From: Zack M. Davis Date: Sun, 27 Sep 2026 23:47:57 +0000 (-0700) Subject: provisioning for move to shared blogmistress droplet X-Git-Url: http://unremediatedgender.space/source?a=commitdiff_plain;h=823f8a1f3978ec3980f226f2556651ba3e35bcc3;p=Ultimately_Untrue_Thought.git provisioning for move to shared blogmistress droplet nginx server block alongside zackmdavis.net's (HTTP and HTTPS, no forced redirect), Isso as a systemd service, a UUT-specific Gitweb config layered over the shared one, and /home/mtsw paths replaced with blogmistress ones. Co-Authored-By: Claude Opus 5.5 --- diff --git a/provisioning/gitweb.conf b/provisioning/gitweb.conf new file mode 100644 index 0000000..295a4e9 --- /dev/null +++ b/provisioning/gitweb.conf @@ -0,0 +1,10 @@ +# Deployed as /etc/gitweb-uut.conf (see the /source location in +# nginx_siteconf). Reuses the droplet's shared /etc/gitweb.conf (from the +# An_Algorithmic_Lucidity repo), but that one points gitweb's assets at +# zackmdavis.net's /blog/gitweb-static, which doesn't exist on this domain. +do "/etc/gitweb.conf"; + +@stylesheets = ("/static/gitweb.css"); +$javascript = "/static/gitweb.js"; +$logo = "/static/git-logo.png"; +$favicon = "/static/git-favicon.png"; diff --git a/provisioning/isso-uut.service b/provisioning/isso-uut.service new file mode 100644 index 0000000..3c8adc5 --- /dev/null +++ b/provisioning/isso-uut.service @@ -0,0 +1,14 @@ +# Deployed as /etc/systemd/system/isso-uut.service. The live isso.cfg is a +# copy of provisioning/isso.cfg with the admin password filled in. +[Unit] +Description=Isso comment server for unremediatedgender.space +After=network.target + +[Service] +User=blogmistress +WorkingDirectory=/home/blogmistress/Ultimately_Untrue_Thought/isso +ExecStart=/home/blogmistress/Ultimately_Untrue_Thought/isso/.venv/bin/isso -c /home/blogmistress/Ultimately_Untrue_Thought/isso/isso.cfg run +Restart=on-failure + +[Install] +WantedBy=multi-user.target diff --git a/provisioning/isso.cfg b/provisioning/isso.cfg index a2e9c21..b505bee 100644 --- a/provisioning/isso.cfg +++ b/provisioning/isso.cfg @@ -1,14 +1,17 @@ [general] ; database location, check permissions, automatically created if not exists -dbpath = /home/mtsw/isso/comments.db +dbpath = /home/blogmistress/Ultimately_Untrue_Thought/isso/comments.db ; your website or blog (not the location of Isso!) ; you can add multiple hosts for local development ; or SSL connections. There is no wildcard to allow ; any domain. host = http://unremediatedgender.space/ + https://unremediatedgender.space/ http://localhost:8000/ - + +latest-enabled = true + [guard] reply-to-self = true require-author = true diff --git a/provisioning/nginx_siteconf b/provisioning/nginx_siteconf index 279df7b..47aa500 100644 --- a/provisioning/nginx_siteconf +++ b/provisioning/nginx_siteconf @@ -1,28 +1,45 @@ -map $sent_http_content_type $expires { - default off; - text/html epoch; -} - +# Lives alongside zackmdavis.net's server block on the shared droplet +# (164.92.81.131). $expires comes from conf.d/common_expires_map.conf and the +# combined_extended log format from conf.d/common_log_formats.conf, both +# included from nginx.conf's http{} block (see the An_Algorithmic_Lucidity +# repo's provisioning/). +# +# HTTPS is available, but plain HTTP is deliberately NOT redirected to it: +# same policy as zackmdavis.net, so a broken cert renewal degrades to a +# warning for HTTPS visitors rather than taking the site dark. server { - listen 80 default_server; - listen [::]:80 default_server; + listen 80; + listen [::]:80; + listen 443 ssl; + listen [::]:443 ssl; + http2 on; - root /var/www/html; + server_name unremediatedgender.space; - index index.html index.htm index.nginx-debian.html; + ssl_certificate /etc/letsencrypt/live/unremediatedgender.space/fullchain.pem; + ssl_certificate_key /etc/letsencrypt/live/unremediatedgender.space/privkey.pem; + include /etc/letsencrypt/options-ssl-nginx.conf; + ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; - server_name _; + root /home/blogmistress/Ultimately_Untrue_Thought/output; + index index.html; expires $expires; + access_log /var/log/nginx/access.log combined_extended; + location / { - # First attempt to serve request as file, then - # as directory, then fall back to displaying a 404. try_files $uri $uri/ =404; } location /papers { - root /var/www; + root /home/blogmistress/Ultimately_Untrue_Thought; + autoindex on; + } + + # shared with zackmdavis.net/media + location /media { + root /home/blogmistress/zackmdavis.net; autoindex on; } @@ -32,8 +49,8 @@ server { include fastcgi_params; gzip off; fastcgi_param SCRIPT_FILENAME /usr/share/gitweb/gitweb.cgi; - fastcgi_param GITWEB_CONFIG /etc/gitweb.conf; - fastcgi_pass unix:/var/run/fcgiwrap.socket; + fastcgi_param GITWEB_CONFIG /etc/gitweb-uut.conf; + fastcgi_pass unix:/run/fcgiwrap.socket; } location /static { # gitweb static files @@ -48,5 +65,4 @@ server { proxy_set_header X-Forwarded-Proto $scheme; proxy_pass http://localhost:8080; } - } diff --git a/provisioning/pelican_scheduler.py b/provisioning/pelican_scheduler.py index 5fdc607..655e2a4 100755 --- a/provisioning/pelican_scheduler.py +++ b/provisioning/pelican_scheduler.py @@ -8,11 +8,11 @@ import os import re import subprocess -WORKING_REPO = "/home/mtsw/working" +WORKING_REPO = "/home/blogmistress/Ultimately_Untrue_Thought/working" INPUT_DIR = os.path.join(WORKING_REPO, "content") -OUTPUT_DIR = "/var/www/html" +OUTPUT_DIR = "/home/blogmistress/Ultimately_Untrue_Thought/output" PUBLISH_CONF = os.path.join(WORKING_REPO, "publishconf.py") -SITEGEN_COMMAND = "bash -c 'cd {} && source bin/activate && pelican {} -o {} -s {}'".format( +SITEGEN_COMMAND = "bash -c 'cd {} && source .venv/bin/activate && pelican {} -o {} -s {}'".format( WORKING_REPO, INPUT_DIR, OUTPUT_DIR, PUBLISH_CONF) DATELINE_REGEX = re.compile(r"^Date: *(\d{4}-\d{2}-\d{2} \d{2}:\d{2}) *$",