mirror of
https://github.com/CPunch/openpunk-ansible.git
synced 2024-11-22 15:30:05 +00:00
Compare commits
2 Commits
06548bf135
...
3047267d19
Author | SHA1 | Date | |
---|---|---|---|
3047267d19 | |||
bea9cb3592 |
14
README.md
14
README.md
@ -3,7 +3,7 @@
|
|||||||
This is my failsafe (and also my helpful migration tool) for restoring the OpenPunk server. This handles setting everything back up, including:
|
This is my failsafe (and also my helpful migration tool) for restoring the OpenPunk server. This handles setting everything back up, including:
|
||||||
|
|
||||||
- gitea
|
- gitea
|
||||||
- sadly, no db migration is supported right now. maybe a future todo?
|
- backup and restoring are also supported
|
||||||
- blog
|
- blog
|
||||||
- cron job for grabbing the `HEAD` of https://github.com/CPunch/openpunk && building the hugo site
|
- cron job for grabbing the `HEAD` of https://github.com/CPunch/openpunk && building the hugo site
|
||||||
- tor mirror
|
- tor mirror
|
||||||
@ -30,6 +30,18 @@ ansible-playbook -i hosts --ask-vault-pass run.yml
|
|||||||
```
|
```
|
||||||
> NOTE: The 'secrets' directory has been omitted from this repo (so it's not going to run without the provided files)
|
> NOTE: The 'secrets' directory has been omitted from this repo (so it's not going to run without the provided files)
|
||||||
|
|
||||||
|
## Backup and restore
|
||||||
|
|
||||||
|
Backup Gitea using the 'backup' tag
|
||||||
|
```sh
|
||||||
|
ansible-playbook -i hosts run.yml --tags backup
|
||||||
|
```
|
||||||
|
|
||||||
|
then, restore from the backup using the 'restore' tag
|
||||||
|
```sh
|
||||||
|
ansible-playbook -i hosts run.yml --tags restore
|
||||||
|
```
|
||||||
|
|
||||||
## Example hosts file
|
## Example hosts file
|
||||||
```
|
```
|
||||||
[hosts]
|
[hosts]
|
||||||
|
@ -15,9 +15,15 @@
|
|||||||
- fail2ban
|
- fail2ban
|
||||||
- goaccess
|
- goaccess
|
||||||
- htop
|
- htop
|
||||||
|
- sqlite3
|
||||||
- zsh # :D
|
- zsh # :D
|
||||||
- python3-certbot-nginx
|
- python3-certbot-nginx
|
||||||
|
|
||||||
|
- name: Grab package facts
|
||||||
|
package_facts:
|
||||||
|
manager: auto
|
||||||
|
tags: always
|
||||||
|
|
||||||
- name: Setup zsh
|
- name: Setup zsh
|
||||||
user:
|
user:
|
||||||
name: "{{ ansible_user }}"
|
name: "{{ ansible_user }}"
|
||||||
|
@ -1,2 +1,3 @@
|
|||||||
---
|
---
|
||||||
giteaPort: 3000
|
giteaPort: 3000
|
||||||
|
giteaBackup: backups/gitea-dump.zip
|
@ -1,26 +1,51 @@
|
|||||||
---
|
---
|
||||||
|
# based on advice from https://docs.gitea.io/en-us/backup-and-restore/
|
||||||
|
|
||||||
- name: Stop Gitea
|
- name: Stop Gitea
|
||||||
systemd:
|
systemd:
|
||||||
name: gitea
|
name: gitea
|
||||||
enabled: yes
|
enabled: yes
|
||||||
state: stopped
|
state: stopped
|
||||||
|
tags: backup
|
||||||
|
|
||||||
|
- name: Make Temp dir
|
||||||
|
file:
|
||||||
|
path: /etc/gitea/temp
|
||||||
|
state: directory
|
||||||
|
owner: gitea
|
||||||
|
tags: backup
|
||||||
|
|
||||||
- name: Dump Gitea
|
- name: Dump Gitea
|
||||||
shell:
|
shell:
|
||||||
cmd: gitea dump -c /etc/gitea/app.ini --work-path=/etc/gitea --file=gitea-dump.zip
|
cmd: gitea dump -c /etc/gitea/app.ini --work-path=/etc/gitea --file=gitea-dump.zip --tempdir=/etc/gitea/temp
|
||||||
chdir: /etc/gitea
|
chdir: /etc/gitea
|
||||||
become: true
|
become: true
|
||||||
become_method: su
|
become_method: su
|
||||||
become_user: gitea
|
become_user: gitea
|
||||||
|
tags: backup
|
||||||
|
|
||||||
|
- name: Fetch backup
|
||||||
|
fetch:
|
||||||
|
src: /etc/gitea/gitea-dump.zip
|
||||||
|
dest: "{{ giteaBackup }}"
|
||||||
|
flat: true
|
||||||
|
tags: backup
|
||||||
|
|
||||||
|
- name: Remove remote dump
|
||||||
|
file:
|
||||||
|
path: "{{ giteaBackup }}"
|
||||||
|
state: absent
|
||||||
|
tags: backup
|
||||||
|
|
||||||
|
- name: Remove Temp
|
||||||
|
file:
|
||||||
|
path: /etc/gitea/temp
|
||||||
|
state: absent
|
||||||
|
tags: backup
|
||||||
|
|
||||||
- name: Start Gitea
|
- name: Start Gitea
|
||||||
systemd:
|
systemd:
|
||||||
name: gitea
|
name: gitea
|
||||||
enabled: yes
|
enabled: yes
|
||||||
state: started
|
state: started
|
||||||
|
tags: backup
|
||||||
- name: Fetch backup
|
|
||||||
fetch:
|
|
||||||
src: /etc/gitea/gitea-dump.zip
|
|
||||||
dest: backups/gitea-dump.zip
|
|
||||||
flat: true
|
|
@ -4,13 +4,7 @@
|
|||||||
path: /etc/apt/trusted.gpg.d/morph027-gitea.gpg
|
path: /etc/apt/trusted.gpg.d/morph027-gitea.gpg
|
||||||
register: gitea_key
|
register: gitea_key
|
||||||
|
|
||||||
- name: Grab package facts
|
- name: Add Gitea key, repository && install
|
||||||
package_facts:
|
|
||||||
manager: auto
|
|
||||||
|
|
||||||
- name: Install Gitea
|
|
||||||
block:
|
|
||||||
- name: Add Gitea key, repository && install
|
|
||||||
block:
|
block:
|
||||||
- name: Import Gitea key
|
- name: Import Gitea key
|
||||||
shell: curl -s https://packaging.gitlab.io/gitea/gpg.key | sudo gpg --no-default-keyring --keyring gnupg-ring:/etc/apt/trusted.gpg.d/morph027-gitea.gpg --import && sudo chmod 644 /etc/apt/trusted.gpg.d/morph027-gitea.gpg
|
shell: curl -s https://packaging.gitlab.io/gitea/gpg.key | sudo gpg --no-default-keyring --keyring gnupg-ring:/etc/apt/trusted.gpg.d/morph027-gitea.gpg --import && sudo chmod 644 /etc/apt/trusted.gpg.d/morph027-gitea.gpg
|
||||||
@ -24,22 +18,22 @@
|
|||||||
- name: Add Gitea package
|
- name: Add Gitea package
|
||||||
package:
|
package:
|
||||||
name: gitea
|
name: gitea
|
||||||
when: "'gitea' not in ansible_facts.packages"
|
|
||||||
|
|
||||||
- name: Configure Gitea
|
- name: Configure Gitea
|
||||||
template:
|
template:
|
||||||
src: templates/app.ini
|
src: templates/app.ini
|
||||||
dest: /etc/gitea/app.ini
|
dest: /etc/gitea/app.ini
|
||||||
owner: gitea
|
owner: gitea
|
||||||
force: no # we don't want to kill our existing config D:
|
when: "'gitea' not in ansible_facts.packages"
|
||||||
|
|
||||||
- name: Reload Gitea
|
- name: Backup db
|
||||||
systemd:
|
|
||||||
name: gitea
|
|
||||||
enabled: yes
|
|
||||||
state: started
|
|
||||||
|
|
||||||
- name: Backup db
|
|
||||||
include_tasks: backup.yml
|
include_tasks: backup.yml
|
||||||
tags: ['never', 'backup']
|
tags:
|
||||||
tags: ['gitea', 'backup']
|
- never
|
||||||
|
- backup
|
||||||
|
|
||||||
|
- name: Restore db
|
||||||
|
include_tasks: restore.yml
|
||||||
|
tags:
|
||||||
|
- never
|
||||||
|
- restore
|
||||||
|
@ -0,0 +1,92 @@
|
|||||||
|
---
|
||||||
|
# based on advice from https://docs.gitea.io/en-us/backup-and-restore/
|
||||||
|
|
||||||
|
- name: Stop Gitea
|
||||||
|
systemd:
|
||||||
|
name: gitea
|
||||||
|
enabled: yes
|
||||||
|
state: stopped
|
||||||
|
tags: restore
|
||||||
|
|
||||||
|
- name: Make restore dir
|
||||||
|
file:
|
||||||
|
path: /etc/gitea/gitea-dump
|
||||||
|
state: directory
|
||||||
|
owner: gitea
|
||||||
|
tags: restore
|
||||||
|
|
||||||
|
- name: Extract backup to host
|
||||||
|
unarchive:
|
||||||
|
src: "{{ giteaBackup }}"
|
||||||
|
dest: /etc/gitea/gitea-dump
|
||||||
|
owner: gitea
|
||||||
|
tags: restore
|
||||||
|
|
||||||
|
- name: Delete Gitea
|
||||||
|
file:
|
||||||
|
path: /var/lib/gitea
|
||||||
|
state: absent
|
||||||
|
tags: restore
|
||||||
|
|
||||||
|
- name: Create Gitea
|
||||||
|
file:
|
||||||
|
path: /var/lib/gitea
|
||||||
|
state: directory
|
||||||
|
owner: gitea
|
||||||
|
tags: restore
|
||||||
|
|
||||||
|
- name: Install data
|
||||||
|
copy:
|
||||||
|
src: /etc/gitea/gitea-dump/data/
|
||||||
|
dest: /var/lib/gitea/data
|
||||||
|
remote_src: true
|
||||||
|
owner: gitea
|
||||||
|
tags: restore
|
||||||
|
|
||||||
|
- name: Install log
|
||||||
|
copy:
|
||||||
|
src: /etc/gitea/gitea-dump/log/
|
||||||
|
dest: /var/lib/gitea/log/
|
||||||
|
remote_src: true
|
||||||
|
owner: gitea
|
||||||
|
tags: restore
|
||||||
|
ignore_errors: true
|
||||||
|
|
||||||
|
- name: Install repositories
|
||||||
|
copy:
|
||||||
|
src: /etc/gitea/gitea-dump/repos/
|
||||||
|
dest: /var/lib/gitea/gitea-repositories/
|
||||||
|
remote_src: true
|
||||||
|
owner: gitea
|
||||||
|
tags: restore
|
||||||
|
|
||||||
|
- name: Install config
|
||||||
|
copy:
|
||||||
|
src: /etc/gitea/gitea-dump/app.ini
|
||||||
|
dest: /etc/gitea/app.ini
|
||||||
|
owner: gitea
|
||||||
|
remote_src: true
|
||||||
|
tags: restore
|
||||||
|
|
||||||
|
- name: Generate sqlite3 db
|
||||||
|
shell: sqlite3 /var/lib/gitea/data/gitea.db </etc/gitea/gitea-dump/gitea-db.sql
|
||||||
|
become: true
|
||||||
|
become_method: su
|
||||||
|
become_user: gitea
|
||||||
|
tags: restore
|
||||||
|
|
||||||
|
- name: Start Gitea
|
||||||
|
systemd:
|
||||||
|
name: gitea
|
||||||
|
enabled: yes
|
||||||
|
state: started
|
||||||
|
tags: restore
|
||||||
|
|
||||||
|
- name: Finalize
|
||||||
|
shell:
|
||||||
|
cmd: ./gitea admin regenerate hooks -c /etc/gitea/app.ini
|
||||||
|
chdir: /usr/bin
|
||||||
|
become: true
|
||||||
|
become_method: su
|
||||||
|
become_user: gitea
|
||||||
|
tags: restore
|
@ -43,6 +43,7 @@ NO_REPLY_ADDRESS = noreply.localhost
|
|||||||
[picture]
|
[picture]
|
||||||
DISABLE_GRAVATAR = true
|
DISABLE_GRAVATAR = true
|
||||||
ENABLE_FEDERATED_AVATAR = false
|
ENABLE_FEDERATED_AVATAR = false
|
||||||
|
REPOSITORY_AVATAR_FALLBACK = random
|
||||||
|
|
||||||
[openid]
|
[openid]
|
||||||
ENABLE_OPENID_SIGNIN = false
|
ENABLE_OPENID_SIGNIN = false
|
||||||
|
@ -23,12 +23,6 @@
|
|||||||
force: no
|
force: no
|
||||||
notify: setup nginx
|
notify: setup nginx
|
||||||
|
|
||||||
- name: Uninstall nginx config for git.{{ domain }}
|
|
||||||
file:
|
|
||||||
path: /etc/nginx/conf.d/git.{{ domain }}.conf
|
|
||||||
state: absent
|
|
||||||
notify: setup nginx
|
|
||||||
|
|
||||||
- name: Install nginx config for our Hidden Service
|
- name: Install nginx config for our Hidden Service
|
||||||
template:
|
template:
|
||||||
src: templates/tor.conf
|
src: templates/tor.conf
|
||||||
|
@ -1,9 +1,6 @@
|
|||||||
---
|
---
|
||||||
- name: Setup certbot for {{ domain }}
|
- name: Setup certbot
|
||||||
shell: "certbot --nginx --non-interactive --agree-tos -m {{ contact_email }} -d {{ domain }}"
|
shell: "certbot --nginx --non-interactive --agree-tos --email {{ contact_email }} -d {{ domain }} -d git.{{ domain }}"
|
||||||
|
|
||||||
- name: Setup certbot for git.{{ domain }}
|
|
||||||
shell: "certbot --nginx --non-interactive --agree-tos -m {{ contact_email }} -d git.{{ domain }}"
|
|
||||||
|
|
||||||
- name: Reload Nginx
|
- name: Reload Nginx
|
||||||
systemd:
|
systemd:
|
||||||
|
4
run.yml
4
run.yml
@ -11,10 +11,12 @@
|
|||||||
- role: essential
|
- role: essential
|
||||||
- role: firewall
|
- role: firewall
|
||||||
- role: git
|
- role: git
|
||||||
|
tags: secrets
|
||||||
- role: deadswitch
|
- role: deadswitch
|
||||||
|
tags: secrets
|
||||||
- role: blog
|
- role: blog
|
||||||
- role: gitea
|
- role: gitea
|
||||||
tags: [backup]
|
|
||||||
- role: nginx
|
- role: nginx
|
||||||
- role: goaccess
|
- role: goaccess
|
||||||
- role: tor
|
- role: tor
|
||||||
|
tags: secrets
|
Loading…
Reference in New Issue
Block a user