Commit graph

19 commits

Author SHA1 Message Date
8709321ca3 heather: install jitsi meet from scratch (web/prosody/jicofo/jvb)
Fresh install per https://jitsi.github.io/handbook/docs/devops-guide/devops-guide-docker
- Images on GHCR: ghcr.io/jitsi/*:stable-11031
- Named volumes: jitsi-{web,prosody,jicofo,jvb,transcripts}
- Network meet-jitsi (bridge) with prosody alias xmpp.meet.jitsi
- Reverse proxy mode (DISABLE_HTTPS=1), Caddy terminates TLS
- Internal auth (ENABLE_AUTH=1, AUTH_TYPE=internal)
- JVB_ADVERTISE_IPS=51.250.45.111, :10000/udp public
- Secrets NEW in /var/lib/jitsi-secrets/jitsi.env (root:docker 0640):
  JICOFO_COMPONENT_SECRET, JICOFO_AUTH_PASSWORD, JVB_AUTH_PASSWORD
- Caddy vhost jitsi.iscg.dev with /xmpp-websocket + /colibri-ws upgrade routes
- Firewall: 10000/udp (jvb). Coturn not included (optional, add later for NAT)
- No jigasi/jibri/transcriber (minimal stack)
2026-07-12 22:42:36 +03:00
fd605c51ce heather: remove jitsi stack (web/prosody/jicofo/jvb/coturn)
Fully remove jitsi from arion-compose.nix, caddy.nix, default.nix.
Will be reinstalled from scratch.
2026-07-12 22:35:03 +03:00
57f2fe314b heather: jitsi — fix networks to top-level + meet-jitsi (no dots) 2026-07-12 22:12:33 +03:00
2d37b744e6 heather: jitsi — networks is top-level option (not docker-compose.networks)
Arion: `networks` — top-level опция как `services`, не внутри docker-compose.
service.networks принимает listOf str или attrsOf с aliases. meet.jitsi → meet-jitsi
(имя без точки, docker-compose требование к network names).
2026-07-12 22:08:34 +03:00
b697744a46 heather: jitsi — add meet.jitsi network with prosody alias xmpp.meet.jitsi
Jicofo/jvb/web ищут prosody по FQDN xmpp.meet.jitsi (default docker-jitsi).
Custom bridge network даёт prosody DNS alias. Coturn в host network — вне.
2026-07-12 22:01:19 +03:00
ee8ce3f99f heather: enable jitsi meet stack (jitsi.iscg.dev)
Стек: web + prosody + jicofo + jvb + coturn. Перенесено с jul11 (2026-07-12):
- config (web/prosody/jicofo/jvb) → named volumes heather_jitsi-{web,prosody,jicofo,jvb,transcripts}
- prosody user mikl.dat сохранён (internal auth)
- образ PIN: stable-11031 (как на jul11, НЕ :latest)
- пароли (jicofo/jvb/jigasi/jibri/turn) НОВЫЕ, в pass iscg.dev/jitsi/
- env-файл /var/lib/jitsi-secrets/jitsi.env (root:docker 0640)
- coturn в host network (real client IPs), realm=turn.iscg.dev
- JVB 10000/udp публично (YC SG уже ANY ANY open)
- Caddy: WebSocket routes /xmpp-websocket, /colibri-ws (hop-by-hop upgrade)
- DISABLE_HTTPS=1 (Caddy терминирует TLS)
2026-07-12 21:56:37 +03:00
cc6ef61d0a heather: pin teable to working image digest, revert port to 3000
:latest (release 2198, 2026-07-11) сломал роутинг: Next.js отдаёт 404
на / и /health, assets под /plugin/. Пиним digest из iscg-dev (март 2026)
где / → 307 → /space работает. Старый образ слушает 3000 (не 3002).
2026-07-12 20:46:53 +03:00
c079adba66 heather: teable listens on 3002, fix port mapping 2026-07-12 20:16:22 +03:00
3e3241683f heather: enable teable stack (teable.iscg.dev)
app + postgres:15 + redis. Данные перенесены с iscg-dev (2026-07-12):
- postgres восстановлен из pg_dump (18M) с новым паролем
- .assets (3.2G, 4392 файлов) в named volume heather_teable-assets
- teable-data, redis пустые (наполнятся при старте)

Секреты (POSTGRES_PASSWORD, SECRET_KEY, PRISMA_DATABASE_URL) новые,
в pass iscg.dev/teable/. env-файл /var/lib/teable-secrets/teable.env
на heather (вне git, root:docker 0640).
2026-07-12 20:09:15 +03:00
260a6c64bf heather: enable silverbullet (note.iscg.dev)
Bind mount /srv/syncthing/herbarium → /space. Данные перенесены с iscg-dev
(564K, 41 файл). Auth-файл .silverbullet.auth.json в составе данных.
SB_USER/SB_INDEX_PAGE из старого compose на iscg-dev.
2026-07-12 18:51:11 +03:00
e99b6e1c28 heather: fix syncthing host-check error behind Caddy reverse proxy
Syncthing отдаёт 403 'Host check error' когда Host header не совпадает с
адресом прослушивания (127.0.0.1:8384) — это DNS rebinding protection.
Caddy подменяет Host на бэкенде через header_up Host 127.0.0.1:8384.
2026-07-12 18:19:22 +03:00
483454bf17 heather: rotate sync.iscg.dev basicauth password
Старый хеш был скопирован с iscg-dev, пароль неизвестен. Новый пароль
в mindful-стиле. Сгенерирован через caddy hash-password (bcrypt cost 14).
2026-07-12 18:05:22 +03:00
6324d3b676 heather: make strelaysrv private (pools="")
Relay больше не регистрируется в public pool relays.syncthing.net.
Чужие syncthing-устройства не подключаются, трафик не возим.
Свои устройства могут использовать relay://heather:22067 если прописан в config.
2026-07-12 17:55:52 +03:00
4eb5a1e61c heather: switch caddy to production ACME (DNS moved to heather) 2026-07-12 13:21:25 +03:00
ebf74814bf heather: fix arion volumes declaration + syncthing configDir perms
- arion-compose: project.name (required) + docker-compose.volumes (correct
  option, was docker-compose.raw.volumes which didn't exist)
- syncthing: tmpfiles for /var/lib/syncthing (configDir) owned by mikl,
  fixes 'mkdir /var/lib/syncthing: permission denied' when running as non-default user
2026-07-12 12:39:26 +03:00
220d1f651c heather: replace k3s with docker+arion+caddy+syncthing
- remove k3s.nix (1.3GB overhead unjustified for single-node)
- add docker.nix (docker + arion CLI, mikl in docker group)
- add caddy.nix (edge proxy, TLS via ACME staging, host-based routing)
- add syncthing.nix (sync daemon + strelaysrv via systemd, /srv/syncthing)
- add arion-compose.nix (forgejo first, others stubbed as TODO)
- add arion flake input + nixos module
- default.nix: wire up arion project as systemd service (serviceName=heather)

Architecture: Caddy (host) terminates TLS, routes to host services (syncthing)
and docker containers (arion, 127.0.0.1:PORT). Named volumes everywhere except
silverbullet (bind /srv/syncthing/herbarium).
2026-07-12 12:23:05 +03:00
2cbca9a665 heather: add root rescue ssh key (mikl.keys) to avoid lockout 2026-07-11 22:57:29 +03:00
411a8ba689 heather/common: passwordless sudo for mikl + fix deprecated options
- common/default.nix: add mikl to wheel + security.sudo.wheelNeedsPassword=false.
  Without this, root is unreachable on a fresh NixOS-yc image (no root password,
  no rescue channel) — nixos-rebuild switch is impossible. Mirrors the
  NOPASSWD:ALL that old YC boxes got via cloud-config user-data.
- home/server.nix: programs.git.extraConfig -> .settings, programs.git.delta
  -> programs.delta with enableGitIntegration=true (deprecated warnings).
- image.nix: boot.loader.grub.timeout -> boot.loader.timeout (renamed option).
2026-07-11 22:55:00 +03:00
79260cec6f heather: switch to make-disk-image (qcow2 for YC), drop disko
- Rename muscari -> heather (YC VM). rosemary reserved for future EU server.
- Add hosts/heather/image.nix: YC guest profile + qcow2 build target based on
  nixos/lib/make-disk-image.nix (the nixpkgs-standard cloud image builder).
  partitionTableType=legacy (MBR + single ext4 root, label nixos), GRUB in MBR
  on /dev/vda, virtio drivers, console=ttyS0, cloud-init (Ec2 datasource) so
  poppy ssh key auto-lands from YC metadata, growPartition.
- Drop disko flake input + disk-config.nix (was only for nixos-anywhere runtime
  install; replaced by make-disk-image build-time approach, no kexec).
- Add home/server.nix: minimal headless home for NixOS hosts (no ollama/
  texliveFull/kitty/syncthing/pass). flake mkNixos uses it instead of full ./home.
- k3s.nix: drop dead firewall block (firewall off in image.nix -> trustedInterfaces
  was a no-op). Cilium manages pod networking via BPF.
- image.baseName=heather, configurationLimit=1, remove virtio dups (qemu-guest
  profile already provides most).
- Fix sha256 pin on forgejo mikl.keys (was stale, would break fetchurl).
- home/zsh.nix: source yandex-cloud yc completion.
2026-07-11 21:13:38 +03:00