Files
2026-07-20 08:06:33 +01:00

186 lines
5.1 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# thingy!
some kind of hosting setup
## setup
1. log into the vps, make sure it's fedora (or else 🔪)
2. create a new admin user
- `sudo useradd -m -G wheel admin`
- `sudo passwd admin`
- `sudo su - admin`
3. use the system setup script, and log out
- `sudo dnf install git -y`
- `git clone https://gitlab.com/futile/thingy`
- `./thingy/scripts/system-setup.sh`
- `exit`
4. log in again, populate the `.env` and start everything up
- `cd thingy`
- `micro .env`
- `docker compose up`
5. continue with service-specific setups .....
## services
specifics for everything
**currently serving**
- via docker
- **caddy** http server & reverse proxy
- **stalwart** mailserver
- **bulwark** webmail
- **gitea** git server
- via caddy
- `mail.yaoi.dog` mail (server & admin dash)
- `post.yaoi.dog` mail (webmail)
- `git.yaoi.dog` git
**dns setup**
| type | host | value | notes |
|-------|-----------|---------------------------- |----------------------------|
| `A` | `@` | `<ip>` | apex domain |
| `A` | `mail` | `<ip>` | mailserver |
| `A` | `post` | `<ip>` | webmail |
| `A` | `git` | `<ip>` | gitea |
| `CAA` | `@` | `0 issue "letsencrypt.org"` | allow caddy to issue certs |
### caddy
> [!NOTE]
> **todo** // detail setup
### stalwart
<details>
<summary>initial setup</summary>
1. server identity
- server hostname: `mail.yaoi.dog`
- default email domain: `yaoi.dog`
- automatically obtain tls certificate: `true`
- generate email signing keys: `true`
2. storage
- main data storage: `rocksdb`
- path: `/var/lib/stalwart/`
3. account directory
- directory type: `use internal`
4. logging
- log destination: `console`
5. automatic dns management
- dns server type: `porkbun`
- description: `porkbun`
</details>
<details>
<summary>further setup</summary>
- settings -> security -> allowed ips
- added `172.18.0.0/24`; reason: `internal`
- settings -> network -> http -> security
- permissive cors policy: `true` **[restart needed]**
- settings -> authentication -> oidc provider
- oauth settings
- key: `secret read from environment variable`
- variable name: `OIDC_KEY`
- openid connect
- signature algorithm: `ECDSA using P-384 and SHA-384`
- signature key: `secret read from environment variable`
- variable name: `OIDC_SIGNATURE_KEY`
</details>
<details>
<summary>useful links</summary>
- https://stalw.art/docs
- https://testconnectivity.microsoft.com/tests/Imap/input
- https://mail-tester.com
</details>
### bulwark
> [!NOTE]
> **todo** // detail setup
<details>
<summary>useful links</summary>
- https://bulwarkmail.org/docs
</details>
### gitea
<details>
<summary>initial setup</summary>
- database settings
- database type: `sqlite3`
- path: `/data/gitea/gitea.db`
- general settings
- site title: `We cock. Dick. BALLING.`
- server domain: `git.yaoi.dog`
- ssh server port: `22`
- gitea base url: `https://git.yaoi.dog/`
- enable update checker: `true`
- email settings
- smtp host: `mail.yaoi.dog`
- smtp port: `465`
- send email as: `"Gitea" <system@yaoi.dog>`
- smtp username: `system@yaoi.dog`
- smtp password: `<password>`
- enable email notifications: `true`
- server and third-party service settings
- enable openid sign-in: `false`
- disable self-registration: `false`
- allow registration only through external services: `true`
- enable openid self-registration: `true`
- hidden email domain: `git.yaoi.dog`
- password hash algorithm: `argon2`
</details>
## backups
backups are done with [vykar](https://vykar.borgbase.com) to [borgbase](https://borgbase.com)
always remember to `docker compose stop` before doing any of this!
**creating**
- if on a new borgbase repo, run `vykar init` first
- to back up, run `sudo vykar backup` (sudo required as we are accessing `/var/lib/docker/volumes/`)
- to back up automatically, run `sudo EDITOR=micro crontab -e` and add the following:
```
TZ=UTC
0 6 * * * /home/admin/thingy/scripts/volume-backup.sh
```
**restoring**
the restore process is kind of fucked up but doable
- restore on new system
- run `vykar list` to find a snapshot to use
- `sudo rm -rf /var/lib/docker/volumes/`
- then `sudo vykar restore abcd1234 /var/lib/docker/volumes/`
- figure out the UID:GID for all containers and `sudo chown -R UID:GID /var/lib/docker/volumes/.../_data/` their respective volumes
- restore on same system
- run `vykar list` to find a snapshot to use
- then `sudo vykar restore abcd1234 /var/lib/docker/volumes/`
## todo
- further secure the server (ratelimiting, hardening...)
- figure out best way to store .env, other credentials, and various secrets
- more services
- ~~gitea (need to change host ssh port)~~
- vaultwarden
- ~~tie all services together with an sso~~
- use postgres for everything
## misc
**useful commands**
- `docker exec <service> env`