Compare commits

Author SHA1 Message Date
linnealovespie 87b78d99af bad merge 2026-02-26 22:22:44 -08:00
linnealovespie b7efd7f718 Merge remote-tracking branch 'origin/main' into linnealovespie/maubot 2026-02-26 22:21:04 -08:00
linnealovespie 04921c8e44 maubot and gitignore 2026-02-26 22:17:26 -08:00
linnealovespie 8e3492e533 add draupnir recipe 2026-02-26 22:00:21 -08:00
25 changed files with 84 additions and 113 deletions
+1 -3
View File
@@ -1,6 +1,4 @@
*~
abra/catalogue
abra/recipes/*
!abra/recipes/rtm-astro-recipe
!abra/recipes/mapbattle-recipe
abra/recipes
abra/logs
-6
View File
@@ -1,6 +0,0 @@
[submodule "abra/recipes/rtm-astro-recipe"]
path = abra/recipes/rtm-astro-recipe
url = https://git.coopcloud.tech/RTM/rtm-astro-recipe
[submodule "abra/recipes/mapbattle-recipe"]
path = abra/recipes/mapbattle-recipe
url = ssh://git@git.coopcloud.tech:2222/RTM/mapbattle-recipe.git
-33
View File
@@ -1,33 +0,0 @@
## Setup
Members of RTM: check out the "RTM Reference" collective on our nextcloud for information on how to set up tailscale, ssh access, and user accounts on our servers. Without this, you won't be able to do operations.
Once you have network access, install abra. Read the "Install" and "Quick start"/"New operators tutorial" sections of https://docs.coopcloud.tech/abra/, which will guide you through `wget`ting abra.
Then, run:
```
$ git clone --recurse-submodules https://git.coopcloud.tech/RTM/rtm-config.git
$ cd rtm-config
$ abra server add laylotta.resisttechmonopolies.online
$ abra server add mango.resisttechmonmopolies.online
$ abra server add sootie.resisttechmonopolies.online
```
If you skipped the `--recurse-submodules` flag, you can still do `git submodule update --init` later to get the rtm-astro-recipe recipe.
## Usage
Once you've got this repo cloned and abra installed, you can run abra commands. To test:
```
$ abra app logs resisttechmonopolies.online
```
Should give a list of logs for our website! Other abra commands will work here.
From here, use `abra` to make changes (and reach out to a member of our infra/member-services working group for a tutorial if you would like!). Then, contribute your git changes back to this repository so everyone else sees what you've done and doesn't clobber your changes.
## Dev environment
Sootie is our dev server. If you would like to experiment with changes and fuck around there, use sootie! The implication here is that sootie has a greater chance of having uncommitted changes in its environment than other servers, and that these changes are safe to clobber over.
@@ -1,29 +0,0 @@
TYPE=headscale:00a12a21
DOMAIN=headscale.laylotta.resisttechmonopolies.online
## Domain aliases
#EXTRA_DOMAINS=', `www.headscale.laylotta.resisttechmonopolies.online`'
LETS_ENCRYPT_ENV=production
COMPOSE_FILE="compose.yml"
# Defines the base domain to create the hostnames for MagicDNS.
BASE_DOMAIN=rtm.online
# set this to true to enable using the built-in DERP rather than tailscale's
ENABLE_DERP=true
# enable oidc
OIDC_ENABLED=1
OIDC_ISSUER=https://auth.resisttechmonopolies.online/application/o/headscale/
SECRET_OIDC_CLIENT_KEY_VERSION=v1
COMPOSE_FILE="$COMPOSE_FILE:compose.oidc.yml"
# See https://git.coopcloud.tech/coop-cloud/backup-bot-two
ENABLE_BACKUPS=true
## allow cron updater
COMPOSE_FILE="$COMPOSE_FILE:compose.dns.yml"
DNS_REPO=RTM/sootie-dynamic-dns
@@ -1,4 +1,4 @@
TYPE=loomio:5.2.0+v3.0.20
TYPE=loomio:5.1.3+v3.0.0
COMPOSE_FILE="compose.yml"
DOMAIN=loomio.resisttechmonopolies.online
@@ -1,4 +1,4 @@
TYPE=monitoring-ng:23b13cb8
TYPE=monitoring-ng:1.6.0+v1.8.1
LETS_ENCRYPT_ENV=production
COMPOSE_FILE=compose.yml
DOMAIN=m.laylotta.resisttechmonopolies.online
@@ -6,32 +6,33 @@ TIMEOUT=120
ENABLE_BACKUPS=true
## Enable this secret for Promtail / Prometheus
SECRET_BASIC_AUTH_VERSION=v1
## Promtail (Gathering Logs)
COMPOSE_FILE="$COMPOSE_FILE:compose.promtail.yml"
LOKI_PUSH_URL=https://loki.${DOMAIN}/loki/api/v1/push
# SECRET_BASIC_AUTH_VERSION=v1
#
# Promtail (Gathering Logs)
# COMPOSE_FILE="$COMPOSE_FILE:compose.promtail.yml"
# LOKI_PUSH_URL=https://loki.monitoring.example.org/loki/api/v1/push
## Expose node and cadvisor ports instead of traefik
COMPOSE_FILE="$COMPOSE_FILE:compose.expose-ports.yml"
# COMPOSE_FILE="$COMPOSE_FILE:compose.expose-ports.yml"
# Monitoring Server
#
## Prometheus
COMPOSE_FILE="$COMPOSE_FILE:compose.prometheus.yml"
PROMETHEUS_RETENTION_TIME=1y
# COMPOSE_FILE="$COMPOSE_FILE:compose.prometheus.yml"
# PROMETHEUS_RETENTION_TIME=1y
#
## Prometheus Pushgateway
COMPOSE_FILE="$COMPOSE_FILE:compose.pushgateway.yml"
# COMPOSE_FILE="$COMPOSE_FILE:compose.pushgateway.yml"
#
## Loki
# Loki Server
COMPOSE_FILE="$COMPOSE_FILE:compose.loki.yml"
#
# COMPOSE_FILE="$COMPOSE_FILE:compose.loki.yml"
#
# Set to 0 to disable retention
LOKI_RETENTION_PERIOD=744h
LOKI_STORAGE_FILESYSTEM=1
# LOKI_RETENTION_PERIOD=744h
# LOKI_STORAGE_FILESYSTEM=1
#
## S3 Storage
# LOKI_STORAGE_S3=1
# LOKI_AWS_ENDPOINT=https://minio.autonomic.zone
@@ -1,6 +0,0 @@
# https://git.coopcloud.tech/coop-cloud/monitoring-ng/src/branch/main/scrape-config.example.yml
# https://prometheus.io/docs/prometheus/latest/getting_started/#configure-prometheus-to-monitor-the-sample-targets
- targets
- 'm.laylotta.resisttechmonopolies.online:8082'
- 'node.m.laylotta.resisttechmonopolies.online'
- 'cadvisor.m.laylotta.resisttechmonopolies.online'
@@ -4,7 +4,7 @@
###############################################################################
# BOILERPLATE SETTINGS (shouldn't need to change these) #
###############################################################################
TYPE=mailu:3.0.1+2024.06.37
TYPE=mailu:23309a1a+U
LETS_ENCRYPT_ENV=production
COMPOSE_FILE="compose.yml"
@@ -1,9 +0,0 @@
TYPE=rtm-astro-recipe:6e6418fb
DOMAIN=resisttechmonopolies.online
## Domain aliases
#EXTRA_DOMAINS=', `www.website.resisttechmonopolies.online`'
LETS_ENCRYPT_ENV=production
VERSION=0.0.21
@@ -1,4 +1,4 @@
TYPE=shlink:0.1.0+4.4
TYPE=shlink:21d93464
DOMAIN=shlink.resisttechmonopolies.online
@@ -1,4 +1,4 @@
TYPE=uptime-kuma:3.0.0+2.2.1
TYPE=uptime-kuma:2.0.0+2.0.0-beta.1
COMPOSE_FILE="compose.yml"
LETS_ENCRYPT_ENV=production
@@ -1,4 +1,4 @@
TYPE=vaultwarden:2.1.3+1.35.4
TYPE=vaultwarden:2.1.1+1.34.3
DOMAIN=vw.resisttechmonopolies.online
LETS_ENCRYPT_ENV=production
@@ -1,4 +1,4 @@
TYPE=authentik:11.0.4+2026.2.1
TYPE=authentik:7.4.0+2025.6.3
TIMEOUT=900
ENABLE_AUTO_UPDATE=true
POST_DEPLOY_CMDS="worker set_admin_pass"
@@ -0,0 +1,31 @@
TYPE=draupnir:785815dd+U
DOMAIN=draupnir.resisttechmonopolies.online
## Domain aliases
#EXTRA_DOMAINS=', `www.draupnir.resisttechmonopolies.online`'
LETS_ENCRYPT_ENV=production
HOME_SERVER_URL="https://matrix.resisttechmonopolies.online"
RAW_HOMESERVER_URL="https://matrix.resisttechmonopolies.online"
DRAUPNIR_LOG_LEVEL="DEBUG"
# The room ID (or room alias) of the management room, anyone in this room can issue commands to Draupnir.
#
# Draupnir has no more granular access controls other than this, be sure you trust everyone in this room - secure it!
#
# This should be a room alias or room ID - not a matrix.to URL.
#
# Note: By default, Draupnir is fairly verbose - expect a lot of messages in this room.
# (see verboseLogging to adjust this a bit.)
MANAGEMENT_ROOM="!KTOGIJKnLqziezPzuO:matrix.org"
# If true (the default), Draupnir will only accept invites from users present in managementRoom.
AUTO_JOIN_ONLY_IF_MANAGER=true
# If `autojoinOnlyIfManager` is false, only the members in this space can invite
# the bot to new rooms.
# ACCEPT_INVITES_FROM_SPACE="!example:example.org"
ACCESS_TOKEN_VERSION=v1
@@ -0,0 +1,18 @@
TYPE=maubot:f5b93759+U
DOMAIN=maubot.resisttechmonopolies.online
## Domain aliases
#EXTRA_DOMAINS=', `www.maubot.resisttechmonopolies.online`'
LETS_ENCRYPT_ENV=production
HOMESERVER_HOST=matrix.resisttechmonopolies.online
# Client-server API URL
HOMESERVER_URL=https://matrix.resisttechmonopolies.online
ADMIN_USER_NAME=charlie
## Secrets
SECRET_ADMIN_PASSWORD_VERSION=v1
SECRET_HOMESERVER_REGISTRATION_VERSION=v1
@@ -19,5 +19,3 @@ abra app command nextcloud.resisttechmonopolies.online app run_occ "'db:add-miss
# Your installation has no default phone region set. This is required to validate phone numbers in the profile settings without a country code. To allow numbers without a country code, please add "default_phone_region" with the respective ISO 3166-1 code of the region to your config file.
# Solution found at: https://help.nextcloud.com/t/your-installation-has-no-default-phone-region-set/153632/3
abra app command nextcloud.resisttechmonopolies.online app run_occ "'config:system:set default_phone_region --value=\"us\"'"
# move shared folder: "Node for share not found": https://github.com/nextcloud/server/issues/46467#issuecomment-2336672900
abra app command nextcloud.resisttechmonopolies.online app run_occ "'sharing:delete-orphan-shares'"
@@ -0,0 +1,10 @@
TYPE=rtm-astro-recipe:6e6418f
DOMAIN=resisttechmonopolies.online
## Domain aliases
#EXTRA_DOMAINS=', `www.resisttechmonopolies.online`'
LETS_ENCRYPT_ENV=production
VERSION=0.0.10