| Age | Commit message (Collapse) | Author |
|
Amp-Thread-ID: https://ampcode.com/threads/T-019fc408-6e41-73fe-826d-d47b0408981b
Co-authored-by: Amp <amp@ampcode.com>
|
|
f3s hosts don't get a distinct standby certificate/keypair; alias the
primary cert's files under the standby name (relayd selects a keypair
by SNI, so it needs matching filenames) and add standby.<host> as a
SAN on the primary cert. Every host now also gets www.<host> as a SAN
unconditionally, since public DNS publishes www for all of them.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
|
|
|
|
|
internal)
|
|
Rex's <%# ... %> only comments the first line; the multi-line comment
was parsed as Perl (bareword 'generation'/'1 week').
|
|
Add a custom gogios check that monitors shuriken album freshness via
dist/status.json's unix_epoch, read locally on each frontend (so it
covers the whole generation+sync pipeline). warn at 1 week, crit at 2
weeks; CRIT if status.json is missing (album not published). DependsOn
the site's HTTP checks.
The check_shuriken_age plugin (Perl, Nagios API) lives in the
shuriken.sh repo (contrib/); the frontends Rexfile gogios task installs
it to /usr/local/bin/ from the sibling shuriken.sh checkout (single
source of truth, no vendored copy).
|
|
Per feedback: the shuriken-sync CronJob now uses the rsync daemon
protocol (rsync://) instead of SSH -- no key/Secret needed. The
frontends run rsyncd via inetd with hosts allow *.wg0; k3s pods run on
r-nodes with .wg0 (WireGuard) connectivity, so they're authorized to
push over the mesh. Add writable irregular-ninja and alt-irregular-ninja
modules to frontends/etc/rsyncd.conf.tpl (deploy with rex rsync).
It only publishes when a generation has COMPLETED since the last sync:
shuriken now deletes dist/status.json at the start of a run and writes
it last on success, so status.json presence+freshness vs a .last-sync
marker on NFS is the completed/not-yet-published signal. Most ticks
skip; a publish fires once after each daily generation. hostAliases pin
the .wg0 frontend names to mesh IPs (cluster DNS doesn't resolve *.wg0).
The nfs-check initContainer stays so rsync --delete can't wipe the live
site if NFS is down. shuriken --sync over SSH stays as a manual option.
|
|
The NodePort is LAN-only, so the advertised clone URL
(ssh://git@r0.lan.buetow.org:30222/...) did not work from outside. Add a plain
TCP relay on the gateways forwarding 2022 to NodePort 30222, and have Forgejo
advertise code.f3s.buetow.org:2022.
Port 2022 rather than 22: the gateways run their own sshd on port 2, so 22 was
in fact free, but leaving the forge off the default port keeps it clear of the
mass scanning that port attracts. That is noise reduction and not security --
the real protection is that Forgejo's SSH does key-only auth for git operations
and offers no shell. 2222 would have been the conventional choice but dserver
(DTail) already holds it on the gateways; verified 2022 free on both.
The relay carries no "protocol" line, so relayd forwards the stream untouched.
TLS must not be involved: SSH secures its own transport and the client verifies
Forgejo's host key at the far end. A dedicated <forgejo_ssh> table keeps the
health check on the SSH port, since the web UI can be up while SSH is not.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
|
Deliberately independent of the cgit git-server: separate namespace (services),
separate NFS volumes, separate SSH NodePort (30222 vs 30022), and no shared
storage. cgit keeps serving the existing 80 bare repos at c-git.f3s.buetow.org
and is not touched. Forgejo starts empty; repos get migrated by hand later.
ArgoCD deliberately keeps reading conf.git from the existing git-server, so
Forgejo has no consumers and cannot take cluster deploys down with it.
SQLite rather than a PostgreSQL pod: single writer (replicas 1 + Recreate) and
NFSv4.2 does real byte-range locking, so the usual SQLite-on-NFS failure mode
does not apply. Uses the -rootless image so the pod runs wholly as UID 1000
with all capabilities dropped, and both volumes carry the .nfs-sentinel guard.
The installer is locked and registration disabled because the instance is
reachable from the internet; the admin account is created via the CLI.
code.f3s.buetow.org added to @f3s_hosts, which drives the DNS zone, the relayd
route, the ACME cert and the gogios checks.
Not yet activated: the ArgoCD Application still needs applying, the NFS
directories creating, and the frontends deploying. See f3s/forgejo/README.md.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
|
The three cache-control response rules were unscoped, so relayd rewrote every
response passing through the https relay -- not just the fallback pages the
comment described. Everything the k3s cluster serves was forced to
"no-cache, no-store, must-revalidate", overriding whatever the backend set.
cgit, for example, marks its CSS and logo "expires 30d", but browsers
re-fetched them on every page view.
relayd cannot filter a response by the backend table that produced it, and a
"header set" cannot be combined with a header match in the same rule. So match
the Server header -- the local httpd is the only backend answering
"OpenBSD httpd" -- and carry that across with a sticky tag.
Verified on blowfish before rollout with an isolated relayd instance: a
response from httpd:8080 gets the tagged headers, one from the cluster's nginx
does not. Fallback behaviour retested after deploy: c-git.f3s.buetow.org
served from httpd:8080 still returns the "Server turned off" page on any path,
with all three headers intact. cgit.css now passes through max-age=2592000.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
|
|
|
- dtail-freebsd.json.tpl: move HostKeyFile from volatile
/var/run/dserver/cache to persistent /var/db/dserver/ssh_host_key —
FreeBSD's cleanvar purges /var/run at boot, so the host key was
regenerated on every reboot (mirrors the NetBSD/OpenBSD templates)
- dserver-freebsd.tpl rc.d: start_precmd now creates /var/db/dserver
(0700, dserver-owned) and re-runs dserver-update-key-cache.sh on
every start, so the volatile key cache repopulates right after a
reboot or restart instead of waiting for the daily periodic job
- packages/Makefile: .SHELLFLAGS gains -o pipefail — the
"git archive | ssh ... tar" pipeline could mask a git archive
failure as long as tar succeeded on the truncated stream (the only
recipe-level pipeline; $(shell ...) calls are unaffected)
- packages/Makefile: OS-suffixed /tmp staging names for the OpenBSD
and NetBSD dtail tgz (dtail-openbsd-*/dtail-netbsd-*) — a dash-less
version would have made both targets stage to the same
/tmp/dtail-<version>.tgz locally and on f0; the final repo copy
keeps the canonical dtail-<version>.tgz name
- dserver-update-key-cache.sh.tpl (OpenBSD): port the NetBSD
hardening — quote all variable expansions, derive the user via
basename suffix stripping instead of cut -d. -f1 (dotted usernames
broke), fix the obsolete-cachefile echo that used single quotes and
never interpolated $cachefile, add a header comment documenting the
rc_pre and /etc/daily.local call sites
- dserver.tpl (OpenBSD rc.d): replace 'rc_cmd $1 &' with rc_bg=YES and
a plain rc_cmd "$1" — the daemon needs backgrounding because it does
not daemonize, but backgrounding the whole rc framework made rc_pre
failures and the start result invisible to rcctl; rc_bg is rc.subr's
supported way to background only the daemon
- dserver-update-key-cache-freebsd.sh.tpl: header now documents the
new rc.d start_precmd call site
Deployed: FreeBSD pkg republished, f0/f1/f2 upgraded with host key
migrated to /var/db/dserver first (sha256 verified identical); f3
unreachable, still on the old package. OpenBSD pkg republished,
fishfinger reinstalled + restarted, host key unchanged, dcat verified.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
|
install -d applies -o/-m only to the final directory, so the previous
single 'install -d -o _dserver /var/run/dserver/cache' left the parent
/var/run/dserver (the _dserver home dir) implicitly created as
root:wheel after a reboot. Create the parent explicitly with the right
ownership, matching the NetBSD template (dserver-netbsd.tpl).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
|
The OpenBSD dserver template used relative CacheDir "cache" and
HostKeyFile "cache/ssh_host_key", which only worked because rc.d starts
the daemon via su -l _dserver (CWD = /var/run/dserver). Any start from
another directory broke public key lookup — same bug class dtail commit
fec2f9d fixed on the server side. Switch to absolute paths like the
FreeBSD/NetBSD templates.
OpenBSD /etc/rc wipes /var/run/* at boot, so move the SSH host key to
persistent /var/db/dserver/ssh_host_key (mirrors the NetBSD template) —
a regenerated host key would break clients' known_hosts. The rc.d
rc_pre now also creates /var/db/dserver and re-runs the key-cache
helper on every service start, so the volatile cache is repopulated
right after a reboot instead of waiting for the daily cron job.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
|
- Makefile: .SHELLFLAGS := -ec — with .ONESHELL a failing intermediate
recipe line (remote pkg_create, scp, PV upload) previously did not
stop the recipe and make exited 0; also remove stale /tmp package
artifacts at target start so a failed build can never silently
re-upload an old tgz, guard against an empty extracted version, and
quote the tr operand
- dtail-netbsd.json.tpl + rc.d: move the SSH host key from volatile
/var/run/dserver/cache to persistent /var/db/dserver/ssh_host_key so
it survives reboots (clients re-accept the key once after upgrade)
- pkg-dtail-netbsd.sh: reject a missing version argument; write the
pkg_summary via a temp file so a pkg_info failure cannot publish a
truncated pkg_summary.gz; document that the dserver user/group is a
deliberate manual install step
- key-cache template: comment now states the daily cron entry is added
manually at install time (documented in the pkgrepo skill)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
|
- Makefile target dtail-netbsd: cross-compile netbsd/arm64 (CGO_ENABLED=0,
nozstd), package natively on pi0 with pkg_create, upload package plus
pkg_summary.gz to the PV at netbsd/10.1/packages/aarch64/ via f0
- scripts/pkg-dtail-netbsd.sh: NetBSD pkg_create packaging (prefix /,
root-owned files via @owner/@group plist directives)
- frontends: NetBSD dserver rc.d script, dtail.json (absolute cache
paths), and key-cache helper templates
- pkgrepo nginx: serve /netbsd/ with autoindex
- Fix stale ROCKY_ARM_BUILD_HOST: pi0 was re-imaged to NetBSD, aarch64
RPMs are built on pi2
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
|
|
|
|
|
|
|
Adds FreeBSD .tpl variants of the existing dserver templates and a
matching pkg-dtail-freebsd.sh packaging script, plus a pkg-dtail-rpm.sh
script and packages/files/dtail-rocky/ (systemd units, key-cache script,
dtail.json) for the Rocky Linux dtail build.
|
|
|
|
|
|
Bypass Traefik for anki-sync-server to fix HTTP 303 stream failures.
The Anki client maps zstd response body read errors to SEE_OTHER (303).
This was caused by Traefik's HTTP proxy layer interfering with the binary
zstd-compressed response bodies. Route directly to the anki NodePort like
Jellyfin's 30096, which avoids the double-proxy issue.
|
|
Deploy goprecords-upload-client.sh from goprecords/scripts/ instead of the
inline-token template. Token is now stored in /etc/goprecords-upload.token
(mode 600) and the script reads it at runtime. Old goprecords-upload.sh
(token baked in, mode 500) is removed. daily.local entry updated to pass
GOPRECORDS_HOST=<host> as environment variable.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
|
|
Add POSIX sh script template deployed to /usr/local/bin/goprecords-upload.sh,
invoked from /etc/daily.local. Rex task goprecords_upload installs curl, renders
per-host script from geheim secrets/etc/goprecords/<host>.token, and hooks
commons. Document token layout and kubectl key creation in README.
Made-with: Cursor
|
|
|
|
|
|
|
|
- Skip standby.blowfish.buetow.org and standby.fishfinger.buetow.org
(no DNS records, no httpd/acme-client.conf entries)
- Use 'rcctl check && reload || restart' for relayd so a dead relayd
gets restarted instead of silently failing on reload
Amp-Thread-ID: https://ampcode.com/threads/T-019d77bf-0537-74e1-a1a9-c1b47d2af392
Co-authored-by: Amp <amp@ampcode.com>
|
|
- relayd: route www.snonux.foo to localhost for redirect, keep bare/standby on f3s_static_proxy
- httpd: www.snonux.foo returns 302 redirect to snonux.foo
- gogios: monitor pi0/pi1 via wg0.wan.buetow.org instead of lan.buetow.org
- AGENTS.md: document Pi lighttpd Host-based virtual hosting pattern
Amp-Thread-ID: https://ampcode.com/threads/T-019d7766-909d-741c-bcb9-1e1e931f1e1b
Co-authored-by: Amp <amp@ampcode.com>
|
|
|
|
|
|
|
|
|
|
|
|
Add table <garage> (192.168.2.130-132), Host header match in f3s block,
and forward to port 3900 with tcp health checks on https4/https6.
Made-with: Cursor
|
|
Include garage in f3s host list so DNS, TLS (acme), and httpd/relayd
templates generate config for the new hostname.
Made-with: Cursor
|
|
Amp-Thread-ID: https://ampcode.com/threads/T-019d6727-d603-72c5-97a0-c1e419211767
Co-authored-by: Amp <amp@ampcode.com>
|
|
|
|
Add a QEMU/KVM OpenBSD VM for native compilation of CGo packages
(e.g. dtail with DataDog/zstd). The VM is fully automated via expect
driving the serial console installer.
- packages/buildvm/: setup, provision, start, stop scripts and expect installer
- packages/scripts/pkg-dtail-openbsd.sh: multi-binary package with signify signing
- packages/Makefile: build VM management and dtail-openbsd target using git archive
- frontends/Rexfile: dtail_install task uses custom pkg repo, dtail task enabled
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
|
Packages are now signed via pkg_sign with the custom-pkg signify key
on the OpenBSD build host. The public key at /etc/signify/custom-pkg.pub
on each client allows pkg_add to verify without -D unsigned.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
|
Replace manual binary copy in gogios_install with pkg install (FreeBSD)
and pkg_add (OpenBSD). Add pkgrepo_setup task that configures PKG_PATH
in root's .profile on OpenBSD frontends. The gogios task now calls
gogios_install automatically.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
|
Serve custom-built FreeBSD and OpenBSD packages via nginx in the k3s
cluster. Includes helm chart, ArgoCD app, test artifact build script,
and DNS entry via frontends Rexfile.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
|
|
|
|
|
|
|
|
|
|
|
Keep the first-line prefix strip without trimming spaces.
|