clean old ssh config, split network, improve caddy config

This commit is contained in:
2026-05-15 00:48:31 +02:00
parent 4bb3fe6d98
commit 54cc6f0802
57 changed files with 271 additions and 226 deletions
+2 -2
View File
@@ -24,8 +24,8 @@
PROJECT_DIRECTORY := infrastructure PROJECT_DIRECTORY := infrastructure
CONFIG_DIRECTORY := presets CONFIG_DIRECTORY := presets
# 7dtd minecraft satisfactory # 7dtd minecraft satisfactory torrent
CONFIGS := minecraft satisfactory CONFIGS := torrent
#DOCKER_PROFILES := #DOCKER_PROFILES :=
include DockerCompose.mk include DockerCompose.mk
+25 -13
View File
@@ -1,6 +1,6 @@
# Infrastructure # Infrastructure
_Open source, decentralized and self-hosted infrastructure for many services._ _Open source, decentralized and self-hosted infrastructure for many local services._
## About ## About
@@ -12,19 +12,25 @@ If you have any **questions** or **suggestions**, feel free to open an issue or
- [x] caddy 2 HTTP/S reverse proxy - [x] caddy 2 HTTP/S reverse proxy
- [x] Docker / docker-compose - [x] Docker / docker-compose
- [x] Wordpress (Via FASTCGI/caddy) - [x] Homepage (Dashboard)
- [x] Jellyfin (Media server) - [x] Jellyfin (Eg Netflix, Disney+)
- [x] Forgejo (Git server, fork of Gitea) - [x] Forgejo (Git server, fork of Gitea)
- [x] Uptime Kuma (Monitoring) - [x] Uptime Kuma (Monitoring)
- [x] Argus (Application update monitoring)
- [x] qbittorrent and transmission (Torrent client/server) - [x] qbittorrent and transmission (Torrent client/server)
- [x] SyncThing (File synchronization) - [x] SyncThing (File synchronization)
- [x] Dufs (File server)
- [x] PsiTransfer, ProjectSend, Picoshare (File sharing) - [x] PsiTransfer, ProjectSend, Picoshare (File sharing)
- [x] it-tools and omni-tools (Tools for IT) - [x] it-tools, omni-tools and cyberchef (Tools for IT)
- [x] Open-WebUI (Local chatGPT) - [x] Open-WebUI + Ollama (Local chatGPT)
- [x] Privatebin (Pastebin) - [x] Privatebin (Pastebin)
- [X] [Satisfactory](https://github.com/bensuperpc/docker-satisfactory) - [x] Memos (Note-taking)
- [x] [7 days to die](https://github.com/bensuperpc/docker-7daystodie) - [x] Stirling PDF (PDF tools)
- [x] [minecraft](https://github.com/bensuperpc/docker-minecraft-server) - [x] Wordpress (Via FASTCGI/caddy)
- [X] Satisfactory
- [x] 7 days to die
- [x] Minecraft
- [x] Team Fortress 2
## Architecture ## Architecture
@@ -45,7 +51,7 @@ The homepage is a dashboard with many widgets and services.
- [Git](https://git-scm.com/book/en/v2/Getting-Started-Installing-Git) - [Git](https://git-scm.com/book/en/v2/Getting-Started-Installing-Git)
- [Web domain](https://www.ovh.com/world/domains/) (I use OVH) - [Web domain](https://www.ovh.com/world/domains/) (I use OVH)
- [Open port 80, 443, 22, 2222 and 5555 on your router](http://192.168.1.1/) - [Open port 80, 443, 22, 2222 and 5555 on your router](http://192.168.1.1/)
- For games server, you need to open these ports (7777, 25565, 26900, 26901, 26903) - For games server, you need to open these ports (7777, 8888, 25565, 26900, 26901, 26903)
List of ports used by the services in this infrastructure: List of ports used by the services in this infrastructure:
@@ -56,10 +62,13 @@ List of ports used by the services in this infrastructure:
| 22 | Forgejo | Git/SSH access | | 22 | Forgejo | Git/SSH access |
| 2222 | OpenSSH | Global SSH access | | 2222 | OpenSSH | Global SSH access |
| 7777 | Satisfactory | Game server port | | 7777 | Satisfactory | Game server port |
| 8888 | Satisfactory | Game server port |
| 25565 | Minecraft | Game server port | | 25565 | Minecraft | Game server port |
| 8100 | Bluemap Minecraft | Web map port |
| 26900 | 7 Days to Die | Game server port | | 26900 | 7 Days to Die | Game server port |
| 26901 | 7 Days to Die | Game server port | | 26901 | 7 Days to Die | Game server port |
| 26903 | 7 Days to Die | Game server port | | 26903 | 7 Days to Die | Game server port |
| 27015 | Team Fortress 2 | Game server port |
**To avoid get rate limit from letsencrypt (10 certificates per 3 hours), you need to disable some certificates in the caddyfiles and enable them 3h later...** **To avoid get rate limit from letsencrypt (10 certificates per 3 hours), you need to disable some certificates in the caddyfiles and enable them 3h later...**
@@ -113,8 +122,9 @@ And then, caddy will generate the certificate for you and renew it automatically
| [projectsend.bensuperpc.org](https://projectsend.bensuperpc.org) | Sub | ProjectSend for file sharing | | [projectsend.bensuperpc.org](https://projectsend.bensuperpc.org) | Sub | ProjectSend for file sharing |
| [picoshare.bensuperpc.org](https://picoshare.bensuperpc.org) | Sub | Picoshare for file sharing | | [picoshare.bensuperpc.org](https://picoshare.bensuperpc.org) | Sub | Picoshare for file sharing |
| [dufs.bensuperpc.org](https://dufs.bensuperpc.org) | Sub | Dufs for file sharing | | [dufs.bensuperpc.org](https://dufs.bensuperpc.org) | Sub | Dufs for file sharing |
| [memos.bensuperpc.org](https://memos.bensuperpc.org) | Sub | Caddy for file sharing | | [memos.bensuperpc.org](https://memos.bensuperpc.org) | Sub | Memos note-taking app |
| [stirlingpdf.bensuperpc.org](https://stirlingpdf.bensuperpc.org) | Sub | Stirling PDF tools | | [stirlingpdf.bensuperpc.org](https://stirlingpdf.bensuperpc.org) | Sub | Stirling PDF tools |
| [argus.bensuperpc.org](https://argus.bensuperpc.org) | Sub | Argus for monitoring application updates |
### Configure the infrastructure ### Configure the infrastructure
@@ -236,10 +246,10 @@ docker exec -it ollama ollama run deepseek-r1:8b
Start the website with: Start the website with:
```sh ```sh
make start-at make start-detached
``` ```
Stop the website with (or CTRL+C with the previous command): Stop the website with:
```sh ```sh
make stop make stop
@@ -274,7 +284,7 @@ Once the installation is complete, you need to set the installation lock:
FORGEJO__security__INSTALL_LOCK=true FORGEJO__security__INSTALL_LOCK=true
``` ```
### Forgejo Runner ### Forgejo Runner (Out of date)
```sh ```sh
docker exec -it forgejo_runner /bin/bash docker exec -it forgejo_runner /bin/bash
@@ -374,6 +384,8 @@ To activate the alternative webui theme (VueTorrent), you need to go in the qbit
- [Forgejo-runner](https://code.forgejo.org/forgejo/runner) - [Forgejo-runner](https://code.forgejo.org/forgejo/runner)
- [Forgejo-runner](https://huijzer.xyz/posts/55) - [Forgejo-runner](https://huijzer.xyz/posts/55)
- [Forgejo](https://nickcunningh.am/blog/how-to-setup-and-configure-forgejo-with-support-for-forgejo-actions-and-more) - [Forgejo](https://nickcunningh.am/blog/how-to-setup-and-configure-forgejo-with-support-for-forgejo-actions-and-more)
- [Argus](https://github.com/release-argus/Argus)
- [Forgejo-runner](https://huijzer.xyz/posts/55)
## License ## License
+2
View File
@@ -41,6 +41,8 @@ include:
- services/uptime-kuma/docker-compose.uptime-kuma.yml - services/uptime-kuma/docker-compose.uptime-kuma.yml
# open-webui # open-webui
- services/open-webui/docker-compose.open-webui.yml - services/open-webui/docker-compose.open-webui.yml
# Memos
- services/memos/docker-compose.memos.yml
# Argus # Argus
- services/argus/docker-compose.argus.yml - services/argus/docker-compose.argus.yml
# Minecraft # Minecraft
@@ -19,7 +19,7 @@ services:
- 7daystodie_server_file:/home/sdtdserver/serverfiles # Optional - serverfiles folder - 7daystodie_server_file:/home/sdtdserver/serverfiles # Optional - serverfiles folder
- 7daystodie_server_log:/home/sdtdserver/log - 7daystodie_server_log:/home/sdtdserver/log
networks: networks:
- infra-network - 7daystodie-network
env_file: env_file:
- ./env/7daystodie.env - ./env/7daystodie.env
environment: environment:
@@ -49,6 +49,7 @@ volumes:
name: 7daystodie_server_log name: 7daystodie_server_log
networks: networks:
infra-network: 7daystodie-network:
driver: bridge driver: bridge
name: infra-network name: 7daystodie-network
@@ -12,7 +12,7 @@ services:
depends_on: depends_on:
- caddy - caddy
networks: networks:
- infra-network - argus-network
volumes: volumes:
- argus_data:/app/data/ - argus_data:/app/data/
- ./config/config.yml:/app/config.yml - ./config/config.yml:/app/config.yml
@@ -26,3 +26,8 @@ services:
volumes: volumes:
argus_data: argus_data:
name: argus_data name: argus_data
networks:
argus-network:
driver: bridge
name: argus-network
@@ -1,3 +1,3 @@
argus.{$MAIN_DOMAIN} { argus.{$MAIN_DOMAIN} {
reverse_proxy argus:8080 reverse_proxy {$ARGUS_ADDRESS}
} }
@@ -1,5 +1,5 @@
git.{$MAIN_DOMAIN} { git.{$MAIN_DOMAIN} {
reverse_proxy forgejo:3000 reverse_proxy {$FORGEJO_ADDRESS}
} }
forgejo.{$MAIN_DOMAIN} { forgejo.{$MAIN_DOMAIN} {
@@ -1,3 +1,3 @@
homepage.{$MAIN_DOMAIN} { homepage.{$MAIN_DOMAIN} {
reverse_proxy homepage:3000 reverse_proxy {$HOMEPAGE_ADDRESS}
} }
@@ -1,5 +1,5 @@
jellyfin.{$MAIN_DOMAIN} { jellyfin.{$MAIN_DOMAIN} {
reverse_proxy jellyfin:8096 reverse_proxy {$JELLYFIN_ADDRESS}
header { header {
import header_common import header_common
} }
@@ -1,3 +1,3 @@
memos.{$MAIN_DOMAIN} { memos.{$MAIN_DOMAIN} {
reverse_proxy memos:5230 reverse_proxy {$MEMOS_ADDRESS}
} }
@@ -1,3 +1,3 @@
open-webui.{$MAIN_DOMAIN} { open-webui.{$MAIN_DOMAIN} {
reverse_proxy open-webui:8080 reverse_proxy {$OPEN_WEBUI_ADDRESS}
} }
@@ -1,3 +1,3 @@
picoshare.{$MAIN_DOMAIN} { picoshare.{$MAIN_DOMAIN} {
reverse_proxy picoshare:4001 reverse_proxy {$PICOSHARE_ADDRESS}
} }
@@ -1,5 +1,5 @@
privatebin.{$MAIN_DOMAIN} { privatebin.{$MAIN_DOMAIN} {
reverse_proxy privatebin:8080 reverse_proxy {$PRIVATEBIN_ADDRESS}
} }
pastebin.{$MAIN_DOMAIN} { pastebin.{$MAIN_DOMAIN} {
@@ -1,3 +1,3 @@
projectsend.{$MAIN_DOMAIN} { projectsend.{$MAIN_DOMAIN} {
reverse_proxy projectsend:80 reverse_proxy {$PROJECTSEND_ADDRESS}
} }
@@ -1,5 +1,5 @@
transfer.{$MAIN_DOMAIN} { transfer.{$MAIN_DOMAIN} {
reverse_proxy psitransfer:3000 reverse_proxy {$PSITRANSFER_ADDRESS}
} }
psitransfer.{$MAIN_DOMAIN} { psitransfer.{$MAIN_DOMAIN} {
@@ -1,5 +1,5 @@
torrent.{$MAIN_DOMAIN} { torrent.{$MAIN_DOMAIN} {
reverse_proxy qbittorrent:8080 reverse_proxy {$QBITTORRENT_ADDRESS}
header { header {
Cache-Control "no-store" Cache-Control "no-store"
import header_common import header_common
@@ -1,3 +1,3 @@
stirlingpdf.{$MAIN_DOMAIN} { stirlingpdf.{$MAIN_DOMAIN} {
reverse_proxy stirlingpdf:8080 reverse_proxy {$STIRLINGPDF_ADDRESS}
} }
@@ -1,5 +1,5 @@
syncthing.{$MAIN_DOMAIN} { syncthing.{$MAIN_DOMAIN} {
reverse_proxy syncthing:8384 { reverse_proxy {$SYNCTHING_ADDRESS} {
header_up Host {upstream_hostport} header_up Host {upstream_hostport}
} }
} }
@@ -1,3 +1,3 @@
transmission.{$MAIN_DOMAIN} { transmission.{$MAIN_DOMAIN} {
reverse_proxy transmission:9091 reverse_proxy {$TRANSMISSION_ADDRESS}
} }
@@ -1,5 +1,5 @@
uptimekuma.{$MAIN_DOMAIN} { uptimekuma.{$MAIN_DOMAIN} {
reverse_proxy uptime-kuma:3001 reverse_proxy {$UPTIMEKUMA_ADDRESS}
header { header {
Cache-Control "no-store" Cache-Control "no-store"
import header_common import header_common
@@ -1,6 +1,6 @@
wordpress.{$MAIN_DOMAIN} { wordpress.{$MAIN_DOMAIN} {
root * /var/www/html root * /var/www/html
php_fastcgi wordpress:9000 php_fastcgi {$WORDPRESS_ADDRESS}
file_server file_server
encode zstd gzip encode zstd gzip
@@ -23,7 +23,30 @@ services:
- public_data:/public_data:ro - public_data:/public_data:ro
networks: networks:
- infra-network - qbittorrent-network
- syncthing-network
- jellyfin-network
- forgejo-network
- argus-network
- it-tools-network
- homepage-network
- dufs-network
- cyberchef-network
- open-webui-network
- uptimekuma-network
- stirlingpdf-network
- psitransfer-network
- transmission-network
- projectsend-network
- omni-tools-network
- privatebin-network
- picoshare-network
- memos-network
# - satisfactory-network
# - teamfortress2-network
# - minecraft-network
# - 7daystodie-network
# - openssh-network
env_file: env_file:
- ./env/caddy.env - ./env/caddy.env
security_opt: security_opt:
+17
View File
@@ -1,2 +1,19 @@
MAIN_DOMAIN=bensuperpc.org MAIN_DOMAIN=bensuperpc.org
MAIL_DOMAIN=bensuperpc@gmail.com MAIL_DOMAIN=bensuperpc@gmail.com
# Services
JELLYFIN_ADDRESS=jellyfin:8096
QBITTORRENT_ADDRESS=qbittorrent:8080
ARGUS_ADDRESS=argus:8080
FORGEJO_ADDRESS=forgejo:3000
UPTIMEKUMA_ADDRESS=uptime-kuma:3001
MEMOS_ADDRESS=memos:5230
HOMEPAGE_ADDRESS=homepage:3000
OPEN_WEBUI_ADDRESS=open-webui:8080
PICOSHARE_ADDRESS=picoshare:4001
PRIVATEBIN_ADDRESS=privatebin:8080
PROJECTSEND_ADDRESS=projectsend:80
STIRLINGPDF_ADDRESS=stirlingpdf:8080
SYNCTHING_ADDRESS=syncthing:8384
TRANSMISSION_ADDRESS=transmission:9091
PSITRANSFER_ADDRESS=psitransfer:3000
WORDPRESS_ADDRESS=wordpress:9000
@@ -9,7 +9,7 @@ services:
depends_on: depends_on:
- caddy - caddy
networks: networks:
- infra-network - cyberchef-network
read_only: false read_only: false
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
@@ -34,7 +34,7 @@ services:
depends_on: depends_on:
- caddy - caddy
networks: networks:
- infra-network - cyberchef-network
read_only: false read_only: false
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
@@ -49,3 +49,8 @@ services:
reservations: reservations:
cpus: '0.001' cpus: '0.001'
memory: 20M memory: 20M
networks:
cyberchef-network:
driver: bridge
name: cyberchef-network
@@ -14,7 +14,7 @@ services:
volumes: volumes:
- public_data:/data - public_data:/data
networks: networks:
- infra-network - dufs-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
@@ -23,3 +23,8 @@ volumes:
name: public_data name: public_data
private_data: private_data:
name: private_data name: private_data
networks:
dufs-network:
driver: bridge
name: dufs-network
@@ -1,7 +1,7 @@
services: services:
# forgejo # forgejo
forgejo: forgejo:
image: codeberg.org/forgejo/forgejo:13 image: codeberg.org/forgejo/forgejo:15
container_name: forgejo container_name: forgejo
profiles: profiles:
- forgejo - forgejo
@@ -18,7 +18,7 @@ services:
- /etc/timezone:/etc/timezone:ro - /etc/timezone:/etc/timezone:ro
- /etc/localtime:/etc/localtime:ro - /etc/localtime:/etc/localtime:ro
networks: networks:
- infra-network - forgejo-network
# user: ${PUID:-1000}:${PGID:-1000} # user: ${PUID:-1000}:${PGID:-1000}
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
@@ -38,7 +38,7 @@ services:
- ./env/forgejo_db.env - ./env/forgejo_db.env
command: '--default-authentication-plugin=mysql_native_password' command: '--default-authentication-plugin=mysql_native_password'
networks: networks:
- infra-network - forgejo-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
@@ -48,7 +48,7 @@ services:
container_name: 'docker_dind' container_name: 'docker_dind'
hostname: docker hostname: docker
networks: networks:
- infra-network - forgejo-network
profiles: profiles:
- forgejo-runner - forgejo-runner
privileged: true privileged: true
@@ -61,11 +61,9 @@ services:
forgejo_runner: forgejo_runner:
image: data.forgejo.org/forgejo/runner:12 image: data.forgejo.org/forgejo/runner:12
networks: networks:
- infra-network - forgejo-network
profiles: profiles:
- forgejo-runner - forgejo-runner
links:
- docker-in-docker
depends_on: depends_on:
docker-in-docker: docker-in-docker:
condition: service_started condition: service_started
@@ -91,3 +89,8 @@ volumes:
name: forgejo_certs name: forgejo_certs
forgejo_runner: forgejo_runner:
name: forgejo_runner name: forgejo_runner
networks:
forgejo-network:
driver: bridge
name: forgejo-network
@@ -8,68 +8,68 @@
href: https://wordpress.bensuperpc.org/ href: https://wordpress.bensuperpc.org/
description: Wordpress description: Wordpress
ping: wordpress.bensuperpc.org ping: wordpress.bensuperpc.org
container: wordpress # container: wordpress
- jellyfin: - jellyfin:
icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/jellyfin.png icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/jellyfin.png
href: https://jellyfin.bensuperpc.org/ href: https://jellyfin.bensuperpc.org/
description: Jellyfin description: Jellyfin
ping: jellyfin.bensuperpc.org ping: jellyfin.bensuperpc.org
container: jellyfin # container: jellyfin
- projectsend: - projectsend:
icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/projectsend.png icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/projectsend.png
href: https://projectsend.bensuperpc.org/ href: https://projectsend.bensuperpc.org/
description: ProjectSend description: ProjectSend
ping: projectsend.bensuperpc.org ping: projectsend.bensuperpc.org
container: projectsend # container: projectsend
- Sharing: - Sharing:
- psitransfer: - psitransfer:
icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/psitransfer.png icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/psitransfer.png
href: https://psitransfer.bensuperpc.org/ href: https://psitransfer.bensuperpc.org/
description: PsiTransfer description: PsiTransfer
ping: psitransfer.bensuperpc.org ping: psitransfer.bensuperpc.org
container: psitransfer # container: psitransfer
- picoshare: - picoshare:
# icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/picoshare.png # icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/picoshare.png
href: https://picoshare.bensuperpc.org/ href: https://picoshare.bensuperpc.org/
description: PicoShare description: PicoShare
ping: picoshare.bensuperpc.org ping: picoshare.bensuperpc.org
container: picoshare # container: picoshare
- privatebin: - privatebin:
icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/privatebin.png icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/privatebin.png
href: https://privatebin.bensuperpc.org/ href: https://privatebin.bensuperpc.org/
description: PrivateBin description: PrivateBin
ping: privatebin.bensuperpc.org ping: privatebin.bensuperpc.org
container: privatebin # container: privatebin
- qbittorrent: - qbittorrent:
icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/qbittorrent.png icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/qbittorrent.png
href: https://qbittorrent.bensuperpc.org/ href: https://qbittorrent.bensuperpc.org/
description: qBittorrent description: qBittorrent
ping: qbittorrent.bensuperpc.org ping: qbittorrent.bensuperpc.org
container: qbittorrent # container: qbittorrent
- syncthing: - syncthing:
icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/syncthing.png icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/syncthing.png
href: https://syncthing.bensuperpc.org/ href: https://syncthing.bensuperpc.org/
description: Syncthing description: Syncthing
ping: syncthing.bensuperpc.org ping: syncthing.bensuperpc.org
container: syncthing # container: syncthing
- transmission: - transmission:
icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/transmission.png icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/transmission.png
href: https://transmission.bensuperpc.org/ href: https://transmission.bensuperpc.org/
description: Transmission description: Transmission
ping: transmission.bensuperpc.org ping: transmission.bensuperpc.org
container: transmission # container: transmission
- dufs: - dufs:
# icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/dufs.png # icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/dufs.png
href: https://dufs.bensuperpc.org/ href: https://dufs.bensuperpc.org/
description: Dufs description: Dufs
ping: dufs.bensuperpc.org ping: dufs.bensuperpc.org
container: dufs # container: dufs
# - caddy: # - caddy:
# icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/caddy.png # icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/caddy.png
# href: https://public.bensuperpc.org/ # href: https://public.bensuperpc.org/
# description: File browser # description: File browser
# ping: public.bensuperpc.org # ping: public.bensuperpc.org
# container: caddy # # container: caddy
- Utils: - Utils:
- it-tools: - it-tools:
@@ -77,37 +77,37 @@
href: https://it-tools.bensuperpc.org/ href: https://it-tools.bensuperpc.org/
description: IT Tools description: IT Tools
ping: it-tools.bensuperpc.org ping: it-tools.bensuperpc.org
container: it-tools0 # container: it-tools0
- omni-tools: - omni-tools:
icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/it-tools.png icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/it-tools.png
href: https://omni-tools.bensuperpc.org/ href: https://omni-tools.bensuperpc.org/
description: Omni Tools description: Omni Tools
ping: omni-tools.bensuperpc.org ping: omni-tools.bensuperpc.org
container: omni-tools0 # container: omni-tools0
- cyberchef: - cyberchef:
icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/cyberchef.png icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/cyberchef.png
href: https://cyberchef.bensuperpc.org/ href: https://cyberchef.bensuperpc.org/
description: CyberChef description: CyberChef
ping: cyberchef.bensuperpc.org ping: cyberchef.bensuperpc.org
container: cyberchef0 # container: cyberchef0
- stirlingpdf: - stirlingpdf:
#icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/stirlingpdf.png #icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/stirlingpdf.png
href: https://stirlingpdf.bensuperpc.org/ href: https://stirlingpdf.bensuperpc.org/
description: StirlingPDF description: StirlingPDF
ping: stirlingpdf.bensuperpc.org ping: stirlingpdf.bensuperpc.org
container: stirlingpdf # container: stirlingpdf
- forgejo: - forgejo:
icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/forgejo.png icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/forgejo.png
href: https://forgejo.bensuperpc.org/ href: https://forgejo.bensuperpc.org/
description: Forgejo description: Forgejo
ping: forgejo.bensuperpc.org ping: forgejo.bensuperpc.org
container: forgejo # container: forgejo
- open-webui: - open-webui:
icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/open-webui.png icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/open-webui.png
href: https://open-webui.bensuperpc.org/ href: https://open-webui.bensuperpc.org/
description: ChatGPT local description: ChatGPT local
ping: open-webui.bensuperpc.org ping: open-webui.bensuperpc.org
container: open-webui # container: open-webui
- Games: - Games:
- minecraft: - minecraft:
@@ -115,19 +115,19 @@
# href: https://minecraft.bensuperpc.org/ # href: https://minecraft.bensuperpc.org/
description: Minecraft server description: Minecraft server
# ping: minecraft.bensuperpc.org # ping: minecraft.bensuperpc.org
container: minecraft-server # container: minecraft-server
- 7dtd: - 7dtd:
# icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/7dtd.png # icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/7dtd.png
# href: https://7dtd.bensuperpc.org/ # href: https://7dtd.bensuperpc.org/
description: 7 Days to Die server description: 7 Days to Die server
# ping: 7dtd.bensuperpc.org # ping: 7dtd.bensuperpc.org
container: 7daystodie_server # container: 7daystodie_server
- satisfactory: - satisfactory:
# icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/7dtd.png # icon: https://cdn.jsdelivr.net/gh/walkxcode/dashboard-icons@master/png/7dtd.png
# href: https://7dtd.bensuperpc.org/ # href: https://7dtd.bensuperpc.org/
description: Satisfactory server description: Satisfactory server
# ping: 7dtd.bensuperpc.org # ping: 7dtd.bensuperpc.org
container: satisfactory_server # container: satisfactory_server
- Admin: - Admin:
- uptime-kuma: - uptime-kuma:
@@ -135,5 +135,5 @@
href: https://uptimekuma.bensuperpc.org/ href: https://uptimekuma.bensuperpc.org/
description: Uptime Kuma description: Uptime Kuma
ping: uptimekuma.bensuperpc.org ping: uptimekuma.bensuperpc.org
container: uptime-kuma # container: uptime-kuma
@@ -24,10 +24,15 @@ services:
# path: ./homepage/image # path: ./homepage/image
# target: /app/public/image # target: /app/public/image
networks: networks:
- infra-network - homepage-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
volumes: volumes:
homepage_log: homepage_log:
name: homepage_log name: homepage_log
networks:
homepage-network:
driver: bridge
name: homepage-network
@@ -9,7 +9,7 @@ services:
depends_on: depends_on:
- caddy - caddy
networks: networks:
- infra-network - it-tools-network
read_only: false read_only: false
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
@@ -34,7 +34,7 @@ services:
depends_on: depends_on:
- caddy - caddy
networks: networks:
- infra-network - it-tools-network
read_only: false read_only: false
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
@@ -49,3 +49,8 @@ services:
reservations: reservations:
cpus: '0.001' cpus: '0.001'
memory: 20M memory: 20M
networks:
it-tools-network:
driver: bridge
name: it-tools-network
@@ -22,7 +22,7 @@ services:
devices: devices:
- /dev/dri:/dev/dri - /dev/dri:/dev/dri
networks: networks:
- infra-network - jellyfin-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
@@ -35,3 +35,8 @@ volumes:
name: public_data name: public_data
private_data: private_data:
name: private_data name: private_data
networks:
jellyfin-network:
driver: bridge
name: jellyfin-network
@@ -32,8 +32,3 @@ volumes:
name: public_data name: public_data
private_data: private_data:
name: private_data name: private_data
networks:
infra-network:
driver: bridge
name: infra-network
@@ -13,10 +13,15 @@ services:
volumes: volumes:
- memos_config:/var/opt/memos - memos_config:/var/opt/memos
networks: networks:
- infra-network - memos-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
volumes: volumes:
memos_config: memos_config:
name: memos_config name: memos_config
networks:
memos-network:
driver: bridge
name: memos-network
@@ -1,5 +1,5 @@
include: include:
# Minecraft server # Minecraft server
- minecraft-server/docker-compose.yml - minecraft-server/docker-compose.minecraft.yml
# Backup server # Backup server
- backup/docker-compose.backup.yml - backup/docker-compose.backup.yml
@@ -23,7 +23,7 @@ services:
volumes: volumes:
- minecraft_proxy_data:/server - minecraft_proxy_data:/server
networks: networks:
- infra-network - minecraft-network
mc-server: mc-server:
image: itzg/minecraft-server:latest image: itzg/minecraft-server:latest
@@ -56,7 +56,7 @@ services:
- minecraft_server_data:/data - minecraft_server_data:/data
# - ./asset_links/plugins.txt:/extras/plugins.txt:ro # - ./asset_links/plugins.txt:/extras/plugins.txt:ro
networks: networks:
- infra-network - minecraft-network
deploy: deploy:
resources: resources:
# limits: # limits:
@@ -90,7 +90,7 @@ services:
volumes: volumes:
- minecraft_rcon_data:/opt/rcon-web-admin/db - minecraft_rcon_data:/opt/rcon-web-admin/db
networks: networks:
- infra-network - minecraft-network
volumes: volumes:
minecraft_server_data: minecraft_server_data:
@@ -101,6 +101,6 @@ volumes:
name: minecraft_rcon_data name: minecraft_rcon_data
networks: networks:
infra-network: minecraft-network:
driver: bridge driver: bridge
name: infra-network name: minecraft-network
@@ -9,7 +9,7 @@ services:
depends_on: depends_on:
- caddy - caddy
networks: networks:
- infra-network - omni-tools-network
read_only: false read_only: false
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
@@ -34,7 +34,7 @@ services:
depends_on: depends_on:
- caddy - caddy
networks: networks:
- infra-network - omni-tools-network
read_only: false read_only: false
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
@@ -49,3 +49,8 @@ services:
reservations: reservations:
cpus: '0.001' cpus: '0.001'
memory: 20M memory: 20M
networks:
omni-tools-network:
driver: bridge
name: omni-tools-network
@@ -17,7 +17,7 @@ services:
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
networks: networks:
- infra-network - open-webui-network
# devices: # devices:
# - /dev/dri/card0:/dev/dri/card0 # - /dev/dri/card0:/dev/dri/card0
# - /dev/dri/renderD128:/dev/dri/renderD128 # - /dev/dri/renderD128:/dev/dri/renderD128
@@ -40,10 +40,15 @@ services:
# - GID=${PGID:-1000} # - GID=${PGID:-1000}
restart: on-failure:5 restart: on-failure:5
networks: networks:
- infra-network - open-webui-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
volumes: volumes:
ollama: {} ollama: {}
open-webui: {} open-webui: {}
networks:
open-webui-network:
driver: bridge
name: open-webui-network
@@ -37,7 +37,7 @@ services:
- argus_data:/argus_data:rw - argus_data:/argus_data:rw
- qbittorrent_config:/qbittorrent_config:rw - qbittorrent_config:/qbittorrent_config:rw
networks: networks:
- infra-network - openssh-network
security_opt: security_opt:
- no-new-privileges:false - no-new-privileges:false
ports: ports:
@@ -95,3 +95,8 @@ volumes:
name: argus_data name: argus_data
qbittorrent_config: qbittorrent_config:
name: qbittorrent_config name: qbittorrent_config
networks:
openssh-network:
driver: bridge
name: openssh-network
@@ -13,7 +13,7 @@ services:
volumes: volumes:
- picoshare_data:/data - picoshare_data:/data
networks: networks:
- infra-network - picoshare-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
read_only: false read_only: false
@@ -33,3 +33,8 @@ services:
volumes: volumes:
picoshare_data: picoshare_data:
name: picoshare_data name: picoshare_data
networks:
picoshare-network:
driver: bridge
name: picoshare-network
@@ -12,7 +12,7 @@ services:
- privatebin_data:/srv/data - privatebin_data:/srv/data
- ./config/conf.php:/srv/cfg/conf.php:ro - ./config/conf.php:/srv/cfg/conf.php:ro
networks: networks:
- infra-network - privatebin-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
read_only: true read_only: true
@@ -28,3 +28,8 @@ services:
volumes: volumes:
privatebin_data: privatebin_data:
name: privatebin_data name: privatebin_data
networks:
privatebin-network:
driver: bridge
name: privatebin-network
@@ -11,11 +11,10 @@ services:
env_file: env_file:
- ./env/projectsend.env - ./env/projectsend.env
volumes: volumes:
- /var/run/docker.sock:/var/run/docker.sock
- projectsend_config:/config - projectsend_config:/config
- projectsend_share:/data - projectsend_share:/data
networks: networks:
- infra-network - projectsend-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
cap_drop: cap_drop:
@@ -37,7 +36,7 @@ services:
- ./env/projectsend_db.env - ./env/projectsend_db.env
command: '--default-authentication-plugin=mysql_native_password' command: '--default-authentication-plugin=mysql_native_password'
networks: networks:
- infra-network - projectsend-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
@@ -48,3 +47,9 @@ volumes:
name: projectsend_config name: projectsend_config
projectsend_share: projectsend_share:
name: projectsend_share name: projectsend_share
networks:
projectsend-network:
driver: bridge
name: projectsend-network
@@ -14,7 +14,7 @@ services:
volumes: volumes:
- psitransfer_data:/data - psitransfer_data:/data
networks: networks:
- infra-network - psitransfer-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
read_only: true read_only: true
@@ -30,3 +30,8 @@ services:
volumes: volumes:
psitransfer_data: psitransfer_data:
name: psitransfer_data name: psitransfer_data
networks:
psitransfer-network:
driver: bridge
name: psitransfer-network
@@ -21,7 +21,7 @@ services:
- public_data:/downloads - public_data:/downloads
- private_data:/private_downloads - private_data:/private_downloads
networks: networks:
- infra-network - qbittorrent-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
@@ -32,3 +32,8 @@ volumes:
name: public_data name: public_data
private_data: private_data:
name: private_data name: private_data
networks:
qbittorrent-network:
driver: bridge
name: qbittorrent-network
@@ -1,7 +1,5 @@
include: include:
# Satisfactory server # Satisfactory server
- satisfactory/docker-compose.satisfactory.yml - satisfactory/docker-compose.satisfactory.yml
# OpenSSH server
- openssh/docker-compose.openssh.yml
# Backup server # Backup server
- backup/docker-compose.backup.yml - backup/docker-compose.backup.yml
@@ -1 +0,0 @@
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHVtzpnPr0Boy+bUbL+viOYfqeetDZF6Hu40EwNLXNb0 bensuperpc@gmail.com
@@ -1,36 +0,0 @@
services:
# openssh
satisfactory_openssh:
image: linuxserver/openssh-server:latest
container_name: satisfactory_openssh
profiles:
- satisfactory_openssh
depends_on:
- satisfactory_server
restart: on-failure:5
env_file:
- ./env/openssh.env
environment:
- PUID=${PUID:-1000}
- PGID=${PGID:-1000}
volumes:
- satisfactory_openssh_config:/config
- ./config/authorized_keys:/authorized_ssh_keys:ro
- satisfactory_backup:/satisfactory_backup
- satisfactory_server_config:/satisfactory_server_config
networks:
- infra-network
security_opt:
- no-new-privileges:false
cap_drop:
- SYS_ADMIN
ports:
- 2222:2222
volumes:
satisfactory_openssh_config:
name: satisfactory_openssh_config
satisfactory_backup:
name: satisfactory_backup
satisfactory_server_config:
name: satisfactory_server_config
@@ -1,15 +0,0 @@
TZ=Etc/UTC
SUDO_ACCESS=true
PASSWORD_ACCESS=false
DOCKER_MODS=linuxserver/mods:openssh-server-rsync
#PUBLIC_KEY_URL=https://github.com/bensuperpc.keys
PUBLIC_KEY_DIR=/authorized_ssh_keys
USER_NAME=admin
USER_PASSWORD=zpd91zZkCfdyAB8PZgUD7w7ZIhS8no4V
#PUBLIC_KEY=yourpublickey
#PUBLIC_KEY_FILE=/path/to/file
#PUBLIC_KEY_DIR=/path/to/directory/containing/_only_/pubkeys
#PUBLIC_KEY_URL=https://github.com/username.keys
#USER_PASSWORD_FILE=/path/to/file
#LOG_STDOUT=
@@ -13,7 +13,7 @@ services:
volumes: volumes:
- satisfactory_server_config:/config - satisfactory_server_config:/config
networks: networks:
- infra-network - satisfactory-network
env_file: env_file:
- ./env/satisfactory.env - ./env/satisfactory.env
environment: environment:
@@ -41,6 +41,6 @@ volumes:
name: satisfactory_server_config name: satisfactory_server_config
networks: networks:
infra-network: satisfactory-network:
driver: bridge driver: bridge
name: infra-network name: satisfactory-network
@@ -14,7 +14,7 @@ services:
- stirlingpdf_config:/configs - stirlingpdf_config:/configs
- stirlingpdf_tessdata:/usr/share/tessdata - stirlingpdf_tessdata:/usr/share/tessdata
networks: networks:
- infra-network - stirlingpdf-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
read_only: false read_only: false
@@ -24,3 +24,8 @@ volumes:
name: stirlingpdf_config name: stirlingpdf_config
stirlingpdf_tessdata: stirlingpdf_tessdata:
name: stirlingpdf_tessdata name: stirlingpdf_tessdata
networks:
stirlingpdf-network:
driver: bridge
name: stirlingpdf-network
@@ -18,7 +18,7 @@ services:
- public_data:/data1 - public_data:/data1
- private_data:/data2 - private_data:/data2
networks: networks:
- infra-network - syncthing-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
@@ -29,3 +29,8 @@ volumes:
name: public_data name: public_data
private_data: private_data:
name: private_data name: private_data
networks:
syncthing-network:
driver: bridge
name: syncthing-network
@@ -1,7 +1,5 @@
include: include:
# Team Fortress 2 server # Team Fortress 2 server
- teamfortress2/docker-compose.teamfortress2.yml - teamfortress2/docker-compose.teamfortress2.yml
# OpenSSH server
- openssh/docker-compose.openssh.yml
# Backup server # Backup server
- backup/docker-compose.backup.yml - backup/docker-compose.backup.yml
@@ -1 +0,0 @@
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHVtzpnPr0Boy+bUbL+viOYfqeetDZF6Hu40EwNLXNb0 bensuperpc@gmail.com
@@ -1,36 +0,0 @@
services:
# openssh
teamfortress2_openssh:
image: linuxserver/openssh-server:latest
container_name: teamfortress2_openssh
profiles:
- teamfortress2_openssh
depends_on:
- teamfortress2_server
restart: on-failure:5
env_file:
- ./env/openssh.env
environment:
- PUID=${PUID:-1000}
- PGID=${PGID:-1000}
volumes:
- teamfortress2_openssh_config:/config
- ./config/authorized_keys:/authorized_ssh_keys:ro
- teamfortress2_backup:/teamfortress2_backup
- teamfortress2_data:/teamfortress2_data
networks:
- infra-network
security_opt:
- no-new-privileges:false
cap_drop:
- SYS_ADMIN
ports:
- 2222:2222
volumes:
teamfortress2_openssh_config:
name: teamfortress2_openssh_config
teamfortress2_backup:
name: teamfortress2_backup
teamfortress2_data:
name: teamfortress2_data
@@ -1,15 +0,0 @@
TZ=Etc/UTC
SUDO_ACCESS=true
PASSWORD_ACCESS=false
DOCKER_MODS=linuxserver/mods:openssh-server-rsync
#PUBLIC_KEY_URL=https://github.com/bensuperpc.keys
PUBLIC_KEY_DIR=/authorized_ssh_keys
USER_NAME=admin
USER_PASSWORD=K4CLuwknhW6sl6fxKI5DsNt9R9SSelmC
#PUBLIC_KEY=yourpublickey
#PUBLIC_KEY_FILE=/path/to/file
#PUBLIC_KEY_DIR=/path/to/directory/containing/_only_/pubkeys
#PUBLIC_KEY_URL=https://github.com/username.keys
#USER_PASSWORD_FILE=/path/to/file
#LOG_STDOUT=
@@ -12,7 +12,7 @@ services:
volumes: volumes:
- teamfortress2_data:/home/steam/tf-dedicated - teamfortress2_data:/home/steam/tf-dedicated
networks: networks:
- infra-network - teamfortress2-network
env_file: env_file:
- ./env/teamfortress2.env - ./env/teamfortress2.env
# environment: # environment:
@@ -34,6 +34,6 @@ volumes:
name: teamfortress2_data name: teamfortress2_data
networks: networks:
infra-network: teamfortress2-network:
driver: bridge driver: bridge
name: infra-network name: teamfortress2-network
@@ -18,7 +18,7 @@ services:
- public_data:/downloads - public_data:/downloads
- transmission_watch:/watch - transmission_watch:/watch
networks: networks:
- infra-network - transmission-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
@@ -31,3 +31,8 @@ volumes:
name: public_data name: public_data
private_data: private_data:
name: private_data name: private_data
networks:
transmission-network:
driver: bridge
name: transmission-network
@@ -12,7 +12,7 @@ services:
depends_on: depends_on:
- caddy - caddy
networks: networks:
- infra-network - uptimekuma-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
cap_drop: cap_drop:
@@ -21,3 +21,8 @@ services:
volumes: volumes:
uptimekuma_data: uptimekuma_data:
name: uptimekuma_data name: uptimekuma_data
networks:
uptimekuma-network:
driver: bridge
name: uptimekuma-network
@@ -15,7 +15,7 @@ services:
- ./config/wordpress/php.ini:/usr/local/etc/php/conf.d/custom.ini:ro - ./config/wordpress/php.ini:/usr/local/etc/php/conf.d/custom.ini:ro
- wordpress:/var/www/html:rw - wordpress:/var/www/html:rw
networks: networks:
- infra-network - wordpress-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
@@ -35,7 +35,7 @@ services:
- ./env/wordpress_db.env - ./env/wordpress_db.env
command: '--default-authentication-plugin=mysql_native_password' command: '--default-authentication-plugin=mysql_native_password'
networks: networks:
- infra-network - wordpress-network
security_opt: security_opt:
- no-new-privileges:true - no-new-privileges:true
@@ -66,3 +66,8 @@ volumes:
name: wordpress name: wordpress
wordpress_backup: wordpress_backup:
name: wordpress_backup name: wordpress_backup
networks:
wordpress-network:
driver: bridge
name: wordpress-network