timothykim
0ca8394f8a
add testing section to readme
2026-03-20 15:22:58 -04:00
timothykim
e767ab3235
test -> tests
2026-03-20 15:20:29 -04:00
timothykim
50ab425e8f
fix test directory path in deploy-nginx workflow
2026-03-20 15:19:41 -04:00
timothykim
b7439b23e3
fix nginx security headers not being applied to https responses
...
nginx add_header inheritance meant X-Content-Type-Options and X-Frame-Options
were silently dropped from all https server blocks. moved all security headers
into a shared snippet (security-headers.inc) included per server block. added
pytest-based header verification that auto-discovers sites from conf files.
2026-03-20 15:11:56 -04:00
timothykim
3b41653c04
refactor new-app into app.sh with subcommands
2026-03-20 14:43:47 -04:00
timothykim
eecdf7b002
restructure docs: eliminate duplication across md files
2026-03-20 11:42:06 -04:00
timothykim
be1ad6b456
audit fixes: error handling, docs consistency, bucket idempotency
Provision server / provision (push) Successful in 12s
2026-03-20 11:28:36 -04:00
timothykim
6b1e78350f
document media hosting in readme and usecases
2026-03-19 22:34:47 -04:00
timothykim
4516ed7bab
add media setup instructions to new-app.sh output
2026-03-19 22:31:02 -04:00
timothykim
f9788ff178
fix s3 proxy: forward host header for signature validation
Deploy nginx / deploy (push) Successful in 3s
2026-03-19 21:55:37 -04:00
timothykim
da99d102e9
add s3.hantim.net proxy, fix dns ttl to 3600
Deploy nginx / deploy (push) Successful in 13s
2026-03-19 18:23:39 -04:00
timothykim
a421ecc837
add garage admin api with token, expose via garage.hantim.net
Deploy garage / deploy (push) Successful in 5s
Deploy nginx / deploy (push) Successful in 13s
2026-03-19 17:19:03 -04:00
timothykim
a64f81f503
upgrade garage to v2.2.0, add /media/ proxy to nginx
Deploy garage / deploy (push) Successful in 7s
Deploy nginx / deploy (push) Successful in 3s
2026-03-19 16:45:22 -04:00
timothykim
df179546ae
update docs, fix deploy to not restart unchanged services
...
- deploy.sh: use compose up instead of down+up, fetch secrets individually
- configure.sh: delegate all service deployment to deploy.sh
- docs: add garage cluster init, .env.keys mechanism, update configure.sh description
- remove 2>/dev/null from bws calls
2026-03-19 12:39:55 -04:00
timothykim
76d01c66d6
fix deploy: use compose up instead of down+up, fetch secrets individually
...
Provision server / provision (push) Successful in 11s
- docker compose up -d --remove-orphans instead of down then up
- configure.sh delegates all service deployment to deploy.sh
- deploy.sh generates .env from bws before starting services
- remove 2>/dev/null from bws calls so errors are visible
2026-03-19 12:28:49 -04:00
timothykim
82582028a2
fix garage dockerfile: use alpine base with envsubst
Deploy garage / deploy (push) Failing after 7s
2026-03-19 12:14:38 -04:00
timothykim
3478e05c49
add garage service with env-based secret injection
Deploy garage / deploy (push) Failing after 6s
2026-03-19 12:13:07 -04:00
timothykim
3a8fb09bcf
add .env generation from bws, handle build services in deploy
...
Provision server / provision (push) Successful in 6s
- configure.sh generates .env files from .env.keys + bws
- deploy.sh detects build: services and runs docker compose build
- new-service.sh prints .env.keys instructions
- clean up .gitignore
2026-03-19 12:11:46 -04:00
timothykim
7e35042b71
add haanmind.net
Deploy haanmind.net / deploy (push) Successful in 2s
Deploy nginx / deploy (push) Successful in 3s
2026-03-19 11:23:53 -04:00
timothykim
037b78734f
move dev scripts to tools/, migrate to bws, use example.com in docs
...
Provision server / provision (push) Successful in 7s
- Move new-app.sh, new-service.sh, remove-app.sh from scripts/ to tools/
- Migrate new-app.sh and remove-app.sh from bw to bws
- Replace real domains with example.com in documentation and help text
2026-03-19 11:10:14 -04:00
timothykim
5a8d9a8aa0
install bws to /usr/bin instead of /usr/local/bin
2026-03-18 19:15:44 -04:00
timothykim
ef7fe7677c
migrate bootstrap.sh from bw to bws, update docs
2026-03-18 19:04:22 -04:00
timothykim
00ab7d1b8d
auto-issue certs on nginx deploy, document one-domain-per-conf convention
2026-03-18 15:18:11 -04:00
timothykim
46b27e0780
reverse thekims.family redirect: www -> bare domain
Deploy nginx / deploy (push) Successful in 4s
2026-03-18 15:08:51 -04:00
timothykim
63d1d92333
add hcsuzukiviolin.com redirect to hcsuzuki.net
Deploy nginx / deploy (push) Failing after 3s
2026-03-18 15:01:41 -04:00
timothykim
199ed98e7d
make new scripts executable
Provision server / provision (push) Successful in 7s
2026-03-18 14:53:46 -04:00
timothykim
919c5353bc
split setup.sh into bootstrap.sh and configure.sh
...
Provision server / provision (push) Failing after 2s
bootstrap.sh handles first-time setup (manual, Bitwarden).
configure.sh handles idempotent config (CI-safe).
Add provision workflow, deploy-garage workflow, new-service.sh.
Remove git-crypt references and empty .gitattributes.
2026-03-18 14:51:19 -04:00
timothykim
3b4ff1f291
fix dns record creation in new-app.sh
2026-03-16 22:38:57 -04:00
timothykim
0ffca0335f
add hcsuzuki.net
Deploy hcsuzuki.net / deploy (push) Successful in 2s
Deploy nginx / deploy (push) Successful in 4s
2026-03-16 22:26:45 -04:00
timothykim
1a31381bfb
update gitignore
2026-03-16 22:08:51 -04:00
timothykim
a45813db35
cache secrets to file, fix spinner animation
2026-03-16 22:06:47 -04:00
timothykim
423de9c9e8
add thekims.family
Deploy nginx / deploy (push) Successful in 3s
Deploy thekims.family / deploy (push) Successful in 3s
2026-03-16 22:05:46 -04:00
timothykim
164087f82a
remove thekims.family
Deploy nginx / deploy (push) Successful in 3s
2026-03-16 22:04:48 -04:00
timothykim
0702059044
add thekims.family
Deploy nginx / deploy (push) Failing after 2s
Deploy thekims.family / deploy (push) Successful in 2s
2026-03-16 22:00:16 -04:00
timothykim
43b0730b7b
remove thekims.family
Deploy nginx / deploy (push) Successful in 3s
2026-03-16 21:59:41 -04:00
timothykim
98aa8e7727
use workflow dispatch api instead of deploy-trigger file
2026-03-16 21:54:19 -04:00
timothykim
126061bbcb
add thekims.family
Deploy nginx / deploy (push) Failing after 3s
Deploy thekims.family / deploy (push) Successful in 2s
2026-03-16 21:47:22 -04:00
timothykim
34cba34856
remove thekims.family
Deploy nginx / deploy (push) Successful in 4s
2026-03-16 21:46:30 -04:00
timothykim
0493910966
deploy: clean up old containers before starting new ones
2026-03-16 21:43:01 -04:00
timothykim
e6cbc53065
update timothykim.net image to match new naming convention
Deploy timothykim.net / deploy (push) Failing after 2s
2026-03-16 21:40:05 -04:00
timothykim
0bbe1d48e2
add thekims.family
Deploy nginx / deploy (push) Failing after 3s
Deploy thekims.family / deploy (push) Successful in 2s
2026-03-16 21:23:39 -04:00
timothykim
99a4a4b3ea
cache bitwarden secrets in env vars to skip unlock on repeated runs
2026-03-16 21:22:53 -04:00
timothykim
9d999c319d
add hantim.net
Deploy hantim.net / deploy (push) Successful in 2s
Deploy nginx / deploy (push) Successful in 3s
2026-03-16 21:10:02 -04:00
timothykim
b32a7ae5b6
remove hantim.net
Deploy nginx / deploy (push) Successful in 3s
2026-03-16 21:08:06 -04:00
timothykim
7df77db7b3
fix new-app: retry build trigger, clean up temp nginx conf, add remove-app script
2026-03-16 21:07:34 -04:00
timothykim
e86b7bc58f
add hantim.net
Deploy hantim.net / deploy (push) Failing after 1s
Deploy nginx / deploy (push) Failing after 1s
2026-03-16 18:16:37 -04:00
timothykim
f4771cccf6
remove hantim.net
Deploy nginx / deploy (push) Successful in 3s
2026-03-16 18:16:01 -04:00
timothykim
d12ee0271e
add hantim.net
Deploy hantim.net / deploy (push) Failing after 1s
Deploy nginx / deploy (push) Failing after 1s
2026-03-16 18:13:27 -04:00
timothykim
fad1b3ab59
remove hantim.net
Deploy nginx / deploy (push) Successful in 2s
2026-03-16 18:12:29 -04:00
timothykim
8a30405d18
add hantim.net
Deploy hantim.net / deploy (push) Failing after 1s
Deploy nginx / deploy (push) Failing after 1s
2026-03-16 18:09:23 -04:00