Commit Graph
100 Commits
Author SHA1 Message Date
greg f5051d6352 Revert "Move the environment variables to an EnvironmentFile"
This reverts commit 79023a65f2.
2019-04-23 14:12:16 +02:00
greg ecf5870195 Only add the Let's Encrypt set up when not in the dev environment 2019-04-23 11:41:12 +02:00
greg 79023a65f2 Move the environment variables to an EnvironmentFile 2019-04-23 11:40:33 +02:00
greg 451d182ca9 Add kredits_github role for the node app and the nginx vhost 2019-04-23 11:30:59 +02:00
greg fabbe398a2 Remove the nginx recipe inclusion and the dependency on nginx in the service
The nginx vhost should be set up after the app is deployed. The node app
doesn't need nginx to run
2019-04-23 11:28:23 +02:00
greg 1d0f66adc4 Remove an unused dependency on the firewall cookbook 2019-04-23 11:25:16 +02:00
greg 3b2a3bf3fa Replace reference to sockethub, remove comment that's not relevant 2019-04-23 10:33:31 +02:00
greg 6da6d2a2bf Add the kosmos-btcpayserver nginx reverse proxy to andromeda 2019-04-15 10:54:35 +02:00
greg 6c7ec545ce Initial kosmos-btcpayserver cookbook setting up an nginx reverse proxy
Closes #19
2019-04-15 10:53:55 +02:00
greg d2142b046f Reload nginx immediately after enabling the Let's Encrypt vhost 2019-04-15 10:51:18 +02:00
greg cd00f4c049 Remove boilerplate from the CHANGELOG 2019-04-12 11:42:29 +02:00
greg 57d0885d26 Change the licenses of hte kosmos cookbooks to MIT 2019-04-12 11:41:20 +02:00
greg e65374c893 Add TODO prefix 2019-04-12 11:21:37 +02:00
greg 5a125982af Merge branch 'master' into chef_14 2019-04-11 18:23:23 +02:00
greg ba6e4220a1 Do not vendor cookbooks using Berkshelf anymore
Instead, use the Berkshelf support in knife-solo and the
vagrant-berkshelf plugin on Vagrant
2019-04-11 18:21:34 +02:00
greg 99fc183172 Do not vendor cookbooks using Berkshelf anymore
Instead, use the Berkshelf support in knife-solo and the
vagrant-berkshelf plugin on Vagrant
2019-04-11 18:16:28 +02:00
greg 67a2c1ea55 Fix the mastodon user variable 2019-04-10 16:38:57 +02:00
greg 4a6c1541ad Add the sockethub firewall rule for dev.kosmos.org 2019-04-10 16:34:25 +02:00
greg e0aa4c5b11 Move the firewall rule for sockethub to its own recipe 2019-04-10 16:33:56 +02:00
greg 39744f517f Fix an undefined variable on older Ubuntu versions 2019-04-10 16:19:05 +02:00
greg b3786053a5 Don't try to install packages on older Ubuntu versions (dev.kosmos.org)
The package repositories do not exist anymore
2019-04-10 16:18:22 +02:00
greg 590e1f83d2 Remove sockethub from the run list of dev to avoid updating it 2019-04-10 12:29:27 +02:00
greg 1844422fb8 Update the mediawiki cookbook 2019-04-10 11:50:23 +02:00
greg 919f5db431 Fix the application resources to work on Chef 14 2019-04-10 11:49:26 +02:00
greg 126b5f8dd5 Update the kosmos-mastodon cookbook to use the new postgresql cookbook
Don't depend on the deprecated database cookbook to create the database
2019-04-10 11:49:26 +02:00
greg f6d88bbd66 Use the new base role in the dev run list 2019-04-10 11:24:56 +02:00
greg 1349020bb9 Remove the mediawiki cookbook from dev, it is now on andromeda 2019-04-10 11:22:12 +02:00
greg ca118ca8f8 Use the second Redis database for sockethub 2019-04-09 11:39:35 +02:00
greg 2d18e4cd45 Set the mysql version for Ubuntu 18.04
The current mysql cookbook doesn't know the version it ships with
2019-04-09 11:09:54 +02:00
greg 05adca7fb2 Update the mediawiki to avoid setting permissions on /var/www 2019-04-09 11:09:33 +02:00
greg 21f0e4143e Move the hubot user creation to its own recipe 2019-04-08 17:58:02 +02:00
greg e137188a4e Add the build_essential resource to both recipes 2019-04-08 17:58:02 +02:00
greg e2c1a43a62 Fix cookbook dependency 2019-04-08 17:58:02 +02:00
greg 58d0557e9d Add the new base role and sockethub (moved from dev.kosmos.org) 2019-04-08 17:58:02 +02:00
greg 12355a6b27 Add a base role, so that chef is updated before anything else 2019-04-08 17:58:02 +02:00
greg fddadbce25 Install the ruby-dev package since the backup gem needs it 2019-04-08 12:35:43 +02:00
greg 4b75ae78dc Set the minimum Chef version since it depends on the new sudo resource 2019-04-08 12:31:47 +02:00
greg aa60d19743 Update sockethub to the latest tag
2.0.5 wasn't compatible with Node 10
2019-04-08 12:31:10 +02:00
greg 504ac417e2 Update nodejs to the latest LTS, using packages 2019-04-08 11:23:24 +02:00
greg 44eee142a7 Do nothing on old Ubuntu versions 2019-04-08 11:22:54 +02:00
greg 7bf583b5a3 Update Mediawiki to 1.32.0 2019-04-08 11:22:24 +02:00
greg 96cb3794f9 Don't try to enable TLS in the development environment 2019-04-08 11:21:45 +02:00
greg 4693b15826 Remove the kosmos-wordpress cookbook 2019-04-08 11:21:20 +02:00
greg 777b85c2ab Update the mediawiki cookbook and upstream cookbooks
Compatibility with Chef 14
2019-04-08 11:20:12 +02:00
greg 6e3e8cde1b Create the Let's Encrypt hook subdirectories 2019-04-08 11:16:38 +02:00
greg adc417282d Update the build-essential cookbook
This removes deprecation warnings on Chef 14, which ships with the
build_essential resource
2019-04-03 15:33:53 +02:00
greg 374d6bc975 Update the poise and postgresql cookbooks 2019-04-03 15:28:06 +02:00
greg 448bffe34e Get rid of the deprecated set_unless 2019-04-03 12:56:15 +02:00
greg b1a3c5e2cd Revert "Revert "Remove the sudo cookbook""
This reverts commit 87d7c721b1.
2019-04-03 12:52:40 +02:00
greg 2f05629fde Revert "Revert "Update Chef to 14.11.21""
This reverts commit db4b45b5c2.
2019-04-03 12:52:32 +02:00
greg 6b9ce81212 Set postgresql password from an encrypted data bag 2019-04-03 11:34:59 +02:00
greg d8a0ecec76 Update the postgresql cookbook 2019-04-03 11:34:41 +02:00
greg 85b7278ccc Add initial kosmos-postgresql cookbook
This is to install PostgreSQL all in one place instead of for each
service that needs it (Mastodon, ejabberd, ...)
2019-04-03 11:34:34 +02:00
greg 1ef24a2091 Install bundler 1.17.3 since we're still on Ruby 2.5 for now
Bundler 2.0 needs Ruby 2.6 or RubyGems 3.0
2019-04-03 11:02:51 +02:00
greg 58b5e5ac22 Move the creation of the SystemD service files outside of the application
This prevents a crash on the initial Chef run due to the service files
not being there yet before the services gets notified to restart
2019-04-03 11:02:25 +02:00
greg 87d7c721b1 Revert "Remove the sudo cookbook"
This reverts commit 73d1722d4b.
2019-04-03 10:30:38 +02:00
greg db4b45b5c2 Revert "Update Chef to 14.11.21"
This reverts commit 2f599ffd6d.
2019-04-03 10:30:24 +02:00
greg 73d1722d4b Remove the sudo cookbook
Chef 14 ships with a sudo resource:
https://docs.chef.io/resource_sudo.html
2019-04-02 12:17:06 +02:00
greg 2f599ffd6d Update Chef to 14.11.21
Closes #21
2019-04-02 12:16:13 +02:00
greg 5fa0fa661b Install certbot from the direct download when on 15.04
It does not have a ppa release. Add a cron job for renewal. When using
the PPA a Systemd timer is part of the package
2019-03-18 16:52:05 +01:00
greg 17f1b2a20a Create a nginx_certbot_site resource to remove duplication
It creates a folder, the nginx vhost for certbot and HTTP redirects, and
also runs certbot and recreates the nginx vhost that includes the TLS
cert
2019-03-15 19:03:28 +01:00
greg b30dcab4da Remove an IPFS port from the ejabberd firewall 2019-03-15 12:30:56 +01:00
greg c3135402ad Move the nginx hook to the deploy directory, create renewal-hooks dir 2019-03-14 20:21:34 +01:00
greg f50f48b55b Remove the old deploy hook, we moved it to the certbot config dir 2019-03-14 18:07:52 +01:00
greg a978f2a6a5 Fix the path to the Gandi DNS certbot script 2019-03-14 18:06:55 +01:00
greg f12ddefec8 Move the Gandi DNS hook for certbot to the kosmos-base cookbook 2019-03-14 18:01:29 +01:00
greg 65482f09c3 Extract the post hooks to their own script in Certbot's config dir 2019-03-14 15:21:50 +01:00
greg 36e046ea73 Run certbot using the binary provided by the Ubuntu PPA 2019-03-14 10:52:44 +01:00
greg fa27187f11 Switch from the git version of certbot to the Ubuntu PPA 2019-03-14 10:49:47 +01:00
greg fc265014de Switch back to the upstream nginx cookbook
chef_nginx is deprecated
2019-03-14 10:35:11 +01:00
greg 566e4278fd Update the ipfs cookbook 2019-03-13 15:11:02 +01:00
greg fee449f347 Set the ipfs user's shell to bash 2019-03-13 11:00:21 +01:00
greg b661f6780c Update chef, berkshelf and knife-solo gems 2019-02-26 14:51:56 +01:00
greg 886958270f Set REDIS_URL for botka
It was using the same Redis key to write its brain as hal8000 (`hubot:storage`),
causing scores to not be persisted to Redis. Right now botka is only
saving the online users to the database. It looks like this was only
enabled recently, as the last saved score was from Feb 8

Fixes #14
2019-02-25 18:29:18 +01:00
greg 5fc158cb5e Install the latest version of the backup gem 2019-02-25 18:28:55 +01:00
greg 2e1cdbecc6 Update the ipfs cookbook 2019-02-25 12:57:11 +01:00
greg 33b8b39be2 Update ipfs and ipfs-cluster 2019-02-25 12:50:07 +01:00
greg 56d14748f9 Fix the Let's Encrypt renew hook script
Only copy over the certs to the prosody directory if it's the 5apps.com
wildcard, not for any 5apps.com subdomain
2018-12-20 17:26:37 +01:00
greg 74a1f1b8a1 Update the ipfs cookbook to the latest version 2018-12-11 10:46:21 +01:00
greg 32b89422e7 Merge branch 'feature/5apps_xmpp_certs' into 'master'
Automatically generate a Let's Encrypt cert for all 5apps xmpp domains

See merge request kosmos/chef!8
2018-12-03 16:32:25 +00:00
greg 9c97cb4a58 Remove empty environment 2018-12-03 16:53:41 +01:00
greg 1e3f84ed9b Merge branch 'master' into feature/5apps_xmpp_certs 2018-12-03 16:52:26 +01:00
greg c1ea7d347d Merge branch 'bugfix/27-backup_notifications' into 'master'
Fix backup gem notifications failing

Closes #27

See merge request kosmos/chef!13
2018-11-09 17:07:22 +00:00
greg ffc6858dcc Do not pass the password on the command line anymore to fix a warning
Since email notifications work now we do not want warnings. Write an
option file with the credentials for mysqldump
(https://dev.mysql.com/doc/refman/5.7/en/option-files.html)
2018-11-09 14:08:32 +01:00
greg 7073e5d574 Fix backup gem notifications failing
This was caused by a bogus PATH that did not include /usr/sbin. The root
user's default PATH includes that, so /usr/sbin/sendmail provided by
postfix is in it

Fixes #27
2018-11-09 14:08:32 +01:00
greg 81c68a9609 Merge branch 'master' into feature/5apps_xmpp_certs 2018-11-08 14:13:09 +01:00
greg bb7dc26f43 Run IPFS Cluster on dev too 2018-10-26 18:30:13 +02:00
greg d65de56412 Add IPFS Cluster support
See merge request kosmos/chef!7
2018-10-26 16:29:40 +00:00
greg 3ce78a9ef4 Merge branch 'master' into feature/25-ipfs_cluster 2018-10-26 17:54:05 +02:00
greg edfe891f48 Add the kosmos-ipfs::letsencrypt recipe to Andromeda
It has been extracted from the ipfs-kosmos::default recipe
2018-10-26 17:51:16 +02:00
greg 5e973b6875 Use the kosmos-ipfs recipe in the hal8000 recipe
This changes the port to not conflict with hubot and sets the gateway to
be writable
2018-10-26 17:49:06 +02:00
greg a7871770b8 Remove an unnecessary require and letsencrypt recipe
This way kosmos-ipfs::default can be used without adding the Let's
Encrypt certificate
2018-10-26 17:46:47 +02:00
greg 4c7dc764a4 Add the updated Berksfile.lock 2018-10-26 17:06:03 +02:00
greg f0542bdf2e Update the ipfs cookbook 2018-10-26 17:02:30 +02:00
greg 4a42fc4ae3 Merge branch 'master' into feature/25-ipfs_cluster 2018-10-26 16:46:44 +02:00
greg 4dff379065 Merge branch 'feature/s3_oncall' into 'master'
Set the S3 credentials to write the new oncall file

See merge request kosmos/chef!12
2018-10-26 13:08:15 +00:00
greg d236d138dc Set the S3 credentials to write the new oncall file 2018-10-26 13:38:12 +02:00
greg 293d1a8a8a Fix formatting 2018-10-04 18:59:30 +02:00
greg 8da7ebbef0 Add initial docs for ejabberd 2018-10-04 18:56:35 +02:00
greg 185649a5f9 Automatically generate a Let's Encrypt cert for all 5apps xmpp domains
Uses the Gandi LiveDNS API
2018-09-04 17:38:17 +02:00