Commit Graph
100 Commits
Author SHA1 Message Date
Râu Cao 9648e071ca Configure akkounts for Discourse Connect 2023-06-04 15:24:06 +03:00
Râu Cao 807ca52f1c Upgrade LND to 0.16.1 2023-04-26 15:05:17 +02:00
Râu Cao 78eb3c033a Upgrade golang to 1.20.3 2023-04-26 15:05:06 +02:00
Râu Cao efb07ad3c1 Allow akkounts to set private XML storage data
Enables kosmos/akkounts#116
2023-04-19 17:32:30 +02:00
Râu Cao 14e04d77a9 Activate real-time MUC blocklist module 2023-04-19 17:32:15 +02:00
Râu Cao f8f3fc7c3a Upgrade ejabberd to 23.04
Also add a package version attribute, since the value changed in the
past.
2023-04-19 17:30:55 +02:00
Râu Cao 5ad15ba1f3 Upgrade Gitea to 1.19.1 2023-04-13 18:31:42 +02:00
Râu Cao 1afc860b21 Fix Gitea Actions runner not working with private host 2023-04-11 12:14:17 +02:00
Râu Cao 03a02a19c4 Use proxy protocol for ejabberd nginx streams 2023-04-04 15:14:41 +02:00
Râu Cao 7a1be33b7a Make all nginx vhosts listen on IPv6 2023-04-04 15:10:23 +02:00
Râu Cao f36268e906 Update ejabberd admin list 2023-04-04 10:14:50 +02:00
Râu Cao 2dd4d572a6 Configure akkounts domain 2023-04-04 09:32:40 +02:00
Râu Cao 797dd241e0 Improve ejabberd HTTP API configs and access
Move the listener to a separate endpoint on port 80, which is only
accessible from the private network. Change accounts.kosmos.org to use
the new endpoint via a `.local` domain instead of faking external
access.
2023-04-03 15:38:40 +02:00
Râu Cao 059812524e Set up Gitea Actions runners 2023-04-01 12:56:21 +02:00
Râu Cao 702449acc1 Upgrade Gitea to 1.19.0, enable Actions 2023-03-28 19:36:30 +02:00
Râu Cao b78de9a3c9 Deploy Sentry from release tag 2023-03-28 15:23:57 +02:00
Râu Cao 99d985c0d5 Configure Sentry for akkounts 2023-03-27 19:10:48 +02:00
Râu Cao 9f886cc286 Configure Sentry DSN for lndhub-go 2023-03-27 19:04:03 +02:00
Râu Cao 05d0a19b5f Add Sentry client recipe and role
Configures a local domain for Sentry in the hostsfile.
2023-03-27 19:04:03 +02:00
Râu Cao 798ee3d1d8 Basic Sentry setup
Not running the install script automatically at this point yet.
2023-03-27 19:03:58 +02:00
Râu Cao 6e31c7a79b Use proxy protocol 2023-03-24 16:35:23 +07:00
Râu Cao a2fc3ba25c Remove obsolete folder permissions 2023-03-24 16:35:07 +07:00
Râu Cao 13fc2e6e24 Improve MUC config 2023-03-24 16:34:40 +07:00
Râu Cao f34647b2bd Fix akkounts asset requests when nginx is on proxy 2023-03-17 19:29:24 +07:00
Râu Cao 8ae7cdfafd Switch Discourse uploads and backups to Garage/S3 2023-03-17 19:13:04 +07:00
Râu Cao d8d1609572 Serve static assets from Rails in prod 2023-03-04 11:14:11 +08:00
Râu Cao cf082833a7 Add lndhub pubkey in prod, update node config 2023-03-03 21:48:38 +08:00
Râu Cao 8225e1b67b Move akkounts nginx to nginx proxy 2023-03-02 18:05:37 +08:00
Râu Cao 9d1dd499bb Upgrade BTCPay Server to 1.8.0
* Fixed build and run scripts
  https://github.com/btcpayserver/btcpayserver/pull/4655
* Fixed bug when using LndHub account as Lightning back-end
  https://github.com/btcpayserver/btcpayserver/issues/4658
2023-03-02 15:31:47 +08:00
Râu Cao 53f8a06e6f Add keysend support for Lightning Address 2023-03-02 13:32:07 +08:00
Râu Cao a1ec9b4d6a Write akkounts .env config, add config for lndhub admin UI
closes #462
2023-02-13 22:39:11 +08:00
Râu Cao b762d70b43 Use service resource 2023-02-11 17:22:22 +08:00
Râu Cao 99e029a5ca Switch NBXplorer to Postgres 2023-02-08 15:30:44 +08:00
Râu Cao 4c7a5f4db8 Upgrade bitcoind, NBXplorer, BTCPayServer 2023-02-03 17:04:16 +08:00
Râu Cao 5e709a3a4f Update node configs 2023-02-01 21:53:50 +08:00
Râu Cao d04e2f4fd5 Bump cookbook version 2023-02-01 20:45:01 +08:00
Râu Cao f9e7d98bf9 Document testing commands 2023-02-01 20:44:45 +08:00
Râu Cao 9c33fbda21 Bump rskj version 2023-02-01 20:44:07 +08:00
Râu Cao a7b990c64f Update preseed syntax 2023-02-01 20:43:41 +08:00
Râu Cao 55e48cca86 Include nginx cookbook in local deps (for testing) 2023-02-01 20:43:07 +08:00
Râu Cao 063858f06c Install imagemagick for mediawiki thumbnail generation 2023-02-01 18:17:39 +08:00
Râu Cao cd4d21efc8 Remove superfluous license header 2023-02-01 18:17:29 +08:00
Râu Cao ad10e8cceb Fix up lndhub hook config, converge all relevant nodes 2023-01-25 13:02:09 +08:00
Râu Cao 3e79955261 Deploy akkounts from master again 2023-01-25 12:31:17 +08:00
Râu Cao d3d046b0d0 Merge branch 'feature/libretranslate' 2023-01-25 12:28:33 +08:00
Râu Cao 03fa49ed0c Remove unused import 2023-01-17 17:15:16 +08:00
Râu Cao ed0e030106 Set up libretranslate for kosmos.social 2023-01-17 17:12:22 +08:00
Râu Cao 3933e4c310 Fix endpoint URL 2023-01-17 15:36:42 +08:00
Râu Cao f777af22b8 Finish up Garage S3 config for kosmos.social 2023-01-14 15:59:47 +08:00
Râu Cao 345ba14f0e Add garage S3 config for Mastodon 2023-01-14 15:03:38 +08:00
Râu Cao 89865bcd2a Allow send_message endpoint from akkounts 2023-01-12 15:37:08 +08:00
Râu Cao 62d1a86555 Configure Webhook URL for lndhub.go 2023-01-12 15:37:04 +08:00
Râu Cao 2eb0544ea9 Update README 2023-01-05 17:14:46 +08:00
Râu Cao e54112418e Upgrade Gitea 1.18.0
Requires some config changes for the mailer.
2022-12-30 23:05:40 +07:00
Râu Cao 176dd64438 Remove peerswap policy file from recipe
This will be auto-created anyway, and we don't want to overwrite changes
added by the CLI.
2022-12-26 11:29:17 +07:00
Râu Cao 4f1b1aff30 Set up PeerSwap
Allows to swap sats in and out of Lightning channels without a 3rd party
(and their fees). Instead, swaps can be initiated directly with the
channel peer.

https://www.peerswap.dev/
2022-12-26 11:16:22 +07:00
Râu Cao b3465e186f Fix comment 2022-12-26 11:16:01 +07:00
Râu Cao ea635a52e9 Formatting 2022-12-26 11:14:40 +07:00
Râu Cao 90e17b0abc Rename bitcoind recipe
Was still using a name from when the cookbook didn't set up anything
else
2022-12-25 16:28:14 +07:00
Râu Cao 8c8e978ae9 Update node configs 2022-12-24 00:58:31 +07:00
Râu Cao 3d7b4df376 Add rate limit config for lndhub-go 2022-12-24 00:58:11 +07:00
Râu Cao b738dc1e80 Add nginx proxy hosts for Garage Web access
The respective bucket needs to be configured with a domain alias. When a
new alias is added to the `s3_web_domains` config, a new nginx site can
then be deployed to the `nginx_proxy` hosts.
2022-12-23 18:07:39 +07:00
Râu Cao 3641ea7a60 Deploy lndhub.go branch of akkounts 2022-12-23 18:02:42 +07:00
Râu Cao a7e04f4e63 Exclude lndhub backups in dev 2022-12-23 14:17:43 +07:00
Râu Cao e0c400c007 Use correct asset URL for lndhub logo 2022-12-22 20:03:58 +07:00
Râu Cao 7802ea25e6 Ignore chef environment when looking up primary
We use mixed environments still, not everything is in "production" yet.
2022-12-22 19:45:45 +07:00
Râu Cao fb1206d03f Refactor bitcoin-related roles and node config 2022-12-22 19:35:41 +07:00
Râu Cao 379a503dd0 Move lndhub nginx site to proxy
And configure for lndhub-go. Also configure branding for public lndhub
dashboard
2022-12-22 19:35:30 +07:00
Râu Cao 7d11450c4e Set up lndhub.go
closes #454
2022-12-11 14:30:27 +01:00
Râu Cao a460302728 Add missing sidekiq queue 2022-12-01 17:08:17 +01:00
Râu Cao 2ecb4e2385 Upgrade Ruby to 3.0.4 2022-12-01 15:29:38 +01:00
Râu Cao cdd3f026c4 Always use config for skipping post-deployment migrations 2022-12-01 15:05:24 +01:00
Râu Cao 5d05d5c187 Move Mastodon nginx to proxy/LB 2022-11-30 12:07:54 +01:00
Râu Cao f3ca307e64 Fix Tor access
Configure alternate_domains for Rails app to re-enable Tor access (was
throwing 403s without this config)
2022-11-30 12:06:25 +01:00
Râu Cao 66f5217a41 Refactor Mastodon nginx recipe for proxy usage
Works both as local deployment and proxy (via roles and environments)

* Use upstreams for proxy_pass
* Access static assets from proxy, configure caching for them
* Move Tor config to environment, install via role
* ...
2022-11-30 12:02:17 +01:00
Râu Cao 83e55c84a2 Use domain name for log file paths 2022-11-30 12:00:01 +01:00
Râu Cao 83513dbd9d Remove request limits for ipfs proxy
In favor of fail2ban
2022-11-30 11:58:22 +01:00
Râu Cao c4d43b7f4e Make Mastodon services listen on private IP in prod
And allow access to them from the private network
2022-11-30 11:57:51 +01:00
Râu Cao c3e98688fd Deploy second dirsrv supplier
Manually configured (once) to replicate data from and to the first
supplier on `ldap-3`.
2022-11-26 16:47:55 +01:00
Râu Cao 2958ba4b81 Use *.kosmos.local hostnames for LDAP nodes 2022-11-26 16:47:28 +01:00
Râu Cao 991458208d Use a role for configuring LDAP hostname on clients
This way it's also easy to converge all LDAP clients at once.
2022-11-26 16:45:45 +01:00
Râu Cao 8d4db7290e Rename dirsrv_primary role
The term used in 389 docs is "supplier" instead (ex "master")
2022-11-26 16:44:05 +01:00
Râu Cao e0fb84e56c Store Gitea data (avatars, attachments, etc.) in Garage/S3
Also adds a new garage gateway role, which only allows RPC (inter-node)
traffic to Garage.
2022-11-26 13:05:07 +01:00
Râu CaoandGitea 9a89af0fe3 Add basic Garage doc 2022-11-25 10:56:22 +00:00
Râu CaoandGitea 20e6bdb7f9 Add production environment, replication for garage
Also deploy a third node in a different data center
2022-11-25 10:56:22 +00:00
Râu CaoandGitea b5ff60214c Install/configure Garage
Add a garage cookbook that installs the garage binary distribution and
creates the necessary configuration and system service.

Also deploy two new VMs to act as storage nodes.

refs #428
2022-11-25 10:56:22 +00:00
Râu Cao d06f5d7723 Set up fail2ban for nginx, move IPFS gateway to proxy role 2022-11-24 14:02:43 +01:00
Râu Cao 7f545404b1 Update node info 2022-11-22 21:23:39 +01:00
Râu Cao 4188b2976b Use Ruby 3.0.3, skip post-deployment migrations 2022-11-07 14:53:52 +01:00
Râu Cao 3620a43190 Upgrade Elasticsearch from 6.x to latest 7.x 2022-11-06 13:56:15 +01:00
Râu Cao 28454c0849 Change VM backup schedule for draco 2022-11-05 17:43:53 +01:00
Râu Cao 6df168f32f Prune VM backups after every run 2022-11-05 17:43:48 +01:00
Râu Cao 65933bef4b Move hubot nginx sites to proxy role, deploy to fornax 2022-11-04 14:41:21 +01:00
Râu Cao 6cce1d9df8 Upgrade hal8000 setup for new hubot-kredits 2022-11-04 14:41:12 +01:00
Râu Cao 534f23eebc Remove obsolete recipes 2022-11-04 14:38:51 +01:00
Râu Cao 37710be28b Bundle main IPFS node recipes in a role
So we can find the VM/IP
2022-11-04 14:37:23 +01:00
Râu Cao 76fd629e40 Deploy new kredits ipfs-pinner
refs kredits/meta#10
2022-11-03 14:16:37 +01:00
Râu Cao 0297298ce0 Upgrade LND to 0.15.4
Fixes a critical issue that prevents block sync in production
2022-11-03 11:02:52 +01:00
Râu Cao 90b62e3fc1 Remove ufw logging for ipfs 2022-11-02 19:27:09 +01:00
Râu Cao b1922d26f6 Allow IPFS connections on private network
(HAProxy is now also using the private network.)

This fixes IPFS connections to Kosmos nodes from outside the network, as
well as in between nodes on the private network.
2022-11-02 14:06:07 +01:00