
||||||
|
|
||||||
</html>
|
|
||||||
@@ -1,207 +0,0 @@
|
|||||||
<!DOCTYPE html>
|
|
||||||
<html lang="en">
|
|
||||||
|
|
||||||
<head>
|
|
||||||
<meta charset="UTF-8">
|
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
||||||
<title>404 // Not Found</title>
|
|
||||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
|
||||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
|
||||||
<style>
|
|
||||||
/* hidden in a plain sight? */
|
|
||||||
:root {
|
|
||||||
--bg-color: #050505;
|
|
||||||
--text-color: #e0e0e0;
|
|
||||||
--accent: #ffffff;
|
|
||||||
--dim: #666666;
|
|
||||||
--font-mono: 'Courier New', Courier, monospace;
|
|
||||||
}
|
|
||||||
|
|
||||||
* {
|
|
||||||
box-sizing: border-box;
|
|
||||||
margin: 0;
|
|
||||||
padding: 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
body {
|
|
||||||
background-color: var(--bg-color);
|
|
||||||
color: var(--text-color);
|
|
||||||
font-family: var(--font-mono);
|
|
||||||
line-height: 1.6;
|
|
||||||
font-size: 16px;
|
|
||||||
padding: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
a {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-decoration: none;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
transition: all 0.2s;
|
|
||||||
}
|
|
||||||
|
|
||||||
a:hover {
|
|
||||||
background-color: var(--text-color);
|
|
||||||
color: var(--bg-color);
|
|
||||||
border-color: var(--text-color);
|
|
||||||
}
|
|
||||||
|
|
||||||
.container {
|
|
||||||
max-width: 800px;
|
|
||||||
margin: 0 auto;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* TEXT */
|
|
||||||
h1 {
|
|
||||||
font-size: 2.5rem;
|
|
||||||
text-transform: uppercase;
|
|
||||||
letter-spacing: -2px;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
h2 {
|
|
||||||
font-size: 1.2rem;
|
|
||||||
margin-bottom: 1.5rem;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
display: inline-block;
|
|
||||||
padding-right: 20px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.subtitle {
|
|
||||||
color: var(--dim);
|
|
||||||
margin-bottom: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
hr {
|
|
||||||
border: 0;
|
|
||||||
border-top: 1px dashed var(--dim);
|
|
||||||
margin: 2rem 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
.comment {
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.9rem;
|
|
||||||
margin-left: 10px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* SECTIONS */
|
|
||||||
section {
|
|
||||||
margin-bottom: 3rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* LISTS */
|
|
||||||
ul {
|
|
||||||
list-style: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
.link-list li {
|
|
||||||
margin-bottom: 0.8rem;
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
gap: 15px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* STACK GRID */
|
|
||||||
.grid-2 {
|
|
||||||
display: grid;
|
|
||||||
grid-template-columns: 1fr 1fr;
|
|
||||||
gap: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.skill-item {
|
|
||||||
display: flex;
|
|
||||||
justify-content: space-between;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.level {
|
|
||||||
font-weight: bold;
|
|
||||||
}
|
|
||||||
|
|
||||||
.special .level {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* my dudes */
|
|
||||||
.team-grid {
|
|
||||||
display: flex;
|
|
||||||
gap: 2rem;
|
|
||||||
flex-wrap: wrap;
|
|
||||||
margin-top: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.member {
|
|
||||||
text-align: center;
|
|
||||||
width: 100px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.avatar {
|
|
||||||
width: 80px;
|
|
||||||
height: 80px;
|
|
||||||
background-color: #222;
|
|
||||||
border: 2px solid var(--text-color);
|
|
||||||
margin: 0 auto 10px auto;
|
|
||||||
background-size: cover;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* if no avatar added: */
|
|
||||||
.placeholder::before {
|
|
||||||
content: "?";
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
justify-content: center;
|
|
||||||
height: 100%;
|
|
||||||
font-size: 2rem;
|
|
||||||
color: var(--dim);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* REPOS */
|
|
||||||
.repo-list li {
|
|
||||||
margin-bottom: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* FOOTER */
|
|
||||||
footer {
|
|
||||||
text-align: center;
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.8rem;
|
|
||||||
/* flag{why-are-you-here?} */
|
|
||||||
margin-top: 4rem;
|
|
||||||
}
|
|
||||||
/* SMTH RESPONSIVE */
|
|
||||||
@media (max-width: 600px) {
|
|
||||||
.grid-2 {
|
|
||||||
grid-template-columns: 1fr;
|
|
||||||
gap: 0;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
</style>
|
|
||||||
</head>
|
|
||||||
|
|
||||||
<body>
|
|
||||||
|
|
||||||
<div class="container">
|
|
||||||
<header>
|
|
||||||
<h1 class="glitch" data-text="404">404</h1>
|
|
||||||
<p class="subtitle">> Page Not Found / Lost in the Void.</p>
|
|
||||||
</header>
|
|
||||||
|
|
||||||
<hr>
|
|
||||||
|
|
||||||
<section id="message">
|
|
||||||
<h2>./error_message</h2>
|
|
||||||
<p>The page you are looking for does not exist or has been moved.</p>
|
|
||||||
<br>
|
|
||||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> if you believe this is an error.</p>
|
|
||||||
</section>
|
|
||||||
|
|
||||||
<footer>
|
|
||||||
<p>root@error:~$ ping target</p>
|
|
||||||
<p>Destination Host Unreachable</p>
|
|
||||||
<p>© XRock - Just Signal.</p>
|
|
||||||
</footer>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
</body>
|
|
||||||
|
|
||||||
</html>
|
|
||||||
@@ -1,207 +0,0 @@
|
|||||||
<!DOCTYPE html>
|
|
||||||
<html lang="en">
|
|
||||||
|
|
||||||
<head>
|
|
||||||
<meta charset="UTF-8">
|
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
||||||
<title>500 // Server Error</title>
|
|
||||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
|
||||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
|
||||||
<style>
|
|
||||||
/* hidden in a plain sight? */
|
|
||||||
:root {
|
|
||||||
--bg-color: #050505;
|
|
||||||
--text-color: #e0e0e0;
|
|
||||||
--accent: #ffffff;
|
|
||||||
--dim: #666666;
|
|
||||||
--font-mono: 'Courier New', Courier, monospace;
|
|
||||||
}
|
|
||||||
|
|
||||||
* {
|
|
||||||
box-sizing: border-box;
|
|
||||||
margin: 0;
|
|
||||||
padding: 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
body {
|
|
||||||
background-color: var(--bg-color);
|
|
||||||
color: var(--text-color);
|
|
||||||
font-family: var(--font-mono);
|
|
||||||
line-height: 1.6;
|
|
||||||
font-size: 16px;
|
|
||||||
padding: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
a {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-decoration: none;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
transition: all 0.2s;
|
|
||||||
}
|
|
||||||
|
|
||||||
a:hover {
|
|
||||||
background-color: var(--text-color);
|
|
||||||
color: var(--bg-color);
|
|
||||||
border-color: var(--text-color);
|
|
||||||
}
|
|
||||||
|
|
||||||
.container {
|
|
||||||
max-width: 800px;
|
|
||||||
margin: 0 auto;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* TEXT */
|
|
||||||
h1 {
|
|
||||||
font-size: 2.5rem;
|
|
||||||
text-transform: uppercase;
|
|
||||||
letter-spacing: -2px;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
h2 {
|
|
||||||
font-size: 1.2rem;
|
|
||||||
margin-bottom: 1.5rem;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
display: inline-block;
|
|
||||||
padding-right: 20px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.subtitle {
|
|
||||||
color: var(--dim);
|
|
||||||
margin-bottom: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
hr {
|
|
||||||
border: 0;
|
|
||||||
border-top: 1px dashed var(--dim);
|
|
||||||
margin: 2rem 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
.comment {
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.9rem;
|
|
||||||
margin-left: 10px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* SECTIONS */
|
|
||||||
section {
|
|
||||||
margin-bottom: 3rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* LISTS */
|
|
||||||
ul {
|
|
||||||
list-style: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
.link-list li {
|
|
||||||
margin-bottom: 0.8rem;
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
gap: 15px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* STACK GRID */
|
|
||||||
.grid-2 {
|
|
||||||
display: grid;
|
|
||||||
grid-template-columns: 1fr 1fr;
|
|
||||||
gap: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.skill-item {
|
|
||||||
display: flex;
|
|
||||||
justify-content: space-between;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.level {
|
|
||||||
font-weight: bold;
|
|
||||||
}
|
|
||||||
|
|
||||||
.special .level {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* my dudes */
|
|
||||||
.team-grid {
|
|
||||||
display: flex;
|
|
||||||
gap: 2rem;
|
|
||||||
flex-wrap: wrap;
|
|
||||||
margin-top: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.member {
|
|
||||||
text-align: center;
|
|
||||||
width: 100px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.avatar {
|
|
||||||
width: 80px;
|
|
||||||
height: 80px;
|
|
||||||
background-color: #222;
|
|
||||||
border: 2px solid var(--text-color);
|
|
||||||
margin: 0 auto 10px auto;
|
|
||||||
background-size: cover;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* if no avatar added: */
|
|
||||||
.placeholder::before {
|
|
||||||
content: "?";
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
justify-content: center;
|
|
||||||
height: 100%;
|
|
||||||
font-size: 2rem;
|
|
||||||
color: var(--dim);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* REPOS */
|
|
||||||
.repo-list li {
|
|
||||||
margin-bottom: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* FOOTER */
|
|
||||||
footer {
|
|
||||||
text-align: center;
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.8rem;
|
|
||||||
/* flag{why-are-you-here?} */
|
|
||||||
margin-top: 4rem;
|
|
||||||
}
|
|
||||||
/* SMTH RESPONSIVE */
|
|
||||||
@media (max-width: 600px) {
|
|
||||||
.grid-2 {
|
|
||||||
grid-template-columns: 1fr;
|
|
||||||
gap: 0;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
</style>
|
|
||||||
</head>
|
|
||||||
|
|
||||||
<body>
|
|
||||||
|
|
||||||
<div class="container">
|
|
||||||
<header>
|
|
||||||
<h1 class="glitch" data-text="500">500</h1>
|
|
||||||
<p class="subtitle">> Internal Server Error / System Failure.</p>
|
|
||||||
</header>
|
|
||||||
|
|
||||||
<hr>
|
|
||||||
|
|
||||||
<section id="message">
|
|
||||||
<h2>./error_message</h2>
|
|
||||||
<p>Something went wrong on our end. We are working to fix it.</p>
|
|
||||||
<br>
|
|
||||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> for more information.</p>
|
|
||||||
</section>
|
|
||||||
|
|
||||||
<footer>
|
|
||||||
<p>root@error:~$ systemctl status service</p>
|
|
||||||
<p>Active: failed (Result: core-dump)</p>
|
|
||||||
<p>© XRock - Just Signal.</p>
|
|
||||||
</footer>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
</body>
|
|
||||||
|
|
||||||
</html>
|
|
||||||
@@ -1,207 +0,0 @@
|
|||||||
<!DOCTYPE html>
|
|
||||||
<html lang="en">
|
|
||||||
|
|
||||||
<head>
|
|
||||||
<meta charset="UTF-8">
|
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
||||||
<title>502 // Bad Gateway</title>
|
|
||||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
|
||||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
|
||||||
<style>
|
|
||||||
/* hidden in a plain sight? */
|
|
||||||
:root {
|
|
||||||
--bg-color: #050505;
|
|
||||||
--text-color: #e0e0e0;
|
|
||||||
--accent: #ffffff;
|
|
||||||
--dim: #666666;
|
|
||||||
--font-mono: 'Courier New', Courier, monospace;
|
|
||||||
}
|
|
||||||
|
|
||||||
* {
|
|
||||||
box-sizing: border-box;
|
|
||||||
margin: 0;
|
|
||||||
padding: 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
body {
|
|
||||||
background-color: var(--bg-color);
|
|
||||||
color: var(--text-color);
|
|
||||||
font-family: var(--font-mono);
|
|
||||||
line-height: 1.6;
|
|
||||||
font-size: 16px;
|
|
||||||
padding: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
a {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-decoration: none;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
transition: all 0.2s;
|
|
||||||
}
|
|
||||||
|
|
||||||
a:hover {
|
|
||||||
background-color: var(--text-color);
|
|
||||||
color: var(--bg-color);
|
|
||||||
border-color: var(--text-color);
|
|
||||||
}
|
|
||||||
|
|
||||||
.container {
|
|
||||||
max-width: 800px;
|
|
||||||
margin: 0 auto;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* TEXT */
|
|
||||||
h1 {
|
|
||||||
font-size: 2.5rem;
|
|
||||||
text-transform: uppercase;
|
|
||||||
letter-spacing: -2px;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
h2 {
|
|
||||||
font-size: 1.2rem;
|
|
||||||
margin-bottom: 1.5rem;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
display: inline-block;
|
|
||||||
padding-right: 20px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.subtitle {
|
|
||||||
color: var(--dim);
|
|
||||||
margin-bottom: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
hr {
|
|
||||||
border: 0;
|
|
||||||
border-top: 1px dashed var(--dim);
|
|
||||||
margin: 2rem 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
.comment {
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.9rem;
|
|
||||||
margin-left: 10px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* SECTIONS */
|
|
||||||
section {
|
|
||||||
margin-bottom: 3rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* LISTS */
|
|
||||||
ul {
|
|
||||||
list-style: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
.link-list li {
|
|
||||||
margin-bottom: 0.8rem;
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
gap: 15px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* STACK GRID */
|
|
||||||
.grid-2 {
|
|
||||||
display: grid;
|
|
||||||
grid-template-columns: 1fr 1fr;
|
|
||||||
gap: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.skill-item {
|
|
||||||
display: flex;
|
|
||||||
justify-content: space-between;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.level {
|
|
||||||
font-weight: bold;
|
|
||||||
}
|
|
||||||
|
|
||||||
.special .level {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* my dudes */
|
|
||||||
.team-grid {
|
|
||||||
display: flex;
|
|
||||||
gap: 2rem;
|
|
||||||
flex-wrap: wrap;
|
|
||||||
margin-top: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.member {
|
|
||||||
text-align: center;
|
|
||||||
width: 100px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.avatar {
|
|
||||||
width: 80px;
|
|
||||||
height: 80px;
|
|
||||||
background-color: #222;
|
|
||||||
border: 2px solid var(--text-color);
|
|
||||||
margin: 0 auto 10px auto;
|
|
||||||
background-size: cover;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* if no avatar added: */
|
|
||||||
.placeholder::before {
|
|
||||||
content: "?";
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
justify-content: center;
|
|
||||||
height: 100%;
|
|
||||||
font-size: 2rem;
|
|
||||||
color: var(--dim);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* REPOS */
|
|
||||||
.repo-list li {
|
|
||||||
margin-bottom: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* FOOTER */
|
|
||||||
footer {
|
|
||||||
text-align: center;
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.8rem;
|
|
||||||
/* flag{why-are-you-here?} */
|
|
||||||
margin-top: 4rem;
|
|
||||||
}
|
|
||||||
/* SMTH RESPONSIVE */
|
|
||||||
@media (max-width: 600px) {
|
|
||||||
.grid-2 {
|
|
||||||
grid-template-columns: 1fr;
|
|
||||||
gap: 0;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
</style>
|
|
||||||
</head>
|
|
||||||
|
|
||||||
<body>
|
|
||||||
|
|
||||||
<div class="container">
|
|
||||||
<header>
|
|
||||||
<h1 class="glitch" data-text="502">502</h1>
|
|
||||||
<p class="subtitle">> Bad Gateway / System Failure.</p>
|
|
||||||
</header>
|
|
||||||
|
|
||||||
<hr>
|
|
||||||
|
|
||||||
<section id="message">
|
|
||||||
<h2>./error_message</h2>
|
|
||||||
<p>The server received an invalid response from the upstream server.</p>
|
|
||||||
<br>
|
|
||||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> for more information.</p>
|
|
||||||
</section>
|
|
||||||
|
|
||||||
<footer>
|
|
||||||
<p>root@error:~$ curl -I upstream_host</p>
|
|
||||||
<p>HTTP/1.1 502 Bad Gateway</p>
|
|
||||||
<p>© XRock - Just Signal.</p>
|
|
||||||
</footer>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
</body>
|
|
||||||
|
|
||||||
</html>
|
|
||||||
@@ -1,207 +0,0 @@
|
|||||||
<!DOCTYPE html>
|
|
||||||
<html lang="en">
|
|
||||||
|
|
||||||
<head>
|
|
||||||
<meta charset="UTF-8">
|
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
||||||
<title>503 // Service Unavailable</title>
|
|
||||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
|
||||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
|
||||||
<style>
|
|
||||||
/* hidden in a plain sight? */
|
|
||||||
:root {
|
|
||||||
--bg-color: #050505;
|
|
||||||
--text-color: #e0e0e0;
|
|
||||||
--accent: #ffffff;
|
|
||||||
--dim: #666666;
|
|
||||||
--font-mono: 'Courier New', Courier, monospace;
|
|
||||||
}
|
|
||||||
|
|
||||||
* {
|
|
||||||
box-sizing: border-box;
|
|
||||||
margin: 0;
|
|
||||||
padding: 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
body {
|
|
||||||
background-color: var(--bg-color);
|
|
||||||
color: var(--text-color);
|
|
||||||
font-family: var(--font-mono);
|
|
||||||
line-height: 1.6;
|
|
||||||
font-size: 16px;
|
|
||||||
padding: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
a {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-decoration: none;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
transition: all 0.2s;
|
|
||||||
}
|
|
||||||
|
|
||||||
a:hover {
|
|
||||||
background-color: var(--text-color);
|
|
||||||
color: var(--bg-color);
|
|
||||||
border-color: var(--text-color);
|
|
||||||
}
|
|
||||||
|
|
||||||
.container {
|
|
||||||
max-width: 800px;
|
|
||||||
margin: 0 auto;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* TEXT */
|
|
||||||
h1 {
|
|
||||||
font-size: 2.5rem;
|
|
||||||
text-transform: uppercase;
|
|
||||||
letter-spacing: -2px;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
h2 {
|
|
||||||
font-size: 1.2rem;
|
|
||||||
margin-bottom: 1.5rem;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
display: inline-block;
|
|
||||||
padding-right: 20px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.subtitle {
|
|
||||||
color: var(--dim);
|
|
||||||
margin-bottom: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
hr {
|
|
||||||
border: 0;
|
|
||||||
border-top: 1px dashed var(--dim);
|
|
||||||
margin: 2rem 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
.comment {
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.9rem;
|
|
||||||
margin-left: 10px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* SECTIONS */
|
|
||||||
section {
|
|
||||||
margin-bottom: 3rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* LISTS */
|
|
||||||
ul {
|
|
||||||
list-style: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
.link-list li {
|
|
||||||
margin-bottom: 0.8rem;
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
gap: 15px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* STACK GRID */
|
|
||||||
.grid-2 {
|
|
||||||
display: grid;
|
|
||||||
grid-template-columns: 1fr 1fr;
|
|
||||||
gap: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.skill-item {
|
|
||||||
display: flex;
|
|
||||||
justify-content: space-between;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.level {
|
|
||||||
font-weight: bold;
|
|
||||||
}
|
|
||||||
|
|
||||||
.special .level {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* my dudes */
|
|
||||||
.team-grid {
|
|
||||||
display: flex;
|
|
||||||
gap: 2rem;
|
|
||||||
flex-wrap: wrap;
|
|
||||||
margin-top: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.member {
|
|
||||||
text-align: center;
|
|
||||||
width: 100px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.avatar {
|
|
||||||
width: 80px;
|
|
||||||
height: 80px;
|
|
||||||
background-color: #222;
|
|
||||||
border: 2px solid var(--text-color);
|
|
||||||
margin: 0 auto 10px auto;
|
|
||||||
background-size: cover;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* if no avatar added: */
|
|
||||||
.placeholder::before {
|
|
||||||
content: "?";
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
justify-content: center;
|
|
||||||
height: 100%;
|
|
||||||
font-size: 2rem;
|
|
||||||
color: var(--dim);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* REPOS */
|
|
||||||
.repo-list li {
|
|
||||||
margin-bottom: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* FOOTER */
|
|
||||||
footer {
|
|
||||||
text-align: center;
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.8rem;
|
|
||||||
/* flag{why-are-you-here?} */
|
|
||||||
margin-top: 4rem;
|
|
||||||
}
|
|
||||||
/* SMTH RESPONSIVE */
|
|
||||||
@media (max-width: 600px) {
|
|
||||||
.grid-2 {
|
|
||||||
grid-template-columns: 1fr;
|
|
||||||
gap: 0;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
</style>
|
|
||||||
</head>
|
|
||||||
|
|
||||||
<body>
|
|
||||||
|
|
||||||
<div class="container">
|
|
||||||
<header>
|
|
||||||
<h1 class="glitch" data-text="503">503</h1>
|
|
||||||
<p class="subtitle">> Service Unavailable / System Failure.</p>
|
|
||||||
</header>
|
|
||||||
|
|
||||||
<hr>
|
|
||||||
|
|
||||||
<section id="message">
|
|
||||||
<h2>./error_message</h2>
|
|
||||||
<p>The server is currently unable to handle the request due to maintenance or overload.</p>
|
|
||||||
<br>
|
|
||||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> for more information.</p>
|
|
||||||
</section>
|
|
||||||
|
|
||||||
<footer>
|
|
||||||
<p>root@error:~$ systemctl start service</p>
|
|
||||||
<p>Job for service failed because the control process exited with error code.</p>
|
|
||||||
<p>© XRock - Just Signal.</p>
|
|
||||||
</footer>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
</body>
|
|
||||||
|
|
||||||
</html>
|
|
||||||
@@ -1,207 +0,0 @@
|
|||||||
<!DOCTYPE html>
|
|
||||||
<html lang="en">
|
|
||||||
|
|
||||||
<head>
|
|
||||||
<meta charset="UTF-8">
|
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
||||||
<title>504 // Gateway Timeout</title>
|
|
||||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
|
||||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
|
||||||
<style>
|
|
||||||
/* hidden in a plain sight? */
|
|
||||||
:root {
|
|
||||||
--bg-color: #050505;
|
|
||||||
--text-color: #e0e0e0;
|
|
||||||
--accent: #ffffff;
|
|
||||||
--dim: #666666;
|
|
||||||
--font-mono: 'Courier New', Courier, monospace;
|
|
||||||
}
|
|
||||||
|
|
||||||
* {
|
|
||||||
box-sizing: border-box;
|
|
||||||
margin: 0;
|
|
||||||
padding: 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
body {
|
|
||||||
background-color: var(--bg-color);
|
|
||||||
color: var(--text-color);
|
|
||||||
font-family: var(--font-mono);
|
|
||||||
line-height: 1.6;
|
|
||||||
font-size: 16px;
|
|
||||||
padding: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
a {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-decoration: none;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
transition: all 0.2s;
|
|
||||||
}
|
|
||||||
|
|
||||||
a:hover {
|
|
||||||
background-color: var(--text-color);
|
|
||||||
color: var(--bg-color);
|
|
||||||
border-color: var(--text-color);
|
|
||||||
}
|
|
||||||
|
|
||||||
.container {
|
|
||||||
max-width: 800px;
|
|
||||||
margin: 0 auto;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* TEXT */
|
|
||||||
h1 {
|
|
||||||
font-size: 2.5rem;
|
|
||||||
text-transform: uppercase;
|
|
||||||
letter-spacing: -2px;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
h2 {
|
|
||||||
font-size: 1.2rem;
|
|
||||||
margin-bottom: 1.5rem;
|
|
||||||
border-bottom: 1px solid var(--dim);
|
|
||||||
display: inline-block;
|
|
||||||
padding-right: 20px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.subtitle {
|
|
||||||
color: var(--dim);
|
|
||||||
margin-bottom: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
hr {
|
|
||||||
border: 0;
|
|
||||||
border-top: 1px dashed var(--dim);
|
|
||||||
margin: 2rem 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
.comment {
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.9rem;
|
|
||||||
margin-left: 10px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* SECTIONS */
|
|
||||||
section {
|
|
||||||
margin-bottom: 3rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* LISTS */
|
|
||||||
ul {
|
|
||||||
list-style: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
.link-list li {
|
|
||||||
margin-bottom: 0.8rem;
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
gap: 15px;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* STACK GRID */
|
|
||||||
.grid-2 {
|
|
||||||
display: grid;
|
|
||||||
grid-template-columns: 1fr 1fr;
|
|
||||||
gap: 2rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.skill-item {
|
|
||||||
display: flex;
|
|
||||||
justify-content: space-between;
|
|
||||||
margin-bottom: 0.5rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.level {
|
|
||||||
font-weight: bold;
|
|
||||||
}
|
|
||||||
|
|
||||||
.special .level {
|
|
||||||
color: var(--text-color);
|
|
||||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* my dudes */
|
|
||||||
.team-grid {
|
|
||||||
display: flex;
|
|
||||||
gap: 2rem;
|
|
||||||
flex-wrap: wrap;
|
|
||||||
margin-top: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
.member {
|
|
||||||
text-align: center;
|
|
||||||
width: 100px;
|
|
||||||
}
|
|
||||||
|
|
||||||
.avatar {
|
|
||||||
width: 80px;
|
|
||||||
height: 80px;
|
|
||||||
background-color: #222;
|
|
||||||
border: 2px solid var(--text-color);
|
|
||||||
margin: 0 auto 10px auto;
|
|
||||||
background-size: cover;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* if no avatar added: */
|
|
||||||
.placeholder::before {
|
|
||||||
content: "?";
|
|
||||||
display: flex;
|
|
||||||
align-items: center;
|
|
||||||
justify-content: center;
|
|
||||||
height: 100%;
|
|
||||||
font-size: 2rem;
|
|
||||||
color: var(--dim);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* REPOS */
|
|
||||||
.repo-list li {
|
|
||||||
margin-bottom: 1rem;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* FOOTER */
|
|
||||||
footer {
|
|
||||||
text-align: center;
|
|
||||||
color: var(--dim);
|
|
||||||
font-size: 0.8rem;
|
|
||||||
/* flag{why-are-you-here?} */
|
|
||||||
margin-top: 4rem;
|
|
||||||
}
|
|
||||||
/* SMTH RESPONSIVE */
|
|
||||||
@media (max-width: 600px) {
|
|
||||||
.grid-2 {
|
|
||||||
grid-template-columns: 1fr;
|
|
||||||
gap: 0;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
</style>
|
|
||||||
</head>
|
|
||||||
|
|
||||||
<body>
|
|
||||||
|
|
||||||
<div class="container">
|
|
||||||
<header>
|
|
||||||
<h1 class="glitch" data-text="504">504</h1>
|
|
||||||
<p class="subtitle">> Gateway Timeout / System Failure.</p>
|
|
||||||
</header>
|
|
||||||
|
|
||||||
<hr>
|
|
||||||
|
|
||||||
<section id="message">
|
|
||||||
<h2>./error_message</h2>
|
|
||||||
<p>The server did not receive a timely response from the upstream server.</p>
|
|
||||||
<br>
|
|
||||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> for more information.</p>
|
|
||||||
</section>
|
|
||||||
|
|
||||||
<footer>
|
|
||||||
<p>root@error:~$ timeout 30s curl upstream</p>
|
|
||||||
<p>curl: (28) Operation timed out after 30001 milliseconds with 0 bytes received</p>
|
|
||||||
<p>© XRock - Just Signal.</p>
|
|
||||||
</footer>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
</body>
|
|
||||||
|
|
||||||
</html>
|
|
||||||
@@ -1,8 +1,7 @@
|
|||||||
services:
|
services:
|
||||||
server:
|
server:
|
||||||
image: docker.gitea.com/gitea:1.26
|
image: docker.gitea.com/gitea:1.25.1
|
||||||
container_name: gitea
|
container_name: gitea
|
||||||
restart: always
|
|
||||||
environment:
|
environment:
|
||||||
- USER_UID=1000
|
- USER_UID=1000
|
||||||
- USER_GID=1000
|
- USER_GID=1000
|
||||||
@@ -25,37 +24,47 @@ services:
|
|||||||
- GITEA__mailer__PROTOCOL=SMTP
|
- GITEA__mailer__PROTOCOL=SMTP
|
||||||
- GITEA__service__REGISTER_EMAIL_CONFIRM=true
|
- GITEA__service__REGISTER_EMAIL_CONFIRM=true
|
||||||
- GITEA__service__ENABLE_NOTIFY_MAIL=true
|
- GITEA__service__ENABLE_NOTIFY_MAIL=true
|
||||||
|
restart: always
|
||||||
|
networks:
|
||||||
|
- gitea-db
|
||||||
|
- proxy
|
||||||
volumes:
|
volumes:
|
||||||
- ./gitea-data:/data
|
- ./gitea-data:/data
|
||||||
- /etc/timezone:/etc/timezone:ro
|
- /etc/timezone:/etc/timezone:ro
|
||||||
- /etc/localtime:/etc/localtime:ro
|
- /etc/localtime:/etc/localtime:ro
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.http.services.gitea.loadbalancer.server.port=3000"
|
- "traefik.docker.network=proxy"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)"
|
- "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)"
|
||||||
- "traefik.http.routers.gitea.entrypoints=websecure"
|
- "traefik.http.routers.gitea.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.gitea.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.gitea.service=gitea"
|
||||||
- "traefik.http.routers.gitea.tls=true"
|
- "traefik.http.routers.gitea.tls=true"
|
||||||
|
- "traefik.http.services.gitea.loadbalancer.server.port=3000"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.gitea-local.rule=Host(`gitea.workstation.internal`)"
|
- "traefik.http.routers.gitea-local.rule=Host(`gitea.workstation.internal`) || Host(`gitea.internal`)"
|
||||||
- "traefik.http.routers.gitea-local.entrypoints=websecure"
|
- "traefik.http.routers.gitea-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.gitea-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.gitea-local.service=gitea"
|
||||||
- "traefik.http.routers.gitea-local.tls=true"
|
- "traefik.http.routers.gitea-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.gitea-dev.rule=Host(`gitea.gigaforust.internal`)"
|
- "traefik.http.routers.gitea-dev.rule=Host(`gitea.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.gitea-dev.entrypoints=websecure"
|
- "traefik.http.routers.gitea-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.gitea-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.gitea-dev.service=gitea"
|
||||||
- "traefik.http.routers.gitea-dev.tls=true"
|
- "traefik.http.routers.gitea-dev.tls=true"
|
||||||
# SSH Router
|
|
||||||
- "traefik.tcp.services.gitea.loadbalancer.server.port=22"
|
|
||||||
- "traefik.tcp.routers.gitea.entrypoints=ssh"
|
- "traefik.tcp.routers.gitea.entrypoints=ssh"
|
||||||
- "traefik.tcp.routers.gitea.rule=HostSNI(`*`)"
|
- "traefik.tcp.routers.gitea.rule=HostSNI(`*`)"
|
||||||
|
- "traefik.tcp.services.gitea.loadbalancer.server.port=22"
|
||||||
ports:
|
ports:
|
||||||
- "2221:22"
|
- "2221:22"
|
||||||
networks:
|
|
||||||
- gitea-db
|
|
||||||
- proxy
|
|
||||||
depends_on:
|
depends_on:
|
||||||
- db
|
- db
|
||||||
|
|
||||||
db:
|
db:
|
||||||
image: docker.io/library/postgres:14
|
image: docker.io/library/postgres:14
|
||||||
restart: always
|
restart: always
|
||||||
@@ -63,10 +72,11 @@ services:
|
|||||||
- POSTGRES_USER=gitea
|
- POSTGRES_USER=gitea
|
||||||
- POSTGRES_PASSWORD=gitea
|
- POSTGRES_PASSWORD=gitea
|
||||||
- POSTGRES_DB=gitea
|
- POSTGRES_DB=gitea
|
||||||
volumes:
|
|
||||||
- ./gitea-db/:/var/lib/postgresql/data
|
|
||||||
networks:
|
networks:
|
||||||
- gitea-db
|
- gitea-db
|
||||||
|
volumes:
|
||||||
|
- ./gitea-db/:/var/lib/postgresql/data
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
gitea-db:
|
gitea-db:
|
||||||
external: false
|
external: false
|
||||||
|
|||||||
@@ -12,22 +12,29 @@ services:
|
|||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
- "traefik.services.glance.loadbalancer.server.port=8080"
|
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.glance.rule=Host(`glance.forust.xyz`)"
|
- "traefik.http.routers.glance.rule=Host(`glance.forust.xyz`)"
|
||||||
- "traefik.http.routers.glance.entrypoints=websecure"
|
- "traefik.http.routers.glance.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.glance.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.glance.tls=true"
|
- "traefik.http.routers.glance.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.glance-local.rule=Host(`glance.workstation.internal`)"
|
- "traefik.http.routers.glance-local.rule=Host(`glance.workstation.internal`) || Host(`glance.internal`)"
|
||||||
- "traefik.http.routers.glance-local.entrypoints=websecure"
|
- "traefik.http.routers.glance-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.glance-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.glance-local.tls=true"
|
- "traefik.http.routers.glance-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.glance-dev.rule=Host(`glance.gigaforust.internal`)"
|
- "traefik.http.routers.glance-dev.rule=Host(`glance.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.glance-dev.entrypoints=websecure"
|
- "traefik.http.routers.glance-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.glance-dev.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.glance-dev.tls=true"
|
- "traefik.http.routers.glance-dev.tls=true"
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
|
dns:
|
||||||
|
- 1.1.1.1
|
||||||
|
- 8.8.8.8
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
@@ -1,18 +1,16 @@
|
|||||||
services:
|
services:
|
||||||
headscale:
|
server:
|
||||||
image: headscale/headscale:latest
|
image: headscale/headscale:latest
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
container_name: headscale-server
|
|
||||||
command: serve
|
command: serve
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
volumes:
|
volumes:
|
||||||
- ./config/headscale.yaml:/etc/headscale/config.yaml
|
- ./config:/etc/headscale
|
||||||
- data:/var/lib/headscale
|
- ./data:/var/lib/headscale
|
||||||
- ./config/policy.json:/var/lib/headscale/policy.json
|
|
||||||
labels:
|
labels:
|
||||||
- "me.tale.headplane.target: headscale"
|
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
|
- "traefik.docker.network=proxy"
|
||||||
- "traefik.http.services.headscale.loadbalancer.server.port=8080"
|
- "traefik.http.services.headscale.loadbalancer.server.port=8080"
|
||||||
- "traefik.http.services.headscale-metrics.loadbalancer.server.port=9090"
|
- "traefik.http.services.headscale-metrics.loadbalancer.server.port=9090"
|
||||||
|
|
||||||
@@ -49,45 +47,38 @@ services:
|
|||||||
- "traefik.http.routers.headscale-metrics-dev.entrypoints=websecure"
|
- "traefik.http.routers.headscale-metrics-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.headscale-metrics-dev.service=headscale-metrics"
|
- "traefik.http.routers.headscale-metrics-dev.service=headscale-metrics"
|
||||||
- "traefik.http.routers.headscale-metrics-dev.tls=true"
|
- "traefik.http.routers.headscale-metrics-dev.tls=true"
|
||||||
headplane:
|
dns:
|
||||||
image: ghcr.io/tale/headplane:latest
|
- 1.1.1.1
|
||||||
container_name: headplane
|
- 1.0.0.1
|
||||||
restart: unless-stopped
|
|
||||||
ports:
|
|
||||||
- '3000:3000'
|
|
||||||
volumes:
|
|
||||||
- ./config/headplane.yaml:/etc/headplane/config.yaml
|
|
||||||
- ./config/headscale.yaml:/etc/headscale/config.yaml
|
|
||||||
- headplane-data:/var/lib/headplane
|
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
web:
|
web:
|
||||||
image: goodieshq/headscale-admin:latest
|
image: goodieshq/headscale-admin:latest
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
|
- "treafik.docker.network=proxy"
|
||||||
- "traefik.http.services.headscale-ui.loadbalancer.server.port=80"
|
- "traefik.http.services.headscale-ui.loadbalancer.server.port=80"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.headscale-ui.rule=Host(`hs.forust.xyz`) && PathPrefix(`/admin`)"
|
- "traefik.http.routers.headscale-ui.rule=Host(`hs.forust.xyz`) && PathPrefix(`/admin`)"
|
||||||
- "traefik.http.routers.headscale-ui.entrypoints=websecure"
|
- "traefik.http.routers.headscale-ui.entrypoints=websecure"
|
||||||
- "traefik.http.routers.headscale-ui.middlewares=security-chain@file"
|
- "traefik.http.routers.headscale-ui.middlewares=security-chain@file"
|
||||||
|
- "traefik.http.routers.headscale-ui.service=headscale-ui"
|
||||||
- "traefik.http.routers.headscale-ui.tls=true"
|
- "traefik.http.routers.headscale-ui.tls=true"
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.headscale-ui-local.rule=Host(`hs.workstation.internal`) && PathPrefix(`/admin`)"
|
- "traefik.http.routers.headscale-ui-local.rule=Host(`hs.workstation.internal`) && PathPrefix(`/admin`)"
|
||||||
- "traefik.http.routers.headscale-ui-local.entrypoints=websecure"
|
- "traefik.http.routers.headscale-ui-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.headscale-ui-local.middlewares=security-chain@file"
|
||||||
|
- "traefik.http.routers.headscale-ui-local.service=headscale-ui"
|
||||||
- "traefik.http.routers.headscale-ui-local.tls=true"
|
- "traefik.http.routers.headscale-ui-local.tls=true"
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.headscale-ui-dev.rule=Host(`hs.gigaforust.internal`) && PathPrefix(`/admin`)"
|
- "traefik.http.routers.headscale-ui-dev.rule=Host(`hs.gigaforust.internal`) && PathPrefix(`/admin`)"
|
||||||
- "traefik.http.routers.headscale-ui-dev.entrypoints=websecure"
|
- "traefik.http.routers.headscale-ui-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.headscale-ui-dev.middlewares=security-chain@file"
|
||||||
|
- "traefik.http.routers.headscale-ui-dev.service=headscale-ui"
|
||||||
- "traefik.http.routers.headscale-ui-dev.tls=true"
|
- "traefik.http.routers.headscale-ui-dev.tls=true"
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
volumes:
|
|
||||||
data:
|
|
||||||
headplane-data:
|
|
||||||
name: headplane_data
|
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -1,221 +0,0 @@
|
|||||||
# Configuration for the Headplane server and web application
|
|
||||||
server:
|
|
||||||
# These are the default values, change them as needed
|
|
||||||
host: "0.0.0.0"
|
|
||||||
port: 3000
|
|
||||||
# Should not include the dashboard prefix (/admin) portion.
|
|
||||||
# # Prod server_url
|
|
||||||
# base_url: https://hs.forust.xyz
|
|
||||||
# # Local base_url
|
|
||||||
# base_url: https://hs.workstation.internal
|
|
||||||
# # Dev base_url
|
|
||||||
# base_url: https://hs.gigaforust.internal
|
|
||||||
|
|
||||||
# You may provide `cookie_secret_path` instead to read a value from disk.
|
|
||||||
# See https://headplane.net/configuration/#sensitive-values
|
|
||||||
cookie_secret: "<change_me_to_something_secure!>"
|
|
||||||
|
|
||||||
# Whether cookies should be marked as Secure
|
|
||||||
# * Should be false if running without HTTPs
|
|
||||||
# * Should be true if running behind a reverse proxy with HTTPs
|
|
||||||
cookie_secure: true
|
|
||||||
# The maximum age of the session cookie in seconds
|
|
||||||
cookie_max_age: 86400 # 1 day in seconds
|
|
||||||
|
|
||||||
# This is not required, but if you want to restrict the cookie
|
|
||||||
# to a specific domain, set it here. Otherwise leave it commented out.
|
|
||||||
# This may not work as expected if not using a reverse proxy.
|
|
||||||
# cookie_domain: ""
|
|
||||||
|
|
||||||
# The path to persist Headplane specific data. All data going forward
|
|
||||||
# is stored in this directory, including the internal database and
|
|
||||||
# any cache related files.
|
|
||||||
data_path: "/var/lib/headplane"
|
|
||||||
|
|
||||||
# The info secret is optional and allows access to certain debug endpoints
|
|
||||||
# that may expose sensitive information about your Headplane instance.
|
|
||||||
#
|
|
||||||
# As of now, this protects the /api/info endpoint which exposes details about
|
|
||||||
# the Headplane and Headscale versions in use. In the future, more endpoints
|
|
||||||
# may be protected by this secret.
|
|
||||||
#
|
|
||||||
# If not set, these endpoints will be disabled.
|
|
||||||
# info_secret: "<change_me_to_something_secure!>"
|
|
||||||
|
|
||||||
# Headscale specific settings to allow Headplane to talk
|
|
||||||
# to Headscale and access deep integration features
|
|
||||||
headscale:
|
|
||||||
# The URL to your Headscale instance
|
|
||||||
# (All API requests are routed through this URL)
|
|
||||||
# (THIS IS NOT the gRPC endpoint, but the HTTP endpoint)
|
|
||||||
#
|
|
||||||
# IMPORTANT: If you are using TLS this MUST be set to `https://`
|
|
||||||
url: "http://headscale-server:8080"
|
|
||||||
|
|
||||||
# If you use the TLS configuration in Headscale, and you are not using
|
|
||||||
# Let's Encrypt for your certificate, pass in the path to the certificate.
|
|
||||||
# (This has no effect if `url` does not start with `https://`)
|
|
||||||
# tls_cert_path: "/var/lib/headplane/tls.crt"
|
|
||||||
|
|
||||||
# Optional, public URL if its different from the `headscale.url`
|
|
||||||
# This affects certain parts of the web UI which shows Headscale's URL
|
|
||||||
public_url: "https://headscale.example.com"
|
|
||||||
|
|
||||||
# Path to the Headscale configuration file
|
|
||||||
# This is optional, but HIGHLY recommended for the best experience
|
|
||||||
# If this is read only, Headplane will show your configuration settings
|
|
||||||
# in the Web UI, but they cannot be changed.
|
|
||||||
config_path: "/etc/headscale/config.yaml"
|
|
||||||
|
|
||||||
# Whether the Headscale configuration should be strictly validated
|
|
||||||
# when reading from `config_path`. If true, Headplane will not interact
|
|
||||||
# with Headscale if there are any issues with the configuration file.
|
|
||||||
#
|
|
||||||
# This is recommended to be true for production deployments to, however it
|
|
||||||
# may not work if you are using a version of Headscale that has configuration
|
|
||||||
# options unknown to Headplane.
|
|
||||||
config_strict: true
|
|
||||||
|
|
||||||
# If you are using `dns.extra_records_path` in your Headscale
|
|
||||||
# configuration, you need to set this to the path for Headplane
|
|
||||||
# to be able to read the DNS records.
|
|
||||||
#
|
|
||||||
# Pass it in if using Docker and ensure that the file is both
|
|
||||||
# readable and writable to the Headplane process.
|
|
||||||
# When using this, Headplane will no longer need to automatically
|
|
||||||
# restart Headscale for DNS record changes.
|
|
||||||
# dns_records_path: "/var/lib/headscale/extra_records.json"
|
|
||||||
|
|
||||||
# Integration configurations for Headplane to interact with Headscale
|
|
||||||
integration:
|
|
||||||
# The Headplane agent allows retrieving information about nodes
|
|
||||||
# This allows the UI to display version, OS, and connectivity data
|
|
||||||
# You will see the Headplane agent in your Tailnet as a node when
|
|
||||||
# it connects.
|
|
||||||
agent:
|
|
||||||
enabled: false
|
|
||||||
|
|
||||||
# To connect to your Tailnet, you need to generate a pre-auth key
|
|
||||||
# This can be done via the web UI or through the `headscale` CLI.
|
|
||||||
pre_authkey: "<your-preauth-key>"
|
|
||||||
|
|
||||||
# Optionally change the name of the agent in the Tailnet.
|
|
||||||
# host_name: "headplane-agent"
|
|
||||||
|
|
||||||
# Configure different caching settings. By default, the agent will store
|
|
||||||
# caches in the path below for a maximum of 1 minute. If you want data
|
|
||||||
# to update faster, reduce the TTL, but this will increase the frequency
|
|
||||||
# of requests to Headscale.
|
|
||||||
# cache_ttl: 60
|
|
||||||
# cache_path: /var/lib/headplane/agent_cache.json
|
|
||||||
|
|
||||||
# The work_dir represents where the agent will store its data to be able
|
|
||||||
# to automatically reauthenticate with your Tailnet. It needs to be
|
|
||||||
# writable by the user running the Headplane process.
|
|
||||||
#
|
|
||||||
# If using Docker, it is best to leave this as the default.
|
|
||||||
# work_dir: "/var/lib/headplane/agent"
|
|
||||||
|
|
||||||
# Only one of these should be enabled at a time or you will get errors
|
|
||||||
# This does not include the agent integration (above), which can be enabled
|
|
||||||
# at the same time as any of these and is recommended for the best experience.
|
|
||||||
docker:
|
|
||||||
enabled: true
|
|
||||||
|
|
||||||
# By default we check for the presence of a container label (see the docs)
|
|
||||||
# to determine the container to signal when changes are made to DNS settings.
|
|
||||||
container_label: "me.tale.headplane.target=headscale"
|
|
||||||
|
|
||||||
# HOWEVER, you can fallback to a container name if you desire, but this is
|
|
||||||
# not recommended as its brittle and doesn't work with orchestrators that
|
|
||||||
# automatically assign container names.
|
|
||||||
#
|
|
||||||
# If `container_name` is set, it will override any label checks.
|
|
||||||
# container_name: "headscale-server"
|
|
||||||
|
|
||||||
# The path to the Docker socket (do not change this if you are unsure)
|
|
||||||
# Docker socket paths must start with unix:// or tcp:// and at the moment
|
|
||||||
# https connections are not supported.
|
|
||||||
socket: "unix:///var/run/docker.sock"
|
|
||||||
|
|
||||||
# Please refer to docs/integration/Kubernetes.md for more information
|
|
||||||
# on how to configure the Kubernetes integration. There are requirements in
|
|
||||||
# order to allow Headscale to be controlled by Headplane in a cluster.
|
|
||||||
kubernetes:
|
|
||||||
enabled: false
|
|
||||||
# Validates the manifest for the Pod to ensure all of the criteria
|
|
||||||
# are set correctly. Turn this off if you are having issues with
|
|
||||||
# shareProcessNamespace not being validated correctly.
|
|
||||||
validate_manifest: true
|
|
||||||
# This should be the name of the Pod running Headscale and Headplane.
|
|
||||||
# If this isn't static you should be using the Kubernetes Downward API
|
|
||||||
# to set this value (refer to docs/Integrated-Mode.md for more info).
|
|
||||||
pod_name: "headscale"
|
|
||||||
|
|
||||||
# Proc is the "Native" integration that only works when Headscale and
|
|
||||||
# Headplane are running outside of a container. There is no configuration,
|
|
||||||
# but you need to ensure that the Headplane process can terminate the
|
|
||||||
# Headscale process.
|
|
||||||
#
|
|
||||||
# (If they are both running under systemd as sudo, this will work).
|
|
||||||
proc:
|
|
||||||
enabled: false
|
|
||||||
|
|
||||||
# OIDC Configuration for simpler authentication
|
|
||||||
# (This is optional, but recommended for the best experience)
|
|
||||||
# oidc:
|
|
||||||
# The OIDC issuer URL
|
|
||||||
# issuer: "https://accounts.google.com"
|
|
||||||
|
|
||||||
# If you are using OIDC, you need to generate an API key
|
|
||||||
# that can be used to authenticate other sessions when signing in.
|
|
||||||
#
|
|
||||||
# This can be done with `headscale apikeys create --expiration 999d`
|
|
||||||
# headscale_api_key: "<your-headscale-api-key>"
|
|
||||||
|
|
||||||
# If your OIDC provider does not support discovery (does not have the URL at
|
|
||||||
# `/.well-known/openid-configuration`), you need to manually set endpoints.
|
|
||||||
# This also works to override endpoints if you so desire or if your OIDC
|
|
||||||
# discovery is missing certain endpoints (ie GitHub).
|
|
||||||
# For some typical providers, see https://headplane.net/features/sso.
|
|
||||||
# authorization_endpoint: ""
|
|
||||||
# token_endpoint: ""
|
|
||||||
# userinfo_endpoint: ""
|
|
||||||
|
|
||||||
# The authentication method to use when communicating with the token endpoint.
|
|
||||||
# This is fully optional and Headplane will attempt to auto-detect the best
|
|
||||||
# method and fall back to `client_secret_basic` if unsure.
|
|
||||||
# token_endpoint_auth_method: "client_secret_post"
|
|
||||||
|
|
||||||
# The client ID for the OIDC client
|
|
||||||
# For the best experience please ensure this is *identical* to the client_id
|
|
||||||
# you are using for Headscale. because
|
|
||||||
# client_id: "your-client-id"
|
|
||||||
|
|
||||||
# The client secret for the OIDC client
|
|
||||||
# You may also provide `client_secret_path` instead to read a value from disk.
|
|
||||||
# See https://headplane.net/configuration/#sensitive-values
|
|
||||||
# client_secret: "<your-client-secret>"
|
|
||||||
|
|
||||||
# Whether to use PKCE when authenticating users. This is recommended as it
|
|
||||||
# adds an extra layer of security to the authentication process. Enabling this
|
|
||||||
# means your OIDC provider must support PKCE and it must be enabled on the
|
|
||||||
# client.
|
|
||||||
# use_pkce: true
|
|
||||||
|
|
||||||
# If you want to disable traditional login via Headscale API keys
|
|
||||||
# disable_api_key_login: false
|
|
||||||
|
|
||||||
# By default profile pictures are pulled from the OIDC provider when
|
|
||||||
# we go to fetch the userinfo endpoint. Optionally, this can be set to
|
|
||||||
# "oidc" or "gravatar" as of 0.6.1.
|
|
||||||
# profile_picture_source: "gravatar"
|
|
||||||
|
|
||||||
# The scopes to request when authenticating users. The default is below.
|
|
||||||
# scope: "openid email profile"
|
|
||||||
|
|
||||||
# Extra query parameters can be passed to the authorization endpoint
|
|
||||||
# by setting them here. This is useful for providers that require any kind
|
|
||||||
# of custom hinting.
|
|
||||||
# extra_params:
|
|
||||||
# prompt: "select_account" # Example: force account selection on Google
|
|
||||||
@@ -1,26 +0,0 @@
|
|||||||
{
|
|
||||||
"groups": {
|
|
||||||
"group:admin": [
|
|
||||||
"admin@"
|
|
||||||
],
|
|
||||||
"group:users": []
|
|
||||||
},
|
|
||||||
"tagOwners": {},
|
|
||||||
"hosts": {},
|
|
||||||
"acls": [
|
|
||||||
{
|
|
||||||
"#ha-meta": {
|
|
||||||
"name": "users",
|
|
||||||
"open": true
|
|
||||||
},
|
|
||||||
"action": "accept",
|
|
||||||
"src": [
|
|
||||||
"autogroup:member"
|
|
||||||
],
|
|
||||||
"dst": [
|
|
||||||
"autogroup:self:*"
|
|
||||||
]
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"ssh": []
|
|
||||||
}
|
|
||||||
@@ -12,48 +12,71 @@ services:
|
|||||||
- proxy
|
- proxy
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
|
- "traefik.docker.network=proxy"
|
||||||
|
|
||||||
|
# Services
|
||||||
- "traefik.http.services.forust-homepage.loadbalancer.server.port=80"
|
- "traefik.http.services.forust-homepage.loadbalancer.server.port=80"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.forust-homepage.rule=Host(`forust.xyz`)"
|
- "traefik.http.routers.forust-homepage.rule=Host(`forust.xyz`)"
|
||||||
- "traefik.http.routers.forust-homepage.entrypoints=websecure"
|
- "traefik.http.routers.forust-homepage.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.forust-homepage.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.forust-homepage.service=forust-homepage"
|
||||||
- "traefik.http.routers.forust-homepage.tls=true"
|
- "traefik.http.routers.forust-homepage.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.forust-homepage-local.rule=Host(`landing.workstation.internal`)"
|
- "traefik.http.routers.forust-homepage-local.rule=Host(`landing.workstation.internal`) || Host(`landing.internal`)"
|
||||||
- "traefik.http.routers.forust-homepage-local.entrypoints=websecure"
|
- "traefik.http.routers.forust-homepage-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.forust-homepage-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.forust-homepage-local.service=forust-homepage"
|
||||||
- "traefik.http.routers.forust-homepage-local.tls=true"
|
- "traefik.http.routers.forust-homepage-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.forust-homepage-dev.rule=Host(`landing.gigaforust.internal`)"
|
- "traefik.http.routers.forust-homepage-dev.rule=Host(`landing.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.forust-homepage-dev.entrypoints=websecure"
|
- "traefik.http.routers.forust-homepage-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.forust-homepage-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.forust-homepage-dev.service=forust-homepage"
|
||||||
- "traefik.http.routers.forust-homepage-dev.tls=true"
|
- "traefik.http.routers.forust-homepage-dev.tls=true"
|
||||||
|
|
||||||
xdfnx:
|
xdfnx:
|
||||||
build:
|
build:
|
||||||
context: .
|
context: .
|
||||||
dockerfile: Dockerfile.xdfnx
|
dockerfile: Dockerfile.xdfnx
|
||||||
restart: unless-stopped
|
|
||||||
# ports:
|
# ports:
|
||||||
# - "8086:80"
|
# - "8086:80"
|
||||||
|
restart: unless-stopped
|
||||||
volumes:
|
volumes:
|
||||||
- ./xdfnx_files:/usr/share/nginx/html
|
- ./xdfnx_files:/usr/share/nginx/html
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
|
- "traefik.docker.network=proxy"
|
||||||
|
|
||||||
|
# Services
|
||||||
- "traefik.http.services.xdfnx-homepage.loadbalancer.server.port=80"
|
- "traefik.http.services.xdfnx-homepage.loadbalancer.server.port=80"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.xdfnx.rule=Host(`xdfnx.cfd`)"
|
- "traefik.http.routers.xdfnx.rule=Host(`xdfnx.cfd`)"
|
||||||
- "traefik.http.routers.xdfnx.entrypoints=websecure"
|
- "traefik.http.routers.xdfnx.entrypoints=websecure"
|
||||||
- "traefik.http.routers.xdfnx.tls.certresolver=letsencrypt"
|
- "traefik.http.routers.xdfnx.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.xdfnx.service=xdfnx-homepage"
|
||||||
- "traefik.http.routers.xdfnx.tls=true"
|
- "traefik.http.routers.xdfnx.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.xdfnx-local.rule=Host(`xdfnx.workstation.internal`)"
|
- "traefik.http.routers.xdfnx-local.rule=Host(`xdfnx.workstation.internal`) || Host(`xdfnx.internal`)"
|
||||||
- "traefik.http.routers.xdfnx-local.entrypoints=websecure"
|
- "traefik.http.routers.xdfnx-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.xdfnx-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.xdfnx-local.service=xdfnx-homepage"
|
||||||
- "traefik.http.routers.xdfnx-local.tls=true"
|
- "traefik.http.routers.xdfnx-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.xdfnx-dev.rule=Host(`xdfnx.gigaforust.internal`)"
|
- "traefik.http.routers.xdfnx-dev.rule=Host(`xdfnx.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.xdfnx-dev.entrypoints=websecure"
|
- "traefik.http.routers.xdfnx-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.xdfnx-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.xdfnx-dev.service=xdfnx-homepage"
|
||||||
- "traefik.http.routers.xdfnx-dev.tls=true"
|
- "traefik.http.routers.xdfnx-dev.tls=true"
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
|
Before Width: | Height: | Size: 46 KiB |
|
Before Width: | Height: | Size: 95 KiB |
|
Before Width: | Height: | Size: 14 KiB |
|
Before Width: | Height: | Size: 59 KiB |
|
Before Width: | Height: | Size: 66 KiB |
|
Before Width: | Height: | Size: 43 KiB |
|
Before Width: | Height: | Size: 61 KiB |
@@ -41,7 +41,7 @@
|
|||||||
</li>
|
</li>
|
||||||
<li>
|
<li>
|
||||||
<i class="fas fa-envelope"></i>
|
<i class="fas fa-envelope"></i>
|
||||||
<a href="mailto:contact@forust.xyz">mail/contact@forust.xyz</a>
|
<a href="mailto:forust@forust.xyz">mail/contact@forust.xyz</a>
|
||||||
</li>
|
</li>
|
||||||
<li>
|
<li>
|
||||||
<i class="fa-solid fa-key"></i>
|
<i class="fa-solid fa-key"></i>
|
||||||
@@ -116,7 +116,7 @@
|
|||||||
<div class="avatar"
|
<div class="avatar"
|
||||||
style="background-image: url('assets/images/team/anna.jpg'); background-size: cover; background-position: center;">
|
style="background-image: url('assets/images/team/anna.jpg'); background-size: cover; background-position: center;">
|
||||||
</div>
|
</div>
|
||||||
<a href="./assets/images/love.png" target="_blank">Anna~</a>
|
<a href="" target="_blank">Anna~</a>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="member">
|
<div class="member">
|
||||||
|
|||||||
@@ -1,54 +0,0 @@
|
|||||||
# Resolved: Overlay FS failure (and so containers)
|
|
||||||
|
|
||||||
15-12-2025 03:02 AM EET: Degraded control panels' performances, following by full cascade docker failure
|
|
||||||
|
|
||||||
15-12-2025 04:36 AM EET: Identified: Services are terminated due to server software (Overlay FS) + hardware issues (HDD).
|
|
||||||
|
|
||||||
15-12-2025 08:45 PM EET: Restored NextCloud service with few tweaks to lower I/O
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
16-12-2025 08:34 PM EET: Ordered new HDD, ETA 22nd of December - 2nd of January
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
17-12-2025 02:47 AM EET: To avoid additional I/O into kuma's database, disabled uptime monitoring for non-critical services, such as:
|
|
||||||
|
|
||||||
- Game servers
|
|
||||||
- Gitea (no public projects being hosted yet)
|
|
||||||
- Landings
|
|
||||||
- Cloud services
|
|
||||||
- PenPot
|
|
||||||
- Auth provider
|
|
||||||
- Secondary management tools
|
|
||||||
- Chernuha's non-important infrastructure
|
|
||||||
|
|
||||||
These can be identified by seeing ">2m ago" under monitor's heartbeats.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
09-01-2026 02:32 PM EET: NextCloud's frontend files are corrupted due to the unknown issue. All user data is integrity-verified. To prevent user data corruption, NextCloud service will be restored after new hardware will be available.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
14-01-2026 08:42 PM EET: After planned updating and restarting server, critical firmware software were corrupted because of physical degradation of the disk. Server inaccessible in any way
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
15-01-2026 11:30 AM EET: A new NAS-Grade HDD (Seagate IronWolf Pro) was ordered. ETA 16-01-2026 EET Before 12:00 PM
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
16-01-2026 12:47 AM EET: New server system is installed, data backed up. Experiencing docker memory leak.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
17-01-2026 01:27 PM EET: All services except NextCloud and Satisfactory server are online.
|
|
||||||
|
|
||||||
17-01-2026 03:48 PM EET: Nextcloud is online. Satisfactory will be provided on-demand. Monitoring status
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
##### Status: All services are online
|
|
||||||
|
|
||||||
**Solution: moving all infrastructure onto new NAS-Grade HDD with fresh OS install**
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
KENER_SECRET_KEY=your_secret_key_here
|
|
||||||
ORIGIN=http://localhost:3000
|
|
||||||
TZ=Etc/UTC
|
|
||||||
@@ -1,59 +0,0 @@
|
|||||||
services:
|
|
||||||
kener:
|
|
||||||
image: rajnandan1/kener:4.0.23
|
|
||||||
container_name: kener
|
|
||||||
restart: unless-stopped
|
|
||||||
# ports:
|
|
||||||
# - 3000:3000/tcp
|
|
||||||
environment:
|
|
||||||
- KENER_SECRET_KEY=${KENER_SECRET_KEY?Kener requires a secret key}
|
|
||||||
- ORIGIN=${ORIGIN:-http://localhost:3000}
|
|
||||||
- REDIS_URL=redis://redis:6379
|
|
||||||
- TZ:${TZ:-Etc/UTC}
|
|
||||||
depends_on:
|
|
||||||
redis:
|
|
||||||
condition: service_healthy
|
|
||||||
volumes:
|
|
||||||
- db:/app/database
|
|
||||||
- uploads:/app/uploads
|
|
||||||
labels:
|
|
||||||
- "traefik.enable=true"
|
|
||||||
- "traefik.http.services.kener.loadbalancer.server.port=3000"
|
|
||||||
|
|
||||||
# Prod Router
|
|
||||||
- "traefik.http.routers.kener.rule=Host(`status.forust.xyz`)"
|
|
||||||
- "traefik.http.routers.kener.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.kener.tls=true"
|
|
||||||
# Local Router
|
|
||||||
- "traefik.http.routers.kener-local.rule=Host(`status.workstation.internal`)"
|
|
||||||
- "traefik.http.routers.kener-local.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.kener-local.tls=true"
|
|
||||||
# Dev Router
|
|
||||||
- "traefik.http.routers.kener-dev.rule=Host(`status.gigaforust.internal`)"
|
|
||||||
- "traefik.http.routers.kener-dev.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.kener-dev.tls=true"
|
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
- kener
|
|
||||||
redis:
|
|
||||||
image: redis:7-alpine
|
|
||||||
container_name: kener-redis
|
|
||||||
restart: unless-stopped
|
|
||||||
volumes:
|
|
||||||
- redis:/data
|
|
||||||
healthcheck:
|
|
||||||
test: [ "CMD", "redis-cli", "ping" ]
|
|
||||||
interval: 6s
|
|
||||||
timeout: 5s
|
|
||||||
retries: 5
|
|
||||||
networks:
|
|
||||||
- kener
|
|
||||||
volumes:
|
|
||||||
db:
|
|
||||||
uploads:
|
|
||||||
redis:
|
|
||||||
networks:
|
|
||||||
proxy:
|
|
||||||
external: true
|
|
||||||
kener:
|
|
||||||
external: false
|
|
||||||
@@ -1,7 +1,7 @@
|
|||||||
services:
|
services:
|
||||||
metube:
|
metube:
|
||||||
image: ghcr.io/alexta69/metube
|
image: ghcr.io/alexta69/metube
|
||||||
container_name: metube
|
# container_name: metube
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
# ports:
|
# ports:
|
||||||
# - "8081:8081"
|
# - "8081:8081"
|
||||||
@@ -13,22 +13,31 @@ services:
|
|||||||
volumes:
|
volumes:
|
||||||
- ./MeTube_downloads:/downloads
|
- ./MeTube_downloads:/downloads
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- traefik.enable=true
|
||||||
- "traefik.http.services.metube.loadbalancer.server.port=8081"
|
- "traefik.docker.network=proxy"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.metube.rule=Host(`metube.forust.xyz`)"
|
- "traefik.http.routers.metube.rule=Host(`metube.forust.xyz`)"
|
||||||
- "traefik.http.routers.metube.entrypoints=websecure"
|
- "traefik.http.routers.metube.entrypoints=websecure"
|
||||||
- "traefik.http.routers.metube.middlewares=security-chain@file"
|
- "traefik.http.routers.metube.middlewares=security-chain@file"
|
||||||
|
- "traefik.http.routers.metube.service=metube"
|
||||||
- "traefik.http.routers.metube.tls=true"
|
- "traefik.http.routers.metube.tls=true"
|
||||||
|
- "traefik.http.services.metube.loadbalancer.server.port=8081"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.metube-local.rule=Host(`metube.workstation.internal`)"
|
- "traefik.http.routers.metube-local.rule=Host(`metube.workstation.internal`) || Host(`metube.internal`)"
|
||||||
- "traefik.http.routers.metube-local.entrypoints=websecure"
|
- "traefik.http.routers.metube-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.metube-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.metube-local.service=metube"
|
||||||
- "traefik.http.routers.metube-local.tls=true"
|
- "traefik.http.routers.metube-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.metube-dev.rule=Host(`metube.gigaforust.internal`)"
|
- "traefik.http.routers.metube-dev.rule=Host(`metube.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.metube-dev.entrypoints=websecure"
|
- "traefik.http.routers.metube-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.metube-dev.middlewares=security-chain@file"
|
||||||
|
- "traefik.http.routers.metube-dev.service=metube"
|
||||||
- "traefik.http.routers.metube-dev.tls=true"
|
- "traefik.http.routers.metube-dev.tls=true"
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
networks:
|
networks:
|
||||||
|
|||||||
@@ -13,8 +13,8 @@ services:
|
|||||||
- N8N_SECURE_COOKIE=false
|
- N8N_SECURE_COOKIE=false
|
||||||
- N8N_COMMUNITY_PACKAGES_ALLOW_TOOL_USAGE=true
|
- N8N_COMMUNITY_PACKAGES_ALLOW_TOOL_USAGE=true
|
||||||
volumes:
|
volumes:
|
||||||
- node-data:/home/node/.n8n
|
- ./n8n-node-data:/home/node/.n8n
|
||||||
- files:/files
|
- ./n8n-files:/files
|
||||||
extra_hosts:
|
extra_hosts:
|
||||||
- "enterprise.n8n.io:104.26.13.187"
|
- "enterprise.n8n.io:104.26.13.187"
|
||||||
- "enterprise.n8n.io:104.26.12.187"
|
- "enterprise.n8n.io:104.26.12.187"
|
||||||
@@ -27,19 +27,28 @@ services:
|
|||||||
- n8n
|
- n8n
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.http.services.n8n.loadbalancer.server.port=5678"
|
- "traefik.docker.network=proxy"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.n8n.rule=Host(`n8n.forust.xyz`)"
|
- "traefik.http.routers.n8n.rule=Host(`n8n.forust.xyz`)"
|
||||||
- "traefik.http.routers.n8n.entrypoints=websecure"
|
- "traefik.http.routers.n8n.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.n8n.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.n8n.service=n8n"
|
||||||
- "traefik.http.routers.n8n.tls=true"
|
- "traefik.http.routers.n8n.tls=true"
|
||||||
|
- "traefik.http.services.n8n.loadbalancer.server.port=5678"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.n8n-local.rule=Host(`n8n.workstation.internal`)"
|
- "traefik.http.routers.n8n-local.rule=Host(`n8n.workstation.internal`) || Host(`n8n.internal`)"
|
||||||
- "traefik.http.routers.n8n-local.entrypoints=websecure"
|
- "traefik.http.routers.n8n-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.n8n-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.n8n-local.service=n8n"
|
||||||
- "traefik.http.routers.n8n-local.tls=true"
|
- "traefik.http.routers.n8n-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.n8n-dev.rule=Host(`n8n.gigaforust.internal`)"
|
- "traefik.http.routers.n8n-dev.rule=Host(`n8n.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.n8n-dev.entrypoints=websecure"
|
- "traefik.http.routers.n8n-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.n8n-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.n8n-dev.service=n8n"
|
||||||
- "traefik.http.routers.n8n-dev.tls=true"
|
- "traefik.http.routers.n8n-dev.tls=true"
|
||||||
|
|
||||||
- glance.name=n8n
|
- glance.name=n8n
|
||||||
@@ -51,7 +60,3 @@ networks:
|
|||||||
external: false
|
external: false
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|
||||||
volumes:
|
|
||||||
node-data:
|
|
||||||
files:
|
|
||||||
@@ -1,29 +0,0 @@
|
|||||||
## https://github.com/autobrr/netronome?tab=readme-ov-file#environment-variables
|
|
||||||
|
|
||||||
# Server settings
|
|
||||||
NETRONOME__HOST=0.0.0.0 # Listen address
|
|
||||||
NETRONOME__PORT=7575 # Web UI port
|
|
||||||
NETRONOME__BASE_URL=/netronome # Base URL for reverse proxy
|
|
||||||
|
|
||||||
# Database (SQLite by default)
|
|
||||||
NETRONOME__DB_TYPE=postgres # sqlite or postgres
|
|
||||||
NETRONOME__DB_PATH=netronome.db # SQLite database path
|
|
||||||
|
|
||||||
# PostgreSQL (when DB_TYPE=postgres)
|
|
||||||
NETRONOME__DB_TYPE=postgres
|
|
||||||
NETRONOME__DB_HOST=postgres
|
|
||||||
NETRONOME__DB_PORT=5432
|
|
||||||
NETRONOME__DB_USER=netronome
|
|
||||||
NETRONOME__DB_PASSWORD=netronome
|
|
||||||
NETRONOME__DB_NAME=netronome
|
|
||||||
NETRONOME__DB_SSLMODE=disable
|
|
||||||
|
|
||||||
# Authentication
|
|
||||||
NETRONOME__AUTH_WHITELIST=127.0.0.1/32,192.168.1.0/24 # IP whitelist (comma-separated)
|
|
||||||
NETRONOME__SESSION_SECRET= # Session secret (auto-generated if empty)
|
|
||||||
|
|
||||||
# OIDC (optional)
|
|
||||||
NETRONOME__OIDC_ISSUER=https://accounts.google.com
|
|
||||||
NETRONOME__OIDC_CLIENT_ID=your-client-id
|
|
||||||
NETRONOME__OIDC_CLIENT_SECRET=your-secret
|
|
||||||
NETRONOME__OIDC_REDIRECT_URL=https://example.com/api/auth/oidc/callback
|
|
||||||
@@ -1,59 +0,0 @@
|
|||||||
services:
|
|
||||||
netronome:
|
|
||||||
image: ghcr.io/autobrr/netronome:latest
|
|
||||||
restart: unless-stopped
|
|
||||||
container_name: netronome
|
|
||||||
ports:
|
|
||||||
- "7575:7575"
|
|
||||||
cap_add:
|
|
||||||
- NET_RAW
|
|
||||||
env_file:
|
|
||||||
- .env
|
|
||||||
labels:
|
|
||||||
- "traefik.enable=true"
|
|
||||||
- "traefik.http.services.netronome.loadbalancer.server.port=7575"
|
|
||||||
|
|
||||||
# Prod Router
|
|
||||||
- "traefik.http.routers.netronome.rule=Host(`nm.forust.xyz`)"
|
|
||||||
- "traefik.http.routers.netronome.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.netronome.tls=true"
|
|
||||||
# Local Router
|
|
||||||
- "traefik.http.routers.netronome-local.rule=Host(`nm.workstation.internal`)"
|
|
||||||
- "traefik.http.routers.netronome-local.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.netronome-local.tls=true"
|
|
||||||
# Dev Router
|
|
||||||
- "traefik.http.routers.netronome-dev.rule=Host(`nm.gigaforust.internal`)"
|
|
||||||
- "traefik.http.routers.netronome-dev.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.netronome-dev.tls=true"
|
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
- netronome
|
|
||||||
depends_on:
|
|
||||||
postgres:
|
|
||||||
condition: service_healthy
|
|
||||||
postgres:
|
|
||||||
container_name: netronome-postgres
|
|
||||||
image: postgres:17-alpine
|
|
||||||
environment:
|
|
||||||
- POSTGRES_USER=netronome
|
|
||||||
- POSTGRES_PASSWORD=netronome
|
|
||||||
- POSTGRES_DB=netronome
|
|
||||||
volumes:
|
|
||||||
- data:/var/lib/postgresql/data
|
|
||||||
healthcheck:
|
|
||||||
test: [ "CMD-SHELL", "pg_isready -U netronome" ]
|
|
||||||
interval: 5s
|
|
||||||
timeout: 5s
|
|
||||||
retries: 5
|
|
||||||
restart: unless-stopped
|
|
||||||
networks:
|
|
||||||
- netronome
|
|
||||||
volumes:
|
|
||||||
data:
|
|
||||||
|
|
||||||
|
|
||||||
networks:
|
|
||||||
proxy:
|
|
||||||
external: true
|
|
||||||
netronome:
|
|
||||||
external: false
|
|
||||||
@@ -7,7 +7,6 @@ services:
|
|||||||
volumes:
|
volumes:
|
||||||
- nextcloud_aio_mastercontainer:/mnt/docker-aio-config # Do not change (backup)
|
- nextcloud_aio_mastercontainer:/mnt/docker-aio-config # Do not change (backup)
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
- /dev/dri:/dev/dri
|
|
||||||
networks:
|
networks:
|
||||||
- nextcloud-aio
|
- nextcloud-aio
|
||||||
- proxy # Optional: Connects the mastercontainer to the proxy network in order to make the built-in reverse proxy detection work. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
- proxy # Optional: Connects the mastercontainer to the proxy network in order to make the built-in reverse proxy detection work. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||||
@@ -18,6 +17,8 @@ services:
|
|||||||
|
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
|
- "traefik.docker.network=proxy"
|
||||||
|
|
||||||
# AIO Services configuration
|
# AIO Services configuration
|
||||||
- "traefik.http.services.nextcloud-aio.loadbalancer.server.port=8080"
|
- "traefik.http.services.nextcloud-aio.loadbalancer.server.port=8080"
|
||||||
- "traefik.http.services.nextcloud-aio.loadbalancer.server.scheme=https"
|
- "traefik.http.services.nextcloud-aio.loadbalancer.server.scheme=https"
|
||||||
@@ -27,20 +28,29 @@ services:
|
|||||||
# - "traefik.http.routers.nextcloud-aio.rule=Host(`naio.forust.xyz`)"
|
# - "traefik.http.routers.nextcloud-aio.rule=Host(`naio.forust.xyz`)"
|
||||||
# - "traefik.http.routers.nextcloud-aio.entrypoints=websecure"
|
# - "traefik.http.routers.nextcloud-aio.entrypoints=websecure"
|
||||||
# - "traefik.http.routers.nextcloud-aio.middlewares=security-chain@file"
|
# - "traefik.http.routers.nextcloud-aio.middlewares=security-chain@file"
|
||||||
|
# - "traefik.http.routers.nextcloud-aio.service=nextcloud-aio"
|
||||||
# - "traefik.http.routers.nextcloud-aio.tls=true"
|
# - "traefik.http.routers.nextcloud-aio.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.nextcloud-aio-local.rule=Host(`naio.workstation.internal`)"
|
- "traefik.http.routers.nextcloud-aio-local.rule=Host(`naio.workstation.internal`) || Host(`nextcloud-aio.internal`)"
|
||||||
- "traefik.http.routers.nextcloud-aio-local.entrypoints=websecure"
|
- "traefik.http.routers.nextcloud-aio-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.nextcloud-aio-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.nextcloud-aio-local.service=nextcloud-aio"
|
||||||
- "traefik.http.routers.nextcloud-aio-local.tls=true"
|
- "traefik.http.routers.nextcloud-aio-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.nextcloud-aio-dev.rule=Host(`naio.gigaforust.internal`)"
|
- "traefik.http.routers.nextcloud-aio-dev.rule=Host(`naio.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.nextcloud-aio-dev.entrypoints=websecure"
|
- "traefik.http.routers.nextcloud-aio-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.nextcloud-aio-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.nextcloud-aio-dev.service=nextcloud-aio"
|
||||||
- "traefik.http.routers.nextcloud-aio-dev.tls=true"
|
- "traefik.http.routers.nextcloud-aio-dev.tls=true"
|
||||||
|
|
||||||
# Glance Metadata
|
# Glanceapp/glance config
|
||||||
- glance.name=Nextcloud
|
- glance.name=Nextcloud
|
||||||
|
# - glance.icon=si:nextcloud
|
||||||
- glance.url=https://nextcloud.forust.xyz/
|
- glance.url=https://nextcloud.forust.xyz/
|
||||||
- glance.description=Nextcloud is a suite of client-server software for creating and using file hosting services.
|
- glance.description=Nextcloud is a suite of client-server software for creating and using file hosting services.
|
||||||
|
|
||||||
environment:
|
environment:
|
||||||
AIO_DISABLE_BACKUP_SECTION: false
|
AIO_DISABLE_BACKUP_SECTION: false
|
||||||
APACHE_PORT: 11000 # Is needed when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else). See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
APACHE_PORT: 11000 # Is needed when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else). See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||||
@@ -58,7 +68,7 @@ services:
|
|||||||
NEXTCLOUD_STARTUP_APPS: deck twofactor_totp tasks calendar contacts notes # Allows to modify the Nextcloud apps that are installed on starting AIO the first time. See https://github.com/nextcloud/all-in-one#how-to-change-the-nextcloud-apps-that-are-installed-on-the-first-startup
|
NEXTCLOUD_STARTUP_APPS: deck twofactor_totp tasks calendar contacts notes # Allows to modify the Nextcloud apps that are installed on starting AIO the first time. See https://github.com/nextcloud/all-in-one#how-to-change-the-nextcloud-apps-that-are-installed-on-the-first-startup
|
||||||
NEXTCLOUD_ADDITIONAL_APKS: imagemagick # This allows to add additional packages to the Nextcloud container permanently. Default is imagemagick but can be overwritten by modifying this value. See https://github.com/nextcloud/all-in-one#how-to-add-os-packages-permanently-to-the-nextcloud-container
|
NEXTCLOUD_ADDITIONAL_APKS: imagemagick # This allows to add additional packages to the Nextcloud container permanently. Default is imagemagick but can be overwritten by modifying this value. See https://github.com/nextcloud/all-in-one#how-to-add-os-packages-permanently-to-the-nextcloud-container
|
||||||
NEXTCLOUD_ADDITIONAL_PHP_EXTENSIONS: imagick # dditional php extensions to the Nextcloud container permanently. Default is imagick but can be overwritten by modifying this value. See https://github.com/nextcloud/all-in-one#how-to-add-php-extensions-permanently-to-the-nextcloud-container
|
NEXTCLOUD_ADDITIONAL_PHP_EXTENSIONS: imagick # dditional php extensions to the Nextcloud container permanently. Default is imagick but can be overwritten by modifying this value. See https://github.com/nextcloud/all-in-one#how-to-add-php-extensions-permanently-to-the-nextcloud-container
|
||||||
# NEXTCLOUD_ENABLE_DRI_DEVICE: true # This allows to enable the /dev/dri device for containers that profit from it. ⚠️⚠️⚠️ Warning: this only works if the '/dev/dri' device is present on the host! If it should not exist on your host, don't set this to true as otherwise the Nextcloud container will fail to start! See https://github.com/nextcloud/all-in-one#how-to-enable-hardware-acceleration-for-nextcloud
|
NEXTCLOUD_ENABLE_DRI_DEVICE: true # This allows to enable the /dev/dri device for containers that profit from it. ⚠️⚠️⚠️ Warning: this only works if the '/dev/dri' device is present on the host! If it should not exist on your host, don't set this to true as otherwise the Nextcloud container will fail to start! See https://github.com/nextcloud/all-in-one#how-to-enable-hardware-acceleration-for-nextcloud
|
||||||
# NEXTCLOUD_KEEP_DISABLED_APPS: false # Setting this to true will keep Nextcloud apps that are disabled in the AIO interface and not uninstall them if they should be installed. See https://github.com/nextcloud/all-in-one#how-to-keep-disabled-apps
|
# NEXTCLOUD_KEEP_DISABLED_APPS: false # Setting this to true will keep Nextcloud apps that are disabled in the AIO interface and not uninstall them if they should be installed. See https://github.com/nextcloud/all-in-one#how-to-keep-disabled-apps
|
||||||
SKIP_DOMAIN_VALIDATION: true # This should only be set to true if things are correctly configured. See https://github.com/nextcloud/all-in-one?tab=readme-ov-file#how-to-skip-the-domain-validation
|
SKIP_DOMAIN_VALIDATION: true # This should only be set to true if things are correctly configured. See https://github.com/nextcloud/all-in-one?tab=readme-ov-file#how-to-skip-the-domain-validation
|
||||||
# TALK_PORT: 3478 # This a-llows to adjust the port that the talk container is using which is exposed on the host. See https://github.com/nextcloud/all-in-one#how-to-adjust-the-talk-port
|
# TALK_PORT: 3478 # This a-llows to adjust the port that the talk container is using which is exposed on the host. See https://github.com/nextcloud/all-in-one#how-to-adjust-the-talk-port
|
||||||
@@ -68,7 +78,6 @@ networks:
|
|||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
nextcloud-aio:
|
nextcloud-aio:
|
||||||
name: nextcloud-aio
|
|
||||||
driver: bridge
|
driver: bridge
|
||||||
external: false
|
external: false
|
||||||
volumes:
|
volumes:
|
||||||
|
|||||||
@@ -102,22 +102,33 @@ services:
|
|||||||
|
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.http.services.penpot.loadbalancer.server.port=8080"
|
- "traefik.docker.network=proxy"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.penpot.rule=Host(`penpot.forust.xyz`)"
|
- "traefik.http.routers.penpot.rule=Host(`penpot.forust.xyz`)"
|
||||||
- "traefik.http.routers.penpot.entrypoints=websecure"
|
- "traefik.http.routers.penpot.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.penpot.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.penpot.service=penpot"
|
||||||
- "traefik.http.routers.penpot.tls=true"
|
- "traefik.http.routers.penpot.tls=true"
|
||||||
|
- "traefik.http.services.penpot.loadbalancer.server.port=8080"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.penpot-local.rule=Host(`penpot.workstation.internal`)"
|
- "traefik.http.routers.penpot-local.rule=Host(`penpot.workstation.internal`) || Host(`penpot.internal`)"
|
||||||
- "traefik.http.routers.penpot-local.entrypoints=websecure"
|
- "traefik.http.routers.penpot-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.penpot-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.penpot-local.service=penpot"
|
||||||
- "traefik.http.routers.penpot-local.tls=true"
|
- "traefik.http.routers.penpot-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.penpot-dev.rule=Host(`penpot.gigaforust.internal`)"
|
- "traefik.http.routers.penpot-dev.rule=Host(`penpot.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.penpot-dev.entrypoints=websecure"
|
- "traefik.http.routers.penpot-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.penpot-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.penpot-dev.service=penpot"
|
||||||
- "traefik.http.routers.penpot-dev.tls=true"
|
- "traefik.http.routers.penpot-dev.tls=true"
|
||||||
|
|
||||||
environment:
|
environment:
|
||||||
<<: [ *penpot-flags, *penpot-http-body-size ]
|
<<: [ *penpot-flags, *penpot-http-body-size ]
|
||||||
|
|
||||||
penpot-backend:
|
penpot-backend:
|
||||||
image: "penpotapp/backend:${PENPOT_VERSION:-latest}"
|
image: "penpotapp/backend:${PENPOT_VERSION:-latest}"
|
||||||
restart: always
|
restart: always
|
||||||
|
|||||||
@@ -1,39 +1,54 @@
|
|||||||
services:
|
services:
|
||||||
portainer:
|
portainer:
|
||||||
image: portainer/portainer-ce:2.41.0
|
|
||||||
container_name: portainer
|
container_name: portainer
|
||||||
|
image: portainer/portainer-ce:latest
|
||||||
restart: always
|
restart: always
|
||||||
volumes:
|
volumes:
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
- data:/data
|
- ./portainer_data:/data
|
||||||
ports:
|
ports:
|
||||||
- 9000:9000
|
- 9443:9443
|
||||||
# - 8000:8000 # Remove if you do not intend to use Edge Agents
|
# - 8000:8000 # Remove if you do not intend to use Edge Agents
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.http.services.portainer.loadbalancer.server.port=9000"
|
- "traefik.docker.network=proxy"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.portainer.rule=Host(`portainer.forust.xyz`)"
|
- "traefik.http.routers.portainer.rule=Host(`portainer.forust.xyz`)"
|
||||||
- "traefik.http.routers.portainer.entrypoints=websecure"
|
- "traefik.http.routers.portainer.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.portainer.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.portainer.service=portainer"
|
||||||
- "traefik.http.routers.portainer.tls=true"
|
- "traefik.http.routers.portainer.tls=true"
|
||||||
|
- "traefik.http.services.portainer.loadbalancer.server.port=9443"
|
||||||
|
- "traefik.http.services.portainer.loadbalancer.server.scheme=https"
|
||||||
|
- "traefik.http.services.portainer.loadbalancer.serverstransport=insecureTransport@file"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.portainer-local.rule=Host(`portainer.workstation.internal`)"
|
- "traefik.http.routers.portainer-local.rule=Host(`portainer.workstation.internal`) || Host(`portainer.internal`)"
|
||||||
- "traefik.http.routers.portainer-local.entrypoints=websecure"
|
- "traefik.http.routers.portainer-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.portainer-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.portainer-local.service=portainer"
|
||||||
- "traefik.http.routers.portainer-local.tls=true"
|
- "traefik.http.routers.portainer-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.portainer-dev.rule=Host(`portainer.gigaforust.internal`)"
|
- "traefik.http.routers.portainer-dev.rule=Host(`portainer.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.portainer-dev.entrypoints=websecure"
|
- "traefik.http.routers.portainer-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.portainer-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.portainer-dev.service=portainer"
|
||||||
- "traefik.http.routers.portainer-dev.tls=true"
|
- "traefik.http.routers.portainer-dev.tls=true"
|
||||||
|
|
||||||
# Glance Metadata
|
|
||||||
- glance.name=Portainer
|
- glance.name=Portainer
|
||||||
- glance.url=https://portainer.forust.xyz/
|
- glance.url=https://portainer.forust.xyz/
|
||||||
- glance.description=Portainer is a lightweight management UI which allows you to easily manage your Docker environments.
|
- glance.description=Portainer is a lightweight management UI which allows you to easily manage your Docker environments.
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
volumes:
|
volumes:
|
||||||
data:
|
portainer_data:
|
||||||
|
name: portainer_data
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
|
default:
|
||||||
|
name: portainer_network
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -1,15 +0,0 @@
|
|||||||
# Read the documentation before using the `docker-compose.yml` file:
|
|
||||||
# https://docs.searxng.org/admin/installation-docker.html
|
|
||||||
#
|
|
||||||
# Additional ENVs:
|
|
||||||
# https://docs.searxng.org/admin/settings/settings_general.html#settings-general
|
|
||||||
# https://docs.searxng.org/admin/settings/settings_server.html#settings-server
|
|
||||||
|
|
||||||
# Use a specific version tag. E.g. "latest" or "2026.3.25-541c6c3cb".
|
|
||||||
#SEARXNG_VERSION=latest
|
|
||||||
|
|
||||||
# Listen to a specific address.
|
|
||||||
#SEARXNG_HOST=[::]
|
|
||||||
|
|
||||||
# Listen to a specific port.
|
|
||||||
SEARXNG_PORT=8080
|
|
||||||
@@ -1,45 +0,0 @@
|
|||||||
# Read the documentation before using the `docker-compose.yml` file:
|
|
||||||
# https://docs.searxng.org/admin/installation-docker.html
|
|
||||||
services:
|
|
||||||
core:
|
|
||||||
container_name: searxng-core
|
|
||||||
image: docker.io/searxng/searxng:${SEARXNG_VERSION:-latest}
|
|
||||||
restart: unless-stopped
|
|
||||||
# ports:
|
|
||||||
# - ${SEARXNG_PORT:-8080}
|
|
||||||
env_file: .env
|
|
||||||
labels:
|
|
||||||
- "traefik.enable=true"
|
|
||||||
- "traefik.http.services.searxng.loadbalancer.server.port=8080"
|
|
||||||
# Prod Router
|
|
||||||
- "traefik.http.routers.searxng.rule=Host(`s.forust.xyz` || `searxng.forust.xyz`)"
|
|
||||||
- "traefik.http.routers.searxng.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.searxng.tls=true"
|
|
||||||
# Local Router
|
|
||||||
- "traefik.http.routers.searxng-local.rule=Host(`s.workstation.internal` || `searxng.workstation.internal`)"
|
|
||||||
- "traefik.http.routers.searxng-local.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.searxng-local.tls=true"
|
|
||||||
# Dev Router
|
|
||||||
- "traefik.http.routers.searxng-dev.rule=Host(`searxng.gigaforust.internal`)"
|
|
||||||
- "traefik.http.routers.searxng-dev.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.searxng-dev.tls=true"
|
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
volumes:
|
|
||||||
- ./core-config/:/etc/searxng/:Z
|
|
||||||
- core-data:/var/cache/searxng/
|
|
||||||
|
|
||||||
valkey:
|
|
||||||
container_name: searxng-valkey
|
|
||||||
image: docker.io/valkey/valkey:9-alpine
|
|
||||||
command: valkey-server --save 30 1 --loglevel warning
|
|
||||||
restart: unless-stopped
|
|
||||||
volumes:
|
|
||||||
- valkey-data:/data/
|
|
||||||
|
|
||||||
volumes:
|
|
||||||
core-data:
|
|
||||||
valkey-data:
|
|
||||||
networks:
|
|
||||||
proxy:
|
|
||||||
external: true
|
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
TZ=Europe/Moscow
|
||||||
@@ -0,0 +1,74 @@
|
|||||||
|
services:
|
||||||
|
jellyfin:
|
||||||
|
image: lscr.io/linuxserver/jellyfin:latest
|
||||||
|
container_name: jellyfin
|
||||||
|
restart: unless-stopped
|
||||||
|
ports:
|
||||||
|
- "8096:8096/tcp"
|
||||||
|
- "7359:7359/udp"
|
||||||
|
volumes:
|
||||||
|
# HACK: Binding while bootstrapping, testing
|
||||||
|
# - jellyfin-cfg:/config
|
||||||
|
- ./config/jellyfin:/config
|
||||||
|
- /mnt/mediaserver/media/movies:/media/movies
|
||||||
|
- /mnt/mediaserver/media/movies:/media/movies
|
||||||
|
devices:
|
||||||
|
- /dev/dri:/dev/dri
|
||||||
|
labels:
|
||||||
|
- "traefik.enable=true"
|
||||||
|
- "traefik.docker.network=proxy"
|
||||||
|
- "traefik.http.services.jellyfin.loadbalancer.server.port=8096"
|
||||||
|
# Prod Router
|
||||||
|
- "traefik.http.routers.jellyfin.rule=Host(`media.forust.xyz`)"
|
||||||
|
- "traefik.http.routers.jellyfin.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.jellyfin.tls=true"
|
||||||
|
# Local Router
|
||||||
|
- "traefik.http.routers.jellyfin-local.rule=Host(`media.workstation.internal`) || Host(`ms.internal`)"
|
||||||
|
- "traefik.http.routers.jellyfin-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.jellyfin-local.tls=true"
|
||||||
|
# Dev Router
|
||||||
|
- "traefik.http.routers.jellyfin-dev.rule=Host(`media.gigaforust.internal`)"
|
||||||
|
- "traefik.http.routers.jellyfin-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.jellyfin-dev.tls=true"
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
|
- streaming
|
||||||
|
qbittorrent:
|
||||||
|
image: lscr.io/linuxserver/qbittorrent:latest
|
||||||
|
container_name: qbittorrent
|
||||||
|
restart: unless-stopped
|
||||||
|
environment:
|
||||||
|
- WEBUI_PORT=8080
|
||||||
|
volumes:
|
||||||
|
# HACK: Binding while bootstrapping, testing
|
||||||
|
# - qbittorrent-cfg:/config
|
||||||
|
- ./config/qbittorrent:/config
|
||||||
|
- /mnt/mediaserver/downloads:/downloads
|
||||||
|
ports:
|
||||||
|
- 8080:8080
|
||||||
|
- 6881:6881
|
||||||
|
- 6881:6881/udp
|
||||||
|
networks:
|
||||||
|
- streaming
|
||||||
|
radarr:
|
||||||
|
image: lscr.io/linuxserver/radarr:latest
|
||||||
|
container_name: radarr
|
||||||
|
restart: unless-stopped
|
||||||
|
ports:
|
||||||
|
- 7878:7878
|
||||||
|
volumes:
|
||||||
|
# HACK: Binding while bootstrapping, testing
|
||||||
|
# - radarr-cfg:/config
|
||||||
|
- ./config/radarr:/config
|
||||||
|
- /mnt/mediaserver/downloads:/downloads
|
||||||
|
- /mnt/mediaserver/movies:/movies
|
||||||
|
networks:
|
||||||
|
- streaming
|
||||||
|
volumes:
|
||||||
|
jellyfin-cfg:
|
||||||
|
qbittorrent-cfg:
|
||||||
|
networks:
|
||||||
|
proxy:
|
||||||
|
external: true
|
||||||
|
streaming:
|
||||||
|
name: streaming
|
||||||
@@ -6,29 +6,41 @@ services:
|
|||||||
# ports:
|
# ports:
|
||||||
# - "3331:8080"
|
# - "3331:8080"
|
||||||
volumes:
|
volumes:
|
||||||
- data:/app/data
|
- ./termix-data:/app/data
|
||||||
environment:
|
environment:
|
||||||
PORT: "8080"
|
PORT: "8080"
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.http.services.termix.loadbalancer.server.port=8080"
|
- "traefik.docker.network=proxy"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.termix.rule=Host(`termix.forust.xyz`)"
|
- "traefik.http.routers.termix.rule=Host(`termix.forust.xyz`)"
|
||||||
- "traefik.http.routers.termix.entrypoints=websecure"
|
- "traefik.http.routers.termix.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.termix.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.termix.service=termix"
|
||||||
- "traefik.http.routers.termix.tls=true"
|
- "traefik.http.routers.termix.tls=true"
|
||||||
|
- "traefik.http.services.termix.loadbalancer.server.port=8080"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.termix-local.rule=Host(`termix.workstation.internal`)"
|
- "traefik.http.routers.termix-local.rule=Host(`termix.workstation.internal`) || Host(`termix.internal`)"
|
||||||
- "traefik.http.routers.termix-local.entrypoints=websecure"
|
- "traefik.http.routers.termix-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.termix-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.termix-local.service=termix"
|
||||||
- "traefik.http.routers.termix-local.tls=true"
|
- "traefik.http.routers.termix-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.termix-dev.rule=Host(`termix.gigaforust.internal`)"
|
- "traefik.http.routers.termix-dev.rule=Host(`termix.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.termix-dev.entrypoints=websecure"
|
- "traefik.http.routers.termix-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.termix-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.termix-dev.service=termix"
|
||||||
- "traefik.http.routers.termix-dev.tls=true"
|
- "traefik.http.routers.termix-dev.tls=true"
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
data:
|
termix-data:
|
||||||
|
driver: local
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
services:
|
services:
|
||||||
traefik:
|
traefik:
|
||||||
image: traefik:v3.7
|
image: traefik:latest
|
||||||
container_name: traefik
|
container_name: traefik
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
command:
|
command:
|
||||||
@@ -17,11 +17,10 @@ services:
|
|||||||
|
|
||||||
# EntryPoints
|
# EntryPoints
|
||||||
- "--entryPoints.web.address=:80"
|
- "--entryPoints.web.address=:80"
|
||||||
- "--entryPoints.web.http.redirections.entryPoint.scheme=https"
|
|
||||||
- "--entryPoints.web.http.redirections.entryPoint.to=websecure"
|
|
||||||
- "--entryPoints.websecure.address=:443"
|
- "--entryPoints.websecure.address=:443"
|
||||||
- "--entryPoints.websecure.http.middlewares=error-pages@docker"
|
|
||||||
- "--entryPoints.websecure.http.tls=true"
|
- "--entryPoints.websecure.http.tls=true"
|
||||||
|
- "--entryPoints.web.http.redirections.entryPoint.to=websecure"
|
||||||
|
- "--entryPoints.web.http.redirections.entryPoint.scheme=https"
|
||||||
- "--entryPoints.ssh.address=:2221"
|
- "--entryPoints.ssh.address=:2221"
|
||||||
|
|
||||||
# Let's Encrypt
|
# Let's Encrypt
|
||||||
@@ -35,14 +34,15 @@ services:
|
|||||||
# Cloudflare
|
# Cloudflare
|
||||||
- "--entryPoints.web.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
- "--entryPoints.web.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
||||||
- "--entryPoints.websecure.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
- "--entryPoints.websecure.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
||||||
# Logging
|
# # Logging
|
||||||
- "--log.level=INFO"
|
# - "--log.level=INFO"
|
||||||
- "--log.filePath=/var/log/traefik/traefik.log"
|
# - "--log.filePath=/var/log/traefik/traefik.log"
|
||||||
- "--log.format=json"
|
# - "--accesslog=true"
|
||||||
- "--accesslog=true"
|
# - "--accesslog.filepath=/var/log/traefik/access.log"
|
||||||
- "--accesslog.filepath=/var/log/traefik/access.log"
|
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
|
- "traefik.docker.network=proxy"
|
||||||
|
|
||||||
# Prod Router (Dash)
|
# Prod Router (Dash)
|
||||||
- "traefik.http.routers.traefik-dashboard.rule=Host(`traefik.forust.xyz`)"
|
- "traefik.http.routers.traefik-dashboard.rule=Host(`traefik.forust.xyz`)"
|
||||||
@@ -50,32 +50,42 @@ services:
|
|||||||
- "traefik.http.routers.traefik-dashboard.middlewares=security-chain@file"
|
- "traefik.http.routers.traefik-dashboard.middlewares=security-chain@file"
|
||||||
- "traefik.http.routers.traefik-dashboard.service=api@internal"
|
- "traefik.http.routers.traefik-dashboard.service=api@internal"
|
||||||
- "traefik.http.routers.traefik-dashboard.tls=true"
|
- "traefik.http.routers.traefik-dashboard.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.traefik-dashboard-local.rule=Host(`traefik.workstation.internal`)"
|
- "traefik.http.routers.traefik-dashboard-local.rule=Host(`traefik.workstation.internal`) || Host(`traefik.internal`)"
|
||||||
- "traefik.http.routers.traefik-dashboard-local.entrypoints=websecure"
|
- "traefik.http.routers.traefik-dashboard-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.traefik-dashboard-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.traefik-dashboard-local.service=api@internal"
|
- "traefik.http.routers.traefik-dashboard-local.service=api@internal"
|
||||||
- "traefik.http.routers.traefik-dashboard-local.tls=true"
|
- "traefik.http.routers.traefik-dashboard-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.traefik-dashboard-dev.rule=Host(`traefik.gigaforust.internal`)"
|
- "traefik.http.routers.traefik-dashboard-dev.rule=Host(`traefik.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.traefik-dashboard-dev.entrypoints=websecure"
|
- "traefik.http.routers.traefik-dashboard-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.traefik-dashboard-dev.middlewares=security-chain@file"
|
||||||
- "traefik.http.routers.traefik-dashboard-dev.service=api@internal"
|
- "traefik.http.routers.traefik-dashboard-dev.service=api@internal"
|
||||||
- "traefik.http.routers.traefik-dashboard-dev.tls=true"
|
- "traefik.http.routers.traefik-dashboard-dev.tls=true"
|
||||||
|
|
||||||
# Glance Metadata
|
|
||||||
- glance.name=Traefik
|
- glance.name=Traefik
|
||||||
- glance.url=https://traefik.forust.xyz/
|
- glance.url=https://traefik.forust.xyz/
|
||||||
- glance.description=Traefik is a modern reverse proxy and load balancer
|
- glance.description=Traefik is a modern reverse proxy and load balancer
|
||||||
|
|
||||||
|
ports:
|
||||||
|
- "80:80"
|
||||||
|
- "443:443"
|
||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
- ./dynamic:/etc/traefik/dynamic:ro
|
- ./dynamic:/etc/traefik/dynamic:ro
|
||||||
- ./certs:/certs:ro
|
- ./certs:/certs:ro
|
||||||
- ./logs:/var/log/traefik
|
- ./logs:/var/log/traefik
|
||||||
- ./letsencrypt:/letsencrypt
|
- ./letsencrypt:/letsencrypt
|
||||||
ports:
|
|
||||||
- "80:80"
|
|
||||||
- "443:443"
|
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
|
|
||||||
|
environment:
|
||||||
|
- TZ=Europe/Bratislava
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
http:
|
http:
|
||||||
serversTransports:
|
serversTransports:
|
||||||
insecureTransport:
|
insecureTransport:
|
||||||
insecureSkipVerify: true
|
insecureSkipVerify: true
|
||||||
|
|||||||
@@ -35,7 +35,6 @@ http:
|
|||||||
forwardAuth:
|
forwardAuth:
|
||||||
address: "http://authentik-server:9000/outpost.goauthentik.io/auth/traefik"
|
address: "http://authentik-server:9000/outpost.goauthentik.io/auth/traefik"
|
||||||
trustForwardHeader: true
|
trustForwardHeader: true
|
||||||
maxResponseBodySize: 1048576
|
|
||||||
authResponseHeaders:
|
authResponseHeaders:
|
||||||
- X-authentik-username
|
- X-authentik-username
|
||||||
- X-authentik-groups
|
- X-authentik-groups
|
||||||
|
|||||||
@@ -15,6 +15,7 @@ http:
|
|||||||
rule: "Host(`nextcloud.workstation.internal`)"
|
rule: "Host(`nextcloud.workstation.internal`)"
|
||||||
entrypoints:
|
entrypoints:
|
||||||
- websecure
|
- websecure
|
||||||
|
- web
|
||||||
service: nextcloud
|
service: nextcloud
|
||||||
middlewares:
|
middlewares:
|
||||||
- nextcloud-chain
|
- nextcloud-chain
|
||||||
@@ -25,6 +26,7 @@ http:
|
|||||||
rule: "Host(`nextcloud.gigaforust.internal`)"
|
rule: "Host(`nextcloud.gigaforust.internal`)"
|
||||||
entrypoints:
|
entrypoints:
|
||||||
- websecure
|
- websecure
|
||||||
|
- web
|
||||||
service: nextcloud
|
service: nextcloud
|
||||||
middlewares:
|
middlewares:
|
||||||
- nextcloud-chain
|
- nextcloud-chain
|
||||||
|
|||||||
@@ -2,14 +2,16 @@
|
|||||||
tls:
|
tls:
|
||||||
certificates:
|
certificates:
|
||||||
# Cloudflare Origin CA *.forust.xyz
|
# Cloudflare Origin CA *.forust.xyz
|
||||||
# - certFile: /certs/cloudflare.pem
|
- certFile: /certs/cloudflare.pem
|
||||||
# keyFile: /certs/cloudflare.key
|
keyFile: /certs/cloudflare.key
|
||||||
|
- certFile: /certs/xdfnx.pem
|
||||||
|
keyFile: /certs/xdfnx.key
|
||||||
stores:
|
stores:
|
||||||
default:
|
default:
|
||||||
defaultCertificate:
|
defaultCertificate:
|
||||||
# Fallback local certificate
|
# Fallback local certificate
|
||||||
certFile: /certs/local.pem
|
certFile: /certs/gigaforust.internal+1.pem
|
||||||
keyFile: /certs/local-key.pem
|
keyFile: /certs/gigaforust.internal+1-key.pem
|
||||||
|
|
||||||
options:
|
options:
|
||||||
default:
|
default:
|
||||||
|
|||||||
@@ -1,32 +1,34 @@
|
|||||||
services:
|
services:
|
||||||
uptime-kuma:
|
uptime-kuma:
|
||||||
image: louislam/uptime-kuma:2
|
image: louislam/uptime-kuma:2
|
||||||
container_name: uptime-kuma
|
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
|
container_name: uptime-kuma
|
||||||
volumes:
|
volumes:
|
||||||
- data:/app/data
|
- ./data:/app/data
|
||||||
# ports:
|
# ports:
|
||||||
# - "3001:3001"
|
# <Host Port>:<Container Port>
|
||||||
|
# - "3001:3001"
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.http.services.uptime-kuma.loadbalancer.server.port=3001"
|
- "traefik.docker.network=proxy"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.uptime-kuma.rule=Host(`uptime.forust.xyz`)"
|
- "traefik.http.routers.uptime-kuma.rule=Host(`uptime.forust.xyz`)"
|
||||||
- "traefik.http.routers.uptime-kuma.entrypoints=websecure"
|
- "traefik.http.routers.uptime-kuma.entrypoints=websecure"
|
||||||
- "traefik.http.routers.uptime-kuma.tls=true"
|
- "traefik.http.routers.uptime-kuma.tls=true"
|
||||||
|
- "traefik.http.services.uptime-kuma.loadbalancer.server.port=3001"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.uptime-kuma-local.rule=Host(`uptime.workstation.internal`)"
|
- "traefik.http.routers.uptime-kuma-local.rule=Host(`uptime.workstation.internal`) || Host(`uptime.internal`)"
|
||||||
- "traefik.http.routers.uptime-kuma-local.entrypoints=websecure"
|
- "traefik.http.routers.uptime-kuma-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.uptime-kuma-local.tls=true"
|
- "traefik.http.routers.uptime-kuma-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.uptime-kuma-dev.rule=Host(`uptime.gigaforust.internal`)"
|
- "traefik.http.routers.uptime-kuma-dev.rule=Host(`uptime.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.uptime-kuma-dev.entrypoints=websecure"
|
- "traefik.http.routers.uptime-kuma-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.uptime-kuma-dev.tls=true"
|
- "traefik.http.routers.uptime-kuma-dev.tls=true"
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
volumes:
|
|
||||||
data:
|
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -1,12 +1 @@
|
|||||||
.unused
|
.unused
|
||||||
Downloads
|
|
||||||
.venv
|
|
||||||
volumes
|
|
||||||
.env
|
|
||||||
.env.*
|
|
||||||
my_account.session
|
|
||||||
.gitignore
|
|
||||||
README.md
|
|
||||||
.git
|
|
||||||
uv.lock
|
|
||||||
.deepsource.toml
|
|
||||||
@@ -1,18 +1,10 @@
|
|||||||
FROM python:3.11-slim
|
FROM python:3.11
|
||||||
|
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
RUN apt-get update && apt-get install -y --no-install-recommends \
|
|
||||||
git wget ffmpeg mediainfo && \
|
|
||||||
rm -rf /var/lib/apt/lists/*
|
|
||||||
|
|
||||||
COPY requirements.txt /app/
|
|
||||||
|
|
||||||
RUN python -m pip install --no-cache-dir --upgrade pip && \
|
|
||||||
python -m pip install --no-cache-dir -r /app/requirements.txt
|
|
||||||
|
|
||||||
COPY . /app
|
COPY . /app
|
||||||
|
RUN apt-get -qq update && apt-get -qq install -y git wget ffmpeg mediainfo\
|
||||||
ENV PYTHONUNBUFFERED=1
|
&& apt-get clean \
|
||||||
|
&& rm -rf /var/lib/apt/lists/*
|
||||||
CMD ["python", "-u", "main.py"]
|
RUN python -m venv --copies /opt/venv
|
||||||
|
ENV PATH="/opt/venv/bin:$PATH"
|
||||||
|
RUN pip install --no-cache-dir -r requirements.txt
|
||||||
|
CMD ["python", "main.py"]
|
||||||
|
|||||||
@@ -3,8 +3,6 @@ services:
|
|||||||
build:
|
build:
|
||||||
context: .
|
context: .
|
||||||
dockerfile: Dockerfile
|
dockerfile: Dockerfile
|
||||||
image: userbot:latest
|
|
||||||
pull_policy: never
|
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
env_file:
|
env_file:
|
||||||
- .env
|
- .env
|
||||||
@@ -18,10 +16,9 @@ services:
|
|||||||
- 1.1.1.1
|
- 1.1.1.1
|
||||||
|
|
||||||
anna:
|
anna:
|
||||||
image: userbot:latest
|
build:
|
||||||
pull_policy: never
|
context: .
|
||||||
depends_on:
|
dockerfile: Dockerfile
|
||||||
- forust
|
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
env_file:
|
env_file:
|
||||||
- .env
|
- .env
|
||||||
|
|||||||
@@ -90,19 +90,11 @@ def load_missing_modules():
|
|||||||
os.makedirs(custom_modules_path, exist_ok=True)
|
os.makedirs(custom_modules_path, exist_ok=True)
|
||||||
|
|
||||||
try:
|
try:
|
||||||
resp = requests.get(
|
f = requests.get(
|
||||||
"https://raw.githubusercontent.com/The-MoonTg-project/custom_modules/main/full.txt",
|
"https://raw.githubusercontent.com/The-MoonTg-project/custom_modules/main/full.txt"
|
||||||
timeout=10,
|
).text
|
||||||
)
|
except Exception:
|
||||||
if not resp.ok:
|
logging.error("Failed to fetch custom modules list")
|
||||||
logging.error(
|
|
||||||
"Failed to fetch custom modules list: HTTP %s",
|
|
||||||
resp.status_code,
|
|
||||||
)
|
|
||||||
return
|
|
||||||
f = resp.text
|
|
||||||
except Exception as e:
|
|
||||||
logging.error("Failed to fetch custom modules list: %s", e)
|
|
||||||
return
|
return
|
||||||
modules_dict = {
|
modules_dict = {
|
||||||
line.split("/")[-1].split()[0]: line.strip() for line in f.splitlines()
|
line.split("/")[-1].split()[0]: line.strip() for line in f.splitlines()
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ name = "userbot"
|
|||||||
version = "0.1.0"
|
version = "0.1.0"
|
||||||
description = "Add your description here"
|
description = "Add your description here"
|
||||||
readme = "README.md"
|
readme = "README.md"
|
||||||
requires-python = ">=3.11"
|
requires-python = ">=3.13"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"aiofiles>=25.1.0",
|
"aiofiles>=25.1.0",
|
||||||
"aiohttp>=3.13.2",
|
"aiohttp>=3.13.2",
|
||||||
|
|||||||
@@ -18,5 +18,3 @@ aiohttp
|
|||||||
aiofiles
|
aiofiles
|
||||||
pySmartDL
|
pySmartDL
|
||||||
qrcode
|
qrcode
|
||||||
bottle
|
|
||||||
dulwich
|
|
||||||
@@ -1,8 +1,8 @@
|
|||||||
import os
|
import os
|
||||||
import environs
|
import environs
|
||||||
|
|
||||||
env = environs.Env()
|
|
||||||
try:
|
try:
|
||||||
|
env = environs.Env()
|
||||||
env.read_env("./.env")
|
env.read_env("./.env")
|
||||||
except FileNotFoundError:
|
except FileNotFoundError:
|
||||||
print("No .env file found, using os.environ.")
|
print("No .env file found, using os.environ.")
|
||||||
|
|||||||
@@ -22,7 +22,6 @@ import re
|
|||||||
import shlex
|
import shlex
|
||||||
import subprocess
|
import subprocess
|
||||||
import sys
|
import sys
|
||||||
import tempfile
|
|
||||||
import time
|
import time
|
||||||
import traceback
|
import traceback
|
||||||
from PIL import Image
|
from PIL import Image
|
||||||
@@ -86,17 +85,13 @@ async def edit_or_send_as_file(
|
|||||||
return
|
return
|
||||||
if len(tex) > 1024:
|
if len(tex) > 1024:
|
||||||
await message.edit("<code>OutPut is Too Large, Sending As File!</code>")
|
await message.edit("<code>OutPut is Too Large, Sending As File!</code>")
|
||||||
with tempfile.NamedTemporaryFile(
|
file_names = f"{file_name}.txt"
|
||||||
"w", delete=False, suffix=".txt", prefix=f"{file_name}_"
|
with open(file_names, "w") as fn:
|
||||||
) as fn:
|
|
||||||
fn.write(tex)
|
fn.write(tex)
|
||||||
temp_path = fn.name
|
await client.send_document(message.chat.id, file_names, caption=caption)
|
||||||
try:
|
await message.delete()
|
||||||
await client.send_document(message.chat.id, temp_path, caption=caption)
|
if os.path.exists(file_names):
|
||||||
await message.delete()
|
os.remove(file_names)
|
||||||
finally:
|
|
||||||
if os.path.exists(temp_path):
|
|
||||||
os.remove(temp_path)
|
|
||||||
return
|
return
|
||||||
return await message.edit(tex)
|
return await message.edit(tex)
|
||||||
|
|
||||||
@@ -254,7 +249,12 @@ def is_admin(func):
|
|||||||
chat_member = await client.get_chat_member(
|
chat_member = await client.get_chat_member(
|
||||||
message.chat.id, message.from_user.id
|
message.chat.id, message.from_user.id
|
||||||
)
|
)
|
||||||
if chat_member.status in ("administrator", "creator"):
|
chat_admins = []
|
||||||
|
async for member in client.get_chat_members(
|
||||||
|
message.chat.id, filter=ChatMembersFilter.ADMINISTRATORS
|
||||||
|
):
|
||||||
|
chat_admins.append(member)
|
||||||
|
if chat_member in chat_admins:
|
||||||
return await func(client, message)
|
return await func(client, message)
|
||||||
await message.edit("You need to be an admin to perform this action.")
|
await message.edit("You need to be an admin to perform this action.")
|
||||||
except UserNotParticipant:
|
except UserNotParticipant:
|
||||||
|
|||||||