timothykim
54d6c03bd1
add nginx and cert subcommands to service.sh
2026-04-07 20:59:58 -04:00
timothykim
d2b9d0bce9
fix idempotency in app.sh, service.sh and nginx reload in cert handler
2026-04-07 15:56:59 -04:00
timothykim
c87f76a78a
rename new-service.sh to service.sh with subcommands
2026-03-27 12:28:32 -04:00
timothykim
81151f90aa
update the deploy and new service
2026-03-26 20:01:06 -04:00
timothykim
697de3e199
add uptimerobot monitor subcommand to app.sh
2026-03-26 13:13:41 -04:00
timothykim
43fc8c2e7b
remove new-app.sh, update docs to reference app.sh directly
2026-03-20 20:14:16 -04:00
timothykim
7daf7a267b
pin ssh host key in all workflows
2026-03-20 16:31:03 -04:00
timothykim
b7439b23e3
fix nginx security headers not being applied to https responses
...
nginx add_header inheritance meant X-Content-Type-Options and X-Frame-Options
were silently dropped from all https server blocks. moved all security headers
into a shared snippet (security-headers.inc) included per server block. added
pytest-based header verification that auto-discovers sites from conf files.
2026-03-20 15:11:56 -04:00
timothykim
3b41653c04
refactor new-app into app.sh with subcommands
2026-03-20 14:43:47 -04:00
timothykim
be1ad6b456
audit fixes: error handling, docs consistency, bucket idempotency
Provision server / provision (push) Successful in 12s
2026-03-20 11:28:36 -04:00
timothykim
4516ed7bab
add media setup instructions to new-app.sh output
2026-03-19 22:31:02 -04:00
timothykim
da99d102e9
add s3.hantim.net proxy, fix dns ttl to 3600
Deploy nginx / deploy (push) Successful in 13s
2026-03-19 18:23:39 -04:00
timothykim
a421ecc837
add garage admin api with token, expose via garage.hantim.net
Deploy garage / deploy (push) Successful in 5s
Deploy nginx / deploy (push) Successful in 13s
2026-03-19 17:19:03 -04:00
timothykim
a64f81f503
upgrade garage to v2.2.0, add /media/ proxy to nginx
Deploy garage / deploy (push) Successful in 7s
Deploy nginx / deploy (push) Successful in 3s
2026-03-19 16:45:22 -04:00
timothykim
76d01c66d6
fix deploy: use compose up instead of down+up, fetch secrets individually
...
Provision server / provision (push) Successful in 11s
- docker compose up -d --remove-orphans instead of down then up
- configure.sh delegates all service deployment to deploy.sh
- deploy.sh generates .env from bws before starting services
- remove 2>/dev/null from bws calls so errors are visible
2026-03-19 12:28:49 -04:00
timothykim
3a8fb09bcf
add .env generation from bws, handle build services in deploy
...
Provision server / provision (push) Successful in 6s
- configure.sh generates .env files from .env.keys + bws
- deploy.sh detects build: services and runs docker compose build
- new-service.sh prints .env.keys instructions
- clean up .gitignore
2026-03-19 12:11:46 -04:00
timothykim
037b78734f
move dev scripts to tools/, migrate to bws, use example.com in docs
...
Provision server / provision (push) Successful in 7s
- Move new-app.sh, new-service.sh, remove-app.sh from scripts/ to tools/
- Migrate new-app.sh and remove-app.sh from bw to bws
- Replace real domains with example.com in documentation and help text
2026-03-19 11:10:14 -04:00