feat(debyltech-cloud): add cloud.debyltech.com Nextcloud

A de Byl Technologies LLC Nextcloud cloned from the Skudak instance:
LibreSign signing for people without an account, registration off
(admin-created accounts only), no Group Folders. DNS is a terraform-managed
ALIAS to fulfillr.debyltech.com.

- containers/debyltech/cloud.yml: nextcloud/mariadb/redis on port 8091.
  It installs unattended on the first deploy, sends mail through SES as
  noreply@debyltech.com, and re-asserts the Skudak LibreSign settings.
- files/debyltechmail: skudakmail rebranded, with a new black-and-white
  wordmark and white web-UI logos.
- LibreSign is pinned to 14.2.2 from the GitHub release (sha256-checked)
  rather than `occ app:install`. The app store served a same-day 14.2.3
  whose tarball has no binary-signature metadata. 14.2.x also doesn't
  create its own download dirs, so they're pre-created.
- The backup runs nightly at 04:15 to TrueNAS /mnt/glacier/debyltechcloud and
  reaches personal iDrive via the "iDrive E2 Backup" task; the TrueNAS side
  excludes /debyltechcloud/_backup/config/**.
- Fix the libresign:configure:check gate in both instances: '\berror\b'
  becomes a backspace in Jinja and never matched, so a check reporting three
  errors passed clean. Now '\\berror\\b'.
- vault: cloud_debyltech_* secrets.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Bastian de Byl
2026-09-28 17:04:04 -04:00
co-authored by Claude Opus 5.5
parent 0eca63d4b7
commit fa5bbf8e54
19 changed files with 1653 additions and 12 deletions
+16
View File
@@ -79,6 +79,22 @@
image: docker.io/library/nextcloud:34.0.3-apache
tags: skudak, skudak-cloud
# cloud.debyltech.com -- cloned from the Skudak instance above; keep the two
# image pins in step. DNS is a terraform-managed ALIAS (see defaults).
- import_tasks: containers/debyltech/cloud.yml
vars:
db_image: docker.io/library/mariadb:10.6
# Fully qualified on purpose: podman records `docker.io/library/redis`, and
# podman-check compares names literally, so the short `docker.io/redis`
# form (as in the Skudak block above) recreates redis on every deploy.
redis_image: docker.io/library/redis:8.2-alpine
image: docker.io/library/nextcloud:34.0.3-apache
# GitHub release asset + its sha256 -- see the pinned-install comment in
# the task file for why this is not left to the app store.
libresign_version: "14.2.2"
libresign_sha256: 8655a4c89f52ca7eaf542d0764d07a7732cb23b39906e7246b37e569ec7a6579
tags: debyltech, debyltech-cloud
- import_tasks: containers/debyltech/fulfillr.yml
vars:
image: git.debyl.io/debyltech/fulfillr:20260915.0011