propellor/config-joey.hs

221 lines
8.1 KiB
Haskell
Raw Normal View History

2014-04-03 16:06:58 +00:00
-- | This is the live config file used by propellor's author.
import Propellor
import Propellor.CmdLine
2014-04-09 04:54:27 +00:00
import Propellor.Property.Scheduled
2014-04-03 16:06:58 +00:00
import qualified Propellor.Property.File as File
import qualified Propellor.Property.Apt as Apt
import qualified Propellor.Property.Network as Network
import qualified Propellor.Property.Ssh as Ssh
import qualified Propellor.Property.Cron as Cron
import qualified Propellor.Property.Sudo as Sudo
import qualified Propellor.Property.User as User
import qualified Propellor.Property.Hostname as Hostname
2014-04-10 04:10:08 +00:00
import qualified Propellor.Property.Reboot as Reboot
2014-04-03 16:06:58 +00:00
import qualified Propellor.Property.Tor as Tor
2014-04-10 05:46:33 +00:00
import qualified Propellor.Property.Dns as Dns
2014-04-08 20:58:11 +00:00
import qualified Propellor.Property.OpenId as OpenId
2014-04-03 16:06:58 +00:00
import qualified Propellor.Property.Docker as Docker
2014-04-10 06:51:25 +00:00
import qualified Propellor.Property.Git as Git
2014-04-03 16:06:58 +00:00
import qualified Propellor.Property.SiteSpecific.GitHome as GitHome
import qualified Propellor.Property.SiteSpecific.GitAnnexBuilder as GitAnnexBuilder
import qualified Propellor.Property.SiteSpecific.JoeySites as JoeySites
2014-04-04 05:16:16 +00:00
import Data.List
2014-04-03 16:06:58 +00:00
main :: IO ()
main = defaultMain [host, Docker.containerProperties container]
-- | This is where the system's HostName, either as returned by uname
-- or one specified on the command line, is converted into a list of
-- Properties for that system.
--
-- Edit this to configure propellor!
host :: HostName -> Maybe [Property]
2014-04-03 17:49:26 +00:00
-- Clam is a tor bridge, and an olduse.net shellbox and other fun stuff.
2014-04-10 04:10:08 +00:00
host hostname@"clam.kitenet.net" = Just $ withSystemd $ props
2014-04-03 16:06:58 +00:00
& cleanCloudAtCost hostname
2014-04-10 04:10:08 +00:00
& standardSystem Unstable
2014-04-03 16:06:58 +00:00
& Apt.unattendedUpgrades
& Network.ipv6to4
& Apt.installed ["git-annex", "mtr"]
& Tor.isBridge
& JoeySites.oldUseNetshellBox
2014-04-08 20:58:11 +00:00
& Docker.docked container hostname "openid-provider"
2014-04-09 16:00:23 +00:00
`requires` Apt.installed ["ntp"]
2014-04-10 15:03:47 +00:00
& Docker.docked container hostname "ancient-kitenet"
2014-04-03 16:06:58 +00:00
& Docker.configured
2014-04-09 04:54:27 +00:00
& Docker.garbageCollected `period` Daily
2014-04-03 17:49:26 +00:00
-- Orca is the main git-annex build box.
2014-04-10 04:10:08 +00:00
host hostname@"orca.kitenet.net" = Just $ props -- no systemd due to #726375
& standardSystem Unstable
2014-04-03 16:06:58 +00:00
& Hostname.set hostname
& Apt.unattendedUpgrades
& Docker.configured
2014-04-09 04:54:27 +00:00
& Apt.buildDep ["git-annex"] `period` Daily
2014-04-04 20:05:45 +00:00
& Docker.docked container hostname "amd64-git-annex-builder"
& Docker.docked container hostname "i386-git-annex-builder"
2014-04-08 22:56:40 +00:00
! Docker.docked container hostname "armel-git-annex-builder-companion"
! Docker.docked container hostname "armel-git-annex-builder"
2014-04-09 04:54:27 +00:00
& Docker.garbageCollected `period` Daily
2014-04-10 04:10:08 +00:00
-- Diatom is my downloads and git repos server, and secondary dns server.
2014-04-10 04:30:57 +00:00
host hostname@"diatom.kitenet.net" = Just $ props
2014-04-10 04:10:08 +00:00
& standardSystem Stable
& Hostname.set hostname
& Apt.unattendedUpgrades
& Apt.serviceInstalledRunning "ntp"
2014-04-10 05:46:33 +00:00
& Dns.zones myDnsSecondary
2014-04-10 04:37:03 +00:00
& Apt.serviceInstalledRunning "apache2"
& Apt.installed ["git", "git-annex", "rsync"]
2014-04-10 04:10:08 +00:00
& Apt.buildDep ["git-annex"] `period` Daily
2014-04-10 06:51:25 +00:00
& Git.daemonRunning "/srv/git"
2014-04-10 07:06:35 +00:00
& File.ownerGroup "/srv/git" "joey" "joey"
2014-04-10 06:51:25 +00:00
-- git repos restore (how?)
2014-04-10 15:02:29 +00:00
-- family annex needs family members to have accounts,
-- ssh host key etc.. finesse?
-- (also should upgrade git-annex-shell for it..)
2014-04-10 06:51:25 +00:00
-- kgb installation and setup
-- ssh keys for branchable and github repo hooks
-- gitweb
-- downloads.kitenet.net setup (including ssh key to turtle)
2014-04-03 17:49:26 +00:00
-- My laptop
host _hostname@"darkstar.kitenet.net" = Just $ props
& Docker.configured
2014-04-09 04:54:27 +00:00
& Apt.buildDep ["git-annex"] `period` Daily
2014-04-03 17:49:26 +00:00
2014-04-03 16:06:58 +00:00
-- add more hosts here...
--host "foo.example.com" =
host _ = Nothing
-- | This is where Docker containers are set up. A container
-- can vary by hostname where it's used, or be the same everywhere.
container :: HostName -> Docker.ContainerName -> Maybe (Docker.Container)
2014-04-08 22:41:30 +00:00
container _parenthost name
2014-04-08 20:58:11 +00:00
-- Simple web server, publishing the outside host's /var/www
2014-04-08 23:42:54 +00:00
| name == "webserver" = Just $ standardContainer Stable "amd64"
2014-04-03 16:06:58 +00:00
[ Docker.publish "8080:80"
, Docker.volume "/var/www:/var/www"
, Docker.inside $ props
2014-04-08 23:31:03 +00:00
& Apt.serviceInstalledRunning "apache2"
2014-04-03 16:06:58 +00:00
]
2014-04-08 21:10:52 +00:00
2014-04-08 20:58:11 +00:00
-- My own openid provider. Uses php, so containerized for security
-- and administrative sanity.
2014-04-08 23:42:54 +00:00
| name == "openid-provider" = Just $ standardContainer Stable "amd64"
2014-04-08 20:58:11 +00:00
[ Docker.publish "8081:80"
, Docker.inside $ props
2014-04-08 23:42:54 +00:00
& OpenId.providerFor ["joey", "liw"]
"openid.kitenet.net:8081"
2014-04-08 20:58:11 +00:00
]
2014-04-08 05:42:59 +00:00
2014-04-10 15:03:47 +00:00
| name == "ancient-kitenet" = Just $ standardContainer Stable "amd64"
2014-04-10 15:02:29 +00:00
[ Docker.publish "1994:80"
, Docker.inside $ props
& Apt.serviceInstalledRunning "apache2"
& Apt.installed ["git"]
& scriptProperty
[ "cd /var/"
, "rm -rf www"
2014-04-10 15:09:16 +00:00
, "git clone git://git.kitenet.net/kitewiki www"
2014-04-10 15:10:17 +00:00
, "cd www"
2014-04-10 15:02:29 +00:00
, "git checkout remotes/origin/old-kitenet.net"
] `flagFile` "/var/www/blastfromthepast.html"
]
2014-04-08 05:42:59 +00:00
-- armel builder has a companion container that run amd64 and
-- runs the build first to get TH splices. They share a home
-- directory, and need to have the same versions of all haskell
-- libraries installed.
| name == "armel-git-annex-builder-companion" = Just $ Docker.containerFrom
(image $ System (Debian Unstable) "amd64")
[ Docker.volume GitAnnexBuilder.homedir
2014-04-08 21:29:56 +00:00
, Docker.inside $ props
& Apt.unattendedUpgrades
2014-04-08 05:42:59 +00:00
]
| name == "armel-git-annex-builder" = Just $ Docker.containerFrom
(image $ System (Debian Unstable) "armel")
[ Docker.link (name ++ "-companion") "companion"
, Docker.volumes_from (name ++ "-companion")
, Docker.inside $ props
-- & GitAnnexBuilder.builder "armel" "15 * * * *" True
2014-04-08 21:29:56 +00:00
& Apt.unattendedUpgrades
2014-04-08 05:42:59 +00:00
]
2014-04-03 16:06:58 +00:00
| "-git-annex-builder" `isSuffixOf` name =
let arch = takeWhile (/= '-') name
in Just $ Docker.containerFrom
(image $ System (Debian Unstable) arch)
2014-04-08 21:29:56 +00:00
[ Docker.inside $ props
& GitAnnexBuilder.builder arch "15 * * * *" True
& Apt.unattendedUpgrades
]
2014-04-08 05:42:59 +00:00
2014-04-03 16:06:58 +00:00
| otherwise = Nothing
-- | Docker images I prefer to use.
image :: System -> Docker.Image
2014-04-04 05:12:09 +00:00
image (System (Debian Unstable) arch) = "joeyh/debian-unstable-" ++ arch
2014-04-08 20:58:11 +00:00
image (System (Debian Stable) arch) = "joeyh/debian-stable-" ++ arch
2014-04-04 05:12:09 +00:00
image _ = "debian-stable-official" -- does not currently exist!
2014-04-03 16:06:58 +00:00
-- This is my standard system setup
2014-04-10 04:10:08 +00:00
standardSystem :: DebianSuite -> Property
standardSystem suite = propertyList "standard system" $ props
& Apt.stdSourcesList suite `onChange` Apt.upgrade
& Apt.installed ["etckeeper"]
& Apt.installed ["ssh"]
& GitHome.installedFor "root"
& User.hasSomePassword "root"
-- Harden the system, but only once root's authorized_keys
-- is safely in place.
& check (Ssh.hasAuthorizedKeys "root")
(Ssh.passwordAuthentication False)
& User.accountFor "joey"
& User.hasSomePassword "joey"
& Sudo.enabledFor "joey"
& GitHome.installedFor "joey"
& Apt.installed ["vim", "screen", "less"]
& Cron.runPropellor "30 * * * *"
-- I use postfix, or no MTA.
& Apt.removed ["exim4", "exim4-daemon-light", "exim4-config", "exim4-base"]
`onChange` Apt.autoRemove
withSystemd :: [Property] -> [Property]
2014-04-10 04:17:39 +00:00
withSystemd ps = ps ++ [Apt.installed ["systemd-sysv"] `onChange` Reboot.now]
2014-04-03 16:06:58 +00:00
2014-04-09 01:28:15 +00:00
-- This is my standard container setup, featuring automatic upgrades.
2014-04-08 23:42:54 +00:00
standardContainer :: DebianSuite -> Architecture -> [Docker.Containerized Property] -> Docker.Container
standardContainer suite arch ps = Docker.containerFrom
(image $ System (Debian suite) arch) $
[ Docker.inside $ props
& Apt.stdSourcesList suite
& Apt.unattendedUpgrades
] ++ ps
2014-04-03 16:06:58 +00:00
-- Clean up a system as installed by cloudatcost.com
cleanCloudAtCost :: HostName -> Property
cleanCloudAtCost hostname = propertyList "cloudatcost cleanup"
[ Hostname.set hostname
, Ssh.uniqueHostKeys
, "worked around grub/lvm boot bug #743126" ==>
"/etc/default/grub" `File.containsLine` "GRUB_DISABLE_LINUX_UUID=true"
`onChange` cmdProperty "update-grub" []
`onChange` cmdProperty "update-initramfs" ["-u"]
, combineProperties "nuked cloudatcost cruft"
[ File.notPresent "/etc/rc.local"
, File.notPresent "/etc/init.d/S97-setup.sh"
, User.nuked "user" User.YesReallyDeleteHome
]
]
2014-04-10 05:46:33 +00:00
myDnsSecondary :: [Dns.Zone]
myDnsSecondary =
[ Dns.secondary "kitenet.net" master
, Dns.secondary "joeyh.name" master
, Dns.secondary "ikiwiki.info" master
, Dns.secondary "olduse.net" master
, Dns.secondary "branchable.com" branchablemaster
]
where
master = ["80.68.85.49", "2001:41c8:125:49::10"] -- wren
branchablemaster = ["66.228.46.55", "2600:3c03::f03c:91ff:fedf:c0e5"]