feat(debyltech-cloud): add cloud.debyltech.com Nextcloud
A de Byl Technologies LLC Nextcloud cloned from the Skudak instance: LibreSign signing for people without an account, registration off (admin-created accounts only), no Group Folders. DNS is a terraform-managed ALIAS to fulfillr.debyltech.com. - containers/debyltech/cloud.yml: nextcloud/mariadb/redis on port 8091. It installs unattended on the first deploy, sends mail through SES as noreply@debyltech.com, and re-asserts the Skudak LibreSign settings. - files/debyltechmail: skudakmail rebranded, with a new black-and-white wordmark and white web-UI logos. - LibreSign is pinned to 14.2.2 from the GitHub release (sha256-checked) rather than `occ app:install`. The app store served a same-day 14.2.3 whose tarball has no binary-signature metadata. 14.2.x also doesn't create its own download dirs, so they're pre-created. - The backup runs nightly at 04:15 to TrueNAS /mnt/glacier/debyltechcloud and reaches personal iDrive via the "iDrive E2 Backup" task; the TrueNAS side excludes /debyltechcloud/_backup/config/**. - Fix the libresign:configure:check gate in both instances: '\berror\b' becomes a backspace in Jinja and never matched, so a check reporting three errors passed clean. Now '\\berror\\b'. - vault: cloud_debyltech_* secrets. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
0eca63d4b7
commit
fa5bbf8e54
@@ -39,9 +39,13 @@ before you need it, and record the date you last did.
|
||||
|
||||
Dumps live on the host at `/var/backups/nextcloud/<name>/db/<name>-YYYYMMDD.sql.gz`
|
||||
and on TrueNAS at `<remote_path>/_backup/db/`. TrueNAS in turn cloud-syncs
|
||||
`/mnt/glacier/skudakcloud` to Skudak's own iDrive e2 bucket, so a third copy
|
||||
exists there — but restoring from it means going through the TrueNAS console,
|
||||
not this host.
|
||||
each dataset offsite, so a third copy exists there — but restoring from it
|
||||
means going through the TrueNAS console, not this host:
|
||||
|
||||
| Dataset | Offsite |
|
||||
|---|---|
|
||||
| `skudakcloud`, `skudakapps`, `skudakgit` | Skudak's own iDrive e2 bucket (excluded from the personal task) |
|
||||
| `nextcloud`, `gitea`, `debyltechcloud` | Personal iDrive e2 bucket, via the "iDrive E2 Backup" task over `/mnt/glacier` |
|
||||
|
||||
Verify the dump before trusting it:
|
||||
|
||||
@@ -102,23 +106,25 @@ The signing CA lives in the data tree at
|
||||
brings it back with everything else. After restoring, confirm it:
|
||||
|
||||
```bash
|
||||
sudo -H -u podman bash -c 'cd; podman exec -u www-data skudak-cloud php occ libresign:configure:check'
|
||||
sudo -H -u podman bash -c 'cd; podman exec -u www-data <skudak-cloud|debyltech-cloud> php occ libresign:configure:check'
|
||||
```
|
||||
|
||||
Every check must report `success`. If `openssl-configure` reports an error, the
|
||||
`certificate_engine` / `config_path` app config is pointing somewhere without a
|
||||
CA — see the guarded generate task in `tasks/containers/skudak/cloud.yml`.
|
||||
CA — see the guarded generate task in `tasks/containers/{skudak,debyltech}/cloud.yml`.
|
||||
**Do not** simply re-run `libresign:configure:openssl` on a restored instance
|
||||
without understanding why: it mints a *new* root CA and invalidates the trust
|
||||
chain on every document already signed under the old one.
|
||||
|
||||
## LibreSign
|
||||
|
||||
Deployed on `skudak-cloud` only. LibreSign 14.1.0 requires Nextcloud server
|
||||
`>=34.0.0,<35.0.0`, which the pinned `nextcloud:34.0.2-apache` satisfies. If the
|
||||
Nextcloud tag is bumped to 35, LibreSign must be held or upgraded in step — the
|
||||
two instances are pinned independently in `tasks/main.yml`, so `skudak-cloud`
|
||||
can lag `cloud` if needed.
|
||||
Deployed on `skudak-cloud` and `debyltech-cloud`. LibreSign 14.1.0 requires
|
||||
Nextcloud server `>=34.0.0,<35.0.0`, which the pinned `nextcloud:34.0.3-apache`
|
||||
satisfies. If the Nextcloud tag is bumped to 35, LibreSign must be held or
|
||||
upgraded in step — each instance is pinned independently in `tasks/main.yml`,
|
||||
so the LibreSign instances can lag `cloud` if needed. The branding apps
|
||||
(`files/skudakmail`, `files/debyltechmail`) pin `max-version="34"` too and
|
||||
must be bumped alongside.
|
||||
|
||||
Dependency split, which drives what survives a container recreate:
|
||||
|
||||
|
||||
Reference in New Issue
Block a user