| Age | Commit message (Collapse) | Author |
|
The three cache-control response rules were unscoped, so relayd rewrote every
response passing through the https relay -- not just the fallback pages the
comment described. Everything the k3s cluster serves was forced to
"no-cache, no-store, must-revalidate", overriding whatever the backend set.
cgit, for example, marks its CSS and logo "expires 30d", but browsers
re-fetched them on every page view.
relayd cannot filter a response by the backend table that produced it, and a
"header set" cannot be combined with a header match in the same rule. So match
the Server header -- the local httpd is the only backend answering
"OpenBSD httpd" -- and carry that across with a sticky tag.
Verified on blowfish before rollout with an isolated relayd instance: a
response from httpd:8080 gets the tagged headers, one from the cluster's nginx
does not. Fallback behaviour retested after deploy: c-git.f3s.buetow.org
served from httpd:8080 still returns the "Server turned off" page on any path,
with all three headers intact. cgit.css now passes through max-age=2592000.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
|
|
|
- dtail-freebsd.json.tpl: move HostKeyFile from volatile
/var/run/dserver/cache to persistent /var/db/dserver/ssh_host_key —
FreeBSD's cleanvar purges /var/run at boot, so the host key was
regenerated on every reboot (mirrors the NetBSD/OpenBSD templates)
- dserver-freebsd.tpl rc.d: start_precmd now creates /var/db/dserver
(0700, dserver-owned) and re-runs dserver-update-key-cache.sh on
every start, so the volatile key cache repopulates right after a
reboot or restart instead of waiting for the daily periodic job
- packages/Makefile: .SHELLFLAGS gains -o pipefail — the
"git archive | ssh ... tar" pipeline could mask a git archive
failure as long as tar succeeded on the truncated stream (the only
recipe-level pipeline; $(shell ...) calls are unaffected)
- packages/Makefile: OS-suffixed /tmp staging names for the OpenBSD
and NetBSD dtail tgz (dtail-openbsd-*/dtail-netbsd-*) — a dash-less
version would have made both targets stage to the same
/tmp/dtail-<version>.tgz locally and on f0; the final repo copy
keeps the canonical dtail-<version>.tgz name
- dserver-update-key-cache.sh.tpl (OpenBSD): port the NetBSD
hardening — quote all variable expansions, derive the user via
basename suffix stripping instead of cut -d. -f1 (dotted usernames
broke), fix the obsolete-cachefile echo that used single quotes and
never interpolated $cachefile, add a header comment documenting the
rc_pre and /etc/daily.local call sites
- dserver.tpl (OpenBSD rc.d): replace 'rc_cmd $1 &' with rc_bg=YES and
a plain rc_cmd "$1" — the daemon needs backgrounding because it does
not daemonize, but backgrounding the whole rc framework made rc_pre
failures and the start result invisible to rcctl; rc_bg is rc.subr's
supported way to background only the daemon
- dserver-update-key-cache-freebsd.sh.tpl: header now documents the
new rc.d start_precmd call site
Deployed: FreeBSD pkg republished, f0/f1/f2 upgraded with host key
migrated to /var/db/dserver first (sha256 verified identical); f3
unreachable, still on the old package. OpenBSD pkg republished,
fishfinger reinstalled + restarted, host key unchanged, dcat verified.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
|
install -d applies -o/-m only to the final directory, so the previous
single 'install -d -o _dserver /var/run/dserver/cache' left the parent
/var/run/dserver (the _dserver home dir) implicitly created as
root:wheel after a reboot. Create the parent explicitly with the right
ownership, matching the NetBSD template (dserver-netbsd.tpl).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
|
The OpenBSD dserver template used relative CacheDir "cache" and
HostKeyFile "cache/ssh_host_key", which only worked because rc.d starts
the daemon via su -l _dserver (CWD = /var/run/dserver). Any start from
another directory broke public key lookup — same bug class dtail commit
fec2f9d fixed on the server side. Switch to absolute paths like the
FreeBSD/NetBSD templates.
OpenBSD /etc/rc wipes /var/run/* at boot, so move the SSH host key to
persistent /var/db/dserver/ssh_host_key (mirrors the NetBSD template) —
a regenerated host key would break clients' known_hosts. The rc.d
rc_pre now also creates /var/db/dserver and re-runs the key-cache
helper on every service start, so the volatile cache is repopulated
right after a reboot instead of waiting for the daily cron job.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
|
- Makefile: .SHELLFLAGS := -ec — with .ONESHELL a failing intermediate
recipe line (remote pkg_create, scp, PV upload) previously did not
stop the recipe and make exited 0; also remove stale /tmp package
artifacts at target start so a failed build can never silently
re-upload an old tgz, guard against an empty extracted version, and
quote the tr operand
- dtail-netbsd.json.tpl + rc.d: move the SSH host key from volatile
/var/run/dserver/cache to persistent /var/db/dserver/ssh_host_key so
it survives reboots (clients re-accept the key once after upgrade)
- pkg-dtail-netbsd.sh: reject a missing version argument; write the
pkg_summary via a temp file so a pkg_info failure cannot publish a
truncated pkg_summary.gz; document that the dserver user/group is a
deliberate manual install step
- key-cache template: comment now states the daily cron entry is added
manually at install time (documented in the pkgrepo skill)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
|
- Makefile target dtail-netbsd: cross-compile netbsd/arm64 (CGO_ENABLED=0,
nozstd), package natively on pi0 with pkg_create, upload package plus
pkg_summary.gz to the PV at netbsd/10.1/packages/aarch64/ via f0
- scripts/pkg-dtail-netbsd.sh: NetBSD pkg_create packaging (prefix /,
root-owned files via @owner/@group plist directives)
- frontends: NetBSD dserver rc.d script, dtail.json (absolute cache
paths), and key-cache helper templates
- pkgrepo nginx: serve /netbsd/ with autoindex
- Fix stale ROCKY_ARM_BUILD_HOST: pi0 was re-imaged to NetBSD, aarch64
RPMs are built on pi2
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
|
|
|
Adds FreeBSD .tpl variants of the existing dserver templates and a
matching pkg-dtail-freebsd.sh packaging script, plus a pkg-dtail-rpm.sh
script and packages/files/dtail-rocky/ (systemd units, key-cache script,
dtail.json) for the Rocky Linux dtail build.
|
|
Bypass Traefik for anki-sync-server to fix HTTP 303 stream failures.
The Anki client maps zstd response body read errors to SEE_OTHER (303).
This was caused by Traefik's HTTP proxy layer interfering with the binary
zstd-compressed response bodies. Route directly to the anki NodePort like
Jellyfin's 30096, which avoids the double-proxy issue.
|
|
|
|
|
|
|
|
- relayd: route www.snonux.foo to localhost for redirect, keep bare/standby on f3s_static_proxy
- httpd: www.snonux.foo returns 302 redirect to snonux.foo
- gogios: monitor pi0/pi1 via wg0.wan.buetow.org instead of lan.buetow.org
- AGENTS.md: document Pi lighttpd Host-based virtual hosting pattern
Amp-Thread-ID: https://ampcode.com/threads/T-019d7766-909d-741c-bcb9-1e1e931f1e1b
Co-authored-by: Amp <amp@ampcode.com>
|
|
|
|
|
|
|
|
|
|
|
|
Add table <garage> (192.168.2.130-132), Host header match in f3s block,
and forward to port 3900 with tcp health checks on https4/https6.
Made-with: Cursor
|
|
Amp-Thread-ID: https://ampcode.com/threads/T-019d6727-d603-72c5-97a0-c1e419211767
Co-authored-by: Amp <amp@ampcode.com>
|
|
|
|
|
|
This enables an overlay editor binding and installs the send-keys script on frontends.
|
|
session timeout
Amp-Thread-ID: https://ampcode.com/threads/T-019c1549-6538-740f-b867-595c2dff8117
Co-authored-by: Amp <amp@ampcode.com>
|
|
Amp-Thread-ID: https://ampcode.com/threads/T-019c14ac-164f-776f-8648-471d4ac4ce5a
Co-authored-by: Amp <amp@ampcode.com>
|
|
Amp-Thread-ID: https://ampcode.com/threads/T-019c14ac-164f-776f-8648-471d4ac4ce5a
Co-authored-by: Amp <amp@ampcode.com>
|
|
- acme.sh: Change grep from exact match to prefix match for f3s hosts
Server blocks for f3s hosts use -port80/-port8080 suffixes
- relayd: Add explicit routing for f3s hosts (except registry/jellyfin)
minvid and other f3s hosts now route to <f3s> backend table
Amp-Thread-ID: https://ampcode.com/threads/T-019c14ac-164f-776f-8648-471d4ac4ce5a
Co-authored-by: Amp <amp@ampcode.com>
|
|
Amp-Thread-ID: https://ampcode.com/threads/T-019c1492-bec0-70f8-8d02-ef3596a7228b
Co-authored-by: Amp <amp@ampcode.com>
|
|
F3S hosts don't have DNS records for www variants, causing ACME validation
to fail. Only non-f3s hosts get www.hostname as alternative name in cert.
Fixes: audiobookshelf.f3s.buetow.org and other f3s hosts unable to obtain valid TLS certs
Amp-Thread-ID: https://ampcode.com/threads/T-019c1441-7e3a-77cd-890f-cd31df998a31
Co-authored-by: Amp <amp@ampcode.com>
|
|
- Fixed Perl template syntax error in relayd.conf.tpl (lines 68-77) with improperly nested if/elsif blocks
- Added ipv4address subroutine to Rexfile to lookup IPv4 by hostname
- Updated relayd template to use ipv4address->($hostname) instead of undefined $vio0_ip variable
- Pass ipv4address to template engine in relayd task
Amp-Thread-ID: https://ampcode.com/threads/T-019c1441-7e3a-77cd-890f-cd31df998a31
Co-authored-by: Amp <amp@ampcode.com>
|
|
Amp-Thread-ID: https://ampcode.com/threads/T-019c1392-78a3-7440-9d95-1a1b2fd7dfec
Co-authored-by: Amp <amp@ampcode.com>
|
|
Amp-Thread-ID: https://ampcode.com/threads/T-019c1392-78a3-7440-9d95-1a1b2fd7dfec
Co-authored-by: Amp <amp@ampcode.com>
|
|
Amp-Thread-ID: https://ampcode.com/threads/T-019c1392-78a3-7440-9d95-1a1b2fd7dfec
Co-authored-by: Amp <amp@ampcode.com>
|
|
Amp-Thread-ID: https://ampcode.com/threads/T-019c1392-78a3-7440-9d95-1a1b2fd7dfec
Co-authored-by: Amp <amp@ampcode.com>
|
|
Amp-Thread-ID: https://ampcode.com/threads/T-019c1392-78a3-7440-9d95-1a1b2fd7dfec
Co-authored-by: Amp <amp@ampcode.com>
|
|
This reverts commit 0818e6d7d06c5026dd33a6313480a21b1c555ae8.
|
|
Amp-Thread-ID: https://ampcode.com/threads/T-019c1392-78a3-7440-9d95-1a1b2fd7dfec
Co-authored-by: Amp <amp@ampcode.com>
|
|
Amp-Thread-ID: https://ampcode.com/threads/T-019c1392-78a3-7440-9d95-1a1b2fd7dfec
Co-authored-by: Amp <amp@ampcode.com>
|
|
Amp-Thread-ID: https://ampcode.com/threads/T-019c12b1-e861-773b-8f74-64b6c2255a5f
Co-authored-by: Amp <amp@ampcode.com>
|
|
Amp-Thread-ID: https://ampcode.com/threads/T-019c12b1-e861-773b-8f74-64b6c2255a5f
Co-authored-by: Amp <amp@ampcode.com>
|
|
Amp-Thread-ID: https://ampcode.com/threads/T-019c12b1-e861-773b-8f74-64b6c2255a5f
Co-authored-by: Amp <amp@ampcode.com>
|
|
Amp-Thread-ID: https://ampcode.com/threads/T-019c12b1-e861-773b-8f74-64b6c2255a5f
Co-authored-by: Amp <amp@ampcode.com>
|
|
- Skip ipv4/ipv6 prefixed hosts from main check loop (no www/standby variants)
- Add separate checks with appropriate IP version only:
- ipv4.ipv6test.f3s.buetow.org: IPv4 HTTP check only
- ipv6.ipv6test.f3s.buetow.org: IPv6 HTTP check only
Amp-Thread-ID: https://ampcode.com/threads/T-019c08b8-cd58-73e9-8a1d-c8f124223367
Co-authored-by: Amp <amp@ampcode.com>
|
|
Amp-Thread-ID: https://ampcode.com/threads/T-019c086d-c760-779d-b740-0f748094b62a
Co-authored-by: Amp <amp@ampcode.com>
|
|
- Add meta tags to prevent browser caching of fallback page
- Add response header directives in relayd to set Cache-Control headers
- Prevents cached fallback page from being served when cluster comes back online
Amp-Thread-ID: https://ampcode.com/threads/T-019c0589-2021-71cc-a2ba-2cd942f4fdef
Co-authored-by: Amp <amp@ampcode.com>
|
|
- Add explicit httpd server blocks for f3s.buetow.org and *.f3s.buetow.org on port 8080
- These blocks serve /htdocs/f3s_fallback with request rewrite to /index.html
- Prevents httpd from falling back to blowfish.buetow.org's directory autoindex
- Now correctly shows fallback page for all f3s hosts when k3s cluster is unreachable
Amp-Thread-ID: https://ampcode.com/threads/T-019c00f6-c61d-772a-8fe2-dc0aee0a4ce2
Co-authored-by: Amp <amp@ampcode.com>
|
|
Set MinNotifyIntervalS to 3600 (1 hour) to batch email notifications.
Gogios will only send emails when both the interval has elapsed AND
there's been a state change. HTML reports continue updating on every run.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
|
|
|
|
- Add all 18 f3s hosts to @acme_hosts for certificate issuance
- Skip standby certificate variants for f3s hosts (not needed for k3s cluster)
- Add port 80 ACME challenge blocks to httpd for all f3s hosts
- Add port 8080 fallback page blocks to httpd for f3s hosts (when cluster is down)
- Update relayd.conf.tpl to skip standby keypairs for f3s hosts
- Update acme-client.conf.tpl to skip standby certificates for f3s hosts
Fixes missing certificates on flux.f3s.buetow.org, anki.f3s.buetow.org, and other f3s services
|