• Joined on 2026-03-20
jack pushed to master at jack/infra 2026-03-22 09:20:20 +00:00
bf59b75c8f fix: redesign backup archive structure + enable Outline email auth
jack pushed to master at jack/infra 2026-03-22 08:55:44 +00:00
2b5524f258 fix: remove promtail nested /var/log/traefik volume mount
jack pushed to master at jack/infra 2026-03-22 08:39:36 +00:00
6279bcb9b4 fix: remove cs-firewall-bouncer from image pre-pull list
jack pushed to master at jack/infra 2026-03-22 08:18:14 +00:00
54ba45acaa fix: ensure SSH private key has trailing newline in CI workflow
jack pushed to master at jack/infra 2026-03-22 08:10:59 +00:00
a7b14759af fix: add front network to tools stack for Docker port binding
jack pushed to master at jack/infra 2026-03-22 07:50:12 +00:00
28f8c76433 fix: plane and authelia health check URLs
jack pushed to master at jack/infra 2026-03-22 01:14:16 +00:00
9ca1177461 fix: crowdsec proxy network, uptime-kuma curl healthcheck, outline en_US, n8n 127.0.0.1
jack pushed to master at jack/infra 2026-03-21 23:19:46 +00:00
92d2c845d8 feat: add n8n, outline routes, remove syncthing, fix backup awscli
jack pushed to master at jack/infra 2026-03-21 22:36:10 +00:00
05bcbab858 feat: add tools role (Outline wiki) + 3-server architecture
jack pushed to master at jack/infra 2026-03-21 22:32:39 +00:00
85a5857a5f infra: add visual-tools and visual-mon servers, fix inventory
jack pushed to master at jack/infra 2026-03-21 21:51:47 +00:00
321e1c4daa feat: extend fail2ban with Forgejo SSH and Traefik HTTP jails
jack pushed to master at jack/infra 2026-03-21 21:47:52 +00:00
c2f9a0c21c feat: wildcard TLS via Cloudflare DNS-01 + real-IP forwarding
jack pushed to master at jack/infra 2026-03-21 21:18:26 +00:00
f183fe485f revert: switch back to HTTP-01 until Cloudflare NS propagation
jack pushed to master at jack/infra 2026-03-21 21:13:49 +00:00
0496e9ab61 feat: wildcard TLS certificate *.csrx.ru via Cloudflare DNS-01
jack pushed to master at jack/infra 2026-03-21 21:11:44 +00:00
5befd48a50 fix: allow Docker bridge networks through UFW for runner + add unattended-upgrades
jack pushed to master at jack/infra 2026-03-21 21:06:51 +00:00
fccbd1a45a feat: Cloudflare DNS-01 ACME + Docker hardening + sysctl
jack pushed to master at jack/infra 2026-03-21 21:02:12 +00:00
e935c897c6 feat: Cloudflare integration — real IP forwarding + firewall lockdown
jack pushed to master at jack/infra 2026-03-21 21:00:01 +00:00
1f03022086 fix: correct invalid PromQL in ContainerHighMemory alert rule
jack pushed to master at jack/infra 2026-03-21 20:59:03 +00:00
fc6b1c0cec feat: Timeweb S3 offsite backup uploads
jack pushed to master at jack/infra 2026-03-21 20:54:32 +00:00
a344998405 feat: add uptime-kuma pull, logrotate deploy task, logrotate package