Commit graph

1508 commits

Author SHA1 Message Date
91a247868b
Add routes from forrest to tailscale network
All checks were successful
/ terraform (push) Successful in 27s
/ ansible (push) Successful in 1m35s
2024-02-07 22:12:08 +00:00
df43be6f9b
Set private_ip for some other machines
All checks were successful
/ terraform (push) Successful in 36s
/ ansible (push) Successful in 1m39s
2024-02-07 19:27:48 +00:00
b6eca40ae0
Allow tailscale IP in more places 2024-02-07 18:21:16 +00:00
6c1c245c23 Update matrixdotorg/synapse Docker tag to v1.100.0
All checks were successful
/ terraform (push) Successful in 25s
/ ansible (push) Successful in 1m38s
2024-02-02 13:38:12 +00:00
379d4a26fa Update vabene1111/recipes Docker tag to v1.5.12
Some checks failed
/ ansible (push) Has been cancelled
/ terraform (push) Has been cancelled
2024-02-02 13:38:00 +00:00
f1a2694f1a Update lscr.io/linuxserver/mastodon Docker tag to v4.2.5
Some checks failed
/ terraform (push) Successful in 29s
/ ansible (push) Has been cancelled
2024-02-02 13:37:05 +00:00
02847355a7
Install tailscale
All checks were successful
/ terraform (push) Successful in 29s
/ ansible (push) Successful in 1m34s
Install, not configure
2024-02-01 19:41:47 +00:00
29cac09b48
Remove explicit port for headscale 2024-02-01 18:32:53 +00:00
dba0262801
Remove website tmpfs
All checks were successful
/ terraform (push) Successful in 29s
/ ansible (push) Successful in 1m36s
The server's disk is probably fast enough, and container restarts will nuke that storage anyway
2024-02-01 18:15:51 +00:00
0c6528f9ca
Restrict access to headscale OIDC and API
All checks were successful
/ terraform (push) Successful in 29s
/ ansible (push) Successful in 1m33s
2024-01-31 21:40:43 +00:00
dfa8328e7b
Move gateway logs to separate file 2024-01-31 21:06:19 +00:00
53c758a781
Monitor headscale with prometheus
All checks were successful
/ terraform (push) Successful in 29s
/ ansible (push) Successful in 1m38s
2024-01-27 17:40:02 +00:00
b51677b795
Back up headscale config
All checks were successful
/ terraform (push) Successful in 48s
/ ansible (push) Successful in 1m51s
2024-01-27 15:04:53 +00:00
2ceeaf091d
Deploy headscale
Some checks failed
/ terraform (push) Failing after 11m20s
/ ansible (push) Failing after 11m6s
2024-01-27 14:18:37 +00:00
06784563a7
Don't resolve ipv6
All checks were successful
/ terraform (push) Successful in 30s
/ ansible (push) Successful in 1m36s
Something about this setup doesn't like it, so I'll disable v6 for now
2024-01-26 21:43:04 +00:00
4f6f4143ce Update matrixdotorg/synapse Docker tag to v1.99.0
All checks were successful
/ terraform (push) Successful in 31s
/ ansible (push) Successful in 1m46s
2024-01-22 09:15:38 +00:00
5292785cd9 Update wallabag/wallabag Docker tag to v2.6.8
Some checks are pending
/ terraform (push) Has started running
/ ansible (push) Successful in 1m38s
2024-01-22 09:11:27 +00:00
d297674fb5 Update vabene1111/recipes Docker tag to v1.5.11
All checks were successful
/ terraform (push) Successful in 49s
/ ansible (push) Successful in 1m51s
2024-01-22 08:42:36 +00:00
88f0828153
Use primary Quad9 servers
All checks were successful
/ terraform (push) Successful in 47s
/ ansible (push) Successful in 1m39s
DNSSEC and malware blocking is probably useful, just in case
2024-01-21 23:19:49 +00:00
cfc3de61b4
Add fallback quad9 address
This aids availability, along with a healthcheck
2024-01-21 23:05:25 +00:00
c6bae0f797
Do simple endsWith matching for docker view
All checks were successful
/ terraform (push) Successful in 33s
/ ansible (push) Successful in 1m42s
This saves the need for a regex
2024-01-14 22:27:02 +00:00
4c5936b2aa
Disable Grafana analytics
All checks were successful
/ terraform (push) Successful in 32s
/ ansible (push) Successful in 1m41s
2024-01-14 15:30:12 +00:00
9d685d85aa
Update website deployment to unify containers
All checks were successful
/ terraform (push) Successful in 1m9s
/ ansible (push) Successful in 2m17s
2024-01-14 14:22:19 +00:00
ac166c3874
Start resolved to support mDNS
All checks were successful
/ terraform (push) Successful in 34s
/ ansible (push) Successful in 1m44s
2024-01-10 13:28:45 +00:00
06b9197c5b
Sync terraform state to restic
All checks were successful
/ terraform (push) Successful in 31s
/ ansible (push) Successful in 1m47s
This allows it to be backed up easily
2024-01-09 19:56:06 +00:00
4a69df1d6c
Ignore ansible-lint for nebula install block
All checks were successful
/ terraform (push) Successful in 1m28s
/ ansible (push) Successful in 1m48s
I'm smarter than it is
2024-01-08 21:49:38 +00:00
f33d19e156
Move AdGuardHome configuration to Terraform
https://git.theorangeone.net/systems/adguardhome
2024-01-08 21:45:28 +00:00
ed59458f39
Add backups to tang
Some checks failed
/ terraform (push) Successful in 1m21s
/ ansible (push) Failing after 1m37s
2024-01-08 19:20:55 +00:00
616d20e23b
Tweak some AGH settings
Some checks failed
/ terraform (push) Successful in 1m15s
/ ansible (push) Failing after 1m59s
2024-01-08 19:01:46 +00:00
383a57d1f2
Use DoH endpoint fot quad9
Seems latency is much lower
2024-01-08 18:21:03 +00:00
c8211d4756
Use Debian repo version of nginx
Some checks failed
/ terraform (push) Successful in 1m3s
/ ansible (push) Failing after 1m53s
It's older, and doesn't have `stream` compiled in, but the repo one can't link to any of the installed modules, which is a non-starter.
2024-01-04 14:17:36 +00:00
57ad143268
Set password for homeassistant SMB mount
Some checks failed
/ terraform (push) Successful in 38s
/ ansible (push) Failing after 1m40s
It had an IP restriction, but still
2024-01-03 21:23:49 +00:00
16e9952b2f
Replace custom restic logs with runitor 2024-01-03 21:09:07 +00:00
f5154d1683
Use CoreDNS to do recursive CNAME aliasing for AGH
Some checks failed
/ terraform (push) Successful in 47s
/ ansible (push) Failing after 1m38s
2024-01-02 17:48:47 +00:00
3ed7074af6
Rename coredns role 2024-01-02 17:02:34 +00:00
5581bbc01a
Replace pihole with adguardhome
All checks were successful
/ terraform (push) Successful in 1m13s
/ ansible (push) Successful in 2m19s
AGH is much simpler to install and manage, and does DoH natively.
2024-01-01 15:48:14 +00:00
56bfe544e4
nginx HTTPS redirect on ipv6 2023-12-31 22:49:11 +00:00
83543fe081
Update lscr.io/linuxserver/nextcloud Docker tag to v28.0.1
All checks were successful
/ terraform (push) Successful in 33s
/ ansible (push) Successful in 1m49s
2023-12-28 21:39:28 +00:00
0e0d0c9b82
walker doesn't have a traefik anymore
All checks were successful
/ terraform (push) Successful in 1m8s
/ ansible (push) Successful in 2m15s
2023-12-26 22:31:12 +00:00
026d8db13e
Be root when generating dhparams
All checks were successful
/ terraform (push) Successful in 37s
/ ansible (push) Successful in 1m50s
This is needed to write to the destination
2023-12-24 19:44:30 +00:00
593a945c5c
Install nginx from package manager if available 2023-12-24 19:44:30 +00:00
bd15946f3b
Update Nebula 2023-12-24 19:44:30 +00:00
f4b96afcfa
Deploy ntfy
All checks were successful
/ terraform (push) Successful in 1m15s
/ ansible (push) Successful in 2m22s
2023-12-23 16:40:53 +00:00
c0c7f393e3
Only pin to minor versions of gitea
All checks were successful
/ terraform (push) Successful in 32s
/ ansible (push) Successful in 1m48s
2023-12-21 16:43:18 +00:00
5fd952be4c
Only pin to minor version of Authentik 2023-12-21 16:42:02 +00:00
1e798ac5ce
Don't require role variables to be prefixed 2023-12-21 16:38:24 +00:00
39899cd1e0
Use certbot to issue certificates 2023-12-21 16:38:07 +00:00
8e1a203df2
Add helper map for better websocket support 2023-12-21 16:38:07 +00:00
a3baf8be1e
Use nginx as reverse proxy on walker, removing traefik
SSL coming soon
2023-12-21 16:38:07 +00:00
a7eb372899
Fix HTTPS redirect hostname 2023-12-21 14:58:19 +00:00
80a770f399
Add include files before main nginx config 2023-12-21 14:58:04 +00:00
ef432642dd
Unify nginx module tasks
Some checks failed
/ terraform (push) Successful in 1m8s
/ ansible (push) Failing after 2m0s
2023-12-20 22:35:11 +00:00
b32a63bd72
Add helpful includes
Along with ensuring there are dhparams
2023-12-20 22:29:42 +00:00
2336e4dd5b
Add brotli
All checks were successful
/ terraform (push) Successful in 1m5s
/ ansible (push) Successful in 2m19s
2023-12-17 18:12:33 +00:00
46eda36515
Fully block Server header
All checks were successful
/ terraform (push) Successful in 31s
/ ansible (push) Successful in 1m46s
2023-12-16 21:57:19 +00:00
cfb498d7c6
Only add HTTPS redirect when it's needed
All checks were successful
/ terraform (push) Successful in 1m3s
/ ansible (push) Successful in 2m7s
2023-12-16 18:13:49 +00:00
48efcf4d91
Use mainline nginx release on Arch 2023-12-16 18:03:01 +00:00
930cf87084
gzip as much as makes sense 2023-12-16 17:58:15 +00:00
92052a3d0a
Unify nginx configuration
This creates a simple base configuration skeleton, that other configuration can be easily loaded into.
2023-12-16 17:47:04 +00:00
943c141d59
Ensure ingress proxy doesn't terminate connections
All checks were successful
/ terraform (push) Successful in 1m6s
/ ansible (push) Successful in 2m16s
This mostly works around a weird issues with Jellyfin
2023-12-14 22:08:02 +00:00
2ff2128330
Set pihole temp unit 2023-12-14 22:04:14 +00:00
b33e19e152
Remove unnecessary extra variable definitions
The world could do with a bit less YAML!
2023-12-14 22:03:23 +00:00
7ad5d6e51e
Deploy coredns as a proxy to Docker's internal DNS 2023-12-14 21:04:26 +00:00
7381c1f10a
Update nextcloud version in config.php
All checks were successful
/ terraform (push) Successful in 27s
/ ansible (push) Successful in 1m41s
2023-12-13 17:48:46 +00:00
18fd0631e1 Update lscr.io/linuxserver/nextcloud Docker tag to v28
All checks were successful
/ terraform (push) Successful in 29s
/ ansible (push) Successful in 1m37s
2023-12-13 17:38:40 +00:00
05eee3f4de Update gitea/gitea Docker tag to v1.21.2
Some checks failed
/ terraform (push) Successful in 31s
/ ansible (push) Has been cancelled
2023-12-13 17:37:11 +00:00
e0f7b47961 Update lscr.io/linuxserver/mastodon Docker tag to v4.2.3
All checks were successful
/ terraform (push) Successful in 1m4s
/ ansible (push) Successful in 2m6s
2023-12-05 18:00:28 +00:00
c0df505f70
Disable browser updates for nextcloud
All checks were successful
/ terraform (push) Successful in 27s
/ ansible (push) Successful in 1m36s
2023-12-04 09:39:14 +00:00
aecd7c0a18
Upgrade nextcloud version in config 2023-12-04 09:38:43 +00:00
b9c5c7ce01 Update lscr.io/linuxserver/nextcloud Docker tag to v27.1.4
All checks were successful
/ terraform (push) Successful in 26s
/ ansible (push) Successful in 1m34s
2023-12-04 09:35:32 +00:00
e815fcb2be
Pin all redis versions to 7
All checks were successful
/ terraform (push) Successful in 28s
/ ansible (push) Successful in 1m34s
Keeps them all in sync
2023-12-04 09:22:51 +00:00
ad7bd24fec Update dependency ansible-lint to v6.22.1
All checks were successful
/ terraform (push) Successful in 25s
/ ansible (push) Successful in 2m38s
2023-12-04 09:10:46 +00:00
85352014ab Update matrixdotorg/synapse Docker tag to v1.97.0
Some checks failed
/ terraform (push) Successful in 27s
/ ansible (push) Has been cancelled
2023-12-04 09:09:07 +00:00
01eb469ac8 Update vabene1111/recipes Docker tag to v1.5.10
Some checks failed
/ terraform (push) Successful in 26s
/ ansible (push) Has been cancelled
2023-12-03 14:00:28 +00:00
461ec71b12
Update gitea branding path
All checks were successful
/ terraform (push) Successful in 32s
/ ansible (push) Successful in 1m46s
2023-11-27 19:19:58 +00:00
2fe093668d Update ghcr.io/goauthentik/server Docker tag to v2023.10.4
All checks were successful
/ terraform (push) Successful in 26s
/ ansible (push) Successful in 1m36s
2023-11-27 08:37:21 +00:00
58c14c7f94 Update vaultwarden/server Docker tag to v1.30.1
All checks were successful
/ terraform (push) Successful in 26s
/ ansible (push) Successful in 1m36s
2023-11-27 08:35:50 +00:00
d0a994198c Update gitea/gitea Docker tag to v1.21.1
All checks were successful
/ terraform (push) Successful in 1m4s
/ ansible (push) Successful in 2m7s
2023-11-26 18:00:27 +00:00
5e8918221f Update gitea/gitea Docker tag to v1.21.0
All checks were successful
/ terraform (push) Successful in 31s
/ ansible (push) Successful in 1m38s
2023-11-19 18:04:14 +00:00
0d970d276d Update matrixdotorg/synapse Docker tag to v1.96.1
All checks were successful
/ terraform (push) Successful in 31s
/ ansible (push) Successful in 1m37s
2023-11-19 17:59:53 +00:00
8666933bfb
Revert "Use OIDC to log in to tt-rss"
All checks were successful
/ terraform (push) Successful in 1m5s
/ ansible (push) Successful in 2m11s
OIDC breaks any kind of API integration, which is very annoying

This reverts commit 66ddef96e2.
2023-11-18 21:57:16 +00:00
3df1e1d46b
Update Nextcloud version in config.php
All checks were successful
/ terraform (push) Successful in 24s
/ ansible (push) Successful in 1m41s
2023-11-13 18:22:42 +00:00
e3da2710a7 Update lscr.io/linuxserver/nextcloud Docker tag to v27.1.3
All checks were successful
/ terraform (push) Successful in 28s
/ ansible (push) Successful in 1m39s
2023-11-13 18:22:06 +00:00
19febd9c35 Update matrixdotorg/synapse Docker tag to v1.95.1
All checks were successful
/ terraform (push) Successful in 29s
/ ansible (push) Successful in 1m41s
2023-11-13 18:19:38 +00:00
f0c0b6d4b4 Update vaultwarden/server Docker tag to v1.30.0
All checks were successful
/ terraform (push) Successful in 28s
/ ansible (push) Successful in 1m41s
2023-11-13 18:17:52 +00:00
d76ff190b3 Update dependency yamllint to v1.33.0
All checks were successful
/ terraform (push) Successful in 25s
/ ansible (push) Successful in 1m36s
2023-11-13 18:15:52 +00:00
a4958e619a Update ghcr.io/goauthentik/server Docker tag to v2023.10.3
All checks were successful
/ terraform (push) Successful in 28s
/ ansible (push) Successful in 1m45s
2023-11-13 18:15:28 +00:00
e4b2318c82
Monitor authentik
All checks were successful
/ terraform (push) Successful in 37s
/ ansible (push) Successful in 1m42s
2023-11-12 21:25:02 +00:00
dfef31cbfa
Deploy minio
My own S3, for various things
2023-11-12 21:23:54 +00:00
38840402b9
Disable repo units I don't use by default
All checks were successful
/ terraform (push) Successful in 31s
/ ansible (push) Successful in 1m41s
2023-11-12 18:28:01 +00:00
5f31a39804
Ensure Nextcloud can talk to local servers
All checks were successful
/ terraform (push) Successful in 30s
/ ansible (push) Successful in 1m40s
Needed for Authentik
2023-11-08 19:51:16 +00:00
66ddef96e2
Use OIDC to log in to tt-rss 2023-11-08 19:46:16 +00:00
935b099c4f
Decommission upload
All checks were successful
/ terraform (push) Successful in 30s
/ ansible (push) Successful in 1m38s
It was never really used for anything, and I want to replace it with something better eventually
2023-11-07 21:17:21 +00:00
dbbfe55975
Deploy authentik
_again_.
2023-11-07 21:17:21 +00:00
48dbaeed99
Deploy remark42
All checks were successful
/ terraform (push) Successful in 29s
/ ansible (push) Successful in 1m43s
To soon replace Commento
2023-11-06 21:29:28 +00:00
5fb605231d
Allow pings to ingress
All checks were successful
/ terraform (push) Successful in 33s
/ ansible (push) Successful in 1m50s
This makes testing connections much simpler
2023-11-05 21:48:25 +00:00
dd1558bafa
Set sensible permissions on nftables config 2023-11-05 21:43:16 +00:00
b0347fc037
Remove redundant quotes 2023-11-05 21:43:02 +00:00
64f5763571
Ensure nginx role is actually installed
Some checks failed
/ terraform (push) Successful in 33s
/ ansible (push) Failing after 1m36s
2023-11-05 21:37:33 +00:00
f1ac40f432
Reduce pihole cache size
Some checks failed
/ terraform (push) Successful in 1m9s
/ ansible (push) Failing after 2m11s
This is still a lot of records, and pihole complains with values any larger
2023-11-05 13:22:05 +00:00
850278ab19
Allow nebula through firewall
Some checks failed
/ terraform (push) Successful in 1m6s
/ ansible (push) Failing after 2m8s
2023-11-03 18:06:36 +00:00
b1284877a3
Update blackbox configuration for not following redirects
Some checks failed
/ terraform (push) Successful in 30s
/ ansible (push) Failing after 1m23s
2023-11-01 22:14:35 +00:00
6b4285a264
Let alertmanager run as its own user
It's already not-root, and can't access the filesystem anyway
2023-11-01 22:13:37 +00:00
3ed786336e
Remove wireguard_53
Some checks failed
/ terraform (push) Successful in 34s
/ ansible (push) Failing after 1m25s
I never used it - no reason to maintain it
2023-10-26 21:50:22 +01:00
9f83efa53b
Use nftables for firewall on ingress
See ya never, iptables!
2023-10-26 21:34:06 +01:00
54e2205e48
Don't bother renaming speedtest metrics
Some checks failed
/ terraform (push) Successful in 32s
/ ansible (push) Failing after 1m20s
2023-10-23 22:09:25 +01:00
c29dfb5ad2
Add hostname label for blackbox
Some checks failed
/ terraform (push) Successful in 37s
/ ansible (push) Failing after 1m22s
2023-10-23 21:06:43 +01:00
2bd22cb2f6 Update lscr.io/linuxserver/nextcloud Docker tag to v27.1.2
All checks were successful
/ terraform (push) Successful in 35s
/ ansible (push) Successful in 1m51s
2023-10-15 21:36:02 +01:00
a1d92ef080 Update lscr.io/linuxserver/mastodon Docker tag to v4.2.1
All checks were successful
/ ansible (push) Successful in 2m4s
/ terraform (push) Successful in 34s
2023-10-15 21:35:23 +01:00
70ad33189c Update gitea/gitea Docker tag to v1.20.5
All checks were successful
/ ansible (push) Successful in 2m13s
/ terraform (push) Successful in 28s
2023-10-15 21:34:29 +01:00
92914303ad Update matrixdotorg/synapse Docker tag to v1.94.0
All checks were successful
/ terraform (push) Successful in 46s
/ ansible (push) Successful in 2m21s
2023-10-15 21:33:22 +01:00
a1a61f1069 Update wallabag/wallabag Docker tag to v2.6.7
All checks were successful
/ terraform (push) Successful in 30s
/ ansible (push) Successful in 2m6s
2023-10-15 21:32:01 +01:00
4950082c28
Remove deprecated gitea config settings
All checks were successful
/ terraform (push) Successful in 1m13s
/ ansible (push) Successful in 2m20s
2023-10-15 21:27:23 +01:00
ad867f9654
Add JWT secret for gitea
This appeared in my config - it's probably important
2023-10-15 18:55:24 +01:00
ad3b5bc42d
Move repo archive to "files" subvolume
It's better suited for this kind of file storage
2023-10-15 18:53:30 +01:00
37b8c48a77
Remove legacy short domains
All checks were successful
/ terraform (push) Successful in 1m24s
/ ansible (push) Successful in 2m47s
I never used them, and the certificate renewal didn't work anyway.
2023-10-02 09:37:05 +01:00
54c88d4253
Fix lint issues
All checks were successful
/ terraform (push) Successful in 42s
/ ansible (push) Successful in 1m56s
2023-10-01 17:10:37 +01:00
5770ab4a59
Sync dokku data to tank
This is much easier than mounting the files themselves
2023-10-01 17:06:09 +01:00
3b303e4940
Deploy db-auto-backup to dokku
It might have DBs somewhen
2023-10-01 16:47:06 +01:00
a54a91ea44
Deploy a dokku 2023-10-01 16:34:01 +01:00
b02be4e77a
Add email to Vikunja
Some checks failed
/ terraform (push) Successful in 1m26s
/ ansible (push) Failing after 2m48s
2023-10-01 14:08:25 +01:00
28a5089190
Bootstrap a new dokku machine on PVE
Some checks failed
/ terraform (push) Successful in 41s
/ ansible (push) Failing after 2m3s
2023-09-29 22:03:23 +01:00
12c46e50b5
Decommission grimes
All checks were successful
/ terraform (push) Successful in 41s
/ ansible (push) Successful in 2m10s
Dokku will return, soon...
2023-09-29 21:42:05 +01:00
90c9164306 Update renovate/renovate Docker tag to v37
All checks were successful
/ terraform (push) Successful in 42s
/ ansible (push) Successful in 1m56s
2023-09-27 16:00:37 +01:00
a1285612f1
Increase pihole cache
Some checks failed
/ terraform (push) Failing after 2m46s
/ ansible (push) Successful in 3m45s
2023-09-24 13:45:40 +01:00
1801a21e5d
Update nextcloud config to 27.1.1
All checks were successful
/ terraform (push) Successful in 50s
/ ansible (push) Successful in 2m7s
2023-09-23 21:51:15 +01:00
60d6be41ab Update lscr.io/linuxserver/nextcloud Docker tag to v27.1.1
All checks were successful
/ terraform (push) Successful in 52s
/ ansible (push) Successful in 2m8s
2023-09-23 21:42:32 +01:00
5c247013fb Update lscr.io/linuxserver/mastodon Docker tag to v4.2.0
All checks were successful
/ terraform (push) Successful in 55s
/ ansible (push) Successful in 2m9s
2023-09-23 21:40:04 +01:00
ea33feb643 Update matrixdotorg/synapse Docker tag to v1.92.3
All checks were successful
/ terraform (push) Successful in 1m35s
/ ansible (push) Successful in 2m44s
2023-09-23 13:57:28 +01:00
7de73287fd
Move spotify proxy alongside website
All checks were successful
/ ansible (push) Successful in 2m25s
/ terraform (push) Successful in 1m3s
That's all it's really used for right now.
2023-09-21 14:20:54 +01:00
27da7a7494
Fix occ command
All checks were successful
/ terraform (push) Successful in 57s
/ ansible (push) Successful in 2m16s
2023-09-18 19:21:42 +01:00
0789abaa0b
Update nextcloud config version 2023-09-18 18:49:04 +01:00
c2989aad5c Update lscr.io/linuxserver/nextcloud Docker tag to v27.1.0
All checks were successful
/ terraform (push) Successful in 1m2s
/ ansible (push) Successful in 2m8s
2023-09-18 18:35:09 +01:00
61088d18f6 Update matrixdotorg/synapse Docker tag to v1.92.2
All checks were successful
/ terraform (push) Successful in 1m49s
/ ansible (push) Successful in 3m7s
2023-09-15 16:00:30 +01:00
5419e173d5 Update matrixdotorg/synapse Docker tag to v1.91.2
All checks were successful
/ terraform (push) Successful in 47s
/ ansible (push) Successful in 2m19s
2023-09-10 21:02:18 +01:00
d9a50cce64 Update lscr.io/linuxserver/mastodon Docker tag to v4.1.7
All checks were successful
/ terraform (push) Successful in 47s
/ ansible (push) Successful in 2m29s
2023-09-10 21:01:50 +01:00
2303f7b247 Update wallabag/wallabag Docker tag to v2.6.6
All checks were successful
/ terraform (push) Successful in 56s
/ ansible (push) Successful in 2m46s
2023-09-10 21:00:55 +01:00
3deda7bde7 Update gitea/gitea Docker tag to v1.20.4
All checks were successful
/ terraform (push) Successful in 1m27s
/ ansible (push) Successful in 3m28s
2023-09-08 10:00:33 +01:00
e56ffa576f
Deploy vikunja
All checks were successful
/ terraform (push) Successful in 1m2s
/ ansible (push) Successful in 2m32s
2023-09-07 20:18:32 +01:00
d16feb2f89
Override DNS for vaultwarden
All checks were successful
/ terraform (push) Successful in 46s
/ ansible (push) Successful in 2m13s
Make sure it finds icons for local applications
2023-09-07 18:04:03 +01:00
bdf48295a6 Update matrixdotorg/synapse Docker tag to v1.91.0
All checks were successful
/ terraform (push) Successful in 50s
/ ansible (push) Successful in 2m20s
2023-09-03 21:17:27 +01:00
9644a09021 Update vabene1111/recipes Docker tag to v1.5.6
All checks were successful
/ terraform (push) Successful in 46s
/ ansible (push) Successful in 2m11s
2023-09-03 21:09:24 +01:00
d120274b00 Update vaultwarden/server Docker tag to v1.29.2
All checks were successful
/ terraform (push) Successful in 1m29s
/ ansible (push) Successful in 2m56s
2023-09-03 21:06:33 +01:00
5a0df92a6a
Disable ip_forward
All checks were successful
/ terraform (push) Successful in 1m4s
/ ansible (push) Successful in 2m20s
I don't need P2P comms for this, so disable this for extra security.

I should add a proper firewall at some point...
2023-09-01 19:52:36 +01:00
ccadc7fbfa
Migrate wallabag to postgres
All checks were successful
/ terraform (push) Successful in 1m20s
/ ansible (push) Successful in 2m36s
2023-08-28 19:10:37 +01:00
2b75b526ac
Update nextcloud version in config 2023-08-28 17:53:29 +01:00
16be8dd87c
Disable registration on wallabag
The documented default is wrong
2023-08-28 17:51:58 +01:00
33b7921067
Update lscr.io/linuxserver/nextcloud Docker tag to v27.0.2 2023-08-28 17:15:41 +01:00
8208845738 Update vabene1111/recipes Docker tag to v1.5.5
All checks were successful
/ terraform (push) Successful in 1m5s
/ ansible (push) Successful in 2m41s
2023-08-28 16:53:56 +01:00
444fa61436 Update wallabag/wallabag Docker tag to v2.6.5
All checks were successful
/ ansible (push) Successful in 2m53s
/ terraform (push) Successful in 3m1s
2023-08-28 10:00:28 +01:00
84678087d1 Update dependency geerlingguy.docker to v6.2.0
All checks were successful
/ terraform (push) Successful in 40s
/ ansible (push) Successful in 1m51s
2023-08-20 22:16:19 +01:00
283bb3f11f Update gitea/gitea Docker tag to v1.20.3
All checks were successful
/ terraform (push) Successful in 42s
/ ansible (push) Successful in 1m58s
2023-08-20 22:00:28 +01:00
f7d8a237dd Update dependency geerlingguy.ntp to v2.3.3
All checks were successful
/ terraform (push) Successful in 47s
/ ansible (push) Successful in 1m52s
2023-08-17 08:00:29 +01:00
266601d6f5
Vaguely harden vaultwarden config
All checks were successful
/ terraform (push) Successful in 45s
/ ansible (push) Successful in 2m8s
2023-08-16 22:03:22 +01:00
1b24578fe6 Update plausible/analytics Docker tag to v2
All checks were successful
/ terraform (push) Successful in 41s
/ ansible (push) Successful in 1m50s
2023-08-05 16:25:55 +01:00
82281c6307
Decommission BG
All checks were successful
/ ansible (push) Successful in 1m52s
/ terraform (push) Successful in 46s
2023-08-01 21:49:20 +01:00
ce53032819
Fix nextcloud config dir
Some checks failed
/ terraform (push) Failing after 5s
/ ansible (push) Failing after 5s
2023-08-01 21:19:35 +01:00
b499882ca7
Update Nextcloud to 27.0.1 2023-08-01 21:18:50 +01:00
6d8d65a136 Update gitea/gitea Docker tag to v1.20.2
Some checks failed
/ terraform (push) Failing after 5s
/ ansible (push) Failing after 5s
2023-08-01 14:36:12 +01:00
e5a246d24a Update vaultwarden/server Docker tag to v1.29.1
Some checks failed
/ terraform (push) Failing after 5s
/ ansible (push) Failing after 5s
2023-08-01 14:34:54 +01:00
65f54326f3 Update wallabag/wallabag Docker tag to v2.6.2
Some checks failed
/ terraform (push) Failing after 5s
/ ansible (push) Failing after 4s
2023-08-01 14:32:46 +01:00
426c8f4e40 Update matrixdotorg/synapse Docker tag to v1.89.0
Some checks failed
/ terraform (push) Failing after 5s
/ ansible (push) Failing after 5s
2023-08-01 14:32:02 +01:00
463f5228e4 Update lscr.io/linuxserver/mastodon Docker tag to v4.1.6
Some checks failed
/ terraform (push) Failing after 5s
/ ansible (push) Failing after 6s
2023-08-01 14:30:07 +01:00
dfa6ffdcd2
Update Gitea token for renovate
Some checks failed
/ terraform (push) Failing after 5s
/ ansible (push) Failing after 5s
It seems in a recent update, the token stopped working, possibly due to a permissions issue.
2023-08-01 14:17:16 +01:00
6224b8f675
Remove aurto
All checks were successful
/ terraform (push) Successful in 47s
/ ansible (push) Successful in 2m0s
I never used it, and trust chaotic-aur enough for AUR things
2023-07-30 19:09:34 +01:00
f5faad1b2d
Upgrade Gitea to 1.20.1
All checks were successful
/ terraform (push) Successful in 1m22s
/ ansible (push) Successful in 2m25s
2023-07-22 14:30:49 +01:00
a1d8764a90
Expose tt-rss plugins to nginx container
All checks were successful
/ terraform (push) Successful in 46s
/ ansible (push) Successful in 2m2s
2023-07-21 12:57:01 +01:00
5aff824389
Remove feediron plugin
All checks were successful
/ terraform (push) Successful in 1m21s
/ ansible (push) Successful in 2m40s
It causes lots of issues for GitHub feeds
2023-07-21 09:13:24 +01:00
4de69e3955
Rotate Gandi API key
All checks were successful
/ terraform (push) Successful in 41s
/ ansible (push) Successful in 1m53s
Had to regenerate it to debug an issue
2023-07-17 15:03:04 +01:00
0e9e63d8b7
Use correct gandi API 2023-07-17 15:03:04 +01:00
9e7ccb81ec
Fix external storage for gitea packages 2023-07-17 14:26:12 +01:00
2e7d60d87d
Use gandi as cert resolver for 0rng.one 2023-07-17 14:26:12 +01:00
d91ad7c517
Update gitea to 1.20.0
All checks were successful
/ terraform (push) Successful in 1m27s
/ ansible (push) Successful in 2m49s
2023-07-17 09:30:33 +01:00
a406e72ab2
Update Vaultwarden to 1.29.0
All checks were successful
/ terraform (push) Successful in 41s
/ ansible (push) Successful in 1m54s
2023-07-10 13:41:56 +01:00
56c1f8563f
Fix renovate base directory
All checks were successful
/ terraform (push) Successful in 1m41s
/ ansible (push) Successful in 2m23s
2023-07-10 08:33:30 +01:00
1acc8b3fd6
Mount entire config dir into Nextcloud
All checks were successful
/ terraform (push) Successful in 40s
/ ansible (push) Successful in 1m50s
Seems newer LSIO containers try and copy a config over the top, which doesn't play well with it being a Docker mount
2023-07-09 16:17:55 +01:00
cb2ed2dd62 Update renovate/renovate Docker tag to v36
All checks were successful
/ terraform (push) Successful in 40s
/ ansible (push) Successful in 1m50s
2023-07-09 12:57:05 +01:00
f037a393e4 Update vabene1111/recipes Docker tag to v1.5.4
All checks were successful
/ terraform (push) Successful in 41s
/ ansible (push) Successful in 2m5s
2023-07-09 12:56:45 +01:00
29f7c55b6b Update lscr.io/linuxserver/mastodon Docker tag to v4.1.4
All checks were successful
/ terraform (push) Successful in 1m25s
/ ansible (push) Successful in 2m37s
2023-07-07 22:00:36 +01:00
8ff2cbce90 Update dependency geerlingguy.ntp to v2.3.2
All checks were successful
/ terraform (push) Successful in 3m35s
/ ansible (push) Successful in 1m52s
2023-07-04 21:33:48 +01:00
56b846f38c
Prune mastodon accounts and orphan media
All checks were successful
/ terraform (push) Successful in 40s
/ ansible (push) Successful in 1m49s
2023-07-04 21:19:35 +01:00
b7d90cee98 Update matrixdotorg/synapse Docker tag to v1.87.0
All checks were successful
/ terraform (push) Successful in 43s
/ ansible (push) Successful in 1m51s
2023-07-04 21:18:11 +01:00
6d83becaaf Update wallabag/wallabag Docker tag to v2.6.1
All checks were successful
/ terraform (push) Successful in 40s
/ ansible (push) Successful in 1m43s
2023-07-04 21:10:41 +01:00
f04e61543c Update vabene1111/recipes Docker tag to v1.5.3
All checks were successful
/ terraform (push) Successful in 38s
/ ansible (push) Successful in 1m55s
2023-07-04 21:10:10 +01:00
c558a8d86d Update gitea/gitea Docker tag to v1.19.4
All checks were successful
/ ansible (push) Successful in 1m55s
/ terraform (push) Successful in 38s
2023-07-04 20:00:29 +01:00
1f6460f610 Update vabene1111/recipes Docker tag to v1.5.2
All checks were successful
/ terraform (push) Successful in 54s
/ ansible (push) Successful in 2m0s
2023-06-26 09:43:32 +01:00
7619e826f4
Remove deprecated traefik hub config
All checks were successful
/ terraform (push) Successful in 1m27s
/ ansible (push) Successful in 2m31s
2023-06-26 09:27:16 +01:00
decfbf65c9
Move scripts to justfile 2023-06-18 17:14:49 +01:00
983c3adca1
Move backups out of DB directory
All checks were successful
/ terraform (push) Successful in 46s
/ ansible (push) Successful in 1m39s
I've now increased the compression and record size
2023-06-17 16:37:07 +01:00
da55e3fb5f
Fix references to home dir
All checks were successful
/ terraform (push) Successful in 47s
/ ansible (push) Successful in 1m46s
2023-06-17 16:00:30 +01:00
677c70618f
Update Nextcloud to 27 2023-06-17 16:00:17 +01:00
4d3aa3d67c Update matrixdotorg/synapse Docker tag to v1.85.2
All checks were successful
/ terraform (push) Successful in 1m22s
/ ansible (push) Successful in 2m14s
2023-06-17 15:42:23 +01:00
b07d424d87
Move remaining DBs to SSD
All checks were successful
/ ansible (push) Successful in 1m43s
/ terraform (push) Successful in 42s
2023-06-15 21:18:50 +01:00
2af9f8529d
Fix new ansible-lint errors
All checks were successful
/ terraform (push) Successful in 46s
/ ansible (push) Successful in 1m53s
Quite a few changes here, hopefully they work!
2023-06-15 15:16:19 +01:00
2a0d40aca9
Only pass vault pass when deploying
This makes linting much simpler
2023-06-15 14:45:09 +01:00
c27043269c
Fix excluded paths for ansible lint
We `cd` into the `ansible/` directory, so they should be relative to that
2023-06-15 14:26:19 +01:00
aa8ceec290
Remove duplicate depends_on keys
Some checks failed
/ terraform (push) Successful in 48s
/ ansible (push) Failing after 2m13s
2023-06-15 14:20:52 +01:00
cdbdca1fb8
Update dev dependencies to support newer Ansible versions 2023-06-15 14:17:16 +01:00
5ccaaefdc7
Move more projects over to new "speed" SSD
Some checks failed
/ terraform (push) Successful in 49s
/ ansible (push) Failing after 1m28s
2023-06-15 13:55:36 +01:00
2998958ddd
Provision a new SSD for DBs
Some checks failed
/ terraform (push) Successful in 1m16s
/ ansible (push) Failing after 1m57s
This makes the data easier to back up and splits it out from the main boot pool
2023-06-15 09:09:48 +01:00