aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorJan Tuomi <jan@jantuomi.fi>2026-08-03 22:27:15 +0300
committerJan Tuomi <jan@jantuomi.fi>2026-08-03 22:27:15 +0300
commit017b29539749da3c62202879d757a45ffc71208c (patch)
treee44ad456a4dd4e883b4496c4345c57d77a359819
parent0eb9ce78949c148cb20c6396a15033b10f4eb902 (diff)
Improvements
-rw-r--r--roles/host/tasks/main.yml5
-rw-r--r--roles/host/templates/usr_local_etc_pylogsentinel.conf.j212
-rw-r--r--roles/jails/01_ingress/defaults/main.yml2
-rw-r--r--roles/jails/01_ingress/handlers/main.yml3
-rw-r--r--roles/jails/01_ingress/tasks/main.yml9
-rw-r--r--roles/jails/01_ingress/templates/etc_pf.conf.j223
-rw-r--r--roles/jails/05_homepage/defaults/main.yml33
-rw-r--r--roles/jails/05_homepage/templates/etc_crontab.j23
-rw-r--r--roles/jails/05_homepage/templates/usr_local_bin_update_agate_certs.sh.j228
-rw-r--r--roles/jails/16_dl/files/fix-library-permissions.sh2
10 files changed, 104 insertions, 16 deletions
diff --git a/roles/host/tasks/main.yml b/roles/host/tasks/main.yml
index 0840f08..2a18e7a 100644
--- a/roles/host/tasks/main.yml
+++ b/roles/host/tasks/main.yml
@@ -44,11 +44,6 @@
- bash
- git
- python312
- - py312-pip
- - py312-setuptools
- - py312-build
- - py312-installer
- - py312-wheel
- python
- fastfetch
- vim
diff --git a/roles/host/templates/usr_local_etc_pylogsentinel.conf.j2 b/roles/host/templates/usr_local_etc_pylogsentinel.conf.j2
index c3f000e..cf24b20 100644
--- a/roles/host/templates/usr_local_etc_pylogsentinel.conf.j2
+++ b/roles/host/templates/usr_local_etc_pylogsentinel.conf.j2
@@ -3,7 +3,10 @@ state_dir = /var/run/pylogsentinel
max_block_size = 10M
[logs.standard]
-cmd = /usr/local/bin/fd -t f -E 'access.log' -E 'syncthing.log' '^[a-zA-Z-_]+(\.log|\.txt)$' /var/log /usr/local/jails/containers/*/var/log /usr/local/jails/containers/dl/usr/local/*/logs
+cmd = /usr/local/bin/fd -t f -E 'access.log' -E 'syncthing.log' '^[a-zA-Z-_]+(\.log|\.txt)$' /var/log /usr/local/jails/containers/*/var/log
+
+[logs.arr]
+cmd = /usr/local/bin/fd -t f '^[a-zA-Z-_]+(\.log|\.txt)$' /usr/local/jails/containers/dl/usr/local/*/logs
[logs.access]
paths = /usr/local/jails/containers/ingress/var/log/nginx/access.log
@@ -11,11 +14,16 @@ paths = /usr/local/jails/containers/ingress/var/log/nginx/access.log
[action.default]
cmd = echo -e "---------\nMatched $RULE_ID in $FILE at line $LINE, context:\n\n$CONTEXT\n" >> /tmp/pylogsentinel.daily
-[rule.error]
+[rule.error_std]
description = Error-like conditions
pattern = /(error|fatal|exception|killed)/i
logs = standard
+[rule.error_arr]
+description = Arr software error
+pattern = /(\|error\|)/i
+logs = arr
+
[rule.access]
description = HTTP code >=500 in access log
pattern = /HTTP\/[0-9].[0-9]" 5[0-9][0-9]/
diff --git a/roles/jails/01_ingress/defaults/main.yml b/roles/jails/01_ingress/defaults/main.yml
index 1527cd9..f5e848b 100644
--- a/roles/jails/01_ingress/defaults/main.yml
+++ b/roles/jails/01_ingress/defaults/main.yml
@@ -46,8 +46,6 @@ pkg:
- py312-certbot-nginx
files:
- - src: etc_pf.conf.j2
- dest: /etc/pf.conf
- src: acme-dns-auth.py
dest: /usr/local/bin/acme-dns-auth.py
mode: "0755"
diff --git a/roles/jails/01_ingress/handlers/main.yml b/roles/jails/01_ingress/handlers/main.yml
index 1819a68..f9c7907 100644
--- a/roles/jails/01_ingress/handlers/main.yml
+++ b/roles/jails/01_ingress/handlers/main.yml
@@ -2,3 +2,6 @@
service:
name: nginx
state: reloaded
+
+- name: Reload pf
+ shell: pfctl -f /etc/pf.conf
diff --git a/roles/jails/01_ingress/tasks/main.yml b/roles/jails/01_ingress/tasks/main.yml
index a6fdc3c..6c8a30b 100644
--- a/roles/jails/01_ingress/tasks/main.yml
+++ b/roles/jails/01_ingress/tasks/main.yml
@@ -38,6 +38,15 @@
name: jail
tasks_from: jail_setup
+- name: Deploy pf.conf
+ template:
+ src: "{{ jail_role_dir }}/templates/etc_pf.conf.j2"
+ dest: /etc/pf.conf
+ owner: root
+ group: wheel
+ mode: "0644"
+ notify: Reload pf
+
- name: Deploy nginx config
template:
src: "{{ jail_role_dir }}/templates/usr_local_etc_nginx_nginx.conf.j2"
diff --git a/roles/jails/01_ingress/templates/etc_pf.conf.j2 b/roles/jails/01_ingress/templates/etc_pf.conf.j2
index c0528e1..1d8f4c8 100644
--- a/roles/jails/01_ingress/templates/etc_pf.conf.j2
+++ b/roles/jails/01_ingress/templates/etc_pf.conf.j2
@@ -4,24 +4,37 @@
lan = "epl{{ jail.num }}b"
wan = "epw{{ jail.num }}b"
lan_net = "{{ lan_ipv4_network }}"
+gemini_host = "{{ jail_lan_cidr | ipv4_nth(5 + jail_lan_offset | int) }}"
table <blocked> persist
-# Keep PF out of loopback, drop by default if you add blocks later
+# Keep PF out of loopback
set skip on lo0
set block-policy drop
# NAT: translate LAN traffic to the WAN interface address
nat on $wan from $lan_net to any -> ($wan)
-# Block traffic from IPs in the blocked table
+# Gemini: redirect WAN port 1965 to the homepage jail
+rdr on $wan inet proto tcp from any to ($wan) port 1965 -> $gemini_host
+
+# Default deny
+block all
+
+# Always block listed source addresses
block in quick from <blocked> to any
-# Allow all outbound traffic from the jail and LAN via both interfaces
-# NAT will be applied automatically when source is in $lan_net and going out $wan
+# Allow LAN traffic to enter for forwarding/NAT
+pass in on $lan inet from $lan_net to any keep state
+
+# Allow outbound traffic
pass out on $wan all keep state
pass out on $lan all keep state
-pass in on $wan inet proto {tcp, udp} from any to any port {80, 443} keep state
+# Allow public HTTP and HTTPS
+pass in on $wan inet proto { tcp, udp } from any to ($wan) port { 80, 443 } keep state
+
+# Allow redirected Gemini traffic to the backend
+pass in on $wan inet proto tcp from any to $gemini_host port 1965 keep state
{% endif %}
{% endfor %}
diff --git a/roles/jails/05_homepage/defaults/main.yml b/roles/jails/05_homepage/defaults/main.yml
index dbf767e..99c74e5 100644
--- a/roles/jails/05_homepage/defaults/main.yml
+++ b/roles/jails/05_homepage/defaults/main.yml
@@ -3,18 +3,51 @@ userland: "15.1-RELEASE"
zfs:
- name: zroot/jails/volumes/homepage_www
mountpoint: /var/www
+ - name: zroot/jails/volumes/homepage_agate_tls
+ mountpoint: /usr/local/etc/agate/tls
+ owner: "80"
+ group: "80"
+ - name: zroot/jails/volumes/homepage_gemini
+ mountpoint: /var/gemini
+
+nullfs:
+ - src: /usr/local/jails/containers/ingress/usr/local/etc/letsencrypt
+ dst: /mnt/letsencrypt
+ mode: ro
pkg:
- pcre2
- nginx
- rsync
- bash
+ - agate
files:
- src: usr_local_etc_nginx_nginx.conf.j2
dest: /usr/local/etc/nginx/nginx.conf
- src: etc_crontab.j2
dest: /etc/crontab
+ - src: usr_local_bin_update_agate_certs.sh.j2
+ dest: /usr/local/bin/update-agate-certs
+ mode: "0755"
services:
- nginx
+ - agate
+
+dirs:
+ - /var/log/agate
+
+sysrc:
+ - name: agate_hostname
+ value: "jan.systems"
+ - name: agate_content
+ value: "/var/gemini"
+ - name: agate_certs
+ value: "/usr/local/etc/agate/tls"
+ - name: agate_logfile
+ value: "/var/log/agate/agate.log"
+ - name: agate_addr
+ value: "0.0.0.0"
+ - name: agate_port
+ value: "1965"
diff --git a/roles/jails/05_homepage/templates/etc_crontab.j2 b/roles/jails/05_homepage/templates/etc_crontab.j2
index 8541f57..6ec1b69 100644
--- a/roles/jails/05_homepage/templates/etc_crontab.j2
+++ b/roles/jails/05_homepage/templates/etc_crontab.j2
@@ -6,4 +6,5 @@ PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin
#
#minute hour mday month wday who command
-# TODO: update linklog
+# Update agate TLS certs if letsencrypt cert has changed
+*/5 * * * * root /usr/local/bin/update-agate-certs >> /var/log/update-agate-certs.log 2>&1
diff --git a/roles/jails/05_homepage/templates/usr_local_bin_update_agate_certs.sh.j2 b/roles/jails/05_homepage/templates/usr_local_bin_update_agate_certs.sh.j2
new file mode 100644
index 0000000..4f0ddaf
--- /dev/null
+++ b/roles/jails/05_homepage/templates/usr_local_bin_update_agate_certs.sh.j2
@@ -0,0 +1,28 @@
+#!/bin/sh
+# update-agate-certs - convert letsencrypt PEM certs to DER for agate
+# Runs from cron; only converts if the cert has changed
+
+set -eu
+
+CERT_SRC="/mnt/letsencrypt/live/jan.systems/fullchain.pem"
+KEY_SRC="/mnt/letsencrypt/live/jan.systems/privkey.pem"
+TLS_DIR="/usr/local/etc/agate/tls"
+CHECKSUM_FILE="${TLS_DIR}/.cert.sha256"
+
+# Check if cert has changed
+CURRENT_SUM=$(sha256 -q "${CERT_SRC}")
+if [ -f "${CHECKSUM_FILE}" ] && [ "$(cat "${CHECKSUM_FILE}")" = "${CURRENT_SUM}" ]; then
+ exit 0
+fi
+
+echo "Certificate changed, converting to DER..."
+
+openssl x509 -in "${CERT_SRC}" -out "${TLS_DIR}/cert.der" -outform DER
+openssl pkey -in "${KEY_SRC}" -out "${TLS_DIR}/key.der" -outform DER
+chown www:www "${TLS_DIR}/cert.der" "${TLS_DIR}/key.der"
+chmod 640 "${TLS_DIR}/cert.der" "${TLS_DIR}/key.der"
+
+echo "${CURRENT_SUM}" > "${CHECKSUM_FILE}"
+
+service agate status > /dev/null 2>&1 && service agate restart
+echo "Done."
diff --git a/roles/jails/16_dl/files/fix-library-permissions.sh b/roles/jails/16_dl/files/fix-library-permissions.sh
index 852dca6..4910d68 100644
--- a/roles/jails/16_dl/files/fix-library-permissions.sh
+++ b/roles/jails/16_dl/files/fix-library-permissions.sh
@@ -6,5 +6,5 @@ DIRS="/mnt/storage/media /mnt/storage/downloads"
for d in $DIRS; do
chown -R storage:storage $d
- chmod -R u=rwX,g=rX,o=rX $d
+ chmod -R u=rwX,g=rwX,o=rX $d
done