No description
- Shell 100%
|
|
||
|---|---|---|
| .forgejo/workflows | ||
| docs | ||
| image | ||
| rootfs | ||
| tests | ||
| adopt.sh | ||
| app.func | ||
| CHANGELOG.md | ||
| ct.sh | ||
| iac.json | ||
| install.sh | ||
| packages.list | ||
| README.md | ||
| update.sh | ||
| vm.sh | ||
iac-nginx
nginx aus Debian 13 als LXC oder VM auf Proxmox VE – mit
iac-nginx-sites, das statische Seiten selbstständig aus der Paket-Registry abholt.
Teil von iac.
Installation (auf der Proxmox-Node)
bash -c "$(curl -fsSL https://git.heyer.systems/iac/iac-nginx/raw/branch/main/ct.sh)" # LXC
bash -c "$(curl -fsSL https://git.heyer.systems/iac/iac-nginx/raw/branch/main/vm.sh)" # VM
Statische Seiten
iac-nginx-sites add iac https://git.heyer.systems/api/packages/iac/generic/iac-website iac.heyer.systems default
iac-nginx-sites list
iac-nginx-sites rollback iac
Ein Timer gleicht alle 5 Minuten ab: neue Version → Prüfsumme → nginx -t → atomar umschalten.
Bei Fehlern bleibt die alte Version aktiv. Das Paket muss site.tar.gz (mit public/, optional
nginx/*.conf für zusätzliche Regeln) und SHA256SUMS enthalten – so wie
iac-core/tools/publish-package.sh es ablegt.
Update (im Gast)
update
Standard-Einrichtung
| nginx | Debian-Paket, Konfiguration nach Debian-Standard |
| iac-Vorgaben | /etc/nginx/conf.d/00-iac.conf (server_tokens, echte Client-IP hinter Proxy, gzip) |
| Eigene vhosts | /etc/nginx/sites-enabled/ – gehören dir |
| Seitenquellen | /etc/iac/nginx/sites.d/<name>.conf – gehören dir |
| Seiten-Daten | /var/lib/iac-nginx/sites/<name>/ (letzte 3 Versionen) |
| Firewall | nftables: SSH, 80, 443 |