A single Go binary with SQLite, built and loaded as localhost/rsvpd:<VERSION> by make deploy-remote in ~/src/rsvp-debylio. Both of its listeners are published on 127.0.0.1 only: Caddy proxies the public one to everyone and the admin one (/admin, no login) only to caddy_local_networks. A Caddyfile mistake alone cannot expose admin, and neither can a port mistake alone. Guests' invite links are the credential and they sit in the URL path, which shapes the vhost: - It does not import common_headers. That snippet sets Referrer-Policy same-origin, which would replace the app's no-referrer and let a token leak in a Referer header. - Its access log rewrites request>uri to /i/REDACTED and drops the Location response header, since every POST 303s back to /i/<token>. - Caddy's error logger is separate from the site's and wrote the raw URI to caddy.log when the upstream was down. The global log now excludes http.log.error.rsvp and a filtered rsvp-errors logger takes it instead. Verified with zero token occurrences in both logs, locally and live. The data directory is owned directly by the host uid of the container's uid 10001 (subuid + 10000). Setting it to the podman user and chowning back each run flipped ownership on every deploy and briefly locked the app out of its database. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Deploy Home
There's no place like home!
Just as Dorothy managed the simple task of clicking her heels together, the desire for an equally simple one-button push deployment was in my heart. Thus, this repository was made.
Ansible
Ansible, along with double encrypted secrets, deploys the necessary configurations to make the home fit for certain needs and desires. Namely, having access to my home from anywhere, securely, and a self-hosted CI server that easily ties into existing workflows.
Makefile
The makefile is primarily used as a wrapper script to ensure that necessary
files, such as the secret vault password file, are provisioned as part of this.
One such addition to the task is utilizing dependency pinning through the
utilization of Python's virtualenv to lock down the specific dependency
versions within the requirements.txt file. This, ideally, prevents any
deployment issues with dependency version woes (e.g. version conflicts, major
updates in newest versions, etc.)
| Target Name | Description |
|---|---|
lint |
(default) Runs yamllint and ansible-lint on all YAML files in ansible/ |
deploy |
Deploys everything, or only tasks specified in TAGS= environment variable |
check |
Runs deploy in a "dry-run", showing diff-style outputs on tasks indicating changes |
vault |
Opens the Ansible vault file for editing |