This commit is contained in:
16
Technical/Server/Actual (finance).md
Executable file
16
Technical/Server/Actual (finance).md
Executable file
@@ -0,0 +1,16 @@
|
||||
# Notes:
|
||||
|
||||
- \<2026-04-01 Wed\>: There is one transaction waiting to show on the statement for \<2026-03-31 Tue\>. Will need to redo March full. \[ \]
|
||||
|
||||
# Setup
|
||||
|
||||
In order to update the balance, I have decided for the moment to export as `csv` the monthly transactions from Halifax. Place the file into the `~/master-folder/attachments/bank-statements/` folder and name it as `halifax-YYYY-MM.csv`, where `YYYY` is the four-digit year and `MM` is the two-digit month.
|
||||
|
||||
Then run the following command in the terminal whilst being in the `~/master-folder/projects/scripts/` directory:
|
||||
|
||||
``` python
|
||||
python3 clean-halifax-actual.py ../../attachments/bank-statements/halifax-YYYY-MM.csv ../../attachments/bank-statements/halifax-YYYY-MM-cleaned.csv
|
||||
|
||||
```
|
||||
|
||||
Then you can go to the website `https://actual.zainezq.com/` and upload the cleaned file to update the balance.
|
||||
79
Technical/Server/Cloudflare.md
Executable file
79
Technical/Server/Cloudflare.md
Executable file
@@ -0,0 +1,79 @@
|
||||
---
|
||||
note type:
|
||||
- server
|
||||
- note
|
||||
date: 2026-06-03
|
||||
done: true
|
||||
---
|
||||
# Go to: <https://dash.cloudflare.com/49b791cb8f903fdcab3db1cfa124321b/one/access-controls/apps>
|
||||
|
||||
This is to edit the access control in the zero trust cloudflare.
|
||||
|
||||
# Origin certificate
|
||||
|
||||
```
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIEojCCA4qgAwIBAgIUGvC9u3SW6C6y5uOcQjul2hyghmgwDQYJKoZIhvcNAQEL
|
||||
BQAwgYsxCzAJBgNVBAYTAlVTMRkwFwYDVQQKExBDbG91ZEZsYXJlLCBJbmMuMTQw
|
||||
MgYDVQQLEytDbG91ZEZsYXJlIE9yaWdpbiBTU0wgQ2VydGlmaWNhdGUgQXV0aG9y
|
||||
aXR5MRYwFAYDVQQHEw1TYW4gRnJhbmNpc2NvMRMwEQYDVQQIEwpDYWxpZm9ybmlh
|
||||
MB4XDTI2MDQwOTEyNDYwMFoXDTQxMDQwNTEyNDYwMFowYjEZMBcGA1UEChMQQ2xv
|
||||
dWRGbGFyZSwgSW5jLjEdMBsGA1UECxMUQ2xvdWRGbGFyZSBPcmlnaW4gQ0ExJjAk
|
||||
BgNVBAMTHUNsb3VkRmxhcmUgT3JpZ2luIENlcnRpZmljYXRlMIIBIjANBgkqhkiG
|
||||
9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwnW7egyN30IndtYbCdk4EA9IVb+icJo4d9mR
|
||||
Bsiw4TJ6YSlnFkVXuHl1iitSZiMnlGxHke5AsDGm8rnyCa5BzT/n+VI27WwyncoO
|
||||
PJXjSjOFIWVg/VAaHJUwXcc+taqNn/U3661iSN+1TlJFgpVwF6ei6t+raJcCAXxN
|
||||
ajrA3ksf4FhMWQcpdi6J0ecM8LWsa94nNHFZJCH8nTGsND90zw7ueOMu5JIhc6Ru
|
||||
0Iw5kke2jIkhVQpg4DYTzKoEa1SmgGCZAPBlBaOc7Ii4VpVMmydhRh0TFDZbe5Bz
|
||||
lgVMslOSj1qnq4o7nFCk0LY8gfSykbuKJEHr/aboOEkot+E4kwIDAQABo4IBJDCC
|
||||
ASAwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcD
|
||||
ATAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBThHBF5Sw8X+uuHUB0NIANwIakBsjAf
|
||||
BgNVHSMEGDAWgBQk6FNXXXw0QIep65TbuuEWePwppDBABggrBgEFBQcBAQQ0MDIw
|
||||
MAYIKwYBBQUHMAGGJGh0dHA6Ly9vY3NwLmNsb3VkZmxhcmUuY29tL29yaWdpbl9j
|
||||
YTAlBgNVHREEHjAcgg0qLnphaW5lenEuY29tggt6YWluZXpxLmNvbTA4BgNVHR8E
|
||||
MTAvMC2gK6AphidodHRwOi8vY3JsLmNsb3VkZmxhcmUuY29tL29yaWdpbl9jYS5j
|
||||
cmwwDQYJKoZIhvcNAQELBQADggEBALfCfzqPuLXLepdyY/O8j9+0kiwdgby6ir1x
|
||||
1O8HKm0y47WZx7nntromSo4Bgq+R1KglUCvkcy+kCwlsfFk1WmCgVMiE9WCnn6Pv
|
||||
NriftoM5Q1tiHeSR0kLOJ9mROmiy5roThMm2EOWCjhWw2jJzVfvTj1s651dpmGRj
|
||||
E6BoX6NJr9NvzVEeCqhgjoiCXIv5bfGEwl1Mj/mIj2/GIbLiayT90vi8T89ixgca
|
||||
RTLlmRiEEJnKP0NN45vGYjgtJCgkXtCDL0lfSBt5FuEXq4sXIjDhhIn/hH004doJ
|
||||
fHlwK4tTfpZPYterSRRuy4zSgV7IekKS2z9pjCloQbDbMjqnAKI=
|
||||
-----END CERTIFICATE-----
|
||||
|
||||
|
||||
```
|
||||
|
||||
# Private key
|
||||
|
||||
```
|
||||
-----BEGIN PRIVATE KEY-----
|
||||
MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDCdbt6DI3fQid2
|
||||
1hsJ2TgQD0hVv6Jwmjh32ZEGyLDhMnphKWcWRVe4eXWKK1JmIyeUbEeR7kCwMaby
|
||||
ufIJrkHNP+f5UjbtbDKdyg48leNKM4UhZWD9UBoclTBdxz61qo2f9TfrrWJI37VO
|
||||
UkWClXAXp6Lq36tolwIBfE1qOsDeSx/gWExZByl2LonR5wzwtaxr3ic0cVkkIfyd
|
||||
Maw0P3TPDu544y7kkiFzpG7QjDmSR7aMiSFVCmDgNhPMqgRrVKaAYJkA8GUFo5zs
|
||||
iLhWlUybJ2FGHRMUNlt7kHOWBUyyU5KPWqerijucUKTQtjyB9LKRu4okQev9pug4
|
||||
SSi34TiTAgMBAAECggEADPLiBQKI//Dbx+IB8unv/cHGw077dhwO3owySA1dGeHO
|
||||
nGGxZ54+dR5BYW35EqwMmqmLKoB+9jyYLVmMcHCWGSDERanf1nd591/ZCtfARtSf
|
||||
bNXfW37V/klA6z21Q0uUGq6thpgJD2k2HX0E++kPicOz6YfzVgeYLpkkXoqDBUpF
|
||||
dzC+eGZDzjI1BECoW/N/U3P2F8nv7fHv/4xVudkMehlkPJ56BiMbx2K15jvh2Dyz
|
||||
znZvelNNw/XRHv29GgOkggh4BQRDXHl3/mTMTe8JmLWU560rNZ99xjpv1lrbqwuO
|
||||
W5WNRKcQRXCELXsEDiH1dEsteU1wVUaOyZSzEg6OYQKBgQD4InmF5kuhPrgnNwKu
|
||||
uRYZB60JFvkVdxal1xIGDwjylWBVsWWJEIAko3wbt6iI2/r1Est4tsBnap9nMciG
|
||||
Zn4FKJRAj0bZW6CwFHUZy6q91qK7JFM1e1dcrDXhgFOCG4rI802roPSjCo/rztkI
|
||||
LEQomGbMVs/86KtqaSRqVjGXXQKBgQDIn7StCglsRD/+RDWFIgtSOJbdIe0imP1h
|
||||
ewRa7iSKBMbc8ZFwDuZ3JxDI1a0DTQdMM3MpZRtGO2urnnepNV3fqSnZaaruaEL0
|
||||
1IKvCtZn1MHMEi4gErqpEBqgHfvSOIBvFhKQ6bbclmZJ5u1OFBrbu9EALfLk1Tkz
|
||||
Luje1fnArwKBgF7zIjlgtJQRIfqvjDE71f7h9w7BYbMbDOmM8PKskinxixl/dnEK
|
||||
hV5/yJ/6mV01gESDWqTomZt5K2IbpLX5RkPHEWPa76uA6m42hdDHJKDcHw0pi0Wt
|
||||
2vI1W7DcoBfrXiIjKBeC0doJ0qTTVC1Scwpttvh+R7xpdB6V+T9PmE5pAoGBALhm
|
||||
On31xLVzgdImRX8JzJgVFW1JOpnbPsFzfYxKaOFHBLWdf40c1O3dxUqjQ3POQA/l
|
||||
FkuM9+W0xgEnFVs8hv0FkkaYHhklUa2RClDzSCCFaF82spiePl0YRTC4fnY5oqr4
|
||||
Abaaao4T2w7AJ4vlZM5ksfRVR3TXGs0Vp8rxp65XAoGAPNgi8uz9zcAp5tUizZVg
|
||||
6nP68Cws6I3PmExMnbr2BmYAi2tl2NY93PQG1OT9MZ51Z0W+ynM6nTzti2zm7iXO
|
||||
Rs4AAsErEG1YDt4U0GExJdoEBIJ14+9Q6PSYPAMBbx0nv1WA1hvdvDHIUaYNPWqZ
|
||||
wuSVw419xlxUkj9uCb1kQoo=
|
||||
-----END PRIVATE KEY-----
|
||||
|
||||
|
||||
```
|
||||
24
Technical/Server/Gitea.md
Executable file
24
Technical/Server/Gitea.md
Executable file
@@ -0,0 +1,24 @@
|
||||
---
|
||||
note type:
|
||||
- server
|
||||
- note
|
||||
date: 2026-06-03
|
||||
done: true
|
||||
---
|
||||
In order to connect to the gitea server and run git commands, you will need to do the following:
|
||||
|
||||
Run `cat ~/.ssh/id_ed25519.pub`
|
||||
|
||||
Copy that key and add it to the ssh keys in gitea
|
||||
|
||||
`ssh-keygen -t ed25519 -C "windows-gitea"`
|
||||
|
||||
`ssh -T -p 222 git@192.168.0.241`
|
||||
|
||||
Check the remote url of the git project.
|
||||
|
||||
`git remote -v`
|
||||
|
||||
Change it to:
|
||||
|
||||
`git remote set-url origin git@`
|
||||
289
Technical/Server/Nextcloud.md
Executable file
289
Technical/Server/Nextcloud.md
Executable file
@@ -0,0 +1,289 @@
|
||||
---
|
||||
note type:
|
||||
- note
|
||||
- server
|
||||
date: 2026-06-03
|
||||
done: true
|
||||
---
|
||||
# The docker file:
|
||||
|
||||
``` bash
|
||||
|
||||
version: '3.8'
|
||||
services:
|
||||
app:
|
||||
image: nextcloud
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- 8007:80
|
||||
volumes:
|
||||
- nextcloud:/var/www/html
|
||||
environment:
|
||||
- POSTGRES_DB=nextcloud
|
||||
- POSTGRES_USER=nextcloud
|
||||
- POSTGRES_PASSWORD=zxq123_nextcloud
|
||||
- POSTGRES_HOST=postgres
|
||||
networks:
|
||||
- postgres_network
|
||||
|
||||
volumes:
|
||||
nextcloud:
|
||||
|
||||
networks:
|
||||
postgres_network:
|
||||
external: true
|
||||
|
||||
```
|
||||
|
||||
# Database related things:
|
||||
|
||||
``` bash
|
||||
|
||||
zxq_db=# CREATE DATABASE nextcloud;
|
||||
CREATE DATABASE
|
||||
zxq_db=# CREATE USER nextcloud WITH PASSWORD 'zxq123_nextcloud';
|
||||
CREATE ROLE
|
||||
zxq_db=# GRANT ALL PRIVILEGES ON DATABASE nextcloud TO nextcloud;
|
||||
GRANT
|
||||
zxq_db=#
|
||||
|
||||
```
|
||||
|
||||
# Permissions:
|
||||
|
||||
## **Not sure if the below still applies**
|
||||
|
||||
``` bash
|
||||
|
||||
# Add yourself and www-data to a shared group
|
||||
|
||||
### Create a shared group:
|
||||
|
||||
sudo groupadd ncshare
|
||||
|
||||
### Add both users:
|
||||
|
||||
sudo usermod -aG ncshare zaine
|
||||
sudo usermod -aG ncshare www-data
|
||||
|
||||
### Set the folder to that group:
|
||||
|
||||
sudo chown -R zaine:ncshare /home/zaine/master-folder
|
||||
sudo chmod -R 775 /home/zaine/master-folder
|
||||
|
||||
|
||||
```
|
||||
|
||||
## \<2026-03-25 Wed\> fixes:
|
||||
|
||||
Up To Date Fixes:
|
||||
We need to add zaine to the www-data group:
|
||||
|
||||
``` bash
|
||||
sudo usermod -aG www-data zaine
|
||||
```
|
||||
|
||||
Then we need to make the directories setgid, so that any new files created will have the group www-data:
|
||||
|
||||
``` bash
|
||||
sudo chown -R zaine:www-data /home/zaine/master-folder
|
||||
sudo chmod -R 2775 /home/zaine/master-folder # the 2 sets the setgid bit, which means that new files will inherit the group of the directory, which is www-data
|
||||
```
|
||||
|
||||
### Older fixes
|
||||
|
||||
So apparently, nextcloud needs to have www-data as the owner of the files, and to do that, we need to run the following command:
|
||||
|
||||
``` bash
|
||||
sudo chown -R www-data:www-data /home/zaine/master-folder
|
||||
```
|
||||
|
||||
I modified the build scripts to change permissions back to zaine:zaine when deleting the output folder, then changing it back to www-<data:www-data>.
|
||||
|
||||
One other useful thing may be:
|
||||
|
||||
``` bash
|
||||
|
||||
docker exec -u 1000:1000 -it nextcloud-app-1 php occ files:scan --all
|
||||
|
||||
# or
|
||||
|
||||
docker exec -u 1000 nextcloud-app-1 php occ files:scan --path="zaine/files/master-folder"
|
||||
|
||||
```
|
||||
|
||||
One other thing:
|
||||
|
||||
``` bash
|
||||
i FIXED IT BY doing this:
|
||||
|
||||
zaine@zaine-HP-ProDesk-400-G1-SFF [09:47:47] [~/docker-services/nextcloud]
|
||||
-> % docker exec -it postgres psql -U nextcloud -d nextcloud
|
||||
psql (17.5 (Debian 17.5-1.pgdg120+1))
|
||||
Type "help" for help.
|
||||
|
||||
nextcloud=> SELECT * FROM oc_file_locks;
|
||||
nextcloud=> DELETE FROM oc_file_locks;
|
||||
DELETE 15002
|
||||
nextcloud=> \q
|
||||
zaine@zaine-HP-ProDesk-400-G1-SFF [09:49:01] [~/docker-services/nextcloud]
|
||||
-> % docker exec -it nextcloud-app-1 ls /mnt/master-folder
|
||||
alimiyyah attachments booking career hurra.txt org_files pdfs projects uni
|
||||
zaine@zaine-HP-ProDesk-400-G1-SFF [09:49:04] [~/docker-services/nextcloud]
|
||||
-> % docker exec -u 1000 -it nextcloud-app-1 php occ files:scan --all
|
||||
Starting scan for user 1 out of 2 (halima)
|
||||
Starting scan for user 2 out of 2 (zaine)
|
||||
+---------+-------+-----+---------+---------+--------+--------------+
|
||||
| Folders | Files | New | Updated | Removed | Errors | Elapsed time |
|
||||
+---------+-------+-----+---------+---------+--------+--------------+
|
||||
| 1985 | 12906 | 0 | 522 | 0 | 0 | 00:00:50 |
|
||||
+---------+-------+-----+---------+---------+--------+--------------+
|
||||
zaine@zaine-HP-ProDesk-400-G1-SFF [09:49:59] [~/docker-services/nextcloud]
|
||||
-> %
|
||||
|
||||
there is some issue in the nextcloud permissions itself. if i create a file and delete it in windows, i get this error in the client: A
|
||||
master-folder/hehe.txt
|
||||
now
|
||||
The resource you are trying to access is currently locked and cannot be modified. Please try changing it later, or contact your server administrator ...
|
||||
|
||||
and if i try to delete it in nextcloud ui (web), it says file cant be deleted
|
||||
|
||||
```
|
||||
|
||||
# Config
|
||||
|
||||
Location is:
|
||||
|
||||
sudo nano /var/lib/docker/volumes/nextcloud<sub>nextcloud</sub>/<sub>data</sub>/config/config.php
|
||||
|
||||
# Accounts
|
||||
|
||||
User is: zaine
|
||||
Pass: Shakkal123\!
|
||||
|
||||
# Legacy stuff
|
||||
|
||||
Something I've been trying to reverse proxy ahead of time. Go to <https://zserver.zapto.org/nextcloud> , you'll be prompted to login with a username and password:
|
||||
Here's your credentials:
|
||||
|
||||
Username: halima
|
||||
Password: loser2104\!
|
||||
|
||||
Once you've logged in, I've set up your account already, so there should be a calendar already there.
|
||||
|
||||
To get your phone logged in, there's two ways:
|
||||
|
||||
1. go to the following address: <https://zserver.zapto.org/nextcloud/settings/user/security> , scroll to the bottom, under devices and sessions, type in a random name (iphone), and click create new app password. You should then be able to generate a QR code (next to or under the password field), then you can scan that on your iphone app.
|
||||
|
||||
2. inside the app, type the following URL: <https://zserver.zapto.org/nextcloud> then follow the instructions.
|
||||
|
||||
Im thinking of having this as our shared calendar and file system. The only users are us 2 and its completely off the internet (self-hosted).
|
||||
|
||||
## network issues resolved by:
|
||||
|
||||
``` bash
|
||||
|
||||
docker network connect postgres_network postgres
|
||||
|
||||
zaine@zaine-HP-ProDesk-400-G1-SFF [21:00:27] [~/docker-services/nextcloud]
|
||||
-> % psql -h zserver.zapto.org -p 5432 -U zaine -d zxq_db
|
||||
Password for user zaine:
|
||||
psql (14.18 (Ubuntu 14.18-0ubuntu0.22.04.1), server 17.5 (Debian 17.5-1.pgdg120+1))
|
||||
WARNING: psql major version 14, server major version 17.
|
||||
Some psql features might not work.
|
||||
Type "help" for help.
|
||||
|
||||
zxq_db=# \c nextcloud
|
||||
psql (14.18 (Ubuntu 14.18-0ubuntu0.22.04.1), server 17.5 (Debian 17.5-1.pgdg120+1))
|
||||
WARNING: psql major version 14, server major version 17.
|
||||
Some psql features might not work.
|
||||
You are now connected to database "nextcloud" as user "zaine".
|
||||
nextcloud=# GRANT ALL PRIVILEGES ON DATABASE nextcloud TO nextcloud;
|
||||
GRANT
|
||||
nextcloud=# GRANT USAGE ON SCHEMA public TO nextcloud;
|
||||
GRANT CREATE ON SCHEMA public TO nextcloud;
|
||||
GRANT
|
||||
GRANT
|
||||
nextcloud=# GRANT ALL PRIVILEGES ON ALL TABLES IN SCHEMA public TO nextcloud;
|
||||
GRANT
|
||||
nextcloud=# GRANT ALL PRIVILEGES ON ALL SEQUENCES IN SCHEMA public TO nextcloud;
|
||||
GRANT
|
||||
nextcloud=#
|
||||
|
||||
zaine
|
||||
M22ZN-fmefj-RdF36-3BMfT-LfWo8
|
||||
|
||||
zaine
|
||||
zxh123!
|
||||
|
||||
```
|
||||
|
||||
## Connecting to IOS
|
||||
|
||||
<https://www.reddit.com/r/NextCloud/comments/1pehpft/calendar_app_for_ios/>
|
||||
|
||||
# ICS stuff:
|
||||
|
||||
## To get the ID of a calendar subscription:
|
||||
|
||||
```
|
||||
zaine@zaine-HP-ProDesk-400-G1-SFF [14:14:27] [~]
|
||||
-> % docker exec nextcloud-app-1 php occ dav:list-subscriptions zaine
|
||||
+-----------------------+-----------------------+----------------+-------------------------------------------------------------------------------------------------------------------------------------------------------------+
|
||||
| URI | Displayname | Refresh rate | Source |
|
||||
+-----------------------+-----------------------+----------------+-------------------------------------------------------------------------------------------------------------------------------------------------------------+
|
||||
| outlookoffice365com-1 | outlook.office365.com | PT5M (default) | https://outlook.office365.com/owa/calendar/b910ea835e414663831e505f3d10baa2@microlise.com/d2568a0134fb49af92d39c1669c4729317662288011094411305/calendar.ics |
|
||||
+-----------------------+-----------------------+----------------+-------------------------------------------------------------------------------------------------------------------------------------------------------------+
|
||||
|
||||
|
||||
```
|
||||
|
||||
## emacs config to sync calendars:
|
||||
|
||||
```
|
||||
(require 'org-caldav)
|
||||
(require 'url)
|
||||
(require 'icalendar)
|
||||
(modify-coding-system-alist 'file "caldav-work\\.org\\'" 'utf-8-unix)
|
||||
(defvar my/outlook-ics-url
|
||||
"https://outlook.office365.com/owa/calendar/b910ea835e414663831e505f3d10baa2@microlise.com/d2568a0134fb49af92d39c1669c4729317662288011094411305/calendar.ics")
|
||||
|
||||
(defvar my/outlook-org-file
|
||||
"D:\\_nextcloud\\master-folder\\org_files\\calendar\\caldav-work.org")
|
||||
|
||||
(defvar my/ics-python-script
|
||||
"D:\\_nextcloud\\master-folder\\org_files\\calendar\\ics_to_org.py")
|
||||
|
||||
(defun my/sync-outlook-calendar ()
|
||||
"Fetch and expand Outlook ICS (including recurrences) into org file."
|
||||
(interactive)
|
||||
(message "Syncing Outlook calendar...")
|
||||
(let* ((cmd (format "python \"%s\" \"%s\" \"%s\""
|
||||
my/ics-python-script
|
||||
my/outlook-ics-url
|
||||
my/outlook-org-file))
|
||||
(result (shell-command-to-string cmd)))
|
||||
(message "Outlook calendar sync: %s" (string-trim result))))
|
||||
|
||||
;; Sync on startup and every 30 minutes
|
||||
(my/sync-outlook-calendar)
|
||||
(run-with-timer (* 30 60) (* 30 60) #'my/sync-outlook-calendar)
|
||||
;; --- CalDAV for native Nextcloud calendars ---
|
||||
(setq org-caldav-url "https://nextcloud.zainezq.com/remote.php/dav/calendars/zaine/")
|
||||
(setq org-caldav-calendars
|
||||
'((:calendar-id "personal"
|
||||
:inbox "D:\\_nextcloud\\master-folder\\org_files\\calendar\\caldav-personal.org"
|
||||
:files nil)
|
||||
(:calendar-id "zxh"
|
||||
:inbox "D:\\_nextcloud\\master-folder\\org_files\\calendar\\caldav-family.org"
|
||||
:files nil)))
|
||||
|
||||
;; --- Agenda files ---
|
||||
(setq org-agenda-files
|
||||
'("D:\\_nextcloud\\master-folder\\org_files\\calendar\\caldav-personal.org"
|
||||
"D:\\_nextcloud\\master-folder\\org_files\\calendar\\caldav-work.org"
|
||||
"D:\\_nextcloud\\master-folder\\org_files\\calendar\\caldav-family.org"
|
||||
"D:\\_nextcloud\\master-folder\\org_files\\org_roam\\Books\\20250724230557-books_org_agenda.org"))
|
||||
|
||||
|
||||
```
|
||||
265
Technical/Server/Old NGINX Code.md
Executable file
265
Technical/Server/Old NGINX Code.md
Executable file
@@ -0,0 +1,265 @@
|
||||
---
|
||||
note type:
|
||||
- server
|
||||
- note
|
||||
date: 2026-06-03
|
||||
done: true
|
||||
---
|
||||
``` bash
|
||||
|
||||
|
||||
-> % cat /etc/nginx/sites-available/zserver
|
||||
|
||||
|
||||
server {
|
||||
server_name zainezq.com;
|
||||
|
||||
access_log /var/log/nginx/zserver.access.log combined;
|
||||
error_log /var/log/nginx/zserver.error.log warn;
|
||||
# Basic authentication for the entire server
|
||||
auth_basic "Restricted Access";
|
||||
auth_basic_user_file /etc/nginx/.htpasswd;
|
||||
|
||||
# Root location
|
||||
location / {
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_redirect off;
|
||||
|
||||
root /home/zaine/master-folder/org_files/org_web/output;
|
||||
index index.html index.htm;
|
||||
try_files $uri $uri/ =404;
|
||||
}
|
||||
|
||||
location /nginx_status {
|
||||
stub_status;
|
||||
}
|
||||
|
||||
location /dockge/ {
|
||||
proxy_pass http://127.0.0.1:5021/;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
}
|
||||
|
||||
|
||||
|
||||
location /guac/ {
|
||||
proxy_pass http://127.0.0.1:3003/guacamole/;
|
||||
proxy_http_version 1.1;
|
||||
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection $connection_upgrade;
|
||||
}
|
||||
|
||||
# PGAdmin4 location
|
||||
location /pgadmin4/ {
|
||||
proxy_set_header X-Script-Name /pgadmin4;
|
||||
proxy_set_header Host $host;
|
||||
proxy_pass http://127.0.0.1:5050;
|
||||
proxy_redirect off;
|
||||
}
|
||||
|
||||
location /pdf/ {
|
||||
proxy_pass http://127.0.0.1:8002/pdf/;
|
||||
proxy_set_header X-Script-Name /pdf;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header Host $host;
|
||||
proxy_redirect off;
|
||||
}
|
||||
|
||||
location /calibre {
|
||||
proxy_bind $server_addr;
|
||||
proxy_pass http://127.0.0.1:8083;
|
||||
proxy_set_header Host $http_host;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Scheme $scheme;
|
||||
proxy_set_header X-Script-Name /calibre; # IMPORTANT: path has NO trailing slash
|
||||
# This rewrites Calibre-Web's internal paths
|
||||
proxy_redirect off;
|
||||
proxy_http_version 1.1;
|
||||
client_max_body_size 100M;
|
||||
}
|
||||
|
||||
|
||||
location /codeserver/ {
|
||||
proxy_pass http://localhost:8441/;
|
||||
rewrite ^/codeserver(/.*)$ $1 break;
|
||||
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
proxy_set_header Accept-Encoding gzip;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
}
|
||||
|
||||
location /filebrowser {
|
||||
# prevents 502 bad gateway error
|
||||
proxy_buffers 8 32k;
|
||||
proxy_buffer_size 64k;
|
||||
|
||||
client_max_body_size 75M;
|
||||
|
||||
# redirect all HTTP traffic to localhost:8088;
|
||||
proxy_pass http://127.0.0.1:9991;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header Host $http_host;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
#proxy_set_header X-NginX-Proxy true;
|
||||
|
||||
# enables WS support
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
|
||||
proxy_read_timeout 999999999;
|
||||
}
|
||||
|
||||
|
||||
# Miniflux location
|
||||
location /miniflux/ {
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_pass http://127.0.0.1:9433/miniflux/;
|
||||
proxy_redirect off;
|
||||
}
|
||||
|
||||
# Jupyter location
|
||||
location /jupyter/ {
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_pass http://127.0.0.1:8888/jupyter/;
|
||||
proxy_redirect off;
|
||||
|
||||
# WebSocket support
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "Upgrade";
|
||||
}
|
||||
|
||||
location /portainer/ {
|
||||
proxy_pass https://localhost:9443/;
|
||||
proxy_ssl_verify off; # Because Portainer uses a self-signed cert by default
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header Authorization "";
|
||||
# Required for WebSocket support
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
|
||||
# Rewrite URL base path
|
||||
rewrite ^/portainer(/.*)$ $1 break;
|
||||
}
|
||||
|
||||
location /wireguard/ {
|
||||
proxy_pass http://127.0.0.1:124/;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "Upgrade";
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
|
||||
# Rewrite assets for subpath compatibility
|
||||
proxy_set_header Accept-Encoding "";
|
||||
sub_filter 'href="/' 'href="/wireguard/';
|
||||
sub_filter 'src="/' 'src="/wireguard/';
|
||||
sub_filter_types text/css application/javascript;
|
||||
sub_filter_once off;
|
||||
}
|
||||
|
||||
# /password -> /password/
|
||||
location = /password { return 301 /password/; }
|
||||
|
||||
# Main app/API (disable inherited basic auth here)
|
||||
location ^~ /password/ {
|
||||
auth_basic off;
|
||||
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
|
||||
# WebSockets
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
|
||||
# Keep the /password prefix upstream (NO trailing slash here)
|
||||
proxy_pass http://127.0.0.1:8006;
|
||||
}
|
||||
|
||||
# (Optional but tidy) If you keep a dedicated WS block, disable auth there too
|
||||
location ^~ /password/notifications/hub {
|
||||
auth_basic off;
|
||||
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
proxy_set_header Host $host;
|
||||
|
||||
proxy_pass http://127.0.0.1:8006;
|
||||
}
|
||||
|
||||
|
||||
# Optional: Add a custom error page
|
||||
error_page 500 502 503 504 /50x.html;
|
||||
location = /50x.html {
|
||||
root /usr/share/nginx/html;
|
||||
}
|
||||
|
||||
# Optional: Cache static assets for performance (add this new block)
|
||||
# location ~* \.(jpg|jpeg|png|gif|ico|css|js|woff|woff2|ttf|eot|svg|html|htm)$ {
|
||||
# root /home/zaine/master-folder/org_files/org_web/output;
|
||||
# expires 30d;
|
||||
# access_log off;
|
||||
# }
|
||||
|
||||
# Optional: Deny access to hidden files
|
||||
location ~ /\. {
|
||||
deny all;
|
||||
}
|
||||
|
||||
listen 443 ssl; # managed by Certbot
|
||||
ssl_certificate /etc/letsencrypt/live/zainezq.com-0001/fullchain.pem; # managed by Certbot
|
||||
ssl_certificate_key /etc/letsencrypt/live/zainezq.com-0001/privkey.pem; # managed by Certbot
|
||||
include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
|
||||
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
}
|
||||
|
||||
|
||||
server {
|
||||
if ($host = zserver.zapto.org) {
|
||||
return 301 https://$host$request_uri;
|
||||
} # managed by Certbot
|
||||
|
||||
listen 80;
|
||||
server_name zserver.zapto.org;
|
||||
return 404; # managed by Certbot
|
||||
}
|
||||
|
||||
```
|
||||
70
Technical/Server/Old Nextcloud.md
Executable file
70
Technical/Server/Old Nextcloud.md
Executable file
@@ -0,0 +1,70 @@
|
||||
---
|
||||
note type:
|
||||
- server
|
||||
- note
|
||||
date: 2026-06-03
|
||||
done: true
|
||||
---
|
||||
# wg
|
||||
|
||||
Shakkal123\!
|
||||
|
||||
docker run ghcr.io/wg-easy/wg-easy:14 node -e 'const bcrypt = require("bcryptjs"); const hash = bcrypt.hashSync("Shakkal123\!", 10); console.log(hash.replace(/\\$/g, "\[\]"));'
|
||||
|
||||
Unable to find image 'ghcr.io/wg-easy/wg-easy:14' locally
|
||||
14: Pulling from wg-easy/wg-easy
|
||||
Digest: sha256:5f26407fd2ede54df76d63304ef184576a6c1bb73f934a58a11abdd852fab549
|
||||
Status: Downloaded newer image for ghcr.io/wg-easy/wg-easy:14
|
||||
|
||||
\[2a\]10$$E1lkGe/IH5EnFrQLhDH2M.yKk3Q7KlgRuu.fzf/76CbWoAMy4G83u
|
||||
|
||||
# nextcloud:
|
||||
|
||||
location ^\~ *nextcloud* {
|
||||
auth<sub>basic</sub> off;
|
||||
|
||||
proxy<sub>pass</sub> <http://localhost:8007/>;
|
||||
proxy<sub>setheader</sub> Host $host;
|
||||
proxy<sub>setheader</sub> X-Real-IP $remote<sub>addr</sub>;
|
||||
proxy<sub>setheader</sub> X-Forwarded-For $proxy<sub>addxforwardedfor</sub>;
|
||||
proxy<sub>setheader</sub> X-Forwarded-Proto $scheme;
|
||||
|
||||
proxy<sub>httpversion</sub> 1.1;
|
||||
proxy<sub>setheader</sub> Upgrade $http<sub>upgrade</sub>;
|
||||
proxy<sub>setheader</sub> Connection "upgrade";
|
||||
|
||||
client<sub>maxbodysize</sub> 512M;
|
||||
client<sub>bodybuffersize</sub> 512k;
|
||||
|
||||
add<sub>header</sub> Referrer-Policy "no-referrer" always;
|
||||
add<sub>header</sub> X-Content-Type-Options "nosniff" always;
|
||||
add<sub>header</sub> X-Frame-Options "SAMEORIGIN" always;
|
||||
add<sub>header</sub> X-XSS-Protection "1; mode=block" always;
|
||||
}
|
||||
|
||||
location ^\~ /.well-known/carddav {
|
||||
return 301 $scheme://$host/nextcloud/remote.php/dav;
|
||||
}
|
||||
|
||||
location ^\~ /.well-known/caldav {
|
||||
return 301 $scheme://$host/nextcloud/remote.php/dav;
|
||||
}
|
||||
|
||||
location ^\~ /.well-known {
|
||||
return 301 $scheme://$host/nextcloud/index.php$uri;
|
||||
}
|
||||
|
||||
# technitium
|
||||
|
||||
location *technitium* {
|
||||
proxy<sub>pass</sub> <http://localhost:5380/>;
|
||||
proxy<sub>httpversion</sub> 1.1;
|
||||
proxy<sub>setheader</sub> Host $host;
|
||||
proxy<sub>setheader</sub> X-Real-IP $remote<sub>addr</sub>;
|
||||
proxy<sub>setheader</sub> X-Forwarded-For $proxy<sub>addxforwardedfor</sub>;
|
||||
proxy<sub>setheader</sub> X-Forwarded-Proto $scheme;
|
||||
|
||||
rewrite ^/technitium/(.\*)$ /$1 break;
|
||||
}
|
||||
|
||||
curl -X GET "<https://zserver.zapto.org/portainer/api/endpoints/3/docker/containers/json?all=true>" -H "X-API-Key: ptr<sub>KFQqKse9K4Nc9M5jnpc61fpAvGzdTOXTzswz9CwOF74</sub>=" -u "admin:shakkal123"
|
||||
102
Technical/Server/Server Backend.md
Executable file
102
Technical/Server/Server Backend.md
Executable file
@@ -0,0 +1,102 @@
|
||||
---
|
||||
note type:
|
||||
- note
|
||||
- server
|
||||
date: 2026-06-03
|
||||
done: true
|
||||
---
|
||||
# Introduction
|
||||
|
||||
The original backend was written using FastAPI and has now been archived.
|
||||
|
||||
In replacement, I have written a Java Spring Boot backend that handles all of the API calls the domain `zainezq.com` uses.
|
||||
|
||||
Here is the repository for the backend:
|
||||
|
||||
[Link to the backend repository](https://gitea.zainezq.com/zaine/org_backend)
|
||||
|
||||
# Structure
|
||||
|
||||
The backend is structured as a typical Spring Boot application. It consists of several packages that handle different aspects of the application:
|
||||
|
||||
- ****Controllers****: These classes handle incoming HTTP requests and map them to appropriate service methods.
|
||||
- ****Services****: These classes contain the business logic of the application.
|
||||
- ****Repositories****: These classes interact with the database to perform CRUD operations.
|
||||
- ****Models****: These classes represent the data structures used in the application.
|
||||
|
||||
The full list of API endpoints can be viewed using Swagger UI, which is available at the `/swagger-ui.html` endpoint once the application is running.
|
||||
|
||||
# Running the Application
|
||||
|
||||
The application is built using Maven. To run the application, you can utilise the `Makefile` provided in the repository.
|
||||
|
||||
The project is packaged as a Docker container, making it easy to deploy. You can build and run the Docker container using the following commands:
|
||||
|
||||
``` bash
|
||||
|
||||
docker compose build org_backend
|
||||
|
||||
docker compose up -d org_backend
|
||||
|
||||
# Alternatively:
|
||||
docker compose down && docker compose build --no-cache && docker compose up -d
|
||||
|
||||
# To check logs
|
||||
|
||||
docker logs -f org_backend
|
||||
|
||||
```
|
||||
|
||||
# Bruno
|
||||
|
||||
Bruno is used for testing the backend API endpoints. It is a simple HTTP client that allows you to send requests to the backend and view the responses. I used the OpenAPI specification to generate Bruno tests for each endpoint.
|
||||
|
||||
# Authentication
|
||||
|
||||
The backend exposes public `/api/auth/register` and `/api/auth/login` endpoints. The website has a login page only; users are created through the API, then the login page stores the returned JWT in the browser.
|
||||
|
||||
Protected requests include:
|
||||
|
||||
``` text
|
||||
Authorization: Bearer <jwt-token>
|
||||
```
|
||||
|
||||
# Future?
|
||||
|
||||
## Integration with `notes.zainezq.com`
|
||||
|
||||
As the API is primarily used by `zainezq.com`, I want to think of ways that `notes.zainezq.com` could also use it. This website is used to store all my notes, and they are exported using `org-publish` in Emacs. Perhaps I could write an Emacs Lisp package that interacts with the backend API to store and retrieve notes.
|
||||
|
||||
Flow of how a note would be written:
|
||||
|
||||
1. User writes a note in `notes.zainezq.com` as org mode.
|
||||
2. When the note is saved, a POST request is sent to the backend API with the note content.
|
||||
3. The backend API stores the note in the database.
|
||||
4. This will trigger a function that republishes the notes website to include the new note.
|
||||
|
||||
****Need to think more about this.****
|
||||
|
||||
# Update
|
||||
|
||||
The org-backend is no longer hosted using docker, it is now using systemd. The backend is still built using Maven, but it is now deployed as a standalone application rather than a Docker container.
|
||||
|
||||
Here are the commands needed:
|
||||
|
||||
``` bash
|
||||
|
||||
# To build the application
|
||||
mvn clean package -DskipTests
|
||||
|
||||
# To run the application
|
||||
java -jar target/org_backend-1.0.0-SNAPSHOT.jar
|
||||
|
||||
# systemctl commands
|
||||
sudo systemctl start org_backend
|
||||
sudo systemctl stop org_backend
|
||||
sudo systemctl restart org_backend
|
||||
sudo systemctl status org_backend
|
||||
|
||||
# To check logs
|
||||
journalctl -u org_backend -f
|
||||
|
||||
```
|
||||
22
Technical/Server/Server MOC.md
Executable file
22
Technical/Server/Server MOC.md
Executable file
@@ -0,0 +1,22 @@
|
||||
---
|
||||
note type:
|
||||
- moc
|
||||
- server
|
||||
date: 2026-06-03
|
||||
done: true
|
||||
---
|
||||
- [[Old Nextcloud]]
|
||||
|
||||
- [[Old NGINX Code]]
|
||||
|
||||
- [[Actual (finance)]]
|
||||
|
||||
- [[Server Backend]]
|
||||
|
||||
- [[Nextcloud]]
|
||||
|
||||
- [[Vaultwarden]]
|
||||
|
||||
- [[Cloudflare]]
|
||||
|
||||
- [[Gitea]]
|
||||
16
Technical/Server/Vaultwarden.md
Executable file
16
Technical/Server/Vaultwarden.md
Executable file
@@ -0,0 +1,16 @@
|
||||
---
|
||||
note type:
|
||||
- note
|
||||
- server
|
||||
date: 2026-06-03
|
||||
done: true
|
||||
---
|
||||
Just ran into an issue where the IOS app was failing due to the latest version of bitwarden not being installed on the server. To fix this:
|
||||
|
||||
``` bash
|
||||
|
||||
docker compose pull
|
||||
|
||||
docker compose up -d
|
||||
|
||||
```
|
||||
Reference in New Issue
Block a user