# thingy! some kind of hosting setup ## setup 1. log into the vps, make sure it's fedora (or else 🔪) 2. create a new admin user - `sudo useradd -m -G wheel admin` - `sudo passwd admin` - `sudo su - admin` 3. use the system setup script, and log out - `sudo dnf install git -y` - `git clone https://gitlab.com/futile/thingy` - `./thingy/scripts/system-setup.sh` - `exit` 4. log in again, populate the `.env` and start everything up - `cd thingy` - `micro .env` - `docker compose up` 5. continue with service-specific setups ..... ## services specifics for everything **currently serving** - via docker - **caddy** – http server & reverse proxy - **stalwart** – mailserver - **bulwark** – webmail - **gitea** – git server - via caddy - `mail.yaoi.dog` – mail (server & admin dash) - `post.yaoi.dog` – mail (webmail) - `git.yaoi.dog` – git **dns setup** | type | host | value | notes | |-------|-----------|---------------------------- |----------------------------| | `A` | `@` | `` | apex domain | | `A` | `mail` | `` | mailserver | | `A` | `post` | `` | webmail | | `A` | `git` | `` | gitea | | `CAA` | `@` | `0 issue "letsencrypt.org"` | allow caddy to issue certs | ### caddy > [!NOTE] > **todo** // detail setup ### stalwart
initial setup 1. server identity - server hostname: `mail.yaoi.dog` - default email domain: `yaoi.dog` - automatically obtain tls certificate: `true` - generate email signing keys: `true` 2. storage - main data storage: `rocksdb` - path: `/var/lib/stalwart/` 3. account directory - directory type: `use internal` 4. logging - log destination: `console` 5. automatic dns management - dns server type: `porkbun` - description: `porkbun`
further setup - settings -> security -> allowed ips - added `172.18.0.0/24`; reason: `internal` - settings -> network -> http -> security - permissive cors policy: `true` **[restart needed]** - settings -> authentication -> oidc provider - oauth settings - key: `secret read from environment variable` - variable name: `OIDC_KEY` - openid connect - signature algorithm: `ECDSA using P-384 and SHA-384` - signature key: `secret read from environment variable` - variable name: `OIDC_SIGNATURE_KEY`
useful links - https://stalw.art/docs - https://testconnectivity.microsoft.com/tests/Imap/input - https://mail-tester.com
### bulwark > [!NOTE] > **todo** // detail setup
useful links - https://bulwarkmail.org/docs
### gitea
initial setup - database settings - database type: `sqlite3` - path: `/data/gitea/gitea.db` - general settings - site title: `We cock. Dick. BALLING.` - server domain: `git.yaoi.dog` - ssh server port: `22` - gitea base url: `https://git.yaoi.dog/` - enable update checker: `true` - email settings - smtp host: `mail.yaoi.dog` - smtp port: `465` - send email as: `"Gitea" ` - smtp username: `system@yaoi.dog` - smtp password: `` - enable email notifications: `true` - server and third-party service settings - enable openid sign-in: `false` - disable self-registration: `false` - allow registration only through external services: `true` - enable openid self-registration: `true` - hidden email domain: `git.yaoi.dog` - password hash algorithm: `argon2`
## backups backups are done with [vykar](https://vykar.borgbase.com) to [borgbase](https://borgbase.com) always remember to `docker compose stop` before doing any of this! **creating** - if on a new borgbase repo, run `vykar init` first - to back up, run `sudo vykar backup` (sudo required as we are accessing `/var/lib/docker/volumes/`) - to back up automatically, run `sudo EDITOR=micro crontab -e` and add the following: ``` TZ=UTC 0 6 * * * /home/admin/thingy/scripts/volume-backup.sh ``` **restoring** the restore process is kind of fucked up but doable - restore on new system - run `vykar list` to find a snapshot to use - `sudo rm -rf /var/lib/docker/volumes/` - then `sudo vykar restore abcd1234 /var/lib/docker/volumes/` - figure out the UID:GID for all containers and `sudo chown -R UID:GID /var/lib/docker/volumes/.../_data/` their respective volumes - restore on same system - run `vykar list` to find a snapshot to use - then `sudo vykar restore abcd1234 /var/lib/docker/volumes/` ## todo - further secure the server (ratelimiting, hardening...) - figure out best way to store .env, other credentials, and various secrets - more services - ~~gitea (need to change host ssh port)~~ - vaultwarden - ~~tie all services together with an sso~~ - use postgres for everything ## misc **useful commands** - `docker exec env`