| @@ -1,4 +1,4 @@ | |||||
| terraform.tfvars | terraform.tfvars | ||||
| .terraform | .terraform | ||||
| terraform.tfstate | terraform.tfstate | ||||
| terraform.tfstate.backup | |||||
| terraform.tfstate.backup | |||||
| @@ -0,0 +1,22 @@ | |||||
| TF:=terraform | |||||
| SSH:=ssh | |||||
| USER_SSH_OPTS:= | |||||
| SSH_OPTS:=-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no $(USER_SSH_OPTS) | |||||
| .PHONY: all | |||||
| all: up | |||||
| .PHONY: rebuild | |||||
| rebuild: down up | |||||
| .PHONY: up | |||||
| up: | |||||
| $(TF) apply -auto-approve | |||||
| .PHONY: down | |||||
| down: | |||||
| $(TF) destroy -auto-approve | |||||
| .PHONY: ssh | |||||
| ssh: | |||||
| $(SSH) $(SSH_OPTS) root@`$(TF) output ipv4` | |||||
| @@ -0,0 +1,91 @@ | |||||
| # gitea is a PITA to automate installation of, watch this pr for when it'll be | |||||
| # fully setup-able from the cli https://github.com/go-gitea/gitea/issues/9210 | |||||
| variable "gitea_db_passwd" { | |||||
| type = string | |||||
| } | |||||
| variable "cloudflare_functionalidiot_zoneid" { | |||||
| type = string | |||||
| } | |||||
| resource "cloudflare_record" "www" { | |||||
| depends_on = [ | |||||
| cloudflare_record.root, | |||||
| cloudflare_record.splat ] | |||||
| zone_id = var.cloudflare_functionalidiot_zoneid | |||||
| name = "www" | |||||
| value = "functionalidiot.com" | |||||
| type = "CNAME" | |||||
| ttl = 1 | |||||
| proxied = true | |||||
| } | |||||
| resource "cloudflare_record" "root" { | |||||
| depends_on = [ | |||||
| linode_instance.prod, | |||||
| cloudflare_record.functionalidiot_com_ns1, | |||||
| cloudflare_record.functionalidiot_com_ns2 ] | |||||
| zone_id = var.cloudflare_functionalidiot_zoneid | |||||
| name = "@" | |||||
| value = linode_instance.prod.ip_address | |||||
| type = "A" | |||||
| ttl = 1 | |||||
| proxied = true | |||||
| } | |||||
| resource "cloudflare_record" "splat" { | |||||
| depends_on = [ | |||||
| linode_instance.prod, | |||||
| cloudflare_record.functionalidiot_com_ns1, | |||||
| cloudflare_record.functionalidiot_com_ns2 ] | |||||
| zone_id = var.cloudflare_functionalidiot_zoneid | |||||
| name = "*" | |||||
| value = linode_instance.prod.ip_address | |||||
| type = "A" | |||||
| ttl = 1 | |||||
| proxied = true | |||||
| } | |||||
| resource "cloudflare_record" "functionalidiot_com_ns1" { | |||||
| zone_id = var.cloudflare_functionalidiot_zoneid | |||||
| name = "@" | |||||
| value = "mitch.ns.cloudflare.com" | |||||
| type = "NS" | |||||
| } | |||||
| resource "cloudflare_record" "functionalidiot_com_ns2" { | |||||
| zone_id = var.cloudflare_functionalidiot_zoneid | |||||
| name = "@" | |||||
| value = "tegan.ns.cloudflare.com" | |||||
| type = "NS" | |||||
| } | |||||
| resource "null_resource" "functionalidiot_com_setup" { | |||||
| depends_on = [ null_resource.post_setup ] | |||||
| connection { | |||||
| host = linode_instance.prod.ip_address | |||||
| user = "root" | |||||
| private_key = file("~/.ssh/id_rsa") | |||||
| } | |||||
| provisioner "file" { | |||||
| source = "setup_gitea.sh" | |||||
| destination = "/tmp/setup_gitea.sh" | |||||
| } | |||||
| provisioner "remote-exec" { | |||||
| inline = [<<FIN | |||||
| install -m755 /tmp/setup_gitea.sh /usr/local/bin/setup_gitea | |||||
| rm /tmp/setup_gitea.sh | |||||
| apk add gitea | |||||
| rc-update add gitea default | |||||
| skey=$(su - gitea -c "gitea generate secret SECRET_KEY") | |||||
| itoken=$(su - gitea -c "gitea generate secret INTERNAL_TOKEN") | |||||
| SECRET_KEY=$skey INTERNAL_TOKEN=$itoken /usr/local/bin/setup_gitea | |||||
| chown gitea:www-data /var/lib/gitea/db/gitea.db | |||||
| rc-service gitea restart | |||||
| su - gitea -c "gitea migrate --config /etc/gitea/app.ini" | |||||
| su - gitea -c "gitea admin create-user --username test --password test --email spam@whatever.mitchty.com --config /etc/gitea/app.ini" | |||||
| su - gitea -c "gitea admin create-user --username mitch --password ${var.gitea_db_passwd} --email spam@mitchty.com --admin --config /etc/gitea/app.ini" | |||||
| FIN | |||||
| ] | |||||
| } | |||||
| } | |||||
| @@ -1,10 +1,15 @@ | |||||
| provider "linode" { | |||||
| token = var.linode_token | |||||
| # entry point for terraform configuration | |||||
| variable "ssh_pub_key" { | |||||
| type = string | |||||
| } | } | ||||
| resource "linode_instance" "functionalidiot_net" { | |||||
| variable "root_password" { | |||||
| type = string | |||||
| } | |||||
| resource "linode_instance" "prod" { | |||||
| image = "linode/alpine3.11" | image = "linode/alpine3.11" | ||||
| label = "functionalidiot.net" | |||||
| label = "vps" | |||||
| group = "terraform" | group = "terraform" | ||||
| region = "us-central" | region = "us-central" | ||||
| type = "g6-nanode-1" | type = "g6-nanode-1" | ||||
| @@ -13,21 +18,5 @@ resource "linode_instance" "functionalidiot_net" { | |||||
| } | } | ||||
| output "ipv4" { | output "ipv4" { | ||||
| value = "${linode_instance.functionalidiot_net.ip_address}" | |||||
| value = "${linode_instance.prod.ip_address}" | |||||
| } | } | ||||
| resource "null_resource" "post-setup" { | |||||
| depends_on = [ linode_instance.functionalidiot_net ] | |||||
| connection { | |||||
| host = linode_instance.functionalidiot_net.ip_address | |||||
| user = "root" | |||||
| password = var.root_password | |||||
| private_key = file("~/.ssh/id_rsa") | |||||
| } | |||||
| provisioner "remote-exec" { | |||||
| inline = [<<FIN | |||||
| uname -a | |||||
| FIN | |||||
| ] | |||||
| } | |||||
| } | |||||
| @@ -0,0 +1,20 @@ | |||||
| resource "null_resource" "post_setup" { | |||||
| depends_on = [ linode_instance.prod ] | |||||
| connection { | |||||
| host = linode_instance.prod.ip_address | |||||
| user = "root" | |||||
| private_key = file("~/.ssh/id_rsa") | |||||
| } | |||||
| provisioner "remote-exec" { | |||||
| inline = [<<FIN | |||||
| apk update | |||||
| apk upgrade | |||||
| apk add nginx muacme gitea iproute2 sqlite bind-tools | |||||
| rc-update add nginx default | |||||
| rc-service nginx restart | |||||
| sed -i -e 's/AllowTcpForwarding .*/AllowTcpForwarding yes/g' /etc/ssh/sshd_config | |||||
| rc-service sshd restart | |||||
| FIN | |||||
| ] | |||||
| } | |||||
| } | |||||
| @@ -0,0 +1,20 @@ | |||||
| # Terraform provider specific setup | |||||
| variable "linode_token" { | |||||
| type = string | |||||
| } | |||||
| provider "linode" { | |||||
| token = var.linode_token | |||||
| } | |||||
| # TODO: When the domain finally transfers setup | |||||
| # dns A/AAAA/C records to point to the ip | |||||
| variable "cloudflare_api_token" { | |||||
| type = string | |||||
| } | |||||
| provider "cloudflare" { | |||||
| version = "~> 2.0" | |||||
| api_token = var.cloudflare_api_token | |||||
| } | |||||
| @@ -0,0 +1,78 @@ | |||||
| #!/usr/bin/env sh | |||||
| #-*-mode: Shell-script; coding: utf-8;-*- | |||||
| gitea_ini=/etc/gitea/app.ini | |||||
| # We want to listen on 127.0.0.1 instead of 0.0.0.0 for now | |||||
| if ! grep HTTP_ADDR $gitea_ini; then | |||||
| sed -i -e '/\[server\]/a HTTP_ADDR=127.0.0.1' $gitea_ini | |||||
| fi | |||||
| if ! grep OFFLINE_MODE $gitea_ini; then | |||||
| # Setup offlinemode we don't need the cdn crap | |||||
| sed -i -e '/\[server\]/a OFFLINE_MODE = true' $gitea_ini | |||||
| fi | |||||
| # Change the gitea APP_NAME | |||||
| if ! grep APP_NAME $gitea_ini; then | |||||
| sed -i -e '/^RUN_MODE.*/a APP_NAME = mitchtys git house' $gitea_ini | |||||
| fi | |||||
| # Ensure all new repos are private by default | |||||
| if ! grep FORCE_PRIVATE $gitea_ini; then | |||||
| sed -i -e '/\[repository\]/a FORCE_PRIVATE=true' $gitea_ini | |||||
| fi | |||||
| # No limits to repos | |||||
| if ! grep MAX_CREATION_LIMIT $gitea_ini; then | |||||
| sed -i -e '/\[repository\]/a MAX_CREATION_LIMIT=-1' $gitea_ini | |||||
| fi | |||||
| # Don't use http for git operations | |||||
| if ! grep DISABLE_HTTP_GIT $gitea_ini; then | |||||
| sed -i -e '/\[repository\]/a DISABLE_HTTP_GIT=true' $gitea_ini | |||||
| fi | |||||
| if ! grep CUSTOM $gitea_ini; then | |||||
| cat <<- FIN | tee -a $gitea_ini | |||||
| # CUSTOM | |||||
| [security] | |||||
| INTERNAL_TOKEN = $INTERNAL_TOKEN | |||||
| SECRET_KEY = $SECRET_KEY | |||||
| INSTALL_LOCK = true | |||||
| [oauth2] | |||||
| ENABLE = false | |||||
| [other] | |||||
| SHOW_FOOTER_VERSION = false | |||||
| [openid] | |||||
| ENABLE_OPENID_SIGNIN = false | |||||
| ENABLE_OPENID_SIGNUP = false | |||||
| [ui] | |||||
| SHOW_USER_EMAIL = false | |||||
| [api] | |||||
| ENABLE_SWAGGER = false | |||||
| [service] | |||||
| DEFAULT_KEEP_EMAIL_PRIVATE = true | |||||
| DISABLE_REGISTRATION = true | |||||
| REGISTER_EMAIL_CONFIRM = false | |||||
| ENABLE_NOTIFY_MAIL = false | |||||
| ENABLE_CAPTCHA = false | |||||
| REQUIRE_SIGNIN_VIEW = false | |||||
| DEFAULT_ALLOW_CREATE_ORGANIZATION = true | |||||
| NO_REPLY_ADDRESS = noreply.example.org | |||||
| ALLOW_ONLY_EXTERNAL_REGISTRATION = false | |||||
| DEFAULT_ENABLE_TIMETRACKING = true | |||||
| [mailer] | |||||
| ENABLED = false | |||||
| [picture] | |||||
| DISABLE_GRAVATAR = false | |||||
| ENABLE_FEDERATED_AVATAR = true | |||||
| FIN | |||||
| fi | |||||
| @@ -0,0 +1,12 @@ | |||||
| # nix-shell -p terraform -p terraform-providers.linode -p terraform-providers.null -p terraform-providers.random | |||||
| { | |||||
| pkgs ? import <nixpkgs> {} | |||||
| }: pkgs.mkShell { | |||||
| buildInputs = [ | |||||
| pkgs.terraform | |||||
| pkgs.terraform-providers.cloudflare | |||||
| pkgs.terraform-providers.linode | |||||
| pkgs.terraform-providers.null | |||||
| ]; | |||||
| } | |||||
| @@ -1,11 +0,0 @@ | |||||
| variable "ssh_pub_key" { | |||||
| type = string | |||||
| } | |||||
| variable "linode_token" { | |||||
| type = string | |||||
| } | |||||
| variable "root_password" { | |||||
| type = string | |||||
| } | |||||