feat(debyltech-cloud): add cloud.debyltech.com Nextcloud
A de Byl Technologies LLC Nextcloud cloned from the Skudak instance: LibreSign signing for people without an account, registration off (admin-created accounts only), no Group Folders. DNS is a terraform-managed ALIAS to fulfillr.debyltech.com. - containers/debyltech/cloud.yml: nextcloud/mariadb/redis on port 8091. It installs unattended on the first deploy, sends mail through SES as noreply@debyltech.com, and re-asserts the Skudak LibreSign settings. - files/debyltechmail: skudakmail rebranded, with a new black-and-white wordmark and white web-UI logos. - LibreSign is pinned to 14.2.2 from the GitHub release (sha256-checked) rather than `occ app:install`. The app store served a same-day 14.2.3 whose tarball has no binary-signature metadata. 14.2.x also doesn't create its own download dirs, so they're pre-created. - The backup runs nightly at 04:15 to TrueNAS /mnt/glacier/debyltechcloud and reaches personal iDrive via the "iDrive E2 Backup" task; the TrueNAS side excludes /debyltechcloud/_backup/config/**. - Fix the libresign:configure:check gate in both instances: '\berror\b' becomes a backspace in Jinja and never matched, so a check reporting three errors passed clean. Now '\\berror\\b'. - vault: cloud_debyltech_* secrets. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
0eca63d4b7
commit
fa5bbf8e54
@@ -5,6 +5,7 @@ bookstack_path: "{{ podman_volumes }}/bookstack"
|
||||
cam2ip_path: "{{ podman_volumes }}/cam2ip"
|
||||
cloud_path: "{{ podman_volumes }}/cloud"
|
||||
cloud_skudak_path: "{{ podman_volumes }}/skudakcloud"
|
||||
cloud_debyltech_path: "{{ podman_volumes }}/debyltechcloud"
|
||||
debyltech_path: "{{ podman_volumes }}/debyltech"
|
||||
# drone_path: removed - Drone CI decommissioned
|
||||
factorio_path: "{{ podman_volumes }}/factorio"
|
||||
@@ -218,6 +219,29 @@ libresign_skudak_cert_c: US
|
||||
libresign_skudak_cert_st: New Hampshire
|
||||
libresign_skudak_cert_l: Newbury
|
||||
|
||||
# de Byl Technologies Nextcloud (containers/debyltech/cloud.yml). DNS is a
|
||||
# Route53 ALIAS to fulfillr.debyltech.com, managed in ~/src/debyltech/terraform
|
||||
# (aws/cloud.tf), so no awsddns container of its own.
|
||||
cloud_debyltech_server_name: cloud.debyltech.com
|
||||
# debyltech-com $primary-color (copper). Drives the web UI theming; the mail
|
||||
# CTA carries the same value as a constant in files/debyltechmail.
|
||||
theming_debyltech_primary: "#bc804d"
|
||||
# Login/header background. Dark site ink rather than copper so the white
|
||||
# wordmark and mark shipped in files/debyltechmail/img stay legible on it.
|
||||
theming_debyltech_background: "#0a1a2b"
|
||||
# LibreSign root CA identity: the issuer on every signed document. Same caveat
|
||||
# as the Skudak block above -- changing these does not re-issue the CA.
|
||||
libresign_debyltech_cert_cn: de Byl Technologies LLC
|
||||
libresign_debyltech_cert_o: de Byl Technologies LLC
|
||||
libresign_debyltech_cert_c: US
|
||||
libresign_debyltech_cert_st: New Hampshire
|
||||
libresign_debyltech_cert_l: Newbury
|
||||
# Outbound mail via AWS SES SMTP as noreply@debyltech.com. The IAM user is
|
||||
# NextcloudSMTP in the terraform repo; its SMTP username/password are
|
||||
# cloud_debyltech_smtp_user / cloud_debyltech_smtp_pass in the vault.
|
||||
cloud_debyltech_smtp_host: email-smtp.us-east-1.amazonaws.com
|
||||
cloud_debyltech_smtp_port: 465
|
||||
|
||||
|
||||
# Legacy nginx/ModSecurity configuration removed - Caddy provides built-in security
|
||||
|
||||
@@ -284,6 +308,7 @@ caddy_log_names:
|
||||
- graylog
|
||||
- cloud
|
||||
- cloud-skudak
|
||||
- cloud-debyltech
|
||||
- gitea-debyl
|
||||
- gitea-skudak
|
||||
- fulfillr
|
||||
|
||||
Reference in New Issue
Block a user