Cleaning up
This commit is contained in:
@@ -1,6 +0,0 @@
|
|||||||
[Unit]
|
|
||||||
Description=Let's Encrypt renewal
|
|
||||||
|
|
||||||
[Service]
|
|
||||||
Type=oneshot
|
|
||||||
ExecStart=/usr/bin/certbot renew --quiet --agree-tos --deploy-hook "cp /etc/letsencrypt/live/scarif.space-0001/fullchain.pem /opt/ssl/scarif.space.crt && cp /etc/letsencrypt/live/scarif.space-0001/privkey.pem /opt/ssl/scarif.space.key && docker-compose -f /opt/scarif/docker-compose.yml exec nginx nginx -s reload"
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
[Unit]
|
|
||||||
Description=Twice daily renewal of Let's Encrypt's certificates
|
|
||||||
|
|
||||||
[Timer]
|
|
||||||
OnCalendar=0/12:00:00
|
|
||||||
RandomizedDelaySec=1h
|
|
||||||
Persistent=true
|
|
||||||
|
|
||||||
[Install]
|
|
||||||
WantedBy=timers.target
|
|
||||||
Binary file not shown.
|
Before Width: | Height: | Size: 353 KiB |
@@ -1,51 +0,0 @@
|
|||||||
[Settings]
|
|
||||||
theme = dark
|
|
||||||
accent = blueGrey
|
|
||||||
background = static/images/backgrounds/scarif.jpg
|
|
||||||
roles = admin
|
|
||||||
home_access_groups = admin_only
|
|
||||||
settings_access_groups = admin_only
|
|
||||||
custom_app_title = Scarif Command
|
|
||||||
sidebar_default = no_sidebar
|
|
||||||
|
|
||||||
[admin]
|
|
||||||
role = admin
|
|
||||||
password =
|
|
||||||
confirm_password =
|
|
||||||
|
|
||||||
[Tower]
|
|
||||||
prefix = https://
|
|
||||||
url = tower.scarif.local
|
|
||||||
icon = static/images/apps/nextcloud.png
|
|
||||||
sidebar_icon = static/images/apps/nextcloud.png
|
|
||||||
description = Imperial data store
|
|
||||||
open_in = this_tab
|
|
||||||
|
|
||||||
[Personel]
|
|
||||||
prefix = https://
|
|
||||||
url = personel.scarif.local
|
|
||||||
icon = static/images/icons/monica.svg
|
|
||||||
sidebar_icon = static/images/icons/monica.svg
|
|
||||||
description = Personel manifest
|
|
||||||
open_in = this_tab
|
|
||||||
|
|
||||||
[Labs]
|
|
||||||
prefix = https://
|
|
||||||
url = labs.scarif.local
|
|
||||||
icon = static/images/apps/gitea.png
|
|
||||||
sidebar_icon = static/images/apps/gitea.png
|
|
||||||
description = Top secret development projects
|
|
||||||
open_in = this_tab
|
|
||||||
|
|
||||||
[weather]
|
|
||||||
platform = weather
|
|
||||||
woeid = 44418
|
|
||||||
temp_unit = c
|
|
||||||
wind_speed_unit = kph
|
|
||||||
air_pressure_unit = mbar
|
|
||||||
visibility_unit = km
|
|
||||||
|
|
||||||
[Conditions]
|
|
||||||
type = custom
|
|
||||||
data_sources = weather
|
|
||||||
|
|
||||||
Binary file not shown.
|
Before Width: | Height: | Size: 106 KiB |
@@ -1 +0,0 @@
|
|||||||
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="500" height="500" version="1.1" viewBox="0 0 500 500"><title>Artboard 3.1</title><desc>Created using Figma</desc><g id="Canvas" transform="translate(-2984 68)"><clipPath id="clip-0" clip-rule="evenodd"><path fill="#FFF" d="M 2984 -68L 3484 -68L 3484 432L 2984 432L 2984 -68Z"/></clipPath><g id="Artboard 3.1" clip-path="url(#clip-0)"><g id="Group 2"><g id="Oval"><use fill="#2C2B29" transform="translate(3002.51 -26.4788)" xlink:href="#path0_fill"/></g><g id="Oval"><use fill="#FFF" transform="translate(3047.56 17.3456)" xlink:href="#path1_fill"/></g><g id="Oval 2"><use fill="#2C2B29" transform="translate(2990 -39)" xlink:href="#path2_fill"/></g><g id="Oval 2"><use fill="#2C2B29" transform="matrix(-1 0 0 1 3478 -39)" xlink:href="#path2_fill"/></g><g id="Group"><g id="Oval 4"><use fill="#2B2A28" transform="translate(3265.32 122.647)" xlink:href="#path3_fill"/></g><g id="Oval 3"><use fill="#FFF" transform="translate(3292.63 154.768)" xlink:href="#path4_fill"/></g></g><g id="Group"><g id="Oval 4"><use fill="#2B2A28" transform="matrix(-1 0 0 1 3203.93 122.647)" xlink:href="#path3_fill"/></g><g id="Oval 3"><use fill="#FFF" transform="matrix(-1 0 0 1 3176.62 154.768)" xlink:href="#path4_fill"/></g></g><g id="Oval 5"><use fill="#2C2B29" transform="translate(3200.22 256.501)" xlink:href="#path5_fill"/></g></g></g></g><defs><path id="path0_fill" fill-rule="evenodd" d="M 235.425 429.479C 349.64 429.479 476.369 356.022 460.345 214.739C 444.321 73.4567 349.64 0 235.425 0C 121.21 0 27.2705 64.3949 2.77082 214.739C -21.7289 365.084 121.21 429.479 235.425 429.479Z"/><path id="path1_fill" fill-rule="evenodd" d="M 188.85 344.334C 280.47 344.334 382.128 285.44 369.274 172.167C 356.42 58.8939 280.47 0 188.85 0C 97.2312 0 21.8755 51.6286 2.22266 172.167C -17.4302 292.706 97.2312 344.334 188.85 344.334Z"/><path id="path2_fill" fill-rule="evenodd" d="M 65.5865 165.28C 78.0014 165.322 83.3945 120.9 105.565 100.675C 125.919 82.1083 172.677 75.742 172.677 54.2762C 172.677 9.42729 124.055 0 81.1199 0C 38.1853 0 0 45.4903 0 90.3392C 0 135.188 41.7747 165.201 65.5865 165.28Z"/><path id="path3_fill" fill-rule="evenodd" d="M 69.6 154.572C 102.094 146.823 115.643 133.157 115.643 88.997C 115.643 44.8368 94.944 0 59.3049 0C 23.6657 0 0 31.8863 0 76.0465C 0 120.207 37.106 162.32 69.6 154.572Z"/><path id="path4_fill" fill-rule="evenodd" d="M 30.3863 66.4287C 39.2286 66.4287 41.8586 64.1715 45.8555 59.1037C 50.3374 53.421 53.6797 46.8294 52.5868 33.2144C 50.7608 10.465 41.1736 0 22.4162 0C 3.6587 0 -3.78365e-16 14.4228 0 33.2144C -3.78365e-16 52.0059 11.6288 66.4287 30.3863 66.4287Z"/><path id="path5_fill" fill-rule="evenodd" d="M 35.2906 50.085C 52.9487 50.085 70.0718 24.0956 70.0718 12.9499C 70.0718 1.80416 52.6939 0 35.0359 0C 17.3779 0 0 1.80416 0 12.9499C 0 24.0956 17.6326 50.085 35.2906 50.085Z"/></defs></svg>
|
|
||||||
|
Before Width: | Height: | Size: 2.8 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 18 KiB |
+44
-17
@@ -20,7 +20,7 @@ services:
|
|||||||
<<: *logging
|
<<: *logging
|
||||||
image: felddy/foundryvtt:release
|
image: felddy/foundryvtt:release
|
||||||
volumes:
|
volumes:
|
||||||
- /mnt/tower/foundry:/data
|
- /mnt/tower/containers/foundry:/data
|
||||||
- ./foundry/patches:/data/patches
|
- ./foundry/patches:/data/patches
|
||||||
restart: always
|
restart: always
|
||||||
environment:
|
environment:
|
||||||
@@ -37,6 +37,7 @@ services:
|
|||||||
- FOUNDRY_UID=1000
|
- FOUNDRY_UID=1000
|
||||||
- FOUNDRY_GID=1000
|
- FOUNDRY_GID=1000
|
||||||
- VIRTUAL_HOST=rec.${DOMAIN}
|
- VIRTUAL_HOST=rec.${DOMAIN}
|
||||||
|
- LETSENCRYPT_HOST=rec.${DOMAIN}
|
||||||
- CERT_NAME=${DOMAIN}
|
- CERT_NAME=${DOMAIN}
|
||||||
- VIRTUAL_PORT=30000
|
- VIRTUAL_PORT=30000
|
||||||
- VIRTUAL_PATH=/foundry
|
- VIRTUAL_PATH=/foundry
|
||||||
@@ -53,12 +54,13 @@ services:
|
|||||||
ports:
|
ports:
|
||||||
- 9000:9000
|
- 9000:9000
|
||||||
volumes:
|
volumes:
|
||||||
- nextcloud:/var/www/html
|
- /mnt/tower/containers/nextcloud:/var/www/html
|
||||||
- ./nextcloud/redis-session.ini:/usr/local/etc/php/conf.d/redis-session.ini
|
- ./nextcloud/redis-session.ini:/usr/local/etc/php/conf.d/redis-session.ini
|
||||||
- /mnt/tower/stardust:/var/www/html/data
|
- /mnt/tower/stardust:/var/www/html/data
|
||||||
- /mnt/tower/foundry:/var/www/foundry
|
- /mnt/tower/foundry:/var/www/foundry
|
||||||
environment:
|
environment:
|
||||||
- VIRTUAL_HOST=tower.${DOMAIN}
|
- VIRTUAL_HOST=tower.${DOMAIN}
|
||||||
|
- LETSENCRYPT_HOST=tower.${DOMAIN}
|
||||||
- CERT_NAME=${DOMAIN}
|
- CERT_NAME=${DOMAIN}
|
||||||
- VIRTUAL_PORT=9000
|
- VIRTUAL_PORT=9000
|
||||||
- VIRTUAL_PROTO=fastcgi
|
- VIRTUAL_PROTO=fastcgi
|
||||||
@@ -99,6 +101,7 @@ services:
|
|||||||
- MKNOD
|
- MKNOD
|
||||||
environment:
|
environment:
|
||||||
- VIRTUAL_HOST=office.${DOMAIN}
|
- VIRTUAL_HOST=office.${DOMAIN}
|
||||||
|
- LETSENCRYPT_HOST=office.${DOMAIN}
|
||||||
- CERT_NAME=${DOMAIN}
|
- CERT_NAME=${DOMAIN}
|
||||||
- VIRTUAL_PORT=9980
|
- VIRTUAL_PORT=9980
|
||||||
- "DONT_GEN_SSL_CERT=True"
|
- "DONT_GEN_SSL_CERT=True"
|
||||||
@@ -122,6 +125,7 @@ services:
|
|||||||
image: gitea/gitea:1
|
image: gitea/gitea:1
|
||||||
environment:
|
environment:
|
||||||
- VIRTUAL_HOST=labs.${DOMAIN}
|
- VIRTUAL_HOST=labs.${DOMAIN}
|
||||||
|
- LETSENCRYPT_HOST=labs.${DOMAIN}
|
||||||
- CERT_NAME=${DOMAIN}
|
- CERT_NAME=${DOMAIN}
|
||||||
- VIRTUAL_PORT=3000
|
- VIRTUAL_PORT=3000
|
||||||
- "APP_NAME=Labs: Where the good stuff happens"
|
- "APP_NAME=Labs: Where the good stuff happens"
|
||||||
@@ -138,7 +142,7 @@ services:
|
|||||||
- DISABLE_REGISTRATION=true
|
- DISABLE_REGISTRATION=true
|
||||||
restart: always
|
restart: always
|
||||||
volumes:
|
volumes:
|
||||||
- gitea:/data
|
- /mnt/tower/containers/gitea:/data
|
||||||
- /mnt/tower/labs:/data/git
|
- /mnt/tower/labs:/data/git
|
||||||
- /home/git/.ssh/:/data/git/.ssh/
|
- /home/git/.ssh/:/data/git/.ssh/
|
||||||
- /etc/timezone:/etc/timezone:ro
|
- /etc/timezone:/etc/timezone:ro
|
||||||
@@ -161,6 +165,7 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
- TZ=Europe/London
|
- TZ=Europe/London
|
||||||
- VIRTUAL_HOST=echo.${DOMAIN}
|
- VIRTUAL_HOST=echo.${DOMAIN}
|
||||||
|
- LETSENCRYPT_HOST=echo.${DOMAIN}
|
||||||
- VIRTUAL_PORT=80
|
- VIRTUAL_PORT=80
|
||||||
networks:
|
networks:
|
||||||
- nginx
|
- nginx
|
||||||
@@ -174,6 +179,7 @@ services:
|
|||||||
- CURRENCY=GBP
|
- CURRENCY=GBP
|
||||||
- DEFAULT_LOCALE=en_GB
|
- DEFAULT_LOCALE=en_GB
|
||||||
- VIRTUAL_HOST=supplies.${DOMAIN}
|
- VIRTUAL_HOST=supplies.${DOMAIN}
|
||||||
|
- LETSENCRYPT_HOST=supplies.${DOMAIN}
|
||||||
- VIRTUAL_PORT=80
|
- VIRTUAL_PORT=80
|
||||||
volumes:
|
volumes:
|
||||||
- /mnt/tower/containers/grocy:/config
|
- /mnt/tower/containers/grocy:/config
|
||||||
@@ -195,6 +201,7 @@ services:
|
|||||||
- HBOX_AUTH_API_KEY_PEPPER=${HOMEBOX_API_KEY_PEPPER}
|
- HBOX_AUTH_API_KEY_PEPPER=${HOMEBOX_API_KEY_PEPPER}
|
||||||
- HBOX_OPTIONS_ALLOW_REGISTRATION=true
|
- HBOX_OPTIONS_ALLOW_REGISTRATION=true
|
||||||
- VIRTUAL_HOST=assets.${DOMAIN}
|
- VIRTUAL_HOST=assets.${DOMAIN}
|
||||||
|
- LETSENCRYPT_HOST=assets.${DOMAIN}
|
||||||
- VIRTUAL_PORT=7745
|
- VIRTUAL_PORT=7745
|
||||||
volumes:
|
volumes:
|
||||||
- /mnt/tower/containers/homebox:/data/
|
- /mnt/tower/containers/homebox:/data/
|
||||||
@@ -209,11 +216,12 @@ services:
|
|||||||
- redis
|
- redis
|
||||||
volumes:
|
volumes:
|
||||||
- ./searxng:/etc/searxng:rw
|
- ./searxng:/etc/searxng:rw
|
||||||
- searxng:/var/cache/searxng:rw
|
- /mnt/tower/containers/searxng:/var/cache/searxng:rw
|
||||||
environment:
|
environment:
|
||||||
- SEARXNG_BASE_URL=https://${SEARXNG_HOSTNAME:-localhost}/
|
- SEARXNG_BASE_URL=https://${SEARXNG_HOSTNAME:-localhost}/
|
||||||
- SEARXNG_SECRET=${SEARXNG_SECRET_KEY}
|
- SEARXNG_SECRET=${SEARXNG_SECRET_KEY}
|
||||||
- VIRTUAL_HOST=holocron.${DOMAIN}
|
- VIRTUAL_HOST=holocron.${DOMAIN}
|
||||||
|
- LETSENCRYPT_HOST=holocron.${DOMAIN}
|
||||||
- VIRTUAL_PORT=8080
|
- VIRTUAL_PORT=8080
|
||||||
- CERT_NAME=${DOMAIN}
|
- CERT_NAME=${DOMAIN}
|
||||||
<<: *logging
|
<<: *logging
|
||||||
@@ -235,7 +243,7 @@ services:
|
|||||||
- MOTD="Scarif Minecraft Server"
|
- MOTD="Scarif Minecraft Server"
|
||||||
- WHITELIST=${MINECRAFT_WHITELIST}
|
- WHITELIST=${MINECRAFT_WHITELIST}
|
||||||
volumes:
|
volumes:
|
||||||
- minecraft:/data
|
- /mnt/tower/containers/minecraft:/data
|
||||||
|
|
||||||
mc-backup:
|
mc-backup:
|
||||||
profiles: ["prod"]
|
profiles: ["prod"]
|
||||||
@@ -253,7 +261,7 @@ services:
|
|||||||
- PLAYERS_ONLINE_CHECK_INTERVAL=10
|
- PLAYERS_ONLINE_CHECK_INTERVAL=10
|
||||||
- PRUNE_BACKUPS_DAYS=30
|
- PRUNE_BACKUPS_DAYS=30
|
||||||
volumes:
|
volumes:
|
||||||
- minecraft:/data:ro
|
- /mnt/tower/containers/minecraft:/data
|
||||||
- /mnt/backups/minecraft:/backups
|
- /mnt/backups/minecraft:/backups
|
||||||
|
|
||||||
navidrome:
|
navidrome:
|
||||||
@@ -263,6 +271,7 @@ services:
|
|||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
- VIRTUAL_HOST=radio.${DOMAIN}
|
- VIRTUAL_HOST=radio.${DOMAIN}
|
||||||
|
- LETSENCRYPT_HOST=radio.${DOMAIN}
|
||||||
- CERT_NAME=${DOMAIN}
|
- CERT_NAME=${DOMAIN}
|
||||||
- VIRTUAL_PORT=4533
|
- VIRTUAL_PORT=4533
|
||||||
- ND_SCANSCHEDULE=1h
|
- ND_SCANSCHEDULE=1h
|
||||||
@@ -305,6 +314,7 @@ services:
|
|||||||
# - ${CONFIG}/transcripts:/usr/share/jitsi-meet/transcripts:Z
|
# - ${CONFIG}/transcripts:/usr/share/jitsi-meet/transcripts:Z
|
||||||
# environment:
|
# environment:
|
||||||
# - VIRTUAL_HOST=comms.${DOMAIN}
|
# - VIRTUAL_HOST=comms.${DOMAIN}
|
||||||
|
# - LETSENCRYPT_HOST=comms.${DOMAIN}
|
||||||
# - VIRTUAL_PORT=80
|
# - VIRTUAL_PORT=80
|
||||||
# - CERT_NAME=${DOMAIN}
|
# - CERT_NAME=${DOMAIN}
|
||||||
# - ENABLE_AUTH=1
|
# - ENABLE_AUTH=1
|
||||||
@@ -420,7 +430,7 @@ services:
|
|||||||
- MYSQL_USER=${DB_USER}
|
- MYSQL_USER=${DB_USER}
|
||||||
- MYSQL_PASSWORD=${DB_PASSWORD}
|
- MYSQL_PASSWORD=${DB_PASSWORD}
|
||||||
volumes:
|
volumes:
|
||||||
- db:/var/lib/mysql
|
- /mnt/tower/containers/db:/var/lib/mysql
|
||||||
- ./db/init:/docker-entrypoint-initdb.d
|
- ./db/init:/docker-entrypoint-initdb.d
|
||||||
restart: always
|
restart: always
|
||||||
networks:
|
networks:
|
||||||
@@ -439,7 +449,7 @@ services:
|
|||||||
image: mongo
|
image: mongo
|
||||||
restart: always
|
restart: always
|
||||||
volumes:
|
volumes:
|
||||||
- mongodb:/data/db
|
- /mnt/tower/containers/mongodb:/data/db
|
||||||
command: mongod
|
command: mongod
|
||||||
networks:
|
networks:
|
||||||
- db
|
- db
|
||||||
@@ -456,20 +466,42 @@ services:
|
|||||||
ports:
|
ports:
|
||||||
- "80:80"
|
- "80:80"
|
||||||
- "443:443"
|
- "443:443"
|
||||||
|
labels:
|
||||||
|
- "com.github.nginx-proxy.nginx"
|
||||||
volumes:
|
volumes:
|
||||||
- /var/run/docker.sock:/tmp/docker.sock:ro
|
- /var/run/docker.sock:/tmp/docker.sock:ro
|
||||||
- /opt/ssl:/etc/nginx/certs:ro
|
- /opt/ssl:/etc/nginx/certs:ro
|
||||||
|
- html:/usr/share/nginx/html
|
||||||
|
- vhost:/etc/nginx/vhost.d
|
||||||
- ./nginx/vhost.d/labs_location:/etc/nginx/vhost.d/labs.${DOMAIN}_location:ro
|
- ./nginx/vhost.d/labs_location:/etc/nginx/vhost.d/labs.${DOMAIN}_location:ro
|
||||||
- ./nginx/vhost.d/office:/etc/nginx/vhost.d/office.${DOMAIN}:ro
|
- ./nginx/vhost.d/office:/etc/nginx/vhost.d/office.${DOMAIN}:ro
|
||||||
- ./nginx/vhost.d/rec:/etc/nginx/vhost.d/rec.${DOMAIN}:ro
|
- ./nginx/vhost.d/rec:/etc/nginx/vhost.d/rec.${DOMAIN}:ro
|
||||||
- ./nginx/vhost.d/tower_location_override:/etc/nginx/vhost.d/tower.${DOMAIN}_location_override:ro
|
- ./nginx/vhost.d/tower_location_override:/etc/nginx/vhost.d/tower.${DOMAIN}_location_override:ro
|
||||||
- ./nginx/vhost.d/tower:/etc/nginx/vhost.d/tower.${DOMAIN}:ro
|
- ./nginx/vhost.d/tower:/etc/nginx/vhost.d/tower.${DOMAIN}:ro
|
||||||
- ./nginx/conf.d/custom_proxy.conf:/etc/nginx/conf.d/custom_proxy.conf:ro
|
- ./nginx/conf.d/custom_proxy.conf:/etc/nginx/conf.d/custom_proxy.conf:ro
|
||||||
- nextcloud:/var/www/html/nextcloud:ro
|
- /mnt/tower/containers/nextcloud:/var/www/html/nextcloud:ro
|
||||||
- ./christmas:/var/www/html/christmas:ro
|
- ./christmas:/var/www/html/christmas:ro
|
||||||
networks:
|
networks:
|
||||||
- nginx
|
- nginx
|
||||||
|
|
||||||
|
acme-companion:
|
||||||
|
<<: *logging
|
||||||
|
profiles: ["prod"]
|
||||||
|
image: nginxproxy/acme-companion
|
||||||
|
restart: always
|
||||||
|
environment:
|
||||||
|
- DEFAULT_EMAIL=stoffles@gmail.com
|
||||||
|
volumes:
|
||||||
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
|
- /opt/ssl:/etc/nginx/certs:rw
|
||||||
|
- acme:/etc/acme.sh
|
||||||
|
- vhost:/etc/nginx/vhost.d:rw
|
||||||
|
- html:/usr/share/nginx/html:rw
|
||||||
|
depends_on:
|
||||||
|
- nginx
|
||||||
|
networks:
|
||||||
|
- nginx
|
||||||
|
|
||||||
certs:
|
certs:
|
||||||
profiles: ["dev"]
|
profiles: ["dev"]
|
||||||
image: paulczar/omgwtfssl
|
image: paulczar/omgwtfssl
|
||||||
@@ -484,14 +516,9 @@ services:
|
|||||||
- SSL_CERT=/certs/${DOMAIN}.crt
|
- SSL_CERT=/certs/${DOMAIN}.crt
|
||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
db:
|
html:
|
||||||
gitea:
|
vhost:
|
||||||
nextcloud:
|
acme:
|
||||||
foundry:
|
|
||||||
minecraft:
|
|
||||||
change:
|
|
||||||
mongodb:
|
|
||||||
searxng:
|
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
db:
|
db:
|
||||||
|
|||||||
Reference in New Issue
Block a user