03d2f6d57a
- scripts/run-bootstrap.sh: copies and runs the deploy user bootstrap on a fresh server, verifies SSH login, checks vault as a preflight step - scripts/bootstrap-deploy-user.sh: runs on the server as root, accepts the SSH public key as an argument (read from keys/ by run-bootstrap.sh) - scripts/check-vault.sh: decrypts vault.yml and verifies all 11 required secrets are present and non-empty - docs/runbook.md: restructured into correct order (collections → DNS → vault → bootstrap → playbook), added scripts reference table, moved first-run notes for Gitea/Keycloak/registry into their own section - README.md: added scripts/ to repo layout
80 lines
2.5 KiB
Markdown
80 lines
2.5 KiB
Markdown
Info:
|
|
--
|
|
Server:
|
|
Strato STRATO VPS Linux VC4-8
|
|
Order Number: 9478462
|
|
|
|
Customer Number: 73171334
|
|
Customer Login: https://www.strato.de/apps/CustomerService
|
|
|
|
Cores: 4 Cores
|
|
RAM: 8 GB RAM
|
|
Storage: 240 HDD
|
|
|
|
IPv4: 217.154.207.148
|
|
IPv6: 2a01:239:35b:c400::1
|
|
|
|
OS: Ubuntu 24.04 LTS
|
|
|
|
DNS Names:
|
|
cloud.ladkau.de
|
|
gitea.ladkau.de
|
|
nextcloud.ladkau.de
|
|
sso.ladkau.de
|
|
mail.ladkau.de
|
|
cr.ladkau.de
|
|
k8s.ladkau.de
|
|
|
|
Purpose:
|
|
--
|
|
This repository tracks the complete server configuration so the server can be
|
|
fully reinstalled from scratch using only this repo. Every configuration change
|
|
must be committed here. The git history serves as the change log.
|
|
|
|
Architecture:
|
|
--
|
|
Provisioning: Ansible
|
|
Ansible playbooks configure the OS and deploy all services. Roles are
|
|
idempotent — re-running them brings the server back to the desired state
|
|
without side effects. The master playbook is ansible/site.yml.
|
|
|
|
Service runtime: Docker Compose
|
|
Each service runs as a Docker Compose stack. Compose files live inside
|
|
their respective Ansible roles (roles/<service>/files/docker-compose.yml).
|
|
This keeps service definition and deployment config together.
|
|
|
|
Reverse proxy / TLS: Traefik
|
|
Traefik is the single entry point for all HTTP/HTTPS traffic. It runs as
|
|
a Docker Compose service and routes to other containers via Docker labels.
|
|
TLS certificates are issued automatically via Let's Encrypt (ACME).
|
|
|
|
Repo layout:
|
|
--
|
|
ansible/
|
|
inventory.ini # host address and connection vars
|
|
site.yml # master playbook — runs all roles in order
|
|
group_vars/all.yml # shared variables (domains, image versions, ...)
|
|
roles/
|
|
base/ # OS hardening, non-root user, SSH, ufw firewall
|
|
docker/ # Docker Engine + Compose plugin install
|
|
traefik/ # reverse proxy, TLS termination
|
|
gitea/ # self-hosted Git
|
|
nextcloud/ # file storage and collaboration
|
|
sso/ # Single Sign-On
|
|
mail/ # mail server
|
|
registry/ # container registry (cr.ladkau.de)
|
|
k8s/ # k3s Kubernetes node
|
|
docs/
|
|
runbook.md # step-by-step reinstall instructions
|
|
scripts/
|
|
run-bootstrap.sh # bootstrap deploy user on a fresh server
|
|
bootstrap-deploy-user.sh # runs on server as root — creates deploy user
|
|
check-vault.sh # verify vault.yml has all required secrets
|
|
keys/
|
|
*.pub # public SSH keys (private keys are gitignored)
|
|
|
|
SSH keys:
|
|
--
|
|
root_cloud_ladkau_de — root access (initial setup only)
|
|
notroot_cloud_ladkau_de — non-root deploy user (used by Ansible)
|