diff --git a/certbot/certbot.service b/certbot/certbot.service deleted file mode 100644 index 6b7ddec..0000000 --- a/certbot/certbot.service +++ /dev/null @@ -1,6 +0,0 @@ -[Unit] -Description=Let's Encrypt renewal - -[Service] -Type=oneshot -ExecStart=/usr/bin/certbot renew --quiet --agree-tos --deploy-hook "cp /etc/letsencrypt/live/scarif.space-0001/fullchain.pem /opt/ssl/scarif.space.crt && cp /etc/letsencrypt/live/scarif.space-0001/privkey.pem /opt/ssl/scarif.space.key && docker-compose -f /opt/scarif/docker-compose.yml exec nginx nginx -s reload" diff --git a/certbot/certbot.timer b/certbot/certbot.timer deleted file mode 100644 index 94c8b8b..0000000 --- a/certbot/certbot.timer +++ /dev/null @@ -1,10 +0,0 @@ -[Unit] -Description=Twice daily renewal of Let's Encrypt's certificates - -[Timer] -OnCalendar=0/12:00:00 -RandomizedDelaySec=1h -Persistent=true - -[Install] -WantedBy=timers.target diff --git a/dashboard/backgrounds/scarif.jpg b/dashboard/backgrounds/scarif.jpg deleted file mode 100644 index 11ac5c1..0000000 Binary files a/dashboard/backgrounds/scarif.jpg and /dev/null differ diff --git a/dashboard/config.ini b/dashboard/config.ini deleted file mode 100644 index 421b3a8..0000000 --- a/dashboard/config.ini +++ /dev/null @@ -1,51 +0,0 @@ -[Settings] -theme = dark -accent = blueGrey -background = static/images/backgrounds/scarif.jpg -roles = admin -home_access_groups = admin_only -settings_access_groups = admin_only -custom_app_title = Scarif Command -sidebar_default = no_sidebar - -[admin] -role = admin -password = -confirm_password = - -[Tower] -prefix = https:// -url = tower.scarif.local -icon = static/images/apps/nextcloud.png -sidebar_icon = static/images/apps/nextcloud.png -description = Imperial data store -open_in = this_tab - -[Personel] -prefix = https:// -url = personel.scarif.local -icon = static/images/icons/monica.svg -sidebar_icon = static/images/icons/monica.svg -description = Personel manifest -open_in = this_tab - -[Labs] -prefix = https:// -url = labs.scarif.local -icon = static/images/apps/gitea.png -sidebar_icon = static/images/apps/gitea.png -description = Top secret development projects -open_in = this_tab - -[weather] -platform = weather -woeid = 44418 -temp_unit = c -wind_speed_unit = kph -air_pressure_unit = mbar -visibility_unit = km - -[Conditions] -type = custom -data_sources = weather - diff --git a/dashboard/icons/jitsi2.png b/dashboard/icons/jitsi2.png deleted file mode 100644 index fb7dcb2..0000000 Binary files a/dashboard/icons/jitsi2.png and /dev/null differ diff --git a/dashboard/icons/monica.svg b/dashboard/icons/monica.svg deleted file mode 100644 index 5c397c7..0000000 --- a/dashboard/icons/monica.svg +++ /dev/null @@ -1 +0,0 @@ -Artboard 3.1Created using Figma \ No newline at end of file diff --git a/dashboard/icons/pinry.jpg b/dashboard/icons/pinry.jpg deleted file mode 100644 index 270e8e4..0000000 Binary files a/dashboard/icons/pinry.jpg and /dev/null differ diff --git a/docker-compose.yml b/docker-compose.yml index 49f0ce5..bb4b8f5 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -20,7 +20,7 @@ services: <<: *logging image: felddy/foundryvtt:release volumes: - - /mnt/tower/foundry:/data + - /mnt/tower/containers/foundry:/data - ./foundry/patches:/data/patches restart: always environment: @@ -37,6 +37,7 @@ services: - FOUNDRY_UID=1000 - FOUNDRY_GID=1000 - VIRTUAL_HOST=rec.${DOMAIN} + - LETSENCRYPT_HOST=rec.${DOMAIN} - CERT_NAME=${DOMAIN} - VIRTUAL_PORT=30000 - VIRTUAL_PATH=/foundry @@ -53,12 +54,13 @@ services: ports: - 9000:9000 volumes: - - nextcloud:/var/www/html + - /mnt/tower/containers/nextcloud:/var/www/html - ./nextcloud/redis-session.ini:/usr/local/etc/php/conf.d/redis-session.ini - /mnt/tower/stardust:/var/www/html/data - /mnt/tower/foundry:/var/www/foundry environment: - VIRTUAL_HOST=tower.${DOMAIN} + - LETSENCRYPT_HOST=tower.${DOMAIN} - CERT_NAME=${DOMAIN} - VIRTUAL_PORT=9000 - VIRTUAL_PROTO=fastcgi @@ -99,6 +101,7 @@ services: - MKNOD environment: - VIRTUAL_HOST=office.${DOMAIN} + - LETSENCRYPT_HOST=office.${DOMAIN} - CERT_NAME=${DOMAIN} - VIRTUAL_PORT=9980 - "DONT_GEN_SSL_CERT=True" @@ -122,6 +125,7 @@ services: image: gitea/gitea:1 environment: - VIRTUAL_HOST=labs.${DOMAIN} + - LETSENCRYPT_HOST=labs.${DOMAIN} - CERT_NAME=${DOMAIN} - VIRTUAL_PORT=3000 - "APP_NAME=Labs: Where the good stuff happens" @@ -138,7 +142,7 @@ services: - DISABLE_REGISTRATION=true restart: always volumes: - - gitea:/data + - /mnt/tower/containers/gitea:/data - /mnt/tower/labs:/data/git - /home/git/.ssh/:/data/git/.ssh/ - /etc/timezone:/etc/timezone:ro @@ -161,6 +165,7 @@ services: environment: - TZ=Europe/London - VIRTUAL_HOST=echo.${DOMAIN} + - LETSENCRYPT_HOST=echo.${DOMAIN} - VIRTUAL_PORT=80 networks: - nginx @@ -174,6 +179,7 @@ services: - CURRENCY=GBP - DEFAULT_LOCALE=en_GB - VIRTUAL_HOST=supplies.${DOMAIN} + - LETSENCRYPT_HOST=supplies.${DOMAIN} - VIRTUAL_PORT=80 volumes: - /mnt/tower/containers/grocy:/config @@ -195,6 +201,7 @@ services: - HBOX_AUTH_API_KEY_PEPPER=${HOMEBOX_API_KEY_PEPPER} - HBOX_OPTIONS_ALLOW_REGISTRATION=true - VIRTUAL_HOST=assets.${DOMAIN} + - LETSENCRYPT_HOST=assets.${DOMAIN} - VIRTUAL_PORT=7745 volumes: - /mnt/tower/containers/homebox:/data/ @@ -209,11 +216,12 @@ services: - redis volumes: - ./searxng:/etc/searxng:rw - - searxng:/var/cache/searxng:rw + - /mnt/tower/containers/searxng:/var/cache/searxng:rw environment: - SEARXNG_BASE_URL=https://${SEARXNG_HOSTNAME:-localhost}/ - SEARXNG_SECRET=${SEARXNG_SECRET_KEY} - VIRTUAL_HOST=holocron.${DOMAIN} + - LETSENCRYPT_HOST=holocron.${DOMAIN} - VIRTUAL_PORT=8080 - CERT_NAME=${DOMAIN} <<: *logging @@ -235,7 +243,7 @@ services: - MOTD="Scarif Minecraft Server" - WHITELIST=${MINECRAFT_WHITELIST} volumes: - - minecraft:/data + - /mnt/tower/containers/minecraft:/data mc-backup: profiles: ["prod"] @@ -253,7 +261,7 @@ services: - PLAYERS_ONLINE_CHECK_INTERVAL=10 - PRUNE_BACKUPS_DAYS=30 volumes: - - minecraft:/data:ro + - /mnt/tower/containers/minecraft:/data - /mnt/backups/minecraft:/backups navidrome: @@ -263,6 +271,7 @@ services: restart: unless-stopped environment: - VIRTUAL_HOST=radio.${DOMAIN} + - LETSENCRYPT_HOST=radio.${DOMAIN} - CERT_NAME=${DOMAIN} - VIRTUAL_PORT=4533 - ND_SCANSCHEDULE=1h @@ -305,6 +314,7 @@ services: # - ${CONFIG}/transcripts:/usr/share/jitsi-meet/transcripts:Z # environment: # - VIRTUAL_HOST=comms.${DOMAIN} + # - LETSENCRYPT_HOST=comms.${DOMAIN} # - VIRTUAL_PORT=80 # - CERT_NAME=${DOMAIN} # - ENABLE_AUTH=1 @@ -420,7 +430,7 @@ services: - MYSQL_USER=${DB_USER} - MYSQL_PASSWORD=${DB_PASSWORD} volumes: - - db:/var/lib/mysql + - /mnt/tower/containers/db:/var/lib/mysql - ./db/init:/docker-entrypoint-initdb.d restart: always networks: @@ -439,7 +449,7 @@ services: image: mongo restart: always volumes: - - mongodb:/data/db + - /mnt/tower/containers/mongodb:/data/db command: mongod networks: - db @@ -456,20 +466,42 @@ services: ports: - "80:80" - "443:443" + labels: + - "com.github.nginx-proxy.nginx" volumes: - /var/run/docker.sock:/tmp/docker.sock:ro - /opt/ssl:/etc/nginx/certs:ro + - html:/usr/share/nginx/html + - vhost:/etc/nginx/vhost.d - ./nginx/vhost.d/labs_location:/etc/nginx/vhost.d/labs.${DOMAIN}_location:ro - ./nginx/vhost.d/office:/etc/nginx/vhost.d/office.${DOMAIN}:ro - ./nginx/vhost.d/rec:/etc/nginx/vhost.d/rec.${DOMAIN}:ro - ./nginx/vhost.d/tower_location_override:/etc/nginx/vhost.d/tower.${DOMAIN}_location_override:ro - ./nginx/vhost.d/tower:/etc/nginx/vhost.d/tower.${DOMAIN}:ro - ./nginx/conf.d/custom_proxy.conf:/etc/nginx/conf.d/custom_proxy.conf:ro - - nextcloud:/var/www/html/nextcloud:ro + - /mnt/tower/containers/nextcloud:/var/www/html/nextcloud:ro - ./christmas:/var/www/html/christmas:ro networks: - nginx + acme-companion: + <<: *logging + profiles: ["prod"] + image: nginxproxy/acme-companion + restart: always + environment: + - DEFAULT_EMAIL=stoffles@gmail.com + volumes: + - /var/run/docker.sock:/var/run/docker.sock:ro + - /opt/ssl:/etc/nginx/certs:rw + - acme:/etc/acme.sh + - vhost:/etc/nginx/vhost.d:rw + - html:/usr/share/nginx/html:rw + depends_on: + - nginx + networks: + - nginx + certs: profiles: ["dev"] image: paulczar/omgwtfssl @@ -484,14 +516,9 @@ services: - SSL_CERT=/certs/${DOMAIN}.crt volumes: - db: - gitea: - nextcloud: - foundry: - minecraft: - change: - mongodb: - searxng: + html: + vhost: + acme: networks: db: