]> unremediatedgender.space Git - Ultimately_Untrue_Thought.git/commitdiff
provisioning for move to shared blogmistress droplet
authorZack M. Davis <ultimatelyuntruethought@gmail.com>
Sun, 27 Sep 2026 23:47:57 +0000 (16:47 -0700)
committerZack M. Davis <ultimatelyuntruethought@gmail.com>
Sun, 27 Sep 2026 23:49:16 +0000 (16:49 -0700)
nginx server block alongside zackmdavis.net's (HTTP and HTTPS, no forced
redirect), Isso as a systemd service, a UUT-specific Gitweb config
layered over the shared one, and /home/mtsw paths replaced with
blogmistress ones.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
provisioning/gitweb.conf [new file with mode: 0644]
provisioning/isso-uut.service [new file with mode: 0644]
provisioning/isso.cfg
provisioning/nginx_siteconf
provisioning/pelican_scheduler.py

diff --git a/provisioning/gitweb.conf b/provisioning/gitweb.conf
new file mode 100644 (file)
index 0000000..295a4e9
--- /dev/null
@@ -0,0 +1,10 @@
+# Deployed as /etc/gitweb-uut.conf (see the /source location in
+# nginx_siteconf). Reuses the droplet's shared /etc/gitweb.conf (from the
+# An_Algorithmic_Lucidity repo), but that one points gitweb's assets at
+# zackmdavis.net's /blog/gitweb-static, which doesn't exist on this domain.
+do "/etc/gitweb.conf";
+
+@stylesheets = ("/static/gitweb.css");
+$javascript = "/static/gitweb.js";
+$logo = "/static/git-logo.png";
+$favicon = "/static/git-favicon.png";
diff --git a/provisioning/isso-uut.service b/provisioning/isso-uut.service
new file mode 100644 (file)
index 0000000..3c8adc5
--- /dev/null
@@ -0,0 +1,14 @@
+# Deployed as /etc/systemd/system/isso-uut.service. The live isso.cfg is a
+# copy of provisioning/isso.cfg with the admin password filled in.
+[Unit]
+Description=Isso comment server for unremediatedgender.space
+After=network.target
+
+[Service]
+User=blogmistress
+WorkingDirectory=/home/blogmistress/Ultimately_Untrue_Thought/isso
+ExecStart=/home/blogmistress/Ultimately_Untrue_Thought/isso/.venv/bin/isso -c /home/blogmistress/Ultimately_Untrue_Thought/isso/isso.cfg run
+Restart=on-failure
+
+[Install]
+WantedBy=multi-user.target
index a2e9c214b3b8f2bfd77112a805bc6fd9ea7b90cb..b505bee34ecbe8013d0eb621a2a5eadd99216141 100644 (file)
@@ -1,14 +1,17 @@
 [general]
 ; database location, check permissions, automatically created if not exists
-dbpath = /home/mtsw/isso/comments.db
+dbpath = /home/blogmistress/Ultimately_Untrue_Thought/isso/comments.db
 ; your website or blog (not the location of Isso!)
 ; you can add multiple hosts for local development
 ; or SSL connections. There is no wildcard to allow
 ; any domain.
 host =
     http://unremediatedgender.space/
+    https://unremediatedgender.space/
     http://localhost:8000/
-    
+
+latest-enabled = true
+
 [guard]
 reply-to-self = true
 require-author = true
index 279df7b98c1ed96ef3952967ce6445458815e0e2..47aa5001c66a64c7b998d55f4284fdfc3ce98759 100644 (file)
@@ -1,28 +1,45 @@
-map $sent_http_content_type $expires {
-    default                    off;
-    text/html                  epoch;
-}
-
+# Lives alongside zackmdavis.net's server block on the shared droplet
+# (164.92.81.131). $expires comes from conf.d/common_expires_map.conf and the
+# combined_extended log format from conf.d/common_log_formats.conf, both
+# included from nginx.conf's http{} block (see the An_Algorithmic_Lucidity
+# repo's provisioning/).
+#
+# HTTPS is available, but plain HTTP is deliberately NOT redirected to it:
+# same policy as zackmdavis.net, so a broken cert renewal degrades to a
+# warning for HTTPS visitors rather than taking the site dark.
 server {
-        listen 80 default_server;
-        listen [::]:80 default_server;
+        listen 80;
+        listen [::]:80;
+        listen 443 ssl;
+        listen [::]:443 ssl;
+        http2 on;
 
-        root /var/www/html;
+        server_name unremediatedgender.space;
 
-        index index.html index.htm index.nginx-debian.html;
+        ssl_certificate /etc/letsencrypt/live/unremediatedgender.space/fullchain.pem;
+        ssl_certificate_key /etc/letsencrypt/live/unremediatedgender.space/privkey.pem;
+        include /etc/letsencrypt/options-ssl-nginx.conf;
+        ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
 
-        server_name _;
+        root /home/blogmistress/Ultimately_Untrue_Thought/output;
+        index index.html;
 
         expires $expires;
 
+        access_log /var/log/nginx/access.log combined_extended;
+
         location / {
-            # First attempt to serve request as file, then
-            # as directory, then fall back to displaying a 404.
             try_files $uri $uri/ =404;
         }
 
         location /papers {
-            root /var/www;
+            root /home/blogmistress/Ultimately_Untrue_Thought;
+            autoindex on;
+        }
+
+        # shared with zackmdavis.net/media
+        location /media {
+            root /home/blogmistress/zackmdavis.net;
             autoindex on;
         }
 
@@ -32,8 +49,8 @@ server {
             include fastcgi_params;
             gzip off;
             fastcgi_param SCRIPT_FILENAME /usr/share/gitweb/gitweb.cgi;
-            fastcgi_param GITWEB_CONFIG /etc/gitweb.conf;
-            fastcgi_pass  unix:/var/run/fcgiwrap.socket;
+            fastcgi_param GITWEB_CONFIG /etc/gitweb-uut.conf;
+            fastcgi_pass  unix:/run/fcgiwrap.socket;
         }
 
         location /static { # gitweb static files
@@ -48,5 +65,4 @@ server {
             proxy_set_header X-Forwarded-Proto $scheme;
             proxy_pass http://localhost:8080;
         }
-
 }
index 5fdc607ba1f558a6f4855a9539f258462a5d2a09..655e2a48ca5664484829b22091f3560973c61cda 100755 (executable)
@@ -8,11 +8,11 @@ import os
 import re
 import subprocess
 
-WORKING_REPO = "/home/mtsw/working"
+WORKING_REPO = "/home/blogmistress/Ultimately_Untrue_Thought/working"
 INPUT_DIR = os.path.join(WORKING_REPO, "content")
-OUTPUT_DIR = "/var/www/html"
+OUTPUT_DIR = "/home/blogmistress/Ultimately_Untrue_Thought/output"
 PUBLISH_CONF = os.path.join(WORKING_REPO, "publishconf.py")
-SITEGEN_COMMAND = "bash -c 'cd {} && source bin/activate && pelican {} -o {} -s {}'".format(
+SITEGEN_COMMAND = "bash -c 'cd {} && source .venv/bin/activate && pelican {} -o {} -s {}'".format(
     WORKING_REPO, INPUT_DIR, OUTPUT_DIR, PUBLISH_CONF)
 
 DATELINE_REGEX = re.compile(r"^Date: *(\d{4}-\d{2}-\d{2} \d{2}:\d{2}) *$",