| Age | Commit message (Collapse) | Author |
|
|
|
Coexists with ytdl-sub rather than replacing it, downloading into its own
tree under /srv/media/incoming so the two never manage the same files.
Podcast clients cannot authenticate, so the feed, cover art, episode art
and media stream routes bypass oauth2-proxy with auth_request off. Those
are exactly the routes pinchflat serves unauthenticated itself, each
addressed by an unguessable UUID. The OPML endpoint is exposed as well but
stays token-protected by the app.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
|
|
|
|
|
Requires /var/secrets/typetype to be populated by hand:
- env with DATABASE_PASSWORD and POSTGRES_PASSWORD (set the same value)
- youtube_remote_login_internal_token
- youtube_session_encryption_key
Postgres data lives at /var/lib/typetype/postgres as a bind mount rather
than a Docker volume.
Downloads (typetype-downloader + Garage) and SSO are not set up yet.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
|
|
|
n8n has trouble building and just seems to be unnecessary trouble. FWIW
it seems like we could improve our configuration by using the more
standard services.n8n.environment
|
|
Use a disposable domain until thinking more about authentication.
|
|
|
|
Getting the right permissions set on the socket is quite awkward.
Perhaps listening on a port would have been preferable. systemd socket
activation would require us to support file descriptor handoff (which
would need to be changed in Nitro).
|
|
broadcom_sta WiFi driver is considered insecure. We weren't using WiFi
anyway, so remove it. It may be possible to use Broadcom open source
drivers for our BCM4360, but these may only support newer hardware.
Also use allowUnfreePredicate to explicitly whitelist packages.
|
|
|
|
Needs /var/secrets/restic to be manually provisioned.
Based on ~/.dotfiles/restic/run, as a starting point.
Backing up /srv/Attic is huge (100s of GBs), redundant (same hard
drive), and slow (hours). It probably makes sense to mirror it instead.
The repo password is stored on the same hard drive in plaintext, which
means our repo is not secure at rest. This is a bigger issue with the
initial setup without full disk encryption, so we choose not to address
it; however, this does expose all backups whereas previously just this
server was exposed.
The most important remaining tasks are to mirror the restic backups
remotely, and to automate on a timer.
|
|
|
|
|
|
We don't want to use Nix for deployment because it's slow. Code must be
manually deployed to /opt/garage.
|
|
Have not allocated the mf.mou.fo subdomain yet while testing the app.
BASE_URL seems nonessential, but at least fixes the API endpoint given.
To create the initial admin user:
$ sudo -u miniflux env DATABASE_URL='user=miniflux host=/run/postgresql dbname=miniflux' miniflux -create-admin
The UI is quite clunky. In particular it is very easy to get lost
navigating between article list and detail views. It would also be nice
to force opening articles on the external site (for Phoronix). Fetching
original content (instead of using the RSS content) is nice though.
To integrate with oauth2-proxy, probably need to set AUTH_PROXY_HEADER.
|
|
Add ACLs for nginx that only allow read access. This is more limited
than allowing all users read access to /srv/syncthing, or adding nginx
as a writable user to the syncthing group.
|
|
|
|
Deduplicate btrfs files.
|
|
|
|
|
|
Quick fix for .dotfiles scripts
|
|
Jellyfin uses its own authentication; it's probably not worthwhile to
try to consolidate with SSO (and may break Jellyfin clients). We don't
bother to allow UDP for DLNA nor Jellyfin auto detection.
|
|
Kanidm development is kind of slow and conservative. Their frontend is
lacking.
The hope was Zitadel would solve some issues logging in to the Home
Assistant app behind oauth2-proxy, but it doesn't really help. In
particular, KeePassium is unable to password complete (login page
reloads to username entry?).
In any case, we probably prefer Zitadel so let's at least record it for
now. Pocket ID is an interesting minimal alternative, but the Home
Assistant app doesn't support passkeys.
$ sudo rm -r /var/lib/kanidm/
|
|
|
|
DISABLE_REGISTRATION needs to be set after the initial administrator
account is manually registered.
Considered the Forgejo community fork, but it doesn't seem to have
attracted very much of the developer community. Despite concerns about
copyright claims, Gitea does not have a CLA; it is MIT licensed. Still
considering even lighter weight options that may be easier to
programmatically control (just an HTTP server that speaks the smart
protocol?).
For managing groups of repositories, can use labels or organizations.
Neither seem particularly convenient.
Gitea defaults to public repositories.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Initial run trimmed nearly the entire volume. May be quite important
since Nix churns through storage.
|
|
|
|
|
|
|
|
- btrfs subvolumes
- hostname
- SSH
|
|
|