Compare commits
153 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
0c5cf29f83
|
|||
|
43c38767a1
|
|||
| a68c01a68f | |||
| bdcdb1cb3d | |||
| fe2b80b51f | |||
| b8d5bc747d | |||
|
6f77b7d845
|
|||
| ea286e117d | |||
| 6a050669e8 | |||
| b9c11b8eab | |||
| 6dac841b2c | |||
| 526a2b617a | |||
| 1e08391e0e | |||
| 0a31601b77 | |||
| 25eb89c902 | |||
| d988b0f7db | |||
| e873f37159 | |||
| 8362f45bdc | |||
| fd5ea6cadd | |||
| aa3598ee3d | |||
|
c0205fa49b
|
|||
|
a22707770f
|
|||
|
646f988a86
|
|||
|
414d17d839
|
|||
|
812e4eb87a
|
|||
| 70b3b203fb | |||
| d857f3838d | |||
| f8620349a9 | |||
| b1acff5c85 | |||
| beb6dca6a2 | |||
| aed6ff31f7 | |||
| 73684af21b | |||
| cd5c90adcc | |||
| 578a1ca544 | |||
| 12ed20a306 | |||
|
400e7b6595
|
|||
| f58e96a25d | |||
| a3e5f5a78b | |||
|
1a09a62a4c
|
|||
|
2593b54402
|
|||
|
42826a037c
|
|||
|
d7a68237e5
|
|||
| bbb8bdf0a7 | |||
| f4d3bd9c6d | |||
|
6b919df7c6
|
|||
| 3ee0b96ed5 | |||
| d25d213d9b | |||
|
a3b7c4c889
|
|||
| 3dbb50c924 | |||
| 54da82432b | |||
| e5eb234c41 | |||
| 721348e67f | |||
|
d58ae2a5e7
|
|||
| aa516c3445 | |||
|
b5cc7d9a0d
|
|||
|
5dfa9c879b
|
|||
| 3c5702a0fb | |||
| dd0ca27f4f | |||
| 7f7d0de090 | |||
| bee3f16cb2 | |||
|
303d23968d
|
|||
|
b7ecf88052
|
|||
|
5068591b8b
|
|||
|
8e57f21e44
|
|||
|
073d9ff569
|
|||
| c6d00e525b | |||
|
539994a145
|
|||
|
95f0afbbee
|
|||
|
9f86bd1142
|
|||
| af9668e8e6 | |||
|
53b71a33ad
|
|||
|
bf72007b14
|
|||
|
0bad0a817e
|
|||
| 525fed3b92 | |||
|
fe5e5c5e35
|
|||
|
72aa022048
|
|||
|
f18d4d9be4
|
|||
|
45ce789f58
|
|||
|
d7c05fd058
|
|||
| c13056fba1 | |||
|
5fe8af82d5
|
|||
| 6d97246997 | |||
| 6970279311 | |||
|
02f4e0ab42
|
|||
|
4a25622552
|
|||
|
0138fbd276
|
|||
|
94b5f39207
|
|||
| 403e88d548 | |||
| d03a4844fb | |||
| 48ff08529e | |||
|
81592b6142
|
|||
| 9480576966 | |||
| 9b43a9bef4 | |||
| 2b03335af5 | |||
| ea738ec14c | |||
|
e4e9d96a0b
|
|||
| 89576032b9 | |||
| a9edfc0a25 | |||
| acb8009307 | |||
| 21f4e46028 | |||
| 0234524635 | |||
| 26f5fb2fb9 | |||
| 122e6f6986 | |||
| ce0bc4613a | |||
| 8f4f460ff3 | |||
| c048efd569 | |||
| 1f1e13ff39 | |||
| c80a6c5351 | |||
| 4fe3d660f1 | |||
| 9675eac2bf | |||
| dc7fe64fbc | |||
| 502810a12e | |||
| c047cc291d | |||
| f2b951673c | |||
| 6b7c0df586 | |||
| fb2f420520 | |||
| 60c7d4ff17 | |||
| d20ec696a3 | |||
| c030b4cffa | |||
| e0f7ab6561 | |||
| f0682319a7 | |||
| dbd3f36f76 | |||
| 4471da827c | |||
| 163ea867ce | |||
| dc75dbaf7c | |||
| db0f0f7bb6 | |||
| 5e4c60bb30 | |||
| 17cae71952 | |||
| f4c695f95e | |||
| 6bdb16ad21 | |||
| 6eb62f41cc | |||
| 586f0e3f7d | |||
| 0e46193f53 | |||
| aed28ed15c | |||
| f3b73bae11 | |||
| be049cfa0d | |||
| bfb21adff7 | |||
| 1c75382a6e | |||
| 9c5e037567 | |||
| 4f9e7ea990 | |||
| 9f784d2c31 | |||
| a07e27bff6 | |||
| c31369f2b7 | |||
| 3bfcd6edf4 | |||
| 504cbc81a0 | |||
| aa7239ee83 | |||
| 6d9427cf2a | |||
| 70d60ed40a | |||
| aca6824309 | |||
| 6843befac3 | |||
| 0dfb09590d | |||
| 625eb9561b | |||
| b367b64879 |
@@ -0,0 +1,39 @@
|
||||
name: Deploy to Server
|
||||
run-name: Deploying to ${{ runner.os}} server on ${{ gitea.ref }}
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
- ci/gitea-actions
|
||||
jobs:
|
||||
deploy:
|
||||
runs-on: prod
|
||||
steps:
|
||||
- name: Fetch and Diff Analysis
|
||||
id: diff
|
||||
run: |
|
||||
cd ${{ secrets.PROD_DIR }}
|
||||
git fetch origin main
|
||||
CHANGES=$(git diff --name-only HEAD origin/main | cut -d/ -f1 | sort -u | tr '\n' ' ')
|
||||
echo "dirs=$CHANGES" >> $GITHUB_OUTPUT
|
||||
echo "Changed dirs: $CHANGES"
|
||||
|
||||
- name: Sync Server Files
|
||||
run: |
|
||||
cd ${{ secrets.PROD_DIR }}
|
||||
git reset --hard origin/main
|
||||
echo "Server files synced with origin/main"
|
||||
|
||||
- name: Deploy Services
|
||||
run: |
|
||||
cd ${{ secrets.PROD_DIR }}
|
||||
for dir in ${{ steps.diff.outputs.dirs }}; do
|
||||
if [ -d "$dir" ] && ([ -f "$dir/compose.yaml" ] || [ -f "$dir/docker-compose.yaml" ]); then
|
||||
echo ">>> Deploying $dir"
|
||||
cd "$dir"
|
||||
DOCKER_BUILDKIT=1 BUILDKIT_PROGRESS=plain docker compose up -d --build --no-color
|
||||
cd ..
|
||||
else
|
||||
echo ">>> Skipping $dir: no compose file found"
|
||||
fi
|
||||
done
|
||||
@@ -0,0 +1,41 @@
|
||||
## BINARY MODE, USE WITH THE GITHUB RUNNER BINARY INSTALLED ON THE SERVER
|
||||
|
||||
name: Deploy to Server
|
||||
run-name: Deploying onto server on ${{ github.ref }}
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
- ci/actions
|
||||
jobs:
|
||||
deploy:
|
||||
runs-on: [prod, self-hosted]
|
||||
steps:
|
||||
- name: Fetch and Diff Analysis
|
||||
id: diff
|
||||
run: |
|
||||
cd ${{ secrets.PROD_DIR }}
|
||||
git fetch origin main
|
||||
CHANGES=$(git diff --name-only HEAD origin/main | cut -d/ -f1 | sort -u | tr '\n' ' ')
|
||||
echo "dirs=$CHANGES" >> $GITHUB_OUTPUT
|
||||
echo "Changed dirs: $CHANGES"
|
||||
|
||||
- name: Sync Server Files
|
||||
run: |
|
||||
cd ${{ secrets.PROD_DIR }}
|
||||
git reset --hard origin/main
|
||||
echo "Server files synced with origin/main"
|
||||
|
||||
- name: Deploy Services
|
||||
run: |
|
||||
cd ${{ secrets.PROD_DIR }}
|
||||
for dir in ${{ steps.diff.outputs.dirs }}; do
|
||||
if [ -d "$dir" ] && ([ -f "$dir/compose.yaml" ] || [ -f "$dir/docker-compose.yaml" ]); then
|
||||
echo ">>> Deploying $dir"
|
||||
cd "$dir"
|
||||
DOCKER_BUILDKIT=1 BUILDKIT_PROGRESS=plain docker compose up -d --build --no-color
|
||||
cd ..
|
||||
else
|
||||
echo ">>> Skipping $dir: no compose file found"
|
||||
fi
|
||||
done
|
||||
@@ -2,25 +2,26 @@
|
||||
sync.ffs_lock
|
||||
.sync.ffs_db
|
||||
|
||||
# Environment
|
||||
.env
|
||||
.env.anna
|
||||
.env.forust
|
||||
.env.*
|
||||
!.env.*example
|
||||
# Copyparty
|
||||
*.hist/
|
||||
|
||||
# Volumes and data directories
|
||||
# Volumes, configs and data directories
|
||||
gitea/gitea-db/
|
||||
gitea/gitea-data/*
|
||||
n8n/n8n-data/*
|
||||
n8n/n8n-node-data/*
|
||||
adguardhome/data/*
|
||||
adguardhome/conf/*
|
||||
dockmon/data/*
|
||||
portainer/portainer_data/*
|
||||
metube/MeTube_downloads
|
||||
uptime-kuma/data/
|
||||
termix/termix-data/*
|
||||
cfddns/config.json
|
||||
checkmk/checkmk/*
|
||||
downtify/Downtify_downloads
|
||||
headscale/config/*
|
||||
headscale/data/*
|
||||
searxng/core-config/*
|
||||
|
||||
# Steaming services files
|
||||
streaming/jellyfin/*
|
||||
@@ -32,11 +33,19 @@ streaming/qbittorrent/*
|
||||
streaming/prowlarr/*
|
||||
|
||||
# Homepage
|
||||
homepage/files/assets/images/team/*
|
||||
homepages/forust_files/.well-known/*
|
||||
|
||||
# Traefik files
|
||||
traefik/letsencrypt/acme.json
|
||||
traefik/dynamic/fileservers.yml
|
||||
traefik/dynamic/*.local.y*ml.*
|
||||
traefik/dynamic/*.external.y*ml
|
||||
|
||||
|
||||
traefik/logs/*
|
||||
|
||||
# SSL Certificates
|
||||
adguardhome/certs/*
|
||||
traefik/certs/*
|
||||
|
||||
# Monitoring
|
||||
@@ -72,6 +81,8 @@ replacements.txt
|
||||
|
||||
# Git
|
||||
.gitattributes
|
||||
# Gitea/github Runners
|
||||
.runner
|
||||
|
||||
# Misc
|
||||
.DS_Store
|
||||
@@ -79,3 +90,11 @@ replacements.txt
|
||||
|
||||
# Temp files
|
||||
edu_master/temp/
|
||||
temp/*
|
||||
|
||||
# Environment
|
||||
.env
|
||||
.env.anna
|
||||
.env.forust
|
||||
.env.*
|
||||
!*example
|
||||
|
||||
@@ -3,48 +3,46 @@ services:
|
||||
image: adguard/adguardhome:latest
|
||||
container_name: adguardhome
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- TZ=${TZ}
|
||||
ports:
|
||||
- "53:53/tcp"
|
||||
- "53:53/udp"
|
||||
- "853:853/tcp" # DNS over TLS
|
||||
# - "67:67/udp" # DHCP
|
||||
# - "68:68/tcp" # DHCP
|
||||
- "3000:3000/tcp"
|
||||
# - "3000:3000/tcp"
|
||||
volumes:
|
||||
- ./data/work:/opt/adguardhome/work
|
||||
- ./data/conf:/opt/adguardhome/conf
|
||||
networks:
|
||||
- traefik-proxy
|
||||
- data:/opt/adguardhome/work
|
||||
- ./conf:/opt/adguardhome/conf
|
||||
- ./certs:/certs:ro
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.adguard.rule=Host(`adguard.forust.xyz`)"
|
||||
- "traefik.http.routers.adguard.entrypoints=websecure"
|
||||
- "traefik.http.routers.adguard.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.adguard.service=adguard"
|
||||
- "traefik.http.routers.adguard.tls=true"
|
||||
- "traefik.http.services.adguard.loadbalancer.server.port=3000"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.adguard.rule=Host(`dns.forust.xyz`) || Host(`adguard.forust.xyz`)"
|
||||
- "traefik.http.routers.adguard.entrypoints=websecure"
|
||||
- "traefik.http.routers.adguard.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.adguard-local.rule=Host(`adguard.workstation.internal`) || Host(`adguard.internal`)"
|
||||
- "traefik.http.routers.adguard-local.rule=Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`)"
|
||||
- "traefik.http.routers.adguard-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.adguard-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.adguard-local.service=adguard"
|
||||
- "traefik.http.routers.adguard-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.adguard-dev.rule=Host(`adguard.gigaforust.internal`)"
|
||||
- "traefik.http.routers.adguard-dev.rule=Host(`adguard.gigaforust.internal`) || Host(`dns.gigaforust.internal`)"
|
||||
- "traefik.http.routers.adguard-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.adguard-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.adguard-dev.service=adguard"
|
||||
- "traefik.http.routers.adguard-dev.tls=true"
|
||||
# DoH Router
|
||||
- "traefik.http.routers.dns.rule=(Host(`dns.forust.xyz`) && PathPrefix(`/dns-query`))"
|
||||
- "traefik.http.routers.dns.entrypoints=websecure"
|
||||
- "traefik.http.routers.dns.tls.certresolver=letsencrypt"
|
||||
|
||||
# Glance Metadata
|
||||
- glance.name=adguard
|
||||
- glance.url=https://adguard.forust.xyz/
|
||||
- glance.description=AdGuard Home is a network-wide software for blocking ads.
|
||||
networks:
|
||||
traefik-proxy:
|
||||
- proxy
|
||||
volumes:
|
||||
data:
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
@@ -0,0 +1,20 @@
|
||||
# ===================================
|
||||
# Authentification app (authentik)
|
||||
|
||||
# PostgresQL conf
|
||||
PG_PASS=change_this_cuz_its_ur_db_pass
|
||||
PG_USER=authentik # it's okay
|
||||
|
||||
# Image Settings
|
||||
AUTHENTIK_IMAGE=ghcr.io/goauthentik/server
|
||||
AUTHENTIK_TAG=2025.10.2
|
||||
|
||||
# Networking
|
||||
PORT_HTTP=9000
|
||||
PORT_HTTPS=9443 # btw likely already used by portainer
|
||||
|
||||
AUTHENTIK_SECRET_KEY=super_secret_super_scary_authenik_key
|
||||
|
||||
AUTHENTIK_BOOTSTRAP_PASSWORD=pls_change_this
|
||||
|
||||
AUTHENTIK_ERROR_REPORTING__ENABLED=true # Or false to turn off
|
||||
@@ -0,0 +1,95 @@
|
||||
services:
|
||||
postgresql:
|
||||
image: docker.io/library/postgres:15-alpine
|
||||
restart: unless-stopped
|
||||
env_file:
|
||||
- .env
|
||||
environment:
|
||||
POSTGRES_DB: ${PG_DB:-authentik}
|
||||
POSTGRES_PASSWORD: ${PG_PASS:?database password required}
|
||||
POSTGRES_USER: ${PG_USER:-authentik}
|
||||
healthcheck:
|
||||
interval: 30s
|
||||
retries: 5
|
||||
start_period: 20s
|
||||
test:
|
||||
- CMD-SHELL
|
||||
- pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}
|
||||
timeout: 5s
|
||||
volumes:
|
||||
- database:/var/lib/postgresql/data
|
||||
networks:
|
||||
- authentik
|
||||
|
||||
server:
|
||||
image: ${AUTHENTIK_IMAGE:-ghcr.io/goauthentik/server}:${AUTHENTIK_TAG:-2025.10.2}
|
||||
command: server
|
||||
container_name: authentik-server
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - ${PORT_HTTP:-9000}:9000
|
||||
# - ${PORT_HTTPS:-9443}:9443
|
||||
env_file:
|
||||
- .env
|
||||
environment:
|
||||
AUTHENTIK_POSTGRESQL__HOST: postgresql
|
||||
AUTHENTIK_POSTGRESQL__NAME: ${PG_DB:-authentik}
|
||||
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
|
||||
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
|
||||
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
||||
volumes:
|
||||
- ./media:/media
|
||||
- ./custom-templates:/templates
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.authentik-server.loadbalancer.server.port=9000"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.authentik-server.rule=Host(`auth.forust.xyz`)"
|
||||
- "traefik.http.routers.authentik-server.entrypoints=websecure"
|
||||
- "traefik.http.routers.authentik-server.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.authentik-server-local.rule=Host(`auth.workstation.internal`)"
|
||||
- "traefik.http.routers.authentik-server-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.authentik-server-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.authentik-server-dev.rule=Host(`auth.gigaforust.internal`)"
|
||||
- "traefik.http.routers.authentik-server-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.authentik-server-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.authentik-server-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
- authentik
|
||||
depends_on:
|
||||
postgresql:
|
||||
condition: service_healthy
|
||||
worker:
|
||||
image: ${AUTHENTIK_IMAGE:-ghcr.io/goauthentik/server}:${AUTHENTIK_TAG:-2025.10.2}
|
||||
restart: unless-stopped
|
||||
user: root
|
||||
command: worker
|
||||
env_file:
|
||||
- .env
|
||||
environment:
|
||||
AUTHENTIK_POSTGRESQL__HOST: postgresql
|
||||
AUTHENTIK_POSTGRESQL__NAME: ${PG_DB:-authentik}
|
||||
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
|
||||
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
|
||||
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- ./media:/media
|
||||
- ./certs:/certs
|
||||
- ./custom-templates:/templates
|
||||
networks:
|
||||
- authentik
|
||||
depends_on:
|
||||
postgresql:
|
||||
condition: service_healthy
|
||||
volumes:
|
||||
database:
|
||||
driver: local
|
||||
networks:
|
||||
authentik:
|
||||
proxy:
|
||||
external: true
|
||||
@@ -0,0 +1,15 @@
|
||||
CLOUDFLARE_API_TOKEN=YOUR_CLOUDFLARE_API_TOKEN
|
||||
DOMAINS=example.com,dns.example.com,mc.example.com,auth.example.com,ssh.example.com
|
||||
IP4_DOMAINS=
|
||||
IP6_DOMAINS=
|
||||
IP4_PROVIDER=cloudflare.trace
|
||||
IP6_PROVIDER=none # change if you want to update AAAA
|
||||
UPDATE_CRON=@every 5m
|
||||
UPDATE_ON_START=true
|
||||
DELETE_ON_STOP=false
|
||||
DELETE_ON_FAILURE=true
|
||||
TTL=1
|
||||
PROXIED=!is(dns.example.com) && !is(mc.example.com) && !is(ssh.example.com)
|
||||
EMOJI=true
|
||||
UPTIMEKUMA=https://uptime-kuma.example.com/api/push/AsaSDFGFkfklaFALSKffkfFKfkfkfkFK?status=up&msg=OK&ping=
|
||||
REJECT_CLOUDFLARE_IPS=true
|
||||
@@ -2,12 +2,29 @@ services:
|
||||
cloudflare-ddns:
|
||||
image: timothyjmiller/cloudflare-ddns:latest
|
||||
container_name: cloudflare-ddns
|
||||
restart: unless-stopped
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
network_mode: 'host'
|
||||
# https://github.com/timothymiller/cloudflare-ddns#-quick-start
|
||||
environment:
|
||||
- PUID=1000
|
||||
- PGID=1000
|
||||
volumes:
|
||||
- ./config.json:/config.json
|
||||
restart: unless-stopped
|
||||
- CLOUDFLARE_API_TOKEN=${CLOUDFLARE_API_TOKEN:?Cloudflare API token is required}
|
||||
- DOMAINS=${DOMAINS:-}
|
||||
- IP4_DOMAINS=${IP4_DOMAINS:-}
|
||||
- IP6_DOMAINS=${IP6_DOMAINS:-}
|
||||
- IP4_PROVIDER=${IP4_PROVIDER:-cloudflare.trace}
|
||||
- IP6_PROVIDER=${IP6_PROVIDER:-none}
|
||||
- UPDATE_CRON=${UPDATE_CRON:-@every 5m}
|
||||
- UPDATE_ON_START=${UPDATE_ON_START:-true}
|
||||
- DELETE_ON_STOP=${DELETE_ON_STOP:-false}
|
||||
- DELETE_ON_FAILURE=${DELETE_ON_FAILURE:-true}
|
||||
- TTL=${TTL:-1} # 1=auto
|
||||
# to proxy only "dns.example.com" and "wfs.example.com" use "!is(dns.domain.com) && !is (wfs.domain.com)"
|
||||
- PROXIED=${PROXIED:-true}
|
||||
- EMOJI=${EMOJI:-true}
|
||||
- UPTIMEKUMA=${UPTIMEKUMA:-}
|
||||
- HEALTHCHECKS=${HEALTHCHECKS:-}
|
||||
- REJECT_CLOUDFLARE_IPS=${REJECT_CLOUDFLARE_IPS:-true}
|
||||
# volumes:
|
||||
# Prefer using environment variables for configuration, config.json legacy support
|
||||
# - ./config.json:/config.json
|
||||
|
||||
@@ -0,0 +1,2 @@
|
||||
CMK_PASSWORD=password
|
||||
TZ=Europe/Berlin
|
||||
@@ -0,0 +1,39 @@
|
||||
services:
|
||||
checkmk:
|
||||
image: "checkmk/check-mk-raw:2.4.0-latest"
|
||||
container_name: "checkmk"
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - 5000:5000
|
||||
# - 6776:8000
|
||||
volumes:
|
||||
- sites:/omd/sites
|
||||
tmpfs:
|
||||
- /opt/omd/sites/cmk/tmp:uid=1000,gid=1000
|
||||
environment:
|
||||
- CMK_PASSWORD=${CMK_PASSWORD:-password}
|
||||
- CMK_SITE_ID=cmk
|
||||
- TZ=${TZ:-Etc/UTC}
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.checkmk.loadbalancer.server.port=5000"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.checkmk.rule=Host(`cmk.forust.xyz`)"
|
||||
- "traefik.http.routers.checkmk.entrypoints=websecure"
|
||||
- "traefik.http.routers.checkmk.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.checkmk-local.rule=Host(`cmk.workstation.internal`)"
|
||||
- "traefik.http.routers.checkmk-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.checkmk-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.checkmk-dev.rule=Host(`cmk.gigaforust.internal`)"
|
||||
- "traefik.http.routers.checkmk-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.checkmk-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
volumes:
|
||||
sites:
|
||||
@@ -3,52 +3,44 @@ services:
|
||||
image: darthnorse/dockmon:latest
|
||||
container_name: dockmon
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- 8000:443
|
||||
environment:
|
||||
- TZ=Europe/Bratislava
|
||||
# ports:
|
||||
# - 8000:443
|
||||
volumes:
|
||||
- ./data:/app/data
|
||||
- data:/app/data
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
healthcheck:
|
||||
test: [ "CMD", "curl", "-k", "-f", "https://localhost:443/health" ]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 3
|
||||
networks:
|
||||
- traefik-proxy
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
|
||||
- "traefik.http.routers.dockmon.entrypoints=websecure"
|
||||
- "traefik.http.routers.dockmon.middlewares=security-headers@file,dockmon-auth@file"
|
||||
- "traefik.http.routers.dockmon.service=dockmon"
|
||||
- "traefik.http.routers.dockmon.tls=true"
|
||||
- "traefik.http.services.dockmon.loadbalancer.server.port=443"
|
||||
- "traefik.http.services.dockmon.loadbalancer.server.scheme=https"
|
||||
- "traefik.http.services.dockmon.loadbalancer.serverstransport=insecureTransport@file"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
|
||||
- "traefik.http.routers.dockmon.entrypoints=websecure"
|
||||
- "traefik.http.routers.dockmon.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.dockmon.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`) || Host(`dockmon.internal`)"
|
||||
- "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`)"
|
||||
- "traefik.http.routers.dockmon-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.dockmon-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.dockmon-local.service=dockmon"
|
||||
- "traefik.http.routers.dockmon-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.dockmon-dev.rule=Host(`dockmon.gigaforust.internal`)"
|
||||
- "traefik.http.routers.dockmon-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.dockmon-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.dockmon-dev.service=dockmon"
|
||||
- "traefik.http.routers.dockmon-dev.tls=true"
|
||||
|
||||
# Glance Metadata
|
||||
- glance.name=dockmon
|
||||
- glance.url=https://dockmon.forust.xyz/
|
||||
- glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface.
|
||||
|
||||
networks:
|
||||
traefik-proxy:
|
||||
- proxy
|
||||
volumes:
|
||||
data:
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
@@ -0,0 +1,31 @@
|
||||
services:
|
||||
downtify:
|
||||
container_name: downtify
|
||||
image: ghcr.io/henriquesebastiao/downtify:latest
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - '7077:8000'
|
||||
volumes:
|
||||
- ./Downtify_downloads:/downloads
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.downtify.loadbalancer.server.port=8000"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.downtify.rule=Host(`downtify.forust.xyz`)"
|
||||
- "traefik.http.routers.downtify.entrypoints=websecure"
|
||||
- "traefik.http.routers.downtify.middlewares=security-chain@file"
|
||||
- "traefik.http.routers.downtify.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.downtify-local.rule=Host(`downtify.workstation.internal`)"
|
||||
- "traefik.http.routers.downtify-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.downtify-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.downtify-dev.rule=Host(`downtify.gigaforust.internal`)"
|
||||
- "traefik.http.routers.downtify-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.downtify-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
@@ -3,10 +3,11 @@ services:
|
||||
build:
|
||||
context: .
|
||||
dockerfile: Dockerfile
|
||||
image: gcr.forust.xyz/forust/dtek-notif:latest
|
||||
pull_policy: build
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- TZ=Europe/Kyiv
|
||||
|
||||
dns:
|
||||
- 1.1.1.1
|
||||
- 8.8.8.8
|
||||
|
||||
@@ -17,6 +17,8 @@ services:
|
||||
|
||||
session-keeper:
|
||||
build: ./phpsessid-bot
|
||||
image: gcr.forust.xyz/forust/session-keeper:latest
|
||||
pull_policy: build
|
||||
env_file: .env
|
||||
restart: unless-stopped
|
||||
depends_on:
|
||||
@@ -31,6 +33,8 @@ services:
|
||||
|
||||
webinar-checker:
|
||||
build: ./webinar-checker
|
||||
image: gcr.forust.xyz/forust/webinar-checker:latest
|
||||
pull_policy: build
|
||||
env_file: .env
|
||||
restart: unless-stopped
|
||||
depends_on:
|
||||
|
||||
@@ -12,15 +12,26 @@ logging.basicConfig(
|
||||
)
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
# Load configuration
|
||||
LOGIN = os.getenv('EDU_LOGIN')
|
||||
PASSWORD = os.getenv('EDU_PASSWORD')
|
||||
URL_LOGIN = os.getenv('EDU_URL_LOGIN', 'https://edu.edu.vn.ua/user/login')
|
||||
URL_VERIFY = os.getenv('EDU_URL_VERIFY', 'https://edu.edu.vn.ua/course/userlist')
|
||||
INTERVAL = int(os.getenv('PHPSESSID_INTERVAL', 10))
|
||||
USER_AGENT = os.getenv('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
|
||||
REDIS_HOST = os.getenv('REDIS_HOST', 'redis')
|
||||
REDIS_PORT = int(os.getenv('REDIS_PORT', 6379))
|
||||
# Load configuration (adapted to .env keys)
|
||||
def _env(key, default=None):
|
||||
v = os.getenv(key, default)
|
||||
if isinstance(v, str) and len(v) >= 2 and ((v[0] == '"' and v[-1] == '"') or (v[0] == "'" and v[-1] == "'")):
|
||||
return v[1:-1]
|
||||
return v
|
||||
|
||||
LOGIN = _env('KEEPER_LOGIN')
|
||||
PASSWORD = _env('KEEPER_PASSWORD')
|
||||
|
||||
EDU_BASE = _env('EDU_URL_BASE', 'https://edu.edu.vn.ua')
|
||||
EDU_LOGIN_PATH = _env('EDU_URL_LOGIN', '/user/login')
|
||||
EDU_COURSES_PATH = _env('EDU_URL_COURSES', '/course/userlist')
|
||||
URL_LOGIN = f"{EDU_BASE.rstrip('/')}/{EDU_LOGIN_PATH.lstrip('/')}"
|
||||
URL_VERIFY = f"{EDU_BASE.rstrip('/')}/{EDU_COURSES_PATH.lstrip('/')}"
|
||||
|
||||
INTERVAL = int(_env('KEEPER_INTERVAL', 10))
|
||||
USER_AGENT = _env('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
|
||||
REDIS_HOST = _env('REDIS_HOST', 'redis')
|
||||
REDIS_PORT = int(_env('REDIS_PORT', 6379))
|
||||
|
||||
SUCCESS_FILE = '/tmp/last_success'
|
||||
|
||||
|
||||
@@ -1,9 +1,13 @@
|
||||
import os
|
||||
import re
|
||||
import logging
|
||||
import redis
|
||||
import json
|
||||
import time
|
||||
from datetime import datetime, timedelta
|
||||
|
||||
from telegram import Update, InlineKeyboardButton, InlineKeyboardMarkup
|
||||
from telegram import Update, InlineKeyboardButton, InlineKeyboardMarkup, ChatMember
|
||||
from telegram.constants import ChatType
|
||||
from telegram.ext import Application, CommandHandler, CallbackQueryHandler, ContextTypes
|
||||
from playwright.async_api import async_playwright
|
||||
|
||||
@@ -14,22 +18,37 @@ logging.basicConfig(
|
||||
)
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
# Suppress HTTP request logs
|
||||
logging.getLogger('urllib3').setLevel(logging.WARNING)
|
||||
logging.getLogger('httpx').setLevel(logging.WARNING)
|
||||
logging.getLogger('telegram.ext._application').setLevel(logging.WARNING)
|
||||
|
||||
# Load environment variables
|
||||
WEBINAR_URL = os.getenv('WEBINAR_URL', 'https://edu.edu.vn.ua/webinar/useractive')
|
||||
WEBINAR_CHECK_INTERVAL = int(os.getenv('WEBINAR_CHECK_INTERVAL', 60))
|
||||
REDIS_HOST = os.getenv('REDIS_HOST', 'redis')
|
||||
REDIS_PORT = int(os.getenv('REDIS_PORT', 6379))
|
||||
PLAYWRIGHT_WS = os.getenv('PLAYWRIGHT_WS', 'ws://playwright-service:3000/ws')
|
||||
USER_AGENT = os.getenv('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
|
||||
WEBINAR_TELEGRAM_TOKEN = os.getenv('WEBINAR_TELEGRAM_TOKEN')
|
||||
ADMIN_ID = int(os.getenv('WEBINAR_ADMIN_ID', '0'))
|
||||
def _env(key, default=None):
|
||||
v = os.getenv(key, default)
|
||||
if isinstance(v, str) and len(v) >= 2 and ((v[0] == '"' and v[-1] == '"') or (v[0] == "'" and v[-1] == "'")):
|
||||
return v[1:-1]
|
||||
return v
|
||||
|
||||
EDU_BASE = _env('EDU_URL_BASE', 'https://edu.edu.vn.ua')
|
||||
EDU_WEBINAR_PATH = _env('EDU_URL_WEBINAR', '/webinar/useractive')
|
||||
WEBINAR_URL = f"{EDU_BASE.rstrip('/')}/{EDU_WEBINAR_PATH.lstrip('/')}"
|
||||
DIARY_URL = f"{EDU_BASE.rstrip('/')}/user/diary"
|
||||
|
||||
WEBINAR_CHECK_INTERVAL = int(_env('WEBINAR_CHECK_INTERVAL', 60))
|
||||
REDIS_HOST = _env('REDIS_HOST', 'redis')
|
||||
REDIS_PORT = int(_env('REDIS_PORT', 6379))
|
||||
PLAYWRIGHT_WS = _env('PLAYWRIGHT_WS', 'ws://playwright-service:3000/ws')
|
||||
USER_AGENT = _env('USER_AGENT', 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36')
|
||||
WEBINAR_TELEGRAM_TOKEN = _env('WEBINAR_TELEGRAM_TOKEN')
|
||||
ADMIN_ID = int(_env('WEBINAR_ADMIN_ID', '0'))
|
||||
|
||||
# Redis Keys
|
||||
KEY_WHITELIST = "bot:whitelist"
|
||||
KEY_WHITELIST_ENABLED = "bot:whitelist_enabled"
|
||||
KEY_SUBSCRIBERS = "bot:subscribers"
|
||||
KEY_PHPSESSID = "EDU_PHPSESSID"
|
||||
KEY_WEBINAR_HISTORY = "bot:webinar_history" # Stores last 5 webinars
|
||||
KEY_WEBINAR_HISTORY = "bot:webinar_history" # Stores last 3 webinars
|
||||
|
||||
# Initialize Redis
|
||||
try:
|
||||
@@ -48,7 +67,7 @@ TRANSLATIONS = {
|
||||
'welcome_admin': "\n\n👑 <b>Режим администратора активен</b>",
|
||||
'access_denied': "⛔ Доступ запрещен. Вас нет в белом списке.",
|
||||
'help_title': "🤖 <b>Помощь по боту</b>\n\n",
|
||||
'help_commands': "/start - Подписаться на уведомления\n/help - Показать это сообщение\n/language - Сменить язык",
|
||||
'help_commands': "/start - Подписаться на уведомления\n/stop - Отписаться от уведомлений\n/help - Показать это сообщение\n/language - Сменить язык",
|
||||
'help_admin': "\n<b>Команды администратора:</b>\n/adduser [user_id] - Добавить пользователя в белый список\n/removeuser [user_id] - Удалить пользователя из белого списка\nИли используйте панель ниже для управления настройками.",
|
||||
'admin_only': "⛔ Только для администратора!",
|
||||
'user_added': "✅ Пользователь {user_id} добавлен в белый список",
|
||||
@@ -79,13 +98,15 @@ TRANSLATIONS = {
|
||||
'flag_ru': "🇷🇺 Русский",
|
||||
'flag_uk': "🇺🇦 Українська",
|
||||
'flag_en': "🇬🇧 English",
|
||||
'history_cleared': "✅ История вебинаров очищена",
|
||||
'history_clear_failed': "❌ Ошибка при очистке истории",
|
||||
},
|
||||
'uk': {
|
||||
'welcome': "👋 Привіт, {name}!\n\nЯ бот-сповіщувач про вебінари. Я повідомлятиму вас, коли з'явиться новий вебінар.\nВи підписані на сповіщення.",
|
||||
'welcome_admin': "\n\n👑 <b>Режим адміністратора активний</b>",
|
||||
'access_denied': "⛔ Доступ заборонено. Вас немає в білому списку.",
|
||||
'help_title': "🤖 <b>Довідка по боту</b>\n\n",
|
||||
'help_commands': "/start - Підписатися на сповіщення\n/help - Показати це повідомлення\n/language - Змінити мову",
|
||||
'help_commands': "/start - Підписатися на сповіщення\n/stop - Відписатися від сповіщень\n/help - Показати це повідомлення\n/language - Змінити мову",
|
||||
'help_admin': "\n<b>Команди адміністратора:</b>\n/adduser [user_id] - Додати користувача до білого списку\n/removeuser [user_id] - Видалити користувача з білого списку\nАбо використовуйте панель нижче для керування налаштуваннями.",
|
||||
'admin_only': "⛔ Тільки для адміністратора!",
|
||||
'user_added': "✅ Користувач {user_id} доданий до білого списку",
|
||||
@@ -116,13 +137,15 @@ TRANSLATIONS = {
|
||||
'flag_ru': "🇷🇺 Русский",
|
||||
'flag_uk': "🇺🇦 Українська",
|
||||
'flag_en': "🇬🇧 English",
|
||||
'history_cleared': "✅ Історія вебінарів очищена",
|
||||
'history_clear_failed': "❌ Помилка при очищенні історії",
|
||||
},
|
||||
'en': {
|
||||
'welcome': "👋 Hello, {name}!\n\nI am the Webinar Checker Bot. I will notify you when a new webinar appears.\nYou have been subscribed to notifications.",
|
||||
'welcome_admin': "\n\n👑 <b>Admin Mode Active</b>",
|
||||
'access_denied': "⛔ Access denied. You are not on the whitelist.",
|
||||
'help_title': "🤖 <b>Bot Help</b>\n\n",
|
||||
'help_commands': "/start - Subscribe to notifications\n/help - Show this message\n/language - Change language",
|
||||
'help_commands': "/start - Subscribe to notifications\n/stop - Unsubscribe from notifications\n/help - Show this message\n/language - Change language",
|
||||
'help_admin': "\n<b>Admin Commands:</b>\n/adduser [user_id] - Add user to whitelist\n/removeuser [user_id] - Remove user from whitelist\nOr use the panel below to manage settings.",
|
||||
'admin_only': "⛔ Admin only!",
|
||||
'user_added': "✅ User {user_id} added to whitelist",
|
||||
@@ -153,6 +176,8 @@ TRANSLATIONS = {
|
||||
'flag_ru': "🇷🇺 Русский",
|
||||
'flag_uk': "🇺🇦 Українська",
|
||||
'flag_en': "🇬🇧 English",
|
||||
'history_cleared': "✅ Webinar history cleared",
|
||||
'history_clear_failed': "❌ Error clearing history",
|
||||
}
|
||||
}
|
||||
|
||||
@@ -203,6 +228,21 @@ def is_whitelisted(user_id: int) -> bool:
|
||||
|
||||
return redis_client.sismember(KEY_WHITELIST, str(user_id))
|
||||
|
||||
async def is_group_admin(update: Update, context: ContextTypes.DEFAULT_TYPE) -> bool:
|
||||
"""Check if the user is an administrator in the group."""
|
||||
user = update.effective_user
|
||||
chat = update.effective_chat
|
||||
|
||||
if chat.type in [ChatType.PRIVATE, "private"]:
|
||||
return True
|
||||
|
||||
try:
|
||||
member = await context.bot.get_chat_member(chat.id, user.id)
|
||||
return member.status in [ChatMember.OWNER, ChatMember.ADMINISTRATOR]
|
||||
except Exception as e:
|
||||
logger.error(f"Failed to check admin status: {e}")
|
||||
return False
|
||||
|
||||
def get_admin_keyboard(user_id: int):
|
||||
"""Generate admin panel keyboard."""
|
||||
whitelist_enabled = redis_client.get(KEY_WHITELIST_ENABLED) != "0"
|
||||
@@ -216,24 +256,225 @@ def get_admin_keyboard(user_id: int):
|
||||
]
|
||||
return InlineKeyboardMarkup(keyboard)
|
||||
|
||||
# --- Diary Functions ---
|
||||
|
||||
DIARY_MONTH_NAMES = ['', 'Січня', 'Лютого', 'Березня', 'Квітня', 'Травня', 'Червня',
|
||||
'Липня', 'Серпня', 'Вересня', 'Жовтня', 'Листопада', 'Грудня']
|
||||
|
||||
DIARY_WEEKDAYS_SHORT = ['Пн', 'Вт', 'Ср', 'Чт', 'Пт', 'Сб', 'Нд']
|
||||
|
||||
def get_diary_keyboard():
|
||||
today = datetime.now()
|
||||
keyboard = [
|
||||
[
|
||||
InlineKeyboardButton(f"📌 Сьогодні ({today.day}.{today.month:02d})", callback_data="diary_today"),
|
||||
InlineKeyboardButton("📌 Завтра", callback_data="diary_tomorrow"),
|
||||
],
|
||||
[
|
||||
InlineKeyboardButton("📅 Цей тиждень", callback_data="diary_week"),
|
||||
InlineKeyboardButton("📅 Весь місяць", callback_data="diary_month"),
|
||||
],
|
||||
]
|
||||
return InlineKeyboardMarkup(keyboard)
|
||||
|
||||
def _parse_calendar_html(table_html: str) -> tuple:
|
||||
"""Parse calendar HTML table into (month_text, {day_num: {weekday, events}})."""
|
||||
days = {}
|
||||
weekdays = []
|
||||
rows = re.findall(r'<tr[^>]*>(.*?)</tr>', table_html, re.DOTALL)
|
||||
|
||||
month_text = ''
|
||||
for r_idx, row in enumerate(rows):
|
||||
cells = re.findall(r'<t[dh][^>]*>(.*?)</t[dh]>', row, re.DOTALL)
|
||||
|
||||
if r_idx == 0:
|
||||
# Month navigation row: extract "Травень 2026" from nav text
|
||||
raw = re.sub(r'<[^>]+>', ' ', row).strip()
|
||||
raw = re.sub(r'\s+', ' ', raw)
|
||||
m = re.search(r'([А-Яа-яіїєґ\']+\s*:?\s*\d{4})', raw)
|
||||
if m:
|
||||
month_text = m.group(1).replace(' : ', ' ').strip()
|
||||
else:
|
||||
month_text = raw
|
||||
elif r_idx == 1:
|
||||
# Day names row
|
||||
for cell in cells:
|
||||
name = re.sub(r'<[^>]+>', '', cell).strip()
|
||||
if name:
|
||||
weekdays.append(name)
|
||||
else:
|
||||
# Data rows: each cell = a day
|
||||
for col_idx, cell in enumerate(cells):
|
||||
# Extract day number — first number in the cell text
|
||||
text = re.sub(r'<[^>]+>', ' ', cell).strip()
|
||||
text = re.sub(r'\s+', ' ', text)
|
||||
dm = re.match(r'(\d+)', text)
|
||||
if not dm:
|
||||
continue
|
||||
day_num = dm.group(1)
|
||||
|
||||
# Extract events: title attribute (full name) of ALL <a> tags inside the cell
|
||||
events = []
|
||||
for a_match in re.finditer(r'<a[^>]*>(.*?)</a>', cell, re.DOTALL):
|
||||
a_tag = a_match.group(0)
|
||||
# Prefer the title attribute (contains full name, not truncated)
|
||||
title_m = re.search(r'title\s*=\s*"([^"]*)"', a_tag)
|
||||
if title_m:
|
||||
et = title_m.group(1).strip()
|
||||
else:
|
||||
et = re.sub(r'<[^>]+>', '', a_match.group(1)).strip()
|
||||
if et:
|
||||
events.append(et)
|
||||
|
||||
weekday = weekdays[col_idx] if col_idx < len(weekdays) else ''
|
||||
days[day_num] = {'weekday': weekday, 'events': events}
|
||||
|
||||
return month_text, days
|
||||
|
||||
|
||||
async def fetch_diary_data(phpsessid: str) -> dict | None:
|
||||
logger.info("Fetching diary data via Playwright...")
|
||||
try:
|
||||
async with async_playwright() as p:
|
||||
browser = await p.chromium.connect(PLAYWRIGHT_WS)
|
||||
try:
|
||||
context_browser = await browser.new_context(user_agent=USER_AGENT)
|
||||
await context_browser.add_cookies([{
|
||||
'name': 'PHPSESSID',
|
||||
'value': phpsessid,
|
||||
'domain': 'edu.edu.vn.ua',
|
||||
'path': '/'
|
||||
}])
|
||||
page = await context_browser.new_page()
|
||||
|
||||
try:
|
||||
await page.goto(DIARY_URL, wait_until='domcontentloaded')
|
||||
await page.wait_for_selector('table.calendar', timeout=10000)
|
||||
await page.wait_for_timeout(1500)
|
||||
|
||||
table_html = await page.evaluate("""
|
||||
() => {
|
||||
const t = document.querySelector('table.calendar');
|
||||
return t ? t.outerHTML : null;
|
||||
}
|
||||
""")
|
||||
if not table_html:
|
||||
logger.error("table.calendar not found in DOM")
|
||||
return None
|
||||
|
||||
# Debug: save HTML for troubleshooting
|
||||
try:
|
||||
with open('/tmp/diary_debug.html', 'w', encoding='utf-8') as f:
|
||||
f.write(table_html)
|
||||
except Exception:
|
||||
pass
|
||||
|
||||
month_text, days = _parse_calendar_html(table_html)
|
||||
logger.info(f"Diary parsed: month={month_text!r}, days_with_events={sum(1 for d in days.values() if d['events'])}/{len(days)}")
|
||||
|
||||
return {'monthFullText': month_text, 'days': days}
|
||||
|
||||
except Exception as e:
|
||||
logger.error(f"Error parsing diary: {e}")
|
||||
return None
|
||||
finally:
|
||||
await page.close()
|
||||
await context_browser.close()
|
||||
finally:
|
||||
await browser.close()
|
||||
except Exception as e:
|
||||
logger.error(f"Playwright error in diary fetch: {e}")
|
||||
return None
|
||||
|
||||
def _parse_diary_month(text: str) -> str:
|
||||
match = re.search(r'([А-Яа-яіїєґ\']+\s*:\s*\d{4})', text)
|
||||
if match:
|
||||
return match.group(1).replace(' : ', ' ').strip()
|
||||
return text.strip()
|
||||
|
||||
def format_diary_day(data: dict, day_num: int) -> str:
|
||||
days = data.get('days', {})
|
||||
month_str = _parse_diary_month(data.get('monthFullText', ''))
|
||||
day_data = days.get(str(day_num))
|
||||
lines = [f"📅 <b>{day_num} {month_str}</b>", "─" * 18]
|
||||
if not day_data or not day_data.get('events'):
|
||||
lines.append("Немає подій")
|
||||
else:
|
||||
for e in day_data['events']:
|
||||
lines.append(f"📌 {e}")
|
||||
lines.append(f"\n🔗 {DIARY_URL}")
|
||||
return "\n".join(lines)
|
||||
|
||||
def format_diary_week(data: dict, today: datetime) -> str:
|
||||
days = data.get('days', {})
|
||||
month_str = _parse_diary_month(data.get('monthFullText', ''))
|
||||
monday = today - timedelta(days=today.weekday())
|
||||
sunday = monday + timedelta(days=6)
|
||||
lines = [f"📅 <b>Тиждень {monday.day}.{monday.month} – {sunday.day}.{sunday.month}</b>\n"]
|
||||
for i in range(7):
|
||||
d = monday + timedelta(days=i)
|
||||
day_data = days.get(str(d.day))
|
||||
lines.append(f"─ <b>{DIARY_WEEKDAYS_SHORT[i]} {d.day}.{d.month}</b> ─")
|
||||
if not day_data or not day_data.get('events'):
|
||||
lines.append("Немає подій\n")
|
||||
else:
|
||||
for e in day_data['events']:
|
||||
lines.append(f"📌 {e}")
|
||||
lines.append("")
|
||||
lines.append(f"🔗 {DIARY_URL}")
|
||||
return "\n".join(lines)
|
||||
|
||||
def format_diary_month(data: dict) -> str:
|
||||
days = data.get('days', {})
|
||||
month_str = _parse_diary_month(data.get('monthFullText', ''))
|
||||
lines = [f"📅 <b>{month_str}</b>\n"]
|
||||
for day_num in sorted(days.keys(), key=int):
|
||||
day_data = days[day_num]
|
||||
events = day_data.get('events', [])
|
||||
weekday = day_data.get('weekday', '')
|
||||
lines.append(f"─ <b>{weekday} {day_num}</b> ─")
|
||||
if not events:
|
||||
lines.append("Немає подій\n")
|
||||
else:
|
||||
for e in events:
|
||||
lines.append(f"📌 {e}")
|
||||
lines.append("")
|
||||
lines.append(f"🔗 {DIARY_URL}")
|
||||
return "\n".join(lines)
|
||||
|
||||
async def _get_diary_data(context: ContextTypes.DEFAULT_TYPE) -> dict | None:
|
||||
cached = context.user_data.get('diary_cache')
|
||||
now_ts = time.time()
|
||||
if cached and (now_ts - cached.get('timestamp', 0)) < 300:
|
||||
return cached['data']
|
||||
phpsessid = redis_client.get(KEY_PHPSESSID)
|
||||
if not phpsessid:
|
||||
return None
|
||||
data = await fetch_diary_data(phpsessid)
|
||||
if data:
|
||||
context.user_data['diary_cache'] = {'data': data, 'timestamp': now_ts}
|
||||
return data
|
||||
|
||||
# --- Command Handlers ---
|
||||
|
||||
async def start(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
"""Handle /start command."""
|
||||
user = update.effective_user
|
||||
logger.info(f"User {user.id} ({user.username}) started the bot.")
|
||||
chat = update.effective_chat
|
||||
logger.info(f"User {user.id} ({user.username}) started the bot in chat {chat.id} ({chat.type}).")
|
||||
|
||||
# Check whitelist - MUST be the user executing the command
|
||||
if not is_whitelisted(user.id):
|
||||
await update.message.reply_text(t(user.id, 'access_denied'))
|
||||
return
|
||||
|
||||
# Add to subscribers
|
||||
redis_client.sadd(KEY_SUBSCRIBERS, user.id)
|
||||
# Add to subscribers (Chat ID!)
|
||||
redis_client.sadd(KEY_SUBSCRIBERS, chat.id)
|
||||
|
||||
msg = t(user.id, 'welcome', name=user.first_name)
|
||||
msg = t(chat.id, 'welcome', name=user.first_name)
|
||||
|
||||
if user.id == ADMIN_ID:
|
||||
msg += t(user.id, 'welcome_admin')
|
||||
if user.id == ADMIN_ID and chat.type == "private":
|
||||
msg += t(chat.id, 'welcome_admin')
|
||||
await update.message.reply_text(msg, parse_mode='HTML', reply_markup=get_admin_keyboard(user.id))
|
||||
else:
|
||||
await update.message.reply_text(msg, parse_mode='HTML')
|
||||
@@ -241,19 +482,39 @@ async def start(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
async def help_command(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
"""Handle /help command."""
|
||||
user_id = update.effective_user.id
|
||||
msg = t(user_id, 'help_title') + t(user_id, 'help_commands')
|
||||
chat_id = update.effective_chat.id
|
||||
msg = t(chat_id, 'help_title') + t(chat_id, 'help_commands')
|
||||
|
||||
if user_id == ADMIN_ID:
|
||||
msg += t(user_id, 'help_admin')
|
||||
if user_id == ADMIN_ID and update.effective_chat.type == "private":
|
||||
msg += t(chat_id, 'help_admin')
|
||||
await update.message.reply_text(msg, parse_mode='HTML', reply_markup=get_admin_keyboard(user_id))
|
||||
else:
|
||||
await update.message.reply_text(msg, parse_mode='HTML')
|
||||
|
||||
async def stop_command(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
"""Handle /stop command (unsubscribe)."""
|
||||
user = update.effective_user
|
||||
chat = update.effective_chat
|
||||
|
||||
# Permission check: Whitelisted user OR Group Admin
|
||||
if not (is_whitelisted(user.id) or await is_group_admin(update, context)):
|
||||
await update.message.reply_text(t(chat.id, 'access_denied')) # Or specific "admin only" message
|
||||
return
|
||||
|
||||
redis_client.srem(KEY_SUBSCRIBERS, chat.id)
|
||||
await update.message.reply_text(t(chat.id, 'whitelist_disabled').replace(" whitelist", " notifications").replace("Білий список", "Сповіщення").replace("Белый список", "Уведомления") if chat.id else "Unsubscribed")
|
||||
|
||||
async def language_command(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
"""Handle /language command."""
|
||||
user_id = update.effective_user.id
|
||||
user = update.effective_user
|
||||
chat = update.effective_chat
|
||||
|
||||
# Permission check for groups
|
||||
if not (is_whitelisted(user.id) or await is_group_admin(update, context)):
|
||||
return
|
||||
|
||||
await update.message.reply_text(
|
||||
t(user_id, 'select_language'),
|
||||
t(chat.id, 'select_language'),
|
||||
parse_mode='HTML',
|
||||
reply_markup=get_language_keyboard()
|
||||
)
|
||||
@@ -303,6 +564,89 @@ async def remove_user(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
except ValueError:
|
||||
await update.message.reply_text(t(admin_id, 'invalid_user_id'))
|
||||
|
||||
async def clear_history(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
"""Clear webinar history (admin only)."""
|
||||
admin_id = update.effective_user.id
|
||||
if admin_id != ADMIN_ID:
|
||||
await update.message.reply_text(t(admin_id, 'admin_only'))
|
||||
return
|
||||
|
||||
try:
|
||||
redis_client.delete(KEY_WEBINAR_HISTORY)
|
||||
await update.message.reply_text(t(admin_id, 'history_cleared'))
|
||||
logger.info("Admin cleared webinar history")
|
||||
except Exception as e:
|
||||
logger.error(f"Failed to clear history: {e}")
|
||||
await update.message.reply_text(t(admin_id, 'history_clear_failed'))
|
||||
|
||||
async def diary_command(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
user = update.effective_user
|
||||
chat = update.effective_chat
|
||||
if not is_whitelisted(user.id):
|
||||
await update.message.reply_text(t(user.id, 'access_denied'))
|
||||
return
|
||||
await update.message.reply_text(
|
||||
"📅 <b>Щоденник</b> — виберіть період:",
|
||||
parse_mode='HTML',
|
||||
reply_markup=get_diary_keyboard()
|
||||
)
|
||||
|
||||
async def diary_callback(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
query = update.callback_query
|
||||
user_id = query.from_user.id
|
||||
await query.answer()
|
||||
|
||||
if user_id != ADMIN_ID:
|
||||
if not is_whitelisted(user_id):
|
||||
await query.edit_message_text("⛔ Доступ заборонено.")
|
||||
return
|
||||
|
||||
data = query.data
|
||||
if data == "diary_refresh":
|
||||
context.user_data.pop('diary_cache', None)
|
||||
await query.edit_message_text("🔄 Завантажую щоденник...")
|
||||
diary_data = await _get_diary_data(context)
|
||||
if not diary_data:
|
||||
await query.edit_message_text("❌ Не вдалося завантажити щоденник. Немає сесії або помилка.")
|
||||
return
|
||||
await query.edit_message_text(
|
||||
"📅 <b>Щоденник</b> — виберіть період:",
|
||||
parse_mode='HTML',
|
||||
reply_markup=get_diary_keyboard()
|
||||
)
|
||||
return
|
||||
|
||||
await query.edit_message_text("🔄 Завантажую щоденник...")
|
||||
diary_data = await _get_diary_data(context)
|
||||
if not diary_data:
|
||||
await query.edit_message_text("❌ Не вдалося завантажити щоденник.")
|
||||
return
|
||||
|
||||
today = datetime.now()
|
||||
if data == "diary_today":
|
||||
text = format_diary_day(diary_data, today.day)
|
||||
elif data == "diary_tomorrow":
|
||||
tomorrow = today + timedelta(days=1)
|
||||
if tomorrow.day < today.day:
|
||||
text = "❌ Дані за наступний місяць недоступні. Перейдіть на сайт."
|
||||
else:
|
||||
text = format_diary_day(diary_data, tomorrow.day)
|
||||
elif data == "diary_week":
|
||||
text = format_diary_week(diary_data, today)
|
||||
elif data == "diary_month":
|
||||
text = format_diary_month(diary_data)
|
||||
else:
|
||||
return
|
||||
|
||||
if len(text) > 4096:
|
||||
text = text[:4090] + "\n\n✂️ ...(обрізано)"
|
||||
|
||||
await query.edit_message_text(
|
||||
text,
|
||||
parse_mode='HTML',
|
||||
reply_markup=get_diary_keyboard()
|
||||
)
|
||||
|
||||
# --- Admin Callbacks ---
|
||||
|
||||
async def admin_callback(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
@@ -363,9 +707,9 @@ async def language_callback(update: Update, context: ContextTypes.DEFAULT_TYPE):
|
||||
|
||||
# --- Webinar Checking Job ---
|
||||
|
||||
def get_webinar_key(name: str, url: str) -> str:
|
||||
"""Generate unique key for a webinar based on name and URL."""
|
||||
return f"{name}|{url}"
|
||||
def get_webinar_key(url: str) -> str:
|
||||
"""Generate unique key for a webinar based on URL."""
|
||||
return url
|
||||
|
||||
def get_stored_webinars() -> list:
|
||||
"""Get list of stored webinar keys from Redis."""
|
||||
@@ -378,9 +722,9 @@ def get_stored_webinars() -> list:
|
||||
return []
|
||||
|
||||
def store_webinars(webinar_keys: list):
|
||||
"""Store up to 5 most recent webinar keys in Redis."""
|
||||
# Keep only last 5
|
||||
webinar_keys = webinar_keys[-5:]
|
||||
"""Store up to 3 most recent webinar keys in Redis."""
|
||||
# Keep only last 3
|
||||
webinar_keys = webinar_keys[-3:]
|
||||
try:
|
||||
redis_client.set(KEY_WEBINAR_HISTORY, json.dumps(webinar_keys))
|
||||
logger.info(f"Stored {len(webinar_keys)} webinar(s) in history")
|
||||
@@ -515,7 +859,7 @@ async def check_webinars_job(context: ContextTypes.DEFAULT_TYPE):
|
||||
current_keys = []
|
||||
|
||||
for webinar in current_webinars:
|
||||
key = get_webinar_key(webinar['name'], webinar['url'])
|
||||
key = get_webinar_key(webinar['url'])
|
||||
current_keys.append(key)
|
||||
|
||||
if key not in stored_keys:
|
||||
@@ -535,6 +879,7 @@ async def check_webinars_job(context: ContextTypes.DEFAULT_TYPE):
|
||||
for sub_id in subscribers:
|
||||
try:
|
||||
# Build message in user's language
|
||||
# sub_id comes from redis set as string, convert to int for translation lookup
|
||||
webinar_items = "\n\n".join([
|
||||
t(int(sub_id), 'webinar_item', name=w['name'], url=w['url'])
|
||||
for w in new_webinars
|
||||
@@ -569,12 +914,16 @@ def main():
|
||||
|
||||
# Handlers
|
||||
app.add_handler(CommandHandler("start", start))
|
||||
app.add_handler(CommandHandler("stop", stop_command))
|
||||
app.add_handler(CommandHandler("help", help_command))
|
||||
app.add_handler(CommandHandler("language", language_command))
|
||||
app.add_handler(CommandHandler("adduser", add_user))
|
||||
app.add_handler(CommandHandler("removeuser", remove_user))
|
||||
app.add_handler(CommandHandler("clearhistory", clear_history))
|
||||
app.add_handler(CommandHandler("diary", diary_command))
|
||||
|
||||
# Callback handlers - language selection first, then admin panel
|
||||
# Callback handlers - diary first, then language selection, then admin panel
|
||||
app.add_handler(CallbackQueryHandler(diary_callback, pattern="^diary_"))
|
||||
app.add_handler(CallbackQueryHandler(language_callback, pattern="^lang_"))
|
||||
app.add_handler(CallbackQueryHandler(admin_callback))
|
||||
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
FROM nginx:alpine
|
||||
RUN rm -rf /usr/share/nginx/html/*
|
||||
COPY html /usr/share/nginx/html
|
||||
EXPOSE 80
|
||||
CMD ["nginx", "-g", "daemon off;"]
|
||||
@@ -0,0 +1,21 @@
|
||||
services:
|
||||
errorpage:
|
||||
build: .
|
||||
image: gcr.forust.xyz/forust/error-pages:latest
|
||||
pull_policy: build
|
||||
container_name: error-pages
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - 1234:80
|
||||
networks:
|
||||
- proxy
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.error-pages.loadbalancer.server.port=80"
|
||||
# Error handler middleware
|
||||
- "traefik.http.middlewares.error-pages.errors.status=400,402-599"
|
||||
- "traefik.http.middlewares.error-pages.errors.service=error-pages"
|
||||
- "traefik.http.middlewares.error-pages.errors.query=/{status}.html"
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
@@ -0,0 +1,208 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>403 // Forbidden</title>
|
||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||
<style>
|
||||
/* hidden in a plain sight? */
|
||||
:root {
|
||||
--bg-color: #050505;
|
||||
--text-color: #e0e0e0;
|
||||
--accent: #ffffff;
|
||||
--dim: #666666;
|
||||
--font-mono: 'Courier New', Courier, monospace;
|
||||
}
|
||||
|
||||
* {
|
||||
box-sizing: border-box;
|
||||
margin: 0;
|
||||
padding: 0;
|
||||
}
|
||||
|
||||
body {
|
||||
background-color: var(--bg-color);
|
||||
color: var(--text-color);
|
||||
font-family: var(--font-mono);
|
||||
line-height: 1.6;
|
||||
font-size: 16px;
|
||||
padding: 2rem;
|
||||
}
|
||||
|
||||
a {
|
||||
color: var(--text-color);
|
||||
text-decoration: none;
|
||||
border-bottom: 1px solid var(--dim);
|
||||
transition: all 0.2s;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
background-color: var(--text-color);
|
||||
color: var(--bg-color);
|
||||
border-color: var(--text-color);
|
||||
}
|
||||
|
||||
.container {
|
||||
max-width: 800px;
|
||||
margin: 0 auto;
|
||||
}
|
||||
|
||||
/* TEXT */
|
||||
h1 {
|
||||
font-size: 2.5rem;
|
||||
text-transform: uppercase;
|
||||
letter-spacing: -2px;
|
||||
margin-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
h2 {
|
||||
font-size: 1.2rem;
|
||||
margin-bottom: 1.5rem;
|
||||
border-bottom: 1px solid var(--dim);
|
||||
display: inline-block;
|
||||
padding-right: 20px;
|
||||
}
|
||||
|
||||
.subtitle {
|
||||
color: var(--dim);
|
||||
margin-bottom: 2rem;
|
||||
}
|
||||
|
||||
hr {
|
||||
border: 0;
|
||||
border-top: 1px dashed var(--dim);
|
||||
margin: 2rem 0;
|
||||
}
|
||||
|
||||
.comment {
|
||||
color: var(--dim);
|
||||
font-size: 0.9rem;
|
||||
margin-left: 10px;
|
||||
}
|
||||
|
||||
/* SECTIONS */
|
||||
section {
|
||||
margin-bottom: 3rem;
|
||||
}
|
||||
|
||||
/* LISTS */
|
||||
ul {
|
||||
list-style: none;
|
||||
}
|
||||
|
||||
.link-list li {
|
||||
margin-bottom: 0.8rem;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 15px;
|
||||
}
|
||||
|
||||
/* STACK GRID */
|
||||
.grid-2 {
|
||||
display: grid;
|
||||
grid-template-columns: 1fr 1fr;
|
||||
gap: 2rem;
|
||||
}
|
||||
|
||||
.skill-item {
|
||||
display: flex;
|
||||
justify-content: space-between;
|
||||
margin-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
.level {
|
||||
font-weight: bold;
|
||||
}
|
||||
|
||||
.special .level {
|
||||
color: var(--text-color);
|
||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
||||
}
|
||||
|
||||
/* my dudes */
|
||||
.team-grid {
|
||||
display: flex;
|
||||
gap: 2rem;
|
||||
flex-wrap: wrap;
|
||||
margin-top: 1rem;
|
||||
}
|
||||
|
||||
.member {
|
||||
text-align: center;
|
||||
width: 100px;
|
||||
}
|
||||
|
||||
.avatar {
|
||||
width: 80px;
|
||||
height: 80px;
|
||||
background-color: #222;
|
||||
border: 2px solid var(--text-color);
|
||||
margin: 0 auto 10px auto;
|
||||
background-size: cover;
|
||||
}
|
||||
|
||||
/* if no avatar added: */
|
||||
.placeholder::before {
|
||||
content: "?";
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
height: 100%;
|
||||
font-size: 2rem;
|
||||
color: var(--dim);
|
||||
}
|
||||
|
||||
/* REPOS */
|
||||
.repo-list li {
|
||||
margin-bottom: 1rem;
|
||||
}
|
||||
|
||||
/* FOOTER */
|
||||
footer {
|
||||
text-align: center;
|
||||
color: var(--dim);
|
||||
font-size: 0.8rem;
|
||||
/* flag{why-are-you-here?} */
|
||||
margin-top: 4rem;
|
||||
}
|
||||
/* SMTH RESPONSIVE */
|
||||
@media (max-width: 600px) {
|
||||
.grid-2 {
|
||||
grid-template-columns: 1fr;
|
||||
gap: 0;
|
||||
}
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
|
||||
<body>
|
||||
|
||||
<div class="container">
|
||||
<header>
|
||||
<h1 class="glitch" data-text="403">403</h1>
|
||||
<p class="subtitle">> Forbidden / Access Denied.</p>
|
||||
</header>
|
||||
|
||||
<hr>
|
||||
|
||||
<section id="message">
|
||||
<h2>./error_message</h2>
|
||||
<p>You do not have permission to access this resource.</p>
|
||||
<br>
|
||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> if you believe this is an
|
||||
error.</p>
|
||||
</section>
|
||||
|
||||
<footer>
|
||||
<p>root@error:~$ sudo access_resource</p>
|
||||
<p>User is not in the sudoers file. This incident will be reported.</p>
|
||||
<p>© XRock - Just Signal.</p>
|
||||
</footer>
|
||||
</div>
|
||||
|
||||
</body>
|
||||
|
||||
</html>
|
||||
@@ -0,0 +1,207 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>404 // Not Found</title>
|
||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||
<style>
|
||||
/* hidden in a plain sight? */
|
||||
:root {
|
||||
--bg-color: #050505;
|
||||
--text-color: #e0e0e0;
|
||||
--accent: #ffffff;
|
||||
--dim: #666666;
|
||||
--font-mono: 'Courier New', Courier, monospace;
|
||||
}
|
||||
|
||||
* {
|
||||
box-sizing: border-box;
|
||||
margin: 0;
|
||||
padding: 0;
|
||||
}
|
||||
|
||||
body {
|
||||
background-color: var(--bg-color);
|
||||
color: var(--text-color);
|
||||
font-family: var(--font-mono);
|
||||
line-height: 1.6;
|
||||
font-size: 16px;
|
||||
padding: 2rem;
|
||||
}
|
||||
|
||||
a {
|
||||
color: var(--text-color);
|
||||
text-decoration: none;
|
||||
border-bottom: 1px solid var(--dim);
|
||||
transition: all 0.2s;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
background-color: var(--text-color);
|
||||
color: var(--bg-color);
|
||||
border-color: var(--text-color);
|
||||
}
|
||||
|
||||
.container {
|
||||
max-width: 800px;
|
||||
margin: 0 auto;
|
||||
}
|
||||
|
||||
/* TEXT */
|
||||
h1 {
|
||||
font-size: 2.5rem;
|
||||
text-transform: uppercase;
|
||||
letter-spacing: -2px;
|
||||
margin-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
h2 {
|
||||
font-size: 1.2rem;
|
||||
margin-bottom: 1.5rem;
|
||||
border-bottom: 1px solid var(--dim);
|
||||
display: inline-block;
|
||||
padding-right: 20px;
|
||||
}
|
||||
|
||||
.subtitle {
|
||||
color: var(--dim);
|
||||
margin-bottom: 2rem;
|
||||
}
|
||||
|
||||
hr {
|
||||
border: 0;
|
||||
border-top: 1px dashed var(--dim);
|
||||
margin: 2rem 0;
|
||||
}
|
||||
|
||||
.comment {
|
||||
color: var(--dim);
|
||||
font-size: 0.9rem;
|
||||
margin-left: 10px;
|
||||
}
|
||||
|
||||
/* SECTIONS */
|
||||
section {
|
||||
margin-bottom: 3rem;
|
||||
}
|
||||
|
||||
/* LISTS */
|
||||
ul {
|
||||
list-style: none;
|
||||
}
|
||||
|
||||
.link-list li {
|
||||
margin-bottom: 0.8rem;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 15px;
|
||||
}
|
||||
|
||||
/* STACK GRID */
|
||||
.grid-2 {
|
||||
display: grid;
|
||||
grid-template-columns: 1fr 1fr;
|
||||
gap: 2rem;
|
||||
}
|
||||
|
||||
.skill-item {
|
||||
display: flex;
|
||||
justify-content: space-between;
|
||||
margin-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
.level {
|
||||
font-weight: bold;
|
||||
}
|
||||
|
||||
.special .level {
|
||||
color: var(--text-color);
|
||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
||||
}
|
||||
|
||||
/* my dudes */
|
||||
.team-grid {
|
||||
display: flex;
|
||||
gap: 2rem;
|
||||
flex-wrap: wrap;
|
||||
margin-top: 1rem;
|
||||
}
|
||||
|
||||
.member {
|
||||
text-align: center;
|
||||
width: 100px;
|
||||
}
|
||||
|
||||
.avatar {
|
||||
width: 80px;
|
||||
height: 80px;
|
||||
background-color: #222;
|
||||
border: 2px solid var(--text-color);
|
||||
margin: 0 auto 10px auto;
|
||||
background-size: cover;
|
||||
}
|
||||
|
||||
/* if no avatar added: */
|
||||
.placeholder::before {
|
||||
content: "?";
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
height: 100%;
|
||||
font-size: 2rem;
|
||||
color: var(--dim);
|
||||
}
|
||||
|
||||
/* REPOS */
|
||||
.repo-list li {
|
||||
margin-bottom: 1rem;
|
||||
}
|
||||
|
||||
/* FOOTER */
|
||||
footer {
|
||||
text-align: center;
|
||||
color: var(--dim);
|
||||
font-size: 0.8rem;
|
||||
/* flag{why-are-you-here?} */
|
||||
margin-top: 4rem;
|
||||
}
|
||||
/* SMTH RESPONSIVE */
|
||||
@media (max-width: 600px) {
|
||||
.grid-2 {
|
||||
grid-template-columns: 1fr;
|
||||
gap: 0;
|
||||
}
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
|
||||
<body>
|
||||
|
||||
<div class="container">
|
||||
<header>
|
||||
<h1 class="glitch" data-text="404">404</h1>
|
||||
<p class="subtitle">> Page Not Found / Lost in the Void.</p>
|
||||
</header>
|
||||
|
||||
<hr>
|
||||
|
||||
<section id="message">
|
||||
<h2>./error_message</h2>
|
||||
<p>The page you are looking for does not exist or has been moved.</p>
|
||||
<br>
|
||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> if you believe this is an error.</p>
|
||||
</section>
|
||||
|
||||
<footer>
|
||||
<p>root@error:~$ ping target</p>
|
||||
<p>Destination Host Unreachable</p>
|
||||
<p>© XRock - Just Signal.</p>
|
||||
</footer>
|
||||
</div>
|
||||
|
||||
</body>
|
||||
|
||||
</html>
|
||||
@@ -0,0 +1,207 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>500 // Server Error</title>
|
||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||
<style>
|
||||
/* hidden in a plain sight? */
|
||||
:root {
|
||||
--bg-color: #050505;
|
||||
--text-color: #e0e0e0;
|
||||
--accent: #ffffff;
|
||||
--dim: #666666;
|
||||
--font-mono: 'Courier New', Courier, monospace;
|
||||
}
|
||||
|
||||
* {
|
||||
box-sizing: border-box;
|
||||
margin: 0;
|
||||
padding: 0;
|
||||
}
|
||||
|
||||
body {
|
||||
background-color: var(--bg-color);
|
||||
color: var(--text-color);
|
||||
font-family: var(--font-mono);
|
||||
line-height: 1.6;
|
||||
font-size: 16px;
|
||||
padding: 2rem;
|
||||
}
|
||||
|
||||
a {
|
||||
color: var(--text-color);
|
||||
text-decoration: none;
|
||||
border-bottom: 1px solid var(--dim);
|
||||
transition: all 0.2s;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
background-color: var(--text-color);
|
||||
color: var(--bg-color);
|
||||
border-color: var(--text-color);
|
||||
}
|
||||
|
||||
.container {
|
||||
max-width: 800px;
|
||||
margin: 0 auto;
|
||||
}
|
||||
|
||||
/* TEXT */
|
||||
h1 {
|
||||
font-size: 2.5rem;
|
||||
text-transform: uppercase;
|
||||
letter-spacing: -2px;
|
||||
margin-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
h2 {
|
||||
font-size: 1.2rem;
|
||||
margin-bottom: 1.5rem;
|
||||
border-bottom: 1px solid var(--dim);
|
||||
display: inline-block;
|
||||
padding-right: 20px;
|
||||
}
|
||||
|
||||
.subtitle {
|
||||
color: var(--dim);
|
||||
margin-bottom: 2rem;
|
||||
}
|
||||
|
||||
hr {
|
||||
border: 0;
|
||||
border-top: 1px dashed var(--dim);
|
||||
margin: 2rem 0;
|
||||
}
|
||||
|
||||
.comment {
|
||||
color: var(--dim);
|
||||
font-size: 0.9rem;
|
||||
margin-left: 10px;
|
||||
}
|
||||
|
||||
/* SECTIONS */
|
||||
section {
|
||||
margin-bottom: 3rem;
|
||||
}
|
||||
|
||||
/* LISTS */
|
||||
ul {
|
||||
list-style: none;
|
||||
}
|
||||
|
||||
.link-list li {
|
||||
margin-bottom: 0.8rem;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 15px;
|
||||
}
|
||||
|
||||
/* STACK GRID */
|
||||
.grid-2 {
|
||||
display: grid;
|
||||
grid-template-columns: 1fr 1fr;
|
||||
gap: 2rem;
|
||||
}
|
||||
|
||||
.skill-item {
|
||||
display: flex;
|
||||
justify-content: space-between;
|
||||
margin-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
.level {
|
||||
font-weight: bold;
|
||||
}
|
||||
|
||||
.special .level {
|
||||
color: var(--text-color);
|
||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
||||
}
|
||||
|
||||
/* my dudes */
|
||||
.team-grid {
|
||||
display: flex;
|
||||
gap: 2rem;
|
||||
flex-wrap: wrap;
|
||||
margin-top: 1rem;
|
||||
}
|
||||
|
||||
.member {
|
||||
text-align: center;
|
||||
width: 100px;
|
||||
}
|
||||
|
||||
.avatar {
|
||||
width: 80px;
|
||||
height: 80px;
|
||||
background-color: #222;
|
||||
border: 2px solid var(--text-color);
|
||||
margin: 0 auto 10px auto;
|
||||
background-size: cover;
|
||||
}
|
||||
|
||||
/* if no avatar added: */
|
||||
.placeholder::before {
|
||||
content: "?";
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
height: 100%;
|
||||
font-size: 2rem;
|
||||
color: var(--dim);
|
||||
}
|
||||
|
||||
/* REPOS */
|
||||
.repo-list li {
|
||||
margin-bottom: 1rem;
|
||||
}
|
||||
|
||||
/* FOOTER */
|
||||
footer {
|
||||
text-align: center;
|
||||
color: var(--dim);
|
||||
font-size: 0.8rem;
|
||||
/* flag{why-are-you-here?} */
|
||||
margin-top: 4rem;
|
||||
}
|
||||
/* SMTH RESPONSIVE */
|
||||
@media (max-width: 600px) {
|
||||
.grid-2 {
|
||||
grid-template-columns: 1fr;
|
||||
gap: 0;
|
||||
}
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
|
||||
<body>
|
||||
|
||||
<div class="container">
|
||||
<header>
|
||||
<h1 class="glitch" data-text="500">500</h1>
|
||||
<p class="subtitle">> Internal Server Error / System Failure.</p>
|
||||
</header>
|
||||
|
||||
<hr>
|
||||
|
||||
<section id="message">
|
||||
<h2>./error_message</h2>
|
||||
<p>Something went wrong on our end. We are working to fix it.</p>
|
||||
<br>
|
||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> for more information.</p>
|
||||
</section>
|
||||
|
||||
<footer>
|
||||
<p>root@error:~$ systemctl status service</p>
|
||||
<p>Active: failed (Result: core-dump)</p>
|
||||
<p>© XRock - Just Signal.</p>
|
||||
</footer>
|
||||
</div>
|
||||
|
||||
</body>
|
||||
|
||||
</html>
|
||||
@@ -0,0 +1,207 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>502 // Bad Gateway</title>
|
||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||
<style>
|
||||
/* hidden in a plain sight? */
|
||||
:root {
|
||||
--bg-color: #050505;
|
||||
--text-color: #e0e0e0;
|
||||
--accent: #ffffff;
|
||||
--dim: #666666;
|
||||
--font-mono: 'Courier New', Courier, monospace;
|
||||
}
|
||||
|
||||
* {
|
||||
box-sizing: border-box;
|
||||
margin: 0;
|
||||
padding: 0;
|
||||
}
|
||||
|
||||
body {
|
||||
background-color: var(--bg-color);
|
||||
color: var(--text-color);
|
||||
font-family: var(--font-mono);
|
||||
line-height: 1.6;
|
||||
font-size: 16px;
|
||||
padding: 2rem;
|
||||
}
|
||||
|
||||
a {
|
||||
color: var(--text-color);
|
||||
text-decoration: none;
|
||||
border-bottom: 1px solid var(--dim);
|
||||
transition: all 0.2s;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
background-color: var(--text-color);
|
||||
color: var(--bg-color);
|
||||
border-color: var(--text-color);
|
||||
}
|
||||
|
||||
.container {
|
||||
max-width: 800px;
|
||||
margin: 0 auto;
|
||||
}
|
||||
|
||||
/* TEXT */
|
||||
h1 {
|
||||
font-size: 2.5rem;
|
||||
text-transform: uppercase;
|
||||
letter-spacing: -2px;
|
||||
margin-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
h2 {
|
||||
font-size: 1.2rem;
|
||||
margin-bottom: 1.5rem;
|
||||
border-bottom: 1px solid var(--dim);
|
||||
display: inline-block;
|
||||
padding-right: 20px;
|
||||
}
|
||||
|
||||
.subtitle {
|
||||
color: var(--dim);
|
||||
margin-bottom: 2rem;
|
||||
}
|
||||
|
||||
hr {
|
||||
border: 0;
|
||||
border-top: 1px dashed var(--dim);
|
||||
margin: 2rem 0;
|
||||
}
|
||||
|
||||
.comment {
|
||||
color: var(--dim);
|
||||
font-size: 0.9rem;
|
||||
margin-left: 10px;
|
||||
}
|
||||
|
||||
/* SECTIONS */
|
||||
section {
|
||||
margin-bottom: 3rem;
|
||||
}
|
||||
|
||||
/* LISTS */
|
||||
ul {
|
||||
list-style: none;
|
||||
}
|
||||
|
||||
.link-list li {
|
||||
margin-bottom: 0.8rem;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 15px;
|
||||
}
|
||||
|
||||
/* STACK GRID */
|
||||
.grid-2 {
|
||||
display: grid;
|
||||
grid-template-columns: 1fr 1fr;
|
||||
gap: 2rem;
|
||||
}
|
||||
|
||||
.skill-item {
|
||||
display: flex;
|
||||
justify-content: space-between;
|
||||
margin-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
.level {
|
||||
font-weight: bold;
|
||||
}
|
||||
|
||||
.special .level {
|
||||
color: var(--text-color);
|
||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
||||
}
|
||||
|
||||
/* my dudes */
|
||||
.team-grid {
|
||||
display: flex;
|
||||
gap: 2rem;
|
||||
flex-wrap: wrap;
|
||||
margin-top: 1rem;
|
||||
}
|
||||
|
||||
.member {
|
||||
text-align: center;
|
||||
width: 100px;
|
||||
}
|
||||
|
||||
.avatar {
|
||||
width: 80px;
|
||||
height: 80px;
|
||||
background-color: #222;
|
||||
border: 2px solid var(--text-color);
|
||||
margin: 0 auto 10px auto;
|
||||
background-size: cover;
|
||||
}
|
||||
|
||||
/* if no avatar added: */
|
||||
.placeholder::before {
|
||||
content: "?";
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
height: 100%;
|
||||
font-size: 2rem;
|
||||
color: var(--dim);
|
||||
}
|
||||
|
||||
/* REPOS */
|
||||
.repo-list li {
|
||||
margin-bottom: 1rem;
|
||||
}
|
||||
|
||||
/* FOOTER */
|
||||
footer {
|
||||
text-align: center;
|
||||
color: var(--dim);
|
||||
font-size: 0.8rem;
|
||||
/* flag{why-are-you-here?} */
|
||||
margin-top: 4rem;
|
||||
}
|
||||
/* SMTH RESPONSIVE */
|
||||
@media (max-width: 600px) {
|
||||
.grid-2 {
|
||||
grid-template-columns: 1fr;
|
||||
gap: 0;
|
||||
}
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
|
||||
<body>
|
||||
|
||||
<div class="container">
|
||||
<header>
|
||||
<h1 class="glitch" data-text="502">502</h1>
|
||||
<p class="subtitle">> Bad Gateway / System Failure.</p>
|
||||
</header>
|
||||
|
||||
<hr>
|
||||
|
||||
<section id="message">
|
||||
<h2>./error_message</h2>
|
||||
<p>The server received an invalid response from the upstream server.</p>
|
||||
<br>
|
||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> for more information.</p>
|
||||
</section>
|
||||
|
||||
<footer>
|
||||
<p>root@error:~$ curl -I upstream_host</p>
|
||||
<p>HTTP/1.1 502 Bad Gateway</p>
|
||||
<p>© XRock - Just Signal.</p>
|
||||
</footer>
|
||||
</div>
|
||||
|
||||
</body>
|
||||
|
||||
</html>
|
||||
@@ -0,0 +1,207 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>503 // Service Unavailable</title>
|
||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||
<style>
|
||||
/* hidden in a plain sight? */
|
||||
:root {
|
||||
--bg-color: #050505;
|
||||
--text-color: #e0e0e0;
|
||||
--accent: #ffffff;
|
||||
--dim: #666666;
|
||||
--font-mono: 'Courier New', Courier, monospace;
|
||||
}
|
||||
|
||||
* {
|
||||
box-sizing: border-box;
|
||||
margin: 0;
|
||||
padding: 0;
|
||||
}
|
||||
|
||||
body {
|
||||
background-color: var(--bg-color);
|
||||
color: var(--text-color);
|
||||
font-family: var(--font-mono);
|
||||
line-height: 1.6;
|
||||
font-size: 16px;
|
||||
padding: 2rem;
|
||||
}
|
||||
|
||||
a {
|
||||
color: var(--text-color);
|
||||
text-decoration: none;
|
||||
border-bottom: 1px solid var(--dim);
|
||||
transition: all 0.2s;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
background-color: var(--text-color);
|
||||
color: var(--bg-color);
|
||||
border-color: var(--text-color);
|
||||
}
|
||||
|
||||
.container {
|
||||
max-width: 800px;
|
||||
margin: 0 auto;
|
||||
}
|
||||
|
||||
/* TEXT */
|
||||
h1 {
|
||||
font-size: 2.5rem;
|
||||
text-transform: uppercase;
|
||||
letter-spacing: -2px;
|
||||
margin-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
h2 {
|
||||
font-size: 1.2rem;
|
||||
margin-bottom: 1.5rem;
|
||||
border-bottom: 1px solid var(--dim);
|
||||
display: inline-block;
|
||||
padding-right: 20px;
|
||||
}
|
||||
|
||||
.subtitle {
|
||||
color: var(--dim);
|
||||
margin-bottom: 2rem;
|
||||
}
|
||||
|
||||
hr {
|
||||
border: 0;
|
||||
border-top: 1px dashed var(--dim);
|
||||
margin: 2rem 0;
|
||||
}
|
||||
|
||||
.comment {
|
||||
color: var(--dim);
|
||||
font-size: 0.9rem;
|
||||
margin-left: 10px;
|
||||
}
|
||||
|
||||
/* SECTIONS */
|
||||
section {
|
||||
margin-bottom: 3rem;
|
||||
}
|
||||
|
||||
/* LISTS */
|
||||
ul {
|
||||
list-style: none;
|
||||
}
|
||||
|
||||
.link-list li {
|
||||
margin-bottom: 0.8rem;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 15px;
|
||||
}
|
||||
|
||||
/* STACK GRID */
|
||||
.grid-2 {
|
||||
display: grid;
|
||||
grid-template-columns: 1fr 1fr;
|
||||
gap: 2rem;
|
||||
}
|
||||
|
||||
.skill-item {
|
||||
display: flex;
|
||||
justify-content: space-between;
|
||||
margin-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
.level {
|
||||
font-weight: bold;
|
||||
}
|
||||
|
||||
.special .level {
|
||||
color: var(--text-color);
|
||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
||||
}
|
||||
|
||||
/* my dudes */
|
||||
.team-grid {
|
||||
display: flex;
|
||||
gap: 2rem;
|
||||
flex-wrap: wrap;
|
||||
margin-top: 1rem;
|
||||
}
|
||||
|
||||
.member {
|
||||
text-align: center;
|
||||
width: 100px;
|
||||
}
|
||||
|
||||
.avatar {
|
||||
width: 80px;
|
||||
height: 80px;
|
||||
background-color: #222;
|
||||
border: 2px solid var(--text-color);
|
||||
margin: 0 auto 10px auto;
|
||||
background-size: cover;
|
||||
}
|
||||
|
||||
/* if no avatar added: */
|
||||
.placeholder::before {
|
||||
content: "?";
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
height: 100%;
|
||||
font-size: 2rem;
|
||||
color: var(--dim);
|
||||
}
|
||||
|
||||
/* REPOS */
|
||||
.repo-list li {
|
||||
margin-bottom: 1rem;
|
||||
}
|
||||
|
||||
/* FOOTER */
|
||||
footer {
|
||||
text-align: center;
|
||||
color: var(--dim);
|
||||
font-size: 0.8rem;
|
||||
/* flag{why-are-you-here?} */
|
||||
margin-top: 4rem;
|
||||
}
|
||||
/* SMTH RESPONSIVE */
|
||||
@media (max-width: 600px) {
|
||||
.grid-2 {
|
||||
grid-template-columns: 1fr;
|
||||
gap: 0;
|
||||
}
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
|
||||
<body>
|
||||
|
||||
<div class="container">
|
||||
<header>
|
||||
<h1 class="glitch" data-text="503">503</h1>
|
||||
<p class="subtitle">> Service Unavailable / System Failure.</p>
|
||||
</header>
|
||||
|
||||
<hr>
|
||||
|
||||
<section id="message">
|
||||
<h2>./error_message</h2>
|
||||
<p>The server is currently unable to handle the request due to maintenance or overload.</p>
|
||||
<br>
|
||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> for more information.</p>
|
||||
</section>
|
||||
|
||||
<footer>
|
||||
<p>root@error:~$ systemctl start service</p>
|
||||
<p>Job for service failed because the control process exited with error code.</p>
|
||||
<p>© XRock - Just Signal.</p>
|
||||
</footer>
|
||||
</div>
|
||||
|
||||
</body>
|
||||
|
||||
</html>
|
||||
@@ -0,0 +1,207 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>504 // Gateway Timeout</title>
|
||||
<script src="https://kit.fontawesome.com/a076d05399.js" crossorigin="anonymous"></script>
|
||||
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
|
||||
<style>
|
||||
/* hidden in a plain sight? */
|
||||
:root {
|
||||
--bg-color: #050505;
|
||||
--text-color: #e0e0e0;
|
||||
--accent: #ffffff;
|
||||
--dim: #666666;
|
||||
--font-mono: 'Courier New', Courier, monospace;
|
||||
}
|
||||
|
||||
* {
|
||||
box-sizing: border-box;
|
||||
margin: 0;
|
||||
padding: 0;
|
||||
}
|
||||
|
||||
body {
|
||||
background-color: var(--bg-color);
|
||||
color: var(--text-color);
|
||||
font-family: var(--font-mono);
|
||||
line-height: 1.6;
|
||||
font-size: 16px;
|
||||
padding: 2rem;
|
||||
}
|
||||
|
||||
a {
|
||||
color: var(--text-color);
|
||||
text-decoration: none;
|
||||
border-bottom: 1px solid var(--dim);
|
||||
transition: all 0.2s;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
background-color: var(--text-color);
|
||||
color: var(--bg-color);
|
||||
border-color: var(--text-color);
|
||||
}
|
||||
|
||||
.container {
|
||||
max-width: 800px;
|
||||
margin: 0 auto;
|
||||
}
|
||||
|
||||
/* TEXT */
|
||||
h1 {
|
||||
font-size: 2.5rem;
|
||||
text-transform: uppercase;
|
||||
letter-spacing: -2px;
|
||||
margin-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
h2 {
|
||||
font-size: 1.2rem;
|
||||
margin-bottom: 1.5rem;
|
||||
border-bottom: 1px solid var(--dim);
|
||||
display: inline-block;
|
||||
padding-right: 20px;
|
||||
}
|
||||
|
||||
.subtitle {
|
||||
color: var(--dim);
|
||||
margin-bottom: 2rem;
|
||||
}
|
||||
|
||||
hr {
|
||||
border: 0;
|
||||
border-top: 1px dashed var(--dim);
|
||||
margin: 2rem 0;
|
||||
}
|
||||
|
||||
.comment {
|
||||
color: var(--dim);
|
||||
font-size: 0.9rem;
|
||||
margin-left: 10px;
|
||||
}
|
||||
|
||||
/* SECTIONS */
|
||||
section {
|
||||
margin-bottom: 3rem;
|
||||
}
|
||||
|
||||
/* LISTS */
|
||||
ul {
|
||||
list-style: none;
|
||||
}
|
||||
|
||||
.link-list li {
|
||||
margin-bottom: 0.8rem;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 15px;
|
||||
}
|
||||
|
||||
/* STACK GRID */
|
||||
.grid-2 {
|
||||
display: grid;
|
||||
grid-template-columns: 1fr 1fr;
|
||||
gap: 2rem;
|
||||
}
|
||||
|
||||
.skill-item {
|
||||
display: flex;
|
||||
justify-content: space-between;
|
||||
margin-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
.level {
|
||||
font-weight: bold;
|
||||
}
|
||||
|
||||
.special .level {
|
||||
color: var(--text-color);
|
||||
text-shadow: 1px 0 0 red, -1px 0 0 blue;
|
||||
}
|
||||
|
||||
/* my dudes */
|
||||
.team-grid {
|
||||
display: flex;
|
||||
gap: 2rem;
|
||||
flex-wrap: wrap;
|
||||
margin-top: 1rem;
|
||||
}
|
||||
|
||||
.member {
|
||||
text-align: center;
|
||||
width: 100px;
|
||||
}
|
||||
|
||||
.avatar {
|
||||
width: 80px;
|
||||
height: 80px;
|
||||
background-color: #222;
|
||||
border: 2px solid var(--text-color);
|
||||
margin: 0 auto 10px auto;
|
||||
background-size: cover;
|
||||
}
|
||||
|
||||
/* if no avatar added: */
|
||||
.placeholder::before {
|
||||
content: "?";
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
height: 100%;
|
||||
font-size: 2rem;
|
||||
color: var(--dim);
|
||||
}
|
||||
|
||||
/* REPOS */
|
||||
.repo-list li {
|
||||
margin-bottom: 1rem;
|
||||
}
|
||||
|
||||
/* FOOTER */
|
||||
footer {
|
||||
text-align: center;
|
||||
color: var(--dim);
|
||||
font-size: 0.8rem;
|
||||
/* flag{why-are-you-here?} */
|
||||
margin-top: 4rem;
|
||||
}
|
||||
/* SMTH RESPONSIVE */
|
||||
@media (max-width: 600px) {
|
||||
.grid-2 {
|
||||
grid-template-columns: 1fr;
|
||||
gap: 0;
|
||||
}
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
|
||||
<body>
|
||||
|
||||
<div class="container">
|
||||
<header>
|
||||
<h1 class="glitch" data-text="504">504</h1>
|
||||
<p class="subtitle">> Gateway Timeout / System Failure.</p>
|
||||
</header>
|
||||
|
||||
<hr>
|
||||
|
||||
<section id="message">
|
||||
<h2>./error_message</h2>
|
||||
<p>The server did not receive a timely response from the upstream server.</p>
|
||||
<br>
|
||||
<p>Check the <a href="https://status.forust.xyz">System Status</a> for more information.</p>
|
||||
</section>
|
||||
|
||||
<footer>
|
||||
<p>root@error:~$ timeout 30s curl upstream</p>
|
||||
<p>curl: (28) Operation timed out after 30001 milliseconds with 0 bytes received</p>
|
||||
<p>© XRock - Just Signal.</p>
|
||||
</footer>
|
||||
</div>
|
||||
|
||||
</body>
|
||||
|
||||
</html>
|
||||
@@ -1,3 +1,6 @@
|
||||
GITEA_POSTGRES_USER=
|
||||
GITEA_POSTGRES_PASSWORD=
|
||||
GITEA_POSTGRES_DB=gitea
|
||||
GITEA_SMTP_PASS=
|
||||
MAILER_ADDR=
|
||||
SERVICE_EMAIL=email.used.by.services@domain.tld
|
||||
@@ -1,7 +1,8 @@
|
||||
services:
|
||||
server:
|
||||
image: docker.gitea.com/gitea:1.25.1
|
||||
image: docker.gitea.com/gitea:1.26
|
||||
container_name: gitea
|
||||
restart: always
|
||||
environment:
|
||||
- USER_UID=1000
|
||||
- USER_GID=1000
|
||||
@@ -13,45 +14,53 @@ services:
|
||||
- GITEA__database__NAME=gitea
|
||||
#Server
|
||||
- GITEA__server__ROOT_URL=https://gitea.forust.xyz
|
||||
- GITEA__server__SSH_DOMAIN=gitssh.forust.xyz
|
||||
- GITEA__server__SSH_PORT=2221
|
||||
restart: always
|
||||
networks:
|
||||
- gitea-db
|
||||
- traefik-proxy
|
||||
# Mailer
|
||||
- GITEA__mailer__ENABLED=true
|
||||
- GITEA__mailer__FROM=${SERVICE_EMAIL}
|
||||
- GITEA__mailer__SMTP_ADDR=${MAILER_ADDR}:465
|
||||
- GITEA__mailer__USER=${SERVICE_EMAIL}
|
||||
- GITEA__mailer__PASSWD=${GITEA_SMTP_PASS}
|
||||
- GITEA__mailer__PROTOCOL=SMTP
|
||||
- GITEA__service__REGISTER_EMAIL_CONFIRM=true
|
||||
- GITEA__service__ENABLE_NOTIFY_MAIL=true
|
||||
volumes:
|
||||
- ./gitea-data:/data
|
||||
- /etc/timezone:/etc/timezone:ro
|
||||
- /etc/localtime:/etc/localtime:ro
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.http.services.gitea.loadbalancer.server.port=3000"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)"
|
||||
- "traefik.http.routers.gitea.entrypoints=websecure"
|
||||
- "traefik.http.routers.gitea.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.gitea.service=gitea"
|
||||
- "traefik.http.routers.gitea.tls=true"
|
||||
- "traefik.http.services.gitea.loadbalancer.server.port=3000"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.gitea-local.rule=Host(`gitea.workstation.internal`) || Host(`gitea.internal`)"
|
||||
- "traefik.http.routers.gitea-local.rule=Host(`gitea.workstation.internal`)"
|
||||
- "traefik.http.routers.gitea-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.gitea-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.gitea-local.service=gitea"
|
||||
- "traefik.http.routers.gitea-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.gitea-dev.rule=Host(`gitea.gigaforust.internal`)"
|
||||
- "traefik.http.routers.gitea-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.gitea-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.gitea-dev.service=gitea"
|
||||
- "traefik.http.routers.gitea-dev.tls=true"
|
||||
# SSH Router
|
||||
- "traefik.tcp.services.gitea.loadbalancer.server.port=22"
|
||||
- "traefik.tcp.routers.gitea.entrypoints=ssh"
|
||||
- "traefik.tcp.routers.gitea.rule=HostSNI(`*`)"
|
||||
# Gitea container registry Router
|
||||
- "traefik.http.routers.gitea-registry.rule=Host(`gcr.forust.xyz`) && PathPrefix(`/v2`)"
|
||||
- "traefik.http.routers.gitea-registry.entrypoints=websecure"
|
||||
- "traefik.http.routers.gitea-registry.tls.certresolver=letsencrypt"
|
||||
- "traefik.http.routers.gitea-registry.tls=true"
|
||||
ports:
|
||||
- "2221:22"
|
||||
networks:
|
||||
- gitea-db
|
||||
- proxy
|
||||
depends_on:
|
||||
- db
|
||||
|
||||
db:
|
||||
image: docker.io/library/postgres:14
|
||||
restart: always
|
||||
@@ -59,13 +68,12 @@ services:
|
||||
- POSTGRES_USER=gitea
|
||||
- POSTGRES_PASSWORD=gitea
|
||||
- POSTGRES_DB=gitea
|
||||
networks:
|
||||
- gitea-db
|
||||
volumes:
|
||||
- ./gitea-db/:/var/lib/postgresql/data
|
||||
|
||||
networks:
|
||||
- gitea-db
|
||||
networks:
|
||||
gitea-db:
|
||||
external: false
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
@@ -11,30 +11,23 @@ services:
|
||||
env_file: .env
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.services.glance.loadbalancer.server.port=8080"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.glance.rule=Host(`glance.forust.xyz`)"
|
||||
- "traefik.http.routers.glance.entrypoints=websecure"
|
||||
- "traefik.http.routers.glance.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.glance.tls=true"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.glance-local.rule=Host(`glance.workstation.internal`) || Host(`glance.internal`)"
|
||||
- "traefik.http.routers.glance-local.rule=Host(`glance.workstation.internal`)"
|
||||
- "traefik.http.routers.glance-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.glance-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.glance-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.glance-dev.rule=Host(`glance.gigaforust.internal`)"
|
||||
- "traefik.http.routers.glance-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.glance-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.glance-dev.tls=true"
|
||||
networks:
|
||||
- traefik-proxy
|
||||
dns:
|
||||
- 1.1.1.1
|
||||
- 8.8.8.8
|
||||
- proxy
|
||||
networks:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
@@ -0,0 +1,93 @@
|
||||
services:
|
||||
headscale:
|
||||
image: headscale/headscale:latest
|
||||
restart: unless-stopped
|
||||
container_name: headscale-server
|
||||
command: serve
|
||||
networks:
|
||||
- proxy
|
||||
volumes:
|
||||
- ./config/headscale.yaml:/etc/headscale/config.yaml
|
||||
- data:/var/lib/headscale
|
||||
- ./config/policy.json:/var/lib/headscale/policy.json
|
||||
labels:
|
||||
- "me.tale.headplane.target: headscale"
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.headscale.loadbalancer.server.port=8080"
|
||||
- "traefik.http.services.headscale-metrics.loadbalancer.server.port=9090"
|
||||
|
||||
## SERVICE
|
||||
# Prod Router
|
||||
- "traefik.http.routers.headscale.rule=Host(`hs.forust.xyz`)"
|
||||
- "traefik.http.routers.headscale.entrypoints=websecure"
|
||||
- "traefik.http.routers.headscale.service=headscale"
|
||||
- "traefik.http.routers.headscale.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.headscale-local.rule=Host(`hs.workstation.internal`)"
|
||||
- "traefik.http.routers.headscale-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.headscale-local.service=headscale"
|
||||
- "traefik.http.routers.headscale-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.headscale-dev.rule=Host(`hs.gigaforust.internal`)"
|
||||
- "traefik.http.routers.headscale-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.headscale-dev.service=headscale"
|
||||
- "traefik.http.routers.headscale-dev.tls=true"
|
||||
|
||||
## METRICS
|
||||
# Prod Router
|
||||
- "traefik.http.routers.headscale-metrics.rule=Host(`hs.forust.xyz`) && PathPrefix(`/metrics`)"
|
||||
- "traefik.http.routers.headscale-metrics.entrypoints=websecure"
|
||||
- "traefik.http.routers.headscale-metrics.service=headscale-metrics"
|
||||
- "traefik.http.routers.headscale-metrics.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.headscale-metrics-local.rule=Host(`hs.workstation.internal`) && PathPrefix(`/metrics`)"
|
||||
- "traefik.http.routers.headscale-metrics-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.headscale-metrics-local.service=headscale-metrics"
|
||||
- "traefik.http.routers.headscale-metrics-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.headscale-metrics-dev.rule=Host(`hs.gigaforust.internal`) && PathPrefix(`/metrics`)"
|
||||
- "traefik.http.routers.headscale-metrics-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.headscale-metrics-dev.service=headscale-metrics"
|
||||
- "traefik.http.routers.headscale-metrics-dev.tls=true"
|
||||
headplane:
|
||||
image: ghcr.io/tale/headplane:latest
|
||||
container_name: headplane
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- '3000:3000'
|
||||
volumes:
|
||||
- ./config/headplane.yaml:/etc/headplane/config.yaml
|
||||
- ./config/headscale.yaml:/etc/headscale/config.yaml
|
||||
- headplane-data:/var/lib/headplane
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||
networks:
|
||||
- proxy
|
||||
web:
|
||||
image: goodieshq/headscale-admin:latest
|
||||
restart: unless-stopped
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.headscale-ui.loadbalancer.server.port=80"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.headscale-ui.rule=Host(`hs.forust.xyz`) && PathPrefix(`/admin`)"
|
||||
- "traefik.http.routers.headscale-ui.entrypoints=websecure"
|
||||
- "traefik.http.routers.headscale-ui.middlewares=security-chain@file"
|
||||
- "traefik.http.routers.headscale-ui.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.headscale-ui-local.rule=Host(`hs.workstation.internal`) && PathPrefix(`/admin`)"
|
||||
- "traefik.http.routers.headscale-ui-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.headscale-ui-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.headscale-ui-dev.rule=Host(`hs.gigaforust.internal`) && PathPrefix(`/admin`)"
|
||||
- "traefik.http.routers.headscale-ui-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.headscale-ui-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
volumes:
|
||||
data:
|
||||
headplane-data:
|
||||
name: headplane_data
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
@@ -0,0 +1,221 @@
|
||||
# Configuration for the Headplane server and web application
|
||||
server:
|
||||
# These are the default values, change them as needed
|
||||
host: "0.0.0.0"
|
||||
port: 3000
|
||||
# Should not include the dashboard prefix (/admin) portion.
|
||||
# # Prod server_url
|
||||
# base_url: https://hs.forust.xyz
|
||||
# # Local base_url
|
||||
# base_url: https://hs.workstation.internal
|
||||
# # Dev base_url
|
||||
# base_url: https://hs.gigaforust.internal
|
||||
|
||||
# You may provide `cookie_secret_path` instead to read a value from disk.
|
||||
# See https://headplane.net/configuration/#sensitive-values
|
||||
cookie_secret: "<change_me_to_something_secure!>"
|
||||
|
||||
# Whether cookies should be marked as Secure
|
||||
# * Should be false if running without HTTPs
|
||||
# * Should be true if running behind a reverse proxy with HTTPs
|
||||
cookie_secure: true
|
||||
# The maximum age of the session cookie in seconds
|
||||
cookie_max_age: 86400 # 1 day in seconds
|
||||
|
||||
# This is not required, but if you want to restrict the cookie
|
||||
# to a specific domain, set it here. Otherwise leave it commented out.
|
||||
# This may not work as expected if not using a reverse proxy.
|
||||
# cookie_domain: ""
|
||||
|
||||
# The path to persist Headplane specific data. All data going forward
|
||||
# is stored in this directory, including the internal database and
|
||||
# any cache related files.
|
||||
data_path: "/var/lib/headplane"
|
||||
|
||||
# The info secret is optional and allows access to certain debug endpoints
|
||||
# that may expose sensitive information about your Headplane instance.
|
||||
#
|
||||
# As of now, this protects the /api/info endpoint which exposes details about
|
||||
# the Headplane and Headscale versions in use. In the future, more endpoints
|
||||
# may be protected by this secret.
|
||||
#
|
||||
# If not set, these endpoints will be disabled.
|
||||
# info_secret: "<change_me_to_something_secure!>"
|
||||
|
||||
# Headscale specific settings to allow Headplane to talk
|
||||
# to Headscale and access deep integration features
|
||||
headscale:
|
||||
# The URL to your Headscale instance
|
||||
# (All API requests are routed through this URL)
|
||||
# (THIS IS NOT the gRPC endpoint, but the HTTP endpoint)
|
||||
#
|
||||
# IMPORTANT: If you are using TLS this MUST be set to `https://`
|
||||
url: "http://headscale-server:8080"
|
||||
|
||||
# If you use the TLS configuration in Headscale, and you are not using
|
||||
# Let's Encrypt for your certificate, pass in the path to the certificate.
|
||||
# (This has no effect if `url` does not start with `https://`)
|
||||
# tls_cert_path: "/var/lib/headplane/tls.crt"
|
||||
|
||||
# Optional, public URL if its different from the `headscale.url`
|
||||
# This affects certain parts of the web UI which shows Headscale's URL
|
||||
public_url: "https://headscale.example.com"
|
||||
|
||||
# Path to the Headscale configuration file
|
||||
# This is optional, but HIGHLY recommended for the best experience
|
||||
# If this is read only, Headplane will show your configuration settings
|
||||
# in the Web UI, but they cannot be changed.
|
||||
config_path: "/etc/headscale/config.yaml"
|
||||
|
||||
# Whether the Headscale configuration should be strictly validated
|
||||
# when reading from `config_path`. If true, Headplane will not interact
|
||||
# with Headscale if there are any issues with the configuration file.
|
||||
#
|
||||
# This is recommended to be true for production deployments to, however it
|
||||
# may not work if you are using a version of Headscale that has configuration
|
||||
# options unknown to Headplane.
|
||||
config_strict: true
|
||||
|
||||
# If you are using `dns.extra_records_path` in your Headscale
|
||||
# configuration, you need to set this to the path for Headplane
|
||||
# to be able to read the DNS records.
|
||||
#
|
||||
# Pass it in if using Docker and ensure that the file is both
|
||||
# readable and writable to the Headplane process.
|
||||
# When using this, Headplane will no longer need to automatically
|
||||
# restart Headscale for DNS record changes.
|
||||
# dns_records_path: "/var/lib/headscale/extra_records.json"
|
||||
|
||||
# Integration configurations for Headplane to interact with Headscale
|
||||
integration:
|
||||
# The Headplane agent allows retrieving information about nodes
|
||||
# This allows the UI to display version, OS, and connectivity data
|
||||
# You will see the Headplane agent in your Tailnet as a node when
|
||||
# it connects.
|
||||
agent:
|
||||
enabled: false
|
||||
|
||||
# To connect to your Tailnet, you need to generate a pre-auth key
|
||||
# This can be done via the web UI or through the `headscale` CLI.
|
||||
pre_authkey: "<your-preauth-key>"
|
||||
|
||||
# Optionally change the name of the agent in the Tailnet.
|
||||
# host_name: "headplane-agent"
|
||||
|
||||
# Configure different caching settings. By default, the agent will store
|
||||
# caches in the path below for a maximum of 1 minute. If you want data
|
||||
# to update faster, reduce the TTL, but this will increase the frequency
|
||||
# of requests to Headscale.
|
||||
# cache_ttl: 60
|
||||
# cache_path: /var/lib/headplane/agent_cache.json
|
||||
|
||||
# The work_dir represents where the agent will store its data to be able
|
||||
# to automatically reauthenticate with your Tailnet. It needs to be
|
||||
# writable by the user running the Headplane process.
|
||||
#
|
||||
# If using Docker, it is best to leave this as the default.
|
||||
# work_dir: "/var/lib/headplane/agent"
|
||||
|
||||
# Only one of these should be enabled at a time or you will get errors
|
||||
# This does not include the agent integration (above), which can be enabled
|
||||
# at the same time as any of these and is recommended for the best experience.
|
||||
docker:
|
||||
enabled: true
|
||||
|
||||
# By default we check for the presence of a container label (see the docs)
|
||||
# to determine the container to signal when changes are made to DNS settings.
|
||||
container_label: "me.tale.headplane.target=headscale"
|
||||
|
||||
# HOWEVER, you can fallback to a container name if you desire, but this is
|
||||
# not recommended as its brittle and doesn't work with orchestrators that
|
||||
# automatically assign container names.
|
||||
#
|
||||
# If `container_name` is set, it will override any label checks.
|
||||
# container_name: "headscale-server"
|
||||
|
||||
# The path to the Docker socket (do not change this if you are unsure)
|
||||
# Docker socket paths must start with unix:// or tcp:// and at the moment
|
||||
# https connections are not supported.
|
||||
socket: "unix:///var/run/docker.sock"
|
||||
|
||||
# Please refer to docs/integration/Kubernetes.md for more information
|
||||
# on how to configure the Kubernetes integration. There are requirements in
|
||||
# order to allow Headscale to be controlled by Headplane in a cluster.
|
||||
kubernetes:
|
||||
enabled: false
|
||||
# Validates the manifest for the Pod to ensure all of the criteria
|
||||
# are set correctly. Turn this off if you are having issues with
|
||||
# shareProcessNamespace not being validated correctly.
|
||||
validate_manifest: true
|
||||
# This should be the name of the Pod running Headscale and Headplane.
|
||||
# If this isn't static you should be using the Kubernetes Downward API
|
||||
# to set this value (refer to docs/Integrated-Mode.md for more info).
|
||||
pod_name: "headscale"
|
||||
|
||||
# Proc is the "Native" integration that only works when Headscale and
|
||||
# Headplane are running outside of a container. There is no configuration,
|
||||
# but you need to ensure that the Headplane process can terminate the
|
||||
# Headscale process.
|
||||
#
|
||||
# (If they are both running under systemd as sudo, this will work).
|
||||
proc:
|
||||
enabled: false
|
||||
|
||||
# OIDC Configuration for simpler authentication
|
||||
# (This is optional, but recommended for the best experience)
|
||||
# oidc:
|
||||
# The OIDC issuer URL
|
||||
# issuer: "https://accounts.google.com"
|
||||
|
||||
# If you are using OIDC, you need to generate an API key
|
||||
# that can be used to authenticate other sessions when signing in.
|
||||
#
|
||||
# This can be done with `headscale apikeys create --expiration 999d`
|
||||
# headscale_api_key: "<your-headscale-api-key>"
|
||||
|
||||
# If your OIDC provider does not support discovery (does not have the URL at
|
||||
# `/.well-known/openid-configuration`), you need to manually set endpoints.
|
||||
# This also works to override endpoints if you so desire or if your OIDC
|
||||
# discovery is missing certain endpoints (ie GitHub).
|
||||
# For some typical providers, see https://headplane.net/features/sso.
|
||||
# authorization_endpoint: ""
|
||||
# token_endpoint: ""
|
||||
# userinfo_endpoint: ""
|
||||
|
||||
# The authentication method to use when communicating with the token endpoint.
|
||||
# This is fully optional and Headplane will attempt to auto-detect the best
|
||||
# method and fall back to `client_secret_basic` if unsure.
|
||||
# token_endpoint_auth_method: "client_secret_post"
|
||||
|
||||
# The client ID for the OIDC client
|
||||
# For the best experience please ensure this is *identical* to the client_id
|
||||
# you are using for Headscale. because
|
||||
# client_id: "your-client-id"
|
||||
|
||||
# The client secret for the OIDC client
|
||||
# You may also provide `client_secret_path` instead to read a value from disk.
|
||||
# See https://headplane.net/configuration/#sensitive-values
|
||||
# client_secret: "<your-client-secret>"
|
||||
|
||||
# Whether to use PKCE when authenticating users. This is recommended as it
|
||||
# adds an extra layer of security to the authentication process. Enabling this
|
||||
# means your OIDC provider must support PKCE and it must be enabled on the
|
||||
# client.
|
||||
# use_pkce: true
|
||||
|
||||
# If you want to disable traditional login via Headscale API keys
|
||||
# disable_api_key_login: false
|
||||
|
||||
# By default profile pictures are pulled from the OIDC provider when
|
||||
# we go to fetch the userinfo endpoint. Optionally, this can be set to
|
||||
# "oidc" or "gravatar" as of 0.6.1.
|
||||
# profile_picture_source: "gravatar"
|
||||
|
||||
# The scopes to request when authenticating users. The default is below.
|
||||
# scope: "openid email profile"
|
||||
|
||||
# Extra query parameters can be passed to the authorization endpoint
|
||||
# by setting them here. This is useful for providers that require any kind
|
||||
# of custom hinting.
|
||||
# extra_params:
|
||||
# prompt: "select_account" # Example: force account selection on Google
|
||||
@@ -0,0 +1,79 @@
|
||||
# https://wiki.serversatho.me/en/headscale
|
||||
|
||||
# # Prod server_url
|
||||
# server_url: https://hs.example.com
|
||||
# # Local server_url
|
||||
# server_url: https://hs.internal_domain.internal
|
||||
# # Dev server_url
|
||||
# server_url: https://hs.dev_internal_domain.internal
|
||||
listen_addr: 0.0.0.0:8080
|
||||
metrics_listen_addr: 127.0.0.1:9090
|
||||
grpc_listen_addr: 127.0.0.1:50443
|
||||
grpc_allow_insecure: false
|
||||
noise:
|
||||
private_key_path: /var/lib/headscale/noise_private.key
|
||||
prefixes:
|
||||
v4: 100.64.0.0/10
|
||||
v6: fd7a:115c:a1e0::/48
|
||||
allocation: sequential
|
||||
derp:
|
||||
server:
|
||||
enabled: true
|
||||
region_id: 999
|
||||
region_code: "headscale"
|
||||
region_name: "Headscale Embedded DERP"
|
||||
stun_listen_addr: "0.0.0.0:3478"
|
||||
private_key_path: /var/lib/headscale/derp_server_private.key
|
||||
automatically_add_embedded_derp_region: true
|
||||
ipv4: 1.2.3.4
|
||||
ipv6: 2001:db8::1
|
||||
urls:
|
||||
- https://controlplane.tailscale.com/derpmap/default
|
||||
paths: []
|
||||
auto_update_enabled: true
|
||||
update_frequency: 24h
|
||||
disable_check_updates: false
|
||||
ephemeral_node_inactivity_timeout: 30m
|
||||
database:
|
||||
type: sqlite
|
||||
debug: false
|
||||
gorm:
|
||||
prepare_stmt: true
|
||||
parameterized_queries: true
|
||||
skip_err_record_not_found: true
|
||||
slow_threshold: 1000
|
||||
sqlite:
|
||||
path: /var/lib/headscale/db.sqlite
|
||||
write_ahead_log: true
|
||||
wal_autocheckpoint: 1000
|
||||
acme_url: https://acme-v02.api.letsencrypt.org/directory
|
||||
acme_email: ""
|
||||
tls_letsencrypt_hostname: ""
|
||||
tls_letsencrypt_cache_dir: /var/lib/headscale/cache
|
||||
tls_letsencrypt_challenge_type: HTTP-01
|
||||
tls_letsencrypt_listen: ":http"
|
||||
tls_cert_path: ""
|
||||
tls_key_path: ""
|
||||
log:
|
||||
format: text
|
||||
level: info
|
||||
policy:
|
||||
mode: database
|
||||
path: ""
|
||||
dns:
|
||||
magic_dns: true
|
||||
base_domain: example.com
|
||||
nameservers:
|
||||
global:
|
||||
- 1.1.1.1
|
||||
- 1.0.0.1
|
||||
- 2606:4700:4700::1111
|
||||
- 2606:4700:4700::1001
|
||||
split: {}
|
||||
search_domains: []
|
||||
extra_records: []
|
||||
unix_socket: /var/run/headscale/headscale.sock
|
||||
unix_socket_permission: "0770"
|
||||
logtail:
|
||||
enabled: false
|
||||
randomize_client_port: false
|
||||
@@ -0,0 +1,26 @@
|
||||
{
|
||||
"groups": {
|
||||
"group:admin": [
|
||||
"admin@"
|
||||
],
|
||||
"group:users": []
|
||||
},
|
||||
"tagOwners": {},
|
||||
"hosts": {},
|
||||
"acls": [
|
||||
{
|
||||
"#ha-meta": {
|
||||
"name": "users",
|
||||
"open": true
|
||||
},
|
||||
"action": "accept",
|
||||
"src": [
|
||||
"autogroup:member"
|
||||
],
|
||||
"dst": [
|
||||
"autogroup:self:*"
|
||||
]
|
||||
}
|
||||
],
|
||||
"ssh": []
|
||||
}
|
||||
@@ -1,39 +0,0 @@
|
||||
services:
|
||||
forust-homepage:
|
||||
build: .
|
||||
ports:
|
||||
- "8085:80"
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- ./files:/usr/share/nginx/html
|
||||
networks:
|
||||
- traefik-proxy
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.forust-homepage.rule=Host(`forust.xyz`)"
|
||||
- "traefik.http.routers.forust-homepage.entrypoints=websecure"
|
||||
- "traefik.http.routers.forust-homepage.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.forust-homepage.service=forust-homepage"
|
||||
- "traefik.http.routers.forust-homepage.tls=true"
|
||||
- "traefik.http.services.forust-homepage.loadbalancer.server.port=80"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.forust-homepage-local.rule=Host(`landing.workstation.internal`) || Host(`landing.internal`)"
|
||||
- "traefik.http.routers.forust-homepage-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.forust-homepage-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.forust-homepage-local.service=forust-homepage"
|
||||
- "traefik.http.routers.forust-homepage-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.forust-homepage-dev.rule=Host(`landing.gigaforust.internal`)"
|
||||
- "traefik.http.routers.forust-homepage-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.forust-homepage-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.forust-homepage-dev.service=forust-homepage"
|
||||
- "traefik.http.routers.forust-homepage-dev.tls=true"
|
||||
|
||||
networks:
|
||||
traefik-proxy:
|
||||
external: true
|
||||
@@ -0,0 +1,10 @@
|
||||
# everyone use that
|
||||
FROM nginx:alpine
|
||||
|
||||
RUN rm -rf /usr/share/nginx/html/*
|
||||
|
||||
COPY ./forust_files /usr/share/nginx/html
|
||||
|
||||
EXPOSE 80
|
||||
# Start
|
||||
CMD ["nginx", "-g", "daemon off;"]
|
||||
@@ -3,7 +3,7 @@ FROM nginx:alpine
|
||||
|
||||
RUN rm -rf /usr/share/nginx/html/*
|
||||
|
||||
COPY ./files /usr/share/nginx/html
|
||||
COPY ./xdfnx_files /usr/share/nginx/html
|
||||
|
||||
EXPOSE 80
|
||||
# Start
|
||||
@@ -0,0 +1,63 @@
|
||||
services:
|
||||
forust:
|
||||
build:
|
||||
context: .
|
||||
dockerfile: Dockerfile.forust
|
||||
image: gcr.forust.xyz/forust/forust-homepage:latest
|
||||
pull_policy: build
|
||||
# ports:
|
||||
# - "8085:80"
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- ./forust_files:/usr/share/nginx/html
|
||||
networks:
|
||||
- proxy
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.forust-homepage.loadbalancer.server.port=80"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.forust-homepage.rule=Host(`forust.xyz`)"
|
||||
- "traefik.http.routers.forust-homepage.entrypoints=websecure"
|
||||
- "traefik.http.routers.forust-homepage.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.forust-homepage-local.rule=Host(`landing.workstation.internal`)"
|
||||
- "traefik.http.routers.forust-homepage-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.forust-homepage-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.forust-homepage-dev.rule=Host(`landing.gigaforust.internal`)"
|
||||
- "traefik.http.routers.forust-homepage-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.forust-homepage-dev.tls=true"
|
||||
xdfnx:
|
||||
build:
|
||||
context: .
|
||||
dockerfile: Dockerfile.xdfnx
|
||||
image: gcr.forust.xyz/forust/xdfnx-homepage:latest
|
||||
pull_policy: build
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - "8086:80"
|
||||
volumes:
|
||||
- ./xdfnx_files:/usr/share/nginx/html
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.xdfnx-homepage.loadbalancer.server.port=80"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.xdfnx.rule=Host(`xdfnx.cfd`)"
|
||||
- "traefik.http.routers.xdfnx.entrypoints=websecure"
|
||||
- "traefik.http.routers.xdfnx.tls.certresolver=letsencrypt"
|
||||
- "traefik.http.routers.xdfnx.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.xdfnx-local.rule=Host(`xdfnx.workstation.internal`)"
|
||||
- "traefik.http.routers.xdfnx-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.xdfnx-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.xdfnx-dev.rule=Host(`xdfnx.gigaforust.internal`)"
|
||||
- "traefik.http.routers.xdfnx-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.xdfnx-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
|
After Width: | Height: | Size: 46 KiB |
|
After Width: | Height: | Size: 95 KiB |
|
After Width: | Height: | Size: 14 KiB |
|
After Width: | Height: | Size: 59 KiB |
|
After Width: | Height: | Size: 66 KiB |
|
After Width: | Height: | Size: 43 KiB |
|
After Width: | Height: | Size: 61 KiB |
@@ -41,7 +41,14 @@
|
||||
</li>
|
||||
<li>
|
||||
<i class="fas fa-envelope"></i>
|
||||
<a href="mailto:forust@forust.xyz">forust@forust.xyz</a>
|
||||
<a href="mailto:contact@forust.xyz">mail/contact@forust.xyz</a>
|
||||
</li>
|
||||
<li>
|
||||
<i class="fa-solid fa-key"></i>
|
||||
<a href=".well-known/pgp-key.asc">security/PGP Key</a>
|
||||
</li>
|
||||
<li>
|
||||
<p class="comment"># PGP Key Fingerprint: A777 7CB7 D9C4 0A97 443D CCF0 7A3D A455 F820 5B82</p>
|
||||
</li>
|
||||
</ul>
|
||||
</section>
|
||||
@@ -109,7 +116,7 @@
|
||||
<div class="avatar"
|
||||
style="background-image: url('assets/images/team/anna.jpg'); background-size: cover; background-position: center;">
|
||||
</div>
|
||||
<a href="" target="_blank">Anna~</a>
|
||||
<a href="./assets/images/love.png" target="_blank">Anna~</a>
|
||||
</div>
|
||||
|
||||
<div class="member">
|
||||
|
After Width: | Height: | Size: 42 KiB |
@@ -0,0 +1,54 @@
|
||||
# Resolved: Overlay FS failure (and so containers)
|
||||
|
||||
15-12-2025 03:02 AM EET: Degraded control panels' performances, following by full cascade docker failure
|
||||
|
||||
15-12-2025 04:36 AM EET: Identified: Services are terminated due to server software (Overlay FS) + hardware issues (HDD).
|
||||
|
||||
15-12-2025 08:45 PM EET: Restored NextCloud service with few tweaks to lower I/O
|
||||
|
||||
---
|
||||
|
||||
16-12-2025 08:34 PM EET: Ordered new HDD, ETA 22nd of December - 2nd of January
|
||||
|
||||
---
|
||||
|
||||
17-12-2025 02:47 AM EET: To avoid additional I/O into kuma's database, disabled uptime monitoring for non-critical services, such as:
|
||||
|
||||
- Game servers
|
||||
- Gitea (no public projects being hosted yet)
|
||||
- Landings
|
||||
- Cloud services
|
||||
- PenPot
|
||||
- Auth provider
|
||||
- Secondary management tools
|
||||
- Chernuha's non-important infrastructure
|
||||
|
||||
These can be identified by seeing ">2m ago" under monitor's heartbeats.
|
||||
|
||||
---
|
||||
|
||||
09-01-2026 02:32 PM EET: NextCloud's frontend files are corrupted due to the unknown issue. All user data is integrity-verified. To prevent user data corruption, NextCloud service will be restored after new hardware will be available.
|
||||
|
||||
---
|
||||
|
||||
14-01-2026 08:42 PM EET: After planned updating and restarting server, critical firmware software were corrupted because of physical degradation of the disk. Server inaccessible in any way
|
||||
|
||||
---
|
||||
|
||||
15-01-2026 11:30 AM EET: A new NAS-Grade HDD (Seagate IronWolf Pro) was ordered. ETA 16-01-2026 EET Before 12:00 PM
|
||||
|
||||
---
|
||||
|
||||
16-01-2026 12:47 AM EET: New server system is installed, data backed up. Experiencing docker memory leak.
|
||||
|
||||
---
|
||||
|
||||
17-01-2026 01:27 PM EET: All services except NextCloud and Satisfactory server are online.
|
||||
|
||||
17-01-2026 03:48 PM EET: Nextcloud is online. Satisfactory will be provided on-demand. Monitoring status
|
||||
|
||||
---
|
||||
|
||||
##### Status: All services are online
|
||||
|
||||
**Solution: moving all infrastructure onto new NAS-Grade HDD with fresh OS install**
|
||||
@@ -0,0 +1,3 @@
|
||||
KENER_SECRET_KEY=your_secret_key_here
|
||||
ORIGIN=http://localhost:3000
|
||||
TZ=Etc/UTC
|
||||
@@ -0,0 +1,59 @@
|
||||
services:
|
||||
kener:
|
||||
image: rajnandan1/kener:4.0.23
|
||||
container_name: kener
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - 3000:3000/tcp
|
||||
environment:
|
||||
- KENER_SECRET_KEY=${KENER_SECRET_KEY?Kener requires a secret key}
|
||||
- ORIGIN=${ORIGIN:-http://localhost:3000}
|
||||
- REDIS_URL=redis://redis:6379
|
||||
- TZ:${TZ:-Etc/UTC}
|
||||
depends_on:
|
||||
redis:
|
||||
condition: service_healthy
|
||||
volumes:
|
||||
- db:/app/database
|
||||
- uploads:/app/uploads
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.kener.loadbalancer.server.port=3000"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.kener.rule=Host(`status.forust.xyz`)"
|
||||
- "traefik.http.routers.kener.entrypoints=websecure"
|
||||
- "traefik.http.routers.kener.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.kener-local.rule=Host(`status.workstation.internal`)"
|
||||
- "traefik.http.routers.kener-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.kener-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.kener-dev.rule=Host(`status.gigaforust.internal`)"
|
||||
- "traefik.http.routers.kener-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.kener-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
- kener
|
||||
redis:
|
||||
image: redis:7-alpine
|
||||
container_name: kener-redis
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- redis:/data
|
||||
healthcheck:
|
||||
test: [ "CMD", "redis-cli", "ping" ]
|
||||
interval: 6s
|
||||
timeout: 5s
|
||||
retries: 5
|
||||
networks:
|
||||
- kener
|
||||
volumes:
|
||||
db:
|
||||
uploads:
|
||||
redis:
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
kener:
|
||||
external: false
|
||||
@@ -1,7 +1,7 @@
|
||||
services:
|
||||
metube:
|
||||
image: ghcr.io/alexta69/metube
|
||||
# container_name: metube
|
||||
container_name: metube
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - "8081:8081"
|
||||
@@ -13,33 +13,24 @@ services:
|
||||
volumes:
|
||||
- ./MeTube_downloads:/downloads
|
||||
labels:
|
||||
- traefik.enable=true
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.metube.loadbalancer.server.port=8081"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.metube.rule=Host(`metube.forust.xyz`)"
|
||||
- "traefik.http.routers.metube.entrypoints=websecure"
|
||||
- "traefik.http.routers.metube.middlewares=security-headers@file,metube-auth@file"
|
||||
- "traefik.http.routers.metube.service=metube"
|
||||
- "traefik.http.routers.metube.middlewares=security-chain@file"
|
||||
- "traefik.http.routers.metube.tls=true"
|
||||
- "traefik.http.services.metube.loadbalancer.server.port=8081"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.metube-local.rule=Host(`metube.workstation.internal`) || Host(`metube.internal`)"
|
||||
- "traefik.http.routers.metube-local.rule=Host(`metube.workstation.internal`)"
|
||||
- "traefik.http.routers.metube-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.metube-local.middlewares=security-headers@file,metube-auth@file"
|
||||
- "traefik.http.routers.metube-local.service=metube"
|
||||
- "traefik.http.routers.metube-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.metube-dev.rule=Host(`metube.gigaforust.internal`)"
|
||||
- "traefik.http.routers.metube-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.metube-dev.middlewares=security-headers@file,metube-auth@file"
|
||||
- "traefik.http.routers.metube-dev.service=metube"
|
||||
- "traefik.http.routers.metube-dev.tls=true"
|
||||
|
||||
networks:
|
||||
- traefik-proxy
|
||||
- proxy
|
||||
networks:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
@@ -13,8 +13,8 @@ services:
|
||||
- N8N_SECURE_COOKIE=false
|
||||
- N8N_COMMUNITY_PACKAGES_ALLOW_TOOL_USAGE=true
|
||||
volumes:
|
||||
- ./n8n-node-data:/home/node/.n8n
|
||||
- ./n8n-files:/files
|
||||
- node-data:/home/node/.n8n
|
||||
- files:/files
|
||||
extra_hosts:
|
||||
- "enterprise.n8n.io:104.26.13.187"
|
||||
- "enterprise.n8n.io:104.26.12.187"
|
||||
@@ -23,32 +23,23 @@ services:
|
||||
- 1.1.1.1
|
||||
- 8.8.8.8
|
||||
networks:
|
||||
- traefik-proxy
|
||||
- proxy
|
||||
- n8n
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.http.services.n8n.loadbalancer.server.port=5678"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.n8n.rule=Host(`n8n.forust.xyz`)"
|
||||
- "traefik.http.routers.n8n.entrypoints=websecure"
|
||||
- "traefik.http.routers.n8n.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.n8n.service=n8n"
|
||||
- "traefik.http.routers.n8n.tls=true"
|
||||
- "traefik.http.services.n8n.loadbalancer.server.port=5678"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.n8n-local.rule=Host(`n8n.workstation.internal`) || Host(`n8n.internal`)"
|
||||
- "traefik.http.routers.n8n-local.rule=Host(`n8n.workstation.internal`)"
|
||||
- "traefik.http.routers.n8n-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.n8n-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.n8n-local.service=n8n"
|
||||
- "traefik.http.routers.n8n-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.n8n-dev.rule=Host(`n8n.gigaforust.internal`)"
|
||||
- "traefik.http.routers.n8n-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.n8n-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.n8n-dev.service=n8n"
|
||||
- "traefik.http.routers.n8n-dev.tls=true"
|
||||
|
||||
- glance.name=n8n
|
||||
@@ -58,5 +49,9 @@ services:
|
||||
networks:
|
||||
n8n:
|
||||
external: false
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
volumes:
|
||||
node-data:
|
||||
files:
|
||||
@@ -0,0 +1,29 @@
|
||||
## https://github.com/autobrr/netronome?tab=readme-ov-file#environment-variables
|
||||
|
||||
# Server settings
|
||||
NETRONOME__HOST=0.0.0.0 # Listen address
|
||||
NETRONOME__PORT=7575 # Web UI port
|
||||
NETRONOME__BASE_URL=/netronome # Base URL for reverse proxy
|
||||
|
||||
# Database (SQLite by default)
|
||||
NETRONOME__DB_TYPE=postgres # sqlite or postgres
|
||||
NETRONOME__DB_PATH=netronome.db # SQLite database path
|
||||
|
||||
# PostgreSQL (when DB_TYPE=postgres)
|
||||
NETRONOME__DB_TYPE=postgres
|
||||
NETRONOME__DB_HOST=postgres
|
||||
NETRONOME__DB_PORT=5432
|
||||
NETRONOME__DB_USER=netronome
|
||||
NETRONOME__DB_PASSWORD=netronome
|
||||
NETRONOME__DB_NAME=netronome
|
||||
NETRONOME__DB_SSLMODE=disable
|
||||
|
||||
# Authentication
|
||||
NETRONOME__AUTH_WHITELIST=127.0.0.1/32,192.168.1.0/24 # IP whitelist (comma-separated)
|
||||
NETRONOME__SESSION_SECRET= # Session secret (auto-generated if empty)
|
||||
|
||||
# OIDC (optional)
|
||||
NETRONOME__OIDC_ISSUER=https://accounts.google.com
|
||||
NETRONOME__OIDC_CLIENT_ID=your-client-id
|
||||
NETRONOME__OIDC_CLIENT_SECRET=your-secret
|
||||
NETRONOME__OIDC_REDIRECT_URL=https://example.com/api/auth/oidc/callback
|
||||
@@ -0,0 +1,59 @@
|
||||
services:
|
||||
netronome:
|
||||
image: ghcr.io/autobrr/netronome:latest
|
||||
restart: unless-stopped
|
||||
container_name: netronome
|
||||
ports:
|
||||
- "7575:7575"
|
||||
cap_add:
|
||||
- NET_RAW
|
||||
env_file:
|
||||
- .env
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.netronome.loadbalancer.server.port=7575"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.netronome.rule=Host(`nm.forust.xyz`)"
|
||||
- "traefik.http.routers.netronome.entrypoints=websecure"
|
||||
- "traefik.http.routers.netronome.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.netronome-local.rule=Host(`nm.workstation.internal`)"
|
||||
- "traefik.http.routers.netronome-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.netronome-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.netronome-dev.rule=Host(`nm.gigaforust.internal`)"
|
||||
- "traefik.http.routers.netronome-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.netronome-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
- netronome
|
||||
depends_on:
|
||||
postgres:
|
||||
condition: service_healthy
|
||||
postgres:
|
||||
container_name: netronome-postgres
|
||||
image: postgres:17-alpine
|
||||
environment:
|
||||
- POSTGRES_USER=netronome
|
||||
- POSTGRES_PASSWORD=netronome
|
||||
- POSTGRES_DB=netronome
|
||||
volumes:
|
||||
- data:/var/lib/postgresql/data
|
||||
healthcheck:
|
||||
test: [ "CMD-SHELL", "pg_isready -U netronome" ]
|
||||
interval: 5s
|
||||
timeout: 5s
|
||||
retries: 5
|
||||
restart: unless-stopped
|
||||
networks:
|
||||
- netronome
|
||||
volumes:
|
||||
data:
|
||||
|
||||
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
netronome:
|
||||
external: false
|
||||
@@ -1,86 +1,77 @@
|
||||
services:
|
||||
nextcloud-aio-mastercontainer:
|
||||
image: ghcr.io/nextcloud-releases/all-in-one:latest # This is the container image used. You can switch to ghcr.io/nextcloud-releases/all-in-one:beta if you want to help testing new releases. See https://github.com/nextcloud/all-in-one#how-to-switch-the-channel
|
||||
image: ghcr.io/nextcloud-releases/all-in-one:beta
|
||||
init: true # This setting makes sure that signals from main process inside the container are correctly forwarded to children. See https://docs.docker.com/reference/compose-file/services/#init
|
||||
restart: unless-stopped # This makes sure that the container starts always together with the host OS. See https://docs.docker.com/reference/compose-file/services/#restart
|
||||
container_name: nextcloud-aio-mastercontainer # This line is not allowed to be changed as otherwise AIO will not work correctly
|
||||
restart: unless-stopped
|
||||
container_name: nextcloud-aio-mastercontainer # Do not change
|
||||
volumes:
|
||||
- nextcloud_aio_mastercontainer:/mnt/docker-aio-config # This line is not allowed to be changed as otherwise the built-in backup solution will not work
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro # May be changed on macOS, Windows or docker rootless. See the applicable documentation. If adjusting, don't forget to also set 'WATCHTOWER_DOCKER_SOCKET_PATH'!
|
||||
# network_mode: bridge # This adds the container to the same network as docker run would do. Comment this line and uncomment the line below and the networks section at the end of the file if you want to define a custom MTU size for the docker network
|
||||
- nextcloud_aio_mastercontainer:/mnt/docker-aio-config # Do not change (backup)
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||
- /dev/dri:/dev/dri
|
||||
networks:
|
||||
- nextcloud-aio
|
||||
- traefik-proxy # Optional: Connects the mastercontainer to the traefik-proxy network in order to make the built-in reverse proxy detection work.
|
||||
- proxy # Optional: Connects the mastercontainer to the proxy network in order to make the built-in reverse proxy detection work. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||
# ports:
|
||||
# - 8081:80 # Can be removed when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else). See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||
# - 8888:8080 # This is the AIO interface, served via https and self-signed certificate. See https://github.com/nextcloud/all-in-one#explanation-of-used-ports
|
||||
# - 8443:8443 # Can be removed when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else). See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||
# - 8081:80 # may be removed if under reverse-proxy
|
||||
# - 8443:8443
|
||||
# - 8888:8080 # AIO
|
||||
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
|
||||
# Prod Router - DISABLED per user request
|
||||
# - "traefik.http.routers.nextcloud-aio.rule=Host(`nextcloud-aio.forust.xyz`)"
|
||||
# - "traefik.http.routers.nextcloud-aio.entrypoints=websecure"
|
||||
# - "traefik.http.routers.nextcloud-aio.middlewares=security-headers"
|
||||
# - "traefik.http.routers.nextcloud-aio.service=nextcloud-aio"
|
||||
# - "traefik.http.routers.nextcloud-aio.tls=true"
|
||||
# AIO Services configuration
|
||||
- "traefik.http.services.nextcloud-aio.loadbalancer.server.port=8080"
|
||||
- "traefik.http.services.nextcloud-aio.loadbalancer.server.scheme=https"
|
||||
- "traefik.http.services.nextcloud-aio.loadbalancer.serverstransport=insecureTransport@file"
|
||||
|
||||
# - "traefik.http.services.nextcloud-aio.loadbalancer.serverstransport=insecureTransport@file"
|
||||
|
||||
# Prod Router
|
||||
# - "traefik.http.routers.nextcloud-aio.rule=Host(`naio.forust.xyz`)"
|
||||
# - "traefik.http.routers.nextcloud-aio.entrypoints=websecure"
|
||||
# - "traefik.http.routers.nextcloud-aio.middlewares=security-chain@file"
|
||||
# - "traefik.http.routers.nextcloud-aio.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.nextcloud-aio-local.rule=Host(`nextcloud-aio.workstation.internal`) || Host(`nextcloud-aio.internal`)"
|
||||
- "traefik.http.routers.nextcloud-aio-local.rule=Host(`naio.workstation.internal`)"
|
||||
- "traefik.http.routers.nextcloud-aio-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.nextcloud-aio-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.nextcloud-aio-local.service=nextcloud-aio"
|
||||
- "traefik.http.routers.nextcloud-aio-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.nextcloud-aio-dev.rule=Host(`nextcloud-aio.gigaforust.internal`)"
|
||||
- "traefik.http.routers.nextcloud-aio-dev.rule=Host(`naio.gigaforust.internal`)"
|
||||
- "traefik.http.routers.nextcloud-aio-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.nextcloud-aio-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.nextcloud-aio-dev.service=nextcloud-aio"
|
||||
- "traefik.http.routers.nextcloud-aio-dev.tls=true"
|
||||
|
||||
# Glance Metadata
|
||||
- glance.name=Nextcloud
|
||||
# - glance.icon=si:nextcloud
|
||||
- glance.url=https://nextcloud.forust.xyz/
|
||||
- glance.description=Nextcloud is a suite of client-server software for creating and using file hosting services.
|
||||
|
||||
environment:
|
||||
# Is needed when using any of the options below
|
||||
AIO_DISABLE_BACKUP_SECTION: false # Setting this to true allows to hide the backup section in the AIO interface. See https://github.com/nextcloud/all-in-one#how-to-disable-the-backup-section
|
||||
AIO_DISABLE_BACKUP_SECTION: false
|
||||
APACHE_PORT: 11000 # Is needed when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else). See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||
APACHE_IP_BINDING: 0.0.0.0 # Should be set when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else) that is running on the same host. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||
APACHE_ADDITIONAL_NETWORK: traefik-proxy # (Optional) Connect the apache container to an additional docker network. Needed when behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else) running in a different docker network on same server. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||
BORG_RETENTION_POLICY: --keep-within=7d --keep-weekly=4 --keep-monthly=6 # Allows to adjust borgs retention policy. See https://github.com/nextcloud/all-in-one#how-to-adjust-borgs-retention-policy
|
||||
APACHE_IP_BINDING: 0.0.0.0 # Configure when going with reverse-proxy https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||
APACHE_ADDITIONAL_NETWORK: proxy # (Optional) Connect the apache container to an additional docker network. When going with reverse-proxy. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||
BORG_RETENTION_POLICY: --keep-within=7d --keep-weekly=4 --keep-monthly=6 # Backup retention See https://github.com/nextcloud/all-in-one#how-to-adjust-borgs-retention-policy
|
||||
COLLABORA_SECCOMP_DISABLED: false # Setting this to true allows to disable Collabora's Seccomp feature. See https://github.com/nextcloud/all-in-one#how-to-disable-collaboras-seccomp-feature
|
||||
FULLTEXTSEARCH_JAVA_OPTIONS: "-Xms1024M -Xmx1024M" # Allows to adjust the fulltextsearch java options. See https://github.com/nextcloud/all-in-one#how-to-adjust-the-fulltextsearch-java-options
|
||||
NEXTCLOUD_DATADIR: /media/forust/nextcloud/ncdata # Allows to set the host directory for Nextcloud's datadir. ⚠️⚠️⚠️ Warning: do not set or adjust this value after the initial Nextcloud installation is done! See https://github.com/nextcloud/all-in-one#how-to-change-the-default-location-of-nextclouds-datadir
|
||||
NEXTCLOUD_MOUNT: /media/forust/nextcloud # Allows the Nextcloud container to access the chosen directory on the host. See https://github.com/nextcloud/all-in-one#how-to-allow-the-nextcloud-container-to-access-directories-on-the-host
|
||||
NEXTCLOUD_UPLOAD_LIMIT: 16G # Can be adjusted if you need more. See https://github.com/nextcloud/all-in-one#how-to-adjust-the-upload-limit-for-nextcloud
|
||||
NEXTCLOUD_MAX_TIME: 3600 # Can be adjusted if you need more. See https://github.com/nextcloud/all-in-one#how-to-adjust-the-max-execution-time-for-nextcloud
|
||||
FULLTEXTSEARCH_JAVA_OPTIONS: "-Xms1024M -Xmx1024M" # adjust fulltextsearch java options. https://github.com/nextcloud/all-in-one#how-to-adjust-the-fulltextsearch-java-options
|
||||
NEXTCLOUD_DATADIR: /mnt/nextcloud/ncdata # Allows to set the host directory for Nextcloud's datadir. ⚠️⚠️⚠️ Warning: do not set or adjust this value after the initial Nextcloud installation is done! See https://github.com/nextcloud/all-in-one#how-to-change-the-default-location-of-nextclouds-datadir
|
||||
NEXTCLOUD_MOUNT: /mnt/ # Allows the Nextcloud container to access the chosen directory on the host. See https://github.com/nextcloud/all-in-one#how-to-allow-the-nextcloud-container-to-access-directories-on-the-host
|
||||
NEXTCLOUD_UPLOAD_LIMIT: 16G # https://github.com/nextcloud/all-in-one#how-to-adjust-the-upload-limit-for-nextcloud
|
||||
NEXTCLOUD_MAX_TIME: 7200 # Max uploading time See https://github.com/nextcloud/all-in-one#how-to-adjust-the-max-execution-time-for-nextcloud
|
||||
NEXTCLOUD_MEMORY_LIMIT: 512M # Can be adjusted if you need more. See https://github.com/nextcloud/all-in-one#how-to-adjust-the-php-memory-limit-for-nextcloud
|
||||
# NEXTCLOUD_TRUSTED_CACERTS_DIR: /path/to/my/cacerts # CA certificates in this directory will be trusted by the OS of the nextcloud container (Useful e.g. for LDAPS) See https://github.com/nextcloud/all-in-one#how-to-trust-user-defined-certification-authorities-ca
|
||||
# NEXTCLOUD_TRUSTED_CACERTS_DIR: /path/to/my/cacerts # CA certificates will be trusted by the OS of the nextcloud container See https://github.com/nextcloud/all-in-one#how-to-trust-user-defined-certification-authorities-ca
|
||||
NEXTCLOUD_STARTUP_APPS: deck twofactor_totp tasks calendar contacts notes # Allows to modify the Nextcloud apps that are installed on starting AIO the first time. See https://github.com/nextcloud/all-in-one#how-to-change-the-nextcloud-apps-that-are-installed-on-the-first-startup
|
||||
NEXTCLOUD_ADDITIONAL_APKS: imagemagick # This allows to add additional packages to the Nextcloud container permanently. Default is imagemagick but can be overwritten by modifying this value. See https://github.com/nextcloud/all-in-one#how-to-add-os-packages-permanently-to-the-nextcloud-container
|
||||
NEXTCLOUD_ADDITIONAL_PHP_EXTENSIONS: imagick # This allows to add additional php extensions to the Nextcloud container permanently. Default is imagick but can be overwritten by modifying this value. See https://github.com/nextcloud/all-in-one#how-to-add-php-extensions-permanently-to-the-nextcloud-container
|
||||
NEXTCLOUD_ENABLE_DRI_DEVICE: true # This allows to enable the /dev/dri device for containers that profit from it. ⚠️⚠️⚠️ Warning: this only works if the '/dev/dri' device is present on the host! If it should not exist on your host, don't set this to true as otherwise the Nextcloud container will fail to start! See https://github.com/nextcloud/all-in-one#how-to-enable-hardware-acceleration-for-nextcloud
|
||||
NEXTCLOUD_ADDITIONAL_PHP_EXTENSIONS: imagick # dditional php extensions to the Nextcloud container permanently. Default is imagick but can be overwritten by modifying this value. See https://github.com/nextcloud/all-in-one#how-to-add-php-extensions-permanently-to-the-nextcloud-container
|
||||
# NEXTCLOUD_ENABLE_DRI_DEVICE: true # This allows to enable the /dev/dri device for containers that profit from it. ⚠️⚠️⚠️ Warning: this only works if the '/dev/dri' device is present on the host! If it should not exist on your host, don't set this to true as otherwise the Nextcloud container will fail to start! See https://github.com/nextcloud/all-in-one#how-to-enable-hardware-acceleration-for-nextcloud
|
||||
# NEXTCLOUD_KEEP_DISABLED_APPS: false # Setting this to true will keep Nextcloud apps that are disabled in the AIO interface and not uninstall them if they should be installed. See https://github.com/nextcloud/all-in-one#how-to-keep-disabled-apps
|
||||
SKIP_DOMAIN_VALIDATION: false # This should only be set to true if things are correctly configured. See https://github.com/nextcloud/all-in-one?tab=readme-ov-file#how-to-skip-the-domain-validation
|
||||
SKIP_DOMAIN_VALIDATION: true # This should only be set to true if things are correctly configured. See https://github.com/nextcloud/all-in-one?tab=readme-ov-file#how-to-skip-the-domain-validation
|
||||
# TALK_PORT: 3478 # This a-llows to adjust the port that the talk container is using which is exposed on the host. See https://github.com/nextcloud/all-in-one#how-to-adjust-the-talk-port
|
||||
# WATCHTOWER_DOCKER_SOCKET_PATH: /var/run/docker.sock # Needs to be specified if the docker socket on the host is not located in the default '/var/run/docker.sock'. Otherwise mastercontainer updates will fail. For macos it needs to be '/var/run/docker.sock'
|
||||
# WATCHTOWER_DOCKER_SOCKET_PATH: /var/run/docker.sock # Needs to be specified if the docker socket on the host is not located in the default '/var/run/docker.sock'. For macos it needs to be '/var/run/docker.sock'
|
||||
|
||||
networks:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
nextcloud-aio:
|
||||
name: nextcloud-aio
|
||||
driver: bridge
|
||||
external: false
|
||||
volumes:
|
||||
# If you want to store the data on a different drive, see https://github.com/nextcloud/all-in-one#how-to-store-the-filesinstallation-on-a-separate-drive
|
||||
nextcloud_aio_mastercontainer:
|
||||
name: nextcloud_aio_mastercontainer # This line is not allowed to be changed as otherwise the built-in backup solution will not work
|
||||
name: nextcloud_aio_mastercontainer # Do not change
|
||||
|
||||
@@ -50,7 +50,7 @@ x-secret-key: &penpot-secret-key
|
||||
|
||||
networks:
|
||||
penpot:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
volumes:
|
||||
@@ -86,8 +86,8 @@ services:
|
||||
penpot-frontend:
|
||||
image: "penpotapp/frontend:${PENPOT_VERSION:-latest}"
|
||||
restart: always
|
||||
ports:
|
||||
- 9001:8080
|
||||
# ports:
|
||||
# - 9001:8080
|
||||
|
||||
volumes:
|
||||
- penpot_assets:/opt/data/assets
|
||||
@@ -98,37 +98,26 @@ services:
|
||||
|
||||
networks:
|
||||
- penpot
|
||||
- traefik-proxy
|
||||
- proxy
|
||||
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.http.services.penpot.loadbalancer.server.port=8080"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.penpot.rule=Host(`penpot.forust.xyz`)"
|
||||
- "traefik.http.routers.penpot.entrypoints=websecure"
|
||||
- "traefik.http.routers.penpot.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.penpot.service=penpot"
|
||||
- "traefik.http.routers.penpot.tls=true"
|
||||
- "traefik.http.services.penpot.loadbalancer.server.port=8080"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.penpot-local.rule=Host(`penpot.workstation.internal`) || Host(`penpot.internal`)"
|
||||
- "traefik.http.routers.penpot-local.rule=Host(`penpot.workstation.internal`)"
|
||||
- "traefik.http.routers.penpot-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.penpot-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.penpot-local.service=penpot"
|
||||
- "traefik.http.routers.penpot-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.penpot-dev.rule=Host(`penpot.gigaforust.internal`)"
|
||||
- "traefik.http.routers.penpot-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.penpot-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.penpot-dev.service=penpot"
|
||||
- "traefik.http.routers.penpot-dev.tls=true"
|
||||
|
||||
environment:
|
||||
<<: [ *penpot-flags, *penpot-http-body-size ]
|
||||
|
||||
penpot-backend:
|
||||
image: "penpotapp/backend:${PENPOT_VERSION:-latest}"
|
||||
restart: always
|
||||
|
||||
@@ -1,54 +1,39 @@
|
||||
services:
|
||||
portainer:
|
||||
image: portainer/portainer-ce:2.41.0
|
||||
container_name: portainer
|
||||
image: portainer/portainer-ce:latest
|
||||
restart: always
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- ./portainer_data:/data
|
||||
- data:/data
|
||||
ports:
|
||||
- 9443:9443
|
||||
- 9000:9000
|
||||
# - 8000:8000 # Remove if you do not intend to use Edge Agents
|
||||
networks:
|
||||
- traefik-proxy
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.http.services.portainer.loadbalancer.server.port=9000"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.portainer.rule=Host(`portainer.forust.xyz`)"
|
||||
- "traefik.http.routers.portainer.entrypoints=websecure"
|
||||
- "traefik.http.routers.portainer.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.portainer.service=portainer"
|
||||
- "traefik.http.routers.portainer.tls=true"
|
||||
- "traefik.http.services.portainer.loadbalancer.server.port=9443"
|
||||
- "traefik.http.services.portainer.loadbalancer.server.scheme=https"
|
||||
- "traefik.http.services.portainer.loadbalancer.serverstransport=insecureTransport@file"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.portainer-local.rule=Host(`portainer.workstation.internal`) || Host(`portainer.internal`)"
|
||||
- "traefik.http.routers.portainer-local.rule=Host(`portainer.workstation.internal`)"
|
||||
- "traefik.http.routers.portainer-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.portainer-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.portainer-local.service=portainer"
|
||||
- "traefik.http.routers.portainer-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.portainer-dev.rule=Host(`portainer.gigaforust.internal`)"
|
||||
- "traefik.http.routers.portainer-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.portainer-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.portainer-dev.service=portainer"
|
||||
- "traefik.http.routers.portainer-dev.tls=true"
|
||||
|
||||
# Glance Metadata
|
||||
- glance.name=Portainer
|
||||
- glance.url=https://portainer.forust.xyz/
|
||||
- glance.description=Portainer is a lightweight management UI which allows you to easily manage your Docker environments.
|
||||
|
||||
volumes:
|
||||
portainer_data:
|
||||
name: portainer_data
|
||||
|
||||
networks:
|
||||
default:
|
||||
name: portainer_network
|
||||
traefik-proxy:
|
||||
- proxy
|
||||
volumes:
|
||||
data:
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
# Read the documentation before using the `docker-compose.yml` file:
|
||||
# https://docs.searxng.org/admin/installation-docker.html
|
||||
#
|
||||
# Additional ENVs:
|
||||
# https://docs.searxng.org/admin/settings/settings_general.html#settings-general
|
||||
# https://docs.searxng.org/admin/settings/settings_server.html#settings-server
|
||||
|
||||
# Use a specific version tag. E.g. "latest" or "2026.3.25-541c6c3cb".
|
||||
#SEARXNG_VERSION=latest
|
||||
|
||||
# Listen to a specific address.
|
||||
#SEARXNG_HOST=[::]
|
||||
|
||||
# Listen to a specific port.
|
||||
SEARXNG_PORT=8080
|
||||
@@ -0,0 +1,45 @@
|
||||
# Read the documentation before using the `docker-compose.yml` file:
|
||||
# https://docs.searxng.org/admin/installation-docker.html
|
||||
services:
|
||||
core:
|
||||
container_name: searxng-core
|
||||
image: docker.io/searxng/searxng:${SEARXNG_VERSION:-latest}
|
||||
restart: unless-stopped
|
||||
# ports:
|
||||
# - ${SEARXNG_PORT:-8080}
|
||||
env_file: .env
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.services.searxng.loadbalancer.server.port=8080"
|
||||
# Prod Router
|
||||
- "traefik.http.routers.searxng.rule=Host(`s.forust.xyz` || `searxng.forust.xyz`)"
|
||||
- "traefik.http.routers.searxng.entrypoints=websecure"
|
||||
- "traefik.http.routers.searxng.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.searxng-local.rule=Host(`s.workstation.internal` || `searxng.workstation.internal`)"
|
||||
- "traefik.http.routers.searxng-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.searxng-local.tls=true"
|
||||
# Dev Router
|
||||
- "traefik.http.routers.searxng-dev.rule=Host(`searxng.gigaforust.internal`)"
|
||||
- "traefik.http.routers.searxng-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.searxng-dev.tls=true"
|
||||
networks:
|
||||
- proxy
|
||||
volumes:
|
||||
- ./core-config/:/etc/searxng/:Z
|
||||
- core-data:/var/cache/searxng/
|
||||
|
||||
valkey:
|
||||
container_name: searxng-valkey
|
||||
image: docker.io/valkey/valkey:9-alpine
|
||||
command: valkey-server --save 30 1 --loglevel warning
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- valkey-data:/data/
|
||||
|
||||
volumes:
|
||||
core-data:
|
||||
valkey-data:
|
||||
networks:
|
||||
proxy:
|
||||
external: true
|
||||
@@ -3,44 +3,32 @@ services:
|
||||
image: ghcr.io/lukegus/termix:latest
|
||||
container_name: termix
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "3331:8080"
|
||||
# ports:
|
||||
# - "3331:8080"
|
||||
volumes:
|
||||
- ./termix-data:/app/data
|
||||
- data:/app/data
|
||||
environment:
|
||||
PORT: "8080"
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.http.services.termix.loadbalancer.server.port=8080"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.termix.rule=Host(`termix.forust.xyz`)"
|
||||
- "traefik.http.routers.termix.entrypoints=websecure"
|
||||
- "traefik.http.routers.termix.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.termix.service=termix"
|
||||
- "traefik.http.routers.termix.tls=true"
|
||||
- "traefik.http.services.termix.loadbalancer.server.port=8080"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.termix-local.rule=Host(`termix.workstation.internal`) || Host(`termix.internal`)"
|
||||
- "traefik.http.routers.termix-local.rule=Host(`termix.workstation.internal`)"
|
||||
- "traefik.http.routers.termix-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.termix-local.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.termix-local.service=termix"
|
||||
- "traefik.http.routers.termix-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.termix-dev.rule=Host(`termix.gigaforust.internal`)"
|
||||
- "traefik.http.routers.termix-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.termix-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.termix-dev.service=termix"
|
||||
- "traefik.http.routers.termix-dev.tls=true"
|
||||
networks:
|
||||
- traefik-proxy
|
||||
|
||||
- proxy
|
||||
networks:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
volumes:
|
||||
termix-data:
|
||||
driver: local
|
||||
data:
|
||||
@@ -0,0 +1,3 @@
|
||||
# ===================================
|
||||
# Traefik envs
|
||||
EMAIL=bobrovod@national.shitposting.agency
|
||||
@@ -1,6 +1,6 @@
|
||||
services:
|
||||
traefik:
|
||||
image: traefik:latest
|
||||
image: traefik:v3.7
|
||||
container_name: traefik
|
||||
restart: unless-stopped
|
||||
command:
|
||||
@@ -11,81 +11,71 @@ services:
|
||||
# Providers
|
||||
- "--providers.docker=true"
|
||||
- "--providers.docker.exposedbydefault=false"
|
||||
- "--providers.docker.network=traefik-proxy"
|
||||
- "--providers.docker.network=proxy"
|
||||
- "--providers.file.directory=/etc/traefik/dynamic"
|
||||
- "--providers.file.watch=true"
|
||||
|
||||
# EntryPoints
|
||||
- "--entryPoints.web.address=:80"
|
||||
- "--entryPoints.websecure.address=:443"
|
||||
- "--entryPoints.websecure.http.tls=true"
|
||||
- "--entryPoints.web.http.redirections.entryPoint.to=websecure"
|
||||
- "--entryPoints.web.http.redirections.entryPoint.scheme=https"
|
||||
- "--entryPoints.web.http.redirections.entryPoint.to=websecure"
|
||||
- "--entryPoints.websecure.address=:443"
|
||||
- "--entryPoints.websecure.http.middlewares=error-pages@docker"
|
||||
- "--entryPoints.websecure.http.tls=true"
|
||||
- "--entryPoints.ssh.address=:2221"
|
||||
|
||||
# Let's Encrypt STAGING. CURRENTLY USING CF ORIGIN CA INSTEAD
|
||||
# - "--certificatesresolvers.letsencrypt.acme.email=${EMAIL}"
|
||||
# - "--certificatesresolvers.letsencrypt.acme.storage=/letsencrypt/acme.json"
|
||||
# Let's Encrypt
|
||||
- "--certificatesresolvers.letsencrypt.acme.email=${EMAIL}"
|
||||
- "--certificatesresolvers.letsencrypt.acme.storage=/letsencrypt/acme.json"
|
||||
- "--certificatesresolvers.letsencrypt.acme.httpchallenge=true"
|
||||
- "--certificatesresolvers.letsencrypt.acme.httpchallenge.entrypoint=web"
|
||||
# # STAGING
|
||||
# - "--certificatesresolvers.letsencrypt.acme.caserver=https://acme-staging-v02.api.letsencrypt.org/directory"
|
||||
# - "--certificatesresolvers.letsencrypt.acme.httpchallenge=true"
|
||||
# - "--certificatesresolvers.letsencrypt.acme.httpchallenge.entrypoint=web"
|
||||
|
||||
# Cloudflare
|
||||
- "--entryPoints.web.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
||||
- "--entryPoints.websecure.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
||||
|
||||
# Logging
|
||||
- "--log.level=INFO"
|
||||
- "--log.filePath=/var/log/traefik/traefik.log"
|
||||
- "--log.format=json"
|
||||
- "--accesslog=true"
|
||||
- "--accesslog.filepath=/var/log/traefik/access.log"
|
||||
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
|
||||
# Prod Router (Dashboard) - DISABLED per user request
|
||||
# - "traefik.http.routers.traefik-dashboard.rule=Host(`traefik.forust.xyz`)"
|
||||
# - "traefik.http.routers.traefik-dashboard.entrypoints=websecure"
|
||||
# - "traefik.http.routers.traefik-dashboard.middlewares=auth,security-headers"
|
||||
# - "traefik.http.routers.traefik-dashboard.service=api@internal"
|
||||
# - "traefik.http.routers.traefik-dashboard.tls=true"
|
||||
|
||||
# Prod Router (Dash)
|
||||
- "traefik.http.routers.traefik-dashboard.rule=Host(`traefik.forust.xyz`)"
|
||||
- "traefik.http.routers.traefik-dashboard.entrypoints=websecure"
|
||||
- "traefik.http.routers.traefik-dashboard.middlewares=security-chain@file"
|
||||
- "traefik.http.routers.traefik-dashboard.service=api@internal"
|
||||
- "traefik.http.routers.traefik-dashboard.tls=true"
|
||||
# Local Router
|
||||
- "traefik.http.routers.traefik-dashboard-local.rule=Host(`traefik.workstation.internal`) || Host(`traefik.internal`)"
|
||||
- "traefik.http.routers.traefik-dashboard-local.rule=Host(`traefik.workstation.internal`)"
|
||||
- "traefik.http.routers.traefik-dashboard-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.traefik-dashboard-local.middlewares=auth@file,security-headers@file"
|
||||
- "traefik.http.routers.traefik-dashboard-local.service=api@internal"
|
||||
- "traefik.http.routers.traefik-dashboard-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.traefik-dashboard-dev.rule=Host(`traefik.gigaforust.internal`)"
|
||||
- "traefik.http.routers.traefik-dashboard-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.traefik-dashboard-dev.middlewares=security-headers@file"
|
||||
- "traefik.http.routers.traefik-dashboard-dev.service=api@internal"
|
||||
- "traefik.http.routers.traefik-dashboard-dev.tls=true"
|
||||
|
||||
# Glance Metadata
|
||||
- glance.name=Traefik
|
||||
- glance.url=https://traefik.forust.xyz/
|
||||
- glance.description=Traefik is a modern reverse proxy and load balancer
|
||||
|
||||
ports:
|
||||
- "80:80"
|
||||
- "443:443"
|
||||
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||
- ./dynamic:/etc/traefik/dynamic:ro
|
||||
- ./certs:/certs:ro
|
||||
- ./logs:/var/log/traefik
|
||||
# - ./traefik/letsencrypt:/letsencrypt
|
||||
|
||||
- ./letsencrypt:/letsencrypt
|
||||
ports:
|
||||
- "80:80"
|
||||
- "443:443"
|
||||
networks:
|
||||
- traefik-proxy
|
||||
|
||||
environment:
|
||||
- TZ=Europe/Bratislava
|
||||
|
||||
- proxy
|
||||
networks:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
|
||||
@@ -1,328 +0,0 @@
|
||||
http:
|
||||
routers:
|
||||
# Traefik Dashboard (ADMIN, local only)
|
||||
traefik-dashboard:
|
||||
rule: "Host(`traefik.workstation`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: api@internal
|
||||
middlewares:
|
||||
# - auth
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Nextcloud AIO Interface (ADMIN, local is better)
|
||||
nextcloud-aio:
|
||||
rule: "Host(`nextcloud-aio.workstation`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: nextcloud-aio
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Termix (public (account required))
|
||||
termix:
|
||||
rule: "Host(`termix.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: termix
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# MeTube
|
||||
metube:
|
||||
rule: "Host(`metube.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: metube
|
||||
middlewares:
|
||||
- metube-auth
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Portainer (public (account required))
|
||||
portainer:
|
||||
rule: "Host(`portainer.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: portainer
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Uptime Kuma
|
||||
uptime-kuma:
|
||||
rule: "Host(`uptime.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: uptime-kuma
|
||||
tls: {}
|
||||
|
||||
# AdGuard Home (public (account required))
|
||||
adguard:
|
||||
rule: "Host(`adguard.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: adguard
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
|
||||
# Nextcloud Main (public (account required))
|
||||
nextcloud:
|
||||
rule: "Host(`nextcloud.forust.xyz`)"
|
||||
entrypoints:
|
||||
- websecure
|
||||
service: nextcloud
|
||||
middlewares:
|
||||
- nextcloud-chain
|
||||
tls: {}
|
||||
|
||||
# Dockmon (public (account required))
|
||||
dockmon:
|
||||
rule: "Host(`dockmon.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: dockmon
|
||||
middlewares:
|
||||
# - dockmon-auth
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Gitea (public (account required))
|
||||
gitea:
|
||||
rule: "Host(`gitea.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
- ssh
|
||||
service: gitea
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# # Glance (local only)
|
||||
# glance:
|
||||
# rule: "Host(`glance.workstation`)"
|
||||
# entryPoints:
|
||||
# - websecure
|
||||
# service: glance
|
||||
# middlewares:
|
||||
# - security-headers
|
||||
# tls: {}
|
||||
|
||||
# Watercrawl (local only)
|
||||
watercrawl:
|
||||
rule: "Host(`watercrawl.workstation`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: watercrawl
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# N8N (local only)
|
||||
n8n:
|
||||
rule: "Host(`n8n.workstation`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: n8n
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
|
||||
services:
|
||||
# Portainer
|
||||
portainer:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "https://portainer:9443"
|
||||
serversTransport: insecureTransport
|
||||
|
||||
# AdGuard Home
|
||||
adguard:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://adguardhome:3000"
|
||||
|
||||
# Nextcloud AIO Interface
|
||||
nextcloud-aio:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "https://nextcloud-aio-mastercontainer:8080"
|
||||
serversTransport: insecureTransport
|
||||
|
||||
# Nextcloud Main
|
||||
nextcloud:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://nextcloud-aio-apache:11000"
|
||||
|
||||
# Uptime Kuma
|
||||
uptime-kuma:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://uptime-kuma:3001"
|
||||
|
||||
# Termix
|
||||
termix:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://termix:8080"
|
||||
|
||||
# Dockmon
|
||||
dockmon:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "https://dockmon:443"
|
||||
serversTransport: insecureTransport
|
||||
|
||||
# # Glance
|
||||
# glance:
|
||||
# loadBalancer:
|
||||
# servers:
|
||||
# - url: "http://glance:8080"
|
||||
|
||||
# Watercrawl
|
||||
watercrawl:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://nginx:80"
|
||||
|
||||
# N8N
|
||||
n8n:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://n8n:5678"
|
||||
|
||||
# Gitea
|
||||
gitea:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://gitea:3000"
|
||||
# MeTube
|
||||
metube:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://metube:8081"
|
||||
|
||||
serversTransports:
|
||||
insecureTransport:
|
||||
insecureSkipVerify: true
|
||||
|
||||
middlewares:
|
||||
# HTTPS Redirect
|
||||
redirect-https:
|
||||
redirectScheme:
|
||||
scheme: https
|
||||
permanent: true
|
||||
|
||||
# Metube Basic Auth
|
||||
metube-auth:
|
||||
basicAuth:
|
||||
users:
|
||||
- "admin:$2y$05$3Q6gyLFW3NFNp4C6elnyfupntqB6VNB/tcIAeo8NEzvaqPxOjN0iC"
|
||||
# - "jeepik:$2y$05$tIKrmhd7SYOe6yImRRAfpen7hpVdF8PnSbgBTCDZ.GI0Djx.Le2bq"
|
||||
realm: "MeTube Access"
|
||||
|
||||
# Basic Auth Traefik Dashboard
|
||||
auth:
|
||||
basicAuth:
|
||||
users:
|
||||
- "admin:$$apr1$$57E60OUM$$JoYwmLr/uZKaTy6U4IQd9."
|
||||
# - "jeepik:$2y$05$Q8QqJwSjpycVYONyk4id/.rDFApW9oL8tycRMlGttNySsDv71Rnsu"
|
||||
# - "vv:"
|
||||
realm: "Traefik Dashboard"
|
||||
|
||||
# Basic Auth Dockmon
|
||||
dockmon-auth:
|
||||
basicAuth:
|
||||
users:
|
||||
- "admin:$$apr1$$.bCpmIHl$$dxPEKdw5aZLAwo8wUz52b1"
|
||||
realm: "Dockmon Access"
|
||||
|
||||
# Cloudflare IP Whitelist
|
||||
cloudflare-ipwhitelist:
|
||||
ipWhiteList:
|
||||
sourceRange:
|
||||
- "173.245.48.0/20"
|
||||
- "103.21.244.0/22"
|
||||
- "103.22.200.0/22"
|
||||
- "103.31.4.0/22"
|
||||
- "141.101.64.0/18"
|
||||
- "108.162.192.0/18"
|
||||
- "190.93.240.0/20"
|
||||
- "188.114.96.0/20"
|
||||
- "197.234.240.0/22"
|
||||
- "198.41.128.0/17"
|
||||
- "162.158.0.0/15"
|
||||
- "104.16.0.0/13"
|
||||
- "104.24.0.0/14"
|
||||
- "172.64.0.0/13"
|
||||
- "131.0.72.0/22"
|
||||
|
||||
# Security Headers
|
||||
security-headers:
|
||||
headers:
|
||||
browserXssFilter: true
|
||||
contentTypeNosniff: true
|
||||
forceSTSHeader: true
|
||||
stsIncludeSubdomains: true
|
||||
stsPreload: true
|
||||
stsSeconds: 31536000
|
||||
customFrameOptionsValue: "SAMEORIGIN"
|
||||
customResponseHeaders:
|
||||
X-Content-Type-Options: "nosniff"
|
||||
Referrer-Policy: "strict-origin-when-cross-origin"
|
||||
|
||||
# Nextcloud specific headers
|
||||
nextcloud-secure-headers:
|
||||
headers:
|
||||
hostsProxyHeaders:
|
||||
- "X-Forwarded-Host"
|
||||
- "X-Forwarded-Proto"
|
||||
referrerPolicy: "same-origin"
|
||||
customFrameOptionsValue: "SAMEORIGIN"
|
||||
|
||||
# Rate limiting
|
||||
rate-limit:
|
||||
rateLimit:
|
||||
average: 100
|
||||
burst: 50
|
||||
period: 1m
|
||||
|
||||
# Nextcloud chain
|
||||
nextcloud-chain:
|
||||
chain:
|
||||
middlewares:
|
||||
- nextcloud-secure-headers
|
||||
- security-headers
|
||||
|
||||
# TLS Configuration
|
||||
tls:
|
||||
certificates:
|
||||
# Cloudflare Origin CA *.forust.xyz
|
||||
- certFile: /certs/cloudflare.pem
|
||||
keyFile: /certs/cloudflare.key
|
||||
# Local certificate
|
||||
- certFile: /certs/workstation+1.pem
|
||||
keyFile: /certs/workstation+1-key.pem
|
||||
|
||||
stores:
|
||||
default:
|
||||
defaultCertificate:
|
||||
# Fallback local certificate
|
||||
certFile: /certs/workstation+1.pem
|
||||
keyFile: /certs/workstation+1-key.pem
|
||||
|
||||
options:
|
||||
default:
|
||||
minVersion: VersionTLS12
|
||||
sniStrict: true
|
||||
cipherSuites:
|
||||
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
|
||||
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
|
||||
- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305
|
||||
@@ -2,20 +2,3 @@ http:
|
||||
serversTransports:
|
||||
insecureTransport:
|
||||
insecureSkipVerify: true
|
||||
|
||||
routers:
|
||||
# Nextcloud Main (public (account required))
|
||||
nextcloud:
|
||||
rule: "Host(`nextcloud.forust.xyz`)"
|
||||
entrypoints:
|
||||
- websecure
|
||||
service: nextcloud
|
||||
middlewares:
|
||||
- nextcloud-chain
|
||||
tls: {}
|
||||
services:
|
||||
# Nextcloud Main
|
||||
nextcloud:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://nextcloud-aio-apache:11000"
|
||||
@@ -0,0 +1,23 @@
|
||||
http:
|
||||
routers:
|
||||
fs1-public:
|
||||
rule: "Host(`fs1.domain.xyz`)"
|
||||
entrypoints:
|
||||
- websecure
|
||||
service: fs1
|
||||
middlewares:
|
||||
- security-chain@file
|
||||
tls: {}
|
||||
|
||||
fs1-workstation:
|
||||
rule: "Host(`fs1.workstation.internal`)"
|
||||
entrypoints:
|
||||
- websecure
|
||||
service: fs1
|
||||
tls: {}
|
||||
|
||||
services:
|
||||
fs1:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://127.0.0.1:3923" # Copyparty port example
|
||||
@@ -5,29 +5,6 @@ http:
|
||||
redirectScheme:
|
||||
scheme: https
|
||||
permanent: true
|
||||
|
||||
# Metube Basic Auth
|
||||
metube-auth:
|
||||
basicAuth:
|
||||
users:
|
||||
- "vv:$2y$05$JdT8AGUO9bd.E/PiCmKaoOJS1RFlXkrrmZ5mJ4f8/a1bEW39L3FbS"
|
||||
|
||||
realm: "MeTube Access"
|
||||
|
||||
# Basic Auth Traefik Dashboard
|
||||
auth:
|
||||
basicAuth:
|
||||
users:
|
||||
- "admin:$2y$05$.CKDD82sNUxcpaRrLbHuK.dopqt1fgurc2yfTKAT5OFzT7RvPrJHK"
|
||||
realm: "Traefik Dashboard"
|
||||
|
||||
# Basic Auth Dockmon
|
||||
dockmon-auth:
|
||||
basicAuth:
|
||||
users:
|
||||
- "admin:$2y$05$.CKDD82sNUxcpaRrLbHuK.dopqt1fgurc2yfTKAT5OFzT7RvPrJHK"
|
||||
realm: "Dockmon Access"
|
||||
|
||||
# Cloudflare IP Whitelist
|
||||
cloudflare-ipwhitelist:
|
||||
ipWhiteList:
|
||||
@@ -48,6 +25,30 @@ http:
|
||||
- "172.64.0.0/13"
|
||||
- "131.0.72.0/22"
|
||||
|
||||
# Authentik + secure headers
|
||||
security-chain:
|
||||
chain:
|
||||
middlewares:
|
||||
- authentik@file
|
||||
- security-headers@file
|
||||
authentik:
|
||||
forwardAuth:
|
||||
address: "http://authentik-server:9000/outpost.goauthentik.io/auth/traefik"
|
||||
trustForwardHeader: true
|
||||
maxResponseBodySize: 1048576
|
||||
authResponseHeaders:
|
||||
- X-authentik-username
|
||||
- X-authentik-groups
|
||||
- X-authentik-email
|
||||
- X-authentik-name
|
||||
- X-authentik-uid
|
||||
- X-authentik-jwt
|
||||
- X-authentik-meta-jwks
|
||||
- X-authentik-meta-outpost
|
||||
- X-authentik-meta-provider
|
||||
- X-authentik-meta-app
|
||||
- X-authentik-meta-version
|
||||
|
||||
# Security Headers
|
||||
security-headers:
|
||||
headers:
|
||||
@@ -82,5 +83,5 @@ http:
|
||||
nextcloud-chain:
|
||||
chain:
|
||||
middlewares:
|
||||
- nextcloud-secure-headers
|
||||
- security-headers
|
||||
- nextcloud-secure-headers@file
|
||||
- security-headers@file
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
http:
|
||||
routers:
|
||||
# Nextcloud prod
|
||||
nextcloud:
|
||||
rule: "Host(`nextcloud.forust.xyz`)"
|
||||
entrypoints:
|
||||
- websecure
|
||||
service: nextcloud
|
||||
middlewares:
|
||||
- nextcloud-chain
|
||||
tls: {}
|
||||
|
||||
# Nextcloud dev
|
||||
nextcloud-local:
|
||||
rule: "Host(`nextcloud.workstation.internal`)"
|
||||
entrypoints:
|
||||
- websecure
|
||||
service: nextcloud
|
||||
middlewares:
|
||||
- nextcloud-chain
|
||||
tls: {}
|
||||
|
||||
# Nextcloud dev
|
||||
nextcloud-dev:
|
||||
rule: "Host(`nextcloud.gigaforust.internal`)"
|
||||
entrypoints:
|
||||
- websecure
|
||||
service: nextcloud
|
||||
middlewares:
|
||||
- nextcloud-chain
|
||||
tls: {}
|
||||
|
||||
services:
|
||||
# Nextcloud Main
|
||||
nextcloud:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://nextcloud-aio-apache:11000"
|
||||
@@ -0,0 +1,8 @@
|
||||
http:
|
||||
routers:
|
||||
acme-challenge-exempt:
|
||||
rule: "PathPrefix(`/.well-known/acme-challenge`)"
|
||||
entryPoints:
|
||||
- web
|
||||
service: noop@internal
|
||||
priority: 100
|
||||
@@ -1,153 +0,0 @@
|
||||
http:
|
||||
routers:
|
||||
# Traefik Dashboard (dev access. local only)
|
||||
traefik-dashboard-dev:
|
||||
rule: "Host(`traefik.gigaforust`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: api@internal
|
||||
middlewares:
|
||||
# - auth
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Nextcloud AIO Interface (dev access. local only)
|
||||
nextcloud-aio-dev:
|
||||
rule: "Host(`nextcloud-aio.gigaforust`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: nextcloud-aio
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Termix (dev access, (account required))
|
||||
termix-dev:
|
||||
rule: "Host(`termix.gigaforust`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: termix
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# MeTube (dev access, (auth required))
|
||||
metube-dev:
|
||||
rule: "Host(`metube.gigaforust`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: metube
|
||||
middlewares:
|
||||
- metube-auth
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Portainer (dev acess, (account required))
|
||||
portainer-dev:
|
||||
rule: "Host(`portainer.gigaforust`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: portainer
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Uptime Kuma (dev access, (account required))
|
||||
uptime-kuma-dev:
|
||||
rule: "Host(`uptime.gigaforust`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: uptime-kuma
|
||||
tls: {}
|
||||
|
||||
# AdGuard Home (dev access, (account required))
|
||||
adguard-dev:
|
||||
rule: "Host(`adguard.gigaforust`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: adguard
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Nextcloud Main (public (account required))
|
||||
nextcloud-dev:
|
||||
rule: "Host(`nextcloud.gigaforust`)"
|
||||
entrypoints:
|
||||
- websecure
|
||||
service: nextcloud
|
||||
middlewares:
|
||||
- nextcloud-chain
|
||||
tls: {}
|
||||
|
||||
# Dockmon (dev access (account required))
|
||||
dockmon-dev:
|
||||
rule: "Host(`dockmon.gigaforust`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: dockmon
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Gitea (dev access (account required))
|
||||
gitea-dev:
|
||||
rule: "Host(`gitea.gigaforust`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
- ssh
|
||||
service: gitea
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Glance (dev access, local only)
|
||||
glance-dev:
|
||||
rule: "Host(`glance.gigaforust`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: glance
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Watercrawl (dev access, local only)
|
||||
watercrawl-dev:
|
||||
rule: "Host(`watercrawl.gigaforust`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: watercrawl
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# N8N (local only)
|
||||
n8n-dev:
|
||||
rule: "Host(`n8n.gigaforust`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: n8n
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Landing Page (public)
|
||||
forust-homepage-dev:
|
||||
rule: "Host(`landing.gigaforust`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: forust-homepage
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Penpot
|
||||
penpot-dev:
|
||||
rule: "Host(`penpot.gigaforust`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
- web
|
||||
service: penpot
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
@@ -1,152 +0,0 @@
|
||||
http:
|
||||
routers:
|
||||
# Traefik Dashboard (local access, ADMIN, local only)
|
||||
traefik-dashboard-local:
|
||||
rule: "Host(`traefik.workstation`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: api@internal
|
||||
middlewares:
|
||||
# - auth
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Nextcloud AIO Interface (local access. ADMIN, local only)
|
||||
nextcloud-aio-local:
|
||||
rule: "Host(`nextcloud-aio.workstation`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: nextcloud-aio
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Termix (local access, (account required))
|
||||
termix-local:
|
||||
rule: "Host(`termix.workstation`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: termix
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# MeTube (local access, (auth required))
|
||||
metube-local:
|
||||
rule: "Host(`metube.workstation`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: metube
|
||||
middlewares:
|
||||
- metube-auth
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Portainer (dev acess, (account required))
|
||||
portainer-local:
|
||||
rule: "Host(`portainer.workstation`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: portainer
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Uptime Kuma (local access, (account required))
|
||||
uptime-kuma-local:
|
||||
rule: "Host(`uptime.workstation`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: uptime-kuma
|
||||
tls: {}
|
||||
|
||||
# AdGuard Home (local access, (account required))
|
||||
adguard-local:
|
||||
rule: "Host(`adguard.workstation`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: adguard
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Nextcloud Main (public (account required))
|
||||
nextcloud-local:
|
||||
rule: "Host(`nextcloud.workstation`)"
|
||||
entrypoints:
|
||||
- websecure
|
||||
service: nextcloud
|
||||
middlewares:
|
||||
- nextcloud-chain
|
||||
tls: {}
|
||||
|
||||
# Nextcloud Main (public (account required))
|
||||
penpot-local:
|
||||
rule: "Host(`penpot.workstation`)"
|
||||
entrypoints:
|
||||
- websecure
|
||||
service: penpot
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Dockmon (local access (account required))
|
||||
dockmon-local:
|
||||
rule: "Host(`dockmon.workstation`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: dockmon
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Gitea (local access (account required))
|
||||
gitea-local:
|
||||
rule: "Host(`gitea.workstation`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
- ssh
|
||||
service: gitea
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Glance (local access)
|
||||
glance-local:
|
||||
rule: "Host(`glance.workstation`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: glance
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Watercrawl (local access)
|
||||
watercrawl-local:
|
||||
rule: "Host(`watercrawl.workstation`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: watercrawl
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# N8N (local only)
|
||||
n8n-local:
|
||||
rule: "Host(`n8n.workstation`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: n8n
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Landing Page (local access)
|
||||
forust-homepage-local:
|
||||
rule: "Host(`landing.workstation`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: forust-homepage
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
@@ -1,152 +0,0 @@
|
||||
http:
|
||||
routers:
|
||||
# Traefik Dashboard (ADMIN, without subdomeain)
|
||||
traefik-dashboard:
|
||||
rule: "Host(`traefik.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: api@internal
|
||||
middlewares:
|
||||
- auth
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Nextcloud AIO Interface (ADMIN, without subdomeain)
|
||||
nextcloud-aio:
|
||||
rule: "Host(`nextcloud-aio.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: nextcloud-aio
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Nextcloud AIO Interface (ADMIN, without subdomeain)
|
||||
penpot:
|
||||
rule: "Host(`penpot.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: penpot
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Termix (public (account required))
|
||||
termix:
|
||||
rule: "Host(`termix.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: termix
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# MeTube (public (auth required))
|
||||
metube:
|
||||
rule: "Host(`metube.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: metube
|
||||
middlewares:
|
||||
- metube-auth
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Portainer (public (account required))
|
||||
portainer:
|
||||
rule: "Host(`portainer.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: portainer
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Uptime Kuma (public (account required))
|
||||
uptime-kuma:
|
||||
rule: "Host(`uptime.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: uptime-kuma
|
||||
tls: {}
|
||||
|
||||
# AdGuard Home (public (account required))
|
||||
adguard:
|
||||
rule: "Host(`adguard.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: adguard
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Nextcloud Main (public (account required))
|
||||
nextcloud:
|
||||
rule: "Host(`nextcloud.forust.xyz`)"
|
||||
entrypoints:
|
||||
- websecure
|
||||
service: nextcloud
|
||||
middlewares:
|
||||
- nextcloud-chain
|
||||
tls: {}
|
||||
|
||||
# Dockmon (public (account required))
|
||||
dockmon:
|
||||
rule: "Host(`dockmon.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: dockmon
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Gitea (public (account required))
|
||||
gitea:
|
||||
rule: "Host(`gitea.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
- ssh
|
||||
service: gitea
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Glance (public, without subdomain)
|
||||
glance:
|
||||
rule: "Host(`glance.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: glance
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Watercrawl (public, without subdomain)
|
||||
watercrawl:
|
||||
rule: "Host(`watercrawl.fourst.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: watercrawl
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# N8N (public, without subdomain)
|
||||
n8n:
|
||||
rule: "Host(`n8n.forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: n8n
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
|
||||
# Landing Page (public)
|
||||
forust-homepage:
|
||||
rule: "Host(`forust.xyz`)"
|
||||
entryPoints:
|
||||
- websecure
|
||||
service: forust-homepage
|
||||
middlewares:
|
||||
- security-headers
|
||||
tls: {}
|
||||
@@ -1,86 +0,0 @@
|
||||
http:
|
||||
services:
|
||||
# Portainer
|
||||
portainer:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "https://portainer:9443"
|
||||
serversTransport: insecureTransport
|
||||
|
||||
# AdGuard Home
|
||||
adguard:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://adguardhome:3000"
|
||||
|
||||
# Nextcloud AIO Interface
|
||||
nextcloud-aio:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "https://nextcloud-aio-mastercontainer:8080"
|
||||
serversTransport: insecureTransport
|
||||
|
||||
# Penpot
|
||||
penpot:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://penpot-frontend:8080"
|
||||
|
||||
# Nextcloud Main
|
||||
nextcloud:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://nextcloud-aio-apache:11000"
|
||||
|
||||
# Uptime Kuma
|
||||
uptime-kuma:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://uptime-kuma:3001"
|
||||
|
||||
# Termix
|
||||
termix:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://termix:8080"
|
||||
|
||||
# Dockmon
|
||||
dockmon:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "https://dockmon:443"
|
||||
serversTransport: insecureTransport
|
||||
|
||||
# Glance
|
||||
glance:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://glance:8080"
|
||||
|
||||
# Watercrawl
|
||||
watercrawl:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://nginx:80"
|
||||
|
||||
# N8N
|
||||
n8n:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://n8n:5678"
|
||||
|
||||
# Gitea
|
||||
gitea:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://gitea:3000"
|
||||
# MeTube
|
||||
metube:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://metube:8081"
|
||||
# Landing Page
|
||||
forust-homepage:
|
||||
loadBalancer:
|
||||
servers:
|
||||
- url: "http://forust-homepage:80"
|
||||
@@ -2,15 +2,14 @@
|
||||
tls:
|
||||
certificates:
|
||||
# Cloudflare Origin CA *.forust.xyz
|
||||
- certFile: /certs/cloudflare.pem
|
||||
keyFile: /certs/cloudflare.key
|
||||
|
||||
stores:
|
||||
default:
|
||||
defaultCertificate:
|
||||
# Fallback local certificate
|
||||
certFile: /certs/gigaforust.internal+1.pem
|
||||
keyFile: /certs/gigaforust.internal+1-key.pem
|
||||
# - certFile: /certs/cloudflare.pem
|
||||
# keyFile: /certs/cloudflare.key
|
||||
# stores:
|
||||
# default:
|
||||
# defaultCertificate:
|
||||
# # Fallback local certificate
|
||||
# certFile: /certs/local.pem
|
||||
# keyFile: /certs/local-key.pem
|
||||
|
||||
options:
|
||||
default:
|
||||
|
||||
@@ -1,34 +1,32 @@
|
||||
services:
|
||||
uptime-kuma:
|
||||
image: louislam/uptime-kuma:2
|
||||
restart: unless-stopped
|
||||
container_name: uptime-kuma
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- ./data:/app/data
|
||||
ports:
|
||||
# <Host Port>:<Container Port>
|
||||
- "3001:3001"
|
||||
- data:/app/data
|
||||
# ports:
|
||||
# - "3001:3001"
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik-proxy"
|
||||
- "traefik.http.services.uptime-kuma.loadbalancer.server.port=3001"
|
||||
|
||||
# Prod Router
|
||||
- "traefik.http.routers.uptime-kuma.rule=Host(`uptime.forust.xyz`)"
|
||||
- "traefik.http.routers.uptime-kuma.entrypoints=websecure"
|
||||
- "traefik.http.routers.uptime-kuma.tls=true"
|
||||
- "traefik.http.services.uptime-kuma.loadbalancer.server.port=3001"
|
||||
|
||||
# Local Router
|
||||
- "traefik.http.routers.uptime-kuma-local.rule=Host(`uptime.workstation.internal`) || Host(`uptime.internal`)"
|
||||
- "traefik.http.routers.uptime-kuma-local.rule=Host(`uptime.workstation.internal`)"
|
||||
- "traefik.http.routers.uptime-kuma-local.entrypoints=websecure"
|
||||
- "traefik.http.routers.uptime-kuma-local.tls=true"
|
||||
|
||||
# Dev Router
|
||||
- "traefik.http.routers.uptime-kuma-dev.rule=Host(`uptime.gigaforust.internal`)"
|
||||
- "traefik.http.routers.uptime-kuma-dev.entrypoints=websecure"
|
||||
- "traefik.http.routers.uptime-kuma-dev.tls=true"
|
||||
networks:
|
||||
- traefik-proxy
|
||||
- proxy
|
||||
volumes:
|
||||
data:
|
||||
networks:
|
||||
traefik-proxy:
|
||||
proxy:
|
||||
external: true
|
||||
@@ -1 +1,12 @@
|
||||
.unused
|
||||
Downloads
|
||||
.venv
|
||||
volumes
|
||||
.env
|
||||
.env.*
|
||||
my_account.session
|
||||
.gitignore
|
||||
README.md
|
||||
.git
|
||||
uv.lock
|
||||
.deepsource.toml
|
||||
@@ -0,0 +1,3 @@
|
||||
API_ID=""
|
||||
API_HASH=""
|
||||
STRINGSESSION=""
|
||||
@@ -0,0 +1,14 @@
|
||||
# apiflash api key only for webshot plugin
|
||||
APIFLASH_KEY=""
|
||||
# gemini api key only for gemini plugin
|
||||
GEMINI_KEY=""
|
||||
# VT api key only for VirusTotal plugin
|
||||
VT_KEY=""
|
||||
# rmbg api key only for removebg plugin
|
||||
RMBG_KEY=""
|
||||
# cohere api key only for cohere plugin
|
||||
COHERE_KEY=""
|
||||
# sqlite/sqlite3 or mongo/mongodb
|
||||
DATABASE_TYPE=""
|
||||
# file name for sqlite3, database name for mongodb
|
||||
DATABASE_NAME=""
|
||||
@@ -14,3 +14,6 @@ __pycache__/
|
||||
/downloads/
|
||||
/Downloads/
|
||||
config.ini
|
||||
|
||||
k8s/*/*secret*.yaml
|
||||
!k8s/account-secrets.yaml.example
|
||||
@@ -1,10 +1,18 @@
|
||||
FROM python:3.11
|
||||
FROM python:3.11-slim
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends \
|
||||
git wget ffmpeg mediainfo && \
|
||||
rm -rf /var/lib/apt/lists/*
|
||||
|
||||
COPY requirements.txt /app/
|
||||
|
||||
RUN python -m pip install --no-cache-dir --upgrade pip && \
|
||||
python -m pip install --no-cache-dir -r /app/requirements.txt
|
||||
|
||||
COPY . /app
|
||||
RUN apt-get -qq update && apt-get -qq install -y git wget ffmpeg mediainfo\
|
||||
&& apt-get clean \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
RUN python -m venv --copies /opt/venv
|
||||
ENV PATH="/opt/venv/bin:$PATH"
|
||||
RUN pip install --no-cache-dir -r requirements.txt
|
||||
CMD ["python", "main.py"]
|
||||
|
||||
ENV PYTHONUNBUFFERED=1
|
||||
|
||||
CMD ["python", "-u", "main.py"]
|
||||
@@ -0,0 +1,35 @@
|
||||
services:
|
||||
forust:
|
||||
build:
|
||||
context: .
|
||||
dockerfile: Dockerfile
|
||||
image: gcr.forust.xyz/forust/userbot:latest
|
||||
pull_policy: build
|
||||
restart: unless-stopped
|
||||
env_file:
|
||||
- .env
|
||||
- .env.forust
|
||||
volumes:
|
||||
- ./volumes/data_forust:/app/data
|
||||
- ./Downloads:/app/downloads
|
||||
- ./volumes/logs_forust:/app/logs
|
||||
dns:
|
||||
- 8.8.8.8
|
||||
- 1.1.1.1
|
||||
|
||||
anna:
|
||||
image: gcr.forust.xyz/forust/userbot:latest
|
||||
pull_policy: build
|
||||
depends_on:
|
||||
- forust
|
||||
restart: unless-stopped
|
||||
env_file:
|
||||
- .env
|
||||
- .env.anna
|
||||
volumes:
|
||||
- ./volumes/data_anna:/app/data
|
||||
- ./Downloads:/app/downloads
|
||||
- ./volumes/logs_anna:/app/logs
|
||||
dns:
|
||||
- 8.8.8.8
|
||||
- 1.1.1.1
|
||||
@@ -1,57 +0,0 @@
|
||||
services:
|
||||
userbot_forust:
|
||||
build:
|
||||
context: .
|
||||
dockerfile: Dockerfile
|
||||
container_name: userbot_forust
|
||||
restart: unless-stopped
|
||||
env_file:
|
||||
- .env
|
||||
- .env.forust
|
||||
volumes:
|
||||
- ./volumes/data_forust:/app/data
|
||||
- ./Downloads:/app/downloads
|
||||
- ./volumes/logs_forust-:/app/logs
|
||||
dns:
|
||||
- 8.8.8.8
|
||||
- 1.1.1.1
|
||||
|
||||
userbot_anna:
|
||||
build:
|
||||
context: .
|
||||
dockerfile: Dockerfile
|
||||
container_name: userbot_anna
|
||||
restart: unless-stopped
|
||||
env_file:
|
||||
- .env
|
||||
- .env.anna
|
||||
volumes:
|
||||
- ./volumes/data_anna:/app/data
|
||||
- ./Downloads:/app/downloads
|
||||
- ./volumes/logs_anna:/app/logs
|
||||
dns:
|
||||
- 8.8.8.8
|
||||
- 1.1.1.1
|
||||
develop:
|
||||
watch:
|
||||
- action: sync
|
||||
path: modules
|
||||
target: /app/modules
|
||||
- action: sync
|
||||
path: utils
|
||||
target: /app/utils
|
||||
- action: sync
|
||||
path: main.py
|
||||
target: /app/main.py
|
||||
- action: rebuild
|
||||
path: .env
|
||||
- action: rebuild
|
||||
path: .env.anna
|
||||
|
||||
|
||||
volumes:
|
||||
downloads:
|
||||
|
||||
networks:
|
||||
userbot_network:
|
||||
driver: bridge
|
||||
@@ -0,0 +1,7 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: userbot-common-config
|
||||
data:
|
||||
DATABASE_TYPE: ""
|
||||
DATABASE_NAME: ""
|
||||
@@ -0,0 +1,9 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
resources:
|
||||
- userbots.yaml
|
||||
- common-secret.yaml
|
||||
- common-config.yaml
|
||||
- forust-secrets.yaml
|
||||
- anna-secrets.yaml
|
||||
@@ -0,0 +1,114 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: forust-userbot-deployment
|
||||
labels:
|
||||
app: forust-userbot
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: forust-userbot
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: forust-userbot
|
||||
spec:
|
||||
containers:
|
||||
- name: forust-userbot
|
||||
image: gcr.forust.xyz/forust/userbot:latest
|
||||
imagePullPolicy: Always
|
||||
resources:
|
||||
limits:
|
||||
memory: "512Mi"
|
||||
cpu: "500m"
|
||||
requests:
|
||||
memory: "256Mi"
|
||||
cpu: "100m"
|
||||
envFrom:
|
||||
- secretRef:
|
||||
name: userbot-common-secrets
|
||||
- configMapRef:
|
||||
name: userbot-common-config
|
||||
- secretRef:
|
||||
name: userbot-forust-secrets
|
||||
volumeMounts:
|
||||
- name: forust-storage
|
||||
mountPath: /app/data
|
||||
subPath: data
|
||||
- name: forust-storage
|
||||
mountPath: /app/logs
|
||||
subPath: logs
|
||||
volumes:
|
||||
- name: forust-storage
|
||||
persistentVolumeClaim:
|
||||
claimName: forust-pvc
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: forust-pvc
|
||||
spec:
|
||||
resources:
|
||||
requests:
|
||||
storage: 1Gi
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: anna-userbot-deployment
|
||||
labels:
|
||||
app: anna-userbot
|
||||
spec:
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: anna-userbot
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: anna-userbot
|
||||
spec:
|
||||
containers:
|
||||
- name: anna-userbot
|
||||
image: gcr.forust.xyz/forust/userbot:latest
|
||||
imagePullPolicy: Always
|
||||
resources:
|
||||
limits:
|
||||
memory: "512Mi"
|
||||
cpu: "500m"
|
||||
requests:
|
||||
memory: "256Mi"
|
||||
cpu: "100m"
|
||||
envFrom:
|
||||
- secretRef:
|
||||
name: userbot-common-secrets
|
||||
- configMapRef:
|
||||
name: userbot-common-config
|
||||
- secretRef:
|
||||
name: userbot-anna-secrets
|
||||
volumeMounts:
|
||||
- name: anna-storage
|
||||
mountPath: /app/data
|
||||
subPath: data
|
||||
- name: anna-storage
|
||||
mountPath: /app/logs
|
||||
subPath: logs
|
||||
volumes:
|
||||
- name: anna-storage
|
||||
persistentVolumeClaim:
|
||||
claimName: anna-pvc
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: anna-pvc
|
||||
spec:
|
||||
resources:
|
||||
requests:
|
||||
storage: 1Gi
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
@@ -0,0 +1,8 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
resources:
|
||||
- ../../base
|
||||
|
||||
patches:
|
||||
- path: patch-downloads.yaml
|
||||
@@ -0,0 +1,35 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: forust-userbot-deployment
|
||||
spec:
|
||||
template:
|
||||
spec:
|
||||
containers:
|
||||
- name: forust-userbot
|
||||
volumeMounts:
|
||||
- name: downloads
|
||||
mountPath: /app/downloads
|
||||
volumes:
|
||||
- name: downloads
|
||||
hostPath:
|
||||
path: /home/user/projects/homelab/userbot/Downloads
|
||||
type: DirectoryOrCreate
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: anna-userbot-deployment
|
||||
spec:
|
||||
template:
|
||||
spec:
|
||||
containers:
|
||||
- name: anna-userbot
|
||||
volumeMounts:
|
||||
- name: downloads
|
||||
mountPath: /app/downloads
|
||||
volumes:
|
||||
- name: downloads
|
||||
hostPath:
|
||||
path: /home/user/projects/homelab/userbot/Downloads
|
||||
type: DirectoryOrCreate
|
||||
@@ -0,0 +1,8 @@
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
resources:
|
||||
- ../../base
|
||||
|
||||
patches:
|
||||
- path: patch-downloads.yaml
|
||||
@@ -0,0 +1,35 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: forust-userbot-deployment
|
||||
spec:
|
||||
template:
|
||||
spec:
|
||||
containers:
|
||||
- name: forust-userbot
|
||||
volumeMounts:
|
||||
- name: downloads
|
||||
mountPath: /app/downloads
|
||||
volumes:
|
||||
- name: downloads
|
||||
hostPath:
|
||||
path: /srv/homelab/userbot/Downloads
|
||||
type: DirectoryOrCreate
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: anna-userbot-deployment
|
||||
spec:
|
||||
template:
|
||||
spec:
|
||||
containers:
|
||||
- name: anna-userbot
|
||||
volumeMounts:
|
||||
- name: downloads
|
||||
mountPath: /app/downloads
|
||||
volumes:
|
||||
- name: downloads
|
||||
hostPath:
|
||||
path: /srv/homelab/userbot/Downloads
|
||||
type: DirectoryOrCreate
|
||||
@@ -90,11 +90,19 @@ def load_missing_modules():
|
||||
os.makedirs(custom_modules_path, exist_ok=True)
|
||||
|
||||
try:
|
||||
f = requests.get(
|
||||
"https://raw.githubusercontent.com/The-MoonTg-project/custom_modules/main/full.txt"
|
||||
).text
|
||||
except Exception:
|
||||
logging.error("Failed to fetch custom modules list")
|
||||
resp = requests.get(
|
||||
"https://raw.githubusercontent.com/The-MoonTg-project/custom_modules/main/full.txt",
|
||||
timeout=10,
|
||||
)
|
||||
if not resp.ok:
|
||||
logging.error(
|
||||
"Failed to fetch custom modules list: HTTP %s",
|
||||
resp.status_code,
|
||||
)
|
||||
return
|
||||
f = resp.text
|
||||
except Exception as e:
|
||||
logging.error("Failed to fetch custom modules list: %s", e)
|
||||
return
|
||||
modules_dict = {
|
||||
line.split("/")[-1].split()[0]: line.strip() for line in f.splitlines()
|
||||
|
||||
@@ -59,26 +59,26 @@ async def version(client: Client, message: Message):
|
||||
|
||||
await message.delete()
|
||||
|
||||
if gitrepo is not None:
|
||||
remote_url = list(gitrepo.remote().urls)[0]
|
||||
commit_time = (
|
||||
datetime.datetime.fromtimestamp(gitrepo.head.commit.committed_date)
|
||||
.astimezone(datetime.timezone.utc)
|
||||
.strftime("%Y-%m-%d %H:%M:%S %Z")
|
||||
)
|
||||
git_info = (
|
||||
f"\n<b>Branch: <a href={remote_url}/tree/{gitrepo.active_branch}>{gitrepo.active_branch}</a>\n"
|
||||
if gitrepo.active_branch != "master" else "\n"
|
||||
) + f"Commit: <a href={remote_url}/commit/{gitrepo.head.commit.hexsha}>" f"{gitrepo.head.commit.hexsha[:7]}</a> by {gitrepo.head.commit.author.name}\n" f"Commit time: {commit_time}</b>"
|
||||
else:
|
||||
git_info = ""
|
||||
|
||||
await message.reply(
|
||||
f"<b>Moon Userbot version: {userbot_version}\n"
|
||||
f"Changelog </b><i><a href=https://t.me/moonuserbot/{changelog}>in channel</a></i>.<b>\n"
|
||||
f"Changelog written by </b><i>"
|
||||
f"<a href=https://t.me/Qbtaumai>Abhi</a></i>\n\n"
|
||||
+ (
|
||||
f"<b>Branch: <a href={remote_url}/tree/{gitrepo.active_branch}>{gitrepo.active_branch}</a>\n"
|
||||
if gitrepo.active_branch != "master"
|
||||
else ""
|
||||
)
|
||||
+ f"Commit: <a href={remote_url}/commit/{gitrepo.head.commit.hexsha}>"
|
||||
f"{gitrepo.head.commit.hexsha[:7]}</a> by {gitrepo.head.commit.author.name}\n"
|
||||
f"Commit time: {commit_time}</b>",
|
||||
f"{git_info}",
|
||||
)
|
||||
|
||||
|
||||
|
||||
@@ -3,7 +3,7 @@ name = "userbot"
|
||||
version = "0.1.0"
|
||||
description = "Add your description here"
|
||||
readme = "README.md"
|
||||
requires-python = ">=3.13"
|
||||
requires-python = ">=3.11"
|
||||
dependencies = [
|
||||
"aiofiles>=25.1.0",
|
||||
"aiohttp>=3.13.2",
|
||||
|
||||
@@ -18,3 +18,5 @@ aiohttp
|
||||
aiofiles
|
||||
pySmartDL
|
||||
qrcode
|
||||
bottle
|
||||
dulwich
|
||||
@@ -1,8 +1,8 @@
|
||||
import os
|
||||
import environs
|
||||
|
||||
try:
|
||||
env = environs.Env()
|
||||
try:
|
||||
env.read_env("./.env")
|
||||
except FileNotFoundError:
|
||||
print("No .env file found, using os.environ.")
|
||||
|
||||
@@ -1,19 +1,3 @@
|
||||
# Moon-Userbot - telegram userbot
|
||||
# Copyright (C) 2020-present Moon Userbot Organization
|
||||
#
|
||||
# This program is free software: you can redistribute it and/or modify
|
||||
# it under the terms of the GNU General Public License as published by
|
||||
# the Free Software Foundation, either version 3 of the License, or
|
||||
# (at your option) any later version.
|
||||
|
||||
# This program is distributed in the hope that it will be useful,
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
# GNU General Public License for more details.
|
||||
|
||||
# You should have received a copy of the GNU General Public License
|
||||
# along with this program. If not, see <https://www.gnu.org/licenses/>.
|
||||
|
||||
from sys import version_info
|
||||
from .db import db
|
||||
import git
|
||||
@@ -37,19 +21,11 @@ prefix = db.get("core.main", "prefix", ".")
|
||||
|
||||
try:
|
||||
gitrepo = git.Repo(".")
|
||||
except git.exc.InvalidGitRepositoryError:
|
||||
repo = git.Repo.init()
|
||||
origin = repo.create_remote(
|
||||
"origin", "https://github.com/The-MoonTg-project/Moon-Userbot"
|
||||
)
|
||||
origin.fetch()
|
||||
repo.create_head("main", origin.refs.main)
|
||||
repo.heads.main.set_tracking_branch(origin.refs.main)
|
||||
repo.heads.main.checkout(True)
|
||||
gitrepo = git.Repo(".")
|
||||
except (git.exc.InvalidGitRepositoryError, git.exc.NoSuchPathError):
|
||||
gitrepo = None
|
||||
|
||||
if len(gitrepo.tags) > 0:
|
||||
if gitrepo is not None and len(gitrepo.tags) > 0:
|
||||
commits_since_tag = list(gitrepo.iter_commits(f"{gitrepo.tags[-1].name}..HEAD"))
|
||||
else:
|
||||
commits_since_tag = []
|
||||
userbot_version = f"2.5.{len(commits_since_tag)}"
|
||||
else:
|
||||
userbot_version = "2.5.0"
|
||||
|
||||
@@ -22,6 +22,7 @@ import re
|
||||
import shlex
|
||||
import subprocess
|
||||
import sys
|
||||
import tempfile
|
||||
import time
|
||||
import traceback
|
||||
from PIL import Image
|
||||
@@ -85,13 +86,17 @@ async def edit_or_send_as_file(
|
||||
return
|
||||
if len(tex) > 1024:
|
||||
await message.edit("<code>OutPut is Too Large, Sending As File!</code>")
|
||||
file_names = f"{file_name}.txt"
|
||||
with open(file_names, "w") as fn:
|
||||
with tempfile.NamedTemporaryFile(
|
||||
"w", delete=False, suffix=".txt", prefix=f"{file_name}_"
|
||||
) as fn:
|
||||
fn.write(tex)
|
||||
await client.send_document(message.chat.id, file_names, caption=caption)
|
||||
temp_path = fn.name
|
||||
try:
|
||||
await client.send_document(message.chat.id, temp_path, caption=caption)
|
||||
await message.delete()
|
||||
if os.path.exists(file_names):
|
||||
os.remove(file_names)
|
||||
finally:
|
||||
if os.path.exists(temp_path):
|
||||
os.remove(temp_path)
|
||||
return
|
||||
return await message.edit(tex)
|
||||
|
||||
@@ -249,12 +254,7 @@ def is_admin(func):
|
||||
chat_member = await client.get_chat_member(
|
||||
message.chat.id, message.from_user.id
|
||||
)
|
||||
chat_admins = []
|
||||
async for member in client.get_chat_members(
|
||||
message.chat.id, filter=ChatMembersFilter.ADMINISTRATORS
|
||||
):
|
||||
chat_admins.append(member)
|
||||
if chat_member in chat_admins:
|
||||
if chat_member.status in ("administrator", "creator"):
|
||||
return await func(client, message)
|
||||
await message.edit("You need to be an admin to perform this action.")
|
||||
except UserNotParticipant:
|
||||
|
||||