diff options
| -rw-r--r-- | .footer.html | 7 | ||||
| -rw-r--r-- | .github/workflows/upload.yml | 3 | ||||
| -rw-r--r-- | 404.html | 27 | ||||
| -rw-r--r-- | LICENSE.md | 24 | ||||
| -rw-r--r-- | README.md | 36 | ||||
| -rw-r--r-- | archetypes/default.md | 6 | ||||
| -rw-r--r-- | auth.html | 122 | ||||
| -rwxr-xr-x | barsup | 18 | ||||
| -rw-r--r-- | bat.html | 92 | ||||
| -rw-r--r-- | bitcoin.html | 102 | ||||
| -rw-r--r-- | calibre.html | 131 | ||||
| -rw-r--r-- | certbot.html | 149 | ||||
| -rw-r--r-- | cgi.html | 268 | ||||
| -rw-r--r-- | cgit.html | 151 | ||||
| -rw-r--r-- | config.toml | 9 | ||||
| -rw-r--r-- | content/_index.md | 45 | ||||
| -rw-r--r-- | content/auth.md | 136 | ||||
| -rw-r--r-- | content/bandwidth.md | 88 | ||||
| -rw-r--r-- | content/basic/certbot.md | 132 | ||||
| -rw-r--r-- | content/basic/dns.md | 96 | ||||
| -rw-r--r-- | content/basic/domain.md | 75 | ||||
| -rw-r--r-- | content/basic/nginx.md | 212 | ||||
| -rw-r--r-- | content/basic/server.md | 98 | ||||
| -rw-r--r-- | content/bitcoin.md | 105 | ||||
| -rw-r--r-- | content/btcpay.md | 57 | ||||
| -rw-r--r-- | content/calibre.md | 116 | ||||
| -rw-r--r-- | content/cgi.md | 210 | ||||
| -rw-r--r-- | content/cgit.md | 135 | ||||
| -rw-r--r-- | content/coturn.md | 110 | ||||
| -rw-r--r-- | content/cron.md | 173 | ||||
| -rw-r--r-- | content/ejabberd.md | 259 | ||||
| -rw-r--r-- | content/federation.md | 57 | ||||
| -rw-r--r-- | content/fosspay.md | 200 | ||||
| -rw-r--r-- | content/gemini.md | 189 | ||||
| -rw-r--r-- | content/git.md | 143 | ||||
| -rw-r--r-- | content/gitea.md | 159 | ||||
| -rw-r--r-- | content/html.md | 143 | ||||
| -rw-r--r-- | content/html2.md | 7 | ||||
| -rw-r--r-- | content/html4.md | 32 | ||||
| -rw-r--r-- | content/i2p.md | 101 | ||||
| -rw-r--r-- | content/imgcompress.md | 51 | ||||
| -rw-r--r-- | content/irc.md | 946 | ||||
| -rw-r--r-- | content/jitsi.md | 199 | ||||
| -rw-r--r-- | content/mail/dovecot.md | 112 | ||||
| -rw-r--r-- | content/mail/opendkim.md | 187 | ||||
| -rw-r--r-- | content/mail/rainloop.md | 117 | ||||
| -rw-r--r-- | content/mail/rdns.md | 35 | ||||
| -rw-r--r-- | content/mail/smtp.md | 70 | ||||
| -rw-r--r-- | content/maintenance.md | 124 | ||||
| -rw-r--r-- | content/matrix.md | 139 | ||||
| -rw-r--r-- | content/monero.md | 89 | ||||
| -rw-r--r-- | content/movim.md | 116 | ||||
| -rw-r--r-- | content/nextcloud.md | 292 | ||||
| -rw-r--r-- | content/nginx-tweaks.md | 46 | ||||
| -rw-r--r-- | content/openalias.md | 102 | ||||
| -rw-r--r-- | content/page-quality.md | 180 | ||||
| -rw-r--r-- | content/peertube.md | 284 | ||||
| -rw-r--r-- | content/pleroma.md | 186 | ||||
| -rw-r--r-- | content/prosody.md | 273 | ||||
| -rw-r--r-- | content/radicale.md | 105 | ||||
| -rw-r--r-- | content/rss-bridge.md | 114 | ||||
| -rw-r--r-- | content/rsync.md | 104 | ||||
| -rw-r--r-- | content/searxng.md | 146 | ||||
| -rw-r--r-- | content/selfhosting.md | 202 | ||||
| -rw-r--r-- | content/sshkeys.md | 153 | ||||
| -rw-r--r-- | content/standalone.md | 40 | ||||
| -rw-r--r-- | content/tor.md | 119 | ||||
| -rw-r--r-- | content/ufw.md | 223 | ||||
| -rw-r--r-- | cron.html | 174 | ||||
| -rw-r--r-- | crypto.html | 86 | ||||
| -rw-r--r-- | dns.html | 129 | ||||
| -rw-r--r-- | domain.html | 146 | ||||
| -rw-r--r-- | donate-bitcoin.html | 23 | ||||
| -rw-r--r-- | donate-monero.html | 23 | ||||
| -rw-r--r-- | federation.html | 71 | ||||
| -rw-r--r-- | gemini.html | 103 | ||||
| -rw-r--r-- | git.html | 190 | ||||
| -rw-r--r-- | gitea.html | 109 | ||||
| -rw-r--r-- | html.html | 200 | ||||
| -rw-r--r-- | html2.html | 27 | ||||
| -rw-r--r-- | html4.html | 99 | ||||
| -rw-r--r-- | i2p.html | 101 | ||||
| -rw-r--r-- | index.html | 172 | ||||
| -rw-r--r-- | irc.html | 801 | ||||
| -rw-r--r-- | jitsi.html | 130 | ||||
| -rw-r--r-- | layouts/partials/footer.html | 13 | ||||
| -rw-r--r-- | layouts/shortcodes/basic.html | 8 | ||||
| -rw-r--r-- | layouts/shortcodes/maintain.html | 4 | ||||
| -rw-r--r-- | layouts/shortcodes/services.html | 4 | ||||
| -rw-r--r-- | maintenance.html | 125 | ||||
| -rw-r--r-- | matrix.html | 131 | ||||
| -rw-r--r-- | monero.html | 111 | ||||
| -rw-r--r-- | nextcloud.html | 207 | ||||
| -rw-r--r-- | nginx.html | 249 | ||||
| -rw-r--r-- | openalias.html | 121 | ||||
| -rw-r--r-- | peertube.html | 223 | ||||
| -rw-r--r-- | pix/brave-01.png | bin | 2876 -> 0 bytes | |||
| -rw-r--r-- | pix/brave-02.png | bin | 68404 -> 0 bytes | |||
| -rw-r--r-- | pix/brave-03.png | bin | 62093 -> 0 bytes | |||
| -rw-r--r-- | pix/brave-04.gif | bin | 131546 -> 0 bytes | |||
| -rw-r--r-- | pix/gitea-push-create.png | bin | 6546 -> 0 bytes | |||
| -rw-r--r-- | pix/rainloop.svg | 127 | ||||
| -rw-r--r-- | pleroma.html | 169 | ||||
| -rw-r--r-- | rainloop.html | 75 | ||||
| -rw-r--r-- | rss-bridge.html | 98 | ||||
| -rw-r--r-- | rss.xml | 2641 | ||||
| -rw-r--r-- | rsync.html | 55 | ||||
| -rw-r--r-- | selfhosting.html | 120 | ||||
| -rw-r--r-- | server.html | 146 | ||||
| -rw-r--r-- | sshkeys.html | 172 | ||||
| -rw-r--r-- | standalone.html | 32 | ||||
| -rw-r--r-- | static/favicon.ico (renamed from favicon.ico) | bin | 8894 -> 8894 bytes | |||
| -rw-r--r-- | static/pix/auth.svg (renamed from pix/auth.svg) | 0 | ||||
| -rw-r--r-- | static/pix/bat.svg (renamed from pix/bat.svg) | 0 | ||||
| -rw-r--r-- | static/pix/bitcoin-01.png (renamed from pix/bitcoin-01.png) | bin | 36149 -> 36149 bytes | |||
| -rw-r--r-- | static/pix/bitcoin-02.png (renamed from pix/bitcoin-02.png) | bin | 27352 -> 27352 bytes | |||
| -rw-r--r-- | static/pix/bitcoin-03.png (renamed from pix/bitcoin-03.png) | bin | 229921 -> 229921 bytes | |||
| -rw-r--r-- | static/pix/bitcoin-04.png (renamed from pix/bitcoin-04.png) | bin | 47177 -> 47177 bytes | |||
| -rw-r--r-- | static/pix/btc.png (renamed from pix/btc.png) | bin | 568 -> 568 bytes | |||
| -rw-r--r-- | static/pix/btc.svg (renamed from pix/btc.svg) | 0 | ||||
| -rw-r--r-- | static/pix/btcpay.svg | 1 | ||||
| -rw-r--r-- | static/pix/calibre.png (renamed from pix/calibre.png) | bin | 17440 -> 17440 bytes | |||
| -rw-r--r-- | static/pix/calibre/calibre-1.png (renamed from pix/calibre/calibre-1.png) | bin | 5823 -> 5823 bytes | |||
| -rw-r--r-- | static/pix/calibre/calibre-2.png (renamed from pix/calibre/calibre-2.png) | bin | 15884 -> 15884 bytes | |||
| -rw-r--r-- | static/pix/certbot-01.png (renamed from pix/certbot-01.png) | bin | 89656 -> 89656 bytes | |||
| -rw-r--r-- | static/pix/certbot-02.png (renamed from pix/certbot-02.png) | bin | 120319 -> 120319 bytes | |||
| -rw-r--r-- | static/pix/certbot-03.png (renamed from pix/certbot-03.png) | bin | 22865 -> 22865 bytes | |||
| -rw-r--r-- | static/pix/cgit.svg (renamed from pix/cgit.svg) | 0 | ||||
| -rw-r--r-- | static/pix/chad.gif (renamed from pix/chad.gif) | bin | 11085 -> 11085 bytes | |||
| -rw-r--r-- | static/pix/devault.jpg | bin | 0 -> 13203 bytes | |||
| -rw-r--r-- | static/pix/dkim-01.png | bin | 0 -> 32501 bytes | |||
| -rw-r--r-- | static/pix/dns-epik.png (renamed from pix/dns-epik.png) | bin | 82393 -> 82393 bytes | |||
| -rw-r--r-- | static/pix/dns-ipv4-done.png (renamed from pix/dns-ipv4-done.png) | bin | 42611 -> 42611 bytes | |||
| -rw-r--r-- | static/pix/dns-ipv4.png (renamed from pix/dns-ipv4.png) | bin | 25183 -> 25183 bytes | |||
| -rw-r--r-- | static/pix/dns-ipv6-done.png (renamed from pix/dns-ipv6-done.png) | bin | 69558 -> 69558 bytes | |||
| -rw-r--r-- | static/pix/dns-ipv6.png (renamed from pix/dns-ipv6.png) | bin | 97056 -> 97056 bytes | |||
| -rw-r--r-- | static/pix/dns-ping.png (renamed from pix/dns-ping.png) | bin | 34174 -> 34174 bytes | |||
| -rw-r--r-- | static/pix/dns-vultr.png (renamed from pix/dns-vultr.png) | bin | 78372 -> 78372 bytes | |||
| -rw-r--r-- | static/pix/domain-cart.png (renamed from pix/domain-cart.png) | bin | 91182 -> 91182 bytes | |||
| -rw-r--r-- | static/pix/domain-search.png (renamed from pix/domain-search.png) | bin | 112250 -> 112250 bytes | |||
| -rw-r--r-- | static/pix/ejabberd-admin.jpg | bin | 0 -> 22266 bytes | |||
| -rw-r--r-- | static/pix/ejabberd-login.jpg | bin | 0 -> 18399 bytes | |||
| -rw-r--r-- | static/pix/ejabberd.png | bin | 0 -> 21911 bytes | |||
| -rw-r--r-- | static/pix/element.svg (renamed from pix/element.svg) | 0 | ||||
| -rw-r--r-- | static/pix/fren_apu_tongue.png | bin | 0 -> 27581 bytes | |||
| -rw-r--r-- | static/pix/git.svg (renamed from pix/git.svg) | 0 | ||||
| -rw-r--r-- | static/pix/gitea.svg (renamed from pix/gitea.svg) | 0 | ||||
| -rw-r--r-- | static/pix/github.svg (renamed from pix/github.svg) | 0 | ||||
| -rw-r--r-- | static/pix/html-01.png (renamed from pix/html-01.png) | bin | 19006 -> 19006 bytes | |||
| -rw-r--r-- | static/pix/html-02.png (renamed from pix/html-02.png) | bin | 26468 -> 26468 bytes | |||
| -rw-r--r-- | static/pix/html2-01.png (renamed from pix/html2-01.png) | bin | 12697 -> 12697 bytes | |||
| -rw-r--r-- | static/pix/i2p.svg (renamed from pix/i2p.svg) | 0 | ||||
| -rw-r--r-- | static/pix/imgcompress-cat.png | bin | 0 -> 252836 bytes | |||
| -rw-r--r-- | static/pix/imgcompress-network.png | bin | 0 -> 59431 bytes | |||
| -rw-r--r-- | static/pix/inok.jpg | bin | 0 -> 205725 bytes | |||
| -rw-r--r-- | static/pix/irc.svg (renamed from pix/irc.svg) | 0 | ||||
| -rw-r--r-- | static/pix/irc/hexchat-connection-complete.png (renamed from pix/irc/hexchat-connection-complete.png) | bin | 44139 -> 44139 bytes | |||
| -rw-r--r-- | static/pix/irc/hexchat-network-edit.png (renamed from pix/irc/hexchat-network-edit.png) | bin | 55960 -> 55960 bytes | |||
| -rw-r--r-- | static/pix/irc/hexchat-network-select.png (renamed from pix/irc/hexchat-network-select.png) | bin | 40520 -> 40520 bytes | |||
| -rw-r--r-- | static/pix/irc/hexchat-sasl.png (renamed from pix/irc/hexchat-sasl.png) | bin | 59369 -> 59369 bytes | |||
| -rw-r--r-- | static/pix/irc/textual-identity.png (renamed from pix/irc/textual-identity.png) | bin | 45779 -> 45779 bytes | |||
| -rw-r--r-- | static/pix/irc/textual-network-edit.png (renamed from pix/irc/textual-network-edit.png) | bin | 49037 -> 49037 bytes | |||
| -rw-r--r-- | static/pix/itoopie.svg (renamed from pix/itoopie.svg) | 0 | ||||
| -rw-r--r-- | static/pix/jitsi-01.webp (renamed from pix/jitsi-01.webp) | bin | 14998 -> 14998 bytes | |||
| -rw-r--r-- | static/pix/jitsi.svg (renamed from pix/jitsi.svg) | 0 | ||||
| -rw-r--r-- | static/pix/landchad.gif (renamed from pix/landchad.gif) | bin | 15127 -> 15127 bytes | |||
| -rw-r--r-- | static/pix/matrix.svg | 48 | ||||
| -rw-r--r-- | static/pix/monero-01.png (renamed from pix/monero-01.png) | bin | 151173 -> 151173 bytes | |||
| -rw-r--r-- | static/pix/monero-02.png (renamed from pix/monero-02.png) | bin | 112885 -> 112885 bytes | |||
| -rw-r--r-- | static/pix/monero-03.png (renamed from pix/monero-03.png) | bin | 135404 -> 135404 bytes | |||
| -rw-r--r-- | static/pix/monero-04.png (renamed from pix/monero-04.png) | bin | 97964 -> 97964 bytes | |||
| -rw-r--r-- | static/pix/movim.svg | 20 | ||||
| -rw-r--r-- | static/pix/nextcloud.svg (renamed from pix/nextcloud.svg) | 0 | ||||
| -rw-r--r-- | static/pix/nginx-password.png (renamed from pix/nginx-password.png) | bin | 34823 -> 34823 bytes | |||
| -rw-r--r-- | static/pix/nginx-website.png (renamed from pix/nginx-website.png) | bin | 16651 -> 16651 bytes | |||
| -rw-r--r-- | static/pix/openalias-01.png (renamed from pix/openalias-01.png) | bin | 23583 -> 23583 bytes | |||
| -rw-r--r-- | static/pix/openalias-02.png (renamed from pix/openalias-02.png) | bin | 22211 -> 22211 bytes | |||
| -rw-r--r-- | static/pix/openalias-03.png (renamed from pix/openalias-03.png) | bin | 28821 -> 28821 bytes | |||
| -rw-r--r-- | static/pix/openalias-04.png (renamed from pix/openalias-04.png) | bin | 18936 -> 18936 bytes | |||
| -rw-r--r-- | static/pix/openalias-05.png (renamed from pix/openalias-05.png) | bin | 13803 -> 13803 bytes | |||
| -rw-r--r-- | static/pix/peertube-login.jpg (renamed from pix/peertube-login.jpg) | bin | 76446 -> 76446 bytes | |||
| -rw-r--r-- | static/pix/peertube.svg (renamed from pix/peertube.svg) | 0 | ||||
| -rw-r--r-- | static/pix/pleroma.svg (renamed from pix/pleroma.svg) | 0 | ||||
| -rw-r--r-- | static/pix/prosody.svg | 9 | ||||
| -rw-r--r-- | static/pix/radicale.svg | 10 | ||||
| -rw-r--r-- | static/pix/rainloop-1.png (renamed from pix/rainloop-1.png) | bin | 154272 -> 154272 bytes | |||
| -rw-r--r-- | static/pix/rainloop-2.png (renamed from pix/rainloop-2.png) | bin | 188083 -> 188083 bytes | |||
| -rw-r--r-- | static/pix/rainloop.png | bin | 0 -> 2424 bytes | |||
| -rw-r--r-- | static/pix/rdns-01.png | bin | 0 -> 36186 bytes | |||
| -rw-r--r-- | static/pix/rdns-02.png | bin | 0 -> 58061 bytes | |||
| -rw-r--r-- | static/pix/rss.svg (renamed from pix/rss.svg) | 0 | ||||
| -rw-r--r-- | static/pix/rsync.png | bin | 0 -> 58869 bytes | |||
| -rw-r--r-- | static/pix/searxng.svg | 19 | ||||
| -rw-r--r-- | static/pix/server-features.png (renamed from pix/server-features.png) | bin | 22214 -> 22214 bytes | |||
| -rw-r--r-- | static/pix/server-location.png (renamed from pix/server-location.png) | bin | 59268 -> 59268 bytes | |||
| -rw-r--r-- | static/pix/server-size.png (renamed from pix/server-size.png) | bin | 77507 -> 77507 bytes | |||
| -rw-r--r-- | static/pix/server-type.png (renamed from pix/server-type.png) | bin | 41632 -> 41632 bytes | |||
| -rw-r--r-- | static/pix/smtp-01.png | bin | 0 -> 42862 bytes | |||
| -rw-r--r-- | static/pix/smtp-02.png | bin | 0 -> 28246 bytes | |||
| -rw-r--r-- | static/pix/ssh-01.png (renamed from pix/ssh-01.png) | bin | 31196 -> 31196 bytes | |||
| -rw-r--r-- | static/pix/tor.svg (renamed from pix/tor.svg) | 0 | ||||
| -rw-r--r-- | static/pix/webrtc.svg | 16 | ||||
| -rw-r--r-- | static/pix/xmpp.svg (renamed from pix/xmpp.svg) | 0 | ||||
| -rw-r--r-- | static/pix/xmr.png (renamed from pix/xmr.png) | bin | 768 -> 768 bytes | |||
| -rw-r--r-- | static/pix/xmr.svg (renamed from pix/xmr.svg) | 0 | ||||
| -rw-r--r-- | static/style.css (renamed from style.css) | 88 | ||||
| -rw-r--r-- | template.html | 20 | ||||
| -rw-r--r-- | tor.html | 109 | ||||
| -rw-r--r-- | ufw.html | 193 | ||||
| -rw-r--r-- | xmpp.html | 210 |
210 files changed, 8116 insertions, 9019 deletions
diff --git a/.footer.html b/.footer.html deleted file mode 100644 index 2d33ffb..0000000 --- a/.footer.html +++ /dev/null @@ -1,7 +0,0 @@ -<a href="https://landchad.net">LandChad.net</a></br> -Because Everyone should be an Internet LandChad.</br> -<a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a> -<a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a> -<a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a> -<a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a> -<a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a> diff --git a/.github/workflows/upload.yml b/.github/workflows/upload.yml index a6c9260..6b7ac9b 100644 --- a/.github/workflows/upload.yml +++ b/.github/workflows/upload.yml @@ -27,6 +27,7 @@ jobs: passphrase: ${{ secrets.chad_pass }} port: 22 script: | - cd landchad + cd landchad-src git stash git pull --force origin master + hugo -s . -t /var/www/lugo -d ~/landchad --cacheDir ~/hugocache diff --git a/404.html b/404.html deleted file mode 100644 index 5e42dee..0000000 --- a/404.html +++ /dev/null @@ -1,27 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>404 – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>404</h1></header> - <nav></nav> - <main> - <p> - This article linked is not yet finalized! - </p> - <p> - To keep tabs on what new articles are published, keep up with our RSS feed at - <img src="pix/rss.svg" alt="rss logo"> - <a href="https://landchad.net/rss.xml">https://landchad.net/rss.xml</a> which - will feature all new pages and significant changes. - </p> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/LICENSE.md b/LICENSE.md new file mode 100644 index 0000000..fdddb29 --- /dev/null +++ b/LICENSE.md @@ -0,0 +1,24 @@ +This is free and unencumbered software released into the public domain. + +Anyone is free to copy, modify, publish, use, compile, sell, or +distribute this software, either in source code form or as a compiled +binary, for any purpose, commercial or non-commercial, and by any +means. + +In jurisdictions that recognize copyright laws, the author or authors +of this software dedicate any and all copyright interest in the +software to the public domain. We make this dedication for the benefit +of the public at large and to the detriment of our heirs and +successors. We intend this dedication to be an overt act of +relinquishment in perpetuity of all present and future rights to this +software under copyright law. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. +IN NO EVENT SHALL THE AUTHORS BE LIABLE FOR ANY CLAIM, DAMAGES OR +OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, +ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR +OTHER DEALINGS IN THE SOFTWARE. + +For more information, please refer to <https://unlicense.org> @@ -6,35 +6,19 @@ Simple step-by-step text and image-based tutorials for creating websites, email Suggestions welcome. +This site is compiled and organized with Hugo, using [this very simple theme](https://github.com/lukesmithxyz/lugo). + ## Submission guidelines -- follow the general style of pre-existing articles +- Follow the general style of pre-existing articles. - use the root user (i.e. no `sudo`) unless there is a specific need. - do not preface commands with `$` or `#` or anything. -- use `.svg` files for icons/logos and for illustrative images, keep filesize low -- Use `example.org` -- custom command/file info should be highlighted with `<strong>` tags - -### On `<pre>` tags - - -In-line code should be in `<code>` tags, while codeblocks should be in a `<code>` tag *inside* of a `<pre>` tag. -`<pre>` allows formatting preserving whitespace. -That said, do *not* format `<pre>` tags as following: - -``` -<pre><code> - echo "Here is a command." - echo "Here is another." -</code></pre> -``` - -but do it like this: +- use `.svg` files for icons/logos and for illustrative images favor webp, keep filesize low. +- Use `example.org` the example domain. +- Do not add Docker tutorials. +- Installable services must have the `service` tag and an `icon` set in the metadata so they properly appear in the service display. +- Server/sysadmin tips should have the `server` tag, so they appear in that list. -``` -<pre><code>echo "Here is a command." -echo "Here is another."</code></pre> -``` +## License -**All** whitespace, including tabbing in and initial and final newlines are displayed by `<pre>`. -To maintain consistency and avoid goofy-looking extra lines, add no extra whitespace. +Adding anything to this site puts it in the public domain. You are welcome to add your personal links to the bottom of pages you write for credit. diff --git a/archetypes/default.md b/archetypes/default.md new file mode 100644 index 0000000..00e77bd --- /dev/null +++ b/archetypes/default.md @@ -0,0 +1,6 @@ +--- +title: "{{ replace .Name "-" " " | title }}" +date: {{ .Date }} +draft: true +--- + diff --git a/auth.html b/auth.html deleted file mode 100644 index 5bf686f..0000000 --- a/auth.html +++ /dev/null @@ -1,122 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Requiring Passwords for Webpages (HTTP Authentication) – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Requiring Passwords for Webpages</h1></header> - <nav></nav> - <main> - <img class=titleimg src="pix/auth.svg" alt="access control with nginx"/> - <p>HTTP basic authentication will allow you to secure parts (or all) of your website with a username and password without the trouble of PHP or Javascript. - This will work with any Nginx server. - </p> - - <h2>Installation</h2> - <p>We will be using the command <code>htpasswd</code> to make username and password pairs.</p> - <pre><code>apt install apache2-utils</code></pre> - <aside> - <p>The apache utils include a small username-password pair encryption tool.</p> - <p>Like the other tutorials on this site, this tutorial is for Nginx, <strong>not</strong> for Apache servers.</p> - </aside> - - <p> - Now think of a username and password and remember them. - </p> - - <pre><code>htpasswd -c /etc/nginx/<strong>myusers</strong> <strong>username</strong></code></pre> - <aside> - <p>The <code>-c</code> flag creates a file. You can make the path of this file anywhere outside of your webroot.</p> - <p>Obviously the username is up to you as well.</p> - </aside> - <p> - Type out your password twice to confirm. You can do this as many times as you'd like. - </p> - <p>Check out user name password pairs (the password will be securely hashed):</p> - <pre><code>cat /etc/nginx/<strong>myusers</strong></code></pre> - - <h2>Nginx Config and Auth Basic</h2> - <p> - From here, we are going to edit our websites config file in <code>/etc/nginx/sites-enabled</code>. - Have in mind which folder you'd like to secure. Add something like this: - </p> - - <pre><code>server { - #... - location /<strong>secret-folder </strong> { - auth_basic "What's the Password?" ; - auth_basic_user_file /etc/nginx/<strong>myusers</strong> ; - } - #... -}</code></pre> - <aside> - <h4>Huh?</h4> - <p>If you're stuck, try finding the line <code>location / {</code></p> - <p>Just below this block is where you should add the custom location block</p> - </aside> - - <p>If you'd like to do the opposite, such as making the entire site private except for a public section, do this:</p> - <pre><code>server { - #... - auth_basic "What's the Password?" ; - auth_basic_user_file /etc/nginx/<strong>myusers</strong> ; - location /<strong>public</strong>/ { - #... - auth_basic off ; - } - #... -}</code></pre> - <h3>IP Addresses</h3> - <p>If passwords aren't enough we can ban an ip or accept one.</p> - <pre><code>location /api { - #... - allow 192.168.1.23:8080 ; - deny 127.0.0.1 ; -}</code></pre> - <p>If you want to check both a username and password with an ip address, use the <code>satisfy</code> directive.</p> - <pre><code>location /api { - #... - satisfy all ; - - allow 192.168.1.23:8080 ; - deny 127.0.0.1 ; - - auth_basic "What's the Password?" ; - auth_basic_user_file /etc/nginx/<strong>myusers</strong> ; -}</code></pre> - <h3>Complete Example</h3> - <pre><code>http { - server { - listen 80; - root /var/www/website ; - - #... - location /<strong>secret-folder</strong> { - satisfy all ; - - allow 192.168.1.3/24; - deny 127.0.0.1 ; - - auth_basic "What's the Password?" ; - auth_basic_user_file /etc/nginx/<strong>myusers</strong> ; - } - } -}</code></pre> - - <p> - Now check your configuration with <code>nginx -t</code> - </p> - - <p>Reload nginx and you're good to go!</p> - - <strong>Contributor</strong> - <a href="https://tomfasano.co" target="_blank">tomfasano.co</a> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> @@ -1,18 +0,0 @@ -#!/bin/sh - -# Replace existing navs and footers with content of nav and footer files. - -navfile="/home/luke/.local/src/landchad/.nav.html" -footerfile="/home/luke/.local/src/landchad/.footer.html" - -files="$(for x in $(find /home/luke/.local/src/landchad -type f -iname '*.html'); do - echo "$x" -done)" - -escnav="$(sed "s|^\s\+||;s|/|\\\\/|g;s|\"|\\\\\"|g" "$navfile" 2>/dev/null | tr -d '\n')" -escfooter="$(sed "s|^\s\+||;s|/|\\\\/|g;s|\"|\\\\\"|g" "$footerfile" 2>/dev/null | tr -d '\n')" - -sed -s -i "s/<nav>.*<\/nav>/<nav>$escnav<\/nav>/; s/<footer>.*<\/footer>/<footer>$escfooter<\/footer>/" $files - -# Multiline: -# sed -n -s -i "1h; 1!H; \${ g; s/<nav>.*<\/nav>/<nav>\n$escnav\n\t<\/nav>/g; s/<footer>.*<\/footer>/<footer>\n$escfooter\n\t<\/footer>/p }" $files diff --git a/bat.html b/bat.html deleted file mode 100644 index 4b67e56..0000000 --- a/bat.html +++ /dev/null @@ -1,92 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Enrolling Your Site in the Basic Attention Token Project – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Enrolling in the Basic Attention Token Project</h1></header> - <nav></nav> - <main> - <h2>What is the <img src="pix/bat.svg" alt="bat logo">Basic Attention Token?</h2> - <p> - The Basic Attention Token (BAT) is a cryptocurrency token associated with the <a href="https://brave.com">Brave Browser</a>.</p> - - <p> - You might want to consider enrolling any and all sites you have on the internet into their project which allows you to earn some of their token based on how many Brave users view your website. - It also enables Brave users to donate BAT directly to you. - </p> - - <p> - You can receive these donations in BAT itself, or in another cryptocurrency of your choosing. - </p> - <h3>Explanation of the BAT system</h3> - <p> - In the Brave Browser, all ads are automatically blocked. - Brave users however, are given the choice to opt into an optional ads system to view occasional notification ads instead and if they do, they are paid some amount of BAT monthly for how many ads they view. - At the end of the month, depending on their settings, Brave users either have their BAT automatically donated to the sites/channels/accounts they spent the most time on, or they can hold onto their token to give away as they please. - </p> - <h3>Why you might <em>not</em> want to enroll...</h3> - <p> - Unlike <a href="bitcoin.html">Bitcoin</a> and <a href="monero.html">Monero</a>, BAT is a token organized by a company, and as such, it has to comply with know-your-customer regulations. - What that means for you is that to get a payout in BAT, you must have a custodial cryptocurrency wallet with either Gemini or Uphold, the two services they are interfaced with. - You can move your payouts elsewhere when you want, but those sites require real-world identification. - </p> - <p> - Enrolling in BAT is thus not an option for people who want to be on the internet totally anonymously. - For those for which this is not an issue, however, enrolling your site in the Basic Attention Token system, even if you do not use Brave yourself, - is an easy, free and no risk thing that you can only gain from. - </p> - <h2>Enrolling in the System</h2> - <h3>Create a Publisher Account with BAT</h3> - <p>Go to <a href="https://publishers.basicattentiontoken.org/">publishers.basicattentiontoken.org</a> and sign up to create a publisher account. - </p> - <h3>Add a new website/channel</h3> - <p> - Once you log in, you can easily create a new Brave channel. - </p> - <img src="pix/brave-01.png" alt="adding a brave channel"> - <p> - As this will show you, you can add your website to the system to receive donations there, - but you can also add a YouTube or Twitch channel, a Github profile or even a R*ddit or Tw*tter account. - </p> - <img src="pix/brave-02.png" alt="channel choices"> - <p> - Once you select what to add, you will have to verify that you own that website/channel via various methods. - You can add DNS settings to your registrar for a website, which is generally the most consistent way for websites. - </p> - <h2>Using Uphold or Gemini for payouts</h2> - <p> - In order to properly receive payouts, you will have to create an account either with Uphold or Gemini which again are custodial cryptocurrency wallets, meaning that while you have your money on their platform, it isn't <em>really</em> yours, so it's a good idea to transfer it off when you accumulate a decent amount. - </p> - <p>Choose either Gemini or Uphold, create an account with them and follow the directions on the BAT site to link them.<p> - Note that right now, Gemini might be the better choice here. - Uphold inexplicably can't send funds to a Segwit wallet as it is right now which is the type that Electrum uses. - So if you select to get your payouts in Bitcoin, this might be an issue. - </p> - <h2>What does this look like in Brave?</h2> - <h3>Donating to websites</h3> - - <p> - Once you have your website connected, Brave users can click on the BAT icon (<img src="pix/bat.svg" alt="bat logo">) by their URL bar to donate to you. - Here is how this looks: - </p> - - <a href="https://lukesmith.xyz"><img style=max-width:300px src="pix/brave-03.png" alt="website example"></a> - <h3>Donating to individual accounts</h3> - - <p>Here is an example of what it looks like to have an individual social media site interfaced. - In the picture below, a "Tip" button appears in the bottom right of this image. - </p> - <a href="https://twitter.com/thefaceberg/status/1402502987742859264"><img style=max-height:400px src="pix/brave-04.gif" alt="example tweet"></a> - <p> - Tip buttons will appear on many other social media sites, for example Github commits, projects and comments by users. - </p> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/bitcoin.html b/bitcoin.html deleted file mode 100644 index 7872291..0000000 --- a/bitcoin.html +++ /dev/null @@ -1,102 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Getting a Bitcoin Wallet – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Getting a Bitcoin Wallet</h1></header> - <nav></nav> - <main> - <p>Let's now get a Bitcoin wallet and become able to receive Bitcoin funds or donations.</p> - <h2>Wallets</h2> - <p> - One of the classical choices for a Bitcoin wallet is Electrum. - Go to <a href="https://electrum.org/#home">https://electrum.org</a> to download and install it, - or if you are a Linux user, it is probably included in your distribution's package repository. - </p> - <h3>Mobile version?</h3> - <p> - Note also that there are mobile/cell phone versions of Electrum for Android and iOS. - I generally advise against using a wallet on a cell phone for security reasons, but if you would like, you can. - </p> - <p> - If you are okay with a mobile wallet, - I recommend getting <a href="https://cakewallet.com/">Cake Wallet</a>, which can use Electrum-style Bitcoin wallets, - but also Monero and Litecoin. - </p> - <h2>Generating a Wallet</h2> - <p>Once you open Electrum (or Cake Wallet), - you can choose to create a new wallet. - Name it whatever you want and choose the "Standard Wallet" option. - </p> - <p> - I will also note that if you are paranoid, it is perfectly possible to generate a wallet without connection to the internet. - </p> - <h3>Your Seed is your money.</h3> - <p> - Now choose the "Create a new seed" option when creating the wallet. - That will randomly produce a "seed" of 12 words. - </p> - <img src="pix/bitcoin-01.png" alt="bitcoin seed"> - <p> - <strong>These words are your money.</strong> - Once you are shown them, <strong>immediately</strong> write them down on physical paper, and you will be storing this somewhere it will not be lost or found. - You can memorize these twelve words if you trust your memory. - </p> - <p> - These twelve words unlock all of the funds/addresses you will have on this wallet. - Whoever has your seed has the ability to spend your money. - </p> - <p>Note obviously that I have included a picture of a seed phrase above in this tutorial. - I or anyone else would be stupid to ever send Bitcoin to the following addresses since the seed phrases are now public. - </p> - <p> - Once you have written down your seed, click "Next" and Electrum will have you input that seed again to ensure you've written it down. - </p> - <p> - You will also be asked to supply a password. - This password merely encrypts your wallet file on this computer so you don't have to retype your seed phrase each time you open Electrum. - Note that anyone with your seed phrase can still obtain your funds. - This password is only protection on your computer here. - </p> - <h2>Managing your Wallet</h2> - <p> - Once your wallet is generated and opened you will be at the wallet page. - First, I recommend opening the "View" menu and unhiding all the different tabs. - </p> - <img src="pix/bitcoin-02.png" alt="electrum options"> - <h3>Addresses</h3> - <p>The address tab contains all the many Bitcoin addresses generated by your seed phrase. - In fact, as you use these up, the wallet will automatically add more. - </p> - <p> - These addresses (which will all be generated with <code>bc1</code> at the beginning) can be used by others to send you Bitcoins. - Someone can just copy-and-paste the address into their wallet to send you funds. - </p> - <img src="pix/bitcoin-03.png" alt="bitcoin addresses"> - <h3>Receive</h3> - <p>Click on the "Receive" tab and then click "New Address." - That will pick your first unused address which will appear on the right side. - You could copy this from the "Addresses" tab, but this tab also generates a QR code which will appear to the right as well if you click on the "QR Code" subtab. - </p> - <img src="pix/bitcoin-04.png" alt="receive qr code"> - <h4>What is the QR code for?</h4> - <p> - In case you don't know, a QR code is a way of storing text information in a format that can be scanned by a phone. - If someone has a wallet program on a phone, they can easily scan the QR code on another screen to avoid having to copy your address over or even worse, write it manually. - </p> - <h3>Let's receive donations on our website.</h3> - <p> - Save the QR code and the wallet address it corresponds to (starting in <code>bc1</code>). - Now simply put these on your website and anyone can send Bitcoin to them. - Bitcoin users will know how to scan and use them. - </p> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/calibre.html b/calibre.html deleted file mode 100644 index 7f4a6c6..0000000 --- a/calibre.html +++ /dev/null @@ -1,131 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Setting up a Calibre library server – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Setting up a Calibre library server</h1></header> - <nav></nav> - <main> - <img src="pix/calibre.png" alt="Calibre logo" class=titleimg> - <p> - The Calibre library server is a great way to store your eBooks. - It allows you to: - </p> - <ul> - <li>Share your books with others.</li> - <li>Easily transfer your books between devices and access them from anywhere.</li> - </ul> - - <h2>Installation</h2> - - <p>Install the Calibre package. - You might also want rsync to upload books.</p> - - <pre><code>apt install -y calibre rsync -mkdir /opt/calibre</code></pre> - - <p> - Either upload your existing library using <code>rsync</code>. For example to <code>/opt/calibre/</code>. - <pre><code>cd ~/Documents -rsync -avuP <strong>your-library-dir</strong> root@<strong>example.org</strong>:/opt/calibre/</code></pre> - - <p> - Or create a library and add a book to it: - </p> - -<pre><code>cd /opt/calibre -calibredb add <strong>book.epub</strong> --with-library <strong>your-library</strong></code></pre> - - <aside> - <p> - For more information about the <code>calibredb</code> command see <code>man calibredb</code>. - </p> - </aside> - - <p> - Add a new user to protect your server: - </p> - - <pre><code>calibre-server --manage-users</code></pre> - - <h2>Creating a service</h2> - - <p> - Create a new file <code>/etc/systemd/system/calibre-server.service</code> and add the following: - </p> - -<pre><code>[Unit] -Description=Calibre library server -After=network.target - -[Service] -Type=simple -User=root -Group=root -ExecStart=/usr/bin/calibre-server --enable-auth --enable-local-write /opt/calibre/your_library --listen-on 127.0.0.1 - -[Install] -WantedBy=multi-user.target -</code></pre> - <aside> - <p> - You can change the port with the <code>--port</code> prefix. Additional information <code>man calibre-server</code>. - </p> - </aside> - - <p> - Issue <code>systemctl daemon-reload</code> to apply the changes. - </p> - - <p> - Enable and start the service. - </p> - -<pre><code>systemctl enable calibre-server -systemctl start calibre-server</code></pre> - - <h2>A reverse proxy with Nginx</h2> - - <p> - Create a new file <code>/etc/nginx/sites-available/calibre</code> and enter the following: - </p> - -<pre><code>server { - listen 80; - client_max_body_size 64M; # to upload large books - server_name <strong>calibre.example.org</strong> ; - - location / { - proxy_pass http://127.0.0.1:8080; - } -}</code></pre> - - <p>Issue a Let's Encrypt certificate. <a href="certbot.html">Detailed instructions and additional information</a>.</p> - - <pre><code>certbot --nginx</code></pre> - - <p>Now just go to <strong>calibre.example.org</strong>. The server will request an username and a password.</p> - - <a href="pix/calibre-1.png"> - <img src="pix/calibre/calibre-1.png" alt="calibre"> - </a> - - <p>After login you will see something like this.</p> - - <a href="pix/calibre-1.png"> - <img src="pix/calibre/calibre-2.png" alt="calibre"> - </a> - - <h2>Contribution</h2> - <li>Author: rflx – <a href="https://rflx.xyz">website</a> -- XMR: <code class=crypto>48T5XpHTXAZ5Nn8YCypA4aWn1ffQLHJkFGDArXQB6cmrP6cqLY72cu7CR2iq2MmL5Ndu3d47e5MKjGpL4prYgdrTCFAHD9c</code> - </li> - </main> -<footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/certbot.html b/certbot.html deleted file mode 100644 index 72351f2..0000000 --- a/certbot.html +++ /dev/null @@ -1,149 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Certbot and HTTPS – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Certbot and HTTPS</h1></header> - <nav></nav> - <main> - <p> - Once you have a website, it is extremely important to enable encrypted connections over HTTPS/SSL. - You might have no idea what that means, but it's easy to do now that we've <a href="nginx.html">set our web server up</a>. - </p> - - <p> - Certbot is a program that automatically creates and deploys the certificates that allow encrypted connections. - It used to be painful (and often expensive) to do this, but now it's all free and automatic. - </p> - - <h2>Why is encryption important?</h2> - - <ul> - <li>With HTTPS, users' ISPs cannot snoop on what they are looking at on your website. - They know that they have connected, but the particular pages they visit are private as everything is encrypted. HTTPS increases user privacy.</li> - <li>If you later create usernames and passwords for any service on your site, lack of encryption can compromise that private data! Most well-designed software will automatically <em>prevent</em> any unencrypted connections over the internet.</li> - <li>Search engines like Google favor pages with HTTPS over unencrypted HTTP.</li> - <li>You get the official-looking green 🔒 symbol in the URL bar in most browsers which makes normies subtly trust your site more.</li> - </ul> - - <h2>Let's do it!</h2> - <img src=pix/nginx-website.png> - - <p>Note in this picture that a browser accessing your site will say "Not secure" or something else to notify you that we are using and unencrypted HTTP connection rather than an encrypted HTTPS one.</p> - - <H2>Installation</h2> - - <p>Just run:</p> - - <pre><code>apt install python3-certbot-nginx</code></pre> - - <p>And this will install <code>certbot</code> and its module for <code>nginx</code>.</p> - - <h2>Run</h2> - - <p> - As I mentioned in the previous article, firewalls might interfere with certbot, so you will want to either disable your firewall or at least ensure that it allows connections on ports 80 and 443: - </p> - - <pre><code>ufw allow 80 -ufw allow 443</code></pre> - - <p> - Now let's run certbot: - </p> - - <pre><code>certbot --nginx</code></pre> - - <p> - The command will ask you for your email. - This is so when the certificates need to be renewed in three months, you will get an email about it. - You can set the certificates to renew automatically, but it's a good idea to check it the first time to ensure it renewed properly. - You can avoid giving your email by running the command with the <code>--register-unsafely-without-email</code> option as well. - </p> - - <p>Agree to the terms, and optionally consent to give your email to the EFF (I recommend against this obviously). - </p> - - <p> - Once all that is done, it will ask you what domains you want a certificate for. You can just press enter to select all. - </p> - - <img src=pix/certbot-01.png> - <p> - It will take a moment to create the certificate, but afterwards, you will be asked if you want to automatically redirect all connections to be encrypted. - Since this is preferable, choose 2 to Redirect. - </p> - <img src=pix/certbot-02.png> - - <h3>Checking for success</h3> - - <p>You should now be able to go to your website and see that there is a lock icon or some other notification that you are now on an encrypted connection.</p> - - - <img src=pix/certbot-03.png> - - <h2>Setting up certificate renewal</h2> - - <p> - As I mentioned in passing, the Certbot certificates last for 3 months. - To renew certificates, you just have to run <code>certbot --nginx renew</code> and it will renew any certificates close to expiry. - </p> - - <p> - Of course, you don't want to have to remember to log in to renew them every three months, so it's easy to tell the server to automatically run this command. - We will use a <a href="cron.html">cronjob</a> for this. Run the following command: - </p> - - <pre><code>crontab -e</code></pre> - - <aside> - <p> - There might be a little menu that pops up asking what text editor you prefer when you run this command. - If you don't know how to use vim, choose <code>nano</code>, the first option. - </p> - </aside> - - <p> - This <code>crontab</code> command will open up a file for editing. - A crontab is a list of commands that your operating system will run automatically at certain times. - We are going to tell it to automatically try to renew our certificates every month so we never have to. - </p> - - <p> - Create a new line at the end of the file and add this content: - </p> - - <pre><code>0 0 1 * * certbot --nginx renew</code></pre> - - <p> - Save the file and exit to activate this cronjob. - </p> - - <p> - For more on cron and crontabs please <a href="cron.html">click here!</a> - </p> - - <span class=prev><a href="nginx.html">Previous: Set up a webserver.</a></span> - <!-- <span class=next><a href="html.html">Next: Use HTML to Make Simple Webpages</a></span> --> - - <span class=next>You've reached the end of the basic course!</span> - - <p> - You now have a live website on the internet. - You can add to it what you wish. - </p> - - <p> - As you add content to your site, there are many other things you can also install linked on <a href="index.html">the main page</a>, - and many more improvements, tweaks and bonuses. - </p> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/cgi.html b/cgi.html deleted file mode 100644 index e1c210b..0000000 --- a/cgi.html +++ /dev/null @@ -1,268 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Server-Side Scripting with CGI</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Server-Side Scripting with CGI</h1></header> - <nav></nav> - <main> - <p> - The basic website tutorial here describes how to set up a static - website — one that just serves HTML files saved on your server, - and until you change something manually, the same content will be served - each time a given page is requested. This is perfectly enough for most - personal website needs. This is how blogs should be implemented, instead - of relying on bloatware like WordPress! - </p> - - <p> - But sometimes you genuinely <i>do</i> need something more. You need your - website to serve different contents depending on the time, on who the - requester is, on the contents of a database, or maybe process user input - from a form. - </p> - - <h2>CGI</h2> - <p> - CGI, or the Common Gateway Interface, is a specification to allow you, - the server owner, to program your web server using pretty much any - programming language you might know. The specification is almost as old - as the Internet itself and for a long time CGI scripting was the primary - method of creating dynamic websites. - </p> - - <p> - CGI is a very simple specification indeed. You write a script in your - favorite language, the script receives input about the request in - environment variables, and whatever you print to the standard output - will be the response. Most likely, though, you will want to use a - library for your language of choice that makes a lot of this - request/response handling simpler (e.g. parsing query parameters for - you, setting appropriate headers, etc.). - </p> - - <h3>Limitations of CGI</h3> - <p> - While in theory you could implement any sort of functionality with CGI - scripts, it's going to get difficult managing a lot of separate scripts - if they're supposed to be working in tandem to implement a dynamic - website. If you want to build a full out web application, you'd probably - be better off learning a web framework than gluing together Perl - scripts. - </p> - - <p> - That said, just as most of the web could be replaced with static - websites, much of the remaining non-static web could be replaced with a - few simple scripts, rather than bloated Ruby on Rails or Django - applications. - </p> - - <h2>Let's write a CGI script!</h2> - - <p> - We'll implement a simple example CGI script. I'll use Ruby for this - tutorial, but you'll be able to follow along even if you don't know - Ruby, just treat it as pseudocode then find a CGI library for your - language. - </p> - - <h3>The working example</h3> - - <p> - Our working example will be the Lazy Calculator. Yeah, you're probably - tired of seeing calculator examples in every programming tutorial, but - have you ever implemented one that takes the weekends off? - </p> - - <p> - Here's how it will work. When in a browser you submit a request to your - website like - </p> - - <pre><code>example.com/calculator.html?a=10&b=32</code></pre> - - <p> - you will receive a page with the result of the addition of 10 and 32: - 42. - </p> - - <p> - <i>Unless</i> you send your request on a weekend. Then the website will - respond with - </p> - - <pre><code>I don't get paid to work on weekends! Come back Monday.</code></pre> - - <p> - This example will show a few things that CGI scripts can do that you - wouldn't have been able to get using just file hosting in your - web server: - - <ul> - <li> getting inputs from the user; </li> - <li> - getting external information (here just the system time, but you - could imagine instead connecting to a database); - </li> - <li> using the above to create dynamic output. </li> - </ul> - - <h3>The code</h3> - - <p> - Here's an implementation of the lazy calculator as a Ruby CGI script: - </p> - - <pre><code>#!/bin/env ruby - -require 'cgi' -require 'date' - -cgi = CGI.new -today = Date::today - -a = cgi["a"].to_i -b = cgi["b"].to_i - -if today.saturday? || today.sunday? - cgi.out do - "I don't get paid to work on weekends! Come back Monday." - end -else - cgi.out do - (a + b).to_s - end -end</code></pre> - - <p> - Let's go through what's happening here. - </p> - - <h3>The shebang line</h3> - <p> - CGI works by pointing your web server to an executable program. A Ruby - or Python script by itself is not immediately executable by a computer. - But on Unix-like systems you can specify the program that will be able - to execute your file in its first line if it starts with <code>#!</code> - (known as the shebang; read more about it on - <a href="https://en.wikipedia.org/wiki/Shebang_(Unix)">Wikipedia</a>). - </p> - - <p> - So if you're going to be using a scripting language, you'll probably - need the appropriate shebang line at the top of your script. If you use - a compiled language, you'll just point your web server to the compiled - executable binary. - </p> - - <h3>Query parameters</h3> - <p> - The next interesting lines of code are where we set the variables - <code>a</code> and <code>b</code>. Here we are getting user inputs from - the request. - </p> - - <p> - In the example request we mentioned above - (<code>example.com/calculator.html?a=10&b=32</code>), the part - starting from the question mark, <code>?a=10&b=32</code>, is the - <i>query string</i>. This is how users can submit parameters with their - web requests. Usually these parameters are set by e.g. a form on your - website, but in our simple example we'll be just manually manipulating - the URL. - </p> - - <p> - The query string contains key-value pairs. The Ruby CGI library makes - them available in the <code>CGI</code> object it provides. We just need - to index it with the desired key, and we'll get the corresponding value. - </p> - - <h3>Wrapping it up</h3> - <p> - The remaining parts of the code should be pretty self-explanatory. We - get today's date, check if it's a Saturday or a Sunday, and depending on - that, we instruct the CGI library to output either the answer, or a - "come back later" message. - </p> - - <p> - The Ruby library by default returns an HTML response, so we really - should have wrapped our outputs in some <code>html</code>, - <code>body</code>, etc. tags. Alternatively, we could have specified - that the response is just plain text with - </p> - - <pre><code>cgi.out 'text/plain' do</code></pre> - - <p> - In general, your CGI library will probably have ways of specifying all - sorts of HTTP response headers, like status code, content type, etc. - </p> - - <h2>Making it work</h2> - <p> - We have a CGI script, now let's point our web server to it. - </p> - - <h3>Installing FastCGI</h3> - - <p> - If you're using Nginx, install <code>fcgiwrap</code>: - </p> - - <pre><code>apt install fcgiwrap</code></pre> - - <p> - This installs the necessary packages for Nginx to use FastCGI — a - layer between your web server and CGI script that allows for faster - handling of scripts than if the web server had to handle it all by - itself. - </p> - - <p> - Other web servers will probably have a similarly simple way of enabling - FastCGI, or you can look into other methods for launching CGI scripts. - </p> - - <h3>Nginx configuration</h3> - <p> - In the configuration file for your website, add something like the - following: - </p> - -<pre><code>location /calculator.html { - include fastcgi_params; - fastcgi_param SCRIPT_FILENAME /usr/local/bin/lazy-calculator.rb; - fastcgi_param QUERY_STRING $query_string; - fastcgi_pass unix:/run/fcgiwrap.socket; -}</code></pre> - - <p> - <code>fastcgi_param</code> directives specify various parameters for - FastCGI. <code>SCRIPT_FILENAME</code> should point to your executable. - For <code>QUERY_STRING</code>, we just copy Nginx's - <code>$query_string</code> variable. You might want to pass other - information to your CGI script as well, see for example - <a href="https://wiki.debian.org/nginx/FastCGI">the Debian wiki</a> for - a more detailed example, including pointing to an entire directory of - CGI scripts, rather than adding each one by hand to your web server - config. - </p> - - <h2>Contribution</h2> - <ul> - <li>Martin Chrzanowski -- <a - href="https://m-chrzan.xyz">website</a>, <a href="https://m-chrzan.xyz/donate.html">donate</a></li> - </ul> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/cgit.html b/cgit.html deleted file mode 100644 index 2ca026d..0000000 --- a/cgit.html +++ /dev/null @@ -1,151 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - -<head> - <title>Setting up Cgit – LandChad.net</title> - <meta charset="utf-8" /> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> -</head> - -<body> - <header> - <h1>Setting up Cgit</h1> - <img src="pix/cgit.svg" class="titleimg"> - </header> - <main> - <p> - Once you have your server hosting your git repositories, you might want to allow others to browse - your repositories on the web. Cgit is a Free Software that allows browsing git repositories through - the web. </p> - - <p> - Note that Cgit is a read-only frontend for Git repositories and doesn't have issues, pull requests - or user management. If that's what you want, consider installing Gitea instead.</p> - - <h2>Installing cgit and fcgiwrap</h2> - <h3>Install fcgiwrap</h3> - <p> - NGINX doesn't have the capability to run CGI scripts by itself, it depends on an intermediate layer - like fcgiwrap to run CGI scripts like cgit:</p> - - <pre><code>apt install fcgiwrap</code></pre> - - <p>And now we can install cgit itself with:</p> - - <pre><code>apt install cgit</code></pre> - - <h2>Setting up NGINX</h2> - <p> - You should have an NGINX server running with a TLS certificate by now. Add the following configuration - to your server to pass the requests to Cgit, while serving static files directly:</p> - - <pre><code> -server { - listen 443 ssl; - listen [::]:443 ssl; - ssl_certificate /etc/ssl/nginx/<strong>git.example.org</strong>.crt; - ssl_certificate_key /etc/ssl/nginx/<strong>git.example.org</strong>.key; - server_name <strong>git.example.org</strong>; - - root /usr/share/cgit ; - try_files $uri @cgit ; - - location @cgit { - include fastcgi_params; - fastcgi_param SCRIPT_FILENAME /usr/lib/cgit/cgit.cgi; - fastcgi_param PATH_INFO $request_uri; - fastcgi_param QUERY_STRING $query_string; - fastcgi_pass unix:/run/fcgiwrap.socket; - } -} - </code></pre> - - <p>Then get NGINX to reload your configuration.</p> - - <h2>Configuring cgit</h2> - <p>You've got cgit up and running now, but you'll probably see it without any style and without any repository. - To change this, we need to configure Cgit to our liking, by editing <code>/etc/cgitrc</code>. - </p> - - <pre><code> -css=/cgit.css -logo=/cgit.svg -virtual-root=/ - -# Title and description shown on top of each page -root-title=<strong>Chad's git server</strong> -root-desc=<strong>A web interface to LandChad's git repositories, powered by Cgit</strong> - -# The location where git repos are stored on the server -scan-path=/srv/git/ - </code></pre> - - <p>This configuration assumes you followed the <a href="/git">git hosting guide</a> and store your repositories - on the <code>/srv/git/</code> directory.</p> - - <p>Cgit's configuration allows changing many settings, as documented on the cgitrc(5) manpage installed with - Cgit.</p> - - <h3>Changing the displayed repository owner</h3> - - <p>Cgit's main page shows each repo's owner, which is "git" in case you followed the git hosting guide, but you - might want to change the name to yours. Cgit shows the owner's system name, so you need to modify the git - user - to give it your name:</p> - - <pre><code> -usermod -c "<strong>Your Name</strong>" git - </code></pre> - - <h3>Changing the repository description</h3> - - <p>Navigate to your bare repository on the server and edit the <code>description</code> file inside it</p> - - <h3>Displaying the repository idle time</h3> - - <p>To do this, we need to create a post-receive hook for each repository that updates the file cgit uses - to determine the idle time. Inside your repository, create a file <code>hooks/post-receive</code> and add - the following contents:</p> - - <pre><code> -#!/bin/sh - -agefile="$(git rev-parse --git-dir)"/info/web/last-modified - -mkdir -p "$(dirname "$agefile")" && -git for-each-ref \ - --sort=-authordate --count=1 \ - --format='%(authordate:iso8601)' \ - >"$agefile" - </code></pre> - - <p>And give it execution permissions with:</p> - - <pre><code>chmod +x hooks/post-receive</code></pre> - - <p>Next time you push to that repository, the idle time should reset and show the correct value.</p> - - <h2>Contribution</h2> - <ul> - <li>Ariel Costas – <a href="https://costas.dev">website</a>, <a - href="https://costas.dev/donations/">donations</a></li> - </ul> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a - href="index.html"> - <li><img src="pix/chad.gif" alt="chad"></li> - </a><a href="rss.xml"> - <li><img src="pix/rss.svg" alt="RSS"></li> - </a><a href="pix/btc.png"> - <li><img src="pix/btc.svg" alt="BTC"></li> - </a><a href="pix/xmr.png"> - <li><img src="pix/xmr.svg" alt="XMR"></li> - </a><a href="https://github.com/lukesmithxyz/landchad"> - <li><img src="pix/git.svg" alt="Github"></li> - </a></footer> -</body> - -</html> diff --git a/config.toml b/config.toml new file mode 100644 index 0000000..ecd1d56 --- /dev/null +++ b/config.toml @@ -0,0 +1,9 @@ +baseURL = 'https://landchad.net' +languageCode = 'en-us' +title = 'LandChad.net' +theme = 'lugo' + +[markup] + [markup.goldmark] + [markup.goldmark.renderer] + unsafe = true diff --git a/content/_index.md b/content/_index.md new file mode 100644 index 0000000..41f6971 --- /dev/null +++ b/content/_index.md @@ -0,0 +1,45 @@ + +This is LandChad.net, a site dedicated to turning internet peasants into Internet Landlords by showing them how to setup websites, email servers, chat servers and everything in between. + +Starting a website is something that can be done in a lazy afternoon and costs pocket change. + +Most of the internet's problems could be solved if more people had their own personal platforms, so the objective of this site is to guide any normal person through the process of installing a website. + +## Start a website + +<div> + +<div class=left> + +This is the basic "course." Follow these quick tutorials and you'll have a fully functioning basic web page on the domain name of your choice. + +⏳ This "basic course" can take **as little as an hour** or even less. + +</div> + +<div class=right> + +{{< basic >}} + +</div> + +</div> + + + +## "Build your own platform!" + +{{< services >}} + +Host your own services, social media and more. + +## Maintaining a Server + +Tips and articles on mastering your server and learning about GNU/Linux systems administration. + +{{< maintain >}} + +## Support LandChad.net + +- BTC: `bc1q9f3tmkhnxj8gduytdktlcw8yrnx3g028nzzsc5` +- XMR: `84RXmrsE7ffCe1ADprxLMHRpmyhZuWYScDR4YghE8pFRFSyLtiZFYwD6EPijVzD3aZiEpg57MfHEr1pGJNPXyJgENMnWrSh` diff --git a/content/auth.md b/content/auth.md new file mode 100644 index 0000000..3f88a90 --- /dev/null +++ b/content/auth.md @@ -0,0 +1,136 @@ +--- +title: "Requiring Passwords for Webpages (HTTP Authentication)" +date: 2020-07-01 +img: 'auth.svg' +tags: ['server'] +--- + +HTTP basic authentication will allow you to secure parts (or all) of +your website with a username and password without the trouble of PHP or +Javascript. This will work with any Nginx server. + +## Installation + +We will be using the command `htpasswd` to make username and password +pairs. + +```sh +apt install apache2-utils +``` + +The apache utils include a small username-password pair encryption tool. + +Like the other tutorials on this site, this tutorial is for Nginx, +**not** for Apache servers. + +Now think of a username and password and remember them. + + htpasswd -c /etc/nginx/myusers username + +The `-c` flag creates a file. You can make the path of this file +anywhere outside of your webroot. + +Obviously the username is up to you as well. + +Type out your password twice to confirm. You can do this as many times +as you\'d like. + +Check out user name password pairs (the password will be securely +hashed): + + cat /etc/nginx/myusers + +## Nginx Config and Auth Basic + +From here, we are going to edit our websites config file in +`/etc/nginx/sites-enabled`. Have in mind which folder you\'d like to +secure. Add something like this: + +```nginx +server { + #... + location /secret-folder { + auth_basic "What's the Password?" ; + auth_basic_user_file /etc/nginx/myusers ; + } + #... +} +``` + +#### Huh? + +If you\'re stuck, try finding the line `location / {` + +Just below this block is where you should add the custom location block + +If you\'d like to do the opposite, such as making the entire site +private except for a public section, do this: + +```nginx +server { + #... + auth_basic "What's the Password?" ; + auth_basic_user_file /etc/nginx/myusers ; + location /public/ { + #... + auth_basic off ; + } + #... +} +``` + +### IP Addresses + +If passwords aren\'t enough we can ban an ip or accept one. + +```nginx +location /api { + #... + allow 192.168.1.23:8080 ; + deny 127.0.0.1 ; +} +``` + +If you want to check both a username and password with an ip address, +use the `satisfy` directive. + +```nginx +location /api { + #... + satisfy all ; + + allow 192.168.1.23:8080 ; + deny 127.0.0.1 ; + + auth_basic "What's the Password?" ; + auth_basic_user_file /etc/nginx/myusers ; +} +``` + +### Complete Example + +```nginx +http { + server { + listen 80; + root /var/www/website ; + + #... + location /secret-folder { + satisfy all ; + + allow 192.168.1.3/24; + deny 127.0.0.1 ; + + auth_basic "What's the Password?" ; + auth_basic_user_file /etc/nginx/myusers ; + } + } +} +``` + +Now check your configuration with `nginx -t` + +Reload nginx and you\'re good to go! + +**Contributor** - [tomfasano.co](https://tomfasano.co){target="_blank"} diff --git a/content/bandwidth.md b/content/bandwidth.md new file mode 100644 index 0000000..2313524 --- /dev/null +++ b/content/bandwidth.md @@ -0,0 +1,88 @@ +--- +title: "Loading Fast and Saving Bandwidth" +draft: true +--- +## Images + +Image files will usually have the most impact on the speed of your +websites (aside from Ad/tracker scripts). Learn to slim down your images +using the ubiquitous *ImageMagick* to make your websites faster on slow +internet connections. + + + +There are some rules of thumb to keep in mind with images: + +1. Only use images as large as you need on the webpage. +2. Use the proper containers. E.g. a photograph should never be a + `.png`, but a `.jpg`, or even better, a `.webp`. +3. Where it will not be visible, reduce image quality. + +### webp vs. png vs. svg + +`png` images are best for accurately recording images **without color +gradients**. A `png` photograph will be massive in size, but a `png` +cartoon without color + +#### An imagemagick experiment + +We can illustrate this difference with imagemagick. Run the following +two commands. They will create two png files containing nothing by the +color red. The first will create a 100x100 pixel image, and the second +will create a massive 10,000x10,000 image. (The second command will take +a few seconds to finish.) + + magick -size 100x100 canvas:red red-small.png + magick -size 10000x10000 canvas:red red-large.png + +Once we\'ve done that, let\'s rerun the same commands, except for let\'s +output them into `jpg` containers: + + magick -size 100x100 canvas:red red-small.jpg + magick -size 10000x10000 canvas:red red-large.jpg + +Once we\'ve run all those commands, you will see that `red-large.jpg` is +a massive 1.2M, while `red-large.png`, despite still being 10,000 square +pixels like the jpg, is a mere 13K in filesize. + +------------------------------------------------------------------------ + +For the examples, I decided to use +[this](https://commons.wikimedia.org/wiki/File:Tabby_cat_with_blue_eyes-3336579.jpg) +public domain image. + +{style="width: 50%;"} + +There are many ways to decrease image size using ImageMagick, the +simplest is to use the `-quality` option, which will compress the image +without changing the resolution. This option takes the value you want to +compress by (between 1 and 100, the lower the value, the lower the file +size). For example: + + convert in.jpg -quality 50 out.jpg + +Compressing the example image above results in the following file size +changes: + + Quality Size + ---------- ------ + Original 2.1M + 90 1.7M + 80 844K + 70 588K + 60 448K + 50 368K + 40 308K + 30 248K + 20 184K + 10 116K + +Due to the images high resolution, it is usable in this website even +when highly compressed (30% quality, still looks decent in my opinion). + +## Contribution + +- [Musse](https://na20a.neocities.org/) +- Monero: + `83is3y69Xv4fkFsTpZhw5c3bfxtimupfgTdpERHM1WtMNAwSqFjTCJm3VabyBKXKnL873dWPmqj4bRcgkm9oCktgQrzmhHd`{.crypto} diff --git a/content/basic/certbot.md b/content/basic/certbot.md new file mode 100644 index 0000000..7cb18cd --- /dev/null +++ b/content/basic/certbot.md @@ -0,0 +1,132 @@ +--- +title: "Certbot and HTTPS" +date: 2021-07-13 +tags: ['basic'] +--- +Once you have a website, it is extremely important to enable encrypted +connections over HTTPS/SSL. You might have no idea what that means, but +it\'s easy to do now that we\'ve [set our web server up](nginx.html). + +Certbot is a program that automatically creates and deploys the +certificates that allow encrypted connections. It used to be painful +(and often expensive) to do this, but now it\'s all free and automatic. + +## Why is encryption important? + +- With HTTPS, users\' ISPs cannot snoop on what they are looking at on + your website. They know that they have connected, but the particular + pages they visit are private as everything is encrypted. HTTPS + increases user privacy. +- If you later create usernames and passwords for any service on your + site, lack of encryption can compromise that private data! Most + well-designed software will automatically *prevent* any unencrypted + connections over the internet. +- Search engines like Google favor pages with HTTPS over unencrypted + HTTP. +- You get the official-looking green 🔒 symbol in the URL bar in most + browsers which makes normies subtly trust your site more. + +## Let\'s do it! + +{{< img alt="website without https/ssl" src="/pix/nginx-website.png" link="/pix/nginx-website.png" >}} + +Note in this picture that a browser accessing your site will say \"Not +secure\" or something else to notify you that we are using and +unencrypted HTTP connection rather than an encrypted HTTPS one. + +## Installation + +Just run: + +```sh +apt install python3-certbot-nginx +``` + +And this will install `certbot` and its module for `nginx`. + +## Run + +As I mentioned in the previous article, firewalls might interfere with +certbot, so you will want to either disable your firewall or at least +ensure that it allows connections on ports 80 and 443: + +```sh +ufw allow 80 +ufw allow 443 +``` + +Now let\'s run certbot: + +```sh +certbot --nginx +``` + +The command will ask you for your email. This is so when the +certificates need to be renewed in three months, you will get an email +about it. You can set the certificates to renew automatically, but it\'s +a good idea to check it the first time to ensure it renewed properly. +You can avoid giving your email by running the command with the +`--register-unsafely-without-email` option as well. + +Agree to the terms, and optionally consent to give your email to the EFF +(I recommend against this obviously). + +Once all that is done, it will ask you what domains you want a +certificate for. You can just press enter to select all. + +{{< img alt="activate HTTPS for a site with certbot" src="/pix/certbot-01.png" link="/pix/certbot-01.png" >}} + +It will take a moment to create the certificate, but afterwards, you +will be asked if you want to automatically redirect all connections to +be encrypted. Since this is preferable, choose 2 to Redirect. + +{{< img alt="redirecting http to encrypted https with certbot" src="/pix/certbot-02.png" link="/pix/certbot-02.png" >}} + +### Checking for success + +You should now be able to go to your website and see that there is a +🔒 lock icon or some other notification that you are now on an encrypted +connection. + +{{< img alt="A 🔒 symbol symbolizing our new HTTPS layer for our website!" src="/pix/certbot-03.png" link="/pix/certbot-03.png" >}} + +## Setting up certificate renewal + +As I mentioned in passing, the Certbot certificates last for 3 months. +To renew certificates, you just have to run `certbot --nginx renew` and +it will renew any certificates close to expiry. + +Of course, you don\'t want to have to remember to log in to renew them +every three months, so it\'s easy to tell the server to automatically +run this command. We will use a [cronjob](/cron) for this. Run the +following command: + +```sh +crontab -e +``` + +There might be a little menu that pops up asking what text editor you +prefer when you run this command. If you don\'t know how to use vim, +choose `nano`, the first option. + +This `crontab` command will open up a file for editing. A crontab is a +list of commands that your operating system will run automatically at +certain times. We are going to tell it to automatically try to renew our +certificates every month so we never have to. + +Create a new line at the end of the file and add this content: + +```txt +0 0 1 * * certbot --nginx renew +``` + +Save the file and exit to activate this cronjob. + +For more on cron and crontabs please [click here!](/cron) + +You now have a live website on the internet. You can add to it what you +wish. + +As you add content to your site, there are many other things you can +also install linked on [the main page](/), and many more +improvements, tweaks and bonuses. diff --git a/content/basic/dns.md b/content/basic/dns.md new file mode 100644 index 0000000..c6d3d42 --- /dev/null +++ b/content/basic/dns.md @@ -0,0 +1,96 @@ +--- +title: "Connect Your Domain and Server with DNS Records" +date: 2021-07-07 +tags: ['basic'] +--- +## The Gist + +Now that we have a [domain](/basic/domain) and a [server](/basic/server), we +can connect the two using DNS records. DNS (domain name system) records +are usually put into your registrar and direct people looking up your +website to the server where your website and other things will be. + +Get your IPv4/IPv6 addresses from Vultr and put them into A/AAAA records +on Epik. Simple process, takes a minute, but here\'s a guide with a +million images just so you know. + +## Open up your Registrar + +As before, we will be using +[Epik](https://www.epik.com/?affid=we2ro7sa6) as a registrar and +[Vultr](https://www.vultr.com/?ref=8384069-6G) as a server host. Go +ahead and log into your accounts on both. Open up Epik, or your +registrar, and click on your domain and then a choice for \"DNS +records.\" This is the screen you\'ll want to see on Epik. + +{{< img alt="Blank Epik DNS records" src="/pix/dns-epik.png" link="/pix/dns-epik.png" >}} + +Note that we are on the \"External Hosts (A, AAAA)\" tab by default. +Epik sometimes adds records to this page once you buy a domain. If they +did, you can go ahead and delete them so they look clean like the +picture above. + +**All we have to do now is get our IP addresses from Vultr and add new +DNS records that will send connections to our server.** + +Keep the Epik tab open and open Vultr and we will copy-and-paste our IP +addresses in. + +## Find your server\'s IP addresses + +Looking at your server in the Vultr menu, you should see a number next +to it. Mine here is `104.238.126.105` as you can see below the server +name (which I have named `landchad.net` after the domain I will soon +attach to it). That is my **IPv4** address. + +{{< img src="/pix/dns-ipv4.png" alt="See the IPv4 address?" link="/pix/dns-ipv4.png" >}} + +Copy your IPv4 address and on Epik, click the \"Add Record\" record +button and add two A entries pasting in your IPv4 address like I\'ve +done for mine here. + +{{< img src="/pix/dns-ipv4-done.png" alt="IPv4 complete" link="/pix/dns-ipv4-done.png" >}} + +I add two entries. One has nothing written in the \"Host\" section. This +will direct connections to `landchad.net` over IPv4 to our IP address. +The second has a `*` in the \"Host\" section. This will direct +connections to all possible subdomains to the right place too, I mean +`mail.landchad.net` or `blog.landchad.net` and any other subdomain we +might want to add later. + +Now let\'s get our IPv6 address, which is a little more hidden for some +reason. IPv6 is important because we are running out of IPv4 addresses, +so it is highly important to allow connections via IPv6 as it will be +standard in the future. Anyway, now back on Vultr, click on the server +name. + +On the server settings, **click on settings** and we will see we are on +a submenu labeled \"IPv4\" where we see our IPv4 address again. + +{{< img src="/pix/dns-vultr.png" alt="Looking for the IPv6" link="/pix/dns-vultr.png" >}} + +Now just click on the **IPv6** submenu to reveal your IPv6 address. + +{{< img alt="The IPv6 address" src="/pix/dns-ipv6.png" link="/pix/dns-ipv6.png" >}} + +That ugly looking sequence of numbers and letters with colons in between +(`2001:19f0:5:ccc:5400:03ff:fe58:324a`) is my **IPv6** address. Yours +will look something like it. Now let\'s put it into Epik. This time, be +sure to select to put in AAAA records as below: + +{{< img src="/pix/dns-ipv6-done.png" alt="IPv6 complete" link="/pix/dns-ipv6-done.png" >}} + +Now just click \"Save Changes.\" It might take a minute for the DNS +settings to propagate across the internet. + +## Test it out! + +Now we should have our domain name directing to our new server. We can +check by pinging our domain name, check this out: + +{{< img src="/pix/dns-ping.png" alt="Pinging landchad.net" link="/pix/dns-ping.png" >}} + +As you can see, our ping to `landchad.net` is now being directed to +`104.238.128.105`. That means we have successfully set up our DNS +records! You can also run the command `host` if you have it, which will +list both IPv4 and IPv6 addresses for a domain name. diff --git a/content/basic/domain.md b/content/basic/domain.md new file mode 100644 index 0000000..67cdd79 --- /dev/null +++ b/content/basic/domain.md @@ -0,0 +1,75 @@ +--- +title: "Get a Domain Name" +tags: ['basic'] +date: 2021-06-01 +--- +## Terms + +Domain name +: The name of a website that you type in an address bar. This site\'s + domain name is `LandChad.net`. + +Top-level domain (TLD) +: The extension of a domain name, like `.com`, `.net`, `.xyz`, etc. + +Registrar +: A service authorized to reserve a domain name for you. + +When domain names first sell, they usually sell for very cheap, but once +someone buys one, they have the rights to it until they decide to sell +it, often for much, much more money. Therefore, it\'s a good idea to +reserve a domain name ASAP, even if you didn\'t intend on doing anything +big with it. + +So let\'s register your domain name! + +## How + +Domains can be registered at any accredited <dfn>registrar</dfn>. In this +guide, I will use the registrar +[Epik](https://www.epik.com/?affid=we2ro7sa6) because it is one of the +more high quality and easy to use. The guides on this site will use +Epik, but if you choose to register your domain with one of the [many, +many other registrars](https://www.icann.org/en/accredited-registrars), +you can still do most of what Epik does, albeit options and settings +might appear in different menus. + +### Basic info about domain names + +- Domain names usually require a *very* small year fee to keep + registered, usually around \$12 for most generic TLDs. There are + some \"specialty\" TLDs that are more expensive, but `.com`, `.xyz` + and other basic TLDs are that cheap. +- Once you own a domain, it is yours as long as you pay the yearly + fee, but you can also sell it to someone for however much you want. +- Domain names do not hold your data or your website, instead, you add + \"DNS settings\" that direct people connecting to your domain to + your IP address. The purpose of a domain name is so that people + don\'t have to remember your IP address to find your website! + +### Looking for domain names + +Let\'s go to [Epik\'s site](https://www.epik.com/?affid=we2ro7sa6) and +you can search for domain names. + +You can look for whatever domain name you want. Domains that are already +bought and owned by someone else might have the option to \"Backorder,\" +but it\'s always best to get one that is unowned, like these: + +{{< img alt="Searching for a domain name" src="/pix/domain-search.png" link="/pix/domain-search.png" >}} + +Note the differences in prices. Some \"specialty\" TLDs like `.game` and +`.io` charge a much larger fee, although you might want one. Some +domains above, like `.xyz` and `.org` have reduced prices for the first +year. + +Choose the domain you want and buy it. These `.xyz` domains are a steal +now on sale. + +{{< img alt="Buying a domain name" src="/pix/domain-cart.png" link="/pix/domain-cart.png" >}} + +That\'s all you have to do to own a domain name! As you register a +domain, you can also setup an automatic payment to pay your fee yearly +to keep your domain. Easy as pie. + +Now we will get a server to host your website on. diff --git a/content/basic/nginx.md b/content/basic/nginx.md new file mode 100644 index 0000000..47a08c1 --- /dev/null +++ b/content/basic/nginx.md @@ -0,0 +1,212 @@ +--- +title: "Setting Up an NginX Webserver" +date: 2021-07-10 +tags: ['basic'] +--- +At this point, we should have a domain name and a server and the domain +name should direct to the IP address of the server with DNS records. As +I said in previous articles, the instructions I will give will be for +**Debian**. In this article, other distributions might work a little +differently. + +## Logging in to the server + +We first want to log into our VPS to get a command prompt where we can +set up the web server. I am assuming you are using either MacOS or +GNU/Linux and you know how to open a terminal. On Windows, you can also +use either PuTTY or the Windows Subsystem for Linux. + +Now on Vultr\'s site, you can click on your VPS and you will see that +there is an area that shows you the password for your server at the +bottom here. + + + +Now pull up a terminal and type: + +```sh +ssh root@example.org +``` + +This command will attempt to log into your server. It should prompt you +for your password, and you can just copy or type in the password from +Vultr\'s site. + +If you get an error here, you might not have done your [DNS +settings](dns.html) right. Double check those. Note you can also replace +the `example.org` with your IP address, but you\'ll want to fix your DNS +settings soon. + +## Installing the Webserver: Nginx + +If the program runs without an error, `ssh` has now logged you into your +server. Let\'s start by running the following commands. + +```sh +apt update +apt upgrade +apt install nginx +``` + +The first command checks for packages that can be updated and the second +command installs any updates. + +The third command installs `nginx` (pronounced Engine-X) which is the +web server we\'ll be using, along with some other programs. + +### Our nginx configuration file + +`nginx` is your webserver. You can make a little website or page, put it +on your VPS and then tell `nginx` where it is and how to host it on the +internet. It\'s simple. Let\'s do it. + +`nginx` configuration files are in `/etc/nginx/`. The two main +subdirectories in there (on Debian and similar OSes) are +`/etc/nginx/sites-available` and `/etc/nginx/sites-enabled`. The names +are descriptive. The idea is that you can make a site configuration file +in `sites-available` and when it\'s all ready, you make a link/shortcut +to it in `sites-enabled` which will activate it. + +First, let\'s create the settings for our website. You can copy and +paste (with required changes) but I will also explain what the lines do. + +Create a file in `/etc/nginx/sites-available` by doing this: + +```sh +nano /etc/nginx/sites-available/mywebsite +``` + +Note that \"nano\" is a command line text editor. You will now be able +to create and edit this file. By saving, this file will now appear. Note +also I name the file `mywebsite`, but you can name it whatever you\'d +like. + +I\'m going to add the following content to the file. The content **like +this** will be different depending on what you want to call your site. + +```nginx +server { + listen 80 ; + listen [::]:80 ; + server_name landchad.net ; + root /var/www/landchad ; + index index.html index.htm index.nginx-debian.html ; + location / { + try_files $uri $uri/ =404 ; + } +} +``` + +#### Explanation of those settings + +The `listen` lines tell `nginx` to listen for connections on both IPv4 +and IPv6. + +The `server_name` is the website that we are looking for. By putting +`landchad.net` here, that means whenever someone connects to this server +and is looking for that address, they will be directed to the content in +this block. + +`root` specifies the directory we\'re going to put our website files in. +This can theoretically be wherever, but it is conventional to have them +in `/var/www/`. Name the directory in that whatever you want. + +`index` determine what the \"default\" file is; normally when you go to +a website, say `landchad.net`, you are actually going to a file at +`landchad.net/index.html`. That\'s all that is. Note that that this in +concert with the line above mean that `/var/www/landchad/index.html`, a +file on our computer that we\'ll create will be the main page of our +website. + +Lastly, the `location` block is really just telling the server how to +look up files, otherwise throw a 404 error. Location settings are very +powerful, but this is all we need them for now. + +### Create the directory and index for the site + +We\'ll actually start making a \"real\" website later, but let\'s go +ahead and create a little page that will appear on when someone looks up +the domain. + +```sh +mkdir /var/www/landchad +``` + +Now let\'s create and index file inside of that directory which will +appear when the website is accessed: + +```sh +nano /var/www/landchad/index.html +``` + +I\'ll add the following basic content, but you can add whatever you +want. This will appear on your website. + +```html +<!DOCTYPE html> +<h1>My website!</h1> +<p>This is my website. Thanks for stopping by!</p> +<p>Now my website is live!</p> +``` + +### Enable the site {#enable} + +Once you save that file, we can enable it making a link to it in the +`sites-enabled` directory: + +```sh +ln -s /etc/nginx/sites-available/mywebsite /etc/nginx/sites-enabled +``` + +Now we can just `reload` or `restart` to make `nginx` service the new +configuration: + +```sh +systemctl reload nginx +``` + +## The Firewall {#firewall} + +Vultr and some other VPS automatically install and enable `ufw`, a +firewall program. This will block basically everything by default, so we +have to change that. If you don\'t have `ufw` installed, you can skip +this section. + +We must open up at least ports 80 and 443 as below: + +```sh +ufw allow 80 +ufw allow 443 +``` + +Port 80 is the canonical webserver port, while 443 is the port used for +encrypted connections. We will certainly need that for the next page. + +<aside> + +As you add more services to your website, they might need you to open more ports, but that will be mentioned on individual articles. +(It should be noted that some local services only running for other services on your machine, so you *don't* need to open ports for every process running locally, *only* those that directly interact with the internet, although it's common to run those through NginX for simplicity and security.) + +</aside> + +## Nginx security hint + +By default, Nginx and most other webservers automatically show their +version number on error pages. It\'s a good idea to disable this from +happening because if an exploit comes out for your server software, +someone could exploit it. Open the main Nginx config file +`/etc/nginx/nginx.conf` and find the line `# server_tokens off;`. +Uncomment it, and reload Nginx. + +Remember to [keep your server software up to +date](maintenance.html#update) to get the latest security fixes! + +## We now have running website! + +At this point you can now type in your website in your browser and this +webpage will appear! + + + +Note the \"Not secure\" notification. The next brief step is securing +encrypted connections to your website. diff --git a/content/basic/server.md b/content/basic/server.md new file mode 100644 index 0000000..e68af8f --- /dev/null +++ b/content/basic/server.md @@ -0,0 +1,98 @@ +--- +title: "Get a Server" +tags: ['basic'] +date: 2021-06-04 +--- +Once you have a [domain name](domain), you\'ll need a server to +host all your website files on. In general, a server is just a computer +that is constanly broadcasting some services on the internet. + +Servers connected to the internet can be extremely useful with or +without proper websites attached to them. You can be your own website, +email, file-sharing service and much more. + +## Getting a VPS + +A Virtual Personal Server (VPS) is a very cheap and easy way to get a +web server. Without you having to buy expensive equipment. There are a +lot of online businesses that have massive server farms with great +internet connection and big power bills that allow you to rent a VPS in +that farm for pocket change. + +A VPS usually costs \$5 a month. Sometimes slightly more, sometimes +slightly less. That\'s a good price for some internet real-estate, but +in truth, you can host a huge number of websites and services on a +single VPS, so you get a lot more. I might have a dozen websites, an +email server, a chat server and a file-sharing services on one VPS. + +The VPS provider that I\'ll be using for this guide is Vultr, since that +is what I use. Vultr provides a free one-month \$100 credit to anyone +who starts an account through [this referral link of +mine](https://www.vultr.com/?ref=8384069-6G) so you can play around with +their services with impunity. + +## Starting your server in two minutes or less + +[Start an account on Vultr](https://www.vultr.com/?ref=8384069-6G) and +let\'s get started. + +Vultr (and other VPS providers) usually give you a choice in where and +what exactly your VPS is. + +#### Server Location + +In general, it doesn\'t *hugely* matter what physical location you have +your server in. You might theoretically want it close to where you or +your audience might be, but if you host a server in Singapore for an +American audience, they won\'t have to be waiting a perceptibly longer +time to load the site. + +[](pix/server-location.png) + +**Some locations might have different abilities and plans than others. +For example, in Vultr, their New York location has optional DDOS +protection and also has some cheaper \$3.50 servers.** + +#### Operating System/Server Type + +{{< img alt="server type" src="/pix/server-type.png" link="/pix/server-type.png" >}} + +I especially recommend **Debian 10** for an operating system for your +server. Debian is the \"classic\" server OS and as such, **I make my +guides on this site for Debian 10**. If you use another OS, just know +that your millage may vary in terms of you might need to change some +instructions here minorly. + +#### Server size + +{{< img alt="server size" src="/pix/server-size.png" link="/pix/server-size.png" >}} + +You finally have a choice in how beefy a server you want. On Vultr, I +recommend getting the cheapest option that is not IPv6 only. + +Web hosting and even moderately complicated sites do not use huge +amounts of RAM or CPU power. If you start doing more intensive stuff +than hosting some webpages and an email server and such, you can always +bump up your plan on Vultr without data loss (it\'s not so easy to bump +down). + +#### Additional features + +{{< img alt="additional features" src="/pix/server-features.png" link="/pix/server-features.png" >}} + +On Vultr, there are some final checkboxes you can select additional +options. **You will want to check *Enable IPv6* and also *Block Storage +Compatible*.** + +We will be setting up IPv6 because it\'s important for future-proofing +your website as more of the web moves to the IPv6 protocol. Block +storage is the ability (if you want) to later rent large storage disks +to connect to your VPS if desired. You just might want that as an +option, so it\'s worth activating now. + +### Done! + +Once you select those settings, your server will automatically be +deployed. Momentarily, you will be able to see your server\'s IP +addresses which will be used for the next brief step: diff --git a/content/bitcoin.md b/content/bitcoin.md new file mode 100644 index 0000000..221ff67 --- /dev/null +++ b/content/bitcoin.md @@ -0,0 +1,105 @@ +--- +title: "Getting a Bitcoin Wallet" +date: 2020-06-28 +icon: "btc.svg" +--- +Let\'s now get a Bitcoin wallet and become able to receive Bitcoin funds +or donations. + +## Wallets + +One of the classical choices for a Bitcoin wallet is Electrum. Go to +[https://electrum.org](https://electrum.org/#home) to download and +install it, or if you are a Linux user, it is probably included in your +distribution\'s package repository. + +### Mobile version? + +Note also that there are mobile/cell phone versions of Electrum for +Android and iOS. I generally advise against using a wallet on a cell +phone for security reasons, but if you would like, you can. + +If you are okay with a mobile wallet, I recommend getting [Cake +Wallet](https://cakewallet.com/), which can use Electrum-style Bitcoin +wallets, but also Monero and Litecoin. + +## Generating a Wallet + +Once you open Electrum (or Cake Wallet), you can choose to create a new +wallet. Name it whatever you want and choose the \"Standard Wallet\" +option. + +I will also note that if you are paranoid, it is perfectly possible to +generate a wallet without connection to the internet. + +### Your Seed is your money. + +Now choose the \"Create a new seed\" option when creating the wallet. +That will randomly produce a \"seed\" of 12 words. + +{{< img alt="bitcoin seed" src="/pix/bitcoin-01.png" link="/pix/bitcoin-01.png" >}} + +**These words are your money.** Once you are shown them, **immediately** +write them down on physical paper, and you will be storing this +somewhere it will not be lost or found. You can memorize these twelve +words if you trust your memory. + +These twelve words unlock all of the funds/addresses you will have on +this wallet. Whoever has your seed has the ability to spend your money. + +Note obviously that I have included a picture of a seed phrase above in +this tutorial. I or anyone else would be stupid to ever send Bitcoin to +the following addresses since the seed phrases are now public. + +Once you have written down your seed, click \"Next\" and Electrum will +have you input that seed again to ensure you\'ve written it down. + +You will also be asked to supply a password. This password merely +encrypts your wallet file on this computer so you don\'t have to retype +your seed phrase each time you open Electrum. Note that anyone with your +seed phrase can still obtain your funds. This password is only +protection on your computer here. + +## Managing your Wallet + +Once your wallet is generated and opened you will be at the wallet page. +First, I recommend opening the \"View\" menu and unhiding all the +different tabs. + +{{< img alt="electrum options" src="/pix/bitcoin-02.png" link="/pix/bitcoin-02.png" >}} + +### Addresses + +The address tab contains all the many Bitcoin addresses generated by +your seed phrase. In fact, as you use these up, the wallet will +automatically add more. + +These addresses (which will all be generated with `bc1` at the +beginning) can be used by others to send you Bitcoins. Someone can just +copy-and-paste the address into their wallet to send you funds. + +{{< img alt="bitcoin addresses" src="/pix/bitcoin-03.png" link="/pix/bitcoin-03.png" >}} + +### Receive + +Click on the \"Receive\" tab and then click \"New Address.\" That will +pick your first unused address which will appear on the right side. You +could copy this from the \"Addresses\" tab, but this tab also generates +a QR code which will appear to the right as well if you click on the +\"QR Code\" subtab. + +{{< img alt="receive qr code" src="/pix/bitcoin-04.png" link="/pix/bitcoin-04.png" >}} + +#### What is the QR code for? + +In case you don\'t know, a QR code is a way of storing text information +in a format that can be scanned by a phone. If someone has a wallet +program on a phone, they can easily scan the QR code on another screen +to avoid having to copy your address over or even worse, write it +manually. + +### Let\'s receive donations on our website. + +Save the QR code and the wallet address it corresponds to (starting in +`bc1`). Now simply put these on your website and anyone can send Bitcoin +to them. Bitcoin users will know how to scan and use them. diff --git a/content/btcpay.md b/content/btcpay.md new file mode 100644 index 0000000..11ed7ed --- /dev/null +++ b/content/btcpay.md @@ -0,0 +1,57 @@ +--- +title: "BTCPay" +icon: 'btcpay.svg' +tags: ['service'] +short_desc: "Host your own payment processor, powered by Bitcoin." +draft: true +--- + +```sh +apt install nginx python3-certbot-nginx tor postgresql postgresql-contrib iptables iptables-persistent +``` + + *filter + :INPUT ACCEPT [0:0] + :FORWARD ACCEPT [0:0] + :OUTPUT ACCEPT [0:0] + -A INPUT -i lo -j ACCEPT + -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT # SSH + -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT # BTCPay HTTP + -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT # BTCPay HTTPS + -A INPUT -p tcp -m tcp --dport 8333 -j ACCEPT # Bitcoind P2P + -A INPUT -p tcp -m tcp --dport 9735 -j ACCEPT # Lightning P2P + -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT + COMMIT + +`iptables-restore > iptables.txt` netfilter-persistent save + + echo "ControlPort 9051 + CookieAuthentication 1" >> /etc/tor/torrc + +certbot \--nginx -d pay.cedars.xyz \--agree-tos +\--register-unsafely-without-email vim /etc/nginx/sites-available/btcpay + +## Building Bitcoin + +Now we can install the Bitcoin node and daemon software. For safety\'s +sake, we will install it from source. + +First, we install the build dependencies: + + apt install build-essential libtool autotools-dev automake pkg-config bsdmainutils python3 libevent-dev libboost-dev libboost-system-dev libboost-filesystem-dev libboost-test-dev git + +Now we can download the Bitcoin source code from the official +repository: + + git clone https://github.com/bitcoin/bitcoin + cd bitcoin + +Now, we compile, then install it. Compiling the software will take some +time. + + ./autogen.sh + ./configure + make + make install + +[[Next:\<++\>](%3C++%3E)]{.next} diff --git a/content/calibre.md b/content/calibre.md new file mode 100644 index 0000000..3e82b62 --- /dev/null +++ b/content/calibre.md @@ -0,0 +1,116 @@ +--- +title: "Calibre" +date: 2021-08-03 +icon: "calibre.png" +short_desc: 'A public or private digital library.' +tags: ['service'] +--- + +The Calibre library server is a great way to store your eBooks. It +allows you to: + +- Share your books with others. +- Easily transfer your books between devices and access them from + anywhere. + +## Installation + +Install the Calibre package. You might also want rsync to upload books. + +```sh +apt install -y calibre rsync +mkdir /opt/calibre +``` + +Either upload your existing library using `rsync`. For example to +`/opt/calibre/`. + +```sh +cd ~/Documents +rsync -avuP your-library-dir root@example.org:/opt/calibre/ +``` + +Or create a library and add a book to it: + +```sh +cd /opt/calibre +calibredb add book.epub --with-library your-library +``` + +For more information about the `calibredb` command see `man calibredb`. + +Add a new user to protect your server: + +```sh +calibre-server --manage-users +``` + +## Creating a service + +Create a new file `/etc/systemd/system/calibre-server.service` and add +the following: + +```systemd +[Unit] +Description=Calibre library server +After=network.target + +[Service] +Type=simple +User=root +Group=root +ExecStart=/usr/bin/calibre-server --enable-auth --enable-local-write /opt/calibre/your_library --listen-on 127.0.0.1 + +[Install] +WantedBy=multi-user.target +``` + +You can change the port with the `--port` prefix. Additional information +`man calibre-server`. + +Issue `systemctl daemon-reload` to apply the changes. + +Enable and start the service. + +```sh +systemctl enable calibre-server +systemctl start calibre-server +``` + +## A reverse proxy with Nginx + +Create a new file `/etc/nginx/sites-available/calibre` and enter the +following: + +```nginx +server { + listen 80; + client_max_body_size 64M; # to upload large books + server_name calibre.example.org ; + + location / { + proxy_pass http://127.0.0.1:8080; + } +} +``` + +Issue a Let\'s Encrypt certificate. [Detailed instructions and additional information](/certbot). + +```sh +certbot --nginx +``` + +Now just go to **calibre.example.org**. The server will request an +username and a password. + +{{< img src="/pix/calibre/calibre-1.png" alt="calibre" >}} + + +After login you will see something like this. + +{{< img src="/pix/calibre/calibre-2.png" alt="calibre" >}} + +## Contribution + +Author: rflx -- [website](https://rflx.xyz) \-- XMR: +`48T5XpHTXAZ5Nn8YCypA4aWn1ffQLHJkFGDArXQB6cmrP6cqLY72cu7CR2iq2MmL5Ndu3d47e5MKjGpL4prYgdrTCFAHD9c` diff --git a/content/cgi.md b/content/cgi.md new file mode 100644 index 0000000..5f293e9 --- /dev/null +++ b/content/cgi.md @@ -0,0 +1,210 @@ +--- +title: "Server-Side Scripting with CGI" +date: 2021-07-25 +tags: ['server'] +--- +The basic website tutorial here describes how to set up a static website +--- one that just serves HTML files saved on your server, and until you +change something manually, the same content will be served each time a +given page is requested. This is perfectly enough for most personal +website needs. This is how blogs should be implemented, instead of +relying on bloatware like WordPress! + +But sometimes you genuinely *do* need something more. You need your +website to serve different contents depending on the time, on who the +requester is, on the contents of a database, or maybe process user input +from a form. + +## CGI + +CGI, or the Common Gateway Interface, is a specification to allow you, +the server owner, to program your web server using pretty much any +programming language you might know. The specification is almost as old +as the Internet itself and for a long time CGI scripting was the primary +method of creating dynamic websites. + +CGI is a very simple specification indeed. You write a script in your +favorite language, the script receives input about the request in +environment variables, and whatever you print to the standard output +will be the response. Most likely, though, you will want to use a +library for your language of choice that makes a lot of this +request/response handling simpler (e.g. parsing query parameters for +you, setting appropriate headers, etc.). + +### Limitations of CGI + +While in theory you could implement any sort of functionality with CGI +scripts, it\'s going to get difficult managing a lot of separate scripts +if they\'re supposed to be working in tandem to implement a dynamic +website. If you want to build a full out web application, you\'d +probably be better off learning a web framework than gluing together +Perl scripts. + +That said, just as most of the web could be replaced with static +websites, much of the remaining non-static web could be replaced with a +few simple scripts, rather than bloated Ruby on Rails or Django +applications. + +## Let\'s write a CGI script! + +We\'ll implement a simple example CGI script. I\'ll use Ruby for this +tutorial, but you\'ll be able to follow along even if you don\'t know +Ruby, just treat it as pseudocode then find a CGI library for your +language. + +### The working example + +Our working example will be the Lazy Calculator. Yeah, you\'re probably +tired of seeing calculator examples in every programming tutorial, but +have you ever implemented one that takes the weekends off? + +Here\'s how it will work. When in a browser you submit a request to your +website like + +```txt +example.com/calculator.html?a=10&b=32 +``` + +you will receive a page with the result of the addition of 10 and 32: +42. + +*Unless* you send your request on a weekend. Then the website will +respond with + +```txt +I don't get paid to work on weekends! Come back Monday. +``` + +This example will show a few things that CGI scripts can do that you +wouldn\'t have been able to get using just file hosting in your web +server: + +- getting inputs from the user; +- getting external information (here just the system time, but you + could imagine instead connecting to a database); +- using the above to create dynamic output. + +### The code + +Here\'s an implementation of the lazy calculator as a Ruby CGI script: + +```ruby +#!/bin/env ruby + +require 'cgi' +require 'date' + +cgi = CGI.new +today = Date::today + +a = cgi["a"].to_i +b = cgi["b"].to_i + +if today.saturday? || today.sunday? + cgi.out do + "I don't get paid to work on weekends! Come back Monday." + end +else + cgi.out do + (a + b).to_s + end +end +``` + +Let\'s go through what\'s happening here. + +### The shebang line + +CGI works by pointing your web server to an executable program. A Ruby +or Python script by itself is not immediately executable by a computer. +But on Unix-like systems you can specify the program that will be able +to execute your file in its first line if it starts with `#!` (known as +the shebang; read more about it on +[Wikipedia](https://en.wikipedia.org/wiki/Shebang_(Unix))). + +So if you\'re going to be using a scripting language, you\'ll probably +need the appropriate shebang line at the top of your script. If you use +a compiled language, you\'ll just point your web server to the compiled +executable binary. + +### Query parameters + +The next interesting lines of code are where we set the variables `a` +and `b`. Here we are getting user inputs from the request. + +In the example request we mentioned above +(`example.com/calculator.html?a=10&b=32`), the part starting from the +question mark, `?a=10&b=32`, is the *query string*. This is how users +can submit parameters with their web requests. Usually these parameters +are set by e.g. a form on your website, but in our simple example we\'ll +be just manually manipulating the URL. + +The query string contains key-value pairs. The Ruby CGI library makes +them available in the `CGI` object it provides. We just need to index it +with the desired key, and we\'ll get the corresponding value. + +### Wrapping it up + +The remaining parts of the code should be pretty self-explanatory. We +get today\'s date, check if it\'s a Saturday or a Sunday, and depending +on that, we instruct the CGI library to output either the answer, or a +\"come back later\" message. + +The Ruby library by default returns an HTML response, so we really +should have wrapped our outputs in some `html`, `body`, etc. tags. +Alternatively, we could have specified that the response is just plain +text with + +```txt +cgi.out 'text/plain' do +``` + +In general, your CGI library will probably have ways of specifying all +sorts of HTTP response headers, like status code, content type, etc. + +## Making it work + +We have a CGI script, now let\'s point our web server to it. + +### Installing FastCGI + +If you\'re using Nginx, install `fcgiwrap`: + +```sh +apt install fcgiwrap +``` + +This installs the necessary packages for Nginx to use FastCGI --- a +layer between your web server and CGI script that allows for faster +handling of scripts than if the web server had to handle it all by +itself. + +Other web servers will probably have a similarly simple way of enabling +FastCGI, or you can look into other methods for launching CGI scripts. + +### Nginx configuration + +In the configuration file for your website, add something like the +following: + +```nginx +location /calculator.html { + include fastcgi_params; + fastcgi_param SCRIPT_FILENAME /usr/local/bin/lazy-calculator.rb; + fastcgi_param QUERY_STRING $query_string; + fastcgi_pass unix:/run/fcgiwrap.socket; +} +``` + +`fastcgi_param` directives specify various parameters for FastCGI. +`SCRIPT_FILENAME` should point to your executable. For `QUERY_STRING`, +we just copy Nginx\'s `$query_string` variable. You might want to pass +other information to your CGI script as well, see for example [the +Debian wiki](https://wiki.debian.org/nginx/FastCGI) for a more detailed +example, including pointing to an entire directory of CGI scripts, +rather than adding each one by hand to your web server config. + +## Contribution + +- Martin Chrzanowski \-- [website](https://m-chrzan.xyz), + [donate](https://m-chrzan.xyz/donate.html) diff --git a/content/cgit.md b/content/cgit.md new file mode 100644 index 0000000..8f239c6 --- /dev/null +++ b/content/cgit.md @@ -0,0 +1,135 @@ +--- +title: "Cgit" +date: 2021-09-14 +short_desc: 'A hyperfast web frontend for git repositories.' +icon: 'cgit.svg' +tags: ['service'] +--- +Once you have your server hosting your git repositories, you might want +to allow others to browse your repositories on the web. Cgit is a Free +Software that allows browsing git repositories through the web. + +Note that Cgit is a read-only frontend for Git repositories and doesn\'t +have issues, pull requests or user management. If that\'s what you want, +consider installing Gitea instead. + +## Installing cgit and fcgiwrap + +### Install fcgiwrap + +NGINX doesn\'t have the capability to run CGI scripts by itself, it +depends on an intermediate layer like fcgiwrap to run CGI scripts like +cgit: + +```sh +apt install fcgiwrap +``` + +And now we can install cgit itself with: + +```sh +apt install cgit +``` + +## Setting up NGINX + +You should have an NGINX server running with a TLS certificate by now. +Add the following configuration to your server to pass the requests to +Cgit, while serving static files directly: + +```nginx +server { + listen 443 ssl; + listen [::]:443 ssl; + ssl_certificate /etc/ssl/nginx/git.example.org.crt; + ssl_certificate_key /etc/ssl/nginx/git.example.org.key; + server_name git.example.org; + + root /usr/share/cgit ; + try_files $uri @cgit ; + + location @cgit { + include fastcgi_params; + fastcgi_param SCRIPT_FILENAME /usr/lib/cgit/cgit.cgi; + fastcgi_param PATH_INFO $request_uri; + fastcgi_param QUERY_STRING $query_string; + fastcgi_pass unix:/run/fcgiwrap.socket; + } +} +``` + +Then get NGINX to reload your configuration. + +## Configuring cgit + +You\'ve got cgit up and running now, but you\'ll probably see it without +any style and without any repository. To change this, we need to +configure Cgit to our liking, by editing `/etc/cgitrc`. + +```txt +css=/cgit.css +logo=/cgit.svg +virtual-root=/ + +# Title and description shown on top of each page +root-title=Chad's git server +root-desc=A web interface to LandChad's git repositories, powered by Cgit + +# The location where git repos are stored on the server +scan-path=/srv/git/ +``` + +This configuration assumes you followed the [git hosting guide](/git) +and store your repositories on the `/srv/git/` directory. + +Cgit\'s configuration allows changing many settings, as documented on +the cgitrc(5) manpage installed with Cgit. + +### Changing the displayed repository owner + +Cgit\'s main page shows each repo\'s owner, which is \"git\" in case you +followed the git hosting guide, but you might want to change the name to +yours. Cgit shows the owner\'s system name, so you need to modify the +git user to give it your name: + +```sh +usermod -c "Your Name" git +``` + +### Changing the repository description + +Navigate to your bare repository on the server and edit the +`description` file inside it + +### Displaying the repository idle time + +To do this, we need to create a post-receive hook for each repository +that updates the file cgit uses to determine the idle time. Inside your +repository, create a file `hooks/post-receive` and add the following +contents: + +```sh +#!/bin/sh + +agefile="$(git rev-parse --git-dir)"/info/web/last-modified + +mkdir -p "$(dirname "$agefile")" && +git for-each-ref \ + --sort=-authordate --count=1 \ + --format='%(authordate:iso8601)' \ + >"$agefile" +``` + +And give it execution permissions with: + +```sh +chmod +x hooks/post-receive +``` + +Next time you push to that repository, the idle time should reset and +show the correct value. + +## Contribution + +- Ariel Costas -- [website](https://costas.dev), + [donations](https://costas.dev/donations/) diff --git a/content/coturn.md b/content/coturn.md new file mode 100644 index 0000000..25c1a34 --- /dev/null +++ b/content/coturn.md @@ -0,0 +1,110 @@ +--- +title: "Coturn" +date: 2022-03-29 +icon: "webrtc.svg" +img: "webrtc.svg" +tags: ['service'] +--- + +[Coturn](https://github.com/coturn/coturn) is a libre **STUN** and +**TURN** server software that allows users of chat protcols (Such as +[XMPP](/prosody) and [Matrix](/matrix)) to perform WebRTC **voice +and video calls** despite them being behind NATs. + +Almost every self-hosted voice and video conferencing program (such as +[Jitsi](/jitsi) and [Nextcloud\'s](/nextcloud) Talk app) will +**require** Coturn or some other equivalent turnserver to function +properly. + +## Installation + +Coturn is available in the Debian repositories: + +```sh +apt install coturn +``` + +## Configuration + +### Base configuration + +Coturn\'s configuration file is `/etc/turnserver.conf`. There are a few +aspects that need to be changed in order to get a fully-functioning +turnserver. + +Here is an example of some sane defaults: + +```md +server-name=turn.example.org +realm=turn.example.org +listening-ip=your_public_ip + +listening-port=3478 +min-port=10000 +max-port=20000 + +## The "verbose" option is useful for debugging issues +verbose +``` + +### Authentication + +There are two options for authentication on a turnserver: + +1. **Usernames** and **passwords,** +2. or **authentication secrets.** + +Depending on what self-hosted service is being used in conjunction with +Coturn, you may need one or the other of these two options. + +#### Usernames and Passwords + +To utilize username and password authentication with Coturn, add the +following configuration in `turnserver.conf`: + +```txt +lt-cred-mech +user=username:password +``` + +#### Authentication Secrets + +To utilize authentication secrets with Coturn, add the following +configuration in `turnserver.conf`: + +```txt +use-auth-secret +static-auth-secret=your_auth_secret +``` + +## TURNS (TLS Encryption) + +Some self-hosted services (such as Matrix and XMPP) may support the use +of **TURNS:** An encrypted version of TURN, which allows for WebRTC +connections to be established with the use of an encrypted TLS tunnel, +just like HTTPS allows for encrypted viewing of websites. + +To utilize TURNS, certificates need to be declared for +**turn.example.org** in `turnserver.conf`: + +```txt +cert=/etc/letsencrypt/live/turn.example.org/fullchain.pem +pkey=/etc/letsencrypt/live/turn.example.org/privkey.pem +``` + +## Starting Coturn + +After all configuration changes are complete, Coturn can be started with +its systemd daemon: + +```sh +systemctl restart coturn +``` + +Congratulations! You\'ve successfully setup a Coturn server! + +------------------------------------------------------------------------ + +*Written by [Denshi.](https://denshi.org) Donate Monero +[here](https://denshi.org/donate.html) +[\[QR\]](https://denshi.org/images/monero.jpg)* diff --git a/content/cron.md b/content/cron.md new file mode 100644 index 0000000..7ca3c10 --- /dev/null +++ b/content/cron.md @@ -0,0 +1,173 @@ +--- +title: "Cronjobs" +date: 2020-07-01 +tags: ['server'] +--- + +Cron is a service that lets you run scheduled tasks on a computer. These tasks +are called **cronjobs.** If you have already followed the initial course you +will have already used cron when you set up Certbot, but we'll explain how they work generally here. + +## What tasks would I want to schedule? + +You can schedule anything! Some examples of what you might have done +already include: + +- `updatedb` to update your `locate` database to let you quicking search for files +- `certbot` to update renewing of your https certs + +Some tasks that you might *want* to schedule may include: + +- Package updates - if you really just want to leave your server alone + you can automated updating packages on your server +- Backups - you may want to backup certain files every day and some + every week, this is possible with cron + +And many more, anything you can do can be turned into a cronjob. + +## Basic Cronjobs + +This the preferred method for personal tasks and scripts; it\'s also the +easiest to get started with. Run the command `crontab -e` to access your +user\'s crontab + +Once you have figured out the command you want to run you need to figure +out how often you want to run it and when. I am going to schedule my +system updates once a week on at 3:30 AM on Mondays. + +We now have to convert this time (Every Monday at 3:30 AM) into a cron +time. Cron uses a simple but effective way of scheduling when to run +things. + +Crontab expressions look like this `* * * * * command-to-run` The five +elements before the command tell when the command is supposed to be run +automatically. + +So for our Monday at 3:30 AM job we would do the following: + +```txt + .---------------- minute (0 - 59) + | .------------- hour (0 - 23) + | | .---------- day of month (1 - 31) + | | | .------- month (1 - 12) + | | | | .---- day of week (0 - 6) + | | | | | + * * * * * +30 3 * * 1 apt -y update && apt -y upgrade +``` + +### Some notes + +- On the day of the week option, Sunday is 0 and counting up from + there, Saturday will be 6. +- `*` designates \"everything\". Our command above has a `*` in the + day of month and month columns. This means it will run regardless of + the day of the month or month. +- The hour option uses 24 hour time. 3 = 3AM, while use 15 for 3PM. + +### More examples + +Let\'s add another job, our backup job (for the purposes of this our +backup command is just called `backup`). We want to run `backup` every +evening at 11PM. Once we work out the timings for this we can add the to +the same file as the above by running `crontab -e` This would mean our +full crontab would look like this: + +```txt +0 23 * * * backup +``` + +### Consecutive times + +Suppose we want a command to run every weekday. We know we can put `1` +(Monday), but we can also use `1-5` to signify from day 1 (Monday) to +day 5 (Friday). + +```txt +0 6 * * 1-5 echo "Wakey, wakey, wagie!" >> /home/wagie/alarm +``` + +The above `echo` command runs every Monday through Friday at 6:00AM. + +### Non-consecutive times + +We can also randomly specify non-consecutive arguments with a comma. +Suppose you have a script you want to run at the midday of the 1st, +15th, and 20th day of every month. You can specify that by putting +`1,15,20` for the day of the month argument: + +```txt +0 12 1,15,20 * * /usr/bin/pay_bills_script +``` + +### \"Every X minutes/days/months\" + +We can also easily run a command every several minutes or months, +without specifying the specific times: + +```txt +*/15 * * * * updatedb +``` + +This cronjob will run the `updatedb` command every 15 minutes. + +### Beware of this Rookie Mistake Though\... + +Suppose you want to run a script once every other month. You might be +*tempted* write this: + +```txt +* * * */2 * +``` + +That might *feel right*, but this script *will be running once every +minute during that every other month*. You should specify the first two +arguments, because with `*` it will be running every minute and hour! + +```txt +0 0 1 */2 * +``` + +This makes the command run *only* at 0:00 (12:00AM) on the first day of +every two months, which is what we really want. + +Consult the website [crontab.guru](https://crontab.guru) for an +intuitive and interactive tester of cronjobs. + +## User vs. Root Cronjobs + +It is important to note that user accounts all have different cronjobs. +If you have a user account `chad` and edit his crontab with +`crontab -e`, the commands you add will be run as the `chad` user, not +`root` or anyone else. + +Bear in mind that if you need root access to run a particular command, +you will usually want to add it as root. + +## System-wide cron directories + +`crontab -e` is the typical interface for adding cronjobs, but it\'s +important to at least know that system-wide jobs are often stored in the +file directory. Some programs which need cronjobs will automatically +install them in the following way. + +Run the command `ls /etc/cron*` you should see a list of directories and +there contents. The directories should be something like the below: + +- /etc/cron.d *This is a crontab like the ones that you create with* + `crontab -e` +- /etc/cron.hourly +- /etc/cron.daily +- /etc/cron.weekly +- /etc/cron.monthly + +The directories cron.{hourly,daily,weekly,monthly} are where you can put +**scripts** to run at those times. You don\'t put normal cron entries +here. I prefer to use these directories for system wide jobs that don\'t +relate to an individual user. + +## Contribution + +- Mark McNally \-- [website](https://mark.mcnally.je), + [Youtube](https://www.youtube.com/channel/UCMiInY8BhSUtCarO6uu6i_g) +- Edits and examples by Luke diff --git a/content/ejabberd.md b/content/ejabberd.md new file mode 100644 index 0000000..7f024f1 --- /dev/null +++ b/content/ejabberd.md @@ -0,0 +1,259 @@ +--- +title: "ejabberd" +date: 2022-03-29 +icon: 'ejabberd.png' +tags: ['service'] +short_desc: "A chat server based on XMPP." +--- + +[Ejabberd](https://ejabberd.im) is a server for the XMPP protocol +written in Erlang. It\'s easier to configure and setup than +[Prosody](/prosody) due to having most of its modules built-in and +pre-configured by default. + +## Prerequisites + +### Subdomains + +Ejabberd presumes that you have already created all the **required and +optional subdomains** for its operation prior to running it. + +Depending on the usecase, you may need any or all of the following +domains for XMPP functionality: + +- **example.org** - Your XMPP hostname +- **conference.example.org** - For Multi User Chats (MUCs) +- **upload.example.org** - For file upload support +- **proxy.example.org** - For SOCKS5 proxy support +- **pubsub.example.org** - For publish-subscribe support + +This guide will assume **all these subdomains** have been created. + +## Installation + +Ejabberd is available in the Debian repositories: + +```sh +apt install ejabberd +``` + +## Configuration + +The ejabberd server is configured in `/etc/ejabberd/ejabberd.yml`. +Changes are only applied by restarting the ejabberd daemon in systemd: + +```sh +systemctl restart ejabberd +``` + +### Hostnames + +The **XMPP hostname** is specified in the `hosts` section of +`ejabberd.yml`: + +```yml +hosts: + - example.org +``` + +### Certificates + +Unlike [Prosody,](https://prosody.im) ejabberd doesn\'t come equipped +with a script that can automatically copy over the relevant certificates +to a directory where the ejabberd user can read them. + +One way of organizing certificates for ejabberd is to have them stored +in `/etc/ejabberd/certs`, with each domain having a separate directory +for both the fullchain cert and private key. + +Using certbot, this process can be easily automated with these commands: + +```sh +$DOMAIN=subdomain.example.org +certbot --nginx -d $DOMAIN certonly; mkdir /etc/ejabberd/certs/$DOMAIN +cp /etc/letsencrypt/live/$DOMAIN/fullchain.pem /etc/ejabberd/certs/$DOMAIN +cp /etc/letsencrypt/live/$DOMAIN/privkey.pem /etc/ejabberd/certs/$DOMAIN +``` + +This should be ran with your XMPP hostname **(example.org)** and +repeated for all your desired subdomains. + +To enable the use of all these certificates in ejabberd, the following +configuration is necessary: + +```yml +certfiles: + - "/etc/ejabberd/certs/*/*.pem" +``` + +### Admin User + +The **admin user** can be specified in `ejabberd.yml` under the `acl` +section: + +```yml +acl: + admin: + user: admin +``` + +This would make **admin@example.org** the user with administrator +privileges. + +### Message Archives + +The ejabberd server supports keeping archives of messages through its +`mod_mam` module. This can be enabled by uncommenting the following +lines: + +```yml +mod_mam: + assume_mam_usage: true + default: always +``` + +## Database + +### Why use a database? + +In the `mod_mam` section of the ejabberd config file, the following +message is in comments: + +```yml +mod_mam: + ## Mnesia is limited to 2GB, better to use an SQL backend + ## For small servers SQLite is a good fit and is very easy + ## to configure. Uncomment this when you have SQL configured: + ## db_type: sql +``` + +As these comments imply, an **SQL backend** is strongly recommended if +you wish to use your ejabberd server for anything more than just +testing. Ejabberd supports **MySQL, SQLite** and **PostgreSQL.** + +While all of those are suitable choices, the best database system to use +is PostgreSQL. It\'s the same database backend used by +[PeerTube](/peertube) and [Matrix](/matrix), making it the most +convenient option if you\'re already running those too. + +### Installing PostgreSQL + +PostgreSQL is available in the Debian repositories: + +```sh +apt install postgresql +``` + +Start the PostgreSQL daemon to begin using it: + +```sh +systemctl start postgresql +``` + +### Creating the Database + +To create the database, first create a PostgreSQL user for ejabberd: + +```sh +su -c "createuser --pwprompt ejabberd" postgres +``` + +Then, create the database and make `ejabberd` its owner: + +```sh +su -c "psql -c 'CREATE DATABASE ejabberd OWNER ejabberd;'" postgres +``` + +### Importing Database Scheme + +Ejabberd doesn\'t create the database scheme by default; It has to be +imported into the database before use. + +```sh +su -c "curl -s https://raw.githubusercontent.com/processone/ejabberd/master/sql/pg.sql | psql ejabberd" postgres +``` + +### Configuring ejabberd to use PostgreSQL + +Finally, add the following configuration to `ejabberd.yml`: + +```yml +sql_type: pgsql +sql_server: "localhost" +sql_database: "ejabberd" +sql_username: "ejabberd" +sql_password: "psql_password" +``` + +Once you\'ve ensured your database name, username and password are all +correct, enable SQL storage for `mod_mam`: + +```yml +mod_mam: + ## (Other parameters) + db_type: sql +``` + +## Using ejabberd + +### Registering the Admin User + +To begin using ejabberd, firstly start the ejabberd daemon: + +```sh +systemctl restart ejabberd +``` + +Then, using `ejabberdctl` as the ejabberd user, register the admin user +which is set in `ejabberd.yml`: + +```sh +su -c "ejabberdctl register admin example.org password" ejabberd +``` + +This will create the user **admin@example.org.** + +### Using the Web Interface + +By default, ejabberd has a web interface accessible from +**http://example.org:5280/admin**. When accessing this interface, you +will be prompted for the admin credentials: + +{{< img src="/pix/ejabberd-login.jpg" >}} + +After signing in with the admin credentials, you will be able to manage +your ejabberd server from this web interface: + +{{< img src="/pix/ejabberd-admin.jpg" >}} + +## TURN & STUN for Calls + +Ejabberd supports the **TURN** and **STUN** protocols to allow internet +users behind NATs to perform voice and video calls with other XMPP +users. + +Firstly, setup a TURN and STUN server with [Coturn,](/coturn) using +an **authentication secret.** + +Then, edit `mod_stun_disco` to contain the appropriate information for +your turnserver: + +```yml + mod_stun_disco: + secret: "your_auth_secret" + services: + - + host: turn.example.org + type: stun + - + host: turn.example.org + type: turn +``` + +And with that, you\'ve successfully setup your ejabberd XMPP server! + +------------------------------------------------------------------------ + +*Written by [Denshi.](https://denshi.org) Donate Monero +[here](https://denshi.org/donate.html) +[\[QR\]](https://denshi.org/images/monero.jpg)* diff --git a/content/federation.md b/content/federation.md new file mode 100644 index 0000000..770739c --- /dev/null +++ b/content/federation.md @@ -0,0 +1,57 @@ +--- +title: "Federation" +draft: true +tags: ['concepts','activity-pub'] +--- +The internet was supposed to be a place where everyone was an internet +LandChad. Everyone had their own website and email and own services. +Obviously, this site is all about getting back to that ideal. + +That\'s why it\'s important to understand the concept of +<dfn>Federation</dfn> in technology. It\'s the idea that instead of one +central \"node\" or site that everyone uses, like Facebook, Twitter, +Insta, R\*ddit, people can run their own sites that can nonetheless +*interact* with othersites as easily as if they were the same. + +You already know one federated technology: email. There is no one site +for email, but many sites, and all people on all those sites can use +email to talk to one another. You can get censored on Facebook. You +can\'t get censored on \"email.\" You could have a Gmail account +deleted, but you are not blocked out of the system, as you can go to any +number of sites and get a new account or [make your own server](/email) and you can still talk to all your friends via +email. + +## \"Federated\" Social Media + +The idea of Federated Social Media is using that principle used in +email, but for other things, like chatting or social media. + +Here\'s an example. There is some software [you can install on your +server](/pleroma) called [Pleroma](https://pleroma.social/). It can +be installed on your site just like a web or email server, but what it +does is creates a Twitter-like microblogging site. You can then have +your friends join and use it just like you use Twitter, with you as the +admin and deciding policy and you can even format and decorate the site +how you want. + +### It gets even better\... + +**But here is the clincher.** Federated social media like Pleroma can +interact with other Pleroma servers on the internet in the same way that +Gmail\'s servers can send messages to any other email server. So you +might have 2 people on your Pleroma site, but you can interact with the +many thousands of other Pleroma sites. + +There is seamless interaction. You can view, like, share and respond to +their posts as if they were part of your own site. + +### And it gets even betterer\... + +Pleroma is based on a protocol called [Activity +Pub](https://activitypub.rocks/). This is also used by other software +like [PeerTube](https://joinpeertube.org/) (which is a self-hosted +YouTube-equivalent), [Friendica](https://friendi.ca/) (Facebook +equivalent). + +Accounts on *all* of these platforms can view, interact with and participate with accounts on other platforms. +You can do the equivalent of posting a comment on a "YouTube" video from your "Twitter" account. diff --git a/content/fosspay.md b/content/fosspay.md new file mode 100644 index 0000000..9414179 --- /dev/null +++ b/content/fosspay.md @@ -0,0 +1,200 @@ +--- +title: "Fosspay" +tags: ['service'] +icon: 'devault.jpg' +short_desc: "A self-hosted payment and donation gateway interfaced with Stripe." +draft: true +--- +[Fosspay](https://sr.ht/~sircmpwn/fosspay/) is a free-software web frontend for receiving donations and +subscriptions, similar to Patreon or Liberapay, but which can be hosted +on your own server. It can also interface with Patreon or Github +Sponsors to aggregate all your donations. + +## Stripe Setup + +Fosspay uses [Stripe](https://stripe.com) as a payment processor, which +is a less annoying and more serious and extensible equivalent of PayPal. +You must set up an account with them to be able to receive card payments +through Fosspay. + +Note that with Stripe, these payments can be arranged to go directly to +a bank account within a day or so. + +Be sure to check out or configure all the Stripe settings you want +before hand. For example, Stripe will automatically include your phone +number on invoices by default, so you might want to change that if you +are not using a dummy number. + +### Note + +LandChad.net strives for free software, privacy and internet +independence. Using Stripe is better than using companies with a bad +reputation like PayPal, but it is still a large company with can +compromise the privacy of you and others and ban people. + +Stripe does do a good job making payments very easy for you: you do not +have to do legally difficult things like storing credit card numbers +(they are sent directly to Stripe via Javascript code). They are also good at +catching fraudulent transactions and other issues that might arise. + +But if you want a truly and fully free and open source monetary system +and will not compromise for less, please use Bitcoin or Monero +exclusively. Compared to any other fiat service, Stripe is about the +best, and Fosspay is a great way to self-host a payment gateway. + +## Dependencies + +We will need git, postgres and the ability to make a python virtual +environment: + +```sh +apt install git python3-venv python3-dev postgresql libpq-dev +``` + +## Download and Installation + +We will download fosspay to `/var/www/fosspay/`. This directory will +also serve as our virtual environement. + +```sh +git clone https://git.sr.ht/~sircmpwn/fosspay /var/www/fosspay +python3 -m venv /var/www/fosspay +``` + +Activate the python environment with the command below, then we will +install the dependencies. + +```sh +source /var/www/fosspay/bin/activate +cd /var/www/fosspay +pip install -r requirements.txt +``` + +The `install` command, at the time of this writing, *might* produce many +errors related to the `psycopg2` package. If it does, you can ignore +them, let the command complete and run `apt install python3-psycopg2` to +get the package globally. + +Be sure you are still in `/var/www/fosspay`, then we will build the +package and create the configuration file. + +```sh +make +cp config.ini.example config.ini +``` + +## Create a Database + +Fosspay uses a postgresql database to store donation information, so +let\'s create a database and user for it. + +First, become the `postgres` user and run the `psql` command: + +```sh +su postgres +psql +``` + +We will create a database named `fosspay` controled by a user named +`fosspay` (also identified by a a password `fosspay`). + +```sql +create database fosspay ; +create user fosspay with encrypted password 'fosspay' ; +grant all privileges on database fosspay to fosspay ; +\q +``` + +Note that if you want to use a different username or password for +whatever reason, change them in the command above, but also in the +`connection-string` variable in the configuration file. + +## Configuration + +Now open up `/var/www/fosspay/config.ini` and we will set things up. +Here are a list of things to edit. + +- `domain` should be set to `donate.example.org`, with your domain. +- `protocol` can be set to `https`. +- Get or create an email account to use as a mailer and add the + account/server information to the email settings. +- Add your public and secret Stripe keys to the information. +- Change the `connection-string` to + `postgresql://fosspay:fosspay@localhost/fosspay` as set up above. + +**An important note:** mail ports *must* be opened on the server you\'re +using, or else Fosspay will silently fail to send mails when someone +tries to donate or reset their password. You do not have to run a mail +server on the same server as Fosspay, but either way, mail submission +ports must be opened. This usually requires contacting your VPS provider +and requesting it from them. + +### Optional Integration with Patreon, Github, Liberapay + +Note that if you have a previous Patreon, Github Sponsors or Liberapay +account, you can create an access token for Fosspay, so that you can +display your income from those sources along side Fosspay monthly +donations. + +For Liberapay, you only need to include your username. You must create a +[Github access token](https://github.com/settings/tokens) with the +\"user\" access to interface with it, and you have to add several +[Patreon client +parameters](https://www.patreon.com/portal/registration/register-clients) +for it. + +## Nginx configuration + +Fosspay runs on port 5000, so we can have Nginx show the site. Create an +Nginx configuration file modeled as below: + +```nginx +server { + listen 80 ; + listen [::]:80 ; + server_name donate.example.org ; + location / { + proxy_pass http://localhost:5000 ; + } +} +``` + +After that, [remember to get HTTPS for the subdomain!](/basic/certbot) +HTTPS is absolutely required for using Stripe as a payment processor. + +## Systemd File + +We can now create a systemd service file for Fosspay. Create a file in +`/etc/systemd/system/fosspay.service` as below: + +```systemd +[Unit] +Description=fosspay website +Wants=network.target +Wants=postgresql.target +Before=network.target +Before=postgresql.target +[Service] +Type=simple +WorkingDirectory=/var/www/fosspay +VIRTUAL_ENV=/var/www/fosspay +Environment=PATH=$VIRTUAL_ENV/bin:$PATH +ExecStart=/var/www/fosspay/bin/gunicorn app:app -b 127.0.0.1:5000 +ExecStop=/var/www/fosspay/bin/gunicorn +[Install] +WantedBy=multi-user.target +``` + +Note that for safety, we are running fosspay through `gunicorn` in our +virtual environment. + +We can now run `systemctl start fosspay` to start the service, and it +should appear at the URL you designated above. + +## Customizing the Page + +Within `/var/www/fosspay/templates`, there are various files that you +can change to add text and other features to the page. The main file is +`summary.html`, where you can add a description and other information +that will appear. Restart the service after updating files to make +changes live. diff --git a/content/gemini.md b/content/gemini.md new file mode 100644 index 0000000..dba5a1a --- /dev/null +++ b/content/gemini.md @@ -0,0 +1,189 @@ +--- +title: "Gemini" +date: 2021-07-01 +tags: ['server'] +short_desc: "A minimalist alternative to HTTP with a modern twist." +--- +## What is Gemini? {#whatis} + +[Gemini](https://gemini.circumlunar.space) is a new +internet protocol which is different from the HTTP and Gopher. It\'s +much cleaner and has a growing community and audience of hackers. + +### Why use gemini protocol? + +- Gemini capsules (webpages of gemini) are lightweight, minimal, and + don\'t use many resources to operate. +- It can run along with your websites. Gemini capsules use port 1965 + by default. Your webserver can run at port 80 or 443 along with + gemini server at port 1965. +- By exploring an alternative protocol, you can check different ways + to serve data and blogs. + +To access any gemini urls i.e. `gemini://example.org`, you can use any +gemini client such as +[amfora](https://github.com/makeworld-the-better-one/amfora), +[lagrange](https://gmi.skyjake.fi/lagrange), +[elpher](https://thelambdalab.xyz/elpher/), etc. + +## Instructions + +### Create a gemini user + +It is most secure and clean to have a separate `gemini` user, so let\'s +create one: + +```sh +useradd -m -s /bin/bash gemini +``` + +Now log in as `gemini` with the following command: + +```sh +su -l gemini +``` + +To create and serve a gemini capsule, we need three basic steps: + +1. Content -- the webpages in our capsule +2. TLS certificate -- Gemini requires encrypted connection. +3. Gemini server -- the program that makes our capsule available + (similar to Nginx for HTTP) + +As the gemini user, we can create three different directories to +simplify the process: + +```sh +mkdir -p ~/gemini/{content,certificate,server} +``` + +### Content + +This will be the directory where your capsule files will be contained. +Gemini uses text/gemini markup (in place of HTTP\'s equivalent HTML). It +heavily borrows from Markdown. Similar to .html or .md, gemini uses .gmi +as its extension. + +To create one gemini file, go inside the `content` directory and create +one `index.gmi` file. + +```sh +nano gemini/content/index.gmi +``` + +We can add the content we want in our Gemini capsule here: + +```yaml +# This is Sample Gemini page +## With header 1 and header 2 +And a short paragraph like this. +=> /index.gmi Link to the same page +``` + +### TLS certificate + +Go to the `certificate` directory which we created earlier and generate +a TLS certificate using OpenSSL. + +```sh +cd ~/gemini/certificate/ +openssl req -new -subj "/CN=example.org" -x509 -newkey ec -pkeyopt ec_paramgen_curve:prime256v1 -days 3650 -nodes -out cert.pem -keyout key.pem +``` + +### Gemini server + +#### Download and prepare the server + +There are [many gemini server software choices +available](https://gemini.circumlunar.space/software). We will use +`agate` server for now. This is a simple gemini server written in Rust. + +It\'s a good idea to always get the most recent version, which you can +see [on the agate releases +page](https://github.com/mbrubeck/agate/releases). At the time of this +writing, that is agate v3.1.0 which we will now download. We will +download it to the `server` directory we made. + +```sh +cd ~/gemini/server +wget https://github.com/mbrubeck/agate/releases/download/v3.1.0/agate.x86_64-unknown-linux-gnu.gz +``` + +Unzip the gz, then rename and make it executable: + +```sh +gunzip agate.x86_64-unknown-linux-gnu.gz +mv agate.x86_64-unknown-linux-gnu agate-server +chmod +x agate-server +``` + +#### Create a system service + +Now we need to create a systemd service to autostart and manage agate. +The gemini user does not have permission to do this, so press `ctrl-d` +to log out of the gemini user and return to root. As root, create the +file below by opening it in your text editor (nano, vim, etc.): + +```sh +nano /etc/systemd/system/agate.service +``` + +Add the following content to the file **customizing highlighted text** +to your use. + +```systemd +[Unit] +Description=agate +After=network.target + +[Service] +User=gemini +Type=simple +ExecStart=/home/gemini/gemini/server/agate-server --content /home/gemini/gemini/content --certs /home/gemini/gemini/certificate/ --hostname example.org --lang en-US + +[Install] +WantedBy=default.target +``` + +Now we are ready to run server. Enable and run agate server. + +```sh +systemctl enable agate +systemctl start agate +``` + +#### Firewall + +Lastly, if you have a firewall running, remember to open port 1965, +which is the port number used by gemini: + +```sh +ufw allow 1965 +``` + +## Finalization + +Now your server should be running. If everything went okay, you can +access your gemini capsule via any gemini client with a url like this: + +```txt +gemini://example.org +``` + +Sample gemini site for reference: + +```txt +gemini://gemini.circumlunar.space +``` + +Enjoy your first gemini capsule. + +For information about how to write in \"gemtext\" the markup language in +Gemini, see this site: +<https://gemini.circumlunar.space/docs/gemtext.gmi>. As you might guess, +it also has an analogous gemini capsule here: +gemini://gemini.circumlunar.space/docs/gemtext.gmi + +------------------------------------------------------------------------ + +*Written by [nihar.page](https://nihar.page)* diff --git a/content/git.md b/content/git.md new file mode 100644 index 0000000..f7cb6b5 --- /dev/null +++ b/content/git.md @@ -0,0 +1,143 @@ +--- +title: "Git Server" +date: 2020-07-01 +icon: 'git.svg' +tags: ['service'] +short_desc: "Hosting your own basic git server." +--- + +Once you have your own VPS or other Internet-available server, you can +start hosting your own git repositories. The goal of this tutorial is +for you to go from + +```sh +git clone github.com/... +``` + +to + +```sh +git clone YourLandChadDomainName.xyz/... +``` + +so you can cultivate your own homegrown, grass-fed code, rather than +relying on a centralized proprietary service like GitHub. + +## Installing git + +You most likely already have it installed on your server, but if not, +run: + +```sh +apt install git +``` + +We don\'t need any additional software, `git` itself ships with +everything needed to host a remote repository! + +## Creating bare repositories + +For each repository you want to host, you will need to manually create +what\'s called a \"bare\" repository on your server. These hold all the +commits and any other git data needed for your repository, but without +an expanded \"index\" in which you can just browse all the files of a +certain commit in the file system. + +These repositories need to be owned by the `git` user, and you should +probably pick a directory where you will store them all. One sane choice +is under `/srv/git/`, and we will use this as the example directory for +the rest of the tutorial, but any other path will do as well. + +### Become the git user and create the directory + +If you\'re logged in to your server as root and have `git` installed, +you can become the `git` user by executing + +```sh +su git +``` + +Now navigate to/create your desired directory, for example + +```sh +cd /srv +mkdir git +``` + +### Create the repo + +Now you can create the bare repository with + +```sh +git init --bare my-repo.git +``` + +By convention, bare repository names end with \".git\". + +Repeat the above command for any other repositories you want to host. + +## Syncing local repositories with your server + +### Set up SSH login for the git user + +You will need to be able to login remotely via `ssh` as the `git` user +we\'ve used before. To do this, you will either need to set up a +password for the `git` user by running `passwd git`, or copy your public +SSH key from your local machine to `/home/git/.ssh/authorized_keys`. See +the [SSH keys instructional](/sshkeys) for details (just log in as +`git` instead of `root`). + +### Syncing a new repository with your server + +If you\'ve just created a new repository on your local machine, you will +need to tell `git` where the remote repository is to be able to sync +with it (using commands like `git push` or `git pull`). We do this by +defining a \"remote\" for your repository. + +A remote is just a named URL remembered in your repo\'s configuration. +So we need a name and a URL. By convention, the \"main\" remote is +called \"origin\". The URL has the format `user@host:path`, where: + +- `user` is `git`, the `git` user we\'ve already worked with before. +- `host` is your domain name. Alternatively you could even use your + server\'s raw IP address. +- `path` is the absolute path to the repository on the server, in our + example `/srv/git/my-repo.git` + +So, to create a new remote, run: + +```sh +git remote add origin git@yourdomain.xyz:/srv/git/my-repo.git +``` + +Now you\'ll be able to run `git push origin master` to push your commits +or `git pull origin` to pull from the remote. + +### Syncing an existing repository + +If you\'ve already set up your local repository to sync with a service +like GitHub it probably already has a remote called \"origin\". You can +see your repo\'s remotes with: + +```sh +git remote -v +``` + +You can follow the above instructions, substituting an arbitrary other +name other than \"origin\" to create a differently named remote, e.g. + +```sh +git remote add vps git@... +``` + +Now you\'ll be able to push/pull with `git push vps master` and +`git pull vps`, respectively. + +Or, to completely sever ties with your centralized git provider, first +remove the original origin with: `git remote remove origin` and then +follow the instructions as above. + +## Contribution + +- Martin Chrzanowski \-- [website](https://m-chrzan.xyz), + [donate](https://m-chrzan.xyz/donate.html) diff --git a/content/gitea.md b/content/gitea.md new file mode 100644 index 0000000..16a722e --- /dev/null +++ b/content/gitea.md @@ -0,0 +1,159 @@ +--- +title: "Gitea" +date: 2020-07-02 +icon: 'gitea.svg' +tags: ['service'] +short_desc: "A fully-featured Github-like git website for serious software projects and communities." +--- + + +Gitea allows you to self-host your git repositories similar to [bare repositories](/git), but comes with additional features that you +might know from GitHub, such as issues, pull requests or multiple users. +Its advantage over GitLab---another Free Software GitHub clone---is that +it is much more lightweight and easier to setup. + +Head over to [gitea.com](https://gitea.com) to see what it looks like in +practice. + +Although Gitea is lighter than Gitlab, if you have a VPS with only 512MB +of RAM, you will probably have to upgrade. Gitea is more +memory-intensive than having just a bare git repository. + +## Installing Gitea + +First install a few dependencies: + +```sh +apt install curl sqlite3 +``` + +Unfortunately, Gitea itself is not in the official Debian repos, so we +will add a third-party repository for it. + +Add the repo\'s gpg key to apt\'s trusted keys: + +```sh +curl -sL -o /etc/apt/trusted.gpg.d/morph027-gitea.asc https://packaging.gitlab.io/gitea/gpg.key +``` + +Then add the actual repository to apt: + +```sh +echo "deb [arch=amd64] https://packaging.gitlab.io/gitea gitea main" > /etc/apt/sources.list.d/morph027-gitea.list +``` + +Now we can install Gitea: + +```sh +apt update +apt install gitea +``` + +Since apt automatically enables and starts the Gitea service, it should +already be running on port `3000` on your server! + +## Setting up a Nginx reverse proxy + +You should know how to generate SSL certificates and use Nginx by now. +Add this to your Nginx config to proxy requests made to your git +subdomain to Gitea running on port 3000: + +```nginx +server { + listen 443 ssl; + listen [::]:443 ssl; + ssl_certificate /etc/ssl/nginx/git.example.org.crt; + ssl_certificate_key /etc/ssl/nginx/git.example.org.key; + server_name git.example.org; + location / { + proxy_pass http://localhost:3000/; # The / is important! + proxy_redirect off; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + } +} +``` + + +And reload Nginx: + +```sh +systemctl reload nginx +``` + +## Setting up Gitea + +If everything worked fine you should now see a setup screen when you go +to your configured domain in the browser. The options should be pretty +self-explanatory, it is only important to select SQLite3 and to replace +the base url and SSH server domain with your own. + +Database Type: +: SQLite3 + +SSH Server Domain: +: **git.example.org** + +Gitea Base URL: +: **git.example.org** + +These and other settings can be changed in a configuration file later so +don\'t worry about making wrong decisions right now. + +After clicking the install button you should now be able to log into +your Gitea instance with the account you just created! Explore the +settings for more things to do, such as setting up your SSH keys. + +If Gitea does not load fully and has random errors, it is possible that +you need to increase your available memory on your VPS. This can usually +be done on your VPS-provider\'s website without too much trouble. + +## A few extras + +### Automatically create a new repo on push + +This is an incredibly useful feature for me. Open up +`/etc/gitea/app.ini` and add `DEFAULT_PUSH_CREATE_PRIVATE = true` to the +`repository` section like so: + +```systemd +[repository] +ROOT = /var/lib/gitea/data/gitea-repositories +DEFAULT_PUSH_CREATE_PRIVATE = true +``` + +If you now add a remote to a repository like this + +```sh +git remote add origin 'ssh://gitea@git.example.org/username/coolproject.git' +``` + +and push, Gitea will automatically create a private `coolproject` +repository in your account! + +### Change tab-width + +By default Gitea displays tabs 8 spaces wide, however I prefer 4 spaces. +We can change this! + +```sh +mkdir -p /var/lib/gitea/custom/templates/custom/ +``` + +And write this into +`/var/lib/gitea/custom/templates/custom/header.tmpl`: + +```css +<style> +.tab-size-8 { +tab-size: 4 !important; +-moz-tab-size: 4 !important; +} +</style> +``` + +## Contribution + +- [phire](https://phire.cc) diff --git a/content/html.md b/content/html.md new file mode 100644 index 0000000..3da7c53 --- /dev/null +++ b/content/html.md @@ -0,0 +1,143 @@ +--- +title: "Make a Simple Webpage" +draft: true +--- +We now have a webpage that\'s actually on the real-live internet! +You\'ve already made it! Now the only issue is putting what you want on +your website. + +In this little series, we\'ll overview the basics of HTML and CSS, the +two important languages that will allow you to make a stylish multi-page +website. We will start with HTML. + +## HTML + +HTML is the **h**yper**t**ext **m**arkup **l**anguage. It is the +\"language\" that all webpages are written in so that all browsers can +read and display them properly. + +A <dfn>markup language</dfn> is *not* the same as a programming language: +Programming languages specify orders for a computer, while markup +languages are ways of specifying the styling of text. Markup languages +are necessary because computers run on mere text, not colors, sizes, +headers and other styling things. + +Let\'s understand what HTML is. In [a previous article](/basic/nginx), we +put this text in your website\'s `index.html`. + +### Paragraphs + +Note how this HTML file appears as a webpage: + ++-----------------------------------+-----------------------------------+ +| <!DOCTYPE html> |  | +| <p>This is my web | | +| site. Thanks for stopping by!</p> | | +| | | +| <p>Now my website is live!</p> | | ++-----------------------------------+-----------------------------------+ + +The content between the `<p>` and `</p>` tag(s) is formatted as +different paragraphs. If you don\'t use these `<p>` tags, the text will +not be formatted as separate paragraphs even if you write it as multiple +lines. Observe if we add lines to the end of this file: + ++-----------------------------------+-----------------------------------+ +| <!DOCTYPE html> |  | +| <h1>My website!</h1> | | +| <p>This is my web | | +| site. Thanks for stopping by!</p> | | +| | | +| <p>Now my website is live!</p> | | +| Here is some more text. | | +| There are | | +| no paragraph tags on this stuff. | | +| So it | | +| will all appear as one paragraph. | | +| | | +| Despite being on multiple lines. | | +| | | +| | | +| Even this! | | ++-----------------------------------+-----------------------------------+ + +This will seem strange at first, but this is the use of HTML as a markup +language: it allows you to style your document with tags and write it in +whatever way is convenient. + +Let\'s learn more about what HTML can do. + +### Headings + +In addition to paragraphs (`<p>`), we can specify headings with inside +`<h1></h1>` tags. Heading tags are for your page\'s title and section +headings in the document: + +- `<h1></h1>` -- Main and largest headings +- `<h2></h2>` -- Subheadings (smaller) +- `<h3></h3>` -- Sub-subheadings (yet smaller) +- `<h4></h4>` -- Etc., etc. + ++-----------------------------------+-----------------------------------+ +| <h1> |  | +| | | +| <p | | +| >Here is some paragraph text.</p> | | +| | | +| | | +| <p>And here is some more...</p> | | +| | | +| < | | +| h2>This is a subheading (h2)</h2> | | +| | | +| <p>And another paragraph.</p> | | +| | | +| <h2>And here is ano | | +| ther subheading (Also an h2)</h2> | | +| | | +| <p>Etc. etc...</p> | | ++-----------------------------------+-----------------------------------+ + +#### A preview to CSS + +It is very important to use headings like this for your pages. Notice +that on this website, headings come in different colors, text-alignment +and sizes for emphasis. If we use these heading tags, when we clear CSS, +we can easily style all `<h2>`, for example, to be the size and color +and alignment we want. + +## Text formatting + +HTML can also be used to do text formatting. We can make bold, italic, +underlined or struck through text with more HTML tags: + ++-----------------------------------+-----------------------------------+ +| |  | +| | | +| < | | +| p>This is <i>italic text</i>.</p> | | +| | | +| | | +| <p>This is <u>underlined</u>.</p> | | +| | | +| <p>T | | +| his is <s>struck through</s>.</p> | | ++-----------------------------------+-----------------------------------+ + +## Semantic Tags + +While `<b></b>` and `<i></i>` do exist, it\'s actually better *not* to +use them directly in text. + +Try using `<strong></strong>` instead of `<b></b>` and `<em></em>` +instead of `<i></i>`. By default, they will look exactly the same. You +complain that they require more key presses, but it\'s thought to be a +very bad idea to modify lower-level tags with CSS directly. + +Note that some bold words on this site have **different color for +emphasis**. This is a setting set via CSS for all `<strong>` tags. It +would not be a good idea for us to use this for `<b>`, since there might +be a non-colored situation we want to occasionally use it in. diff --git a/content/html2.md b/content/html2.md new file mode 100644 index 0000000..9865e88 --- /dev/null +++ b/content/html2.md @@ -0,0 +1,7 @@ +--- +title: "Images and Links in HTML" +draft: true +--- +## Links + +We need to create links diff --git a/content/html4.md b/content/html4.md new file mode 100644 index 0000000..adb8eb3 --- /dev/null +++ b/content/html4.md @@ -0,0 +1,32 @@ +--- +title: "Doing HTML Right" +draft: true +--- +We\'ve noted that HTML is very forgiving + +## A look at a decent template + +I have a template file that I use for this website that includes all the +basics. When I make a new page, I just copy the template and add the +content. Here is what the template looks like: + +`` + + <!DOCTYPE html> + <html lang=en> + <head> + <title>Your page title</title> + <meta charset="utf-8"/> + <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> + <link rel='stylesheet' type='text/css' href='style.css'> + <meta name="viewport" content="width=device-width, initial-scale=1"> + <link rel='alternate' type='application/rss+xml' title='Site Title RSS' href='/rss.xml'> + </head> + <body> + <header><h1>Your page title</h1></header> + + <nav></nav> + + <main> + + Put all your page content here in the <main> tag. diff --git a/content/i2p.md b/content/i2p.md new file mode 100644 index 0000000..fec9d8c --- /dev/null +++ b/content/i2p.md @@ -0,0 +1,101 @@ +--- +title: "i2p" +date: 2021-07-01 +img: 'i2p.svg' +icon: 'itoopie.svg' +tags: ['service'] +short_desc: "A private and uncensorable web-layer similar to Tor." +--- + +Now you have a website, why not offer it in a private alternative such +as the Invisible Internet? + +## Setting up I2P + +There are 2 main I2P implementations, I2P and i2pd, we are using i2pd in +this guide because it\'s easier to use in servers. + +### Installing I2P + +i2pd is in most repos, in debian/ubuntu you can install it simply with + +```sh +apt install i2pd +``` + +### Enabling I2P + +We are going to create a user for i2pd, because i2pd finds the +configuration files in its home directory. And it\'s easier (and more +tidy) to have it in a separate user: + +```sh +useradd -m i2p -s /bin/bash +su -l i2p +mkdir ~/.i2pd +cd ~/.i2pd +``` + +Now that you\'re in \~/.i2pd, you have to create a file named +\"tunnels.conf\". Which is the config file for every hidden service +you\'re offering over I2P, the content should be like this: + +```systemd +[example] +type = http +host = 127.0.0.1 +port = 8080 +keys = example.dat +``` + +### Getting your I2P Hostname + +Then, run `/usr/sbin/i2pd --daemon` to start i2pd and we can retreive +our I2P hostname. + +This can be done in lynx or a command-line browser by going to +`http://127.0.0.1:7070/?page=i2p_tunnels` to get your I2P hostname. + +You can also run these commands to find your hostname: + +```sh +printf "%s.b32.i2p +" $(head -c 391 /home/i2p/.i2pd/example.dat |sha256sum|xxd -r -p | base32 |sed s/=//g | tr A-Z a-z) +``` + +## Adding the Nginx Config + +From here, the steps are almost identical to setting up a normal website +configuration file. Follow the steps as if you were making a new website +on the webserver [tutorial](/basic/nginx) up until the server block of +code. Instead, paste this: + +```nginx +server { + listen 127.0.0.1:8080 ; + root /var/www/example ; + index index.html ; +} +``` + +#### Clarifications + +#### + +Nginx will listen in port 8080, but i2pd will forward your port 8080 to +the i2p site port 80. This way you don\'t have to deal with server names +or anything like that + +From here we are almost done, all we have to do is enable the site and +reload nginx which is also covered in [the webserver +tutorial](nginx.html#enable). + +### Update regularly! + +Make sure to update I2P on a regular basis by running: + +```sh +apt update && apt install i2pd +``` + +**Contributor** - [qorg11](https://qorg11.net) diff --git a/content/imgcompress.md b/content/imgcompress.md new file mode 100644 index 0000000..49dab19 --- /dev/null +++ b/content/imgcompress.md @@ -0,0 +1,51 @@ +--- +title: "Image compression" +date: 2021-07-17 +--- +Image files will usually have the most impact on the speed of your +websites (aside from Ad/tracker scripts). Learn to slim down your images +using the ubiquitous *ImageMagick* to make your websites faster on slow +internet connections. + +{{< img alt="Image network speed" src="/pix/imgcompress-network.png" link="/pix/imgcompress-network.png" >}} + +For the examples, I decided to use +[this](https://commons.wikimedia.org/wiki/File:Tabby_cat_with_blue_eyes-3336579.jpg) +public domain image. + +{{< img alt="Compressed image of a cat" src="/pix/imgcompress-cat.png" link="/pix/imgcompress-cat.png" >}} + +There are many ways to decrease image size using ImageMagick, the +simplest is to use the `-quality` option, which will compress the image +without changing the resolution. This option takes the value you want to +compress by (between 1 and 100, the lower the value, the lower the file +size). For example: + + convert in.jpg -quality 50 out.jpg + +Compressing the example image above results in the following file size +changes: + +``` + Quality Size + ---------- ------ + Original 2.1M + 90 1.7M + 80 844K + 70 588K + 60 448K + 50 368K + 40 308K + 30 248K + 20 184K + 10 116K +``` + +Due to the images high resolution, it is usable in this website even +when highly compressed (30% quality, still looks decent in my opinion). + +## Contribution + +- [Musse](https://na20a.neocities.org/) +- Monero: + `83is3y69Xv4fkFsTpZhw5c3bfxtimupfgTdpERHM1WtMNAwSqFjTCJm3VabyBKXKnL873dWPmqj4bRcgkm9oCktgQrzmhHd`{.crypto} diff --git a/content/irc.md b/content/irc.md new file mode 100644 index 0000000..f61abca --- /dev/null +++ b/content/irc.md @@ -0,0 +1,946 @@ +--- +title: "IRC" +date: 2020-07-03 +icon: 'irc.svg' +tags: ['service'] +short_desc: "Self-hosting the Internet's classic chat protocol." +--- + +Creating your own chat server for you and your friends is easy, and you +don\'t have to rely on a complicated system to get started. IRC is an +old but gold protocol, and has clients for basically every operating +system made since the 80s, with many powerful modern ones on Linux, Mac, +and Windows. + +Having a chat server for you and your friends makes it impossible for a +group of arbitrarily appointed moderators to deplatform you for +wrong-think, and gives you greater freedom of communication. + +## Installing an IRCd {#installing} + +An IRCd is short for \"IRC daemon\", which just means an IRC server. The +most easy IRCd to set up is [Ergo](https://ergo.chat/). + +The first thing you need to do is create a new user for the server to be +run by. This is good practice for installing software/servers manually, +as it give you more fine-grained control over which permissions the +application has. + +```sh +useradd -m ergo -s /bin/bash +``` + +Next, we want to switch to our newly created `ergo` user and create the +server directory. + +```sh +sudo -i -u ergo +mkdir server +``` + +You can find the latest release of Ergo on its GitHub [latest +release](https://github.com/ergochat/ergo/releases/latest) page.\ +There are several platforms available, but you want to choose Linux, +most likely `linux-x86_64`.\ +Once you have selected the correct package, copy its URL and replace the +release url with the package URL (still as the `ergo` user): + +```sh +wget "https://github.com/ergochat/ergo/releases/download/v2.7.0/ergo-2.7.0-linux-x86_64.tar.gz" +tar -xf ergo-2.7.0-linux-x86_64.tar.gz +mv ergo-2.7.0-linux-x86_64/* +rm -r ergo-2.7.0-linux-x86_64* +``` + +Executing `ls -l` should now yield something like this: + +```sh +-rw-r--r-- 1 ergo ergo 118825 Jun 8 00:51 CHANGELOG.md +-rw-r--r-- 1 ergo ergo 1983 May 31 01:48 README +-rw-r--r-- 1 ergo ergo 41440 Jun 8 00:42 default.yaml +drwxr-xr-x 2 ergo ergo 4096 Jul 1 09:01 docs +-rwxr-xr-x 1 ergo ergo 9654272 Jun 8 00:53 ergo +-rw-r--r-- 1 ergo ergo 1753 May 31 01:48 ergo.motd +drwxr-xr-x 2 ergo ergo 12288 Jul 1 09:01 languages +-rw-r--r-- 1 ergo ergo 39722 Jun 8 00:42 traditional.yaml +``` + +If you see something similar to the above, that means Ergo is installed, +although not quite ready to run yet. + +## Configuring Ergo {#configuring} + +Now that Ergo is installed, you want to configure it to fit the needs of +your group.\ +The configuration in this section is tailored towards a small group of +people, and less for a possibly large network, but it should work for +any size of group. + +First thing, make sure you\'re still using the `ergo` user, and are in +the `~/server` directory.\ +If you aren\'t, you can run the following to get back there: + +```sh +sudo -i -u ergo +cd ~/server +``` + +To start configuring, we need to copy some files: + +```sh +cp default.yaml ircd.yaml +cp ergo.motd ircd.motd +``` + +Next, generate certificate files for TLS: + +```sh +./ergo mkcerts +``` + +Ergo comes with a default configuration file with detailed documentation +that can be used to guide you through the configuration process. This +guide will help you setup the server for a typical use-case, but if you +see any settings that you would like to change along the way, go ahead +and change them, as long as you know what you\'re doing. + +The next steps involve editing the newly copied `ircd.yaml` file. If you +do not know how to edit text files from the command line, you can use +`nano`, which is very simple, using arrow keys to navigate, `CTRL+O` to +save, and `CTRL+X` to exit.\ +Another option is `vim`, which is a much more powerful text editor, but +has a learning curve. It is only recommended for this guide if you +already know how to use it.\ +Lastly, you can copy the `ircd.yaml` file to a text editor on your +computer and edit it with a GUI text editor of your choice. If that is +what you choose to do, you may want to just download the file from +[Ergo\'s +GitHub](https://raw.githubusercontent.com/ergochat/ergo/master/default.yaml), +edit it on your computer, clear the `ircd.yaml` file on the server, and +then paste the contents from your computer into the blank file.\ +No matter how you do it, the next steps assume you can edit the +configuration file. + +**Note**:\ +The options highlighted in this section are not a complete overview of +all options. Instead, the options shown are the ones which are most +relevant to a small network.\ +You should read over the configuration file yourself if you are curious +about everything you can change. + +### Network and server names {#configuring-names} + +One of the first properties in the config file is network name. You can +change this to whatever you like, as it will show up as the name when +you connect to the server. + +```yaml +# network configuration +network: + # name of the network + name: "Land-Chat" +``` + +Change the server name to your server\'s domain name. + +```yaml +# server configuration +server: + # server name + name: "example.org" +``` + +### Network password {#configuring-password} + +The next step is optional, depending on if you want your network +password protected or not. The benefit of password protection is fairly +obvious; nobody can connect to your network unless you gave them the +password. If you\'re wanting to run a public network which anyone can +join and create a channel, you want to skip this, but for personal +setups, it is highly recommended. + +Generate a password to use by executing the following: + +```sh +./ergo genpasswd +``` + +It will ask you to enter a password and confirm it, then you will be +given a hashed password.\ +Copy this password, and paste it into the following field (also removing +the `#` before the `password:` line): + +```yaml +# password to login to the server, generated using `ergo genpasswd`: +password: "<your hashed password>" +``` + +### Message of the day (MotD) {#configuring-motd} + +Change the MotD (**M**essage **o**f **t**he **D**ay) file to the one you +copied earlier: + +```yaml +# motd filename +# if you change the motd, you should move it to ircd.motd +motd: ircd.motd +``` + +Feel free to edit `ircd.motd` to your heart\'s content. Its contents +will be sent to clients when they connect to the network. + +### IP limits {#configuring-ip-limits} + +For security purposes, you might want to limit the amount of client +connections per IP. For a private network, 4 is likely the maximum +amount of connections you will have per IP, so that is a safe value.\ +If your network is password protected, this is less of an issue, since +the only people connecting will be people who have the password. The +following is the default, but you can change it to be whichever value +you like: + +```yaml +# IP-based DoS protection +ip-limits: + # whether to limit the total number of concurrent connections per IP/CIDR + count: true + # maximum concurrent connections per IP/CIDR + max-concurrent-connections: 16 +``` + +### IP cloaking {#configuring-ip-cloaking} + +Traditionally, IRC networks expose users\' IP addresses to everyone. +This is not a good practice for privacy, however. With Ergo, IP cloaking +is enable by default. You can enable or disable it if you like, and +change how it looks to users.\ +In this case, `netname` was changed to `"chad"`. + +```yaml +# IP cloaking hides users' IP addresses from other users and from channel admins +# (but not from server admins), while still allowing channel admins to ban +# offending IP addresses or networks. In place of hostnames derived from reverse +# DNS, users see fake domain names like pwbs2ui4377257x8.irc. These names are +# generated deterministically from the underlying IP address, but if the underlying +# IP is not already known, it is infeasible to recover it from the cloaked name. +# If you disable this, you should probably enable lookup-hostnames in its place. +ip-cloaking: + # whether to enable IP cloaking + enabled: true + + # whether to use these cloak settings (specifically, `netname` and `num-bits`) + # to produce unique hostnames for always-on clients. you can enable this even if + # you disabled IP cloaking for normal clients above. if this is disabled, + # always-on clients will all have an identical hostname (the server name). + enabled-for-always-on: true + + # fake TLD at the end of the hostname, e.g., pwbs2ui4377257x8.irc + # you may want to use your network name here + netname: "chad" +``` + +### Password enforcement adjustments for HexChat (and possibly other clients) {#configuring-hexchat-password} + +Ergo offers account registration to allow users to do things like use +history and bouncer features, register channels, etc.\ +In clients such as HexChat, server passwords may conflict with account +passwords, so the following setting should be enabled if you wish to use +accounts with clients such as HexChat.\ +Note that this could under some circumstances be considered a security +hazard, as a user with an account does not need to know the server +password to connect, although that user would have needed to register an +account before the server had a password, and then a password would need +to have been set after the fact, so this can be considered a very small +concern if your setup has always had a password.\ +Also keep in mind that this setting has no effect if your network does +not even have a password at all. + +```yaml +# some clients (notably Pidgin and Hexchat) offer only a single password field, +# which makes it impossible to specify a separate server password (for the PASS +# command) and SASL password. if this option is set to true, a client that +# successfully authenticates with SASL will not be required to send +# PASS as well, so it can be configured to authenticate with SASL only. +skip-server-password: true +``` + +### Multiclient, always-on clients, history, etc {#configuring-multiclient} + +Traditionally, IRC servers have no message history, and once you close +your client, you cannot receive messages, and are not shown to be online +at all. Ergo includes functionality to allow users to both receive +history, and keep their clients \"online\" even after they have left. It +also allows multiple clients to connect to the same account.\ +If you are running a private network for friends, you should set +`always-on` and `auto-away` to `opt-out`, to have all users with +accounts to appear as if they are online at all times, and be able to +receive messages when they are offline.\ +For a public network, keep everything as their default values, since you +probably do not want randoms having this by default.\ +If for some reason you do not want any of these features at all, you can +set `enabled` to `false`, but this is not recommended. Below are the +recommended values for a private network (e.g. for friends) where users +with accounts will be able to receive messages and history while they +are offline. + +```yaml +# multiclient controls whether Ergo allows multiple connections to +# attach to the same client/nickname identity; this is part of the +# functionality traditionally provided by a bouncer like ZNC +multiclient: + # when disabled, each connection must use a separate nickname (as is the + # typical behavior of IRC servers). when enabled, a new connection that + # has authenticated with SASL can associate itself with an existing + # client + enabled: true + + # if this is disabled, clients have to opt in to bouncer functionality + # using nickserv or the cap system. if it's enabled, they can opt out + # via nickserv + allowed-by-default: true + + # whether to allow clients that remain on the server even + # when they have no active connections. The possible values are: + # "disabled", "opt-in", "opt-out", or "mandatory". + always-on: "opt-out" + + # whether to mark always-on clients away when they have no active connections: + auto-away: "opt-out" + + # QUIT always-on clients from the server if they go this long without connecting + # (use 0 or omit for no expiration): + #always-on-expiration: 90d +``` + +### VHosts {#configuring-vhosts} + +IP cloaking was mentioned previously, and somewhat related to that, Ergo +includes \"vhost\" functionality, which allows users to set a custom +IP/host string. This is mostly for cosmetic value, and does not +interfere with operators being able to see actual IP addresses for +banning, but if you do not want it enable for some reason, you can +disable it. + +```yaml +# vhosts controls the assignment of vhosts (strings displayed in place of the user's +# hostname/IP) by the HostServ service +vhosts: + # are vhosts enabled at all? + enabled: true +``` + +### Channels {#configuring-channels} + +Channels are where everyone on an IRC network talk. By default, anyone +can create a channel, and anyone with an account can register one. The +difference between a normal channel and a registered one is that the +registered one will preserve the operator status of the person who +created, whereas a normal channel\'s owner will lose operator status if +they leave the channel or disconnect from the network.\ +There are various settings for channels available, but the defaults are +suitable for a private network with trust among users, or where you just +want anyone to have the ability to create a channel. Below are the +default values: + +```yaml +# channel options +channels: + # modes that are set when new channels are created + # +n is no-external-messages and +t is op-only-topic + # see /QUOTE HELP cmodes for more channel modes + default-modes: +nt + + # how many channels can a client be in at once? + max-channels-per-client: 100 + + # if this is true, new channels can only be created by operators with the + # `chanreg` operator capability + operator-only-creation: false + + # channel registration - requires an account + registration: + # can users register new channels? + enabled: true + + # restrict new channel registrations to operators only? + # (operators can then transfer channels to regular users using /CS TRANSFER) + operator-only: false + + # how many channels can each account register? + max-channels-per-account: 15 +``` + +### Operators (administrators, etc) {#configuring-operators} + +The IRC term for an administrator or another privileged user is +\"operator\", or \"oper\" for short.\ +Ergo\'s opers have different permissions that can be granted to them, +and are defined in \"classes\", basically groups of permissions under a +name. For example, \"chat-moderator\" and \"server-admin\" are defined +in the default configuration: + +```yaml +# operator classes +oper-classes: + # chat moderator: can ban/unban users from the server, join channels, + # fix mode issues and sort out vhosts. + "chat-moderator": + # title shown in WHOIS + title: Chat Moderator + + # capability names + capabilities: + - "kill" + - "ban" + - "nofakelag" + - "roleplay" + - "relaymsg" + - "vhosts" + - "sajoin" + - "samode" + - "snomasks" + + # server admin: has full control of the ircd, including nickname and + # channel registrations + "server-admin": + # title shown in WHOIS + title: Server Admin + + # oper class this extends from + extends: "chat-moderator" + + # capability names + capabilities: + - "rehash" + - "accreg" + - "chanreg" + - "history" + - "defcon" + - "massmessage" +``` + +The above can be kept with their default values, but you are free to +modify them or create any new classes that are appropriate for your +setup.\ +Next, let\'s actually create an operator account: + +```yaml +# ircd operators +opers: + # default operator named 'gigachad'; log in with /OPER gigachad <password> + "gigachad": + # which capabilities this oper has access to + class: "server-admin" + + # custom whois line + whois-line: is the server administrator + + # custom hostname + vhost: "gigachad" + + # normally, operator status is visible to unprivileged users in WHO and WHOIS + # responses. this can be disabled with 'hidden'. ('hidden' also causes the + # 'vhost' line above to be ignored.) + hidden: false + + # modes are modes to auto-set upon opering-up. uncomment this to automatically + # enable snomasks ("server notification masks" that alert you to server events; + # see `/quote help snomasks` while opered-up for more information): + #modes: +is acjknoqtuxv + + # operators can be authenticated either by password (with the /OPER command), + # or by certificate fingerprint, or both. if a password hash is set, then a + # password is required to oper up (e.g., /OPER dan mypassword). to generate + # the hash, use `ergo genpasswd`. + password: "<your oper password>" +``` + +This is a modified version of the default oper entry. The account name +is \"gigachad\", but you can change it to anything.\ +Replace `<your oper password>` with a password generated by +`./ergo genpasswd`, and you will have a new oper account to use.\ +Note that to log into an oper account, clients have to enter +`/OPER <oper name> <oper password>` each time they log in. This can be +automated by most clients by setting the command to be executed when the +client logs in. In the case of HexChat, you can edit your network and +add the command to the `Connect commands` tab of the menu.\ +You can copy everything from `"gigachad"` to the end of the line, paste +it again, and change the name to create another oper account. Another, +less privileged example of an oper is shown as a comment below the above +configuration snippet. + +### Chat history {#configuring-history} + +Traditionally, IRC networks do not store, relay, or handle chat history +in any way.\ +On a privacy standpoint, this is a good thing, since chats are entirely +ephemeral and handled by clients.\ +On a practicality standpoint, this is a bad thing, since people have to +keep a client connected 24/7 to see message history.\ +For normalfriends, this can be a big problem, not only because having to +stay online 24/7 is just annoying or infeasible, but also because they +are likely used to chat platforms that handle history for them.\ +With this in mind, enabling history is a good idea if you want to move +friends over to IRC, and will make things a lot more pleasant for +private networks. + +Ergo\'s `history` configuration group is very long, so it is encouraged +to read over it yourself. This section will go over the most important +pieces of that configuration group. + +History is not endless (unless you want it to be), and the amount that +can be stored for channels is configurable: + +```yaml +# how many channel-specific events (messages, joins, parts) should be tracked per channel? +channel-length: 2048 +``` + +History is already enabled by default, but that just means it is being +collected, not relayed by default. To relay history to clients when they +connect, change the following to the amount of messages that you think +is appropriate: + +```yaml +# number of messages to automatically play back on channel join (0 to disable): +autoreplay-on-join: 250 +``` + +History older than a certain time can be configured to be deleted or be +inaccessible. The default cutoff time is 1 week, but this is +configurable as well. + +```yaml +# options to delete old messages, or prevent them from being retrieved +restrictions: + # if this is set, messages older than this cannot be retrieved by anyone + # (and will eventually be deleted from persistent storage, if that's enabled) + expire-time: 1w +``` + +By default, Ergo only stores chat history in memory, so when the server +restarts, all history is lost. If you wish to have chat history persist +beyond restarts, you must store it in a MySQL database: + +```yaml +# options to store history messages in a persistent database (currently only MySQL). +# in order to enable any of this functionality, you must configure a MySQL server +# in the `datastore.mysql` section. +persistent: + enabled: true + + # store unregistered channel messages in the persistent database? + unregistered-channels: true + +# connection information for MySQL (currently only used for persistent history): +mysql: + enabled: false + host: "localhost" + port: 3306 + # if socket-path is set, it will be used instead of host:port + #socket-path: "/var/run/mysqld/mysqld.sock" + user: "ergo" + password: "hunter2" + history-database: "ergo_history" + timeout: 3s + max-conns: 4 + # this may be necessary to prevent middleware from closing your connections: + #conn-max-lifetime: 180s +``` + +For privacy reasons, you may want to allow users to delete their own +messages in history, or export their messages to JSON: + +```yaml +# options to control how messages are stored and deleted: +retention: + # allow users to delete their own messages from history? + allow-individual-delete: true + + # if persistent history is enabled, create additional index tables, + # allowing deletion of JSON export of an account's messages. this + # may be needed for compliance with data privacy regulations. + enable-account-indexing: true +``` + +### Spam reduction {#configuring-spam} + +Most IRC networks have measures in place to reduce chat spam. By +default, \"fakelag\" is enabled in Ergo, and that can deal with most +aggregious chat spam.\ +If you are running a private network where user trust is high, you can +disable it so that there are no limits on the speed that messages can be +sent. + +```yaml +# fakelag: prevents clients from spamming commands too rapidly +fakelag: + # whether to enforce fakelag + enabled: true + + # time unit for counting command rates + window: 1s + + # clients can send this many commands without fakelag being imposed + burst-limit: 5 + + # once clients have exceeded their burst allowance, they can send only + # this many commands per `window`: + messages-per-window: 2 + + # client status resets to the default state if they go this long without + # sending any commands: + cooldown: 2s +``` + +## Starting and using your server + +Now that Ergo is both installed and configured, you can actually start +using it! + +### Starting the server {#using-starting} + +First thing, make sure you\'re still using the `ergo` user, and are in +the `~/server` directory.\ +If you aren\'t, you can run the following to get back there: + +```sh +sudo -i -u ergo +cd server +``` + +Starting the server is done in one command: + +```sh +./ergo run +``` + +It will stay online until you close the terminal, or press CTRL+C. +Don\'t worry, the next section goes over how to make it run like a +normal server with a SystemD service.\ +If you have not already, make sure the port `6697` is not blocked on +your server. If you are using UFW as your firewall, you need to run +`ufw enable 6697` (not as the `ergo` user, of course).\ +If you make and configuration changes while the server is running, you +can apply them without restarting by typing `/rehash` as an operator. + +### Connecting to the server {#using-connecting} + +To use IRC, you of course need an IRC client. There are many choices +available, but the most widely used for Windows and Linux is +[HexChat](https://hexchat.github.io/). On Mac, you have a slightly nicer +option with [Textual](https://www.codeux.com/textual/), although you +have to [compile it from +source](https://github.com/Codeux-Software/Textual/#building-textual) if +you want to use it for free.\ +A more user-friendly and modern client choice is TheLounge, which is +explained in the last section of this guide, if you want to look into +it. + +Connecting with HexChat is very easy. When you start it, you will see +something like this: + +{{< img alt="HexChat network select" src="/pix/irc/hexchat-network-select.png" link="/pix/irc/hexchat-network-select.png" >}} + +From there, you should click `+ Add` and name the server whatever you +like (so you can find it on the server list).\ +Once you have created a new server and named it, select it and click +`Edit...`. A menu will show up like the one below. Change the domain to +whatever domain your server is running on, and make sure to put in your +server password if you set one. + +{{< img alt="HexChat network edit menu" src="/pix/irc/hexchat-network-edit.png" link="/pix/irc/hexchat-network-edit.png" >}} + +Once you\'re done editing the network, click `(X) Close`, select your +network from the network list, and click `Connect`.\ +If all is well, you should be connected! + +{{< img alt="HexChat connection complete" src="/pix/irc/hexchat-connection-complete.png" link="/pix/irc/hexchat-connection-complete.png" >}} + +The process is very similar on Textual.\ +Create a new network and connect to it. Note that it will ask if you +want to connect even though the certificate is unsigned. This is due to +the self-signed certificates generated for the server, and is not a +problem or security vulnerability, it is just a little annoying. + +{{< img alt="Textual network edit menu" src="/pix/irc/textual-network-edit.png" link="/pix/irc/textual-network-edit.png" >}} + +Surviving restarts with a SystemD service + +In the beginning of the last section, Ergo was started by simply running +`./ergo run`, but this is only suitable for testing. To have a proper +server setup, you need to run it as a service. This can be achieved via +a SystemD service. + +Before creating your service file, make sure you are in `~/server` as +the `ergo` user.\ +Once you have done that, create a file called `start.sh` with the +following content: + +```sh +#!/bin/bash +./ergo run +``` + +Save the file, then mark it as executable: + +```sh +chmod +x start.sh +``` + +Now, create a file called `ergo.service` with the following content: + +```systemd +[Unit] +Description=Ergo IRC server +After=network.target +# If you are using MySQL for history storage, comment out the above line +# and uncomment these two instead (you must independently install and configure +# MySQL for your system): +# Wants=mysql.service +# After=network.target mysql.service + +[Service] +Type=simple +User=ergo +WorkingDirectory=/home/ergo/server +ExecStart=/home/ergo/server/start.sh +ExecReload=/bin/kill -HUP $MAINPID +Restart=on-failure +LimitNOFILE=1048576 +# Uncomment this for a hidden service: +# PrivateNetwork=true + +[Install] +WantedBy=multi-user.target +``` + +You now have your service file, but it is not installed yet. To install +it, switch to your normal user, and execute the following lines to +install, enable, and start the SystemD service: + +```sh +ln -s /home/ergo/server/ergo.service /etc/systemd/system/ergo.service +systemctl enable ergo +systemctl start ergo +``` + +Ergo is now installed and running as a service, and will automatically +start when the system boots. + +## Registering accounts and channels {#registering} + +Account and channel registration were mentioned multiple times in this +guide, and are indeed very important parts of the modern IRC ecosystem. +You can connect to most IRC networks and talk without creating an +account, but you will not be able to reserve your nickname or register +channels, so it is important to register an account. + +### Registering an account with NickServ {#registering-accounts} + +First, make sure you are connected to your IRC network. Once you are, +type `/nickserv help` to make sure NickServ (the registration system) is +working propertly.\ +If all is well, type the following, replacing `<your password>` with the +password you want to use: + +```txt +/nickserv register <your password> +``` + +At this point, you are now registered!\ +The final step is to configure authentication with your client. + +In HexChat, all that needs to be done is changing `Login method` to +`SASL (username + password)`, and entering your NickServ password that +you used earlier into the password field: + +{{< img alt="HexChat SASL in network edit menu" src="/pix/irc/hexchat-sasl.png" link="/pix/irc/hexchat-sasl.png" >}} + +In Textual, open up your network in the menu, and click `Identity` under +`Server Properties`. Enter your password in `Personal Password`, and +check `Wait for identification before joining channels`. + +{{< img alt="Textual identity menu" src="/pix/irc/textual-identity.png" link="/pix/irc/textual-identity.png" >}} + +You will now be logged into your account when you connect to your +network. + +### Registering channels with ChanServ {#registering-channels} + +Once you have an account registered, you can register channels with +ChanServ.\ +To do so, join the channel you want to register, then type the +following, replacing `<your channel>` with the name of the channel you +want to register: + +```txt +/chanserv register #<your channel> +``` + +You are now the channel owner, and are free to appoint operators, +administrators, etc for it. When you go offline, you won\'t lose +ownership, and you cannot be removed as the owner unless you unregister +the channel later. + +## Moderation + +Like any chat, there will come a point where you need to use moderation +tools to keep things under control. Many IRC setup guides do not go over +moderation, so it can be stressful when operators need to actually use +moderation tools.\ +The main difference between IRC and other chat systems in terms of +moderation is the difference between channel bans and network bans. +Channel ban keeps a person out of channel a channel, whereas a network +ban keeps a person out of the entire network. + +### Understanding masks {#moderation-masks} + +Bans are applied \"masks\", which are formatted pieces of text that +contain a user\'s nick (username), their realname value, and their IP +address or host.\ +This is what a mask looks like: `nick!~nick-dude@127.0.0.1`.\ +In bans, asterisks can be used as wildcards, which is useful for banning +IP address ranges, patterns of nicknames, or whatever else you can think +of.\ +A ban on the nick `person`, for example, would look like this: +`person!*@*`.\ +A ban on anyone with the IP address `127.0.0.1` would look like this: +`*!*@127.0.0.1` + +### Discovering real IPs {#moderation-real-ips} + +Even if IP cloaking is enabled on your network, you can still obtain +real IP addresses/hosts if you are an operator. See the **Operators** +part of the configuration section of this guide on how to become an +operator.\ +To find out a user\'s real IP, simply type `/whois` along with the +user\'s nick, and you will see information about the user, along with +their real IP address/host.\ +`/whois` is not a command that is exclusive to operators, but it does +not reveal as much information to non-operators. + +### Banning someone from the network {#moderation-network-ban} + +Any netword-wide moderation action requires being an operator. See the +**Operators** part of the configuration section of this guide on how to +become an operator.\ +Banning someone from the network is achieved with the `/kline` command. +To see more info on the command, type `/helpop kline`.\ + +To ban a nick from the network: + +```txt +/kline andkill <nick>!*@* +``` + +To ban an IP address or host from the network: + +```txt +/kline andkill *!*@<IP or mask> +``` + +To unban a mask, you can use the `/unkline` command with the mask you +want to unban. + +### Banning someone from a channel {#moderation-channel-ban} + +Channel owners, administrators, and operators can ban people from +channels. This is not the same as banning someone from the network, +since it only has an effect on one channel. Additionally, a channel +operator is not the same as a network operator. + +To ban someone in a channel, type the following in that channel, +replacing `<mask>` with the user\'s mask: + +```txt +/mode +b <mask> +``` + +Note that this will only ban the user, not kick them immediately. You +will want to run `/kick` along with the user\'s nick to also kick them.\ +To unban a user, run the command above, but replace the `+` with a `-`.\ +You can see who is banned in a channel by typing `/banlist`. + +### Muting people in a channel {#moderation-muting} + +By default, anyone can speak in an IRC channel. To change this, you must +be a channel owner, administrator, or operator.\ +Channels, along with users, have modes, which modify their behavior. +There is a special mode for channels called `m` (moderated) which +requires users to be privileged in some way to talk.\ +To set a channel as moderated, type the following in the channel: + +```txt +/mode +m +``` + +Now, users must be an owner, administrator, operator, or be voiced to +talk in the channel This be reversed by typing the command above, but +changing the `+` to a `-`.\ +To voice a user, run the following, replacing *\<nick\>* with the +user\'s nick: + +```txt +/mode +v <nick> +``` + +Unvoice the user by typing the above command, but replacing the `+` with +a `-`. + +### Appointing channel administrators and operators {#moderation-appointing} + +Assuming you a channel owner, you can appoint both administrators and +operators. If you are only an operator, you may only appoint operators.\ +The difference between administrator and operator is mainly that +administrators cannot have their privileges taken away by operators, +only owners. To appoint an administrator, type the following, replacing +*\<nick\>* with the user\'s nick: + +```txt +/mode +a <nick> +``` + +To appoint an operator, type the following, replacing *\<nick\>* with +the user\'s nick: + +```txt +/mode +o <nick> +``` + +You can also use `/op` and `/deop` on most clients to appoint and remove +an operator.\ +To remove administrator or operator status, run either of the above +commands, but replace the `+` with a `-`. + +Bringing modern-day features to IRC with TheLounge + +A large downside to IRC as a protocol is just how old it is, and the +limitations that exist because of it. Other old protocols such as HTTP +were built to be content-agnostic and versitile, but IRC was built with +a very specific set of features, so it has not held up so well to +contemporary chat systems.\ +A notable thing that IRC as a protocol is missing is file uploads, and +other fancy features that many other chats have.\ +With that said, these problems can be fixed by clients, although many +clients are still very primitive. + +[TheLounge](https://thelounge.chat/) is a modern self-hosted IRC web +client that tries to make IRC as user-friendly as possible. It can be +the answer to many of the complaints that normalfriends may have about +IRC. It runs on anything with a web browser, can be \"installed\" since +it is a PWA (Progressive Web App), and is optimized for both desktops +and mobile devices. It keeps you logged in even when you are gone, and +even supports file uploads and embeds.\ +Effectively, it brings IRC up to the standard of most other chat +systems. + +If you would like to setup an instance of TheLounge for you and your +friends, you can take a look at their [installation +guide](https://thelounge.chat/docs/install-and-upgrade).\ +It is a self-hosted web app, so you can run it for multiple people, not +just yourself. + +------------------------------------------------------------------------ + +*Written by [Termer](https://termer.net/)* diff --git a/content/jitsi.md b/content/jitsi.md new file mode 100644 index 0000000..aa6bab4 --- /dev/null +++ b/content/jitsi.md @@ -0,0 +1,199 @@ +--- +title: "Jitsi" +date: 2021-07-31 +icon: "jitsi.svg" +tags: ['service'] +short_desc: "Video-chat software." +--- + +<dfn>Jitsi</dfn> is a set of open-source projects that allows you to easily +build and deploy secure video conferencing solutions. + +Is really easy to install, and also a really good private, federated and +libre alternative to Zoom or other video conferencing software. You can +create calls just by typing the URL, and loging-in is not necessary. + +## Dependencies and Installation + +First, install some dependencies: + +```sh +apt install gpg apt-transport-https nginx python3-certbot-nginx +``` + +Jitsi has its own package repository, so let\'s add it. + +```bash +curl https://download.jitsi.org/jitsi-key.gpg.key | gpg --dearmor > /usr/share/keyrings/jitsi-keyring.gpg +echo 'deb [signed-by=/usr/share/keyrings/jitsi-keyring.gpg] https://download.jitsi.org stable/' > /etc/apt/sources.list.d/jitsi-stable.list +apt update -y +``` + +Ok. So now we can install Jitsi, but before we do that, let\'s setup the +firewall `ufw`, in case you have it enabled, and the SSL certificate. + +## Enable Required Ports + +If you are using [ufw](/ufw) or another firewall, there are several +ports we need to ensure are open: + +```sh +ufw allow 80/tcp +ufw allow 443/tcp +ufw allow 10000/udp +ufw allow 3478/udp +ufw allow 5349/tcp +ufw enable +``` + +For your information, these allow the following: + +- 80 TCP -- Certbot. +- 443 TCP -- General access to Jitsi Meet. +- 10000 UDP -- General network video/audio communications. +- 3478 UDP -- Quering the stun server ([Coturn](/coturn), optional, needs config.js change to enable it). +- 5349 TCP -- Fallback network video/audio communications over TCP (when UDP is blocked for example), served by [Coturn](/coturn). + +## SSL certificate + +I\'ll be using [certbot](/basic/certbot) and +[Nginx](/basic/nginx) to generate a certificate for the +Jitsi subdomain to allow encrypted connections. + +```sh +certbot --nginx certonly -d meet.example.org +``` + +We will not create an Nginx config file for Jitsi because the Jitsi +package we will be installing will do that automatically. + +## Installation + +To begin the installation process, just run: + +```sh +apt install jitsi-meet +``` + +It will ask you for your `hostname`; there you\'ll need to input the +subdomain you have just added to Nginx, like `meet.example.org`. + +For the SSL certificate, choose `I want to use my own certificate`. + +When it ask you for the certification key and cert files, input +`/etc/letsencrypt/live/meet.example.org/privkey.pem` and +`/etc/letsencrypt/live/meet.example.org/fullchain.pem` respectively. + +## Using Jitsi + +{{< img alt="Jitsi once installed" src="/pix/jitsi-01.webp" >}} + +Jitsi can be used in a browser by then just going to `meet.example.org`. + +Note that there are also Jitsi clients for all major platforms: + +- [Desktop](https://desktop.jitsi.org/Main/Download.html) (Windows, + MacOS, GNU/Linux) +- Android ([F-Droid](https://f-droid.org/en/packages/org.jitsi.meet/) + and [Google + Play](https://play.google.com/store/apps/details?id=org.jitsi.meet)) +- [iPhone/iOS](https://apps.apple.com/us/app/jitsi-meet/id1165103905) + +**When using a Jitsi app for the first time, remember to go to the +\"Settings\" menu and change your server name to the Jitsi site you just +created.** + +When you create a video chatroom, its address will appear as +`meet.example.org/yourvideochatname` and can be shared as such. + +## Security + +By default, anyone who has access to **meet.example.org** will be able +to create a chatroom. You probably don\'t want that, so you\'ll need to +set up some authentication. The simplest option is to handle +authentication through the local [Prosody](/prosody) user +database. + +### Prosody configuration + +First, we need to enable password authentication in +[Prosody](/prosody). Edit +`/etc/prosody/conf.avail/meet.example.org.cfg.lua`, and locate this +block: + +```lua +VirtualHost "meet.example.org" + authentication = "anonymous" +``` + +And change the authentication mode from `"anonymous"` to +`"internal_hashed"`. + +Then, to enable guests to login and join your chatrooms, add the +following block **after** the one you just edited: + +```lua +VirtualHost "guest.meet.example.org" + authentication = "anonymous" + c2s_require_encryption = false +``` + +### Jitsi Meet configuration + +Next, in `/etc/jitsi/meet/meet.example.org-config.js`, uncomment the +following line: + +```js +var config = { + hosts: { + // anonymousdomain: 'guest.jitsi-meet.example.com', + }, +} +``` + +And change `'guest.jitsi-meet.example.com'` to +`'guest.meet.example.org'`. + +### Jicofo configuration + +Finally, we configure Jicofo to only allow the creation of conferences +when the request is coming from an authenticated user. To do so, add the +following `authentication` section to `/etc/jitsi/jicofo/jicofo.conf`: + +```yaml +jicofo { + authentication: { + enabled: true + type: XMPP + login-url: meet.example.org + } +``` + +### Create users in Prosody and restart the services + +You now need to register some users in [Prosody](/prosody), you +can do so manually using `prosodyctl`: + +```sh +prosodyctl register <username> meet.example.org <password> +``` + +Finally, restart `prosody`, `jicofo`, and `jitsi-videobridge2`: + +```sh +systemctl restart prosody +systemctl restart jicofo +systemctl restart jitsi-videobridge2 +``` + +## More info + +This article is based on [the original +documentation](https://jitsi.github.io/handbook/docs/devops-guide/devops-guide-quickstart). +There you can find more details and configurations. + +- Written by [Jose Fabio.](https://josefabio.com) + Donate Monero: + `484RLdsXQCDGSthNatGApRPTyqcCbM3PkM97axXezEuPZppimXmwWegiF3Et4BHBgjWR7sVXuEUoAeVNpBiVznhoDLqLV7j` + [\[QR\]](https://josefabio.com/figures/monero.jpg) +- Edited and revised by [Luke](https://lukesmith.xyz). diff --git a/content/mail/dovecot.md b/content/mail/dovecot.md new file mode 100644 index 0000000..df2b218 --- /dev/null +++ b/content/mail/dovecot.md @@ -0,0 +1,112 @@ +--- +title: "Dovecot Email Server" +draft: true +--- +In the article on [SMTP and Postfix](smtp.html), we set up a simple +Postfix server that we could use to programatically send mail with the +`mail` command. In order to have a true and fully-functional mail +server, we need Dovecot, which can store mails received by the server, +have and authenticate user accounts and interact with mail + +## Installation + + apt install dovecot-imapd dovecot-sieve + +## Certificate + +We will want a SSL certificate for the `mail.` subdomain. We can get +this with [Certbot](certbot.html). Assuming we are using Nginx for our +server otherwise, run: + + certbot --nginx certonly -d mail.example.org + +## DNS + +## Configuring Dovecot + +Dovecot\'s configuration file is in `/etc/dovecot/docevot.conf`. If you +open that file, you will this line: `!include conf.d/*.conf` which adds +all the `.conf` files in `/etc/dovecot/conf.d/` to the Dovecot +configuration. + +One can edit each of these files individually to get the needed +configuration, but to make things easy here, delete or backup the main +configuration file and we will replace it with one single config file +with all important settings in it. + +``` wide +ssl = required +ssl_cert = </etc/letsencrypt/live/mail.example.org/fullchain.pem +ssl_key = </etc/letsencrypt/live/mail.example.org/privkey.pem +ssl_min_protocol = TLSv1.2 +ssl_cipher_list = EECDH+ECDSA+AESGCM:EECDH+aRSA+AESGCM:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA256:EECDH+ECDSA+SHA384:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA384:EDH+aRSA+AESGCM:EDH+aRSA+SHA256:EDH+aRSA:EECDH:!aNULL:!eNULL:!MEDIUM:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS:!RC4:!SEED +ssl_prefer_server_ciphers = yes +ssl_dh = </usr/share/dovecot/dh.pem +auth_mechanisms = plain login +auth_username_format = %n + +protocols = $protocols imap + +userdb { + driver = passwd +} +passdb { + driver = pam +} + +mail_location = maildir:~/Mail:INBOX=~/Mail/Inbox:LAYOUT=fs +namespace inbox { + inbox = yes + mailbox Drafts { + special_use = \Drafts + auto = subscribe +} + mailbox Junk { + special_use = \Junk + auto = subscribe + autoexpunge = 30d +} + mailbox Sent { + special_use = \Sent + auto = subscribe +} + mailbox Trash { + special_use = \Trash +} + mailbox Archive { + special_use = \Archive +} +} + +service auth { + unix_listener /var/spool/postfix/private/auth { + mode = 0660 + user = postfix + group = postfix +} +} +``` + +### Settings Explained + +Take a good look at the settings to understand what\'s going on. Some of +the settings include: + +1. SSL settings to allow encrypted connections. +2. Default directories for a mail account: Inbox, Sent, Drafts, Junk, + Trash and Archive. +3. The mail server will authenticate users against PAM/passwd, which + means users you create on the server (so long as they are part of + the `mail` group) will be able to receive and send mail. +4. Create a `unix_listener` that will allow Postfix to authenticate + users via Dovecot. + +```{=html} +<!-- --> +``` + echo "auth required pam_unix.so nullok + account required pam_unix.so" >> /etc/pam.d/dovecot + +## Connecting Postfix and Dovecot + +[[Next:\<++\>](%3C++%3E)]{.next} diff --git a/content/mail/opendkim.md b/content/mail/opendkim.md new file mode 100644 index 0000000..bd8eb5d --- /dev/null +++ b/content/mail/opendkim.md @@ -0,0 +1,187 @@ +--- +title: "Validating your emails with OpenDKIM" +draft: true +tags: ['email'] +--- +Email is a lot like real-life mail. You can send email to anyone, but +you can also write whatever return address you\'d like. That is, it\'s +pretty easy to pretend to be someone else via mail, and that was +originally the case with email as well: email is just text, and you +could just change your `From:` address to any email address you wanted! + +DKIM (Domain Keys Identified Mail) helps solve this issue. + +OpenDKIM will generate a public/private cryptographic key pair for your +server. The public key will be made available publicly in your server\'s +DNS records and the private key will be used to sign every single email +that leaves the server. This means that people receiving mail from your +server can now be absolutely sure that it originated from your server +because their servers can check the cryptographic signature on the email +with the public key! + +OpenDKIM ensures that email originated from the server it claims it did, +but it does not ensure that it originated from the user account it +claims it did. This easier problem is solved by server-side +authorization settings. + +## Installation + +```sh +apt install opendkim opendkim-tools +``` + +## The Keys and Files + +We have to generate the DKIM keys and create some secondary files that +will be required for our configuration. + +### Generate the DKIM key + +<!-- +TODO: Make a unique directory for each domain to later allow multiple domain +DKIM validation for servers serving more than one domain name. +--> + +Here we create directories for the OpenDKIM keys, generate them, and +ensure they have the right file permissions. + +```sh +mkdir -p /etc/postfix/dkim +opendkim-genkey -D /etc/postfix/dkim/ -d example.org -s mail +chgrp opendkim /etc/postfix/dkim/* +chmod g+r /etc/postfix/dkim/* +``` + +### Create the key table + +Now we\'ll tell OpenDKIM where the newly generated keys are on the file +system. + +```sh +echo "mail._domainkey.example.org example.org:mail:/etc/postfix/dkim/mail.private" > /etc/postfix/dkim/keytable +``` + +### Create the signing table + +```sh +echo "*@example.org mail._domainkey.example.org" > /etc/postfix/dkim/signingtable +``` + +### Adding trusted hosts + +```sh +echo "127.0.0.1 +10.1.0.0/16 +1.2.3.4/24" > /etc/postfix/dkim/trustedhosts +``` + +## Configuring opendkim.conf + +Now we have all the raw material, so open up `/etc/opendkim.conf` and we +can finalize our server settings. First, add these lines that will +source the files we just created. + +```yaml +KeyTable file:/etc/postfix/dkim/keytable +SigningTable refile:/etc/postfix/dkim/signingtable +InternalHosts refile:/etc/postfix/dkim/trustedhosts + +Canonicalization relaxed/simple +Socket inet:12301@localhost +``` + +There will already be an uncommented `Socket` directive, so delete, +comment out or replace it with the above. + +## Interfacing with Postfix + +There are a couple things we must add to the Postfix SMTP server +settings to interface it with OpenDKIM. Specifically, we have to set our +OpenDKIM server, which will be running on port `12301`, as a milter +(mail filter). This is easy to do with the four commands below: + +```sh +postconf -e "milter_default_action = accept" +postconf -e "milter_protocol = 6" +postconf -e "smtpd_milters = inet:localhost:12301" +postconf -e "non_smtpd_milters = inet:localhost:12301" +``` + +## Restart and reload Postfix and DKIM + +Now that we have all our settings in place: + +```sh +systemctl restart opendkim +systemctl enable opendkim +systemctl reload postfix +``` + +## Adding the DNS record! + +We are only one step away from having functioning OpenDKIM. We must add +the DKIM public key to our server\'s DNS settings, so go ahead and open +up [your registrar\'s site](https://www.epik.com/?affid=we2ro7sa6) or +wherever your site\'s DNS settings are. + +The public key is found in the file `/etc/postfix/dkim/mail.txt`, but it +will display as multiple lines and multiple quoted strings, which is +annoying and hard to copy-and-paste into your registrar. To make things +easier, run the following command to format the key in the way we need +it for the DNS TXT entry: + +```sh +echo -e " + +v=DKIM1; k=rsa; $(tr -d " +" </etc/postfix/dkim/mail.txt | sed "s/k=rsa.* \"p=/k=rsa; p=/;s/\"\s*\"//;s/\"\s*).*//" | grep -o "p=.*") + +" +``` + +Take the very long output of that command, which will start with +`v=DKIM1` and add it as a TXT entry in your DNS settings as below. The +host we put it for is `mail._domainkey`. + +{{< img alt="Adding the OpenDKIM TXT entry in DNS settings" src="/pix/dkim-01.png" link="/pix/dkim-01.png" >}} + +On my registrar, Epik, this is how it is input, but on some registrars, +it may be required to include your domain name as well as +`mail._domainkey.example.org`. + +If you have your own DNS server, add a TXT entry as follows: + +```txt +mail._domainkey.example.org TXT v=DKIM1; k=rsa; p=ThatLongRandomSequenceOfLettersAndNumbersOfYours +``` + +## Testing it out! + +Now we want to send an email to make sure that your emails will now be +signed with OpenDKIM. + +### Hostname + +If you\'ve followed these instructions, all emails from the domain +**example.org** will now have a DKIM signature on them. If we send mail +via the `mail` command, however, their domain of origin will be whatever +your server\'s hostname is, which you may have set to something +different than your domain. + +You can permanently change your hostname by changing it in +`/etc/hostname` and rebooting, or you can just run +`hostname example.org` to change it temporarily for testing. Either way, +this will allow us to run the `mail` command as in [the SMTP +article](smtp.html). + +```sh +echo "Hi there. + +This is the text." | mail -s "Email from the server" your@emailaddress.com +``` + +### More helpful troubleshooting. + +You can also go to [this site](https://appmaildev.com/en/dkim), which +will help you troubleshoot any other DKIM problems if you mistyped +something. diff --git a/content/mail/rainloop.md b/content/mail/rainloop.md new file mode 100644 index 0000000..67fd4cc --- /dev/null +++ b/content/mail/rainloop.md @@ -0,0 +1,117 @@ +--- +title: "Rainloop" +tags: ['service'] +icon: 'rainloop.svg' +short_desc: 'A graphical website for accessing a mail server.' +--- + + +[Rainloop](https://www.rainloop.net/) +is a webmail client, a program that allows you to access your email +online like Gmail. It is useful to be able to access you email from a +web browser because it allows you to easily access your email from any +device with a web browser without any additional setup. + +If you set up +[Nextcloud](/nextcloud) +then you do not need to install Rainloop because Nextcloud comes with a +webmail client. However, if all you want is a webmail client and you do +not need all of the extra things that Nextcloud provides, Rainloop would +be the better choice out of the two since it is less bloated and simpler +to install. + +## Instructions + +First we will install the required packages for Rainloop with the +following command: + +```sh +apt-get install php7.4 php7.4-common php7.4-curl php7.4-xml php7.4-fpm php7.4-json php7.4-dev php7.4-mysql unzip -y +``` + +Then we will download the community version of Rainloop, unzip it into +an appropriate directory and fix all of the file permissions: + +```sh +curl -L "https://www.rainloop.net/repository/webmail/rainloop-community-latest.zip" -o "rainloop.zip" +unzip rainloop.zip -d /var/www/mail +chown -R www-data: /var/www/mail +``` + +We have installed Rainloop itself, but now we need Nginx to serve the +client. We do that by adding the following text into the file +`/etc/nginx/sites-available/mail` (you can replace the bold text with +whatever is appropriate for your server). + +```nginx +server { + + listen 80; + + server_name mail.example.org ; + root /var/www/mail; + + index index.php; + + access_log /var/log/nginx/rainloop_access.log; + error_log /var/log/nginx/rainloop_error.log; + + location / { + try_files $uri $uri/ /index.php?$query_string; + } + + location ~ \.php$ { + fastcgi_index index.php; + fastcgi_split_path_info ^(.+\.php)(.*)$; + fastcgi_keep_conn on; + fastcgi_pass unix:/var/run/php/php7.4-fpm.sock; + include /etc/nginx/fastcgi_params; + fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; + } + location ~ /\.ht { + deny all; + } + + location ^~ /data { + deny all; + } +} +``` + +Then enable the site by linking it to the sites-enabled directory: + +```sh +ln -s /etc/nginx/sites-available/mail /etc/nginx/sites-enabled/ +``` + +Reload nginx: + +```sh +systemctl reload nginx +``` + +Finally get certifications if you are using a new subdomain: + +```sh +certbot --nginx +``` + +After that go to `mail.example.org/?admin` and login with the default +username and password: admin, 12345. Now you are in the admin panel and +the first thing you do should be to change the adminsitrator password by +looking in the security tab on the left. + +{{< img alt="rainloop" src="/pix/rainloop-1.png" >}} + +After securing the admin account you can go to domains and add your own +email address. + +{{< img alt="rainloop" src="/pix/rainloop-2.png" >}} + +Finally, go to `mail.example.org` and login with your email address and +password. + +## Contribution + +[Deniz Telci](https://deniz.telci.org/) - XMR: +`4AcKbpTUc3QX2zHYdh9HZwJAQyexdybFhF1WhXTFhxAcV9jgzB6kroqGZDgeW3rQqXEMYJioYo61kaLBqstwecty9Bjbr4v` diff --git a/content/mail/rdns.md b/content/mail/rdns.md new file mode 100644 index 0000000..6571d8c --- /dev/null +++ b/content/mail/rdns.md @@ -0,0 +1,35 @@ +--- +title: "rDNS and PTR Records" +draft: true +tags: ['email'] +--- +While [DNS records](dns.html) refer a domain name to the IP address +where the the website is hosted, there is also rDNS (reverse DNS) and +specifically PTR (pointer) records which do the reverse: link a +server\'s IP to a domain name. + +This is important for many things, but especially email. Many email +servers require that other servers that send them mail have PTR records +to prevent spam. + +## Setting your PTR Record + +DNS settings are set with your registrar, while rDNS settings are set +with your server or VPS provider. **Remember to set records for both +IPv4 and IPv6!** + +In [Vultr](https://www.vultr.com/?ref=8384069-6G) we want to set the +IPv4 record, click on the server, then \"Settings,\" and make sure the +\"IPv4\" tab is selected. We can then edit the \"Reverse DNS\" blank +shown below. + +{{< img alt="IPv4 rDNS PTR record set in Vultr" src="/pix/rdns-01.png" >}} + +The setting for IPv6 is obviosuly under the IPv6 tab. Note here that we +copy the full IPv6 address from above and create a new rDNS entry by +pasting that and the domain name in the blanks below. Then just select +\"Add.\" + +{{< img alt="IPv6 rDNS PTR record set in Vultr" src="/pix/rdns-02.png" >}} + +That\'s it! diff --git a/content/mail/smtp.md b/content/mail/smtp.md new file mode 100644 index 0000000..6ce92f2 --- /dev/null +++ b/content/mail/smtp.md @@ -0,0 +1,70 @@ +--- +title: "Setting up a Postfix SMTP server" +draft: true +--- +The first step to setting up an email server is having an SMTP server. +SMTP sends and receives email. Whether we want a full email server or +just the ability to send automated email by script, we will need SMTP, +and Postfix is the standard SMTP server. + +Here let\'s set a server up. Note that our goal is to be able to send +emails from our server. If you want a full email server, this is the +first step, and we will address the rest later. + +## Before beginning! + +Whatever VPS ([Vultr](https://www.vultr.com/?ref=8384069-6G) or +[Frantech](https://my.frantech.ca/aff.php?aff=3886)) or IPS you are +using, it is a very common policy to **automatically block all email +ports by default**. VPS providers do this to prevent spammers from using +their services. + +If you want to start an email server, therefore, go to your VPS\'s site +and open a ticket or make a request to open up email ports. This is a +simple process that requires nothing too special. One of the wagies at +your VPS will kindly do the needful and open your ports for you. Note +that this is not the same as unblocking a port with [ufw](ufw.html). + +## Installation + +First, we install Postfix and also `mailutils`, which comes with some +mail programs we will use. + + apt install -y mailutils postfix + +Installing Postfix for the first time will give us some graphical +options. + + + +When asked for a \"mail name\", give your full domain name from which +you would like mail to come and go, e.g. [example.org]{.dfn} or +[landchad.net]{.dfn}. + + + +## Test the email + +That is actually all you need to have set up to have a barebones, +send-only email server. We can test our server by running a `mail` +command like that below. + + echo "Hi there. + + This is the text." | mail -s "Email from the server" your@emailaddress.com + +And that is simply enough the command your server can run to send mail. +Note that we use the `-s` option to specify the email\'s subject while +we pipe the email content into the `mail` command via standard input. In +this example I use a quoted multiline email as an example. + +## Do you see your message? + +If you sent the above test message to an account on Gmail or another +major email provider, there is **very high** chance of the message you +sent above being marked as spam or not appearing at all! + +Don\'t worry, we\'ll take care of that in the next two articles where we +set up rDNS and OpenDKIM to validate the emails you send. + +[[Next: rDNS and PTR Records](rdns.html)]{.next} diff --git a/content/maintenance.md b/content/maintenance.md new file mode 100644 index 0000000..545da82 --- /dev/null +++ b/content/maintenance.md @@ -0,0 +1,124 @@ +--- +title: "Maintaining a Server" +date: 2021-06-29 +tags: ['server'] +--- +Here are some important topics you should be familiar with whenever you +are managing a server. + +## Keep packages up to date. {#update} + +All GNU/Linux distributions use package managers to easily be able to +install and update packages without manually downloading them. On +Debian, which we use here for these tutorial the package manager is +`apt-get` or `apt` for short. + +It\'s a good idea to use `apt` to keep your software reasonably up to +date. + +```sh +apt update +apt upgrade +``` + +Not only do up-to-date packages often come with more features, but they +can also fix any possible security bugs. + +## Troubleshooting general problems + +Often when you are installing something new, you might miss a step and +run into an error, so it\'s important to know how to check and see what +errors have happened on your computer. + +On Debian and other GNU/Linux distributions that use systemd (most of +them), you can use the command `journalctl` to look at the system\'s +general log. You will probably want to run `journalctl -xe` as the `-x` +and `-e` as that gives the most information and starts you at the bottom +of the log to see the most recent errors. + +Some programs do not use this system log, but have their own logs stored +in `/var/log/`, or sometimes it\'s more convenient to look at a specific +program\'s log to see only its issues. + +For example, we can see that in `/var/log/nginx/`, nginx produces both +`error` and `access` files. The `access` files show you all the times +people connect to files on your server and much more. We can look at the +most recent errors by running: + +```sh +tail -n 25 /var/log/nginx/error.log +``` + +The command `tail -n 25` means \"show me the last 25 lines of this +file.\" You can replace that with `less` to browse the whole file. In +`less`, navigate with arrows or vim-keys and exit with `q`. + +### systemctl + +Another tool on systemd distributions is `systemctl`. At a basic level, +use `systemctl status put-service-name-here` to see if a system service +is running and its most recent log. But there\'s much more to +`systemctl`. + +For example, you can run `systemctl stop nginx` to stop NginX and +`systemctl start nginx` to start it back up (or use `restart` for both). +When you make changes to a program\'s configuration files, `reload` well +make them reload them. If you no longer want a service to start when the +system is rebooted, use `disable`, or conversely, to make a service +start on reboot use `enable`. + +## Finding Files + +Especially if you\'re new to how a GNU/Linux system is arranged, you +might need help finding files. To find program-related files, you can +just use `whereis`: + +```sh +$ whereis nginx +nginx: /usr/sbin/nginx /usr/lib/nginx /etc/nginx /usr/share/nginx /usr/share/man/man8/nginx.8.gz +``` + +This command lists the directories related to that program. For example, +`/etc/nginx` is where the configuration files are and `/usr/share/nginx` +is where the library and module-like files are. + +But `whereis` can be used only with installed programs. A more general +tool is the pair of `updatedb` and `locate`. + +`updatedb` is a command that quickly indexes every file and directory on +your computer. Then you can run `locate` to find a file containing a +given name. After running `updatedb`, try running `locate nginx` to find +all files with \"nginx\" in their name. + +You can make your search more specific by chaining other Unix commands +through pipes. For example, `grep` takes input and returns only lines +that match an extra argument. In the example below, we `locate` all +files with \"nginx\" in the name, but we use `grep` to only show us +those with the word \"available\" in them. + +```sh +root@landchad:~# locate nginx | grep available +/etc/nginx/modules-available +/etc/nginx/sites-available +/etc/nginx/sites-available/default +/etc/nginx/sites-available/landchad +/usr/share/nginx/modules-available +/usr/share/nginx/modules-available/mod-http-auth-pam.conf +/usr/share/nginx/modules-available/mod-http-dav-ext.conf +/usr/share/nginx/modules-available/mod-http-echo.conf +/usr/share/nginx/modules-available/mod-http-geoip.conf +/usr/share/nginx/modules-available/mod-http-image-filter.conf +/usr/share/nginx/modules-available/mod-http-subs-filter.conf +/usr/share/nginx/modules-available/mod-http-upstream-fair.conf +/usr/share/nginx/modules-available/mod-http-xslt-filter.conf +/usr/share/nginx/modules-available/mod-mail.conf +/usr/share/nginx/modules-available/mod-stream.conf +``` + +`updatedb` is an ideal candidate for a [cronjob](/cron) so you +don\'t have to worry about running each time. For example, adding the +following to your crontab will run `updatedb` every 30 minutes: + +```sh +*/30 * * * * /usr/bin/updatedb +``` diff --git a/content/matrix.md b/content/matrix.md new file mode 100644 index 0000000..4442cc3 --- /dev/null +++ b/content/matrix.md @@ -0,0 +1,139 @@ +--- +title: "Matrix Synapse" +date: 2021-07-16 +icon: 'element.svg' +tags: ['service'] +short_desc: "An encrypted chat server sleek and accessible even to normies." +--- + +Matrix is easy-to-use, decentralized and encrypted private chat +software. Matrix is federated, meaning that with a Matrix account on any +server, including your own, you can talk to any other Matrix account on +the internet, similar to email. Matrix also allows fully end-to-end +encrypted group chats. + +**Synapse** is the name of the default Matrix server. It is written in +Python. While it is requires somewhat more system resources than [an +XMPP server](/prosody), it makes up for that in being very accessible +to non-technical users. + +## Installation + +Synapse is not in the Debian package repositories by default, but we can +easily add Matrix\'s repository including it: + +```sh +apt install -y lsb-release wget apt-transport-https +wget -O /usr/share/keyrings/matrix-org-archive-keyring.gpg https://packages.matrix.org/debian/matrix-org-archive-keyring.gpg +echo "deb [signed-by=/usr/share/keyrings/matrix-org-archive-keyring.gpg] https://packages.matrix.org/debian/ $(lsb_release -cs) main" > /etc/apt/sources.list.d/matrix-org.list +``` + +After we update our packages lists, we will be able to install Synapse +with `apt`. + +```sh +apt update +apt install matrix-synapse-py3 +``` + +When prompted, give your main domain name (not a subdomain). This will +be the domain appended to your Matrix address, e.g. +`@chad:landchad.net`. + +## Nginx configuration + +Create an Nginx configuration file for Matrix, say +`/etc/nginx/sites-available/matrix` and add the content below: + +```nginx +server { + server_name matrix.example.org ; + listen 80; + listen [::]:80; + location / { + proxy_pass http://localhost:8008; + } + location ~* ^(\/_matrix|\/_synapse\/client) { + proxy_pass http://localhost:8008; + proxy_set_header X-Forwarded-For $remote_addr; + client_max_body_size 50M ; + } + location /.well-known/matrix/server { + return 200 '{"m.homeserver": {"base_url": "https://matrix.example.org"}}'; + default_type application/json; + add_header Access-Control-Allow-Origin *; + } +} +``` + +Note the `client_max_body_size` variable. By default, Nginx caps the +size of files it can transfer. We increase that to 50M if needed by +Matrix. (Note however that both Matrix and Nginx have seperate settings +for this and to raise it to something much larger, you will have to +increase the value in both configuration files.) + +Now let\'s enable the Nginx Matrix site and reload Nginx to make it +active. + +```sh +ln -s /etc/nginx/sites-available/matrix /etc/nginx/sites-enabled +systemctl reload nginx +``` + +### Encryption + +Obviously, we need to encrypt our `matrix` subdomain as well. Let\'s do +that with certbot: + +```sh +certbot --nginx -d matrix.example.org +``` + +## Configuration + +### Read the config file + +The configuration file for Matrix is in +`/etc/matrix-synapse/homeserver.yaml`. It is well documented and +commented, so you can read about the settings, but let\'s change the +essential ones here. + +Make what changes you want and run `systemctl reload matrix-synapse` to +make the system configuration active. + +### Create an administrator account + +If you allow open registration on your server in the configuration file, +you can create an account through Element or another Matrix client, but +you are probably going to want an official admin account to use. To make +one, simply run the following command, which will then give you several +choices for creating a user, among which will be the ability to make it +an admin. + +```sh +register_new_matrix_user -c homeserver.yaml http://localhost:8008 +``` + +## Using Matrix with Element + +There are many different [clients](https://matrix.org/clients/) that can +be used on desktops or phones to chat on your Matrix server, but the +most popular and most widely vetted is Element. + +Get Element to access your Matrix server: + +- Mobile: + - [F-droid](https://f-droid.org/packages/im.vector.app/) + - [Google + Play](https://play.google.com/store/apps/details?id=im.vector.app) + - [Apple App + Store](https://apps.apple.com/app/vector/id1083446067) +- Real computer: + - GNU/Linux: You know how to install it. + - [Windows](https://packages.riot.im/desktop/install/win32/x64/Element%20Setup.exe) + - [Mac](https://packages.riot.im/desktop/install/macos/Element.dmg) + +Note also that Element has a web client (i.e. a version that can be +accessed on your own website) that is also easy to install on an Nginx +server, although that will be covered in another article. diff --git a/content/monero.md b/content/monero.md new file mode 100644 index 0000000..87f1d78 --- /dev/null +++ b/content/monero.md @@ -0,0 +1,89 @@ +--- +title: "Monero" +icon: 'xmr.svg' +date: '2021-06-29' +tags: ['service'] +short_desc: "The ideal private cryptocurrency for the Internet." +--- +Monero (abbreviated XMR) is easily the cryptocurrency most actually used +as such. Unlike Bitcoin, Monero is actually private and has very low +transaction fees. That makes it a good idea to get a Monero wallet and +add an address on your website where you can receive donations. + +## Generate a Monero wallet + +Go to [Monero\'s official site](https://www.getmonero.org/downloads/) and you can download either the GUI (graphical) or CLI (command-line +wallet). Some Linux distributions will have these packages in their +repositories (`monero` and `monero-gui` on Arch-based distributions). + +<aside> + +If you are a Windows user, note that you will *probably* get some kind +of warning that you are installing something malicious. This is because +many malicious pieces of software include crypto miners in them. This +wallet, obviously, does include one as well, because it has the ability +to mine if you want. You can disregard these messages and as that +official site mentions, you can follow their directions to check the +integrity of the download with SHA256. + +</aside> + +Once you install and run the wallet program, you will get a menu like +this: + +{{< img src="/pix/monero-01.png" alt="simple mode" >}} + +Now if you want to start using Monero and using it as a pro, you can +choose to download the whole blockchain which will maximize your +transactional privacy, however for this tutorial or setting up a wallet, +we can just do the Simple Mode and save our bandwidth. **In fact, if you +are paranoid, you can disconnect your computer from the internet while +generating a wallet.** + +Now we choose to create a wallet. + +{{< img src="/pix/monero-02.png" alt="create wallet" >}} + +Now we get the most important and sensitive part, you private mneumonic +seed. **These words are sacred! They are your money!** To be clear, they +are randomly generated words that seed the randomness required to unlock +whatever money you receive or hold. Never show these words to anyone, +don\'t even keep them on your computer, but write them down and store +them securely in real life in a safe or somewhere where only you have +access. + +{{< img src="/pix/monero-03.png" alt="seed" >}} + +It goes without saying that the seed above that we generated for this +tutorial should never be used by anyone since it is public on the +internet and anyone could easily take the funds from the wallet. + +Finally, we get to the main wallet screen. Now we see your public +sharable wallet receiving address. It is the thing that starts with `4` +and is too long to be included in the image below labeled \"Primary +address.\" + +{{< img src="/pix/monero-04.png" alt="address" >}} + +Click the clipboard next to it to copy the whole sequence (which will be +more than 90 letters and numbers) to your clipboard. This is your +address. Put it on your website and you can receive donations! + +You can also click to save that QR code image and you can put it up on +your website and people will be able to scan it and send you Monero. +When scanned, that QR code will read as the public donation address. + +## What do I do now? + +You can now receive Monero/XMR donations! All you need to do is put +either your full address or your QR code on your site and people can +send you tips in Monero. + +Here is the address we use for this site (i.e. not the compromised +wallet generated above): + +<code class=crypto>84RXmrsE7ffCe1ADprxLMHRpmyhZuWYScDR4YghE8pFRFSyLtiZFYwD6EPijVzD3aZiEpg57MfHEr1pGJNPXyJgENMnWrSh</code> + +{{< img src="/pix/xmr.png" class=qr alt="monero donation qr" >}} + +It\'s now up to you how and where to display these on your site. diff --git a/content/movim.md b/content/movim.md new file mode 100644 index 0000000..8743b81 --- /dev/null +++ b/content/movim.md @@ -0,0 +1,116 @@ +--- +title: "Movim" +draft: true +icon: 'movim.svg' +tags: ['service'] +short_desc: 'An XMPP-based social media site, blog and chat site.' +--- +## Installing the Packages and Database + +### Dependencies + + apt install -y nginx python3-certbot-nginx postgresql composer php-fpm php-curl php-mbstring php-imagick php-gd php-pgsql php-xml git + +### Installing Movim Itself + + cd /var/www + git clone https://github.com/movim/movim.git + cd movim + composer install + +### Preparing Permissions + + cd /var/www + chown www-data movim && chown www-data movim/public && chmod u+rwx movim + +### Database setup + + su - postgres # Become the postgres user + psql # Open a postgresql prompt + CREATE USER movim WITH PASSWORD 'yourpassword' ; + CREATE DATABASE movim WITH OWNER movim ; + \q + +leave postgres user + +We now have to tell movim to use this newly created postgresql username +and database that we\'ve created. Create a new file in +`/var/www/movim/config/db.inc.php` and add the following content: + + <?php + $conf = [ + 'type' => 'pgsql', + 'username' => 'movim', + 'password' => 'yourpassword', + 'host' => 'localhost', + 'port' => 5432, + 'database' => 'movim' + ]; + +ask for pass https://movim.yourdomain.com Choose postgresq localhost +pass + +## Configuration with nginx + +Let\'s create an nginx configuration file for this movim site. I will +create a file `movimsite.conf` in `/etc/nginx/sites-available/` and add +the following content: + + server { + listen 80 ; + listen [::]:80 ; + server_name movim.lukesmith.xyz ; + include /etc/nginx/snippets/movim.conf ; + location / { + try_files $uri $uri/ =404; + } + } + +Note above that this is calling the file +`/etc/nginx/snippets/movim.conf` which contains the content needed for +Movim and should be autocreated when installing the Debian package. + +To enable the site, let\'s link the file to the `sites-enabled` +directory and then reload nginx to update it. + + ln -s /etc/nginx/sites-available/movimsite.conf /etc/nginx/sites-enabled/ + systemctl reload nginx + +Now, run [certbot](/basic/certbot) which we installed above to get secured +connections on your site. Choose to \"Redirect\" unencrypted connections +when prompted. + + certbot --nginx + +## Systemd service + +Let\'s create a systemd service for Movim. Create the file +`/etc/systemd/system/movim.service` and add the content below: + + [Unit] + Description=Movim daemon + After=nginx.service network.target local-fs.target + + [Service] + User=www-data + Type=simple + Environment=PUBLIC_URL=https://localhost/movim/ + Environment=WS_PORT=8080 + EnvironmentFile=-/etc/default/movim + ExecStart=/usr/bin/php daemon.php start --url=${PUBLIC_URL} --port=${WS_PORT} + WorkingDirectory=/var/www/movim/ + StandardOutput=syslog + SyslogIdentifier=movim + PIDFile=/run/movim.pid + Restart=on-failure + RestartSec=10 + + [Install] + WantedBy=multi-user.target + + systemctl daemon-reload + systemctl restart movim + +Install prosody modules apt install mercurial mkdir -p +/usr/share/prosody hg clone https://hg.prosody.im/prosody-modules/ +/usr/share/prosody/modules diff --git a/content/nextcloud.md b/content/nextcloud.md new file mode 100644 index 0000000..4d571cc --- /dev/null +++ b/content/nextcloud.md @@ -0,0 +1,292 @@ +--- +title: "Nextcloud" +date: 2021-06-30 +icon: 'nextcloud.svg' +tags: ['service'] +short_desc: 'A free and private Google Drive-like cloud storage system.' +--- + +## What is Nextcloud? {#whatis} + +[Nextcloud](https://nextcloud.com) +is a free and open source solution for cloud storage. However it can +also do other things, such as manage your email, notes, calender, tasks, +and can even connect to the Fediverse (think Mastodon and Pleroma). +Pretty much every service that Google has to offer has a much better +alternative as a Nextcloud app and this is a must-have for anyone +wanting to get away from Google services but still wants a traditional +cloud experience (in the likes of Google Services, anyways). + +## Instructions + +We should upgrade the system and then install packages that we might +need. Run the following command: + +```sh +apt full-upgrade -y && apt install mariadb-server php-mysql php php-gd php-mbstring php-dom php-curl php-zip php-simplexml php-xml php-fpm -y +``` + +Next, we need to set up our SQL database by running a Secure +Installation and creating the tables that will store data that Nextcloud +will need. Run the following command: + +```sh +mysql_secure_installation +``` + +When it asks for root a password, say yes and input a new and secure +password. The root password here is just for the SQL database, not for +the GNU/Linux system. + +Answer the rest of the questions as follows: + +```sh +Remove anonymous users? [Y/n]: Y +Disallow root login remotely? [Y/n]: Y +Remove test database and access to it? [Y/n]: Y +Reload privilege tables now? [Y/n]: Y +``` + + +Next, sign into the SQL database with the new and secure password you +chose before. Run the following command: + +```sh +mysql -u root -p +``` + +We need to create a database for Nextcloud. Follow the instructions +below and change some of the placeholders as you wish: + +```mysql +CREATE DATABASE nextcloud; +GRANT ALL ON nextcloud.* TO 'username'@'localhost' IDENTIFIED BY 'password'; +FLUSH PRIVILEGES; +EXIT; +``` + +Now we need to configure PHP. Let\'s start my making sure that the PHP +user is set to `www-data` and if that is not the case, add the +`www-data` user if needed and set the correct variable in `nginx.conf`. +Make sure this line is at the beginning of `/etc/nginx/nginx.conf`. + +```nginx +user www-data; +``` + +Check for the `www-data` user by running `id -u www-data`. If a number +is output from that command, then the www-data user exists. If not. add +the user simply by running `useradd www-data` + +Next, we need to ensure that we have SSL certificates generated for your +website. If you have not already done this, refer to [this +guide](/basic/certbot). + +In `/etc/nginx/sites-available/` we need to make a new configuration for +Nextcloud (example: `/etc/nginx/sites-available/nextcloud`). Create it +and open it, modify, and add the following lines: + +```nginx +upstream php-handler { + server unix:/var/run/php/php7.4-fpm.sock; + server 127.0.0.1:9000; +} + +server { + listen 80; + listen [::]:80; + server_name example.org; + + return 301 https://$server_name$request_uri; +} + +server { + listen 443 ssl http2; + listen [::]:443 ssl http2; + server_name example.org; + ssl_certificate /etc/letsencrypt/live/example.org/fullchain.pem ; + ssl_certificate_key /etc/letsencrypt/live/example.org/privkey.pem ; + + root /var/www; + + location = /robots.txt { + allow all; + log_not_found off; + access_log off; + } + + location ^~ /.well-known { + location = /.well-known/carddav { return 301 /nextcloud/remote.php/dav/; } + location = /.well-known/caldav { return 301 /nextcloud/remote.php/dav/; } + + location /.well-known/acme-challenge { try_files $uri $uri/ =404; } + location /.well-known/pki-validation { try_files $uri $uri/ =404; } + + return 301 /nextcloud/index.php$request_uri; + } + + location ^~ /nextcloud { + client_max_body_size 512M; + fastcgi_buffers 64 4K; + + gzip on; + gzip_vary on; + gzip_comp_level 4; + gzip_min_length 256; + gzip_proxied expired no-cache no-store private no_last_modified no_etag auth; + gzip_types application/atom+xml application/javascript application/json application/ld+json application/manifest+json application/rss+xml application/vnd.geo+json application/vnd.ms-fontobject application/x-font-ttf application/x-web-app-manifest+json application/xhtml+xml application/xml font/opentype image/bmp image/svg+xml image/x-icon text/cache-manifest text/css text/plain text/vcard text/vnd.rim.location.xloc text/vtt text/x-component text/x-cross-domain-policy; + + add_header Referrer-Policy "no-referrer" always; + add_header X-Content-Type-Options "nosniff" always; + add_header X-Download-Options "noopen" always; + add_header X-Frame-Options "SAMEORIGIN" always; + add_header X-Permitted-Cross-Domain-Policies "none" always; + add_header X-Robots-Tag "none" always; + add_header X-XSS-Protection "1; mode=block" always; + + fastcgi_hide_header X-Powered-By; + + index index.php index.html /nextcloud/index.php$request_uri; + + location = /nextcloud { + if ( $http_user_agent ~ ^DavClnt ) { + return 302 /nextcloud/remote.php/webdav/$is_args$args; + } + } + + location ~ ^/nextcloud/(?:build|tests|config|lib|3rdparty|templates|data)(?:$|/) { return 404; } + location ~ ^/nextcloud/(?:\.|autotest|occ|issue|indie|db_|console) { return 404; } + + location ~ \.php(?:$|/) { + fastcgi_split_path_info ^(.+?\.php)(/.*)$; + set $path_info $fastcgi_path_info; + + try_files $fastcgi_script_name =404; + + include fastcgi_params; + fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; + fastcgi_param PATH_INFO $path_info; + fastcgi_param HTTPS on; + + fastcgi_param modHeadersAvailable true; + fastcgi_param front_controller_active true; + fastcgi_pass php-handler; + + fastcgi_intercept_errors on; + fastcgi_request_buffering off; + } + + location ~ \.(?:css|js|svg|gif)$ { + try_files $uri /nextcloud/index.php$request_uri; + expires 6M; + access_log off; + } + + location ~ \.woff2?$ { + try_files $uri /nextcloud/index.php$request_uri; + expires 7d; + access_log off; + } + + location /nextcloud/remote { + return 301 /nextcloud/remote.php$request_uri; + } + + location /nextcloud { + try_files $uri $uri/ /nextcloud/index.php$request_uri; + } + } +} +``` + +Enable the site by running this command: + +```sh +ln -s /etc/nginx/sites-available/nextcloud /etc/nginx/sites-enabled/ +``` + +Next, we need to download the latest release tarball of Nextcloud. Go to +https://nextcloud.com/install/#instructions-server and copy the URL of +the .tar.bz2 tarball from the More Downloads dropdown menu then go to +your server\'s shell prompt and download the tarball with wget. Here is +an example: + +```sh +wget https://download.nextcloud.com/server/releases/nextcloud-21.0.2.tar.bz2 +``` + +Now we need to extract the Nextcloud tarball. Run the following command: + +```sh +tar -xjf nextcloud*.tar.bz2 -C /var/www +``` + +If you have multiple Nextcloud tarballs in the current working directory +you might want to manually specify which one you wish to extract. + +Let\'s correct the ownership and permissions of those files. Run the +following commands: + +```sh +chown -R www-data:www-data /var/www/nextcloud +chmod -R 755 /var/www/nextcloud +``` + + +Start and enable the php-fpm and the mariadb services (the name of the +php-fpm service may have a version number ahead of it, use bash\'s tab +autocomplete to help you out with that): + +```sh +systemctl enable php7.4-fpm +systemctl start php7.4-fpm +systemctl enable mariadb +systemctl start mariadb +``` + +Reload the nginx service: + +```sh +systemctl reload nginx +``` + +Now we need to head to Nextcloud\'s web interface. Go to your web +browser and go to your website, but go to the subdirectory \"nextcloud\" +instead. Go to `https://example.org/nextcloud`. This will launch the +configuration wizard. + +- Choose an admin username and secure password. +- Leave Data folder at the default value unless it is incorrect. +- For Database user, enter the user you set for the SQL database. +- For Database password, enter the password you chose for the new user + in MariaDB. +- For Database name, enter: `nextcloud` +- Leave \"localhost\" as \"localhost\". +- Click Finish. + +Congratulations, you have set up your own Nextcloud instance. + +## What\'s Next? {#whatsnext} + +Now you may be wondering: What do I do now? Here are some suggestions: + +- Rice your Nextcloud instance by changing your themeing and + installing new themes and plugins in Settings in the Nextcloud Web + Interface. +- Install the Nextcloud Client on your personal computer and sync your + files to your instance. +- Install the Nextcloud App on your mobile device and sync your files + to your instance. +- Set up your email account on the Nextcloud Mail app on the web + interface to view and sync your email there (just like Gmail). +- Schedule events with Nextcloud Calender. +- Write notes in Markdown inside the Nextcloud Notes web and mobile + app. +- Set the Nextcloud Dashboard as your web browser\'s homepage (it is + pretty nice). + +Enjoy your cloud services in freedom. + +------------------------------------------------------------------------ + +*Written by [Matthew \"Madness\" Evan](https://github.com/MattMadness)* diff --git a/content/nginx-tweaks.md b/content/nginx-tweaks.md new file mode 100644 index 0000000..8d4dcb8 --- /dev/null +++ b/content/nginx-tweaks.md @@ -0,0 +1,46 @@ +--- +title: "Nginx Tweaks" +date: 2022-06-16 +--- +The point of this article is to show you how to do some commonly-desired +tweaks in Nginx while in the meantime helping you understand how it +works. + +## Do not require `.html` in URLs + +If your website is using lots of `.html` files for pages, it\'s sort of +overkill to make people type that in for every page they are looking +for. We can remove that requirement with Nginx. + +Open your site\'s configuration file in `/etc/nginx/sites-enabled/` and +within the `server` block, there should be a `location` block that looks +something like this if you have followed [the guide here](/basic/nginx). + +```nginx +location / { + try_files $uri $uri/ =404 ; +} +``` + +What this means is that in the file location of `/`, i.e. anywhere and +everywhere in the root file system, We will look for the three things +listed in `try_files` in that order: + +1. `$uri`: a file that directly matches the content added after the + domain. +2. `$uri/`: a *directory* that directly matches the content added after + the domain. +3. `=404`: if neither of those is found, we give a 404 error, which as + you probably know, signified \"Page not found.\" + +We will now change the content inside the `location` block to the below: + +```nginx +location / { + if ($request_uri ~ ^/(.*)\.html$) { return 302 /$1; } + try_files $uri $uri.html $uri/ =404 ; +} +``` + +`$1` here refers to the first content in the parentheses `()` in the +preceeding regular expression. diff --git a/content/openalias.md b/content/openalias.md new file mode 100644 index 0000000..2760c0c --- /dev/null +++ b/content/openalias.md @@ -0,0 +1,102 @@ +--- +title: "OpenAlias" +date: 2021-07-01 +tags: ['server'] +--- +## The Problem + +Cryptocurrency can be unintuitive. After all, look at this annoying +Monero address of ours: + +- `84RXmrsE7ffCe1ADprxLMHRpmyhZuWYScDR4YghE8pFRFSyLtiZFYwD6EPijVzD3aZiEpg57MfHEr1pGJNPXyJgENMnWrSh` + +It breaks up pages and looks ugly. When you copy and paste it to send +money, you might be paranoid that you somehow added an extra character +in there. That\'s all around a bad user experience. + +### It would be nice\... + +It would be nice if we could just input someone\'s email address or +maybe a website and send Bitcoin or Monero to that instead. So instead +of that long jumble, it would be easier to just type in someone\'s +website or email and sending them money that way. + +## The Solution + +The [OpenAlias](https://openalias.org/) standards are just that. It uses +[DNS](/basic/dns) settings, which you know something about, to link a +website or an email address with a cryptocurrency address. It allows +someone to simply put `landchad.net` or `chad@landchad.net` as a payment +recipient and that will direct to that long address above. + +The default Monero wallet and Bitcoin\'s Electrum are already compatible +with OpenAlias, as are a growing group of wallet software. + +## Let\'s do it. + +Open up your domain registar and open up your DNS settings for the +website you would like to add. + +Open the **TXT record** section. Now, create an entry with text like +that below: + +```txt +oa1:xmr recipient_address=84RXmrsE7ffCe1ADprxLMHRpmyhZuWYScDR4YghE8pFRFSyLtiZFYwD6EPijVzD3aZiEpg57MfHEr1pGJNPXyJgENMnWrSh; recipient_name=LandChad.net; +``` + +Obviously change the address to your desired address and you may also +give a proper name for yourself (this may be multiple words). Note that +the entry above is **all one line**. + +Now create a new TXT entry and input this text into the **TXT Value** +input box. Note here that I have create two entries: + +{{< img alt="openalias" src="/pix/openalias-01.png" link="/pix/openalias-01.png" >}} + +One entry\'s \"Host\" is left empty, this will allow people to send +Monero by merely typing `landchad.net`. + +The second entry has \"chad\" as the \"Host\"; this will allow people to +send money to `chad@landchad.net`, i.e. this is how you allow people to +connect a Monero address with an email address. + +### Checking to see if it works\... + +Let\'s check to see if it works. In the Monero wallet, we can now type +in `landchad.net` as a recipient: + +{{< img alt="checking" src="/pix/openalias-02.png" link="/pix/openalias-02.png" >}} + +And once we press the \"Resolve\" button, it automatically turns into +that address we gave to the DNS! + +{{< img alt="It works!" src="/pix/openalias-03.png" link="/pix/openalias-03.png" >}} + +Now people can donate Monero to you without having to worry about QR +codes or copying-and-pasting super-long public addresses! + +### Now with Bitcoin! + +OpenAlias was originally developed for Monero, but since it\'s such a +good idea, Bitcoin wallets have implemented it as well, so let\'s add +some TXT entries for Bitcoin. The OpenAlias TXT records have the same +format, except for the **xmr** at the beginning is replaced with **btc** +and obviously we use a Bitcoin address instead of Monero. + +```txt +oa1:btc recipient_address=bc1q9f3tmkhnxj8gduytdktlcw8yrnx3g028nzzsc5; recipient_name=LandChad.net; +``` + +Add the TXT entries in and save: + +{{< img alt="bitcoin openalias entries" src="/pix/openalias-04.png" link="/pix/openalias-04.png" >}} + +And we can then check that it\'s working by trying to send money to +`landchad.net` in Electrum. See that it automatically appends the +address! + +{{< img alt="electrum resolves an openalias" src="/pix/openalias-05.png" link="/pix/openalias-05.png" >}} + +And that\'s it. Now users can easily send your website or email address +Bitcoin or Monero without having to worry about hard to read addresses +and QR codes. diff --git a/content/page-quality.md b/content/page-quality.md new file mode 100644 index 0000000..ba45488 --- /dev/null +++ b/content/page-quality.md @@ -0,0 +1,180 @@ +--- +title: "Page Quality" +date: 2022-03-21 +tags: ['server'] +--- +After you\'ve deployed your website, you may want to consider improving +its performance, accessibility, and search-engine optimization (SEO). +Doing so can help make your website more user-friendly and increase its +page rank in search results. Luckily, Google provides a [measurement +tool](https://web.dev/measure) to help you improve these aspects. Start by +entering your website\'s URL and click the *Run Audit* button (it will +take 5-10 seconds to generate the report). + +Once the report has finished, you\'ll be greeted by a score for four +different categories: *Performance*, *Accessibility*, *Best Practices*, +and *SEO*. A lot of the tests listed are self-explanatory, and Google +provides you with articles to help you pass them. Below are some easy +ways to improve your scores, some specific to the nginx configuration +used in the [landchad website tutorial.](/basic/nginx) + +## Performance + +### Serving static assets with an efficient cache policy + +Serving your files with an efficient cache policy will allow the user\'s +browser to cache files such as pictures and CSS so that the browser doesn\'t +need to fetch these files each time the page is visited. + +It\'s very easy to set this up in nginx. Just paste the following within the +server block of your website\'s configuration file: + +```nginx +# Media: images, icons, video, audio, HTC +location ~* \.(?:jpg|jpeg|gif|png|ico|svg|webp)$ { + expires 1M; + access_log off; + # max-age must be in seconds + add_header Cache-Control "max-age=2629746, public"; +} + +# CSS and Javascript +location ~* \.(?:css|js)$ { + expires 1y; + access_log off; + add_header Cache-Control "max-age=31556952, public"; +} +``` + +You can add more types of file extensions (mp3, mp4, ogg) as you see +fit. + +If you\'re changing your CSS files a lot, caching could keep repeat +users from getting the most up-to-date stylesheet. To combat this, you +can version your stylesheets like so: + +```html +<link rel="stylesheet" type="text/css" href="style.css?v=1.0.0"> +``` + +Just increase the version number whenever you update your stylesheet, +and the browser will re-update its cache. + +### Enable text compression + +Another easy addition to your websites configuration file. Enabling text +compression is easy and will save bandwidth for users. Simply paste the +following within the server block of your website\'s configuration file: + +```nginx +gzip on; +gzip_min_length 1100; +gzip_buffers 4 32k; +gzip_types text/plain application/x-javascript text/xml text/css; +gzip_vary on; +``` + +After reloading nginx, you can test if compression is working by opening +your browsers developer tools and going to the network tab. Refresh your +website with the network tab, click on the item with your URL and look +at the response headers. You should see `Content-Encoding: gzip` as one +of the headers displayed. + +### Properly sizing images + +If you\'ve put images on your webpage, you\'ve most definitely gotten +this warning. To pass this audit, you\'ll need to scale your images down +using a tool like gimp or imagemagick to a size appropriate for your +website. It doesn\'t make much sense to serve a high-res image for +images that are rendered much smaller on a webpage. + +Once you\'ve scaled your image down, you can use a tool like `cwebp` to +convert your images into the .webp format, a format specifically created +for serving bandwidth concious images. + +First, you\'ll have to install the webp package: + +```sh +apt install webp +``` + +Now you can easily convert your images to webp (keep in mind that it\'s +much more effective to first size your images appropriately before +this). Using the below command, you can specify the quality of the photo +with the `q` option. I typically shoot for a quality in the range of +60-80, depending on the image and how large it will be displayed on the +webpage. + +```sh +cwebp -q 80 your-photo.png -o your-photo.webp +``` + +You can now check the difference in size of the images using `ls`. + +```sh +ls -lh your-photo* +``` + +After utilizing webp images, the audit typically goes away, but if you +didn\'t scale your image properly before hand, it may still linger. + +## Accessibility + +### Image elements do not have \[alt\] attributes + +It may seem silly to add `alt` attributes to images, but it helps screen +readers convey images to users and can help page rank as a result. The +`alt` attribute should simply describe the image being displayed. + +```html +<img src="img/cabin.webp" alt="A cabin nestled between pine trees"> +``` + +## SEO + +### Document does not have a meta description + +Adding meta descriptions to your webpage allow for web-crawlers and bots +to easily determine what content your website contains. Just like on +other online platforms, you can give your webpage a long list of +keywords to help increase the chance someone stumbles upon your site +from a search engine. You don\'t need to add all of the below meta tags +to pass the audit, only add what\'s necessary. + +```html +// Instructions for web scrapers +<meta name="robots" content="index, follow"> + +<meta name="description" content="your website description>"> +<meta name="keywords" content="your, keywords, here"> +<meta name="author" content="your name>"> + +// Facebook specific standard, but many websites use this so it has become almost standard to include +<meta property="og:site_name" content="Site Name"> +<meta name="twitter:domain" property="twitter:domain" content="example.org"> +<meta name="og:title" property="og:title" content="Site Name"> +<meta property="og:description" content="your website description"> +<meta name="twitter:description" property="twitter:description" content="your website description"> +<meta name="og:image" content="https://link-to-an-image-that-represents-your-site"> + +// below is for twitter sharing previews, you can test this at: +// cards-dev.twitter.com +<meta property="twitter:card" content="https://link-to-an-image-that-represents-your-site"> +<meta name="twitter:image:src" property="twitter:image:src" content="https://link-to-an-image-that-represents-your-site"> +<meta name="twitter:image" property="twitter:image" content="https://link-to-an-image-that-represents-your-site"> +<meta name="og:image:alt" property="og:image:alt" content="alt text for your image>"> + +<meta property="og:url" content="example.org"> +<meta property="og:type" content="website"> + +// If you have accounts on twitter or facebook that are relevant to your site +<meta property="fb:admins" content="facebook group" > +<meta name="twitter:site" property="twitter:site" content="@yourTwitterHandle"> +<meta name="twitter:creator" property="twitter:creator" content="@yourTwitterHandle>"> +``` + + +------------------------------------------------------------------------ + +*Written by [Jacob.](https://mccor.xyz) Donate Monero +[here.](https://mccor.xyz)* diff --git a/content/peertube.md b/content/peertube.md new file mode 100644 index 0000000..b0ec47e --- /dev/null +++ b/content/peertube.md @@ -0,0 +1,284 @@ +--- +title: "PeerTube" +date: 2021-07-31 +icon: 'peertube.svg' +tags: ['service','activity-pub'] +short_desc: 'Your own self-hosted video-site also compatible with Activity Pub.' +--- + +PeerTube is a self-hosted and (optionally) federated video sharing +platform that saves bandwith on videos the more people watch. PeerTube +instances can follow each other to share videos and grow the federated +network, but you can always keep your instance to yourself if you choose +to. + +## Note on Bandwidth + +Video sharing is the most bandwidth intensive thing on the internet! If +you plan on just having a small personal site with a few viewers and +friends, that won\'t be a big concern, but most VPS providers like Vultr +have caps on how much bandwidth can be used within a month without being +throttled. This level is far beyond what most sites need, but it might +be an issue with a video site! + +So if you plan on having a big video-sharing PeerTube site, it\'s a good +idea to host it with a provider that offers infinite bandwidth. I +strongly recommend getting a separate VPS with +[Frantech/BuyVM](https://my.frantech.ca/aff.php?aff=3886). They have +unmetered bandwidth, extremely cheap block storage for hosting many, +many videos and they even have a good record of being censorship +resistant. + +## Prerequisites + +**Most** of PeerTube\'s dependencies can be installed with this command: + +```sh +apt install -y curl sudo unzip vim ffmpeg postgresql postgresql-contrib g++ make redis-server git python-dev cron wget +``` + +It\'s also important to start all associated daemons: + +```sh +systemctl start postgresql redis +``` + +PeerTube also requires **NodeJS 14** and **yarn** which cannot be +installed from the Debian repositories. This means they have to be +installed from separate, external repos: + +```sh +curl -fsSL https://deb.nodesource.com/setup_14.x | bash - +apt install -y nodejs +npm install --global yarn +``` + +Now we create a PeerTube user to run and handle PeerTube with the proper +permissions: + +```sh +useradd -m -d /var/www/peertube -s /bin/bash -p peertube peertube +``` + +## Database + +PeerTube requires a PostgreSQL database to function. To create it, first +make a new Postgres user named PeerTube: + +```bash +su -l postgres +createuser -P peertube +createdb -O peertube -E UTF8 -T template0 peertube_prod +psql -c "CREATE EXTENSION pg_trgm;" peertube_prod +psql -c "CREATE EXTENSION unaccent;" peertube_prod +exit +``` + +Be sure to **make note of your Postgres user password,** as it will be +needed later when setting up PeerTube. + +## Installation + +Using `su -l`, we will become the PeerTube user to create the required +directories and download and install PeerTube itself with the proper +permissions. First, we create the required directories. + +```sh +su -l peertube +mkdir config storage versions +chmod 750 config +``` + +### Downloading PeerTube + +Still as the PeerTube user, we can now check for the most recent +PeerTube versions number, download and install it in the newly created +`versiond` directory. + +```bash +VERSION=$(curl -s https://api.github.com/repos/chocobozzz/peertube/releases/latest | grep tag_name | cut -d '"' -f 4) +cd /var/www/peertube/versions +wget "https://github.com/Chocobozzz/PeerTube/releases/download/${VERSION}/peertube-${VERSION}.zip" +unzip peertube-${VERSION}.zip +rm peertube-${VERSION}.zip +``` + +### Installation via Yarn + +The downloaded release can then be symbolically linked to +`/var/www/peertube/peertube-latest` and **yarn** is used to install +PeerTube: + +```sh +cd /var/www/peertube +ln -s versions/peertube-${VERSION} ./peertube-latest +cd ./peertube-latest +yarn install --production --pure-lockfile +``` + +## Configuration + +PeerTube\'s default config file can be copied over to +`/var/www/peertube/config/production.yaml` so it can actually be used: + +Note that we are still running these as the PeerTube user (having run +`su -l peertube`). + +```sh +cd /var/www/peertube +cp peertube-latest/config/production.yaml.example config/production.yaml +``` + +Now the `production.yaml` file must be edited in the following ways: + +First, add the hostname: + +```yaml +webserver: + https: true + hostname: 'example.org' + port: 443 +``` + +Then, the database: + +```yaml +database: + hostname: 'localhost' + port: 5432 + ssl: false + suffix: '_prod' + username: 'peertube' + password: 'your_password' + pool: + max: 5 +``` + +An email to generate the admin user: + +```yaml +admin: + # Used to generate the root user at first startup + # And to receive emails from the contact form + email: 'chad@example.org' +``` + +And **optionally,** email server information: + +```yaml +smtp: + # smtp or sendmail + transport: smtp + # Path to sendmail command. Required if you use sendmail transport + sendmail: null + hostname: mail.example.org + port: 465 # If you use StartTLS: 587 + username: your_email_username + password: your_email_password + tls: true # If you use StartTLS: false + disable_starttls: false + ca_file: null # Used for self signed certificates + from_address: 'admin@example.org' +``` + +At this point, we have done all we need to do as the PeerTube user. Run +`exit` or press `Ctrl-d` to log out and return to the root prompt where +we will configure Nginx and other system settings. + +## Certbot + +First, we will want a Certbot SSL certificate to encrypt connections to +our PeerTube instance. Just run the following: + +```sh +certbot --nginx -d peertube.example.org certonly +``` + +## Nginx + +PeerTube includes an Nginx configuration that can be copied over to +`/etc/nginx/sites-available:` + +```sh +cp /var/www/peertube/peertube-latest/support/nginx/peertube /etc/nginx/sites-available/peertube +``` + +Because the PeerTube config is so long, it\'s recommended to use `sed` +to modify the contents of the file, replacing `${WEBSERVER_HOST}` with +your hostname, and `$(PEERTUBE_HOST)` with your localhost and port, +which by default should be `127.0.0.1:9000`: + +```sh +sed -i 's/${WEBSERVER_HOST}/example.org/g' /etc/nginx/sites-available/peertube +sed -i 's/${PEERTUBE_HOST}/127.0.0.1:9000/g' /etc/nginx/sites-available/peertube +``` + +Once you\'re happy with the Nginx config file, link it to +`sites-enabled` to activate it: + +```sh +ln -s /etc/nginx/sites-available/peertube /etc/nginx/sites-enabled/peertube +``` + +## Running PeerTube + +A config file for a systemd daemon is included in PeerTube and can be +setup and started like so: + +```sh +cp /var/www/peertube/peertube-latest/support/systemd/peertube.service /etc/systemd/system/ +systemctl daemon-reload +systemctl start peertube +``` + +PeerTube will take a minute or so to start, but after it does, you can check +its status with `systemctl status peertube` and at this point, your +PeerTube site should be live! + +## Using PeerTube + +To set a password for your admin user, run: + +```sh +cd /var/www/peertube/peertube-latest +NODE_CONFIG_DIR=/var/www/peertube/config NODE_ENV=production npm run reset-password -- -u root +``` + +Login to your PeerTube instance using the admin email specified in your +`production.yaml` file and the admin password you just set. + +{{< img alt="PeerTube login" src="/pix/peertube-login.jpg" >}} + +Once logged in, it\'s recommended to create a separate user without +admin privileges for uploading videos to PeerTube. This can be done +easily from the users tab in the administration section. + +Enjoy your PeerTube instance! + +------------------------------------------------------------------------ + +## Updating PeerTube + +PeerTube is constantly adding new features, so it\'s a good idea to +[check for new +updates](https://github.com/Chocobozzz/PeerTube/blob/develop/CHANGELOG.md) +and add them if you wish. Just in the past year, they have added +livestreaming and more. + +Updating is fairly easy now since an `upgrade.sh` script has been added. +Just run: + +```sh +cd /var/www/peertube/peertube-latest/scripts && sudo -H -u peertube ./upgrade.sh +``` + +Although check the +[changelog](https://github.com/Chocobozzz/PeerTube/blob/develop/CHANGELOG.md) +to see if there are additional manual requirements for particular +updates. + +------------------------------------------------------------------------ + +*Written by [Denshi.](https://denshi.org) Donate Monero +[here](https://denshi.org/donate.html) +[\[QR\]](https://denshi.org/images/monero.jpg)* diff --git a/content/pleroma.md b/content/pleroma.md new file mode 100644 index 0000000..78aab03 --- /dev/null +++ b/content/pleroma.md @@ -0,0 +1,186 @@ +--- +title: "Pleroma" +date: 2021-07-01 +icon: 'pleroma.svg' +tags: ['service','activity-pub'] +short_desc: 'A federated Twitter-like microblogging system.' +--- +Hopefully by now you won\'t have to be sold on the invasive practices +that social media companies conduct. Websites such as Facebook and +Twitter aquire so much data on users that they often know more about you +than you know about yourself. The simple solution to this is to not use +social media. However, that just isn\'t an option for most people. So +the next best thing is to setup a self-hosted and federalised social +media site so that you have full control over your data. I\'ve +previously made [a video showing all the steps in depth if you want to +check it out.](https://www.youtube.com/watch?v=l7mVsLSsotU) If you run +into any issues I suggest you look at the video. + +You\'ll need a server or VPS. Nearly any Operating system is supported +but for this tutorial I\'m gonna presume you\'re using a Debian-based +OS. You\'ll also need a domain name pointing to your server\'s IP +address [which is explained in this tutorial.](/basic/dns) + +## Installation + +### Setting Up and Configuring + +First things first you\'ll need to make sure that you\'ve hardened you +SSH so that password authentication is disabled and you\'ll also want to +setup Fail2Ban. There\'s a great tutorial on how to do this [which can +be read here.](/sshkeys) + +Next we\'ll install the required packages: + +```sh +apt install -y curl unzip libncurses5 postgresql postgresql-contrib nginx certbot libmagic-dev +``` + +You can manually configure postgreSQL to suit your system better. [Check +out the documentation +here](https://docs-develop.pleroma.social/backend/configuration/postgresql/) +and then run the below command: + +```sh +systemctl restart postgresql +``` + +### Installing the Pleroma App + +#### First as the root user + +Pleroma is not in the Debian app repositories, so we will install it +manually. First create the Pleroma user by running the below command: + +```sh +useradd -m -s /bin/bash -d /opt/pleroma pleroma +``` + +Then, still as root, we will create the required directories and give +the Pleroma user ownership of them. + +```sh +mkdir -p /var/lib/pleroma/uploads +chown -R pleroma /var/lib/pleroma +mkdir -p /var/lib/pleroma/static +chown -R pleroma /var/lib/pleroma +mkdir -p /etc/pleroma +chown -R pleroma /etc/pleroma +``` + +#### Now, as the new Pleroma user + +Now run `su -l pleroma` to login as the Pleroma user. Now use the `curl` +command below to download the Pleroma software and unzip it. + +```sh +curl 'https://git.pleroma.social/api/v4/projects/2/jobs/artifacts/stable/download?job=amd64' -o /tmp/pleroma.zip +unzip /tmp/pleroma.zip -d /tmp/ +``` + +Note that we are downloading the **amd64** version here. If you know you +have a different CPU architecture, replace that with whatever your +architecture is. + +```sh +mv /tmp/release/* /opt/pleroma +rmdir /tmp/release +rm /tmp/pleroma.zip +./bin/pleroma_ctl instance gen --output /etc/pleroma/config.exs --output-psql /tmp/setup_db.psql +``` + +We need to briefly return to the root user so we can run the following +command (via the postgres user) to set up the database. Type `ctrl-d` or +run `exit` to return to the root user, then run: + +```sh +su postgres -s $SHELL -lc "psql -f /tmp/setup_db.psql" +``` + +Then return to the pleroma user with `su -l pleroma` and we will test to +see that Pleroma can run: + +```sh +./bin/pleroma_ctl migrate +./bin/pleroma daemon +``` + +That will initialize Pleroma. It might take as long as a minute to get +started, so wait a bit, then run the following: + +```sh +curl http://localhost:4000/api/v1/instance +``` + +If everything is working, this command will give you a long line of +messy output. If it is not, you will get a connection error message. +Once it is working successfully, stop the Pleroma daemon and we will +interface Pleroma with the web server. + +```sh +./bin/pleroma stop +``` + +### Setup and Configure Nginx + +Return again to the root user. Let\'s copy Pleroma\'s Nginx +configuration file from the template given in the installation and +enable it: + +```sh +cp /opt/pleroma/installation/pleroma.nginx /etc/nginx/sites-available/pleroma.conf +ln -s /etc/nginx/sites-available/pleroma.conf /etc/nginx/sites-enabled/pleroma.conf +``` + +Edit the `etc/nginx/sites-available/pleroma.conf` file and replace +**example.tld** with your domain name. + +We now have to get a SSL certificate to enable encryption, since we have +a model configuration that already includes SSL information, just check +the brief [the standalone certificate page](/standalone) to get the +needed certificate. Once you\'ve got your cert setup, copy over the +Nginx configuration with the below command: + +Once everything, including your Cerbot certificate is ready, simply +reload Nginx with this command: + +```sh +systemctl reload nginx +``` + +### Setting up the service + +Pleroma itself runs on a SystemD service similar to other things running +on your server like Nginx. To start the service up run the below +commands: + +```sh +cp /opt/pleroma/installation/pleroma.service /etc/systemd/system/pleroma.service +systemctl start pleroma +systemctl enable pleroma +``` + +If everything worked then when you go to your domain in the web browser +you should see a bare-bones Pleroma instance. + +### Creating an Admin User + +You\'ll be able to create new accounts on the Pleroma instance in the +login section on the website but the easiest way to setup an admin +account is with the CLI. Simply run the below command replaced with your +username: + +```sh +su -l pleroma +./bin/pleroma_ctl user new username username@example.org --admin +``` + +If you run into any issues then [feel free to checkout the +documentation](https://docs-develop.pleroma.social/backend/installation/otp_en/) +or send me an email or message. My details are below. + +- [biasedriot.co](https://biasedriot.co) +- [youtube](https://www.youtube.com/channel/UCehh50T6qtDpt_kEUF33GJw) +- Bitcoin: `1Dmn9jEtWAhdLk1HHWkUVNeDdAaBCwNajm`{.crypto} +- Monero: + `84Y4FZiTbLeR5qc1fBrBhB1yq5agKtEdoixq2w1ysXJv486MiBCz3czGT15bqeXDPpdLoNyF93inxY3BCk6g8mrDMNKoArS` diff --git a/content/prosody.md b/content/prosody.md new file mode 100644 index 0000000..1b02b0c --- /dev/null +++ b/content/prosody.md @@ -0,0 +1,273 @@ +--- +title: "Prosody" +date: 2022-04-03 +icon: 'prosody.svg' +tags: ['service'] +short_desc: 'A minimalist XMPP chat server.' +--- + +XMPP is a fantastically simple protocol that\'s usually used as a +messenger. It\'s highly extensible, better than IRC, lighter and more +decentralized than Matrix and Telegram and normie social media can\'t +hold a candle to it. + +XMPP is so decentralized and extensible that there are many *different* +XMPP servers. Here, let\'s set up an [Prosody](https://prosody.im/) XMPP +server. + +## Installation + +Prosody is in the Debian repositories, so we can easily install it on +our server with the following command: + +```sh +apt install prosody +``` + +## Configuration + +The Prosody configuration file is in `/etc/prosody/prosody.cfg.lua`. To +set it all up, we will be changing several things. + +### Setting Admins + +Let\'s go ahead and set who our admin(s) will be. Find the line that +says `admins = { }` and to this we can specify one or more server +admins. + +```cfg +# To add one admin: +admins = { "chad@example.org" } + +# We can add more than one by separating them by commas. (This file is written in Lua.) +admins = { "chad@example.org", "chadmin@example.org" } +``` + +Note that we have not created these accounts yet, we will do this +[below](#user). + +### Set the Server URL + +Find the line `VirtualHost "localhost"` and replace `localhost` with +your domain. In our case, we will have `VirtualHost "example.org"` + +### Multi-User Chats + +Most people will probably want the ability to have chats with more than +two users. This is easily enough to enable. In the config file, add the +following: + +```cfg +Component "chat.example.org" "muc" + modules_enabled = { "muc_mam" } + restrict_room_creation = "admin" +``` + +On the first line, you must have a separate subdomain for your +multi-user chats. I use the `chat.` subdomain, but some use `muc.`. +Anything if possible. + +The second line is important because it prevents non-admins from +creating and squatting rooms on your server. The only situation where +you might not want that is if you indend to open a general public chat +system for people you don\'t know. + +Read more about the `muc` plugin on the Prosody documentation page +[here](https://prosody.im/doc/modules/mod_muc). + +### Enabling chat histories + +By default, Prosody will send out messages received only to the first +available clients. That means that if you have your desktop client +turned off and your cell phone receives a message, it will *not* be +available to the desktop client when you start it. + +While this may be preferred in some cases, enable the MAM module +(Message Archive Management) to have the server hold on messages and +sync them to all clients. + +Within the `modules_enabled` block, you can uncomment the `mam` line to +enable it. You can see other settings for this module +[here](https://prosody.im/doc/modules/mod_mam) like, for example, how +long a server should hold on to message histories for synching. + +Note also that Prosody comes with the `carbons` activated module by +default, which is related. This will send received messages to *all* +active clients (your phone and desktop), although it will not save +messages like MAM for clients not online or to be added later. + +### File sharing + +With this we can bring XMPP to the level of other popular instant +messaging applications like Matrix and whatsapp. It is extremely easy to +setup. This part is optional, but it can make XMPP more normie-friendly +if you plan on moving family members and friends over to XMPP. + +First we need to install extra prosody modules. Run the following +command: + +```sh +apt install prosody-modules +``` + +Then we can add the following line to you prosody config file to enable +file uploads: + +```cfg +Component "uploads.example.org" "http_upload" +``` + +As you will notice, you need another subdomain for this. We will add an +ssl certficate for this later. + +You will also need to go back to `modules_enabled` and uncomment the +`http_files` module. This is used to actually serve the files to users. + +And the last part of the setup is to enable the built in proxy server. +This helps with file transfers for devices behind a NAT, and unless you +are using XMPP in a LAN, you probably need this. Enable the proxy by +adding the following line to the config: + +```cfg +Component "proxy.example.org" "proxy65" +``` + +As you can see, another subdomain is needed. We will add ssl +certificates for this later. + +At this point, file sharing is now setup and ready to be used. Although +there are some concerns that should be addressed. + +A big concern with file sharing is large files, seeing as all files +shared over XMPP will be stored on your server. This can become a +problem when many (and large) files are being shared. We can put a cap +on large files by adding the following line to our config: + +```cfg +http_upload_file_size_limit = 20971520 +``` + +This puts a 20MB cap on all files being shared. The value is specified +in bytes. You can also specify after how long files should be deleted by +adding the following line: + +```cfg +http_upload_expire_after = 60 * 60 * 24 * 7 +``` + +The value is specified in seconds. The above line will make prosody +delete files after a week. + +If it is for some reason neccessary, you can also manually invoke expiry +with the following command: + +```cfg +prosodyctl mod_http_upload expire +``` + +### Other things to check + +Check the config file for other settings you might want to change. For +example, if you want to run a general public XMPP server, you can allow +anyone to create an account by changing `allow_registration` to `true`. + +Another thing you can do is enable the `csi_simple` module, which will +add some optimizations for mobile devices. + +Another thing worth noting is the `archive_expires_after = "1w"` line. +This specifies after how long message archives will be deleted. + +Also the `smacks` module helps a lot with slow internet connections. + +## Certificates + +Obviously, we want to have client-to-server and server-to-server +encryption. Nowadays, use can use Certbot to generate certificates and +use a convenient command below `prosodyctl` to import them. + +**If you have multi-user chat enabled, be sure to get a certificate for +that subdomain as well.** Include the `--nginx` option assuming you have +an Nginx server running. + +```sh +certbot -d chat.example.org --nginx +``` + +**If you have file sharing enabled, be sure to get a certificate for +those subdomains as well.** + +```sh +certbot -d uploads.example.org --nginx +certbot -d proxy.example.org --nginx +``` + +Once you have the certificates for encryption, run the following to +import them into Prosody. + +```sh +prosodyctl --root cert import /etc/letsencrypt/live/ +``` + +Note that you might get an error that a certificate has not been found +if your `muc` subdomain and your main domain share a certificate. It +should still work, this is just notifying you that no specific +certificate for the subdomain. + +**Note:** The above command will need to be rerun when certificates are +renewed. You may want to create a [cronjob](/cron) to have this done +automatically. + +## Creating users/admins manually {#user} + +Let\'s manually create the admin user we prepared for above. Note that +you can indeed do this in your XMPP client if you have not disabled +registration, but this is how it is done on the command line: + +```sh +prosodyctl adduser chad@example.org +``` + +This will prompt you to create a password as well. + +## Make changes active + +With any system service, use `systemctl reload` or `systemctl restart` +to make the new settings active: + +```sh +systemctl restart prosody +``` + +## Using your Server! + +Once your server is set up, you just need an XMPP client to use your new +and secure chat system. + +- GNU/Linux: [Dino](https://dino.im/) or [Gajim](https://gajim.org/) +- Windows: [Gajim](https://gajim.org/) also runs on Windows. +- Android: [Conversations.im](https://conversations.im/) or + [snikket](https://snikket.org/) +- Mac/iOS: [Monal IM](https://monal.im/) or + [Siskin](https://siskin.im/) for iOS alone +- command-line (GNU/Linux, MacOS, Windows): + [Profanity](https://profanity-im.github.io/) +- [See a more complete list kept by + XMPP](https://xmpp.org/software/clients.html) + +Install whichever of these clients you want on your computer or phone +and you can log into your new XMPP server with the account you made. +Note that if you enabled public registration, anyone can create an +account on your server through one of these clients. + +### Account addresses + +XMPP account addressed look just like email addresses: +`username@example.org`. You can message any account on any XMPP server +on the internet with that format. + +### Note on MUCs (multi-user chats) + +Remember that MUCs are kept on a separate subdomain that we created and +should\'ve gotten a certificate for above, for example, +`chat.example.org`. Chatrooms are created and referred to in the +following format: `#chatroomname@chat.example.org`. diff --git a/content/radicale.md b/content/radicale.md new file mode 100644 index 0000000..56d3b0f --- /dev/null +++ b/content/radicale.md @@ -0,0 +1,105 @@ +--- +title: "Radicale" +date: 2021-10-07 +pix: 'radicale.svg' +icon: 'radicale.svg' +tags: ['service'] +short_desc: 'A private calendar, contact and to-do list system.' +--- + +Radicale is an open source calDAV server. CalDAV is a widely supported +internet standard for calendars, todo-lists and contacts. Hosting your +own calDAV server allows sharing calendars between mutliple devices. + +More information can be found on the projects offical website: +[radicale.org](https://radicale.org/3.0.html). + +## Installing Radicale + +Firstly, we have to install radicale on our system, luckily for us +radicale is packaged for the most used distros. + +```sh +apt install radicale apache2-utils +``` + +Next we need to configure Radicale. We configure radicale to be +accessible from other machines, how Radicale handles users and where the +files should be stored. Open /etc/radicale/config with your favourite +editor and add this configuration. + +```systemd +[server] +# Bind all addresses +hosts = 0.0.0.0:5232, [::]:5232 + +[auth] +type = htpasswd +htpasswd_filename = /etc/radicale/users +htpasswd_encryption = bcrypt + +[storage] +filesystem_folder = /var/lib/radicale/collections +``` + +As you can see under \[auth\] we use htpasswd to manage the users. +Execute the following command to add a new user to Radicale. + +```sh +htpasswd -c /etc/radicale/users username +``` + +As Radicale stands now it is fully functional and after starting it by +executing its binary, can be accessed under example.org:5232. But there +are two additional things we can do to make using and managing Radicale +way easier. + +### Setting up a Nginx reverse proxy + +Because the URL of your Radicale server is an URL you will have to +remember and enter it on any device you want to use your calendar on it +is advised to set up a reverse proxy. + +```nginx +server { + listen 443 ssl; + listen [::]:443 ssl; + server_name cal.example.org; + location / { + proxy_pass http://localhost:5232/; # The / is important! + } + # You can also leave these two lines out and use certbot + ssl_certificate /etc/ssl/nginx/cal.example.com/fullchain.pem; + ssl_certificate_key /etc/ssl/nginx/cal.example.com/privkey.pem; +} +``` + +### Run as a service + +Running Radicale as a service makes managing it much easier. Add this +config to /etc/systemd/system/radicale.service. + +```systemd +[Unit] +Description=A simple CalDAV (calendar) and CardDAV (contact) server + +[Service] +ExecStart=/usr/bin/env python3 -m radicale +Restart=on-failure + +[Install] +WantedBy=default.target +``` + +After creating the config load, start and enable the service with the +following commands. + +```sh +systemctl daemon-reload +systemctl enable --now radicale +``` + +## Contribution + +Author: Jocomol -- [jocomol.ch](https://jocomol.ch) \-- XMR: +`41kLv68Nk4N3zvTRFYtHZfRRFMgXkxK2FcXDeCSa4yNwBGTBa1WQ8HtXL8cCAcoZ2iSLBCS6HQqdpRSf56ecMBgWTkn2ARt`{.crypto} diff --git a/content/rss-bridge.md b/content/rss-bridge.md new file mode 100644 index 0000000..5876d88 --- /dev/null +++ b/content/rss-bridge.md @@ -0,0 +1,114 @@ +--- +title: "RSS Bridge" +date: 2021-07-05 +tags: ['service'] +icon: 'rss.svg' +short_desc: 'Creates RSS feeds for normie sites like Facebook.' +--- +RSS Bridge is a useful utility you can use to help you avoid the big +tech sites, like Facebook and Twitter, which instead of the feed you +usually would see, will be a based and minimalist RSS feed. + +You\'ll need a server or VPS. Nearly any Operating system is supported +but for this tutorial I\'m gonna presume you\'re using a Debian-based +OS. You\'ll also need a domain name pointing to your server\'s IP +address [which is explained in this tutorial.](/basic/dns) + +## Installation + +### Setting Up and Configuring + +First things first you\'ll need to make sure that you\'ve hardened you +SSH so that password authentication is disabled and you\'ll also want to +setup Fail2Ban. There\'s a great tutorial on how to do this [which can be read here.](/sshkeys) + +Next we\'ll install the required packages: + +```sh +apt install -y curl unzip nginx certbot php-fpm php-mysql php-cli php7.4-mbstring php7.4-curl php7.4-xml php7.4-sqlite3 php7.4-json +``` + +We now have to create the website configuration file. Create/open the a +file below: + +```sh +nano /etc/nginx/sites-available/rss-bridge +``` + +And add the following content: + +```nginx +server { + root /var/www/rss-bridge; + index index.php index.html index.htm index.nginx-debian.html; + server_name rss-bridge.example.org; + + location / { + try_files $uri $uri/ =404; + } + + location ~ \.php$ { + include snippets/fastcgi-php.conf; + fastcgi_pass unix:/var/run/php/php7.4-fpm.sock; + } + + location ~ /\.ht { + deny all; + } +} +``` + +After you have saved the file, you need to create a symlink so the +server actually will read the file. + +```sh +ln -s /etc/nginx/sites-available/rss-bridge /etc/nginx/sites-enabled/rss-bridge +``` + +Then we have to create the folder where the service will reside in. + +```sh +mkdir -p /var/www/rss-bridge +cd /var/www/rss-bridge +``` + +Lets download the latest version of RSS-Bridge in the directory. + +The newest version can be found +[here](https://github.com/RSS-Bridge/rss-bridge/releases), at the time of +writing that is \"RSS-Bridge 2021-04-25.\" + +```sh +wget https://github.com/RSS-Bridge/rss-bridge/archive/refs/tags/2021-04-25.zip +``` + +Unzip the file: + +```sh +unzip 2021-04-25.zip +``` + +This will create a directory called rss-bridge-version-number, we now +want to move all the file contents of the newly created directory to the +one we are in + +```sh +mv rss-bridge-2021-04-25/* . +rm -rf rss-bridge-2021-04-25 2021-04-25.zip +``` + +Now all we need to do is grant read/write permissions and reload the web +server. + +```sh +chown -R www-data:www-data /var/www/rss-bridge +systemctl reload nginx +``` + +That\'s it, you should now have a working rss-bridge installed. But you +should definately get an SSL certifcate installed [which is done briefly here](/basic/certbot). + +- [handskemager.xyz](https://handskemager.xyz) +- Bitcoin: `bc1qhfjgwjzksf2auqjefwpvq20wvyugq3lhqgkxvu`{.crypto} +- Monero: + `88cPx6Gzv5RWRRJLstUt6hACF1BRKPp1RMka1ukyu2iuHT7iqzkNfMogYq3YdDAC8AAYRqmqQMkCgBXiwdD5Dvqw3LsPGLU`{.crypto} diff --git a/content/rsync.md b/content/rsync.md new file mode 100644 index 0000000..b2ccc07 --- /dev/null +++ b/content/rsync.md @@ -0,0 +1,104 @@ +--- +title: "Rsync: Upload and Sync Files and Websites" +date: 2021-07-01 +img: 'rsync.png' +tags: ['server'] +--- + +rsync is a simple way to copy files and folders between your local computer and +server. While you can install [Nextcloud](/nextcloud) is a more normie-friendly +Dropbox/Google Drive-like way to share files, people familiar with the +command-line will find all they need in the simple `rsync` command. + +It not only makes file-transfer easy, but it allows you to build and +maintain your website offline, then easily upload it to the proper +directory on your server so you don\'t need to constantly be logged into +your server to modify your site. + +## Installing rsync + +Run the following on your server *and* on your local machine. + +```sh +apt install rsync +``` + +## Uploading files with rsync + +From your local machine you can upload files to your server like this: + +```sh +rsync -rtvzP /path/to/file root@example.org:/path/on/the/server +``` + +You will be prompted for the root password and then uploading will +commence. + +If you omit **root@**, rsync will not attempt to log in as root, but +whatever your local username is. + +### Options to rsync + +In this command, we give several options to rsync. You can remove some of these +or add to them based on your needs: + +- `-r` -- run recurssively (include directories) +- `-t` -- transfer modification times, which allows skipping files + that have not been modified on future uploads +- `-v` -- visual, show files uploaded +- `-z` -- compress files for upload +- `-P` -- if uploading a large file and upload breaks, pick up where + we left off rather than reuploading the entire file + +Avoid using the commonly used `-a` option when uploading to a server. It can +transfer your local machine\'s user and group permissions to your +server, which might cause breakage. + +But `-a` is useful for making back-ups of important directories. It's an alias for many options at once (`-rlptgoD`)---read `man rsync` for the details. + +### Scriptability + +It\'s a good idea to build your website offline, then make an rsync +script or bash alias like the one above to upload the edited files when +you have made updates. + +### Password-less authentication + +To avoid having to manually input your password each upload, you can set +up [SSH keys](/sshkeys) to securely idenitify yourself and computer +as a trusted. + +### Picky trailing slashes + +rsync is very particular about trailing slashes. This is useful, but can +be confusing to some new users. Suppose we run the following wanting to +mirror our offline copy of our website in the directory we use on our +server (`/var/www/websitefiles/`): + +```sh +❌ rsync -rtvzP ~/websitefiles/ root@example.org:/var/www/websitefiles/ +``` + +This will *not actually do quite what we want*. It will take our local +`websitefiles` directory and put it *inside* `websitefiles` on the +remote machine, ending up with `/var/www/websitefiles/websitefiles`. + +Instead, remove the trailing slash from the remote server location: + +```sh +✅ rsync -rtvzP ~/websitefiles/ root@example.org:/var/www/websitefiles +``` + +`websitefiles/` has been replaced with `websitefiles`, and this will do +what we want. + +## Downloading files with rsync {#downloading-file-with-rsync} + +You may just as easily download files and directories from your server +with rsync: + +```sh +rsync -rtvzP root@example.org:/path/to/file /path/to/file +``` + +If you don't keep a local copy of your website or other things saved on a server🔒, it might be a good idea to set up a [cronjob](/cron) or just a normal script on your local computer that takes back-ups of your website in case of server failure! diff --git a/content/searxng.md b/content/searxng.md new file mode 100644 index 0000000..4797b69 --- /dev/null +++ b/content/searxng.md @@ -0,0 +1,146 @@ +--- +title: "SearXNG" +date: 2022-05-16 +icon: 'searxng.svg' +tags: ['service'] +short_desc: 'Polls dozens of search engines to give you private and complete search results.' +--- + +SearXNG is a free internet metasearch engine which aggregates results +from more than 70 search services. This guide sets up a working instance +that can be accessed using a domain over HTTPS. Features include: + +- Self-hosted +- No user tracking +- No user profiling +- About 70 supported search engines +- Easy integration with any search engine +- Cookies are not used by default +- Secure, encrypted connections (HTTPS/SSL) + +## Installation + +Install the required packages. + +```sh +apt install git nginx -y +``` + +Open http and https ports. + +```sh +iptables -I INPUT 6 -m state --state NEW -p tcp --dport 80 -j ACCEPT +iptables -I INPUT 6 -m state --state NEW -p tcp --dport 443 -j ACCEPT +netfilter-persistent save +ufw allow 80 +ufw allow 443 +``` + +Clone the SearXNG Repository. + +```sh +git clone https://github.com/searxng/searxng searxng +cd searxng +``` + +Installing SearXNG, Filtron and Morty. + +```sh +./utils/searx.sh install all +./utils/filtron.sh install all +./utils/morty.sh install all +``` + +Check that both filtron and morty are running. + +```sh +systemctl status filtron +systemctl status morty +``` + +## Configure Nginx + +Create a new file `/etc/nginx/sites-available/searxng.conf` and add the +following: + +```nginx +server { + + # Listens on http + listen 80; + listen [::]:80; + + # Your server name + server_name searx.example.org; + + # If you want to log user activity, comment these + access_log /dev/null; + error_log /dev/null; + + # Searx reverse proxy + location / { + proxy_pass http://127.0.0.1:4004/; + + proxy_set_header Host $host; + proxy_set_header Connection $http_connection; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Scheme $scheme; + proxy_set_header X-Script-Name /searx; + } + + location /searx/static { + alias /usr/local/searx/searx-src/searx/static; + } + + # Morty reverse proxy + location /morty { + proxy_pass http://127.0.0.1:3000/; + + proxy_set_header Host $host; + proxy_set_header Connection $http_connection; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Scheme $scheme; + } +} +``` + + +Now create a symbolic link to enable this site. + +```sh +ln -s /etc/nginx/sites-available/searxng.conf /etc/nginx/sites-enabled/searxng.conf +``` + +Restart Nginx and SearXNG. + +```sh +systemctl restart nginx +service uwsgi restart searx +``` + +## Configure HTTPS with Certbot + +Install certbot. + +```sh +apt install python3-certbot-nginx +``` + +Install a Let\'s Encrypt SSL certificate to Nginx and optionally let it +configure HTTPS for you. [Detailed instructions and additional information](/basic/certbot). + +```sh +certbot --nginx +``` + +SearXNG should now be available from your domain. + +## Configuration + +You can change settings by editing `/etc/searxng/settings.yml`. + +## Contribution + +Author: goshawk22 -- [website](https://goshawk22.uk) diff --git a/content/selfhosting.md b/content/selfhosting.md new file mode 100644 index 0000000..0aa00b2 --- /dev/null +++ b/content/selfhosting.md @@ -0,0 +1,202 @@ +--- +title: "Self hosting" +date: 2020-08-19 +tags: ['server'] +--- +## Introduction + +When you have a(n old) computer lying around, and you have cheap +electricity and a good internet connection, self hosting might be a good +option for you. + +### Why would you choose selfhosting? + +- You have control over the hardware, and you can upgrade your server + in the future. For example: if you host a file server and your hard + drive goes full, you can simply add another hard drive or upgrade + it. +- No bandwith limits, storage limits, etc. (some VPSes have this) +- It **can** be cheaper than using a VPS. This only is the case if you + got the server for really cheap and your electricity is cheap. +- You can have a media server to consoom your content (for example + with `Jellyfin`). You can technically do this on a VPS, but that + will be more expensive than self hosting. If you have a media + server, you can stream media from your server to more devices. (I + recommend just downloading it on your device, but if you have + multiple devices, this could be a good solution) + +### Downsides + +Some possible downsides of choosing to host at home could be: + +- Your ISP not approving of what you\'re doing. Some ISP\'s do not + condone you hosting at home. Usually when this is the case, it could + be harder if you want to forward ports, or it could be impossible to + get a static IP address. Check your ISP\'s terms of service. + Sometimes, it will say that hosting a webserver, email server, and + more, is not allowed. +- This can also include blocked ports. ISPs can block certain ports to + the world. Sometimes ISPs only block 445/139 (which is for the + better as Samba, using these ports isn\'t really secure and it\'s + outdated). But some ISPs (sadly) block crucial ports like 80 + and/or 443. You need to check this before trying anything. If this + is the case, a way to get around it is to get another ISP or use an + alternative port. A great website to check this is: + [canyouseeme.org](https://canyouseeme.org/). You can also check if + you did the port forwaring correctly here. +- Security. Opening your network to the public could bring security + risks. For example, never open a Samba server to the public, because + it\'s a pretty old protocol, and it has some security + vulnerabilities. Be sure you are forwarding the right port, and + don\'t just forward random ports to the internet. Also, if you are + getting DDoSed, your ISP will temporarily shut down your whole + internet connection. +- When setting up an email server, it can be way harder to not have + your email show up as spam in other\'s people email. If you use a + VPS, this is way easier. +- Space, power consumption and noise. Of course, this differs per + server. + +Your mileage may vary, go and check each of these points, and see if +selfhosting is the right choice for you. Try and calculate your power +consumption and see if your electricity cost is not too expensive. + +For me, the upsides outweighed the downsides, which is why I chose to +host at home. But, this differs with each person and scenario. Go and +research what your exact situation is, before trying anything. Otherwise +you\'ll have to face some bad surprises. + +## Hardware + +### What kind of hardware should you choose? + +If you pay your own electricity bill, power consumption is a big factor. +Most old laptop computers are ideal in the sense that they don\'t use a +lot of power, and if the battery still works, you have a built-in UPS! +The bad thing is, most old laptop computers aren\'t that powerful, and +they lack in upgradability. (you shouldn\'t really be using anything +older than 2006, and I recommend at least a performance equivalant of a +Core 2 CPU) + +If you can find an energy efficient desktop (under 100W), that is a +great option. They are pretty upgradable and they don\'t use a lot of +power. They can also be pretty cheap, but old laptops are usually +cheaper. If you can afford new hardware, and are willing to build a PC, +you can find really power effecient CPU/motherboard combos, and they can +be cheap, for example the Celeron J3060. I recommend a low wattage power +supply or an effecient one for these kinds of builds. Pico PSUs are +pretty tiny and efficient solutions in these builds. + +Of course, if you don\'t pay your electricity bill or cost is not a +problem for you, you can use just about any old desktop (as long as +it\'s not from the 90\'s, I recommend at least a Core 2 chip again, or +an Athlon 64 X2). + +### Usecases + +Of course, hardware choices depend on the usecase. The above +recommendations I gave you work fine for e-mail server, webserver and +fileserver types of applications, but they will struggle to transcode +video if you are going to host a media server. You\'ll need a faster +CPU, but also a faster GPU. As an example, the Athlon 200GE or 3000G are +good and efficient choices for these builds. They are decent CPUs, but +also have a built in GPU that will transcode video just fine. + +If you need a lot of storage, go for a case with a lot of mounts for +hard drives, this way you can easily mount multiple hard drives. Pros of +multiple hard drives are redundancy and speed. Cons could be that they +create more heat and noise. You can\'t use a laptop if you want multiple +drives, except if you use a hard drive caddy for the CD/DVD drive bay. +Some business laptops even support RAID 1 (redundancy) and RAID 0 (speed +and more storage, but you lose your files if one hard drive breaks) this +way. + +## Getting started + +### Installing Debian + +Once you have the machine, you can install the OS. I recommend Debian, +as all of the guides on this website are Debian specific. Debian just +werks as a server OS. + +You\'ll need to burn a Debian install image onto a USB flash drive or a +CD. You can download the image +[here](https://www.debian.org/CD/netinst/), and you can also find +information on how to burn the image onto a USB flash drive or CD there. + +While installing Debian, do not install any desktop environment. But +install an SSH server when you get the chance. Also leave webserver +unchecked, even if you want to use it as a webserver. You\'ll have a +chance to install this later. + +### Port forwaring + +Every time you are going to set up a new server program, you need to +forward a port corresponding to that program. For example, HTTP is port +80, HTTPS is 443, etc. You need to set this up on your router\'s NAT +settings (sometimes just called port forwarding, this differs per +router). These steps differ for each router. Refer to your routers +manual. A simple command to see what your servers IP address is, is to +run `ifconfig` on your server. This shows a lot of network info, but it +will also show your local IP address needed for port forwarding. + +Basic ports: + +- SSH: port 22 (open this port if you want to admin your server + outside your network) +- HTTP: port 80 (open this port if you want basic webserver + functionality) +- HTTPS: port 443 (you should open this port if you are setting up a + webserver because encryption) + +### Static or dynamic IP address + +If you want to host your server at home, make sure you have a static IP +address, or you can change your dynamic IP address to a static one. +Refer to your router settings, some ISPs will have options on this here. +If you can\'t find anything on this, get in touch with your ISP. + +Once you\'ve made sure you have a static IP address, you can find out +what the IP address is with various websites. You can use a search +engine to easily find this out. Write this down as you\'ll need it +later. + +Once you\'re done, you can pretty much follow every guide on this +website, the only difference is that you\'ll need to forward the ports +you\'ll be using for the server. + +### Finding the ports you\'ll need to forward + +If you need to know what port you\'ll need to forward, there\'s a +command for that. Just type `netstat -tulpn` in your servers command +line. If you want to see the name of the programs, you need to run it as +a root user. You can do this by putting `sudo` before the command. + +```txt +Local Address State PID/Program name +0.0.0.0:25 LISTEN 887/master +0.0.0.0:1883 LISTEN 22452/mosquitto +0.0.0.0:445 LISTEN 798/smbd +0.0.0.0:993 LISTEN 381/dovecot +127.0.0.1:3306 LISTEN 560/mysqld +0.0.0.0:587 LISTEN 887/master +0.0.0.0:139 LISTEN 798/smbd +127.0.1.1:12301 LISTEN 412/opendkim +0.0.0.0:143 LISTEN 381/dovecot +0.0.0.0:465 LISTEN 887/master +0.0.0.0:22 LISTEN 472/sshd +:::25 LISTEN 887/master +:::443 LISTEN 1769/apache2 +:::1883 LISTEN 22452/mosquitto +:::445 LISTEN 798/smbd +``` + +*Example output* + +In this example, if you need to find the port number from `dovecot`, you +can look for it in the `Program name` column. Then you can see in the +local address column that the reported local address is `0.0.0.0:993`. +You need to look for the part after the semicolon. In this case it\'s +993. So you\'ll need to forward port 993. + +*Written by [hiddej](https://github.com/hidde-j)* diff --git a/content/sshkeys.md b/content/sshkeys.md new file mode 100644 index 0000000..f1c8c0d --- /dev/null +++ b/content/sshkeys.md @@ -0,0 +1,153 @@ +--- +title: "Log on with SSH Keys" +date: 2021-06-29 +tags: ['server'] +--- +Let\'s generate and use SSH keys on our computer. This allows us to +ensure our identity better than a password ever could. This allows us to +do two main things: + +1. **Password-less login**: With SSH keys, we can permanently designate + our profile on our local computer as safe for our server, allowing + us to bypass password verification when logging into our server. +2. **Prevent hacking**: Since we no longer need a password to log in, + we can simply deactivate password logins on our server altogether, + which prevents hacking from people who may be so lucky as to guess + our password! + +In other words, using an SSH key to login is **both safer, faster and +easier**. + +This is especially useful once you start making scripts on your computer +that interact with your server. You can upload files in the background, +edit your spam filters or anything else from your local computer without +having to input your password each time you touch the server. + +## Generate an SSH key pair + +Generating an SSH key is simple. Just run: + +```sh +ssh-keygen +``` + +It will prompt you for several options and you can generally chose the +default options in each case. It will ask you to optionally include a +password on your SSH key. I generally recommend against this unless you +happen to be using a computer where you don\'t have root access but +someone else does (it does minimize the ease of using an SSH key in our +case). + +### What does this SSH key do? + +Now whenever you use `ssh` to log into a server, you have the public key +of this SSH key pair as your identifier. You can tell your server to +trust this key and it will automatically allow password-less logins from +this computer. + +### Backing up your key + +We will do that momentarily, but first, I recommend you backup your +newly generated key if you plan to use it. If we disable logins to this +one key and then lose the key, we might be locked out of our server. + +I suggest copying your entire `~/.ssh/` directory (user-specific) to a +USB drive and storing it securely. You may also copy it to the same +place on another computer to use the key there. + +## Making your server trust your key. + +Now that you have generated an SSH key, just run the following: + +```sh +ssh-copy-id root@yourdomain.com +``` + +The command will ask for your server\'s root password and log you in +briefly. What this does is that it puts your public SSH key fingerprint +on your server in a file `/root/.ssh/authorized_keys`. This file in turn +allows approved SSH keys to log in without passwords. + +Note that you can also replace **root** with a username of an account on +the server if you had made a non-root user that you\'d like to easily +log into as well. For the username **user**, it will also store the key +in `/home/user/.ssh/authorized_keys`. + +To test if this has worked, now try logging in normally to your server +with ssh: + +```sh +ssh root@yourdomain.com +``` + +It should now let you log in without a password prompt! + +If you find that this does not work try running the following, make sure +you are in the directory where the keys where created. + +```sh +chmod 700 ~/.ssh/ +chmod 644 ~/.ssh/id_rsa.pub +chmod 600 ~/.ssh/id_rsa +chmod 644 ~/.ssh/authorized_keys +``` + +For whatever reason these files due not have the correct permissions +set, as ssh is very picky about correct file permissions this can cause +errors. The above will fix these. + +## Disabling Password Logins for Security + +Once we have authorized ssh keys for all the devices we need, we can +actually just disable password logins. If you\'ve ever looked at your +system logs (`journalctl -xe`) you will find that there are always +hundreds of random Chinese computers trying to brute force every server +connected to the internet with random passwords. They are usually +unsuccessful, but let\'s make it **impossible** for them. + +Log into your server and open the `/etc/ssh/sshd_config` file. Here we +can set settings for our SSH daemon that receives SSH requests. + +Now find, uncomment or create the following three lines and set them all +to **no**: + +```sh +PasswordAuthentication no +ChallengeResponseAuthentication no +UsePAM no +``` + +Once we\'ve done that, we will reload our SSH daemon: + +```sh +systemctl reload sshd +``` + +### We\'re done! + +Now you can log in quickly and password-less-ly to your server, despite +the fact that it is now more secure than ever! + +With these settings, even if a hacker steals or perfectly guesses an +account password, they still cannot log in without an approved SSH key! + +## What if I lose my SSH key?! + +Firstly, don\'t do this. Take every precaution that you have a backup. + +If this does happen, Vultr and most other VPS providers will have a way +out. Log onto their website and select the server you want to log into. + +{{< img src="/pix/ssh-01.png" alt="vultr login" >}} + +In the image above, to the right of your VPS name are a series of icons. +Click on the computer screen-like icon which is the leftmost one. + +This will open up a browser window emulating a terminal and you can +always login with your password here, since logins here count as being +local---they do not use SSH and therefore can indeed validate with +your password even if you have disabled it over SSH. + +From here, simply reverse the settings we set above and you can log in +via SSH with a password and reapprove a newly created SSH key or +whatever you want to do. diff --git a/content/standalone.md b/content/standalone.md new file mode 100644 index 0000000..c466465 --- /dev/null +++ b/content/standalone.md @@ -0,0 +1,40 @@ +--- +title: "Certbot on Standalone Domains and Subdomains" +date: 2021-07-02 +tags: ['server'] +--- + +The command `certbot --nginx` will take an unencrypted website on an +Nginx configuration file, get a certificate for it and change the +configuration to use that certificate and thus HTTPS. + +Sometimes, however, you are given an Nginx configuration template that +already has encryption/HTTPS, so running the automated `certbot --nginx` +is not possible, as it will simply give an error saying that the +certicate that Nginx is looking for doesn\'t already exist and thus the +Nginx config is broken. + +So suppose you want to get a certificate for **pleroma.example.org** +because you are installing Pleroma and the configuration file +presupposes a certificate. In this case you would want to run this: + +```sh +systemctl stop nginx +certbot certonly --standalone -d pleroma.example.org +systemctl start nginx +``` + +What we do here is temporarily turn of Nginx, then run a `certonly` +subcommand that generates a certificate for the domain without changing +or caring about the Nginx configuration. Then we reactivate Nginx, thus +turning back on our webserver. + +The reason we deactivate Nginx is that it uses the ports that Certbot +will want to bind to, and thus we must temporarily turn Nginx off to let +Certbot use those ports. (What it actually does is spin up a dummy +webserver that doesn\'t need to think about the Nginx configuration.) + +This is just a little note of something that might confuse people, but +the three commands above should suffice. If your site is still managed +by Nginx, it should still be able to renew with simple +`certbot renew --nginx` without a problem. diff --git a/content/tor.md b/content/tor.md new file mode 100644 index 0000000..d4fa9fb --- /dev/null +++ b/content/tor.md @@ -0,0 +1,119 @@ +--- +title: "Tor" +date: 2021-06-30 +icon: 'tor.svg' +tags: ['service'] +short_desc: "Set your site up privately on the 'dark web.'" +--- + +Now that you have a website, why not offer it on a private alternative +such as the onion network? + +## Setting up Tor + +### Installing Tor + +First, we need to ensure that our CPU architecture is supported. Ensure +that it is either amd64, arm64, or i386: + + dpkg --print-architecture + +We need to [add the Tor repos to our +system](https://support.torproject.org/apt/tor-deb-repo/) to get the +latest version of Tor: + + apt install -y apt-transport-https gpg + echo "deb [signed-by=/usr/share/keyrings/tor-archive-keyring.gpg] https://deb.torproject.org/torproject.org $(lsb_release -cs) main + deb-src [signed-by=/usr/share/keyrings/tor-archive-keyring.gpg] https://deb.torproject.org/torproject.org $(lsb_release -cs) main" > /etc/apt/sources.list.d/tor.list + +Then we need to add the GPG keys to our keyring: + + curl -s https://deb.torproject.org/torproject.org/A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89.asc | gpg --dearmor > /usr/share/keyrings/tor-archive-keyring.gpg + +Now install Tor: + + apt update + apt install tor deb.torproject.org-keyring + +### Enabling Tor + +Next edit the file `/etc/tor/torrc`, uncommenting the following lines: + + HiddenServiceDir /var/lib/tor/hidden_service/ + HiddenServicePort 80 127.0.0.1:80 + +#### Optional: Running multiple onion services + +If you want to forward multiple virtual ports for a single onion +service, just add more HiddenServicePort lines (replace the 80 with any +unoccupied port). + +If you want to run multiple onion services from the same Tor client, +just add another HiddenServiceDir line. + +Now start and enable Tor at boot: + + systemctl enable --now tor + +If the next command outputs "active" in green you\'re golden! + + systemctl status tor + +Now your server is on the dark web. The following command will give you +your onion address: + + cat /var/lib/tor/hidden_service/hostname + +## Adding the Nginx Config + +From here, the steps are almost identical to setting up a normal website +configuration file. Follow the steps as if you were making a new website +in the webserver [tutorial](/basic/nginx) up until the server block of +code. Instead, paste this: + + server { + listen 127.0.0.1:80 ; + root /var/www/landchad ; + index index.html ; + server_name your-onion-address.onion ; + } + +#### Clarification + +Nginx will listen on port 80 for your *server\'s* localhost. + +The `root` line is the path to whichever website of yours you\'d like to +mirror. + +Now we are almost done, all we have to do is enable the site and reload +nginx which, is also covered in [the webserver +tutorial](nginx.html#enable). + +### Advertise your onion service + +You can add the Onion-Location header to your normal website to +advertise your onion service to Tor users. On your regular site\'s nginx +config, add the following line: + + server { + ... + add_header Onion-Location http://your-onion-address.onion$request_uri; + } + +After doing this and reloading nginx, when visiting your regular site +via Tor, you should see a \".onion available\" button on the address +bar, which should take you to the onion service. + +### Update regularly! + +Make sure to update Tor on a regular basis by running: + + apt update + apt install tor + +#### Note: + +You do [not]{.underline} need to run certbot for an ssl certificate. +HTTP over tor is plenty secure! + +**Contributor** - [tomfasano.co](https://tomfasano.co){target="_blank"} diff --git a/content/ufw.md b/content/ufw.md new file mode 100644 index 0000000..52cd294 --- /dev/null +++ b/content/ufw.md @@ -0,0 +1,223 @@ +--- +title: "Using UFW as a Firewall" +date: 2021-06-30 +tags: ['server'] +--- +**Uncomplicated Firewall** (UFW) is a front-facing program for the more +involved `iptables` firewall program installed in most GNU/Linux +distributions. We can use `ufw` to restrict machines on the internet to +only access the services (SSH, websites etc) you want them to, but it +can also be used to prevent programs on the computer itself from +accesing parts of the internet it shouldn\'t. + +## How to Get It + +Log into your server by pulling up a terminal and typing: + +```sh +ssh root@example.org +``` + +This command will attempt to log into your server and run a remote +shell. If you leave the settings default, it should prompt you for your +password, and you can just copy or type in the password from Vultr\'s +site. + +Some VPS providers automatically install `ufw`, but if you do not have +it installed already, install it in the typical way: + +```sh +apt install ufw +``` + +## First-Time Setup + +You can check the status of `ufw` right now by running: + +```sh +ufw status +``` + +Without any changes, it should report back `Status: inactive`. Let\'s +set it up so that only connections to SSH (standardized at port 22) are +allowed in, and then enable the firewall: + +**Careful!** Enabling `ufw` without allowing SSH will block you from +remoting to your server. Double-check that you have allowed SSH, and if +you have changed the default SSH port, put in *that* number instead. + +```sh +ufw default deny incoming # block all incoming connections by default +ufw allow in ssh # or: ufw allow in 22 +ufw enable +``` + +`ufw` has an internal list of protocols applications, and the ports used +by them. In this case, it knows SSH is on port 22. We\'ll go more in +detail how to view all protocols `ufw` knows about. By default, when you +allow an incoming port, it allows that port both on IPv4 and IPv6. + +With the firewall enabled and allowing only SSH in, all other ports are +protected from incoming requests. To view all your rules, run: + +```sh +ufw status verbose +``` + +A firewall that allows to connect to SSH and their website may look +like: + +```txt +Status: active +Logging: on (low) +Default: deny (incoming), allow (outgoing), deny (routed) +New profiles: skip + +To Action From +-- ------ ---- +22 (SSH) ALLOW IN Anywhere +80,443/tcp (WWW Full) ALLOW IN Anywhere +22 (SSH (v6)) ALLOW IN Anywhere (v6) +80,443/tcp (WWW Full (v6)) ALLOW IN Anywhere (v6) +``` + +If you want to delete e.g. the \'WWW Full\' rule, run: + +```sh +ufw delete allow in 'WWW Full' +ufw reload +``` + +## Enabling Common Services + +You have blocked all incoming ports but SSH, which means no outsiders +would be able to access other services, like an email server or your +website. You should look at the ports your services are open on and +enable them individually. Here is a list of a few common services: + +### Opening Port Numbers + +Suppose you install [a Gemini server](/gemini), which must broadcast +on port 1965. By default `ufw` blocks all incoming connections on all +ports, so whenever you install a new service like this you will have to +tell `ufw` to enable the desired port: + +```sh +ufw allow 1985 +``` + +### Websites: HTTP and HTTPS + +HTTP uses port 80 and HTTPS uses port 443. We can enable them like this: + +```sh +ufw allow 80 +ufw allow 443 +``` + +But `ufw` additionally knows the typical ports of common serives, so you +can also run this: + +```sh +ufw allow http +ufw allow https +``` + +And that will do the same thing. There are also other abbreviations for +common port lists: + +```sh +ufw allow in 'WWW Full' +``` + +To see these other \"apps\" that `ufw` knows by default, run +`ufw app list` + +### Email: IMAP, POP3, and SMTP + +```sh +ufw allow in IMAPS +ufw allow in POP3 +ufw allow in SMTP +ufw allow in 'Postfix SMTPS' +ufw allow in 'Mail Submission' +``` + +## Fine-Tuning Rules + +Instead of denying all ports by default, you may want to deny (ignores +incoming requests) or reject (explicitly tells requests they\'re not +allowed): + +```sh +ufw default allow in +ufw deny in PORT +ufw reject in PORT +ufw reload +``` + +You can add rules to comments to remember what they are there for: + +```sh +ufw allow in PORT comment 'Secret SSH' +ufw reload +ufw status verbose +``` + +Output: + +```txt +To Action From +-- ------ ---- +PORT ALLOW IN Anywhere # Secret SSH +PORT (v6) ALLOW IN Anywhere (v6) # Secret SSH +``` + +To deny outgoing ports: + +```sh +ufw deny out PORT +``` + +Ratelimiting is useful to protect against brute-force login attacks, +like in SSH. Only IPv4 is supported for now. Enable it by running: + +```sh +ufw limit PORT/tcp +``` + +To blocklist IP addresses: + +```sh +ufw deny from IP_ADDRESS +``` + +To read more what you can do with `ufw`, run: + +```sh +man ufw +``` + +## Recovering SSH {#recovering-from-losing-ssh} + +If you have accidentally firewalled yourself from logging on your +computer, you can recover access by using your VPS\'s virtual console. +On Vultr, this is on your VPS\'s menu. To the right of the server name, +It is the leftmost icon that looks like a monitor. + +{{< img src="/pix/ssh-01.png" link="/pix/ssh-01.png" alt="View Console" >}} + +Log in through there, and disable ufw by typing: + +```sh +ufw disable +``` + +## Further Reading + +- `man ufw` 👈 +- [Ubuntu Wiki: + UncomplicatedFirewall](https://wiki.ubuntu.com/UncomplicatedFirewall) +- [Gufw (Graphical UFW)](https://help.ubuntu.com/community/Gufw) + +**Contributor** - [shunter.xyz](https://shunter.xyz) diff --git a/cron.html b/cron.html deleted file mode 100644 index d3c2c1d..0000000 --- a/cron.html +++ /dev/null @@ -1,174 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Cronjobs – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Using Cronjobs to run scheduled tasks</h1></header> - <nav></nav> - <main> - <p> - Cron is a service that lets you run scheduled tasks. These tasks are called <strong> cronjobs. </strong> If you have already followed the initial course you will have already used cron when you set up certbot. - </p> - <h2> What tasks would I want to schedule? </h2> - <p> - You can schedule anything! Some examples of what you might have done already include: - <ul> - <li><code>updatedb</code> to update your <code>locate</code> database</li> - <li><code>certbot</code> to update renewing of your https certs</li> - </ul> - Some tasks that you might <em>want</em> to schedule may include: - <ul> - <li>Package updates - if you really just want to leave your server alone you can automated updating packages on your server</li> - <li>Backups - you may want to backup certain files every day and some every week, this is possible with cron</li> - </ul> - <p> - And many more, anything you can do can be turned into a cronjob. - </p> - - <h2>Basic Cronjobs</h2> - - <p> - This the preferred method for personal tasks and scripts; it's also the easiest to get started with. Run the command <code>crontab -e</code> to access your user's crontab - </p> - - <p> - Once you have figured out the command you want to run you need to figure out how often you want to run it and when. I am going to schedule my system updates once a week on at 3:30 AM on Mondays. - </p> - <p> - We now have to convert this time (Every Monday at 3:30 AM) into a cron time. Cron uses a simple but effective way of scheduling when to run things. - </p> - <p> - Crontab expressions look like this <code>* * * * * command-to-run</code> - The five elements before the command tell when the command is supposed to be run automatically. - <p> - So for our Monday at 3:30 AM job we would do the following: - <p> - <pre><code> .---------------- minute (0 - 59) - | .------------- hour (0 - 23) - | | .---------- day of month (1 - 31) - | | | .------- month (1 - 12) - | | | | .---- day of week (0 - 6) - | | | | | - * * * * * -30 3 * * 1 apt -y update && apt -y upgrade</code></pre> - - <h3>Some notes</h3> - <ul> - <li>On the day of the week option, Sunday is 0 and counting up from there, Saturday will be 6.</li> - <li><code>*</code> designates "everything". Our command above has a <code>*</code> in the day of month and month columns. This means it will run regardless of the day of the month or month.</li> - <li>The hour option uses 24 hour time. 3 = 3AM, while use 15 for 3PM.</li> - </ul> - - <h3>More examples</h3> - <p> - Let's add another job, our backup job (for the purposes of this our backup command is just called <code>backup</code>). - We want to run <code>backup</code> every evening at 11PM. - Once we work out the timings for this we can add the to the same file as the above by running <code>crontab -e</code> This would mean our full crontab would look like this: - <pre><code>0 23 * * * backup</code></pre> - - <h3>Consecutive times</h3> - - <p> - Suppose we want a command to run every weekday. - We know we can put <code>1</code> (Monday), but we can also use <code>1-5</code> - to signify from day 1 (Monday) to day 5 (Friday). - </p> - - <pre><code>0 6 * * 1-5 echo "Wakey, wakey, wagie!" >> /home/wagie/alarm</code></pre> - - <p>The above <code>echo</code> command runs every Monday through Friday at 6:00AM.</p> - - <h3>Non-consecutive times</h3> - - <p> - We can also randomly specify non-consecutive arguments with a comma. - Suppose you have a script you want to run at the midday of the 1st, 15th, and 20th day of every month. - You can specify that by putting <code>1,15,20</code> for the day of the month argument: - </p> - - <pre><code>0 12 1,15,20 * * /usr/bin/pay_bills_script</code></pre> - - <h3>"Every X minutes/days/months"</h3> - - <p>We can also easily run a command every several minutes or months, without specifying the specific times:</p> - - <pre><code>*/15 * * * * updatedb</code></pre> - - <p>This cronjob will run the <code>updatedb</code> command every 15 minutes.</p> - - <h3>Beware of this Rookie Mistake Though...</h3> - - <p> - Suppose you want to run a script once every other month. - You might be <em>tempted</em> write this: - </p> - - <pre><code>* * * */2 *</code></pre> - - <p> - That might <em>feel right</em>, but this script <em>will be running once every minute during that every other month</em>. - You should specify the first two arguments, because with <code>*</code> it will be running every minute and hour! - </p> - - <pre><code>0 0 1 */2 *</code></pre> - - <p>This makes the command run <em>only</em> at 0:00 (12:00AM) on the first day of every two months, which is what we really want.</p> - - <p> - Consult the website <a href="https://crontab.guru">crontab.guru</a> for an intuitive and interactive tester of cronjobs. - </p> - - <h2>User vs. Root Cronjobs</h2> - - <p> - It is important to note that user accounts all have different cronjobs. - If you have a user account <code>chad</code> and edit his crontab with <code>crontab -e</code>, - the commands you add will be run as the <code>chad</code> user, not <code>root</code> or anyone else. - </p> - - <p> - Bear in mind that if you need root access to run a particular command, - you will usually want to add it as root. - </p> - - <h2>System-wide cron directories</h2> - - <p> - <code>crontab -e</code> is the typical interface for adding cronjobs, but it's important to at least know that system-wide jobs are often stored in the file directory. - Some programs which need cronjobs will automatically install them in the following way. - </p> - - <p> - Run the command <code>ls /etc/cron*</code> you should see a list of directories and there contents. The directories should be something like the below: - </p> - <ul> - <li>/etc/cron.d <em>This is a crontab like the ones that you create with</em> <code>crontab -e</code></li> - <li>/etc/cron.hourly</li> - <li>/etc/cron.daily</li> - <li>/etc/cron.weekly</li> - <li>/etc/cron.monthly</li> - </ul> - - <p> - The directories cron.{hourly,daily,weekly,monthly} are where you can put <strong> scripts </strong> to run at those times. You don't put normal cron entries here. I prefer to use these directories for system wide jobs that don't relate to an individual user. - </p> - - <h2>Contribution</h2> - - <ul> - <li>Mark McNally -- <a href="https://mark.mcnally.je">website</a>, <a href="https://www.youtube.com/channel/UCMiInY8BhSUtCarO6uu6i_g">Youtube</a></li> - <li>Edits and examples by Luke</li> - </ul> - - - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/crypto.html b/crypto.html deleted file mode 100644 index 9302e56..0000000 --- a/crypto.html +++ /dev/null @@ -1,86 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>The Case for Crypto for Normal People – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>The Case for Crypto for Normal People</h1></header> - <nav></nav> - <main> - - <p> - A lot of people get nervous about cryptocurrency because it seems like a confusing world that requires risks. - I however, recommend that if you have your own website, you should absolutely allow people to send you tips/donations in the most important two currencies: - Bitcoin (the classic digital gold) - and Monero (the private and cheaper to use version of Bitcoin). - </p> - - <p> - To accept donations costs you absolutely nothing. - It costs you nothing to hold these donations for years before you bother to figure out how it works. - You don't have to do anything now but create a wallet and put a public address up. - </p> - - <h2>Cryptocurrency is the only open source and peer-to-peer currency</h2> - - <p> - The whole point of being an Internet Landchad is that you do not have to rely on centralized platforms running privacy-violating proprietary software which can be used to censor you and others. - </p> - - <p> - Cryptocurrency is the first ever technology that secures digital scarcity and allows people to transact with one another digitally without any intermediary. - </p> - - <p> - Cryptocurrency might be a wild west, but it is the monetary equivalent of free and open source software. - </p> - - <p> - I will not give investment advice about it, but I will say this, independent of the possibility of a bitcoin being worth more than $1 million later this decade, it is a generally good idea for you to have a way to exchange value without some proprietary intermediary system. - </p> - - <p> - It's a good idea for any person to put some spare money in Bitcoin and Monero and encourage their friends to do so for the mere fact that it can be used to exchange and store value you might owe someone. - It's easier than cash and Monero at least is cheap and easy to transact with. - </p> - - <h2>Why Bitcoin and Monero?</h2> - - <p> - Bitcoin obviously is the original cryptocurrency. - It is clunky, old, sometimes expensive to transact with for small amounts, but it is consistent and is coming to function as "digital gold": - a way of storing value over years. - As the Bitcoin network comes to be used by more and more people, companies, countries and others to store value, it also increases the price, which obviously has made many people very rich. - Bitcoin will surge and crash in cycles, but the long-term trend is unambiguously up as more people store value on the network. - </p> - - <p> - Monero is a more recent cryptocurrency that better preserves privacy and fixes nearly all of Bitcoin's other flaws. - All Bitcoin transactions (and those of nearly all cryptocurrencies) are publicly visible on the blockchain. - That means that people can watch where wallets get and spend money, which can be a massive problem. - Monero, however, uses clever cryptography to avoid this. - This makes it the choice "dark web" currency, but because it has many other benefits (low transaction fees (unlike Bitcoin), ASIC resistance) it is now a staple of the internet. - </p> - - <p> - There are many other coins and tokens used for technology projects, but Bitcoin and Monero are by far the most important. - </p> - - <p> - Due to the difference in transaction fees (it is expensive to transact with Bitcoin), you are probably more likely to get more little tips via Monero. - Big donations might come in Bitcoin though. - </p> - - <ul> - <li><a href="bitcoin.html">Get a Bitcoin wallet and accept Bitcoin donations.</a></li> - <li><a href="monero.html">Get a Monero wallet and accept Monero donations.</a></li> - </ul> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> diff --git a/dns.html b/dns.html deleted file mode 100644 index 9dc09c4..0000000 --- a/dns.html +++ /dev/null @@ -1,129 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Connect Your Domain and Server with DNS Records – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Connect Your Domain and Server with DNS Records</h1></header> - <nav></nav> - <main> - - <h2>The Gist</h2> - <p>Now that we have a <a href=domain.html>domain</a> and a <a href="server.html">server</a>, we can connect the two using DNS records. - DNS (domain name system) records are usually put into your registrar and direct people looking up your website to the server where your website and other things will be. - </p> - - <p> - Get your IPv4/IPv6 addresses from Vultr and put them into A/AAAA records on Epik. - Simple process, takes a minute, but here's a guide with a million images just so you know. - </p> - - <h2>Open up your Registrar</h2> - - <p> - As before, we will be using <a href="https://www.epik.com/?affid=we2ro7sa6">Epik</a> as a registrar and <a href="https://www.vultr.com/?ref=8384069-6G">Vultr</a> as a server host. - Go ahead and log into your accounts on both. - Open up Epik, or your registrar, and click on your domain and then a choice for "DNS records." - This is the screen you'll want to see on Epik. - </p> - - <a href=pix/dns-epik.png><img src="pix/dns-epik.png" alt="Blank Epik DNS records"></a> - - <p> - Note that we are on the "External Hosts (A, AAAA)" tab by default. - Epik sometimes adds records to this page once you buy a domain. - If they did, you can go ahead and delete them so they look clean like the picture above. - </p> - - <p> - <strong>All we have to do now is get our IP addresses from Vultr and add new DNS records that will send connections to our server.</strong> - </p> - - <p> - Keep the Epik tab open and open Vultr and we will copy-and-paste our IP addresses in. - </p> - - <h2>Find your server's IP addresses</h2> - - <p> - Looking at your server in the Vultr menu, you should see a number next to it. - Mine here is <code>104.238.126.105</code> as you can see below the server name (which I have named <code>landchad.net</code> after the domain I will soon attach to it). - That is my <strong>IPv4</strong> address. - </p> - <a href=pix/dns-ipv4.png><img src="pix/dns-ipv4.png" alt="See the IPv4 address?"></a> - - - <p> - Copy your IPv4 address and - on Epik, click the "Add Record" record button and add two A entries pasting in your IPv4 address like I've done for mine here. - </p> - - <a href=pix/dns-ipv4-done.png><img src="pix/dns-ipv4-done.png" alt="IPv4 complete"></a> - - <p> - I add two entries. - One has nothing written in the "Host" section. This will direct connections to <code>landchad.net</code> over IPv4 to our IP address. - The second has a <code>*</code> in the "Host" section. - This will direct connections to all possible subdomains to the right place too, - I mean <code>mail.landchad.net</code> or <code>blog.landchad.net</code> and any other subdomain we might want to add later. - </p> - - - <p> - Now let's get our IPv6 address, which is a little more hidden for some reason. - IPv6 is important because we are running out of IPv4 addresses, so it is highly important to allow connections via IPv6 as it will be standard in the future. - Anyway, now back on Vultr, click on the server name. - </p> - - <p>On the server settings, <strong>click on settings</strong> - and we will see we are on a submenu labeled "IPv4" where we see our IPv4 address again. - </p> - - <a href=pix/dns-vultr.png><img src="pix/dns-vultr.png" alt="Looking for the IPv6"></a> - - <p> - Now just click on the <strong>IPv6</strong> submenu to reveal your IPv6 address. - </p> - - <a href=pix/dns-ipv6.png><img src="pix/dns-ipv6.png" alt="The IPv6 address"></a> - - <p> - That ugly looking sequence of numbers and letters with colons in between (<code>2001:19f0:5:ccc:5400:03ff:fe58:324a</code>) is my <strong>IPv6</strong> address. - Yours will look something like it. - Now let's put it into Epik. - This time, be sure to select to put in AAAA records as below: - </p> - - <a href=pix/dns-ipv6-done.png><img src="pix/dns-ipv6-done.png" alt="IPv6 complete"></a> - - <p> - Now just click "Save Changes." - It might take a minute for the DNS settings to propagate across the internet. - </p> - - <h2>Test it out!</h2> - - <p> - Now we should have our domain name directing to our new server. - We can check by pinging our domain name, check this out: - </p> - - <img src="pix/dns-ping.png" alt="Pinging landchad.net"> - - <p> - As you can see, our ping to <code>landchad.net</code> is now being directed to <code>104.238.128.105</code>. - That means we have successfully set up our DNS records! - You can also run the command <code>host</code> if you have it, which will list both IPv4 and IPv6 addresses for a domain name. - </p> - - <span class=prev><a href="server.html">Previous: Get a server.</a></span> - <span class=next><a href="nginx.html">Next: Setting up the Webserver</a></span> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/domain.html b/domain.html deleted file mode 100644 index a246c2e..0000000 --- a/domain.html +++ /dev/null @@ -1,146 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Get a Domain Name – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Get a Domain Name</h1></header> - <nav></nav> - <main> - - <h2>Terms</h2> - - <dl> - <dt>Domain name</dt><dd>The name of a website that you type in an address bar. This site's domain name is <code>LandChad.net</code>.</dd> - <dt>Top-level domain (TLD)</dt><dd>The extension of a domain name, like <code>.com</code>, <code>.net</code>, <code>.xyz</code>, etc.</dd> - <dt>Registrar</dt><dd>A service authorized to reserve a domain name for you.</dd> - </dl> - - <p> - When domain names first sell, they usually sell for very cheap, but once someone buys one, they have the rights to it until they decide to sell it, often for much, much more money. - Therefore, it's a good idea to reserve a domain name ASAP, even if you didn't intend on doing anything big with it. - </p> - - <p> - So let's register your domain name! - </p> - - <h2>How</h2> - - <p>Domains can be registered at any accredited <dfn>registrar</dfn>. - In this guide, I will use the registrar <a href="https://www.epik.com/?affid=we2ro7sa6">Epik</a> because it is one of the more high quality and easy to use. - The guides on this site will use Epik, but if you choose to register your domain with one of the <a href="https://www.icann.org/en/accredited-registrars">many, many other registrars</a>, - you can still do most of what Epik does, albeit options and settings might appear in different menus. - </p> - - <h3>Basic info about domain names</h3> - - <ul> - <li>Domain names usually require a <em>very</em> small year fee to keep registered, usually around $12 for most generic TLDs. - There are some "specialty" TLDs that are more expensive, but <code>.com</code>, <code>.xyz</code> and other basic TLDs are that cheap.</li> - <li>Once you own a domain, it is yours as long as you pay the yearly fee, but you can also sell it to someone for however much you want.</li> - <li>Domain names do not hold your data or your website, instead, you add "DNS settings" that direct people connecting to your domain to your IP address. - The purpose of a domain name is so that people don't have to remember your IP address to find your website!</li> - </ul> - - <h3>Looking for domain names</h3> - - <p> - Let's go to <a href="https://www.epik.com/?affid=we2ro7sa6">Epik's site</a> and you can search for domain names. - </p> - - <p> - You can look for whatever domain name you want. - Domains that are already bought and owned by someone else might have the option to "Backorder," but it's always best to get one that is unowned, like these: - </p> - - <a href="pix/domain-search.png"><img src="pix/domain-search.png" alt="Searching for a domain name"></a> - - <p> - Note the differences in prices. - Some "specialty" TLDs like <code>.game</code> and <code>.io</code> charge a much larger fee, although you might want one. - Some domains above, like <code>.xyz</code> and <code>.org</code> have reduced prices for the first year. - </p> - - <p> - Choose the domain you want and buy it. - These <code>.xyz</code> domains are a steal now on sale. - </p> - - <a href="pix/domain-cart.png"><img src="pix/domain-cart.png" alt="Buying a domain name"></a> - - <p> - That's all you have to do to own a domain name! - As you register a domain, you can also setup an automatic payment to pay your fee yearly to keep your domain. - Easy as pie. - </p> - - <p>Now we will get a server to host your website on.</p> - - <span class=next><a href="server.html">Next: Get a Server.</a></span> - - <hr> - - <h2>More info on domains</h2> - - <h3>Privacy</h3> - - <p> - One worry people have when reserving a domain is that a domain registrar requires that you submit a home address! - In fact, it used to be even worse: You could easily look up the information of the owner of a website by looking them up in the public WHOIS database! - </p> - - <p> - Firstly, you can easily register a domain under some other address you don't actually have access to. - The internet police does not go looking to see who lives where. - </p> - - <p> - But more importantly, <em>every good registrar</em> like Epik now includes some kind of WHOIS guard, which is a service that logs a dummy address including a dummy email in the WHOIS database instead of your proper information. - By the way, if the registrar you're looking at requires an extra fee for this service, switch to another. All good registrars should do this for free nowadays. - </p> - - <h3>Registrars to avoid</h3> - - <p> - If you are picking a random registrar to use, it's best to avoid any registrar based in America or Europe. - They are more likely to (1) be under the tacit control or cooperation with the "Five Eyes" and other Western privacy-violating regimes - or (2) be staffed by political partisans who have now made a habit out of seizing domains they want to shut up. - </p> - <p> - (2) is a new, but much bigger problem, and even if you don't plan on posting any political content, there is really no predicting what their standards are going to be in the future. - I recommend <a href="https://www.epik.com/?affid=we2ro7sa6">Epik</a> because it is one of the only English-speaking registrars that does what registrars used to do: register domains without political curation, which is unfortunately now becoming more uncommon. - If you don't want to use Epik, use a registrar based in Russia or China or a country more sympathetic to political criticism. - </p> - - <p>Here are some registrars to explicitly avoid:</p> - - - <ul> - <li>GoDaddy – People always want to go here because it's so well advertized. - They have a long record of censorship and nickeling-and-diming accounts. Just avoid them. - They can be lazy because a lot of people use them because they are often the "default" registrar. - </li> - <li>NearlyFreeSpeech – People have signed up for this minor registrar because of its name that's actually tongue-and-cheek. I will let <a href="https://web.archive.org/web/20210121022350/https://blog.nearlyfreespeech.net/2021/01/19/free-speech-in-2021">this post of theirs</a> speak for itself. - Register a domain here only if you want to have it seized.</li> - <li>Google, Amazon – Maybe this is obvious, but if you are trying to escape the control of Google or Amazon, it is a very self-defeating thing to register your domain with them. Sites like Parler figured this out the hard way.</li> - </ul> - - <p> - If you use one of these registrars, be sure to remove your domains from it ASAP. - That is usually a very easy thing to do, although you can only move a domain to a new registrar once every several months. - Pick a good one and stay put. - Registrars without principled policies maintain the right to seize your domain name on their whim. - Don't think for a minute that this doesn't apply to you. - </p> - <span class=next><a href="server.html">Next: Get a Server.</a></span> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/donate-bitcoin.html b/donate-bitcoin.html deleted file mode 100644 index a5bc901..0000000 --- a/donate-bitcoin.html +++ /dev/null @@ -1,23 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Donate Bitcoin – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Donate Bitcoin</h1></header> - <nav></nav> - <main> - <p>Donate Bitcoin to LandChad.net at the address below:</p> - <p><code>bc1q78m8m73pxdxl6fsup3ywexhjuq3rtclhmxdr5h</code></p> - <p>You may also simply type in <code>landchad.net</code> in most wallets and it will resolve to this address as well.</p> - <p>Here is a QR code for the address:</p> - <img style="max-height:250px" src="pix/btc.png" alt="Bitcoin QR Code"> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/donate-monero.html b/donate-monero.html deleted file mode 100644 index 6e0ae35..0000000 --- a/donate-monero.html +++ /dev/null @@ -1,23 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Donate Monero – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Donate Monero</h1></header> - <nav></nav> - <main> - <p>Donate Monero to LandChad.net at the address below:</p> - <p><code>84RXmrsE7ffCe1ADprxLMHRpmyhZuWYScDR4YghE8pFRFSyLtiZFYwD6EPijVzD3aZiEpg57MfHEr1pGJNPXyJgENMnWrSh</code></p> - <p>You may also simply type in <code>landchad.net</code> in most wallets and it will resolve to this address as well.</p> - <p>Here is a QR code for the address:</p> - <img style="max-height:250px" src="pix/xmr.png" alt="Monero QR Code"> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/federation.html b/federation.html deleted file mode 100644 index 0d4ec94..0000000 --- a/federation.html +++ /dev/null @@ -1,71 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Federation – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Federation</h1></header> - <nav></nav> - <main> - <p> - The internet was supposed to be a place where everyone was an internet LandChad. - Everyone had their own website and email and own services. - Obviously, this site is all about getting back to that ideal. - </p> - - <p> - That's why it's important to understand the concept of <dfn>Federation</dfn> in technology. - It's the idea that instead of one central "node" or site that everyone uses, like Facebook, Twitter, Insta, R*ddit, - people can run their own sites that can nonetheless <em>interact</em> with othersites as easily as if they were the same. - </p> - - <p> - You already know one federated technology: email. - There is no one site for email, but many sites, and all people on all those sites can use email to talk to one another. - You can get censored on Facebook. - You can't get censored on "email." - You could have a Gmail account deleted, but you are not blocked out of the system, as you can go to any number of sites and get a new account or <a href="email.html">make your own server</a> and you can still talk to all your friends via email. - </p> - - <h2>"Federated" Social Media</h2> - - <p> - The idea of Federated Social Media is using that principle used in email, but for other things, like chatting or social media. - </p> - - <p> - Here's an example. - There is some software <a href="pleroma.html">you can install on your server</a> called <a href="https://pleroma.social/">Pleroma</a>. - It can be installed on your site just like a web or email server, but what it does is creates a Twitter-like microblogging site. - You can then have your friends join and use it just like you use Twitter, with you as the admin and deciding policy and you can even format and decorate the site how you want. - </p> - - <h3>It gets even better...</h3> - - <p> - <strong>But here is the clincher.</strong> - Federated social media like Pleroma can interact with other Pleroma servers on the internet in the same way that Gmail's servers can send messages to any other email server. - So you might have 2 people on your Pleroma site, but you can interact with the many thousands of other Pleroma sites. - <p> - - <p> - There is seamless interaction. - You can view, like, share and respond to their posts as if they were part of your own site. - </p> - - - <h3>And it gets even betterer...</h3> - - <p> - Pleroma is based on a protocol called <a href="https://activitypub.rocks/">Activity Pub</a>. - This is also used by other software like <a href="https://joinpeertube.org/">PeerTube</a> (which is a self-hosted YouTube-equivalent), <a href="https://friendi.ca/">Friendica</a> (Facebook equivalent) - </p> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/gemini.html b/gemini.html deleted file mode 100644 index 923a454..0000000 --- a/gemini.html +++ /dev/null @@ -1,103 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>How to set up your own gemini server</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1> Creating and serving gemini capsules </h1></header> - <nav></nav> - <main> - <h2 id="whatis">What is Gemini?</h2> - <p><a href="https://gemini.circumlunar.space" target="_blank">Gemini</a> is a new internet protocol which is different from the HTTP and Gopher. It's much cleaner and has a growing community and audience of hackers.</p> - <h3>Why use gemini protocol?</h3> - <ul> - <li>Gemini capsules (webpages of gemini) are lightweight, minimal, and don't use many resources to operate.</li> - <li>It can run along with your websites. Gemini capsules use port 1965 by default. Your webserver can run at port 80 or 443 along with gemini server at port 1965. </li> - <li>By exploring an alternative protocol, you can check different ways to serve data and blogs.</li> - </ul> - <p>To access any gemini urls i.e. <code>gemini://example.org</code>, you can use any gemini client such as <a href="https://github.com/makeworld-the-better-one/amfora" target="_blank">amfora</a>, <a href="https://gmi.skyjake.fi/lagrange" target="_blank">lagrange</a>, <a href="https://thelambdalab.xyz/elpher/" target="_blank">elpher</a>, etc. - <h2 id="instructions">Instructions</h2> - <h3>Create a gemini user</h3> - <p> - It is most secure and clean to have a separate <code>gemini</code> user, so let's create one: - </p> - <pre><code>useradd -m -s /bin/bash gemini</code></pre> - <p>Now log in as <code>gemini</code> with the following command:</p> - <pre><code>su -l gemini</code></pre> - <p>To create and serve a gemini capsule, we need three basic steps:</p> - <ol> - <li>Content – the webpages in our capsule</li> - <li>TLS certificate – Gemini requires encrypted connection.</li> - <li>Gemini server – the program that makes our capsule available (similar to Nginx for HTTP)</li> - </ol> - <p>As the gemini user, we can create three different directories to simplify the process:</p> - <pre><code>mkdir -p ~/gemini/{content,certificate,server}</code></pre> - <h3>Content</h3> - <p>This will be the directory where your capsule files will be contained. Gemini uses text/gemini markup (in place of HTTP's equivalent HTML). It heavily borrows from Markdown. Similar to .html or .md, gemini uses .gmi as its extension.</p> - <p>To create one gemini file, go inside the <code>content</code> directory and create one <code>index.gmi</code> file.</p> - <pre><code>nano gemini/content/index.gmi</code></pre> - <p>We can add the content we want in our Gemini capsule here:</p> - <pre><code># This is Sample Gemini page -## With header 1 and header 2 -And a short paragraph like this. -=> /index.gmi Link to the same page</code></pre> - <h3>TLS certificate</h3> - <p>Go to the <code>certificate</code> directory which we created earlier and generate a TLS certificate using OpenSSL.</p> - <pre><code>cd ~/gemini/certificate/ -openssl req -new -subj "/CN=<strong>example.org</strong>" -x509 -newkey ec -pkeyopt ec_paramgen_curve:prime256v1 -days 3650 -nodes -out cert.pem -keyout key.pem</code></pre> - <h3>Gemini server</h3> - <h4>Download and prepare the server</h4> - <p>There are <a href="https://gemini.circumlunar.space/software">many gemini server software choices available</a>. - We will use <code>agate</code> server for now. This is a simple gemini server written in Rust.</p> - <p>It's a good idea to always get the most recent version, which you can see <a href="https://github.com/mbrubeck/agate/releases">on the agate releases page</a>. At the time of this writing, that is agate v3.1.0 which we will now download. We will download it to the <code>server</code> directory we made.</p> - <pre><code>cd ~/gemini/server -wget https://github.com/mbrubeck/agate/releases/download/v3.1.0/agate.x86_64-unknown-linux-gnu.gz</code></pre> - <p>Unzip the gz, then rename and make it executable:</p> - <pre><code>gunzip agate.x86_64-unknown-linux-gnu.gz -mv agate.x86_64-unknown-linux-gnu agate-server -chmod +x agate-server</code></pre> - <h4>Create a system service</h4> - <p>Now we need to create a systemd service to autostart and manage agate. - The gemini user does not have permission to do this, so press <code>ctrl-d</code> to log out of the gemini user and return to root. - As root, create the file below by opening it in your text editor (nano, vim, etc.):</p> - <pre><code>nano /etc/systemd/system/agate.service</code></pre> - <p>Add the following content to the file <strong>customizing highlighted text</strong> to your use.</p> - <pre><code>[Unit] -Description=agate -After=network.target - -[Service] -User=gemini -Type=simple -ExecStart=/home/gemini/gemini/server/agate-server --content /home/gemini/gemini/content --certs /home/gemini/gemini/certificate/ --hostname <strong>example.org</strong> --lang <strong>en-US</strong> - -[Install] -WantedBy=default.target</code></pre> - <p>Now we are ready to run server. Enable and run agate server.</p> - <pre><code>systemctl enable agate -systemctl start agate</code></pre> - <h4>Firewall</h4> - <p>Lastly, if you have a firewall running, remember to open port 1965, which is the port number used by gemini:</p> - <pre><code>ufw allow 1965</code></pre> - <h2>Finalization</h2> - <p>Now your server should be running. If everything went okay, you can access your gemini capsule via any gemini client with a url like this:</p> - <pre><code>gemini://<strong>example.org</strong></code></pre> - <p>Sample gemini site for reference:</p> - <pre><code>gemini://gemini.circumlunar.space</code></pre> - <p>Enjoy your first gemini capsule.</p> - <p> - For information about how to write in "gemtext" the markup language in Gemini, see this site: <a href="https://gemini.circumlunar.space/docs/gemtext.gmi">https://gemini.circumlunar.space/docs/gemtext.gmi</a>. - As you might guess, it also has an analogous gemini capsule here: gemini://gemini.circumlunar.space/docs/gemtext.gmi - </p> - <hr> - <p><em>Written by <a href="https://nihar.page">nihar.page</a></em></p> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/git.html b/git.html deleted file mode 100644 index c304eb9..0000000 --- a/git.html +++ /dev/null @@ -1,190 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Hosting Your Own Git Repositories – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Hosting Your Own Git Repositories</h1></header> - <nav></nav> - <main> - <img class=titleimg src="pix/git.svg"> - <p> - Once you have your own VPS or other Internet-available server, you can - start hosting your own git repositories. The goal of this tutorial is - for you to go from</p> - - <pre><code>git clone github.com/...</code></pre> - - <p>to</p> - - <pre><code>git clone YourLandChadDomainName.xyz/...</code></pre> - - <p> - so you can cultivate your own homegrown, grass-fed code, rather than - relying on a centralized proprietary service like GitHub. - </p> - - <h2>Installing git</h2> - - <p> - You most likely already have it installed on your server, but if not, - run:</p> - - <pre><code>apt install git</code></pre> - - <p> - We don't need any additional software, <code>git</code> itself ships - with everything needed to host a remote repository! - </p> - - <h2>Creating bare repositories</h2> - - <p> - For each repository you want to host, you will need to manually create - what's called a "bare" repository on your server. These hold all the - commits and any other git data needed for your repository, but without - an expanded "index" in which you can just browse all the files of a - certain commit in the file system. - </p> - - <p> - These repositories need to be owned by the <code>git</code> user, and - you should probably pick a directory where you will store them all. One - sane choice is under <code>/srv/git/</code>, and we will use this as the - example directory for the rest of the tutorial, but any other path will - do as well. - </p> - - <h3>Become the git user and create the directory</h3> - - <p> - If you're logged in to your server as root and have <code>git</code> - installed, you can become the <code>git</code> user by executing - </p> - - <pre><code>su git</code></pre> - - <p> - Now navigate to/create your desired directory, for example - </p> - - <pre><code>cd /srv -mkdir git</code></pre> - - <h3>Create the repo</h3> - - <p> - Now you can create the bare repository with - </p> - - - <pre><code>git init --bare my-repo.git</code></pre> - - <p> - By convention, bare repository names end with ".git". - </p> - - <p> - Repeat the above command for any other repositories you want to host. - </p> - - <h2>Syncing local repositories with your server</h2> - - <h3>Set up SSH login for the git user</h3> - - <p> - You will need to be able to login remotely via <code>ssh</code> as the - <code>git</code> user we've used before. To do this, you will either - need to set up a password for the <code>git</code> user by running - <code>passwd git</code>, - or copy your public SSH key from your local machine to - <code>/home/git/.ssh/authorized_keys</code>. - See the <a href="sshkeys.html">SSH keys instructional</a> for details - (just log in as <code>git</code> instead of <code>root</code>). - </p> - - <h3>Syncing a new repository with your server</h3> - <p> - If you've just created a new repository on your local machine, you will - need to tell <code>git</code> where the remote repository is to be able - to sync with it (using commands like <code>git push</code> or - <code>git pull</code>). We do this by defining a "remote" for your - repository. - </p> - - <p> - A remote is just a named URL remembered in your repo's configuration. So - we need a name and a URL. By convention, the "main" remote is called - "origin". The URL has the format <code>user@host:path</code>, where: - </p> - - <ul> - <li> - <code>user</code> is <code>git</code>, the <code>git</code> user - we've already worked with before. - </li> - <li> - <code>host</code> is your domain name. - Alternatively you could even use your server's raw IP address. - </li> - <li> - <code>path</code> is the absolute path to the repository on the - server, in our example <code>/srv/git/my-repo.git</code> - </li> - </ul> - </p> - - <p> - So, to create a new remote, run: - </p> - - <pre><code>git remote add origin git@yourdomain.xyz:/srv/git/my-repo.git</code></pre> - - <p> - Now you'll be able to run <code>git push origin master</code> to push - your commits or <code>git pull origin</code> to pull from the remote. - </p> - - <h3>Syncing an existing repository</h3> - - <p> - If you've already set up your local repository to sync with a service - like GitHub it probably already has a remote called "origin". You can - see your repo's remotes with: - </p> - - <pre><code>git remote -v</code></pre> - - <p> - You can follow the above instructions, substituting an arbitrary other - name other than "origin" to create a differently named remote, e.g. - </p> - - <pre><code>git remote add vps git@...</code></pre> - - <p> - Now you'll be able to push/pull with <code>git push vps master</code> - and <code>git pull vps</code>, respectively. - </p> - - <p> - Or, to completely sever ties with your centralized git provider, first - remove the original origin with: - <code>git remote remove origin</code> - and then follow the instructions as above. - </p> - - <h2>Contribution</h2> - <ul> - <li>Martin Chrzanowski -- <a - href="https://m-chrzan.xyz">website</a>, <a href="https://m-chrzan.xyz/donate.html">donate</a></li> - </ul> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/gitea.html b/gitea.html deleted file mode 100644 index 647d603..0000000 --- a/gitea.html +++ /dev/null @@ -1,109 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Setting up Gitea – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Setting up Gitea</h1></header> - <nav></nav> - <main> - <img class=titleimg src="pix/gitea.svg"> - <p>Gitea allows you to self-host your git repositories similar to <a href="git.html">bare repositories</a>, but comes with additional features that you might know from GitHub, such as issues, pull requests or multiple users. Its advantage over GitLab—another Free Software GitHub clone—is that it is much more lightweight and easier to setup.</p> - <p>Head over to <a href="https://gitea.com">gitea.com</a> to see what it looks like in practice.</p> - <p>Although Gitea is lighter than Gitlab, if you have a VPS with only 512MB of RAM, you will probably have to upgrade. Gitea is more memory-intensive than having just a bare git repository.</p> - - <h2>Installing Gitea</h2> - <p>First install a few dependencies:</p> - <pre><code>apt install curl sqlite3</code></pre> - <p>Unfortunately, Gitea itself is not in the official Debian repos, so we will add a third-party repository for it.</p> - <p>Add the repo's gpg key to apt's trusted keys:</p> - - <pre><code>curl -sL -o /etc/apt/trusted.gpg.d/morph027-gitea.asc https://packaging.gitlab.io/gitea/gpg.key</code></pre> - - <p>Then add the actual repository to apt:</p> - - <pre><code>echo "deb [arch=amd64] https://packaging.gitlab.io/gitea gitea main" > /etc/apt/sources.list.d/morph027-gitea.list</code></pre> - - <p>Now we can install Gitea:<p> - - <pre><code>apt update -apt install gitea</code></pre> - - <p>Since apt automatically enables and starts the Gitea service, it should already be running on port <code>3000</code> on your server!</p> - - <h2>Setting up a Nginx reverse proxy</h2> - <p>You should know how to generate SSL certificates and use Nginx by now. Add this to your Nginx config to proxy requests made to your git subdomain to Gitea running on port 3000:</p> - - <pre><code> -server { - listen 443 ssl; - listen [::]:443 ssl; - ssl_certificate /etc/ssl/nginx/<strong>git.example.org</strong>.crt; - ssl_certificate_key /etc/ssl/nginx/<strong>git.example.org</strong>.key; - server_name <strong>git.example.org</strong>; - location / { - proxy_pass http://localhost:3000/; # The / is important! - proxy_redirect off; - proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; - } -} - </pre></code> - <p>And reload Nginx:</p> - <pre><code>systemctl reload nginx</code></pre> - - <h2>Setting up Gitea</h2> - - <p>If everything worked fine you should now see a setup screen when you go to your configured domain in the browser. The options should be pretty self-explanatory, it is only important to select SQLite3 and to replace the base url and SSH server domain with your own.</p> - - <dl> - <dt>Database Type:</dt> - <dd>SQLite3</dd> - <dt>SSH Server Domain:</dt> - <dd><strong>git.example.org</strong></dd> - <dt>Gitea Base URL:</dt> - <dd><strong>git.example.org</strong></dd> - </dl> - - <p>These and other settings can be changed in a configuration file later so don't worry about making wrong decisions right now.</p> - - <p>After clicking the install button you should now be able to log into your Gitea instance with the account you just created! Explore the settings for more things to do, such as setting up your SSH keys.</p> - - <p>If Gitea does not load fully and has random errors, it is possible that you need to increase your available memory on your VPS. This can usually be done on your VPS-provider's website without too much trouble.</p> - - <h2>A few extras</h2> - <h3>Automatically create a new repo on push</h3> - <p>This is an incredibly useful feature for me. Open up <code>/etc/gitea/app.ini</code> and add <code>DEFAULT_PUSH_CREATE_PRIVATE = true</code> to the <code>repository</code> section like so:</p> - <img src=pix/gitea-push-create.png> - <br> - <p>If you now add a remote to a repository like this</p> - <pre><code>git remote add origin 'ssh://gitea@git.<strong>example.org</strong>/<strong>username</strong>/<strong>coolproject</strong>.git'</code></pre> - <p>and push, Gitea will automatically create a private <code>coolproject</code> repository in your account!</p> - - <h3>Change tab-width</h3> - <p>By default Gitea displays tabs 8 spaces wide, however I prefer 4 spaces. We can change this!</p> - <pre><code>mkdir -p /var/lib/gitea/custom/templates/custom/</code></pre> - <p>And write this into <code>/var/lib/gitea/custom/templates/custom/header.tmpl</code>:</p> - <pre><code><style> -.tab-size-8 { - tab-size: 4 !important; - -moz-tab-size: 4 !important; -} -</style></code></pre> - - - <h2>Contribution</h2> - <ul> - <li><a href="https://phire.cc">phire</a></li> - </ul> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/html.html b/html.html deleted file mode 100644 index 2b5beee..0000000 --- a/html.html +++ /dev/null @@ -1,200 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Make a Simple Webpage – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Make a Simple Webpage</h1></header> - <nav></nav> - <main> - <p> - We now have a webpage that's actually on the real-live internet! - You've already made it! - Now the only issue is putting what you want on your website. - </p> - - <p> - In this little series, we'll overview the basics of HTML and CSS, - the two important languages that will allow you to make a stylish multi-page website. - We will start with HTML. - </p> - - <h2>HTML</h2> - - <p> - HTML is the <strong>h</strong>yper<strong>t</strong>ext <strong>m</strong>arkup <strong>l</strong>anguage. - It is the "language" that all webpages are written in so that all browsers can read and display them properly. - </p> - <p> - A <dfn>markup language</dfn> is <em>not</em> the same as a programming language: - Programming languages specify orders for a computer, while markup languages are ways of specifying the styling of text. - Markup languages are necessary because computers run on mere text, not colors, sizes, headers and other styling things. - </p> - - <p> - Let's understand what HTML is. - In <a href="nginx.html">a previous article</a>, we put this text in your website's <code>index.html</code>. - </p> - - <h3>Paragraphs</h3> - -<p> -Note how this HTML file appears as a webpage: -</p> - - - -<table class=cnp> - <tr> - <td> -<pre><code><!DOCTYPE html> -<h1>My website!</h1> -<p>This is my website. Thanks for stopping by!</p> -<p>Now my website is live!</p></code></pre> - </td> - <td> -<img src=pix/nginx-website.png alt="The webpage as it appears."> - </td> - </tr> -</table> - -<p> -The content between the <code><p></code> and <code></p></code> tag(s) is formatted as different paragraphs. -If you don't use these <code><p></code> tags, the text will not be formatted as separate paragraphs even if you write it as -multiple lines. -Observe if we add lines to the end of this file: -</p> - -<table class=cnp> - <tr> - <td> -<pre><code><!DOCTYPE html> -<h1>My website!</h1> -<p>This is my website. Thanks for stopping by!</p> -<p>Now my website is live!</p> -Here is some more text. -There are no paragraph tags on this stuff. -So it will all appear as one paragraph. -Despite being on multiple lines. - - -Even this!</code></pre> - </td> - <td> -<img src=pix/html-01.png alt="On p tags"> - </td> - </tr> -</table> - -<p> -This will seem strange at first, but this is the use of HTML as a markup -language: it allows you to style your document with tags and write it in whatever way is convenient. -</p> - -<p> -Let's learn more about what HTML can do. -</p> - - -<h3>Headings</h3> - -<p> -In addition to paragraphs (<code><p></code>), we can specify headings with inside <code><h1></h1></code> tags. -Heading tags are for your page's title and section headings in the document: -</p> - -<ul> - <li><code><h<strong>1</strong>></h<strong>1</strong>></code> – Main and largest headings</li> - <li><code><h<strong>2</strong>></h<strong>2</strong>></code> – Subheadings (smaller)</li> - <li><code><h<strong>3</strong>></h<strong>3</strong>></code> – Sub-subheadings (yet smaller)</li> - <li><code><h<strong>4</strong>></h<strong>4</strong>></code> – Etc., etc.</li> -</ul> - - -<table class=cnp> - <tr> - <td> -<pre><code><h1>This is a top-level heading.</h1> - -<p>Here is some paragraph text.</p> - -<p>And here is some more...</p> - -<h2>This is a subheading (h2)</h2> - -<p>And another paragraph.</p> - -<h2>And here is another subheading (Also an h2)</h2> - -<p>Etc. etc...</p></code></pre> - </td> - <td> -<img src=pix/html-02.png alt="On p and h# tags"> - </td> - </tr> -</table> - -<h4>A preview to CSS</h4> - -<p> -It is very important to use headings like this for your pages. - -Notice that on this website, headings come in different colors, text-alignment and sizes for emphasis. -If we use these heading tags, when we clear CSS, we can easily style all <code><h2></code>, for example, -to be the size and color and alignment we want. -</p> - -<h2>Text formatting</h2> - -<p> -HTML can also be used to do text formatting. -We can make bold, italic, underlined or struck through text with more HTML tags: -</p> - -<table class=cnp> - <tr> - <td> -<pre><code><p>This is <b>bold text</b>.</p> - -<p>This is <i>italic text</i>.</p> - -<p>This is <u>underlined</u>.</p> - -<p>This is <s>struck through</s>.</p></code></pre> - </td> - <td> - <img src="pix/html2-01.png" alt="formatted text"> - </td> - </tr> -</table> - - <h2>Semantic Tags</h2> - - <p> - While <code><b></b></code> and <code><i></i></code> - do exist, it's actually better <em>not</em> to use them directly in text. - </p> - - <p> - Try using <code><strong></strong></code> instead of <code><b></b></code> and <code><em></em></code> instead of <code><i></i></code>. - By default, they will look exactly the same. - You complain that they require more key presses, but it's thought to be a very bad idea to modify lower-level tags with CSS directly. - </p> - - <p> - Note that some bold words on this site have <strong>different color for emphasis</strong>. - This is a setting set via CSS for all <code><strong></code> tags. - It would not be a good idea for us to use this for <code><b></code>, since there might be a non-colored situation we want to occasionally use it in. - </p> - - <span class=next><a href="html2.html">Next: Images and Links in HTML</a></span> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/html2.html b/html2.html deleted file mode 100644 index e263676..0000000 --- a/html2.html +++ /dev/null @@ -1,27 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Images and Links in HTML – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Images and Links in HTML</h1></header> - <nav></nav> - <main> - <h2>Links</h2> - <p> - We need to create links - </p> -<<++>> -<<++>> -<<++>> -<<++>> - <span class=next><a href="<++>">Next:<++></a></span> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/html4.html b/html4.html deleted file mode 100644 index 5653ddc..0000000 --- a/html4.html +++ /dev/null @@ -1,99 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Doing HTML Right – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Doing HTML Right</h1></header> - <nav></nav> - <main> - - <p> - We've noted that HTML is very forgiving - </p> - - <h2>A look at a decent template</h2> - - <p> - I have a template file that I use for this website that includes all the basics. - When I make a new page, I just copy the template and add the content. - Here is what the template looks like: - </p> -<code><pre><!DOCTYPE html> -<html lang=en> - <head> - <title><strong>Your page title</strong></title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='<strong>Site Title</strong> RSS' href='/rss.xml'> - </head> -<body> - <header><h1><strong>Your page title</strong></h1></header> - - <nav></nav> - - <main> - - <strong>Put all your page content here in the <main> tag.</strong> - - </main> - - <footer></footer> -</body> -</html></code></pre> - - <h3>Explanation of All These Important Things</h3> - - <ul> - <li><code><head></code> contains page metadata, including: - <ul> - <li><code><title></code>, the page title that appears in a browser tab.</li> - <li>The <code>charset</code>, which tells the browser what encoding to use (this ensures unicode characters will display)</li> - <li>The <code>favicon</code> is the little site icon that open appears in the browser tab. Just create an <code>.ico</code> file and put it in <code>favicon.ico</code> and each page will read it.</li> - <li>The <code>stylesheet</code> is the CSS stylesheet, which is extremely important for making your site look good and we will get to <a href="css.html">in the CSS lessons</a>.</li> - <li>The <code>RSS</code> feed which is a file you can create to give users updates about your site. <a href="rss.html">We'll talk about making an RSS later too.</a></li> - </ul> - </li> - <li><code><body></code>, which usually designates what content will visibly display.</li> - <li><code><header></code>, which is a semantic tag that where we use to put the main page title in.</li> - <li><code><nav></code>, a place to store a navigation bar later. I use a script to automatically update the bar on all pages and it looks for this tag.</li> - <li><code><main></code>, designates where the main text of the document is.</li> - <li><code><footer></code>, the content appearing at the bottom of the document, I also manage this like nav, with a script.</li> - <li><code><<++>></code>, <++></li> - <li><code><<++>></code>, <++></li> - </ul> - - <h2>The Importance</h2> - - <p> - If you're new to this world, you might be wondering why you should use body and main and nav and header and all this seemingly confusing stuff! - (Especially when even bad HTML displays!) - </p> - - <p> - Not only do many devices, especially mobile ones, specifically use these tags for their features, but - when using CSS, we can also style each of these elements the way you want them to appear without changing the HTML on all your pages. - </p> - - <p> - With CSS, we can say that we might want the whole body to have a image background, but main should be floating over it semi-transparent. - We can tell nav to float off on the left or right and we can change footer and nav settings just by tweaking the CSS. - </p> - - <p> - Speaking of which, we've been talking up CSS for a while, so now it's time to learn it! - </p> - - <span class=next><a href="css.html">Next: Styling with CSS</a></span> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/i2p.html b/i2p.html deleted file mode 100644 index 775bea1..0000000 --- a/i2p.html +++ /dev/null @@ -1,101 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Mirror your site over I2P</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> - <body> - <header><h1>Mirror Your Site Over I2P</h1></header> - <nav></nav> - <main> - <img class=titleimg src="pix/i2p.svg" alt="I2P logo"> - <p> - Now you have a website, why not offer it in a private alternative such as the Invisible Internet? - </p> - - <h2>Setting up I2P</h2> - <p> - There are 2 main I2P implementations, I2P and i2pd, we are using i2pd in this - guide because it's easier to use in servers. - </p> - <h3>Installing I2P</h3> - - <p> - i2pd is in most repos, in debian/ubuntu you can install it simply - with <pre><code>apt install i2pd</code></pre> - </p> - - <h3>Enabling I2P</h3> - <p> - We are going to create a user for i2pd, because i2pd finds the configuration - files in its home directory. And it's easier (and more tidy) to have it in a separate user: - </p> - <pre><code>useradd -m i2p -s /bin/bash -su -l i2p -mkdir ~/.i2pd -cd ~/.i2pd</code></pre> - - <p> - Now that you're in ~/.i2pd, you have to create a file named - "tunnels.conf". Which is the config file for every hidden service you're - offering over I2P, the content should be like this: - </p> - <pre><code>[<strong>example</strong>] -type = http -host = 127.0.0.1 -port = 8080 -keys = <strong>example.dat</strong></code></pre> - - <h3>Getting your I2P Hostname</h3> - - <p> - Then, run <code>/usr/sbin/i2pd --daemon</code> to start i2pd and we can retreive our I2P hostname. - </p> - - <p> - This can be done in lynx or a command-line browser by going to <code>http://127.0.0.1:7070/?page=i2p_tunnels</code> to get your I2P hostname. - </p> - <p> - You - can also run these commands to find your hostname: - </p> - <pre><code>printf "%s.b32.i2p\n" $(head -c 391 /home/i2p/.i2pd/<strong>example.dat</strong> |sha256sum|xxd -r -p | base32 |sed s/=//g | tr A-Z a-z)</code></pre> - - <h2>Adding the Nginx Config</h2> - <p> - From here, the steps are almost identical to setting up a normal website configuration file. - Follow the steps as if you were making a new website on the webserver - <a href="nginx.html">tutorial</a> up until the server block of code. Instead, paste this: - </p> - - <pre><code>server { -listen 127.0.0.1:8080 ; -root /var/www/<strong>example</strong> ; -index index.html ; -}</code></pre> - - <aside> - <h4>Clarifications<h4> - <p> - Nginx will listen in port 8080, but i2pd will forward your port - 8080 to the i2p site port 80. This way you don't have to deal with server names or anything like that - </p> - </aside> - <p> - From here we are almost done, all we have to do is enable the site and reload nginx which is also covered in <a href="nginx.html#enable">the webserver tutorial</a>. - </p> - - <h3>Update regularly!</h3> - - <p>Make sure to update I2P on a regular basis by running:</p> - <pre><code>apt update && apt install i2pd</code></pre> - <p><strong>Contributor</strong> - <a href="https://qorg11.net" target="_blank">qorg11</a></p> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> - </body> -</html> diff --git a/index.html b/index.html deleted file mode 100644 index 84cbeb6..0000000 --- a/index.html +++ /dev/null @@ -1,172 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Chad's Guide to Starting Your Own Website – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> - -<style> -img { border: none ;} -</style> - -<body> - <header><h1>Chad's Guide to Starting Your Own Website</h1></header> - <nav></nav> - <main> - <p> - This is LandChad.net, a site dedicated to turning internet peasants into Internet Landlords - by showing them how to setup websites, email servers, chat servers and everything in between. - </p> - - <p>Starting a website is something that can be done in a lazy afternoon and costs pocket change.</p> - <p>Most of the internet's problems could be solved if more people had their own personal platforms, - so the objective of this site is to guide any normal person through the process of installing a website.</p> - - - <h2>All courses</h2> - - <h3 id=basic>Basic Personal Website Setup</h3> - - <p> - This is the basic "course." Follow these quick tutorials and you'll - have a fully functioning basic web page on the domain name of your - choice. - </p> - - <p> - ⏳ This "basic course" can take <strong>as little as an hour</strong> or even less. - </p> - - <ol class=ll> - <li><a href="domain.html">Get a domain name.</a></li> - <li><a href="server.html">Get a server.</a></li> - <li><a href="dns.html">Set up DNS settings to connect your server and domain name.</a></li> - <li><a href="nginx.html">Set up your web server.</a></li> - <li><a href="certbot.html">Get a secure HTTPS connection with Certbot.</a></li> - </ol> - - <h3 id=other>Excellent Extras</h3> - <ul class=ll> - <li><a href="rsync.html">Rsync: Upload and Sync Files and Websites</a></li> - <li><a href="maintenance.html">How to Maintain a Server.</a></li> - <li><a href="sshkeys.html">Use your SSH keys to prevent hacking.</a></li> - <li><a href="cron.html">Schedule tasks with Crontabs/Cronjobs.</a></li> - <li><a href="cgi.html">Server side scripting with CGI</a></li> - <li><a href="auth.html">Password-protecting Webpages (HTTP Authentication)</a></li> - <li><a href="ufw.html">Using ufw as a firewall.</a></li> - <li><a href="gemini.html">Create a Gemini Capsule.</a></li> - <li><a href="standalone.html">Standalone Certbot Certificates</a></li> - <li><a href="selfhosting.html">Selfhosting on your own server at home</a> - </ul> - - <h3 id=platform>"Build your own platform!"</h3> - - <p>Host your own services, social media and more.</p> - - <dl class=ll> - <dt><a href="xmpp.html"><img src="pix/xmpp.svg" alt="xmpp logo"> XMPP</a></dt><dd>Minimalist and federated chat server</dd> - <dt><a href="pleroma.html"><img src="pix/pleroma.svg" alt="Pleroma logo"> Pleroma</a></dt><dd>A federated Twitter-like microblogging site</dd> - <dt><a href="peertube.html"><img src="pix/peertube.svg" alt="peertube logo"> PeerTube</a></dt><dd>A federated YouTube-like video site</dd> - <dt><a href="nextcloud.html"><img src="pix/nextcloud.svg"> Nextcloud</a></dt><dd>Setting up a Nextcloud Instance (file hosting and more)</dd> - <dt><a href="jitsi.html"><img src="pix/jitsi.svg" alt="Jitsi logo"> Jitsi</a></dt><dd>Free and easy video conferencing</dd> - <dt><a href="git.html"><img src="pix/git.svg"> git</a></dt><dd>Version control software on your own server</dd> - <dt><a href="cgit.html"><img src="pix/cgit.svg"> Cgit</a></dt><dd>A hyperfast web frontend for git repositories</dd> - <dt><a href="gitea.html"><img src="pix/gitea.svg"> Gitea</a></dt><dd>A fully-featured git and issue tracking site</dd> - <dt><a href="irc.html"><img src="pix/irc.svg"> IRC</a></dt><dd>Installing and managing a classic internet relay chat server</dd> - <dt><a href="rss-bridge.html">RSS Bridge</a></dt><dd>Creating RSS feeds for social media sites</dd> - <dt><a href="matrix.html"><img src="pix/element.svg" alt="Element logo">Matrix</a></dt><dd>An easy-to-use, free and federated chat and channel server.</dd> - <dt><a href="calibre.html"><img src="pix/calibre.png"> Calibre</a></dt><dd>A library server</dd> - <dt><a href="i2p.html"><img src="pix/itoopie.svg" alt="Itoopie">I2P</a></dt><dd>Host your site on a private and peer-to-peer internet layer.</dd> - <dt><a href="tor.html"><img src="pix/tor.svg">Tor</a></dt><dd>Host your site on private onion-routing.</dd> - <dt><a href="rainloop.html"><img src="pix/rainloop.svg" style="filter: invert(1);">Rainloop</a></dt><dd>Simple Webmail Client</dd> - </dl> - - <h3 id=crypto>Accepting Cryptocurrency Tips</h3> - <dl class=ll> - <dt><a href="crypto.html">Why crypto?</a></dt><dd>The case for crypto for normal people</dd> - <dt><a href="bitcoin.html"><img src="pix/btc.svg" alt="btc logo"> Bitcoin</a></dt><dd>Accept Bitcoin (BTC) donations</dd> - <dt><a href="monero.html"><img src="pix/xmr.svg" alt="xmr logo"> Monero</a></dt><dd>Accept Monero (XMR) donations for superior privacy</dd> - <dt><a href="openalias.html">OpenAlias</a></dt><dd>OpenAlias to make crypto easy</dd> - <dt><a href="bat.html"><img src="pix/bat.svg"> BAT</a></dt><dd>Receive donations via the Brave browser</dd> - </dl> - - <h2>In the Works...</h2> - - <p> - These articles are still under construction. - Subscribe to our <a href="rss.xml"><img src="pix/rss.svg">RSS feed</a> for updates. - </p> - - <h3>Articles and Tutorials in Progress...</h3> - - <ul> - <li>Full HTML tutorial</li> - <li>Full CSS tutorial</li> - <li>RSS feeds</li> - <li>SearX (search engine)</li> - </ul> - - <h3>On the look out for...</h3> - - <p> - There are other articles not currently under construction which we would like to add the LandChad.net. - If you have experience with any of these, you may submit an article for review on <a href="https://github.com/lukesmithxyz/landchad">the Github</a>. - Please include directions for Debian 11 as default. - Abstain from using containerization (Docker, etc.). - Attempt to follow the same settings as other articles here. - </p> - - <ul> - <li><a href="https://btcpayserver.org/">BTCPay</a> (Docker install permitted only in this case.)</li> - <li>Email webclients</li> - <li>Simple static site generators</li> - <li><a href="https://www.ejabberd.im/">XMPP ejabberd</a></li> - <li><a href="https://movim.eu/">Movim for XMPP</a></li> - <li>Nitter</li> - </ul> - - - <h2>Support LandChad.net</h2> - - <p>Help advertize this site by adding this banner with a link on your website:</p> - - <a href="https://landchad.net"><img src="pix/landchad.gif" alt="LandChad.net"></a> - - <p> - No ads, trackers or trash on this site. - We are funded by doing good and earning gratitude. - Express your gratitude in the following ways: - </p> - - <ul class=ll> - <li>When setting up a website, use our linked affiliate links, like to <a href="https://www.vultr.com/?ref=8384069-6G">Vultr</a> or <a href="https://my.frantech.ca/aff.php?aff=3886">Frantech/BuyVM</a> for a VPS.</li> - <li>If you enjoy a guest article, the author's donation links may be included at the bottom of the page.</li> - <li>Donate crypto to the long-term LandChad maintenance and expansion fund:</li> - </ul> - -<div class=cryptocontainer> -<div class=cryptoinfo> - <p><img style="max-height:1em;max-width:1em" src=pix/xmr.svg> Monero </br> -<code>84RXmrsE7ffCe1ADprxLMHRpmyhZuWYScDR4YghE8pFRFSyLtiZFYwD6EPijVzD3aZiEpg57MfHEr1pGJNPXyJgENMnWrSh</code> </br> - </p> -<a href=pix/xmr.png><img class=qr src=pix/xmr.png></a> -</div> -<div class=cryptoinfo> - <p><img style="max-height:1em;max-width:1em" src=pix/btc.svg> Bitcoin </br> -<code>bc1q9f3tmkhnxj8gduytdktlcw8yrnx3g028nzzsc5</code> </br> - </p> -<a href=pix/btc.png><img class=qr src=pix/btc.png></a> -</div> -</div> - - - - <!--TAGLIST--> - </main> - <!-- <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> --> -</body> -</html> diff --git a/irc.html b/irc.html deleted file mode 100644 index 2d156f8..0000000 --- a/irc.html +++ /dev/null @@ -1,801 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Creating Your Own Chat Server With IRC – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Creating Your Own Chat Server With IRC</h1></header> - <nav></nav> - <main> - <img class=titleimg src="pix/irc.svg"> - <p> - Creating your own chat server for you and your friends is easy, and you don't have to rely on a complicated system to get started. - IRC is an old but gold protocol, and has clients for basically every operating system made since the 80s, with many powerful modern ones on Linux, Mac, and Windows. - </p> - - <p> - Having a chat server for you and your friends makes it impossible for a group of arbitrarily appointed moderators to deplatform you for wrong-think, and gives you greater freedom of communication. - </p> - - <h2 id="installing">Installing an IRCd</h2> - - <p> - An IRCd is short for "IRC daemon", which just means an IRC server. - The most easy IRCd to set up is <a href="https://ergo.chat/">Ergo</a>. - </p> - - <p> - The first thing you need to do is create a new user for the server to be run by. - This is good practice for installing software/servers manually, as it give you more fine-grained control over which permissions the application has. - </p> - -<pre><code>useradd -m ergo -s /bin/bash</code></pre> - - <p> - Next, we want to switch to our newly created <code>ergo</code> user and create the server directory. - </p> - -<pre><code>sudo -i -u ergo -mkdir server</code></pre> - - <p> - You can find the latest release of Ergo on its GitHub <a href="https://github.com/ergochat/ergo/releases/latest">latest release</a> page.<br> - There are several platforms available, but you want to choose Linux, most likely <code>linux-x86_64</code>.<br> - Once you have selected the correct package, copy its URL and replace the release url with the package URL (still as the <code>ergo</code> user): - </p> - -<pre><code>wget https://github.com/ergochat/ergo/releases/download/v2.7.0/ergo-2.7.0-linux-x86_64.tar.gz -tar -xf ergo-2.7.0-linux-x86_64.tar.gz -mv ergo-2.7.0-linux-x86_64/* -rm -r ergo-2.7.0-linux-x86_64*</code></pre> - - <p>Executing <code>ls -l</code> should now yield something like this:</p> - -<pre><code>-rw-r--r-- 1 ergo ergo 118825 Jun 8 00:51 CHANGELOG.md --rw-r--r-- 1 ergo ergo 1983 May 31 01:48 README --rw-r--r-- 1 ergo ergo 41440 Jun 8 00:42 default.yaml -drwxr-xr-x 2 ergo ergo 4096 Jul 1 09:01 docs --rwxr-xr-x 1 ergo ergo 9654272 Jun 8 00:53 ergo --rw-r--r-- 1 ergo ergo 1753 May 31 01:48 ergo.motd -drwxr-xr-x 2 ergo ergo 12288 Jul 1 09:01 languages --rw-r--r-- 1 ergo ergo 39722 Jun 8 00:42 traditional.yaml</code></pre> - - <p>If you see something similar to the above, that means Ergo is installed, although not quite ready to run yet.</p> - - <h2 id="configuring">Configuring Ergo</h2> - - <p> - Now that Ergo is installed, you want to configure it to fit the needs of your group.<br> - The configuration in this section is tailored towards a small group of people, and less for a possibly large network, - but it should work for any size of group. - </p> - - <p> - First thing, make sure you're still using the <code>ergo</code> user, and are in the <code>~/server</code> directory.<br> - If you aren't, you can run the following to get back there: - </p> - -<pre><code>sudo -i -u ergo -cd ~/server</code></pre> - - <p>To start configuring, we need to copy some files:</p> - -<pre><code>cp default.yaml ircd.yaml -cp ergo.motd ircd.motd</code></pre> - - <p> - Next, generate certificate files for TLS: - </p> - - <pre><code>./ergo mkcerts</code></pre> - - <p> - Ergo comes with a default configuration file with detailed documentation that can be used to guide you through the configuration process. - This guide will help you setup the server for a typical use-case, but if you see any settings that you would like to change along the way, - go ahead and change them, as long as you know what you're doing. - </p> - - <p> - The next steps involve editing the newly copied <code>ircd.yaml</code> file. If you do not know how to edit text files from the command line, - you can use <code>nano</code>, which is very simple, using arrow keys to navigate, <code>CTRL+O</code> to save, and <code>CTRL+X</code> to exit.<br> - Another option is <code>vim</code>, which is a much more powerful text editor, but has a learning curve. It is only recommended for this guide if you already know how to use it.<br> - Lastly, you can copy the <code>ircd.yaml</code> file to a text editor on your computer and edit it with a GUI text editor of your choice. - If that is what you choose to do, you may want to just download the file from <a href="https://raw.githubusercontent.com/ergochat/ergo/master/default.yaml">Ergo's GitHub</a>, - edit it on your computer, clear the <code>ircd.yaml</code> file on the server, and then paste the contents from your computer into the blank file.<br> - No matter how you do it, the next steps assume you can edit the configuration file. - </p> - - <p> - <b>Note</b>:<br> - The options highlighted in this section are not a complete overview of all options. - Instead, the options shown are the ones which are most relevant to a small network.<br> - You should read over the configuration file yourself if you are curious about everything you can change. - </p> - - <h3 id="configuring-names">Network and server names</h3> - <p> - One of the first properties in the config file is network name. - You can change this to whatever you like, as it will show up as the name when you connect to the server. - </p> - -<pre><code># network configuration -network: - # name of the network - name: "Land-Chat"</code></pre> - - <p>Change the server name to your server's domain name.</p> - -<pre><code># server configuration -server: - # server name - name: "example.org"</code></pre> - - <h3 id="configuring-password">Network password</h3> - <p> - The next step is optional, depending on if you want your network password protected or not. - The benefit of password protection is fairly obvious; nobody can connect to your network unless you gave them the password. - If you're wanting to run a public network which anyone can join and create a channel, you want to skip this, but for personal setups, - it is highly recommended. - </p> - - <p>Generate a password to use by executing the following:</p> - - <pre><code>./ergo genpasswd</code></pre> - - <p> - It will ask you to enter a password and confirm it, then you will be given a hashed password.<br> - Copy this password, and paste it into the following field (also removing the <code>#</code> before the <code>password:</code> line): - </p> - -<pre><code># password to login to the server, generated using `ergo genpasswd`: -password: "<i><your hashed password></i>"</code></pre> - - <h3 id="configuring-motd">Message of the day (MotD)</h3> - <p>Change the MotD (<b>M</b>essage <b>o</b>f <b>t</b>he <b>D</b>ay) file to the one you copied earlier:</p> - -<pre><code># motd filename -# if you change the motd, you should move it to ircd.motd -motd: ircd.motd</code></pre> - - <p>Feel free to edit <code>ircd.motd</code> to your heart's content. Its contents will be sent to clients when they connect to the network.</p> - - <h3 id="configuring-ip-limits">IP limits</h3> - <p> - For security purposes, you might want to limit the amount of client connections per IP. - For a private network, 4 is likely the maximum amount of connections you will have per IP, so that is a safe value.<br> - If your network is password protected, this is less of an issue, since the only people connecting will be people who have the password. - The following is the default, but you can change it to be whichever value you like: - </p> - -<pre><code># IP-based DoS protection -ip-limits: - # whether to limit the total number of concurrent connections per IP/CIDR - count: true - # maximum concurrent connections per IP/CIDR - max-concurrent-connections: 16</code></pre> - - <h3 id="configuring-ip-cloaking">IP cloaking</h3> - <p> - Traditionally, IRC networks expose users' IP addresses to everyone. This is not a good practice for privacy, however. - With Ergo, IP cloaking is enable by default. You can enable or disable it if you like, and change how it looks to users.<br> - In this case, <code>netname</code> was changed to <code>"chad"</code>. - </p> - -<pre><code># IP cloaking hides users' IP addresses from other users and from channel admins -# (but not from server admins), while still allowing channel admins to ban -# offending IP addresses or networks. In place of hostnames derived from reverse -# DNS, users see fake domain names like pwbs2ui4377257x8.irc. These names are -# generated deterministically from the underlying IP address, but if the underlying -# IP is not already known, it is infeasible to recover it from the cloaked name. -# If you disable this, you should probably enable lookup-hostnames in its place. -ip-cloaking: - # whether to enable IP cloaking - enabled: true - - # whether to use these cloak settings (specifically, `netname` and `num-bits`) - # to produce unique hostnames for always-on clients. you can enable this even if - # you disabled IP cloaking for normal clients above. if this is disabled, - # always-on clients will all have an identical hostname (the server name). - enabled-for-always-on: true - - # fake TLD at the end of the hostname, e.g., pwbs2ui4377257x8.irc - # you may want to use your network name here - netname: "chad"</code></pre> - - <h3 id="configuring-hexchat-password">Password enforcement adjustments for HexChat (and possibly other clients)</h3> - <p> - Ergo offers account registration to allow users to do things like use history and bouncer features, register channels, etc.<br> - In clients such as HexChat, server passwords may conflict with account passwords, so the following setting should be enabled if you wish to use accounts with clients such as HexChat.<br> - Note that this could under some circumstances be considered a security hazard, as a user with an account does not need to know the server password to connect, - although that user would have needed to register an account before the server had a password, and then a password would need to have been set after the fact, so this can be considered a very small concern if your setup has always had a password.<br> - Also keep in mind that this setting has no effect if your network does not even have a password at all. - </p> - -<pre><code># some clients (notably Pidgin and Hexchat) offer only a single password field, -# which makes it impossible to specify a separate server password (for the PASS -# command) and SASL password. if this option is set to true, a client that -# successfully authenticates with SASL will not be required to send -# PASS as well, so it can be configured to authenticate with SASL only. -skip-server-password: true</code></pre> - - <h3 id="configuring-multiclient">Multiclient, always-on clients, history, etc</h3> - <p> - Traditionally, IRC servers have no message history, and once you close your client, you cannot receive messages, and are not shown to be online at all. - Ergo includes functionality to allow users to both receive history, and keep their clients "online" even after they have left. - It also allows multiple clients to connect to the same account.<br> - If you are running a private network for friends, you should set <code>always-on</code> and <code>auto-away</code> to <code>opt-out</code>, - to have all users with accounts to appear as if they are online at all times, and be able to receive messages when they are offline.<br> - For a public network, keep everything as their default values, since you probably do not want randoms having this by default.<br> - If for some reason you do not want any of these features at all, you can set <code>enabled</code> to <code>false</code>, but this is not recommended. - Below are the recommended values for a private network (e.g. for friends) where users with accounts will be able to receive messages and history while they are offline. - </p> - -<pre><code># multiclient controls whether Ergo allows multiple connections to -# attach to the same client/nickname identity; this is part of the -# functionality traditionally provided by a bouncer like ZNC -multiclient: - # when disabled, each connection must use a separate nickname (as is the - # typical behavior of IRC servers). when enabled, a new connection that - # has authenticated with SASL can associate itself with an existing - # client - enabled: true - - # if this is disabled, clients have to opt in to bouncer functionality - # using nickserv or the cap system. if it's enabled, they can opt out - # via nickserv - allowed-by-default: true - - # whether to allow clients that remain on the server even - # when they have no active connections. The possible values are: - # "disabled", "opt-in", "opt-out", or "mandatory". - always-on: "opt-out" - - # whether to mark always-on clients away when they have no active connections: - auto-away: "opt-out" - - # QUIT always-on clients from the server if they go this long without connecting - # (use 0 or omit for no expiration): - #always-on-expiration: 90d</code></pre> - - <h3 id="configuring-vhosts">VHosts</h3> - <p> - IP cloaking was mentioned previously, and somewhat related to that, Ergo includes "vhost" functionality, which allows users to set a custom IP/host string. - This is mostly for cosmetic value, and does not interfere with operators being able to see actual IP addresses for banning, but if you do not want it enable for some reason, you can disable it. - </p> - -<pre><code># vhosts controls the assignment of vhosts (strings displayed in place of the user's -# hostname/IP) by the HostServ service -vhosts: - # are vhosts enabled at all? - enabled: true</code></pre> - - <h3 id="configuring-channels">Channels</h3> - <p> - Channels are where everyone on an IRC network talk. By default, anyone can create a channel, and anyone with an account can register one. - The difference between a normal channel and a registered one is that the registered one will preserve the operator status of the person who created, - whereas a normal channel's owner will lose operator status if they leave the channel or disconnect from the network.<br> - There are various settings for channels available, but the defaults are suitable for a private network with trust among users, or where you just want anyone to have the ability to create a channel. - Below are the default values: - </p> - -<pre><code># channel options -channels: - # modes that are set when new channels are created - # +n is no-external-messages and +t is op-only-topic - # see /QUOTE HELP cmodes for more channel modes - default-modes: +nt - - # how many channels can a client be in at once? - max-channels-per-client: 100 - - # if this is true, new channels can only be created by operators with the - # `chanreg` operator capability - operator-only-creation: false - - # channel registration - requires an account - registration: - # can users register new channels? - enabled: true - - # restrict new channel registrations to operators only? - # (operators can then transfer channels to regular users using /CS TRANSFER) - operator-only: false - - # how many channels can each account register? - max-channels-per-account: 15</code></pre> - - <h3 id="configuring-operators">Operators (administrators, etc)</h3> - <p> - The IRC term for an administrator or another privileged user is "operator", or "oper" for short.<br> - Ergo's opers have different permissions that can be granted to them, and are defined in "classes", basically groups of permissions under a name. - For example, "chat-moderator" and "server-admin" are defined in the default configuration: - </p> - -<pre><code># operator classes -oper-classes: - # chat moderator: can ban/unban users from the server, join channels, - # fix mode issues and sort out vhosts. - "chat-moderator": - # title shown in WHOIS - title: Chat Moderator - - # capability names - capabilities: - - "kill" - - "ban" - - "nofakelag" - - "roleplay" - - "relaymsg" - - "vhosts" - - "sajoin" - - "samode" - - "snomasks" - - # server admin: has full control of the ircd, including nickname and - # channel registrations - "server-admin": - # title shown in WHOIS - title: Server Admin - - # oper class this extends from - extends: "chat-moderator" - - # capability names - capabilities: - - "rehash" - - "accreg" - - "chanreg" - - "history" - - "defcon" - - "massmessage"</code></pre> - - <p> - The above can be kept with their default values, but you are free to modify them or create any new classes that are appropriate for your setup.<br> - Next, let's actually create an operator account: - </p> - -<pre><code># ircd operators -opers: - # default operator named 'gigachad'; log in with /OPER gigachad <password> - "gigachad": - # which capabilities this oper has access to - class: "server-admin" - - # custom whois line - whois-line: is the server administrator - - # custom hostname - vhost: "gigachad" - - # normally, operator status is visible to unprivileged users in WHO and WHOIS - # responses. this can be disabled with 'hidden'. ('hidden' also causes the - # 'vhost' line above to be ignored.) - hidden: false - - # modes are modes to auto-set upon opering-up. uncomment this to automatically - # enable snomasks ("server notification masks" that alert you to server events; - # see `/quote help snomasks` while opered-up for more information): - #modes: +is acjknoqtuxv - - # operators can be authenticated either by password (with the /OPER command), - # or by certificate fingerprint, or both. if a password hash is set, then a - # password is required to oper up (e.g., /OPER dan mypassword). to generate - # the hash, use `ergo genpasswd`. - password: "<i><your oper password></i>"</code></pre> - - <p> - This is a modified version of the default oper entry. The account name is "gigachad", but you can change it to anything.<br> - Replace <code><i><your oper password></i></code> with a password generated by <code>./ergo genpasswd</code>, and you will have a new oper account to use.<br> - Note that to log into an oper account, clients have to enter <code>/OPER <i><oper name></i> <i><oper password></i></code> each time they log in. - This can be automated by most clients by setting the command to be executed when the client logs in. - In the case of HexChat, you can edit your network and add the command to the <code>Connect commands</code> tab of the menu.<br> - You can copy everything from <code>"gigachad"</code> to the end of the line, paste it again, and change the name to create another oper account. - Another, less privileged example of an oper is shown as a comment below the above configuration snippet. - </p> - - <h3 id="configuring-history">Chat history</h3> - <p> - Traditionally, IRC networks do not store, relay, or handle chat history in any way.<br> - On a privacy standpoint, this is a good thing, since chats are entirely ephemeral and handled by clients.<br> - On a practicality standpoint, this is a bad thing, since people have to keep a client connected 24/7 to see message history.<br> - For normalfriends, this can be a big problem, not only because having to stay online 24/7 is just annoying or infeasible, - but also because they are likely used to chat platforms that handle history for them.<br> - With this in mind, enabling history is a good idea if you want to move friends over to IRC, and will make things a lot more pleasant for private networks. - </p> - - <p> - Ergo's <code>history</code> configuration group is very long, so it is encouraged to read over it yourself. - This section will go over the most important pieces of that configuration group. - </p> - - <p> - History is not endless (unless you want it to be), and the amount that can be stored for channels is configurable: - </p> - -<pre><code># how many channel-specific events (messages, joins, parts) should be tracked per channel? -channel-length: 2048</code></pre> - - <p> - History is already enabled by default, but that just means it is being collected, not relayed by default. - To relay history to clients when they connect, change the following to the amount of messages that you think is appropriate: - </p> - -<pre><code># number of messages to automatically play back on channel join (0 to disable): -autoreplay-on-join: 250</code></pre> - - <p> - History older than a certain time can be configured to be deleted or be inaccessible. - The default cutoff time is 1 week, but this is configurable as well. - </p> - -<pre><code> -# options to delete old messages, or prevent them from being retrieved -restrictions: - # if this is set, messages older than this cannot be retrieved by anyone - # (and will eventually be deleted from persistent storage, if that's enabled) - expire-time: 1w -</code></pre> - - <p> - By default, Ergo only stores chat history in memory, so when the server restarts, all history is lost. - If you wish to have chat history persist beyond restarts, you must store it in a MySQL database: - </p> - -<pre><code># options to store history messages in a persistent database (currently only MySQL). -# in order to enable any of this functionality, you must configure a MySQL server -# in the `datastore.mysql` section. -persistent: - enabled: true - - # store unregistered channel messages in the persistent database? - unregistered-channels: true</code></pre> - -<br> - -<pre><code># connection information for MySQL (currently only used for persistent history): -mysql: - enabled: false - host: "localhost" - port: 3306 - # if socket-path is set, it will be used instead of host:port - #socket-path: "/var/run/mysqld/mysqld.sock" - user: "ergo" - password: "hunter2" - history-database: "ergo_history" - timeout: 3s - max-conns: 4 - # this may be necessary to prevent middleware from closing your connections: - #conn-max-lifetime: 180s</code></pre> - - <p> - For privacy reasons, you may want to allow users to delete their own messages in history, or export their messages to JSON: - </p> - -<pre><code># options to control how messages are stored and deleted: -retention: - # allow users to delete their own messages from history? - allow-individual-delete: true - - # if persistent history is enabled, create additional index tables, - # allowing deletion of JSON export of an account's messages. this - # may be needed for compliance with data privacy regulations. - enable-account-indexing: true</code></pre> - - <h3 id="configuring-spam">Spam reduction</h3> - <p> - Most IRC networks have measures in place to reduce chat spam. By default, "fakelag" is enabled in Ergo, and that can deal with most aggregious chat spam.<br> - If you are running a private network where user trust is high, you can disable it so that there are no limits on the speed that messages can be sent. - </p> - -<pre><code># fakelag: prevents clients from spamming commands too rapidly -fakelag: - # whether to enforce fakelag - enabled: true - - # time unit for counting command rates - window: 1s - - # clients can send this many commands without fakelag being imposed - burst-limit: 5 - - # once clients have exceeded their burst allowance, they can send only - # this many commands per `window`: - messages-per-window: 2 - - # client status resets to the default state if they go this long without - # sending any commands: - cooldown: 2s</code></pre> - - <h2 id="using">Starting and using your server</h3> - <p> - Now that Ergo is both installed and configured, you can actually start using it! - </p> - - <h3 id="using-starting">Starting the server</h3> - <p> - First thing, make sure you're still using the <code>ergo</code> user, and are in the <code>~/server</code> directory.<br> - If you aren't, you can run the following to get back there: - </p> - -<pre><code>sudo -i -u ergo -cd server</code></pre> - - <p> - Starting the server is done in one command: - </p> - - <pre><code>./ergo run</code></pre> - - <p> - It will stay online until you close the terminal, or press CTRL+C. Don't worry, the next section goes over how to make it run like a normal server with a SystemD service.<br> - If you have not already, make sure the port <code>6697</code> is not blocked on your server. If you are using UFW as your firewall, - you need to run <code>ufw enable 6697</code> (not as the <code>ergo</code> user, of course).<br> - If you make and configuration changes while the server is running, you can apply them without restarting by typing <code>/rehash</code> as an operator. - </p> - - <h3 id="using-connecting">Connecting to the server</h3> - <p> - To use IRC, you of course need an IRC client. There are many choices available, but the most widely used for Windows and Linux is <a href="https://hexchat.github.io/">HexChat</a>. - On Mac, you have a slightly nicer option with <a href="https://www.codeux.com/textual/">Textual</a>, although you have to <a href="https://github.com/Codeux-Software/Textual/#building-textual">compile it from source</a> if you want to use it for free.<br> - A more user-friendly and modern client choice is TheLounge, which is explained in the last section of this guide, if you want to look into it. - </p> - - <p> - Connecting with HexChat is very easy. When you start it, you will see something like this: - </p> - - <img src="pix/irc/hexchat-network-select.png" alt="HexChat network select"> - - <p> - From there, you should click <code>+ Add</code> and name the server whatever you like (so you can find it on the server list).<br> - Once you have created a new server and named it, select it and click <code>Edit...</code>. - A menu will show up like the one below. Change the domain to whatever domain your server is running on, - and make sure to put in your server password if you set one. - </p> - - <img src="pix/irc/hexchat-network-edit.png" alt="HexChat network edit menu"> - - <p> - Once you're done editing the network, click <code>(X) Close</code>, select your network from the network list, and click <code>Connect</code>.<br> - If all is well, you should be connected! - </p> - - <img src="pix/irc/hexchat-connection-complete.png" alt="HexChat connection complete"> - - <p> - The process is very similar on Textual.<br> - Create a new network and connect to it. Note that it will ask if you want to connect even though the certificate is unsigned. - This is due to the self-signed certificates generated for the server, and is not a problem or security vulnerability, it is just a little annoying. - </p> - - <img src="pix/irc/textual-network-edit.png" alt="Textual network edit menu"> - - <h2 id="service">Surviving restarts with a SystemD service</h3> - <p> - In the beginning of the last section, Ergo was started by simply running <code>./ergo run</code>, but this is only suitable for testing. - To have a proper server setup, you need to run it as a service. This can be achieved via a SystemD service. - </p> - - <p> - Before creating your service file, make sure you are in <code>~/server</code> as the <code>ergo</code> user.<br> - Once you have done that, create a file called <code>start.sh</code> with the following content: - </p> - -<pre><code>#!/bin/bash -./ergo run</code></pre> - - <p>Save the file, then mark it as executable:</p> - - <pre><code>chmod +x start.sh</code></pre> - - <p>Now, create a file called <code>ergo.service</code> with the following content:</p> - -<pre><code>[Unit] -Description=Ergo IRC server -After=network.target -# If you are using MySQL for history storage, comment out the above line -# and uncomment these two instead (you must independently install and configure -# MySQL for your system): -# Wants=mysql.service -# After=network.target mysql.service - -[Service] -Type=simple -User=ergo -WorkingDirectory=/home/ergo/server -ExecStart=/home/ergo/server/start.sh -ExecReload=/bin/kill -HUP $MAINPID -Restart=on-failure -LimitNOFILE=1048576 -# Uncomment this for a hidden service: -# PrivateNetwork=true - -[Install] -WantedBy=multi-user.target</code></pre> - - <p> - You now have your service file, but it is not installed yet. - To install it, switch to your normal user, and execute the following lines to install, enable, and start the SystemD service: - </p> - -<pre><code>ln -s /home/ergo/server/ergo.service /etc/systemd/system/ergo.service -systemctl enable ergo -systemctl start ergo</code></pre> - - <p>Ergo is now installed and running as a service, and will automatically start when the system boots.</p> - - <h2 id="registering">Registering accounts and channels</h2> - <p> - Account and channel registration were mentioned multiple times in this guide, and are indeed very important parts of the modern IRC ecosystem. - You can connect to most IRC networks and talk without creating an account, but you will not be able to reserve your nickname or register channels, so it is important to register an account. - </p> - - <h3 id="registering-accounts">Registering an account with NickServ</h3> - <p> - First, make sure you are connected to your IRC network. - Once you are, type <code>/nickserv help</code> to make sure NickServ (the registration system) is working propertly.<br> - If all is well, type the following, replacing <code><i><your password></i></code> with the password you want to use: - </p> - - <pre><code>/nickserv register <i><your password></i></code></pre> - - <p> - At this point, you are now registered!<br> - The final step is to configure authentication with your client. - </p> - - <p>In HexChat, all that needs to be done is changing <code>Login method</code> to <code>SASL (username + password)</code>, and entering your NickServ password that you used earlier into the password field:</p> - - <img src="pix/irc/hexchat-sasl.png" alt="HexChat SASL in network edit menu"> - - <p> - In Textual, open up your network in the menu, and click <code>Identity</code> under <code>Server Properties</code>. - Enter your password in <code>Personal Password</code>, and check <code>Wait for identification before joining channels</code>. - </p> - - <img src="pix/irc/textual-identity.png" alt="Textual identity menu"> - - <p>You will now be logged into your account when you connect to your network.</p> - - <h3 id="registering-channels">Registering channels with ChanServ</h3> - <p> - Once you have an account registered, you can register channels with ChanServ.<br> - To do so, join the channel you want to register, then type the following, replacing <code><i><your channel></i></code> with the name of the channel you want to register: - </p> - - <pre><code>/chanserv register #<i><your channel></i></code></pre> - - <p> - You are now the channel owner, and are free to appoint operators, administrators, etc for it. - When you go offline, you won't lose ownership, and you cannot be removed as the owner unless you unregister the channel later. - </p> - - <h2 id="moderation">Moderation</h2> - <p> - Like any chat, there will come a point where you need to use moderation tools to keep things under control. - Many IRC setup guides do not go over moderation, so it can be stressful when operators need to actually use moderation tools.<br> - The main difference between IRC and other chat systems in terms of moderation is the difference between channel bans and network bans. - Channel ban keeps a person out of channel a channel, whereas a network ban keeps a person out of the entire network. - </p> - - <h3 id="moderation-masks">Understanding masks</h3> - <p> - Bans are applied "masks", which are formatted pieces of text that contain a user's nick (username), their realname value, and their IP address or host.<br> - This is what a mask looks like: <code>nick!~nick-dude@127.0.0.1</code>.<br> - In bans, asterisks can be used as wildcards, which is useful for banning IP address ranges, patterns of nicknames, or whatever else you can think of.<br> - A ban on the nick <code>person</code>, for example, would look like this: <code>person!*@*</code>.<br> - A ban on anyone with the IP address <code>127.0.0.1</code> would look like this: <code>*!*@127.0.0.1</code> - </p> - - <h3 id="moderation-real-ips">Discovering real IPs</h3> - <p> - Even if IP cloaking is enabled on your network, you can still obtain real IP addresses/hosts if you are an operator. - See the <b>Operators</b> part of the configuration section of this guide on how to become an operator.<br> - To find out a user's real IP, simply type <code>/whois</code> along with the user's nick, and you will see information about the user, along with their real IP address/host.<br> - <code>/whois</code> is not a command that is exclusive to operators, but it does not reveal as much information to non-operators. - </p> - - <h3 id="moderation-network-ban">Banning someone from the network</h3> - <p> - Any netword-wide moderation action requires being an operator. See the <b>Operators</b> part of the configuration section of this guide on how to become an operator.<br> - Banning someone from the network is achieved with the <code>/kline</code> command. To see more info on the command, type <code>/helpop kline</code>.<br> - </p> - - <p>To ban a nick from the network:</p> - - <pre><code>/kline andkill <i><nick></i>!*@*</code></pre> - - <p>To ban an IP address or host from the network:</p> - - <pre><code>/kline andkill *!*@<i><IP or mask></i></code></pre> - - <p>To unban a mask, you can use the <code>/unkline</code> command with the mask you want to unban.</p> - - <h3 id="moderation-channel-ban">Banning someone from a channel</h3> - <p> - Channel owners, administrators, and operators can ban people from channels. - This is not the same as banning someone from the network, since it only has an effect on one channel. - Additionally, a channel operator is not the same as a network operator. - </p> - - <p>To ban someone in a channel, type the following in that channel, replacing <code><i><mask></i></code> with the user's mask:</p> - - <pre><code>/mode +b <i><mask></i></code></pre> - - <p> - Note that this will only ban the user, not kick them immediately. - You will want to run <code>/kick</code> along with the user's nick to also kick them.<br> - To unban a user, run the command above, but replace the <code>+</code> with a <code>-</code>.<br> - You can see who is banned in a channel by typing <code>/banlist</code>. - </p> - - <h3 id="moderation-muting">Muting people in a channel</h3> - <p> - By default, anyone can speak in an IRC channel. To change this, you must be a channel owner, administrator, or operator.<br> - Channels, along with users, have modes, which modify their behavior. There is a special mode for channels called <code>m</code> (moderated) which requires users to be privileged in some way to talk.<br> - To set a channel as moderated, type the following in the channel: - </p> - - <pre><code>/mode +m</code></pre> - - <p> - Now, users must be an owner, administrator, operator, or be voiced to talk in the channel - This be reversed by typing the command above, but changing the <code>+</code> to a <code>-</code>.<br> - To voice a user, run the following, replacing <i><nick></i> with the user's nick: - </p> - - <pre><code>/mode +v <i><nick></i></code></pre> - - <p>Unvoice the user by typing the above command, but replacing the <code>+</code> with a <code>-</code>.</p> - - <h3 id="moderation-appointing">Appointing channel administrators and operators</h3> - <p> - Assuming you a channel owner, you can appoint both administrators and operators. - If you are only an operator, you may only appoint operators.<br> - The difference between administrator and operator is mainly that administrators cannot have their privileges taken away by operators, only owners. - To appoint an administrator, type the following, replacing <i><nick></i> with the user's nick: - </p> - - <pre><code>/mode +a <i><nick></i></code></pre> - - <p>To appoint an operator, type the following, replacing <i><nick></i> with the user's nick:</p> - - <pre><code>/mode +o <i><nick></i></code></pre> - - <p> - You can also use <code>/op</code> and <code>/deop</code> on most clients to appoint and remove an operator.<br> - To remove administrator or operator status, run either of the above commands, but replace the <code>+</code> with a <code>-</code>. - </p> - - <h2 id="thelounge">Bringing modern-day features to IRC with TheLounge</h3> - <p> - A large downside to IRC as a protocol is just how old it is, and the limitations that exist because of it. - Other old protocols such as HTTP were built to be content-agnostic and versitile, but IRC was built with a very specific set of features, so it has not held up so well to contemporary chat systems.<br> - A notable thing that IRC as a protocol is missing is file uploads, and other fancy features that many other chats have.<br> - With that said, these problems can be fixed by clients, although many clients are still very primitive. - </p> - - <p> - <a href="https://thelounge.chat/">TheLounge</a> is a modern self-hosted IRC web client that tries to make IRC as user-friendly as possible. - It can be the answer to many of the complaints that normalfriends may have about IRC. It runs on anything with a web browser, can be "installed" since it is a PWA (Progressive Web App), - and is optimized for both desktops and mobile devices. It keeps you logged in even when you are gone, and even supports file uploads and embeds.<br> - Effectively, it brings IRC up to the standard of most other chat systems. - </p> - - <p> - If you would like to setup an instance of TheLounge for you and your friends, you can take a look at their <a href="https://thelounge.chat/docs/install-and-upgrade">installation guide</a>.<br> - It is a self-hosted web app, so you can run it for multiple people, not just yourself. - </p> - - <hr> - - <p><i>Written by <a href="https://termer.net/">Termer</a></i></p> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/jitsi.html b/jitsi.html deleted file mode 100644 index 3fd42e0..0000000 --- a/jitsi.html +++ /dev/null @@ -1,130 +0,0 @@ -<!-- <!DOCTYPE html> --> -<html lang="en"> - <head> - <title>Jitsi Video Chat – LandChad.net</title> - <meta charset="utf-8" /> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel="stylesheet" type="text/css" href="style.css" /> - <meta name="viewport" content="width=device-width, initial-scale=1" /> - <link rel="alternate" type="application/rss+xml" title="Land Chad RSS" href="/rss.xml" /> - </head> - <body> - <header><h1>Jitsi Video Chat</h1></header> - <nav></nav> - <main> - <img src="pix/jitsi.svg" alt="Jitsi" class=titleimg> - <p> - <dfn>Jitsi</dfn> is a set of open-source projects that allows you to easily build and deploy secure video conferencing solutions. - </p> - <p> - Is really easy to install, and also a really good private, federated and libre alternative to Zoom or other video conferencing software. - You can create calls just by typing the URL, and loging-in is not necessary. - </p> - - <h2>Dependencies and Installation</h2> - - <p>First, install some dependencies:</p> - - <pre><code>apt install gpg apt-transport-https nginx python3-certbot-nginx</code></pre> - - <p>Jitsi has its own package repository, so let's add it.</p> - - <pre class=wide><code>curl https://download.jitsi.org/jitsi-key.gpg.key | gpg --dearmor > /usr/share/keyrings/jitsi-keyring.gpg -echo 'deb [signed-by=/usr/share/keyrings/jitsi-keyring.gpg] https://download.jitsi.org stable/' > /etc/apt/sources.list.d/jitsi-stable.list -apt update -y</code></pre> - - <p> - Ok. So now we can install Jitsi, but before we do that, let's setup the firewall <code>ufw</code>, in case you - have it enabled, and the SSL certificate. - </p> - - <h2>Enable Required Ports</h2> - - <p>If you are using <a href="ufw.html">ufw</a> or another firewall, there are several ports we need to ensure are open:</p> - <pre><code>ufw allow 80/tcp -ufw allow 443/tcp -ufw allow 10000/udp -ufw allow 3478/udp -ufw allow 5349/tcp -ufw enable</code></pre> - - <p>For your information, these allow the following:</p> - - <ul> - <li>80 TCP – Certbot.</li> - <li>443 TCP – General access to Jitsi Meet.</li> - <li>10000 UDP – General network video/audio communications.</li> - <li>3478 UDP – Quering the stun server (coturn, optional, needs config.js change to enable it).</li> - <li> - 5349 TCP – Fallback network video/audio communications over TCP (when UDP is blocked for example), served by coturn. - </li> - </ul> - - <h2>SSL certificate</h2> - - <p> - I'll be using <a href="./certbot.html" target="blank">certbot</a> and - <a href="./nginx.html" target="blank">Nginx</a> to generate a certificate - for the Jitsi subdomain to allow encrypted connections. - </p> - - <pre><code>certbot --nginx certonly -d <strong>meet.example.org</strong></code></pre> - - <p> - We will not create an Nginx config file for Jitsi because the Jitsi package we will be installing will do that automatically. - </p> - - <h2>Installation</h2> - - <p>To begin the installation process, just run:</p> - <pre><code>apt install jitsi-meet</code></pre> - - <p> - It will ask you for your <code><strong>hostname</strong></code - >; there you'll need to input the subdomain you have just added to Nginx, like - <code><strong>meet.example.org</strong></code>. - </p> - - <p>For the SSL certificate, choose <code>I want to use my own certificate</code>.</p> - - <p> - When it ask you for the certification key and cert files, input - <code>/etc/letsencrypt/live/<strong>meet.example.org</strong>/privkey.pem</code> and - <code>/etc/letsencrypt/live/<strong>meet.example.org</strong>/fullchain.pem</code> respectively. - </p> - - <h2>Using Jitsi</h2> - - <img src="pix/jitsi-01.webp" alt="Jitsi once installed"> - - <p>Jitsi can be used in a browser by then just going to <code>meet.example.org</code>.</p> - - <p>Note that there are also Jitsi clients for all major platforms:</p> - - <ul> - <li><a href="https://desktop.jitsi.org/Main/Download.html">Desktop</a> (Windows, MacOS, GNU/Linux)</li> - <li>Android (<a href="https://f-droid.org/en/packages/org.jitsi.meet/">F-Droid</a> and <a href="https://play.google.com/store/apps/details?id=org.jitsi.meet">Google Play</a>)</li> - <li><a href="https://apps.apple.com/us/app/jitsi-meet/id1165103905">iPhone/iOS</a></li> - </ul> - - <p> - <strong>When using a Jitsi app for the first time, remember to go to the "Settings" menu and change your server name to the Jitsi site you just created.</strong> - </p> - - <p>When you create a video chatroom, its address will appear as <code><strong>meet.example.org/yourvideochatname</strong></code> and can be shared as such.</p> - - <h2>More info</h2> - - <p> - This article is based on <a href="https://jitsi.github.io/handbook/docs/devops-guide/devops-guide-quickstart" target="blank">the original documentation</a>. There you can find more details and configurations. - </p> - - <ul> - <li>Written by <a href="https://josefabio.com" target="blank">Jose Fabio.</a> Donate Monero: <code class="crypto">484RLdsXQCDGSthNatGApRPTyqcCbM3PkM97axXezEuPZppimXmwWegiF3Et4BHBgjWR7sVXuEUoAeVNpBiVznhoDLqLV7j</code> <a href="https://josefabio.com/figures/monero.jpg" class="crypto" target="blank">[QR]</a></li> - <li>Edited and revised by <a href="https://lukesmith.xyz">Luke</a>.</li> - </ul> - </main> - - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> - </body> -</html> diff --git a/layouts/partials/footer.html b/layouts/partials/footer.html new file mode 100644 index 0000000..7742c7e --- /dev/null +++ b/layouts/partials/footer.html @@ -0,0 +1,13 @@ + {{ if in .Params.tags "basic" }} + {{ with .NextInSection }} + <a class=next href="{{ .RelPermalink }}">Next: {{ .Title }}</a> + {{ end }} + {{ with .PrevInSection }} + <span class=prev>Or Previous: <a href="{{ .RelPermalink }}">{{ .Title }}</a></span> + {{ end }} + + {{ end }} + </main> + <footer><a href="{{ .Site.BaseURL }}">{{ .Site.BaseURL }}</a></footer> +</body> +</html> diff --git a/layouts/shortcodes/basic.html b/layouts/shortcodes/basic.html new file mode 100644 index 0000000..b2df0d9 --- /dev/null +++ b/layouts/shortcodes/basic.html @@ -0,0 +1,8 @@ +<ol class=ll> +{{range.Site.RegularPages.ByDate}}{{ if in .Params.tags "basic" }}<li> +<a href="{{.Permalink}}"> +{{ with .Params.icon }}<img src="pix/{{ . }}">{{ end }} +<span class=title>{{.Title}}</span> +{{ with .Params.short_desc }}<span class=desc>{{ . }}</span>{{ end }}</a><span style="display:none">{{.Params.Tags}}</span> +</li>{{ end }}{{ end }} +</ol> diff --git a/layouts/shortcodes/maintain.html b/layouts/shortcodes/maintain.html new file mode 100644 index 0000000..a864eab --- /dev/null +++ b/layouts/shortcodes/maintain.html @@ -0,0 +1,4 @@ +<ul class=ll> +{{range.Site.RegularPages.ByTitle}}{{ if in .Params.tags "server" }}<li><a href="{{.Permalink}}">{{ with .Params.icon }}<img src="pix/{{ . }}">{{ end }}<span class=title>{{.Title}}</span>{{ with .Params.short_desc }}<span class=desc>{{ . }}</span>{{ end }}</a><span class=tags>{{.Params.Tags}}</span></li> +{{ end }}{{ end }} +</ul> diff --git a/layouts/shortcodes/services.html b/layouts/shortcodes/services.html new file mode 100644 index 0000000..877140d --- /dev/null +++ b/layouts/shortcodes/services.html @@ -0,0 +1,4 @@ +<ul id=servicelist> +{{range.Site.RegularPages.ByTitle}}{{ if in .Params.tags "service" }}<li><a href="{{.Permalink}}">{{ with .Params.icon }}<img src="pix/{{ . }}">{{ end }}<span class=title>{{.Title}}</span>{{ with .Params.short_desc }}<span class=desc>{{ . }}</span>{{ end }}</a><span class=tags>{{.Params.Tags}}</span></li> +{{ end }}{{ end }} +</ul> diff --git a/maintenance.html b/maintenance.html deleted file mode 100644 index 328f0a8..0000000 --- a/maintenance.html +++ /dev/null @@ -1,125 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Maintaining a Server – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Maintaining a Server</h1></header> - <nav></nav> - <main> - - <p>Here are some important topics you should be familiar with whenever you are managing a server.</p> - <h2 id="update">Keep packages up to date.</h2> - <p>All GNU/Linux distributions use package managers to easily be able to install and update packages without manually downloading them. - On Debian, which we use here for these tutorial the package manager is <code>apt-get</code> or <code>apt</code> for short. - </p> - - <p> - It's a good idea to use <code>apt</code> to keep your software reasonably up to date. - </p> - - <pre><code>apt update -apt upgrade</code></pre> - - <p> - Not only do up-to-date packages often come with more features, but they can also fix any possible security bugs. - </p> - - <h2>Troubleshooting general problems</h2> - <p> - Often when you are installing something new, you might miss a step and run into an error, so it's important to know how to check and see what errors have happened on your computer. - </p> - <p>On Debian and other GNU/Linux distributions that use systemd (most of them), you can use the command <code>journalctl</code> to look at the system's general log. - You will probably want to run <code>journalctl -xe</code> as the <code>-x</code> and <code>-e</code> as that gives the most information and starts you at the bottom of the log to see the most recent errors. - </p> - <p> - Some programs do not use this system log, but have their own logs stored in <code>/var/log/</code>, or sometimes it's more convenient to look at a specific program's log to see only its issues. - </p> - - <p>For example, we can see that in <code>/var/log/nginx/</code>, nginx produces both <code>error</code> and <code>access</code> files. - The <code>access</code> files show you all the times people connect to files on your server and much more. - We can look at the most recent errors by running: - </p> - - <pre><code>tail -n 25 /var/log/nginx/error.log</code></pre> - - <p> - The command <code>tail -n 25</code> means "show me the last 25 lines of this file." - You can replace that with <code>less</code> to browse the whole file. - In <code>less</code>, navigate with arrows or vim-keys and exit with <code>q</code>. - </p> - - <h3>systemctl</h3> - - <p> - Another tool on systemd distributions is <code>systemctl</code>. - At a basic level, use <code>systemctl status put-service-name-here</code> - to see if a system service is running and its most recent log. - But there's much more to <code>systemctl</code>. - </p> - - <p> - For example, you can run <code>systemctl stop nginx</code> to stop NginX and <code>systemctl start nginx</code> to start it back up (or use <code>restart</code> for both). - When you make changes to a program's configuration files, <code>reload</code> well make them reload them. - If you no longer want a service to start when the system is rebooted, use <code>disable</code>, or conversely, to make a service start on reboot use <code>enable</code>. - </p> - - <h2>Finding Files</h2> - - <p> - Especially if you're new to how a GNU/Linux system is arranged, you might need help finding files. - To find program-related files, you can just use <code>whereis</code>: - </p> - <pre><code>$ whereis nginx -nginx: /usr/sbin/nginx /usr/lib/nginx /etc/nginx /usr/share/nginx /usr/share/man/man8/nginx.8.gz</code></pre> - - <p>This command lists the directories related to that program. For example, <code>/etc/nginx</code> is where the configuration files are and <code>/usr/share/nginx</code> is where the library and module-like files are.</p> - <p>But <code>whereis</code> can be used only with installed programs. - A more general tool is the pair of <code>updatedb</code> and <code>locate</code>. - </p> - - <p> - <code>updatedb</code> is a command that quickly indexes every file and directory on your computer. - Then you can run <code>locate</code> to find a file containing a given name. - After running <code>updatedb</code>, try running <code>locate nginx</code> to find all files with "nginx" in their name. - </p> - - <p> - You can make your search more specific by chaining other Unix commands through pipes. - For example, <code>grep</code> takes input and returns only lines that match an extra argument. - In the example below, we <code>locate</code> all files with "nginx" in the name, but we use <code>grep</code> to only show us those with the word "available" in them. - </p> - - <pre><code>root@landchad:~# locate <strong>nginx</strong> | grep <strong>available</strong> -/etc/nginx/modules-available -/etc/nginx/sites-available -/etc/nginx/sites-available/default -/etc/nginx/sites-available/landchad -/usr/share/nginx/modules-available -/usr/share/nginx/modules-available/mod-http-auth-pam.conf -/usr/share/nginx/modules-available/mod-http-dav-ext.conf -/usr/share/nginx/modules-available/mod-http-echo.conf -/usr/share/nginx/modules-available/mod-http-geoip.conf -/usr/share/nginx/modules-available/mod-http-image-filter.conf -/usr/share/nginx/modules-available/mod-http-subs-filter.conf -/usr/share/nginx/modules-available/mod-http-upstream-fair.conf -/usr/share/nginx/modules-available/mod-http-xslt-filter.conf -/usr/share/nginx/modules-available/mod-mail.conf -/usr/share/nginx/modules-available/mod-stream.conf</code></pre> - - <p> - <code>updatedb</code> is an ideal candidate for a <a href="cron.html">cronjob</a> so you don't have to worry about running each time. - For example, adding the following to your crontab will run <code>updatedb</code> every 30 minutes: - </p> - <pre><code>*/30 * * * * /usr/bin/updatedb</code></pre> - <p> - </p> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/matrix.html b/matrix.html deleted file mode 100644 index 32da2da..0000000 --- a/matrix.html +++ /dev/null @@ -1,131 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Matrix Synapse Server – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Matrix Synapse Server</h1></header> - <nav></nav> - <main> - <img src="pix/matrix.svg" alt="Matrix Synapse Logo" class=titleimg> - <p>Matrix is easy-to-use, decentralized and encrypted private chat software. - Matrix is federated, meaning that with a Matrix account on any server, including your own, you can talk to any other Matrix account on the internet, similar to email. - Matrix also allows fully end-to-end encrypted group chats. - </p> - - <p><strong>Synapse</strong> is the name of the default Matrix server. It is written in Python. While it is requires somewhat more system resources than <a href="xmpp.html">an XMPP server</a>, it makes up for that in being very accessible to non-technical users.</p> - - <h2>Installation</h2> - - <p>Synapse is not in the Debian package repositories by default, but we can easily add Matrix's repository including it:</p> - -<pre><code>apt install -y lsb-release wget apt-transport-https -wget -O /usr/share/keyrings/matrix-org-archive-keyring.gpg https://packages.matrix.org/debian/matrix-org-archive-keyring.gpg -echo "deb [signed-by=/usr/share/keyrings/matrix-org-archive-keyring.gpg] https://packages.matrix.org/debian/ $(lsb_release -cs) main" > /etc/apt/sources.list.d/matrix-org.list</code></pre> - <p>After we update our packages lists, we will be able to install Synapse with <code>apt</code>.</p> - -<pre><code>apt update -apt install matrix-synapse-py3</code></pre> - -<p>When prompted, give your main domain name (not a subdomain). This will be the domain appended to your Matrix address, e.g. <code>@chad:landchad.net</code>.</p> - - <h2>Nginx configuration</h2> - - <p>Create an Nginx configuration file for Matrix, say <code>/etc/nginx/sites-available/matrix</code> and add the content below: - </p> - - <pre><code>server { - server_name matrix.<strong>example.org</strong> ; - listen 80; - listen [::]:80; - location / { - proxy_pass http://localhost:8008; - } - location ~* ^(\/_matrix|\/_synapse\/client) { - proxy_pass http://localhost:8008; - proxy_set_header X-Forwarded-For $remote_addr; - client_max_body_size <strong>50M</strong> ; - } - location /.well-known/matrix/server { - return 200 '{"m.homeserver": {"base_url": "https://matrix.<strong>example.org</strong>"}}'; - default_type application/json; - add_header Access-Control-Allow-Origin *; - } -}</code></pre> - - <aside> - <p>Note the <code>client_max_body_size</code> variable. By default, Nginx caps the size of files it can transfer. We increase that to 50M if needed by Matrix. (Note however that both Matrix and Nginx have seperate settings for this and to raise it to something much larger, you will have to increase the value in both congfiguration files.) - </p> - </aside> - - <p>Now let's enable the Nginx Matrix site and reload Nginx to make it active.</p> - - <pre><code>ln -s /etc/nginx/sites-available/matrix /etc/nginx/sites-enabled -systemctl reload nginx</code></pre> - - <h3>Encryption</h3> - - <p>Obviously, we need to encrypt our <code>matrix</code> subdomain as well. Let's do that with certbot:</p> - -<pre><code>certbot --nginx -d matrix.<strong>example.org</strong></code></pre> - - <h2>Configuration</h2> - - <h3>Read the config file</h3> - - <p> - The configuration file for Matrix is in <code>/etc/matrix-synapse/homeserver.yaml</code>. - It is well documented and commented, so you can read about the settings, but let's change the essential ones here. - </p> - - <p> - Make what changes you want and run <code>systemctl reload matrix-synapse</code> to make the system configuration active. - </p> - - <h3>Create an administrator account</h3> - - <p>If you allow open registration on your server in the configuration file, you can create an account through Element or another Matrix client, but you are probably going to want an official admin account to use. - To make one, simply run the following command, which will then give you several choices for creating a user, among which will be the ability to make it an admin. - </p> - - <pre><code>register_new_matrix_user -c homeserver.yaml http://localhost:8008</code></pre> - - <h2>Using Matrix with <img src="pix/element.svg" alt="Element Matrix logo">Element</h2> - - <p> - There are many different <a href="https://matrix.org/clients/">clients</a> that can be used on desktops or phones to chat on your Matrix server, but the most popular and most widely vetted is <img src="pix/element.svg" alt="Element logo">Element. - </p> - - <p>Get Element to access your Matrix server:</p> - - <ul> - <li>Mobile: - <ul> - <li><a href="https://f-droid.org/packages/im.vector.app/">F-droid</a></li> - <li><a href="https://play.google.com/store/apps/details?id=im.vector.app">Google Play</a></li> - <li><a href="https://apps.apple.com/app/vector/id1083446067">Apple App Store</a></li> - </ul> - </li> - <li>Real computer: - <ul> - <li>GNU/Linux: You know how to install it.</li> - <li><a href="https://packages.riot.im/desktop/install/win32/x64/Element%20Setup.exe">Windows</a></li> - <li><a href="https://packages.riot.im/desktop/install/macos/Element.dmg">Mac</a></li> - </ul> - </li> - </ul> - - <p> - Note also that Element has a web client (i.e. a version that can be accessed on your own website) that is also easy to install on an Nginx server, - although that will be covered in another article. - </p> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/monero.html b/monero.html deleted file mode 100644 index 1cc086f..0000000 --- a/monero.html +++ /dev/null @@ -1,111 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Setting up a Monero wallet – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Setting up a Monero wallet</h1></header> - <nav></nav> - <main> - <p> - Monero (abbreviated XMR) is easily the cryptocurrency most actually used as such. - Unlike Bitcoin, Monero is actually private and has very low transaction fees. - That makes it a good idea to get a Monero wallet and add an address on your website where you can receive donations. - </p> - - <h2>Generate a Monero wallet</h2> - - <p> - Got to <a href="https://www.getmonero.org/downloads/">https://www.getmonero.org/downloads/</a> to Monero's official site and you can download either the GUI (graphical) or CLI (command-line wallet). - Some Linux distributions will have these packages in their repositories (<code>monero</code> and <code>monero-gui</code> on Arch-based distributions). - </p> - - <aside> - <p> - If you are a Windows user, note that you will <em>probably</em> get some kind of warning that you are installing something malicious. - This is because many malicious pieces of software include crypto miners in them. - This wallet, obviously, does include one as well, because it has the ability to mine if you want. - You can disregard these messages and as that official site mentions, you can follow their directions to check the integrity of the download with SHA256. - </p> - </aside> - - <p> - Once you install and run the wallet program, you will get a menu like this: - </p> - - <img src="pix/monero-01.png" alt="simple mode"> - - <p> - Now if you want to start using Monero and using it as a pro, you can choose to download the whole blockchain which will maximize your transactional privacy, - however for this tutorial or setting up a wallet, we can just do the Simple Mode and save our bandwidth. - <strong>In fact, if you are paranoid, you can disconnect your computer from the internet while generating a wallet.</strong> - </p> - - <p>Now we choose to create a wallet.</p> - - <img src="pix/monero-02.png" alt="create wallet"> - - <p> - Now we get the most important and sensitive part, you private mneumonic seed. - <strong>These words are sacred! They are your money!</strong> - To be clear, they are randomly generated words that seed the randomness required to unlock whatever money you receive or hold. - Never show these words to anyone, don't even keep them on your computer, but write them down and store them securely in real life in a safe or somewhere where only you have access. - </p> - - <img src="pix/monero-03.png" alt="seed"> - - <aside> - <p> - It goes without saying that the seed above that we generated for this tutorial should never be used by anyone since it is public on the internet and anyone could easily take the funds from the wallet. - </p> - </aside> - - <p> - Finally, we get to the main wallet screen. - Now we see your public sharable wallet receiving address. - It is the thing that starts with <code>4</code> and is too long to be included in the image below labeled "Primary address." - </p> - - <img src="pix/monero-04.png" alt="address"> - - <p> - Click the clipboard next to it to copy the whole sequence (which will be more than 90 letters and numbers) to your clipboard. - This is your address. - Put it on your website and you can receive donations! - </p> - - <p> - You can also click to save that QR code image and you can put it up on your website and people will be able to scan it and send you Monero. - When scanned, that QR code will read as the public donation address. - </p> - - - <h2>What do I do now?</h2> - - <p> - You can now receive Monero/XMR donations! - All you need to do is put either your full address or your QR code on your site and people can send you tips in Monero. - </p> - - <p> - Here is the address we use for this site (i.e. not the compromised wallet generated above): - </p> - - <p style="font-size:small; word-wrap: break-word; ">84RXmrsE7ffCe1ADprxLMHRpmyhZuWYScDR4YghE8pFRFSyLtiZFYwD6EPijVzD3aZiEpg57MfHEr1pGJNPXyJgENMnWrSh</p> - - <img style="max-height:200px" src="pix/xmr.png" alt="monero donation qr"> - - <p> - It's now up to you how and where to display these on your site. - </p> - - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/nextcloud.html b/nextcloud.html deleted file mode 100644 index 6ce665c..0000000 --- a/nextcloud.html +++ /dev/null @@ -1,207 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Setting up a Nextcloud Instance – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1> Setting up a Nextcloud Instance</h1></header> - <nav></nav> - <main> -<img class=titleimg src="pix/nextcloud.svg" alt="logo"> - <h2 id="whatis">What is Nextcloud?</h2> - <p><a href="https://nextcloud.com" target="_blank"><img src="pix/nextcloud.svg" alt="logo">Nextcloud</a> is a free and open source solution for cloud storage. However it can also do other things, such as manage your email, notes, calender, tasks, and can even connect to the Fediverse (think Mastodon and Pleroma). Pretty much every service that Google has to offer has a much better alternative as a Nextcloud app and this is a must-have for anyone wanting to get away from Google services but still wants a traditional cloud experience (in the likes of Google Services, anyways).</p> - - <h2 id="instructions">Instructions</h2> - <p>We should upgrade the system and then install packages that we might need. Run the following command:</p> - <pre><code>apt-get full-upgrade -y && sudo apt-get install mariadb-server php-mysql php php-gd php-mbstring php-dom php-curl php-zip php-simplexml php-xml php-fpm -y</code></pre> - <p>Next, we need to set up our SQL database by running a Secure Installation and creating the tables that will store data that Nextcloud will need. Run the following command:</p> - <pre><code>mysql_secure_installation</code></pre> - <p>When it asks for root a password, say yes and input a new and secure password. The root password here is just for the SQL database, not for the GNU/Linux system.</p> - <p>Answer the rest of the questions as follows:</p> - <pre><code>Remove anonymous users? [Y/n]: Y -Disallow root login remotely? [Y/n]: Y -Remove test database and access to it? [Y/n]: Y -Reload privilege tables now? [Y/n]: Y</code> - </pre> - <p>Next, sign into the SQL database with the new and secure password you chose before. Run the following command:</p> - <pre><code>mysql -u root -p</code></pre> - <p>We need to create a database for Nextcloud. Follow the instructions below and change some of the placeholders as you wish:</p> - <pre><code>CREATE DATABASE nextcloud; -GRANT ALL ON nextcloud.* TO '<strong>username</strong>'@'localhost' IDENTIFIED BY '<strong>password</strong>'; -FLUSH PRIVILEGES; -EXIT;</code></pre> - <p>Now we need to configure PHP. Let's start my making sure that the PHP user is set to <code>www-data</code> and if that is not the case, add the <code>www-data</code> user if needed and set the correct variable in <code>nginx.conf</code>. Make sure this line is at the beginning of <code>/etc/nginx/nginx.conf</code>.</p> - <pre><code>user www-data;</code></pre> - <p>Check for the <code>www-data</code> user by running <code>id -u www-data</code>. If a number is output from that command, then the www-data user exists. If not. add the user simply by running <code>useradd www-data</code></p> - <p>Next, we need to ensure that we have SSL certificates generated for your website. If you have not already done this, refer to <a href="certbot.html">this guide</a>.</p> - <p>In <code>/etc/nginx/sites-available/</code> we need to make a new configuration for Nextcloud (example: <code>/etc/nginx/sites-available/nextcloud</code>). Create it and open it, modify, and add the following lines:</p> - <pre class=wide><code>upstream php-handler { - server unix:/var/run/php/php<strong>7.4</strong>-fpm.sock; - server 127.0.0.1:9000; -} - -server { - listen 80; - listen [::]:80; - server_name <strong>example.org</strong>; - - return 301 https://$server_name$request_uri; -} - -server { - listen 443 ssl http2; - listen [::]:443 ssl http2; - server_name <strong>example.org</strong>; - ssl_certificate /etc/letsencrypt/live/<strong>example.org</strong>/cert.pem ; - ssl_certificate_key /etc/letsencrypt/live/<strong>example.org</strong>/privkey.pem ; - - root /var/www; - - location = /robots.txt { - allow all; - log_not_found off; - access_log off; - } - - location ^~ /.well-known { - location = /.well-known/carddav { return 301 /nextcloud/remote.php/dav/; } - location = /.well-known/caldav { return 301 /nextcloud/remote.php/dav/; } - - location /.well-known/acme-challenge { try_files $uri $uri/ =404; } - location /.well-known/pki-validation { try_files $uri $uri/ =404; } - - return 301 /nextcloud/index.php$request_uri; - } - - location ^~ /nextcloud { - client_max_body_size 512M; - fastcgi_buffers 64 4K; - - gzip on; - gzip_vary on; - gzip_comp_level 4; - gzip_min_length 256; - gzip_proxied expired no-cache no-store private no_last_modified no_etag auth; - gzip_types application/atom+xml application/javascript application/json application/ld+json application/manifest+json application/rss+xml application/vnd.geo+json application/vnd.ms-fontobject application/x-font-ttf application/x-web-app-manifest+json application/xhtml+xml application/xml font/opentype image/bmp image/svg+xml image/x-icon text/cache-manifest text/css text/plain text/vcard text/vnd.rim.location.xloc text/vtt text/x-component text/x-cross-domain-policy; - - add_header Referrer-Policy "no-referrer" always; - add_header X-Content-Type-Options "nosniff" always; - add_header X-Download-Options "noopen" always; - add_header X-Frame-Options "SAMEORIGIN" always; - add_header X-Permitted-Cross-Domain-Policies "none" always; - add_header X-Robots-Tag "none" always; - add_header X-XSS-Protection "1; mode=block" always; - - fastcgi_hide_header X-Powered-By; - - index index.php index.html /nextcloud/index.php$request_uri; - - location = /nextcloud { - if ( $http_user_agent ~ ^DavClnt ) { - return 302 /nextcloud/remote.php/webdav/$is_args$args; - } - } - - location ~ ^/nextcloud/(?:build|tests|config|lib|3rdparty|templates|data)(?:$|/) { return 404; } - location ~ ^/nextcloud/(?:\.|autotest|occ|issue|indie|db_|console) { return 404; } - - location ~ \.php(?:$|/) { - fastcgi_split_path_info ^(.+?\.php)(/.*)$; - set $path_info $fastcgi_path_info; - - try_files $fastcgi_script_name =404; - - include fastcgi_params; - fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; - fastcgi_param PATH_INFO $path_info; - fastcgi_param HTTPS on; - - fastcgi_param modHeadersAvailable true; - fastcgi_param front_controller_active true; - fastcgi_pass php-handler; - - fastcgi_intercept_errors on; - fastcgi_request_buffering off; - } - - location ~ \.(?:css|js|svg|gif)$ { - try_files $uri /nextcloud/index.php$request_uri; - expires 6M; - access_log off; - } - - location ~ \.woff2?$ { - try_files $uri /nextcloud/index.php$request_uri; - expires 7d; - access_log off; - } - - location /nextcloud/remote { - return 301 /nextcloud/remote.php$request_uri; - } - - location /nextcloud { - try_files $uri $uri/ /nextcloud/index.php$request_uri; - } - } -}</code></pre> - <p>Enable the site by running this command:</p> - <pre><code>ln -s /etc/nginx/sites-available/nextcloud /etc/nginx/sites-enabled/</code></pre> - <p>Next, we need to download the latest release tarball of Nextcloud. Go to <a>https://nextcloud.com/install/#instructions-server</a> and copy the URL of the .tar.bz2 tarball from the More Downloads dropdown menu then go to your server's shell prompt and download the tarball with wget. Here is an example:</p> - <pre><code>wget https://download.nextcloud.com/server/releases/nextcloud-21.0.2.tar.bz2</code></pre> - <p>Now we need to extract the Nextcloud tarball. Run the following command:</p> - <pre><code>tar -xjf nextcloud*.tar.bz2 -C /var/www</code></pre> - <p>If you have multiple Nextcloud tarballs in the current working directory you might want to manually specify which one you wish to extract.</p> - <p>Let's correct the ownership and permissions of those files. Run the following commands:</p> - <pre><code>chown -R www-data:www-data /var/www/nextcloud -chmod -R 755 /var/www/nextcloud</code> - </pre> - <p>Start and enable the php-fpm and the mariadb services (the name of the php-fpm service may have a version number ahead of it, use bash's tab autocomplete to help you out with that):</p> - <pre><code>systemctl enable php<strong>7.4</strong>-fpm -systemctl start php<strong>7.4</strong>-fpm -systemctl enable mariadb -systemctl start mariadb</code></pre> - <p>Reload the nginx service:</p> - <pre><code>systemctl reload nginx</code></pre> - <p>Now we need to head to Nextcloud's web interface. Go to your web browser and go to your website, but go to the subdirectory "nextcloud" instead. Go to <code>https://<strong>example.org</strong>/nextcloud</code>. This will launch the configuration wizard.</p> - - <ul> - <li>Choose an admin username and secure password.</li> - <li>Leave Data folder at the default value unless it is incorrect.</li> - <li>For Database user, enter the user you set for the SQL database.</li> - <li>For Database password, enter the password you chose for the new user in MariaDB.</li> - <li>For Database name, enter: <code>nextcloud</code></li> - <li>Leave "localhost" as "localhost".</li> - <li>Click Finish.</li> - </ul> - - <p>Congratulations, you have set up your own Nextcloud instance.</p> - - <h2 id="whatsnext">What's Next?</h2> - <p>Now you may be wondering: What do I do now? Here are some suggestions:</p> - - <ul> - <li>Rice your Nextcloud instance by changing your themeing and installing new themes and plugins in Settings in the Nextcloud Web Interface.</li> - <li>Install the Nextcloud Client on your personal computer and sync your files to your instance.</li> - <li>Install the Nextcloud App on your mobile device and sync your files to your instance.</li> - <li>Set up your email account on the Nextcloud Mail app on the web interface to view and sync your email there (just like Gmail).</li> - <li>Schedule events with Nextcloud Calender.</li> - <li>Write notes in Markdown inside the Nextcloud Notes web and mobile app.</li> - <li>Set the Nextcloud Dashboard as your web browser's homepage (it is pretty nice).</li> - </ul> - - <p>Enjoy your cloud services in freedom.</p> - - <hr> - - <p><em>Written by <a href="https://github.com/MattMadness">Matthew "Madness" Evan</a></em></p> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/nginx.html b/nginx.html deleted file mode 100644 index d0a4cfc..0000000 --- a/nginx.html +++ /dev/null @@ -1,249 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Setting Up a Webserver – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Setting Up a Webserver</h1></header> - <nav></nav> - <main> - <p>At this point, we should have a domain name and a server and the domain name should direct to the IP address of the server with DNS records. - As I said in previous articles, the instructions I will give will be for <strong>Debian</strong>. - In this article, other distributions might work a little differently.</p> - - <h2>Logging in to the server</h2> - - <p> - We first want to log into our VPS to get a command prompt where we can set up the web server. - I am assuming you are using either MacOS or GNU/Linux and you know how to open a terminal. - On Windows, you can also use either PuTTY or the Windows Subsystem for Linux. - </p> - <p> - Now on Vultr's site, you can click on your VPS and you will see that there is an area that shows you the password for your server at the bottom here. - </p> - - <img src="pix/nginx-password.png" alt="Find your password"> - - <p> - Now pull up a terminal and type: - </p> - - <pre><code>ssh root@<strong>example.org</strong></code></pre> - - <p> - This command will attempt to log into your server. - It should prompt you for your password, and you can just copy or type in the password from Vultr's site. - </p> - - <aside> - <p> - If you get an error here, you might not have done your <a href="dns.html">DNS settings</a> right. - Double check those. - Note you can also replace the <code>example.org</code> with your IP address, but you'll want to fix your DNS settings soon. - </p> - </aside> - - <h2>Installing the Webserver: Nginx</h2> - - <p> - If the program runs without an error, <code>ssh</code> has now logged you into your server. - Let's start by running the following commands. - </p> - - <pre><code>apt update -apt upgrade -apt install nginx</code></pre> - - <p> - The first command checks for packages that can be updated and the second command installs any updates. - </p> - - <p> - The third command installs <code>nginx</code> (pronounced Engine-X) which is the web server we'll be using, - along with some other programs. - </p> - - <h3>Our nginx configuration file</h3> - - <p> - <code>nginx</code> is your webserver. - You can make a little website or page, put it on your VPS and then tell <code>nginx</code> where it is and how to host it on the internet. - It's simple. Let's do it. - </p> - - <aside> - <p> - <code>nginx</code> configuration files are in <code>/etc/nginx/</code>. - The two main subdirectories in there (on Debian and similar OSes) are <code>/etc/nginx/sites-available</code> and <code>/etc/nginx/sites-enabled</code>. - The names are descriptive. - The idea is that you can make a site configuration file in <code>sites-available</code> and when it's all ready, - you make a link/shortcut to it in <code>sites-enabled</code> which will activate it. - </p> - </aside> - - <p>First, let's create the settings for our website. You can copy and paste (with required changes) - but I will also explain what the lines do. - </p> - - <p> - Create a file in <code>/etc/nginx/sites-available</code> by doing this: - </p> - - <pre><code>nano /etc/nginx/sites-available/mywebsite</code></pre> - - <p> - Note that "nano" is a command line text editor. - You will now be able to create and edit this file. - By saving, this file will now appear. - Note also I name the file <code>mywebsite</code>, but you can name it whatever you'd like. - </p> - - <p> - I'm going to add the following content to the file. - The content <strong>like this</strong> will be different depending on what you want to call your site. - </p> - -<pre><code>server { - listen 80 ; - listen [::]:80 ; - server_name <strong>landchad.net</strong> ; - root /var/www/<strong>landchad</strong> ; - index index.html index.htm index.nginx-debian.html ; - location / { - try_files $uri $uri/ =404 ; - } -}</code></pre> - - -<aside> -<h4>Explanation of those settings</h4> -<p> -The <code>listen</code> lines tell <code>nginx</code> to listen for connections on both IPv4 and IPv6. -</p> -<p> -The <code>server_name</code> is the website that we are looking for. -By putting <code>landchad.net</code> here, that means whenever someone connects to this server and is looking for that address, -they will be directed to the content in this block. -</p> -<p> -<code>root</code> specifies the directory we're going to put our website files in. -This can theoretically be wherever, but it is conventional to have them in <code>/var/www/</code>. -Name the directory in that whatever you want. -</p> -<p> -<code>index</code> determine what the "default" file is; -normally when you go to a website, say <code>landchad.net</code>, you are actually going to a file at <code>landchad.net/index.html</code>. -That's all that is. -Note that that this in concert with the line above mean that <code>/var/www/landchad/index.html</code>, a file on our computer that we'll create -will be the main page of our website. -</p> -<p> -Lastly, the <code>location</code> block is really just telling the server how to look up files, otherwise throw a 404 error. -Location settings are very powerful, but this is all we need them for now. -</p> -</aside> - -<h3>Create the directory and index for the site</h3> - -<p> -We'll actually start making a "real" website later, but let's go ahead and create a little page that will appear on when someone looks up the domain. -</p> - -<pre><code>mkdir /var/www/landchad</code></pre> - -<p> -Now let's create and index file inside of that directory which will appear when the website is accessed: -</p> - -<pre><code>nano /var/www/landchad/index.html</code></pre> - -<p> -I'll add the following basic content, but you can add whatever you want. -This will appear on your website. -</p> - -<pre><code><!DOCTYPE html> -<h1>My website!</h1> -<p>This is my website. Thanks for stopping by!</p> -<p>Now my website is live!</p></code></pre> - -<h3 id=enable>Enable the site</h3> - -<p> -Once you save that file, we can enable it making a link to it in the <code>sites-enabled</code> directory: -</p> - -<pre><code>ln -s /etc/nginx/sites-available/mywebsite /etc/nginx/sites-enabled</code></pre> - -<p> -Now we can just <code>reload</code> or <code>restart</code> to make <code>nginx</code> service the new configuration: -</p> - -<pre><code>systemctl reload nginx</code></pre> - -<h2 id=firewall>The Firewall</h2> - -<p> -Vultr and some other VPS automatically install and enable <code>ufw</code>, a firewall program. -This will block basically everything by default, so we have to change that. -If you don't have <code>ufw</code> installed, you can skip this section. -</p> - -<h3>Option 1: Disable the firewall entirely...</h3> - -<p>It's usually easier to just entirely disable the firewall as we set up different services. -But be sure to see <a href="ufw.html">the article on how to fully configure the firewall</a> later. -</p> - -<pre><code>systemctl stop ufw -systemctl disable ufw</code></pre> - -<h3>Option 2: Or enable the proper ports.</h3> - -<p>We can also simply manually disable the blocking of connections over HTTP and HTTPS. -This keeps the firewall otherwise active. -</p> - -<pre><code>ufw allow 80 -ufw allow 443</code></pre> - -<p> -Port 80 is the canonical webserver port, while 443 is the port used for encrypted connections. -We will certainly need that for the next page. -</p> - -<h2>Nginx security hint</h2> - -<p>By default, Nginx and most other webservers automatically show their version number on error pages. -It's a good idea to disable this from happening because if an exploit comes out for your server software, someone could exploit it. Open the main Nginx config file <code>/etc/nginx/nginx.conf</code> and find the line <code># server_tokens off;</code>. Uncomment it, and reload Nginx. -</p> - -<p> -Remember to <a href="maintenance.html#update">keep your server software up to date</a> to get the latest security fixes! -</p> - -<h2>We now have running website!</h2> - -<p> -At this point you can now type in your website in your browser and this webpage will appear! -</p> - -<img src=pix/nginx-website.png alt="The webpage as it appears."> - -<p> -Note the "Not secure" notification. -The next brief step is securing encrypted connections to your website. -</p> - - <span class=prev><a href="dns.html">Previous: Set up DNS.</a></span> - <span class=next><a href="certbot.html">Next: Enabling Encrypted Connections.</a></span> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/openalias.html b/openalias.html deleted file mode 100644 index b78bdfd..0000000 --- a/openalias.html +++ /dev/null @@ -1,121 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>OpenAlias – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>OpenAlias</h1></header> - <nav></nav> - <main> - - <h2>The Problem</h2> - <p> - Cryptocurrency can be unintuitive. - After all, look at this annoying Monero address of ours: - </p> - - <ul> - <li><code class=crypto>84RXmrsE7ffCe1ADprxLMHRpmyhZuWYScDR4YghE8pFRFSyLtiZFYwD6EPijVzD3aZiEpg57MfHEr1pGJNPXyJgENMnWrSh</code></p> - </ul> - - <p> - It breaks up pages and looks ugly. When you copy and paste it to send money, you might be paranoid that you somehow added an extra character in there. - That's all around a bad user experience. - </p> - - <h3>It would be nice...</h3> - - <p> - It would be nice if we could just input someone's email address or maybe a website and send Bitcoin or Monero to that instead. - So instead of that long jumble, it would be easier to just type in someone's website or email and sending them money that way. - </p> - - <h2>The Solution</h2> - <p>The <a href="https://openalias.org/">OpenAlias</a> standards are just that. - It uses <a href="dns.html">DNS</a> settings, which you know something about, to link a website or an email address with a cryptocurrency address. - It allows someone to simply put <code>landchad.net</code> or <code>chad@landchad.net</code> as a payment recipient and that will direct to that long address above. - </p> - - <p> - The default Monero wallet and Bitcoin's Electrum are already compatible with OpenAlias, as are a growing group of wallet software. - </p> - - <h2>Let's do it.</h2> - - <p>Open up your domain registar and open up your DNS settings for the website you would like to add.</p> - - <p> - Open the <strong>TXT record</strong> section. - Now, create an entry with text like that below: - </p> - -<pre><code>oa1:xmr recipient_address=<strong>84RXmrsE7ffCe1ADprxLMHRpmyhZuWYScDR4YghE8pFRFSyLtiZFYwD6EPijVzD3aZiEpg57MfHEr1pGJNPXyJgENMnWrSh</strong>; recipient_name=<strong>LandChad.net</strong>;</code></pre> - - <p>Obviously change the address to your desired address and you may also give a proper name for yourself (this may be multiple words). - Note that the entry above is <strong>all one line</strong>. - </p> - - <p> - Now create a new TXT entry and input this text into the <strong>TXT Value</strong> input box. - Note here that I have create two entries: - </p> - - <a href=pix/openalias-01.png><img src="pix/openalias-01.png" alt="openalias"></a> - - <p> - One entry's "Host" is left empty, this will allow people to send Monero by merely typing <code>landchad.net</code>. - </p> - - <p> - The second entry has "chad" as the "Host"; this will allow people to send money to <code>chad@landchad.net</code>, i.e. - this is how you allow people to connect a Monero address with an email address. - </p> - - <h3>Checking to see if it works...</h3> - <p> - Let's check to see if it works. - In the Monero wallet, we can now type in <code>landchad.net</code> as a recipient: - </p> - <a href=pix/openalias-02.png><img src="pix/openalias-02.png" alt="checking"></a> - - <p> - And once we press the "Resolve" button, it automatically turns into that address we gave to the DNS! - </p> - - <a href=pix/openalias-03.png><img src="pix/openalias-03.png" alt="It works!"></a> - - <p> - Now people can donate Monero to you without having to worry about QR codes or copying-and-pasting super-long public addresses! - </p> - - <h3>Now with Bitcoin!</h3> - - <p> - OpenAlias was originally developed for Monero, but since it's such a good idea, Bitcoin wallets have implemented it as well, so let's add some TXT entries for Bitcoin. - The OpenAlias TXT records have the same format, except for the <strong>xmr</strong> at the beginning is replaced with <strong>btc</strong> and obviously we use a Bitcoin address instead of Monero. - </p> - -<pre><code>oa1:<strong>btc</strong> recipient_address=<strong>bc1q9f3tmkhnxj8gduytdktlcw8yrnx3g028nzzsc5</strong>; recipient_name=<strong>LandChad.net</strong>;</code></pre> - - <p>Add the TXT entries in and save:</p> - - <a href=pix/openalias-04.png><img src="pix/openalias-04.png" alt="bitcoin openalias entries"></a> - - <p>And we can then check that it's working by trying to send money to <code>landchad.net</code> in Electrum. - See that it automatically appends the address! - </p> - <a href=pix/openalias-05.png><img src="pix/openalias-05.png" alt="electrum resolves an openalias"></a> - - <p> - And that's it. Now users can easily send your website or email address Bitcoin or Monero without having to worry about hard to read addresses and QR codes. - </p> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/peertube.html b/peertube.html deleted file mode 100644 index 27578d0..0000000 --- a/peertube.html +++ /dev/null @@ -1,223 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>PeerTube Instance – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>PeerTube Instance</h1></header> - <nav></nav> - <main> - - <img class=titleimg src="pix/peertube.svg" alt="PeerTube logo"> - - <p>PeerTube is a self-hosted and (optionally) federated video sharing platform that saves bandwith on videos the more people watch. - PeerTube instances can follow each other to share videos and grow the federated network, - but you can always keep your instance to yourself if you choose to.</p> - - <h2>Note on Bandwidth</h2> - - <p> - Video sharing is the most bandwidth intensive thing on the internet! - If you plan on just having a small personal site with a few viewers and friends, that won't be a big concern, - but most VPS providers like Vultr have caps on how much bandwidth can be used within a month without being throttled. - This level is far beyond what most sites need, but it might be an issue with a video site! - </p> - - <p> - So if you plan on having a big video-sharing PeerTube site, it's a good idea to host it with a provider that offers infinite bandwidth. - I strongly recommend getting a separate VPS with <a href="https://my.frantech.ca/aff.php?aff=3886">Frantech/BuyVM</a>. - They have unmetered bandwidth, extremely cheap block storage for hosting many, many videos and they even have a good record of being censorship resistant. - </p> - - <h2>Prerequisites</h2> - - <p><strong>Most</strong> of PeerTube's dependencies can be installed with this command:</p> - - <pre><code>apt install -y curl sudo unzip vim ffmpeg postgresql postgresql-contrib g++ make redis-server git python-dev cron wget</code></pre> - - <p>It's also important to start all associated daemons:</p> - - <pre><code>systemctl start postgresql redis</code></pre> - - <p>PeerTube also requires <strong>NodeJS 14</strong> and <strong>yarn</strong> which cannot be installed from the Debian repositories. This means they have to be installed from separate, external repos:</p> - - <pre><code>curl -fsSL https://deb.nodesource.com/setup_14.x | bash - -apt install -y nodejs -npm install --global yarn</code></pre> - - <p>Now we create a PeerTube user to run and handle PeerTube with the proper permissions:</p> - - <pre><code>useradd -m -d /var/www/peertube -s /bin/bash -p peertube peertube</code></pre> - - <h2>Database</h2> - - <p>PeerTube requires a PostgreSQL database to function. To create it, first make a new Postgres user named PeerTube:</p> - - <pre><code>su -l postgres -createuser -P peertube -createdb -O peertube -E UTF8 -T template0 peertube_prod -psql -c "CREATE EXTENSION pg_trgm;" peertube_prod -psql -c "CREATE EXTENSION unaccent;" peertube_prod -exit</code></pre> - - <p>Be sure to <strong>make note of your Postgres user password,</strong> as it will be needed later when setting up PeerTube.</p> - - <h2>Installation</h2> - - <p>Using <code>su -l</code>, we will become the PeerTube user to create the required directories and download and install PeerTube itself with the proper permissions. - First, we create the required directories.</p> - - <pre><code>su -l peertube -mkdir config storage versions -chmod 750 config</code></pre> - - <h3>Downloading PeerTube</h3> - <p>Still as the PeerTube user, we can now check for the most recent PeerTube versions number, download and install it in the newly created <code>versiond</code> directory.</p> - <pre class=wide><code>VERSION=$(curl -s https://api.github.com/repos/chocobozzz/peertube/releases/latest | grep tag_name | cut -d '"' -f 4) -cd /var/www/peertube/versions -wget "https://github.com/Chocobozzz/PeerTube/releases/download/${VERSION}/peertube-${VERSION}.zip" -unzip peertube-${VERSION}.zip -rm peertube-${VERSION}.zip</code></pre> - - <h3>Installation via Yarn</h3> - -<p>The downloaded release can then be symbolically linked to <code>/var/www/peertube/peertube-latest</code> and <strong>yarn</strong> is used to install PeerTube:</p> - -<pre><code>cd /var/www/peertube -ln -s versions/peertube-${VERSION} ./peertube-latest -cd ./peertube-latest -yarn install --production --pure-lockfile</code></pre> - - <h2>Configuration</h2> - - <p>PeerTube's default config file can be copied over to <code>/var/www/peertube/config/production.yaml</code> so it can actually be used:</p> - - <p>Note that we are still running these as the PeerTube user (having run <code>su -l peertube</code>).</p> - - <pre><code>cd /var/www/peertube -cp peertube-latest/config/production.yaml.example config/production.yaml</code></pre> - - <p>Now the <code>production.yaml</code> file must be edited in the following ways:</p> - - <p>First, add the hostname:</p> - - <pre><code>webserver: - https: true - hostname: <strong>'example.org'</strong> - port: 443</code></pre> - - <p>Then, the database:</p> - - <pre><code>database: - hostname: 'localhost' - port: 5432 - ssl: false - suffix: '_prod' - username: <strong>'peertube'</strong> - password: <strong>'your_password'</strong> - pool: - max: 5</code></pre> - - <p>An email to generate the admin user:</p> - - <pre><code>admin: - # Used to generate the root user at first startup - # And to receive emails from the contact form - email: <strong>'chad@example.org'</strong></code></pre> - - <p>And <strong>optionally,</strong> email server information:</p> - - <pre><code>smtp: - # smtp or sendmail - transport: smtp - # Path to sendmail command. Required if you use sendmail transport - sendmail: null - hostname: <strong>mail.example.org</strong> - port: 465 # If you use StartTLS: 587 - username: <strong>your_email_username</strong> - password: <strong>your_email_password</strong> - tls: true # If you use StartTLS: false - disable_starttls: false - ca_file: null # Used for self signed certificates - from_address: <strong>'admin@example.org'</strong></code></pre> - - <p>At this point, we have done all we need to do as the PeerTube user. Run <code>exit</code> or press <code>Ctrl-d</code> to log out and return to the root prompt where we will configure Nginx and other system settings.</p> - - <h2>Certbot</h2> - - <p>First, we will want a Certbot SSL certificate to encrypt connections to our PeerTube instance. - Just run the following:</p> - - <pre><code>certbot --nginx -d <strong>peertube.example.org</strong> certonly</code></pre> - - <h2>Nginx</h2> - - <p>PeerTube includes an Nginx configuration that can be copied over to <code>/etc/nginx/sites-available:</code> - - <pre><code>cp /var/www/peertube/peertube-latest/support/nginx/peertube /etc/nginx/sites-available/peertube</code></pre> - - <p>Because the PeerTube config is so long, it's recommended to use <code>sed</code> to modify the contents of the file, - replacing <code>${WEBSERVER_HOST}</code> with your hostname, - and <code>$(PEERTUBE_HOST)</code> with your localhost and port, which by default should be <code>127.0.0.1:9000</code>: - - <pre><code>sed -i 's/${WEBSERVER_HOST}/<strong>example.org</strong>/g' /etc/nginx/sites-available/peertube -sed -i 's/${PEERTUBE_HOST}/127.0.0.1:9000/g' /etc/nginx/sites-available/peertube</code></pre> - - <p>Once you're happy with the Nginx config file, link it to <code>sites-enabled</code> to activate it:</p> - - <pre><code>ln -s /etc/nginx/sites-available/peertube /etc/nginx/sites-enabled/peertube</code></pre> - - <h2>Running PeerTube</h2> - - <p>A config file for a systemd daemon is included in PeerTube and can be setup and started like so:</p> - - <pre><code>cp /var/www/peertube/peertube-latest/support/systemd/peertube.service /etc/systemd/system/ -systemctl daemon-reload -systemctl start peertube</pre></code> - - <p> - PeerTube will take a momemnt to start, but after it does, you can check its status with <code>systemctl status peertube</code> and at this point, your PeerTube site should be live! - </p> - - <h2>Using PeerTube</h2> - - <p>To set a password for your admin user, run:</p> - - <pre><code>cd /var/www/peertube/peertube-latest -NODE_CONFIG_DIR=/var/www/peertube/config NODE_ENV=production npm run reset-password -- -u root</code></pre> - - <p>Login to your PeerTube instance using the admin email specified in your <code>production.yaml</code> file and the admin password you just set.</p> - - <img src="pix/peertube-login.jpg" height=400px> - - <p>Once logged in, it's recommended to create a separate user without admin privileges for uploading videos to PeerTube. - This can be done easily from the users tab in the administration section.</p> - - <p>Enjoy your PeerTube instance!</p> - - <hr> - - <h2>Updating PeerTube</h2> - - <p>PeerTube is constantly adding new features, so it's a good idea to <a href="https://github.com/Chocobozzz/PeerTube/blob/develop/CHANGELOG.md">check for new updates</a> and add them if you wish. Just in the past year, they have added livestreaming and more.</p> - - <p>Updating is fairly easy now since an <code>upgrade.sh</code> script has been added. Just run:</p> - - <pre><code>cd /var/www/peertube/peertube-latest/scripts && sudo -H -u peertube ./upgrade.sh</code></pre> - - <p> - Although check the <a href="https://github.com/Chocobozzz/PeerTube/blob/develop/CHANGELOG.md">changelog</a> to see if there are additional manual requirements for particular updates. - </p> - - <hr> - <p><em>Written by <a href="https://denshi.live">Denshi.</a> Donate Monero <a href="https://denshi.live/donate.html">here</a> <a href="https://denshi.live/images/monero.png">[QR]</a></em></p> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/pix/brave-01.png b/pix/brave-01.png Binary files differdeleted file mode 100644 index 7b5b0dd..0000000 --- a/pix/brave-01.png +++ /dev/null diff --git a/pix/brave-02.png b/pix/brave-02.png Binary files differdeleted file mode 100644 index 555eca8..0000000 --- a/pix/brave-02.png +++ /dev/null diff --git a/pix/brave-03.png b/pix/brave-03.png Binary files differdeleted file mode 100644 index 7074971..0000000 --- a/pix/brave-03.png +++ /dev/null diff --git a/pix/brave-04.gif b/pix/brave-04.gif Binary files differdeleted file mode 100644 index 54cfd7a..0000000 --- a/pix/brave-04.gif +++ /dev/null diff --git a/pix/gitea-push-create.png b/pix/gitea-push-create.png Binary files differdeleted file mode 100644 index ca79c71..0000000 --- a/pix/gitea-push-create.png +++ /dev/null diff --git a/pix/rainloop.svg b/pix/rainloop.svg deleted file mode 100644 index 622853a..0000000 --- a/pix/rainloop.svg +++ /dev/null @@ -1,127 +0,0 @@ -<?xml version="1.0" standalone="no"?> -<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 20010904//EN" - "http://www.w3.org/TR/2001/REC-SVG-20010904/DTD/svg10.dtd"> -<svg version="1.0" xmlns="http://www.w3.org/2000/svg" - width="256.000000pt" height="256.000000pt" viewBox="0 0 256.000000 256.000000" - preserveAspectRatio="xMidYMid meet"> - -<g transform="translate(0.000000,256.000000) scale(0.100000,-0.100000)" -fill="#000000" stroke="none"> -<path d="M450 1976 c0 -19 4 -23 20 -19 11 3 20 1 20 -5 0 -6 -20 -10 -45 -10 --34 1 -45 5 -41 15 4 9 -3 13 -19 13 -27 0 -34 -17 -10 -26 17 -7 18 -13 6 --33 -8 -12 -12 -11 -28 4 -10 10 -18 23 -18 29 0 6 -7 11 -15 11 -12 0 -15 --19 -17 -100 l-2 -100 43 -48 c24 -27 47 -44 50 -39 3 6 0 17 -7 24 -12 11 --12 16 0 26 10 10 11 28 6 69 l-6 57 28 -22 c15 -12 34 -22 41 -22 8 0 11 -6 -8 -15 -4 -8 -1 -15 5 -15 6 0 11 5 11 11 0 6 9 9 20 6 15 -4 22 1 26 19 8 33 --3 42 -20 18 -12 -15 -17 -17 -27 -7 -10 10 -9 16 6 27 19 14 19 15 1 35 -10 -11 -23 18 -27 15 -5 -3 -9 1 -9 8 0 9 14 12 54 10 44 -3 61 1 93 21 22 14 43 -35 46 46 5 20 1 21 -94 21 -98 0 -99 0 -99 -24z m40 4 c0 -5 -4 -10 -10 -10 --5 0 -10 5 -10 10 0 6 5 10 10 10 6 0 10 -4 10 -10z m-157 -96 c-4 -12 -8 -13 --14 -3 -9 15 -2 32 11 24 5 -3 6 -13 3 -21z m136 -30 c-9 -11 -15 -12 -26 -3 --17 14 1 31 24 22 10 -4 11 -9 2 -19z"/> -<path d="M937 1967 c-20 -18 -37 -35 -37 -38 0 -4 21 -9 48 -13 60 -8 164 9 -178 29 6 8 14 15 18 15 4 0 16 9 28 20 l22 20 -110 0 c-108 -1 -109 -1 -147 --33z"/> -<path d="M1442 1955 l-47 -46 95 5 c52 3 104 5 115 6 11 0 40 19 64 40 l44 40 --40 0 c-26 0 -43 -5 -46 -14 -4 -9 -14 -13 -29 -9 -22 4 -22 4 -4 -11 19 -15 -16 -16 -37 -15 -38 1 -56 6 -54 13 2 6 12 13 23 14 38 7 38 22 0 22 -31 0 -45 --8 -84 -45z"/> -<path d="M2020 1990 c0 -5 9 -14 20 -20 11 -6 20 -21 20 -34 0 -20 4 -23 21 --19 12 4 20 2 18 -3 -20 -43 -34 -64 -41 -64 -4 0 -8 -5 -8 -10 0 -5 3 -9 8 --9 19 3 33 -2 27 -10 -11 -18 15 -22 45 -7 l30 14 0 -57 c0 -55 2 -58 50 -106 -l50 -49 0 172 c0 218 4 211 -140 211 -55 0 -100 -4 -100 -9z m80 -50 c0 -5 -4 --10 -10 -10 -5 0 -10 5 -10 10 0 6 5 10 10 10 6 0 10 -4 10 -10z"/> -<path d="M320 1980 c0 -5 6 -10 14 -10 8 0 18 5 21 10 3 6 -3 10 -14 10 -12 0 --21 -4 -21 -10z"/> -<path d="M1975 1920 c3 -5 12 -10 20 -10 8 0 17 5 20 10 4 6 -5 10 -20 10 -15 -0 -24 -4 -20 -10z"/> -<path d="M2027 1823 c-10 -16 16 -74 32 -71 8 2 16 8 18 14 5 16 -42 70 -50 -57z"/> -<path d="M540 1790 c0 -5 9 -14 20 -20 11 -6 20 -20 20 -30 0 -26 16 -26 23 --1 3 12 -4 28 -17 40 -23 22 -46 28 -46 11z"/> -<path d="M1923 1728 c-25 -32 -26 -40 -4 -29 11 7 21 18 21 26 0 18 -5 19 -17 -3z"/> -<path d="M518 1723 c7 -3 16 -2 19 1 4 3 -2 6 -13 5 -11 0 -14 -3 -6 -6z"/> -<path d="M552 1701 c-10 -6 -10 -10 3 -21 12 -10 18 -10 30 0 13 11 13 15 3 -21 -7 5 -15 9 -18 9 -3 0 -11 -4 -18 -9z"/> -<path d="M1995 1700 c-3 -5 1 -10 9 -10 9 0 16 5 16 10 0 6 -4 10 -9 10 -6 0 --13 -4 -16 -10z"/> -<path d="M1895 1631 c-17 -7 -17 -8 8 -13 16 -3 31 0 38 8 9 11 7 14 -7 13 --11 0 -28 -4 -39 -8z"/> -<path d="M720 1590 c-21 -21 -26 -40 -11 -40 15 0 41 30 41 46 0 19 -6 18 -30 --6z"/> -<path d="M1800 1599 c0 -5 9 -9 20 -9 11 0 20 -5 20 -11 0 -7 -11 -9 -31 -5 --28 5 -38 -1 -120 -81 -49 -48 -89 -92 -89 -99 0 -6 -10 -19 -22 -28 -16 -12 --19 -18 -10 -22 6 -3 12 -14 12 -24 0 -10 7 -20 15 -24 22 -8 196 162 193 189 --2 15 3 20 20 21 13 1 41 19 62 40 40 40 51 60 26 51 -7 -3 -19 0 -25 6 -8 8 --11 8 -11 0 0 -8 -9 -9 -30 -3 -18 5 -30 5 -30 -1z m7 -71 c-3 -8 -6 -5 -6 6 --1 11 2 17 5 13 3 -3 4 -12 1 -19z m-107 -76 c0 -14 -11 -21 -26 -15 -8 3 -11 -9 -8 14 7 11 34 12 34 1z m-50 -86 c0 -3 -4 -8 -10 -11 -5 -3 -10 -1 -10 4 0 -6 5 11 10 11 6 0 10 -2 10 -4z"/> -<path d="M740 1495 c7 -8 17 -15 22 -15 6 0 5 7 -2 15 -7 8 -17 15 -22 15 -6 -0 -5 -7 2 -15z"/> -<path d="M813 1484 c-13 -14 -23 -26 -23 -29 0 -4 47 -49 74 -72 21 -18 26 --16 26 7 0 11 6 20 14 20 10 0 12 7 8 22 -3 12 -7 17 -10 10 -7 -21 -22 -13 --22 11 0 21 -28 59 -41 56 -2 -1 -14 -12 -26 -25z m47 -23 c0 -20 -25 -35 -42 --25 -5 3 -2 14 8 25 22 24 34 24 34 0z"/> -<path d="M300 1361 c0 -53 4 -90 9 -87 5 4 13 -8 16 -26 8 -33 30 -57 53 -58 -9 0 12 24 12 88 l0 88 -45 44 -45 44 0 -93z"/> -<path d="M924 1393 c-4 -18 -13 -33 -20 -33 -18 0 -18 -19 0 -26 8 -3 22 -17 -31 -31 l17 -26 -131 -131 c-72 -72 -131 -137 -131 -144 0 -6 -5 -12 -12 -12 --15 0 -58 -49 -58 -66 0 -7 12 -15 28 -17 15 -2 9 -4 -16 -4 -36 0 -49 -5 -71 --29 -15 -16 -30 -37 -34 -46 -3 -10 -13 -18 -22 -18 -8 0 -15 -4 -15 -10 0 -5 -7 -10 15 -10 8 0 15 -5 15 -10 0 -17 -29 -23 -45 -10 -12 10 -16 9 -21 -4 -3 --9 -12 -16 -19 -16 -7 0 -15 -7 -19 -15 -3 -8 -1 -14 3 -12 5 1 10 -2 11 -8 0 --5 -9 -13 -22 -17 l-23 -6 23 -1 c43 -2 21 -19 -24 -18 -38 0 -50 -4 -65 -24 --24 -31 -24 -44 1 -69 18 -18 33 -20 128 -20 l108 0 44 45 43 44 -94 3 -94 3 -78 76 c42 41 77 81 77 87 0 7 6 12 12 12 7 0 97 84 200 187 176 176 186 188 -171 205 -15 17 -14 18 33 11 45 -6 48 -5 35 10 -9 11 -10 17 -2 17 6 0 11 7 -11 15 0 8 -4 15 -10 15 -5 0 -10 6 -10 13 0 19 -56 70 -69 63 -7 -4 -8 -1 -5 -8 4 10 -1 18 -12 23 -11 3 -22 11 -26 17 -4 6 -10 -3 -14 -21z m-257 -459 c-3 --3 -12 -4 -19 -1 -8 3 -5 6 6 6 11 1 17 -2 13 -5z m-32 -74 c-3 -5 -11 -10 --16 -10 -6 0 -7 5 -4 10 3 6 11 10 16 10 6 0 7 -4 4 -10z m-88 -62 c-3 -7 -5 --2 -5 12 0 14 2 19 5 13 2 -7 2 -19 0 -25z m-49 -60 c-3 -7 -11 -13 -18 -13 --7 0 -15 6 -17 13 -3 7 4 12 17 12 13 0 20 -5 18 -12z m-93 -138 c11 -17 -5 --32 -21 -19 -7 6 -11 15 -8 20 7 12 21 11 29 -1z"/> -<path d="M2170 1302 c0 -22 -3 -52 -6 -68 -4 -20 0 -36 13 -51 l19 -21 22 34 -c12 18 22 43 22 54 0 11 5 20 10 20 6 0 10 7 10 15 0 8 -4 15 -10 15 -5 0 -6 -8 -3 18 7 16 6 16 -11 0 -22 -22 -61 -24 -53 -3 4 8 2 17 -3 20 -6 4 -10 -11 --10 -33z"/> -<path d="M1507 1305 c-14 -10 -16 -20 -11 -41 6 -24 5 -27 -7 -18 -18 15 -59 -0 -59 -21 0 -9 -3 -14 -8 -12 -4 3 -23 -10 -41 -29 -19 -19 -43 -36 -53 -40 --10 -3 -16 -9 -13 -14 3 -5 -4 -11 -15 -15 -11 -3 -20 -13 -20 -21 0 -17 -47 --41 -58 -29 -4 4 -1 10 5 12 21 7 -14 35 -39 31 -33 -5 -31 -21 6 -46 82 -56 -147 -35 270 86 l73 73 93 -95 c51 -52 97 -93 102 -90 5 4 7 11 5 18 -18 48 --18 56 0 56 11 0 25 -6 32 -12 11 -11 11 -9 2 10 -6 12 -18 22 -26 22 -7 0 --17 9 -20 20 -3 11 -10 20 -15 20 -5 0 -18 9 -29 21 -11 12 -24 18 -30 14 -16 --10 -13 -25 5 -25 11 0 14 -5 10 -16 -3 -9 -6 -21 -6 -27 0 -6 -9 -1 -20 11 --11 12 -20 26 -20 32 0 5 -4 10 -10 10 -5 0 -10 5 -10 10 0 6 9 10 19 10 14 0 -18 5 14 20 -8 30 -32 47 -44 29 -7 -11 -9 -11 -9 0 0 11 -3 11 -16 0 -15 -12 --16 -11 -10 7 9 30 -22 57 -47 39z m-65 -137 c-12 -12 -35 -1 -27 12 3 5 13 6 -21 3 10 -4 12 -9 6 -15z"/> -<path d="M1044 1209 c-9 -16 10 -31 30 -23 13 5 14 9 5 20 -14 17 -25 18 -35 -3z"/> -<path d="M368 1173 c7 -3 16 -2 19 1 4 3 -2 6 -13 5 -11 0 -14 -3 -6 -6z"/> -<path d="M300 880 c0 -30 4 -62 10 -70 6 -9 5 -17 -2 -21 -6 -4 -7 -12 -4 -18 -11 -18 26 -13 26 9 0 11 3 20 6 20 11 0 35 -30 31 -38 -3 -4 1 -16 9 -27 13 --18 14 -18 14 6 0 13 -7 35 -16 47 -8 12 -12 27 -9 32 3 6 -1 10 -9 10 -23 0 --19 18 5 22 18 3 16 7 -20 43 l-41 39 0 -54z"/> -<path d="M1980 887 c0 -8 7 -17 15 -21 8 -3 15 -2 15 3 0 5 -7 14 -15 21 -12 -10 -15 10 -15 -3z"/> -<path d="M2160 811 l0 -83 -64 57 c-38 32 -67 52 -71 45 -3 -5 1 -10 9 -10 9 -0 16 -4 16 -10 0 -5 -9 -10 -20 -10 -17 0 -19 -5 -14 -27 4 -22 3 -25 -5 -13 --7 9 -11 11 -11 3 0 -7 6 -16 13 -20 8 -4 31 -27 52 -51 26 -30 35 -46 28 -53 --8 -8 -13 -7 -17 0 -4 6 -21 11 -38 11 -25 0 -29 -3 -23 -17 15 -36 17 -53 7 --53 -6 0 -12 6 -14 12 -3 7 -7 3 -10 -8 -5 -21 -2 -21 108 -23 151 -2 154 1 -154 137 l0 98 -50 49 -50 49 0 -83z"/> -<path d="M300 685 c0 -8 7 -15 15 -15 8 0 15 7 15 15 0 8 -7 15 -15 15 -8 0 --15 -7 -15 -15z"/> -<path d="M900 605 l-45 -46 115 3 c67 2 114 7 112 13 -2 5 6 12 17 17 24 9 28 -28 6 28 -8 0 -15 7 -15 15 0 12 -15 15 -73 15 l-73 0 -44 -45z"/> -<path d="M1442 627 c-23 -25 -29 -43 -11 -31 7 4 10 1 7 -7 -3 -8 -14 -14 -25 --14 -12 0 -25 -3 -29 -7 -4 -5 20 -8 54 -8 46 0 62 4 62 14 0 7 9 25 20 39 27 -34 26 37 -18 37 -27 0 -45 -7 -60 -23z"/> -<path d="M1915 580 c-18 -19 -17 -20 2 -20 12 0 23 8 26 20 3 11 2 20 -2 20 --5 0 -16 -9 -26 -20z"/> -</g> -</svg> diff --git a/pleroma.html b/pleroma.html deleted file mode 100644 index 755692a..0000000 --- a/pleroma.html +++ /dev/null @@ -1,169 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Setup a Pleroma Server – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Setup a Pleroma Server</h1></header> - <nav></nav> - <main> - - <p>Hopefully by now you won't have to be sold on the invasive practices that social media companies conduct. Websites such as Facebook and Twitter aquire so much data on users that they often know more about you than you know about yourself. - -The simple solution to this is to not use social media. However, that just isn't an option for most people. So the next best thing is to setup a self-hosted and federalised social media site so that you have full control over your data. - -I've previously made<a href="https://www.youtube.com/watch?v=l7mVsLSsotU"> a video showing all the steps in depth if you want to check it out.</a> If you run into any issues I suggest you look at the video. -</p> - - <p>You'll need a server or VPS. Nearly any Operating system is supported but for this tutorial I'm gonna presume you're using a Debian-based OS. You'll also need a domain name pointing to your server's IP address <a href="https://landchad.net/dns.html">which is explained in this tutorial.</a> - </p> - - - -<h2>Installation</h2> - -<h3>Setting Up and Configuring</h3> - -<p>First things first you'll need to make sure that you've hardened you SSH so that password authentication is disabled and you'll also want to setup Fail2Ban. -There's a great tutorial on how to do this <a href="https://landchad.net/sshkeys.html">which can be read here.</a> -</p> - -<p> -Next we'll install the required packages: -</p> - -<pre><code>apt install -y curl unzip libncurses5 postgresql postgresql-contrib nginx certbot libmagic-dev</code></pre> - -<p> -You can manually configure postgreSQL to suit your system better. <a href="https://docs-develop.pleroma.social/backend/configuration/postgresql/">Check out the documentation here</a> and then run the below command: -</p> - -<pre><code>systemctl restart postgresql</code></pre> - - -<h3>Installing the Pleroma App</h3> - -<h4>First as the root user</h4> -<p> -Pleroma is not in the Debian app repositories, so we will install it manually. -First create the Pleroma user by running the below command: -</p> - -<pre><code>useradd -m -s /bin/bash -d /opt/pleroma pleroma</code></pre> - -<p> -Then, still as root, we will create the required directories and give the Pleroma user ownership of them. -</p> - -<pre><code>mkdir -p /var/lib/pleroma/uploads -chown -R pleroma /var/lib/pleroma -mkdir -p /var/lib/pleroma/static -chown -R pleroma /var/lib/pleroma -mkdir -p /etc/pleroma -chown -R pleroma /etc/pleroma</code></pre> - -<h4>Now, as the new Pleroma user</h4> - -<p> -Now run <code>su -l pleroma</code> to login as the Pleroma user. -Now use the <code>curl</code> command below to download the Pleroma software and unzip it. -</p> - -<pre><code>curl 'https://git.pleroma.social/api/v4/projects/2/jobs/artifacts/stable/download?job=<strong>amd64</strong>' -o /tmp/pleroma.zip -unzip /tmp/pleroma.zip -d /tmp/</code></pre> - -<aside><p>Note that we are downloading the <strong>amd64</strong> version here. If you know you have a different CPU architecture, replace that with whatever your architecture is.</p></aside> - -<pre><code>mv /tmp/release/* /opt/pleroma -rmdir /tmp/release -rm /tmp/pleroma.zip -./bin/pleroma_ctl instance gen --output /etc/pleroma/config.exs --output-psql /tmp/setup_db.psql</code></pre> - -<p>We need to briefly return to the root user so we can run the following command (via the postgres user) to set up the database. -Type <code>ctrl-d</code> or run <code>exit</code> to return to the root user, then run: -</p> - -<pre><code>su postgres -s $SHELL -lc "psql -f /tmp/setup_db.psql"</code></pre> - -<p>Then return to the pleroma user with <code>su -l pleroma</code> and we will test to see that Pleroma can run:</p> - -<pre><code>./bin/pleroma_ctl migrate -./bin/pleroma daemon</code></pre> - -<p> -That will initialize Pleroma. It might take as long as a minute to get started, so wait a bit, then run the following: -</p> -<pre><code>curl http://localhost:4000/api/v1/instance</code></pre> - -<p>If everything is working, this command will give you a long line of messy output. If it is not, you will get a connection error message. -Once it is working successfully, stop the Pleroma daemon and we will interface Pleroma with the web server.</p> - -<pre><code>./bin/pleroma stop</code></pre> - -<h3>Setup and Configure Nginx</h3> - -<p> -Return again to the root user. Let's copy Pleroma's Nginx configuration file from the template given in the installation and enable it: -</p> - -<pre><code>cp /opt/pleroma/installation/pleroma.nginx /etc/nginx/sites-available/pleroma.conf -ln -s /etc/nginx/sites-available/pleroma.conf /etc/nginx/sites-enabled/pleroma.conf</code></pre> - -<p>Edit the <code>etc/nginx/sites-available/pleroma.conf</code> file and replace <strong>example.tld</strong> with your domain name.</p> - -<p> -We now have to get a SSL certificate to enable encryption, since we have a model configuration that already includes SSL information, -just check the brief <a href="standalone.html">the standalone certificate page</a> to get the needed certificate. -Once you've got your cert setup, copy over the Nginx configuration with the below command: -</p> - -<p> -Once everything, including your Cerbot certificate is ready, simply reload Nginx with this command: -</p> - -<pre><code>systemctl reload nginx</code></pre> - - -<h3>Setting up the service</h3> - -<p> -Pleroma itself runs on a SystemD service similar to other things running on your server like Nginx. To start the service up run the below commands: -</p> - -<pre><code>cp /opt/pleroma/installation/pleroma.service /etc/systemd/system/pleroma.service -systemctl start pleroma -systemctl enable pleroma</code></pre> - -<p> -If everything worked then when you go to your domain in the web browser you should see a bare-bones Pleroma instance. -</p> - - -<h3>Creating an Admin User</h3> - -<p>You'll be able to create new accounts on the Pleroma instance in the login section on the website but the easiest way to setup an admin account is with the CLI. Simply run the below command replaced with your username: -</p> - -<pre><code>su -l pleroma -./bin/pleroma_ctl user new <strong>username</strong> <strong>username</strong>@<strong>example.org</strong> --admin</code></pre> - -<p> -If you run into any issues then <a href="https://docs-develop.pleroma.social/backend/installation/otp_en/">feel free to checkout the documentation</a> or send me an email or message. My details are below. -</p> - -<ul> - <li><a href="https://biasedriot.co">biasedriot.co</a></li> - <li><a href="https://www.youtube.com/channel/UCehh50T6qtDpt_kEUF33GJw">youtube</a></li> - <li>Bitcoin: <code class=crypto>1Dmn9jEtWAhdLk1HHWkUVNeDdAaBCwNajm</code></li> - <li>Monero: <code>84Y4FZiTbLeR5qc1fBrBhB1yq5agKtEdoixq2w1ysXJv486MiBCz3czGT15bqeXDPpdLoNyF93inxY3BCk6g8mrDMNKoArS</code></li> -</ul> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/rainloop.html b/rainloop.html deleted file mode 100644 index 4ab0b2a..0000000 --- a/rainloop.html +++ /dev/null @@ -1,75 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Setting up a Rainloop Webmail Client – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Setting up a Rainloop Webmail Client</h1></header> - <img class=titleimg src="pix/rainloop.svg" alt="logo" style="filter: invert(1);"> - <nav></nav> - <main> - <h2 id="whatis">What is Rainloop?</h2> - <p><a href="https://www.rainloop.net/"><img src="pix/rainloop.svg" style="filter: invert(1);">Rainloop</a> is a webmail client, a program that allows you to access your email online like gmail. It is useful to be able to access you email from a web browser because it allows you to easily access your email from any device with a web browser without any additional setup. If you set up <a href="nextcloud.html" target="_blank"><img src="pix/nextcloud.svg" alt="logo">Nextcloud</a> then you do not need to install Rainloop because Nextcloud comes with a webmail client. However, if all you want is a webmail client and you do not need all of the extra things that Nextcloud provides, Rainloop would be the better choice out of the two since it is less bloated and simpler to install.</p> - <h2 id="instructions">Instructions</h2> - <p>First we will install the required packages for Rainloop with the following command:</p> - <pre><code>apt-get full-upgrade -y && apt-get install php7.3 php7.3-common php7.3-curl php7.3-xml php7.3-fpm php7.3-json php7.3-dev php7.3-mysql unzip -y</code></pre> - <p>Then we will download the community version of Rainloop, unzip it into an appropriate directory and fix all of the file permissions:</p> - <pre><code>curl -L "https://www.rainloop.net/repository/webmail/rainloop-community-latest.zip" -o "rainloop.zip" && unzip rainloop.zip -d /var/www/<strong>mail</strong> && chown -R www-data: /var/www/<strong>mail</strong></code></pre> - <p>We have installed Rainloop itself, but now we need Nginx to serve the client. We do that by adding the following text into the file <code>/etc/nginx/sites-available/<strong>mail</strong></code> (you can replace the bold text with whatever is appropriate for your server).</p> - <pre class=wide><code>server { - - listen 80; - - server_name <strong>mail.domain.com</strong>; - root /var/www/<strong>mail</strong>; - - index index.php; - - access_log /var/log/nginx/rainloop_access.log; - error_log /var/log/nginx/rainloop_error.log; - - location / { - try_files $uri $uri/ /index.php?$query_string; - } - - location ~ \.php$ { - fastcgi_index index.php; - fastcgi_split_path_info ^(.+\.php)(.*)$; - fastcgi_keep_conn on; - fastcgi_pass unix:/var/run/php/php7.3-fpm.sock; - include /etc/nginx/fastcgi_params; - fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; - } - location ~ /\.ht { - deny all; - } - - location ^~ /data { - deny all; - } -}</pre></code> - <p>Then enable the site by linking it to the sites-enabled directory:</p> - <pre><code>ln -s /etc/nginx/sites-available/<strong>mail</strong> /etc/nginx/sites-enabled/</pre></code> - <p>Reload nginx:</p> - <pre><code>systemctl reload nginx</pre></code> - <p>Finally get certifications if you are using a new subdomain:</p> - <pre><code>certbot --nginx</pre></code> - <p>After that go to <code><strong>mail.domain.com</strong>/?admin</code> and login with the default username and password: admin, 12345. Now you are in the admin panel and the first thing you do should be to change the adminsitrator password by looking in the security tab on the left.</p> - <img src="pix/rainloop-1.png" alt=rainloop> - - <p> After securing the admin account you can go to domains and add your own email address.</p> - <img src="pix/rainloop-2.png" alt=rainloop> - <p>Finally, go to <code><strong>mail.domain.com</strong></code> and login with your email address and password.</p> - <h2 id="contribution">Contribution</h2> - <ul> - <li><a href=https://deniz.telci.org/>Deniz Telci</a> - XMR: <code>4AcKbpTUc3QX2zHYdh9HZwJAQyexdybFhF1WhXTFhxAcV9jgzB6kroqGZDgeW3rQqXEMYJioYo61kaLBqstwecty9Bjbr4v</code></li> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/rss-bridge.html b/rss-bridge.html deleted file mode 100644 index 3fea0ff..0000000 --- a/rss-bridge.html +++ /dev/null @@ -1,98 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Setting up RSS Bridge – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Setting up RSS Bridge</h1></header> - <nav></nav> - <main> - - <p>RSS Bridge is a useful utility you can use to help you avoid the big tech sites, like Facebook and Twitter, which instead of the feed you usually would see, will be a based and minimalist RSS feed. </p> - - - <p>You'll need a server or VPS. Nearly any Operating system is supported but for this tutorial I'm gonna presume you're using a Debian-based OS. You'll also need a domain name pointing to your server's IP address <a href="https://landchad.net/dns.html">which is explained in this tutorial.</a> - </p> - - - -<h2>Installation</h2> - -<h3>Setting Up and Configuring</h3> - -<p>First things first you'll need to make sure that you've hardened you SSH so that password authentication is disabled and you'll also want to setup Fail2Ban. -There's a great tutorial on how to do this <a href="https://landchad.net/sshkeys.html">which can be read here.</a> -</p> - -<p> -Next we'll install the required packages: -</p> - -<pre><code>apt install -y curl unzip nginx certbot php-fpm php-mysql php-cli php7.3-mbstring php7.3-curl php7.3-xml php7.3-sqlite3 php7.3-json</code></pre> - -<p>We now have to create the website configuration file. Create/open the a file below:</p> -<pre><code>nano /etc/nginx/sites-available/rss-bridge</code></pre> -<p>And add the following content:</p> - -<pre><code>server { - root /var/www/rss-bridge; - index index.php index.html index.htm index.nginx-debian.html; - server_name rss-bridge.<strong>example.org</strong>; - - location / { - try_files $uri $uri/ =404; - } - - location ~ \.php$ { - include snippets/fastcgi-php.conf; - fastcgi_pass unix:/var/run/php/php7.3-fpm.sock; - } - - location ~ /\.ht { - deny all; - } -} -</code></pre> - -<p>After you have saved the file, you need to create a symlink so the server actually will read the file.</p> -<pre><code>ln -s /etc/nginx/sites-available/rss-bridge /etc/nginx/sites-enabled/rss-bridge</code></pre> - -<p>Then we have to create the folder where the service will reside in.</p> -<pre><code>mkdir -p /var/www/rss-bridge -cd /var/www/rss-bridge -</code></pre> - -<p>Lets download the latest version of RSS-Bridge in the directory.</p> -<p>The newest version can be found <a href="https://github.com/RSS-Bridge/rss-bridge/releases">here</a>, at the time of writing that is "RSS-Bridge 2021-04-25."</p> - <pre><code>wget https://github.com/RSS-Bridge/rss-bridge/archive/refs/tags/<strong>2021-04-25.zip</strong></code></pre> -<p>Unzip the file:</p> -<pre><code>unzip <strong>2021-04-25.zip</strong></code></pre> -<p>This will create a directory called rss-bridge-version-number, we now want to move all the file contents of the newly created directory to the one we are in</p> -<pre><code>mv <strong>rss-bridge-2021-04-25</strong>/* . -rm -rf <strong>rss-bridge-2021-04-25 2021-04-25.zip</strong> -</code></pre> - -<p>Now all we need to do is grant read/write permissions and reload the web server.</p> - -<pre><code>chown -R www-data:www-data /var/www/rss-bridge -systemctl reload nginx -</code></pre> - -<p>That's it, you should now have a working rss-bridge installed. But you should definately get an SSL certifcate installed <a href="https://landchad.net/certbot.html">which is done briefly here</a>.</p> - - -<ul> - <li><a href="https://handskemager.xyz">handskemager.xyz</a></li> - <li>Bitcoin: <code class=crypto>bc1qhfjgwjzksf2auqjefwpvq20wvyugq3lhqgkxvu</code></li> - <li>Monero: <code class=crypto>88cPx6Gzv5RWRRJLstUt6hACF1BRKPp1RMka1ukyu2iuHT7iqzkNfMogYq3YdDAC8AAYRqmqQMkCgBXiwdD5Dvqw3LsPGLU</code></li> -</ul> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/rss.xml b/rss.xml deleted file mode 100644 index 393aeb2..0000000 --- a/rss.xml +++ /dev/null @@ -1,2641 +0,0 @@ -<?xml version="1.0" encoding="utf-8"?> -<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"> - -<channel> -<title>LandChad.net: Web Guides for Internet Landchads!</title> -<description>Tutorials on minimalist webpage creation and server maintenance.</description> -<language>en-us</language> -<link>https://landchad.net/rss.xml</link> -<atom:link href="https://landchad.net/rss.xml" rel="self" type="application/rss+xml" /> -<image> -<title>LandChad.net Web Guides for Internet LandChads</title> -<url>https://landchad.net/pix/chad.gif</url> -<link>https://landchad.net/rss.xml</link> -</image> - -<!-- LB --> - -<item> -<title>Setting up Cgit</title> -<guid>https://landchad.net/cgit.html</guid> -<link>https://landchad.net/cgit.html</link> -<pubDate>Tue, 14 Sep 2021 14:06:48 -0400</pubDate> -<description><![CDATA[ - <header> - <h1>Setting up Cgit</h1> - <img src="pix/cgit.svg" class="titleimg"> - </header> - <main> - <p> - Once you have your server hosting your git repositories, you might want to allow others to browse - your repositories on the web. Cgit is a Free Software that allows browsing git repositories through - the web. </p> - <p> - Note that Cgit is a read-only frontend for Git repositories and doesn't have issues, pull requests - or user management. If that's what you want, consider installing Gitea instead.</p> - <h2>Installing cgit and fcgiwrap</h2> - <h3>Install fcgiwrap</h3> - <p> - NGINX doesn't have the capability to run CGI scripts by itself, it depends on an intermediate layer - like fcgiwrap to run CGI scripts like cgit:</p> - <pre><code>apt install fcgiwrap</code></pre> - <p>And now we can install cgit itself with:</p> - <pre><code>apt install cgit</code></pre> - <h2>Setting up NGINX</h2> - <p> - You should have an NGINX server running with a TLS certificate by now. Add the following configuration - to your server to pass the requests to Cgit, while serving static files directly:</p> - <pre><code> -server { - listen 443 ssl; - listen [::]:443 ssl; - ssl_certificate /etc/ssl/nginx/<strong>git.example.org</strong>.crt; - ssl_certificate_key /etc/ssl/nginx/<strong>git.example.org</strong>.key; - server_name <strong>git.example.org</strong>; - root /usr/share/cgit ; - try_files $uri @cgit ; - location @cgit { - include fastcgi_params; - fastcgi_param SCRIPT_FILENAME /usr/lib/cgit/cgit.cgi; - fastcgi_param PATH_INFO $request_uri; - fastcgi_param QUERY_STRING $query_string; - fastcgi_pass unix:/run/fcgiwrap.socket; - } -} - </code></pre> - <p>Then get NGINX to reload your configuration.</p> - <h2>Configuring cgit</h2> - <p>You've got cgit up and running now, but you'll probably see it without any style and without any repository. - To change this, we need to configure Cgit to our liking, by editing <code>/etc/cgitrc</code>. - </p> - <pre><code> -css=/cgit.css -logo=/cgit.svg -virtual-root=/ -# Title and description shown on top of each page -root-title=<strong>Chad's git server</strong> -root-desc=<strong>A web interface to LandChad's git repositories, powered by Cgit</strong> -# The location where git repos are stored on the server -scan-path=/srv/git/ - </code></pre> - <p>This configuration assumes you followed the <a href="/git">git hosting guide</a> and store your repositories - on the <code>/srv/git/</code> directory.</p> - <p>Cgit's configuration allows changing many settings, as documented on the cgitrc(5) manpage installed with - Cgit.</p> - <h3>Changing the displayed repository owner</h3> - <p>Cgit's main page shows each repo's owner, which is "git" in case you followed the git hosting guide, but you - might want to change the name to yours. Cgit shows the owner's system name, so you need to modify the git - user - to give it your name:</p> - <pre><code> -usermod -c "<strong>Your Name</strong>" git - </code></pre> - <h3>Changing the repository description</h3> - <p>Navigate to your bare repository on the server and edit the <code>description</code> file inside it</p> - <h3>Displaying the repository idle time</h3> - <p>To do this, we need to create a post-receive hook for each repository that updates the file cgit uses - to determine the idle time. Inside your repository, create a file <code>hooks/post-receive</code> and add - the following contents:</p> - <pre><code> -#!/bin/sh -agefile="$(git rev-parse --git-dir)"/info/web/last-modified -mkdir -p "$(dirname "$agefile")" && -git for-each-ref \ - --sort=-authordate --count=1 \ - --format='%(authordate:iso8601)' \ - >"$agefile" - </code></pre> - <p>And give it execution permissions with:</p> - <pre><code>chmod +x hooks/post-receive</code></pre> - <p>Next time you push to that repository, the idle time should reset and show the correct value.</p> - <h2>Contribution</h2> - <ul> - <li>Ariel Costas – <a href="https://costas.dev">website</a>, <a - href="https://costas.dev/donations/">donations</a></li> - </ul> - </main> - -]]></description> -</item> - - -<item> -<title>Self hosting</title> -<guid>https://landchad.net/selfhosting.html</guid> -<link>https://landchad.net/selfhosting.html</link> -<pubDate>Sun, 29 Aug 2021 15:35:48 -0400</pubDate> -<description><![CDATA[ - <header><h1>Self hosting</h1></header> - - <main> - <h2>Introduction</h2> - <p>When you have a(n old) computer lying around, and you have cheap electricity and a good internet connection, self hosting might be a good option for you.</p> - <h3>Why would you choose selfhosting?</h3> - <ul> - <li> - You have control over the hardware, and you can upgrade your server in the future. For example: if you host a file server and your hard drive goes full, you can simply add another hard drive or upgrade it. - </li> - <li> - No bandwith limits, storage limits, etc. (some VPSes have this) - </li> - <li> - It <strong>can</strong> be cheaper than using a VPS. This only is the case if you got the server for really cheap and your electricity is cheap. - </li> - <li> - You can have a media server to consoom your content (for example with <code>Jellyfin</code>). You can technically do this on a VPS, but that will be more expensive than self hosting. If you have a media server, you can stream media from your server to more devices. (I recommend just downloading it on your device, but if you have multiple devices, this could be a good solution) - </li> - </ul> - - <h3>Downsides</h3> - <p>Some possible downsides of choosing to host at home could be:</p> - <ul> - <li> - Your ISP not approving of what you're doing. Some ISP's do not condone you hosting at home. Usually when this is the case, it could be harder if you want to forward ports, or it could be impossible to get a static IP address. Check your ISP's terms of service. Sometimes, it will say that hosting a webserver, email server, and more, is not allowed. - </li> - <li> - This can also include blocked ports. ISPs can block certain ports to the world. Sometimes ISPs only block 445/139 (which is for the better as Samba, using these ports isn't really secure and it's outdated). But some ISPs (sadly) block crucial ports like 80 and/or 443. You need to check this before trying anything. If this is the case, a way to get around it is to get another ISP or use an alternative port. A great website to check this is: <a href="https://canyouseeme.org/">canyouseeme.org</a>. You can also check if you did the port forwaring correctly here.</li> - <li> - Security. Opening your network to the public could bring security risks. For example, never open a Samba server to the public, because it's a pretty old protocol, and it has some security vulnerabilities. Be sure you are forwarding the right port, and don't just forward random ports to the internet. Also, if you are getting DDoSed, your ISP will temporarily shut down your whole internet connection. - </li> - <li> - When setting up an email server, it can be way harder to not have your email show up as spam in other's people email. If you use a VPS, this is way easier. - </li> - <li> - Space, power consumption and noise. Of course, this differs per server. - </li> - </ul> - <p>Your mileage may vary, go and check each of these points, and see if selfhosting is the right choice for you. Try and calculate your power consumption and see if your electricity cost is not too expensive.</p> - <p>For me, the upsides outweighed the downsides, which is why I chose to host at home. But, this differs with each person and scenario. Go and research what your exact situation is, before trying anything. Otherwise you'll have to face some bad surprises.</p> - <h2>Hardware</h2> - - <h3>What kind of hardware should you choose?</h3> - <p>If you pay your own electricity bill, power consumption is a big factor. Most old laptop computers are ideal in the sense that they don't use a lot of power, and if the battery still works, you have a built-in UPS! The bad thing is, most old laptop computers aren't that powerful, and they lack in upgradability. (you shouldn't really be using anything older than 2006, and I recommend at least a performance equivalant of a Core 2 CPU) - </p> - <p>If you can find an energy efficient desktop (under 100W), that is a great option. They are pretty upgradable and they don't use a lot of power. They can also be pretty cheap, but old laptops are usually cheaper. If you can afford new hardware, and are willing to build a PC, you can find really power effecient CPU/motherboard combos, and they can be cheap, for example the Celeron J3060. I recommend a low wattage power supply or an effecient one for these kinds of builds. Pico PSUs are pretty tiny and efficient solutions in these builds.</p> - <p>Of course, if you don't pay your electricity bill or cost is not a problem for you, you can use just about any old desktop (as long as it's not from the 90's, I recommend at least a Core 2 chip again, or an Athlon 64 X2).</p> - <h3>Usecases</h3> - <p>Of course, hardware choices depend on the usecase. The above recommendations I gave you work fine for e-mail server, webserver and fileserver types of applications, but they will struggle to transcode video if you are going to host a media server. You'll need a faster CPU, but also a faster GPU. As an example, the Athlon 200GE or 3000G are good and efficient choices for these builds. They are decent CPUs, but also have a built in GPU that will transcode video just fine.</p> - <p> - If you need a lot of storage, go for a case with a lot of mounts for hard drives, this way you can easily mount multiple hard drives. Pros of multiple hard drives are redundancy and speed. Cons could be that they create more heat and noise. You can't use a laptop if you want multiple drives, except if you use a hard drive caddy for the CD/DVD drive bay. Some business laptops even support RAID 1 (redundancy) and RAID 0 (speed and more storage, but you lose your files if one hard drive breaks) this way.</p> - <h2>Getting started</h2> - <h3>Installing Debian</h3> - <p>Once you have the machine, you can install the OS. I recommend Debian, as all of the guides on this website are Debian specific. Debian just werks as a server OS.</p> -</p> -<p>You'll need to burn a Debian install image onto a USB flash drive or a CD. You can download the image <a href="https://www.debian.org/CD/netinst/">here</a>, and you can also find information on how to burn the image onto a USB flash drive or CD there. -</p> -<p>While installing Debian, do not install any desktop environment. But install an SSH server when you get the chance. Also leave webserver unchecked, even if you want to use it as a webserver. You'll have a chance to install this later.</p> -<h3>Port forwaring</h3> -<p>Every time you are going to set up a new server program, you need to forward a port corresponding to that program. For example, HTTP is port 80, HTTPS is 443, etc. You need to set this up on your router's NAT settings (sometimes just called port forwarding, this differs per router). These steps differ for each router. Refer to your routers manual. A simple command to see what your servers IP address is, is to run <code>ifconfig</code> on your server. This shows a lot of network info, but it will also show your local IP address needed for port forwarding. -</p> -<p>Basic ports:</p> -<ul> - <li> - SSH: port 22 (open this port if you want to admin your server outside your network) - </li> - <li> - HTTP: port 80 (open this port if you want basic webserver functionality) - </li> - <li> - HTTPS: port 443 (you should open this port if you are setting up a webserver because encryption) - </li> - </ul> - -<h3>Static or dynamic IP address</h3> -<p>If you want to host your server at home, make sure you have a static IP address, or you can change your dynamic IP address to a static one. Refer to your router settings, some ISPs will have options on this here. If you can't find anything on this, get in touch with your ISP.</p> -<p>Once you've made sure you have a static IP address, you can find out what the IP address is with various websites. You can use a search engine to easily find this out. Write this down as you'll need it later.</p> -<p>Once you're done, you can pretty much follow every guide on this website, the only difference is that you'll need to forward the ports you'll be using for the server.</p> -<h3>Finding the ports you'll need to forward</h3> -<p>If you need to know what port you'll need to forward, there's a command for that. Just type <code>netstat -tulpn</code> in your servers command line. If you want to see the name of the programs, you need to run it as a root user. You can do this by putting <code>sudo</code> before the command.</p> -<pre><code>Local Address State PID/Program name -0.0.0.0:25 LISTEN 887/master -0.0.0.0:1883 LISTEN 22452/mosquitto -0.0.0.0:445 LISTEN 798/smbd -0.0.0.0:993 LISTEN 381/dovecot -127.0.0.1:3306 LISTEN 560/mysqld -0.0.0.0:587 LISTEN 887/master -0.0.0.0:139 LISTEN 798/smbd -127.0.1.1:12301 LISTEN 412/opendkim -0.0.0.0:143 LISTEN 381/dovecot -0.0.0.0:465 LISTEN 887/master -0.0.0.0:22 LISTEN 472/sshd -:::25 LISTEN 887/master -:::443 LISTEN 1769/apache2 -:::1883 LISTEN 22452/mosquitto -:::445 LISTEN 798/smbd</code></pre> -<p><em>Example output</em></p> - -<p>In this example, if you need to find the port number from <code>dovecot</code>, you can look for it in the <code>Program name</code> column. Then you can see in the local address column that the reported local address is <code>0.0.0.0:993</code>. You need to look for the part after the semicolon. In this case it's 993. So you'll need to forward port 993.</p> - -<span class="next"><a href="dns.html">Next: Connect Your Domain and Server</a></span> - -<hr> -<p><em>Written by <a href="https://github.com/hidde-j">hiddej</a></em> - </main> -]]></description> -</item> - - -<item> -<title>Mirror your site over I2P</title> -<guid>https://landchad.net/i2p.html</guid> -<link>https://landchad.net/i2p.html</link> -<pubDate>Sun, 29 Aug 2021 15:32:44 -0400</pubDate> -<description><![CDATA[ - <header><h1>Mirror Your Site Over I2P</h1></header> - - <main> - <img class=titleimg src="pix/i2p.svg" alt="I2P logo"> - <p> - Now you have a website, why not offer it in a private alternative such as the Invisible Internet? - </p> - <h2>Setting up I2P</h2> - <p> - There are 2 main I2P implementations, I2P and i2pd, we are using i2pd in this - guide because it's easier to use in servers. - </p> - <h3>Installing I2P</h3> - <p> - i2pd is in most repos, in debian/ubuntu you can install it simply - with <pre><code>apt install i2pd</code></pre> - </p> - <h3>Enabling I2P</h3> - <p> - We are going to create a user for i2pd, because i2pd finds the configuration - files in its home directory. And it's easier (and more tidy) to have it in a separate user: - </p> - <pre><code>useradd -m i2p -s /bin/bash -su -l i2p -mkdir ~/.i2pd -cd ~/.i2pd</code></pre> - <p> - Now that you're in ~/.i2pd, you have to create a file named - "tunnels.conf". Which is the config file for every hidden service you're - offering over I2P, the content should be like this: - </p> - <pre><code>[<strong>example</strong>] -type = http -host = 127.0.0.1 -port = 8080 -keys = <strong>example.dat</strong></code></pre> - <h3>Getting your I2P Hostname</h3> - <p> - Then, run <code>/usr/sbin/i2pd --daemon</code> to start i2pd and we can retreive our I2P hostname. - </p> - <p> - This can be done in lynx or a command-line browser by going to <code>http://127.0.0.1:7070/?page=i2p_tunnels</code> to get your I2P hostname. - </p> - <p> - You - can also run these commands to find your hostname: - </p> - <pre><code>printf "%s.b32.i2p -" $(head -c 391 /home/i2p/.i2pd/<strong>example.dat</strong> |sha256sum|xxd -r -p | base32 |sed s/=//g | tr A-Z a-z)</code></pre> - <h2>Adding the Nginx Config</h2> - <p> - From here, the steps are almost identical to setting up a normal website configuration file. - Follow the steps as if you were making a new website on the webserver - <a href="nginx.html">tutorial</a> up until the server block of code. Instead, paste this: - </p> - <pre><code>server { -listen 127.0.0.1:8080 ; -root /var/www/<strong>example</strong> ; -index index.html ; -}</code></pre> - <aside> - <h4>Clarifications<h4> - <p> - Nginx will listen in port 8080, but i2pd will forward your port - 8080 to the i2p site port 80. This way you don't have to deal with server names or anything like that - </p> - </aside> - <p> - From here we are almost done, all we have to do is enable the site and reload nginx which is also covered in <a href="nginx.html#enable">the webserver tutorial</a>. - </p> - <h3>Update regularly!</h3> - <p>Make sure to update I2P on a regular basis by running:</p> - <pre><code>apt update && apt install i2pd</code></pre> - <p><strong>Contributor</strong> - <a href="https://qorg11.net" target="_blank">qorg11</a></p> - </main> - - -]]></description> -</item> - - -<item> -<title>Setting up a Calibre library server</title> -<guid>https://landchad.net/calibre.html</guid> -<link>https://landchad.net/calibre.html</link> -<pubDate>Tue, 03 Aug 2021 13:49:21 -0400</pubDate> -<description><![CDATA[ - <header><h1>Setting up a Calibre library server</h1></header> - - <main> - <img src="pix/calibre.png" alt="Calibre logo" class=titleimg> - <p> - The Calibre library server is a great way to store your eBooks. - It allows you to: - </p> - <ul> - <li>Share your books with others.</li> - <li>Easily transfer your books between devices and access them from anywhere.</li> - </ul> - <h2>Installation</h2> - <p>Install the Calibre package. - You might also want rsync to upload books.</p> - <pre><code>apt install -y calibre rsync -mkdir /opt/calibre</code></pre> - <p> - Either upload your existing library using <code>rsync</code>. For example to <code>/opt/calibre/</code>. - </p> - <p> - On client: - </p> - <pre><code>cd ~/Documents -rsync -avuP <strong>your-library-dir</strong> root@<strong>example.org</strong>:/opt/calibre/</code></pre> - <p> - Or create a library and add a book to it: - </p> -<pre><code>cd /opt/calibre -calibredb add <strong>book.epub</strong> --with-library <strong>your-library</strong></code></pre> - <aside> - <p> - For more information about the <code>calibredb</code> command see <code>man calibredb</code>. - </p> - </aside> - <p> - Add a new user to protect your server: - </p> - <pre><code>calibre-server --manage-users</code></pre> - <h2>Creating a service</h2> - <p> - Create a new file <code>/etc/systemd/system/calibre-server.service</code> and add the following: - </p> -<pre><code>[Unit] -Description=Calibre library server -After=network.target -[Service] -Type=simple -User=root -Group=root -ExecStart=/usr/bin/calibre-server --enable-auth --enable-local-write /opt/calibre/your_library --listen-on 127.0.0.1 -[Install] -WantedBy=multi-user.target -</code></pre> - <aside> - <p> - You can change the port with the <code>--port</code> prefix. Additional information <code>man calibre-server</code>. - </p> - </aside> - <p> - Issue <code>systemctl daemon-reload</code> to apply the changes. - </p> - <p> - Enable and start the service. - </p> -<pre><code>systemctl enable calibre-server -systemctl start calibre-server</code></pre> - <h2>A reverse proxy with Nginx</h2> - <p> - Create a new file <code>/etc/nginx/sites-available/calibre</code> and enter the following: - </p> -<pre><code>server { - listen 80; - client_max_body_size 64M; # to upload large books - server_name <strong>calibre.example.org</strong> ; - location / { - proxy_pass http://127.0.0.1:8080; - } -}</code></pre> - <p>Issue a Let's Encrypt certificate. <a href="certbot.html">Detailed instructions and additional information</a>.</p> - <pre><code>certbot --nginx</code></pre> - <p>Now just go to <strong>calibre.example.org</strong>. The server will request an username and a password.</p> - <a href="pix/calibre-1.png"> - <img src="pix/calibre/calibre-1.png" alt="calibre"> - </a> - <p>After login you will see something like this.</p> - <a href="pix/calibre-1.png"> - <img src="pix/calibre/calibre-2.png" alt="calibre"> - </a> - <h2>Contribution</h2> - <li>Author: rflx – <a href="https://rflx.xyz">website</a> -- XMR: <code class=crypto>48T5XpHTXAZ5Nn8YCypA4aWn1ffQLHJkFGDArXQB6cmrP6cqLY72cu7CR2iq2MmL5Ndu3d47e5MKjGpL4prYgdrTCFAHD9c</code> - </li> - </main> -]]></description> -</item> - - -<item> -<title>Jitsi Video Chat</title> -<guid>https://landchad.net/jitsi.html</guid> -<link>https://landchad.net/jitsi.html</link> -<pubDate>Tue, 03 Aug 2021 13:00:23 -0400</pubDate> -<description><![CDATA[ - <header><h1>Jitsi Video Chat</h1></header> - - <main> - <img src="pix/jitsi.svg" alt="Jitsi" class=titleimg> - <p> - <dfn>Jitsi</dfn> is a set of open-source projects that allows you to easily build and deploy secure video conferencing solutions. - </p> - <p> - Is really easy to install, and also a really good private, federated and libre alternative to Zoom or other video conferencing software. - You can create calls just by typing the URL, and loging-in is not necessary. - </p> - <h2>Dependencies and Installation</h2> - <p>First, install some dependencies:</p> - <pre><code>apt install gpg apt-transport-https nginx python3-certbot-nginx</code></pre> - <p>Jitsi has its own package repository, so let's add it.</p> - <pre class=wide><code>curl https://download.jitsi.org/jitsi-key.gpg.key | gpg --dearmor > /usr/share/keyrings/jitsi-keyring.gpg -echo 'deb [signed-by=/usr/share/keyrings/jitsi-keyring.gpg] https://download.jitsi.org stable/' > /etc/apt/sources.list.d/jitsi-stable.list -apt update -y</code></pre> - <p> - Ok. So now we can install Jitsi, but before we do that, let's the firewall <code>ufw</code>, in case you - have it enabled, and the SSL certificate. - </p> - <h2>Enable Required Ports</h2> - <p>If you are using <a href="ufw.html">ufw</a> or another firewall, there are several ports we need to ensure are open:</p> - <pre><code>ufw allow 80/tcp -ufw allow 443/tcp -ufw allow 10000/udp -ufw allow 3478/udp -ufw allow 5349/tcp -ufw enable</code></pre> - <p>For your information, these allow the following:</p> - <ul> - <li>80 TCP – Certbot.</li> - <li>443 TCP – General access to Jitsi Meet.</li> - <li>10000 UDP – General network video/audio communications.</li> - <li>3478 UDP – Quering the stun server (coturn, optional, needs config.js change to enable it).</li> - <li> - 5349 TCP – Fallback network video/audio communications over TCP (when UDP is blocked for example), served by coturn. - </li> - </ul> - <h2>SSL certificate</h2> - <p> - I'll be using <a href="./certbot.html" target="blank">certbot</a> and - <a href="./nginx.html" target="blank">Nginx</a> to generate a certificate - for the Jitsi subdomain to allow encrypted connections. - </p> - <pre><code>certbot --nginx certonly -d <strong>meet.example.org</strong></code></pre> - <p> - We will not create an Nginx config file for Jitsi because the Jitsi package we will be installing will do that automatically. - </p> - <h2>Installation</h2> - <p>To begin the installation process, just run:</p> - <pre><code>apt install jitsi-meet</code></pre> - <p> - It will ask you for your <code><strong>hostname</strong></code - >; there you'll need to input the subdomain you have just added to Nginx, like - <code><strong>meet.example.org</strong></code>. - </p> - <p>For the SSL certificate, choose <code>I want to use my own certificate</code>.</p> - <p> - When it ask you for the certification key and cert files, input - <code>/etc/letsencrypt/live/<strong>meet.example.org</strong>/privkey.pem</code> and - <code>/etc/letsencrypt/live/<strong>meet.example.org</strong>/cert.pem</code> respectively. - </p> - <h2>Using Jitsi</h2> - <img src="pix/jitsi-01.webp" alt="Jitsi once installed"> - <p>Jitsi can be used in a browser by then just going to <code>meet.example.org</code>.</p> - <p>Note that there are also Jitsi clients for all major platforms:</p> - <ul> - <li><a href="https://desktop.jitsi.org/Main/Download.html">Desktop</a> (Windows, MacOS, GNU/Linux)</li> - <li>Android (<a href="https://f-droid.org/en/packages/org.jitsi.meet/">F-Droid</a> and <a href="https://play.google.com/store/apps/details?id=org.jitsi.meet">Google Play</a>)</li> - <li><a href="https://apps.apple.com/us/app/jitsi-meet/id1165103905">iPhone/iOS</a></li> - </ul> - <p> - <strong>When using a Jitsti app for the first time, remember to go to the "Settings" menu and change your server name to the Jitsi site you just created.</strong> - </p> - <p>When you create a video chatroom, its address will appear as <code><strong>meet.example.org/yourvideochatname</strong></code> and can be shared as such.</p> - <h2>More info</h2> - <p> - This article is based on <a href="https://jitsi.github.io/handbook/docs/devops-guide/devops-guide-quickstart" target="blank">the original documentation</a>. There you can find more details and configurations. - </p> - <ul> - <li>Written by <a href="https://josefabio.com" target="blank">Jose Fabio.</a> Donate Monero: <code class="crypto">484RLdsXQCDGSthNatGApRPTyqcCbM3PkM97axXezEuPZppimXmwWegiF3Et4BHBgjWR7sVXuEUoAeVNpBiVznhoDLqLV7j</code> <a href="https://josefabio.com/figures/monero.jpg" class="crypto" target="blank">[QR]</a></li> - <li>Edited and revised by <a href="https://lukesmith.xyz">Luke</a>.</li> - </ul> - </main> - - -]]></description> -</item> - - -<item> -<title>PeerTube Instance</title> -<guid>https://landchad.net/peertube.html</guid> -<link>https://landchad.net/peertube.html</link> -<pubDate>Thu, 29 Jul 2021 10:44:56 -0400</pubDate> -<description><![CDATA[ - <header><h1>PeerTube Instance</h1></header> - - <main> - <img class=titleimg src="pix/peertube.svg" alt="PeerTube logo"> - <p>PeerTube is a self-hosted and (optionally) federated video sharing platform that saves bandwith on videos the more people watch. - PeerTube instances can follow each other to share videos and grow the federated network, - but you can always keep your instance to yourself if you choose to.</p> - <h2>Prerequisites</h2> - <p><strong>Most</strong> of PeerTube's dependencies can be installed with this command:</p> - <pre><code>apt install -y curl sudo unzip vim ffmpeg postgresql postgresql-contrib g++ make redis-server git python-dev cron wget</code></pre> - <p>It's also important to start all associated daemons:</p> - <pre><code>systemctl start postgresql redis</code></pre> - <p>PeerTube also requires <strong>NodeJS 14</strong> and <strong>yarn</strong> which cannot be installed from the Debian repositories. This means they have to be installed from separate, external repos:</p> - <pre><code>curl -fsSL https://deb.nodesource.com/setup_14.x | bash - -apt install -y nodejs -npm install --global yarn</code></pre> - <p>In addition to these dependencies, it's recommended to create a dedicated PeerTube user to install and manage PeerTube.</p> - <pre><code>useradd -m -d /var/www/peertube -s /bin/bash -p peertube peertube</code></pre> - <h2>Database</h2> - <p>PeerTube requires a PostgreSQL database to function. To create it, first make a new Postgres user named PeerTube:</p> - <pre><code>su postgres -createuser -P peertube -createdb -O peertube -E UTF8 -T template0 peertube_prod -psql -c "CREATE EXTENSION pg_trgm;" peertube_prod -psql -c "CREATE EXTENSION unaccent;" peertube_prod -exit</code></pre> - <p>Be sure to <strong>make note of your Postgres user password,</strong> as it will be needed later when setting up PeerTube.</p> - <h2>Installation</h2> - <p>This handy one-liner can be used to determine the latest PeerTube version:</p> - <pre><code>VERSION=$(curl -s https://api.github.com/repos/chocobozzz/peertube/releases/latest | grep tag_name | cut -d '"' -f 4) && echo "Latest Peertube version is $VERSION"</code></pre> - <p>Next, a basic directory structure needs to be setup in the PeerTube user's home directory (/var/www/peertube).</p> - <p>To ensure permissions remain the same while managing files as PeerTube, <code>sudo</code> can be used to perform actions:</p> - <pre><code>sudo -u peertube mkdir config storage versions -sudo -u peertube chmod 750 config</code></pre> - <p>Finally, a PeerTube release can be downloaded from the GitHub page and installed using yarn:</p> - <pre><code>cd versions -sudo -u peertube ln -s versions/peertube-${VERSION} ./peertube-latest -cd ./peertube-latest && sudo -H -u peertube yarn install --production --pure-lockfile</code></pre> - <h2>Configuration</h2> - <p>PeerTube's default config file can be copied over to <code>/var/www/peertube/config.production.yaml</code> so it can actually be used:</p> - <pre><code>cd /var/www/peertube - sudo -u peertube cp peertube-latest/production.yaml config/production.yaml</code></pre> - <p>Now the <code>production.yaml</code> file must be edited in the following ways:</p> - <p>First, add the hostname:</p> - <pre><code>webserver: - https: true - hostname: <strong>'example.org'</strong> - port: 443</code></pre> - <p>Then, the database:</p> - <pre><code>database: - hostname: 'localhost' - port: 5432 - ssl: false - suffix: '_prod' - username: <strong>'peertube'</strong> - password: <strong>'your_password'</strong> - pool: - max: 5</code></pre> - <p>An email to generate the admin user:</p> - <pre><code>admin: - # Used to generate the root user at first startup - # And to receive emails from the contact form - email: <strong>'chad@example.org'</strong></code></pre> - <p>And <strong>optionally,</strong> email server information:</p> - <pre><code>smtp: - # smtp or sendmail - transport: smtp - # Path to sendmail command. Required if you use sendmail transport - sendmail: null - hostname: <strong>mail.example.org</strong> - port: 465 # If you use StartTLS: 587 - username: <strong>your_email_username</strong> - password: <strong>your_email_password</strong> - tls: true # If you use StartTLS: false - disable_starttls: false - ca_file: null # Used for self signed certificates - from_address: <strong>'admin@example.org'</strong></code></pre> - <h2>NGINX</h2> - <p>PeerTube includes an NGINX configuration that can be copied over to <code>/etc/nginx/sites-available:</code> - <pre><code>cp /var/www/peertube/peertube-latest/support/nginx/peertube /etc/nginx/sites-available/peertube</code></pre> - <p>Because the PeerTube config is so long, it's recommended to use <code>sed</code> to modify the contents of the file, - replacing <code>${WEBSERVER_HOST}</code> with your hostname, - and <code>$(PEERTUBE_HOST)</code> with your localhost and port, which by default should be <code>127.0.0.1:9000</code>: - <pre><code>sed -i 's/${WEBSERVER_HOST}/<strong>example.org</strong>/g' /etc/nginx/sites-available/peertube -sed -i 's/${PEERTUBE_HOST}/127.0.0.1:9000/g' /etc/nginx/sites-available/peertube</code></pre> - <p>Once you're happy with the NGINX config file, link it to <code>sites-enabled</code> to activate it:</p> - <pre><code>ln -s /etc/nginx/sites-available/peertube /etc/nginx/sites-enabled/peertube</code></pre> - <h3>Encryption with Certbot</h3> - <p>It's <strong>highly recommended</strong> to generate certificates for use with your PeerTube site, and this can be easily done with Let's Encrypt's <code>certbot</code> command:</p> - <pre><code>systemctl stop nginx -certbot certonly --standalone -d <strong>example.org</strong> -sudo systemctl restart nginx</code></pre> - <p>The certificates are generated <strong>standalone</strong> since the PeerTube NGINX config file already includes configuration for certbot.</p> - <h2>Running PeerTube</h2> - <p>A config file for a systemd daemon is included in PeerTube and can be setup like so:</p> - <pre><code>cp /var/www/peertube/peertube-latest/support/systemd/peertube.service /etc/systemd/system/ -systemctl daemon-reload</code></pre> - <p>Now, finally, run the PeerTube daemon to start PeerTube:</p> - <pre><code>systemctl start peertube</pre></code> - <h2>Using PeerTube</h2> - <p>To set a password for your admin user, run:</p> - <pre><code>cd /var/www/peertube/peertube-latest && NODE_CONFIG_DIR=/var/www/peertube/config NODE_ENV=production npm run reset-password -- -u root</code></pre> - <p>Login to your PeerTube instance using the admin email specified in your <code>production.yaml</code> file and the admin password you just set.</p> - <img src="pix/peertube-login.jpg" height=400px> - <p>Once logged in, it's recommended to create a separate user without admin privileges for uploading videos to PeerTube. - This can be done easily from the users tab in the administration section:</p> - <p>Enjoy your PeerTube instance!</p> - <hr> - <h2>Updating PeerTube</h2> - <p>PeerTube is constantly adding new features, so it's a good idea to <a href="https://github.com/Chocobozzz/PeerTube/blob/develop/CHANGELOG.md">check for new updates</a> and add them if you wish. Just in the past year, they have added livestreaming and more.</p> - <p>Updating is fairly easy now since an <code>upgrade.sh</code> script has been added. Just run:</p> - <pre><code>cd /var/www/peertube/peertube-latest/scripts && sudo -H -u peertube ./upgrade.sh</code></pre> - <p> - Although check the <a href="https://github.com/Chocobozzz/PeerTube/blob/develop/CHANGELOG.md">changelog</a> to see if there are additional manual requirements for particular updates. - </p> - <hr> - <p><em>Written by <a href="https://denshi.live">Denshi.</a> Donate Monero <a href="https://denshi.live/donate.html">here</a> <a href="https://denshi.live/images/monero.png">[QR]</a></em></p> - </main> - -]]></description> -</item> - - -<item> -<title>Server-Side Scripting with CGI</title> -<guid>https://landchad.net/cgi.html</guid> -<link>https://landchad.net/cgi.html</link> -<pubDate>Sun, 25 Jul 2021 14:29:44 -0400</pubDate> -<description><![CDATA[ - <header><h1>Server-Side Scripting with CGI</h1></header> - - <main> - <p> - The basic website tutorial here describes how to set up a static - website — one that just serves HTML files saved on your server, - and until you change something manually, the same content will be served - each time a given page is requested. This is perfectly enough for most - personal website needs. This is how blogs should be implemented, instead - of relying on bloatware like WordPress! - </p> - <p> - But sometimes you genuinely <i>do</i> need something more. You need your - website to serve different contents depending on the time, on who the - requester is, on the contents of a database, or maybe process user input - from a form. - </p> - <h2>CGI</h2> - <p> - CGI, or the Common Gateway Interface, is a specification to allow you, - the server owner, to program your web server using pretty much any - programming language you might know. The specification is almost as old - as the Internet itself and for a long time CGI scripting was the primary - method of creating dynamic websites. - </p> - <p> - CGI is a very simple specification indeed. You write a script in your - favorite language, the script receives input about the request in - environment variables, and whatever you print to the standard output - will be the response. Most likely, though, you will want to use a - library for your language of choice that makes a lot of this - request/response handling simpler (e.g. parsing query parameters for - you, setting appropriate headers, etc.). - </p> - <h3>Limitations of CGI</h3> - <p> - While in theory you could implement any sort of functionality with CGI - scripts, it's going to get difficult managing a lot of separate scripts - if they're supposed to be working in tandem to implement a dynamic - website. If you want to build a full out web application, you'd probably - be better off learning a web framework than gluing together Perl - scripts. - </p> - <p> - That said, just as most of the web could be replaced with static - websites, much of the remaining non-static web could be replaced with a - few simple scripts, rather than bloated Ruby on Rails or Django - applications. - </p> - <h2>Let's write a CGI script!</h2> - <p> - We'll implement a simple example CGI script. I'll use Ruby for this - tutorial, but you'll be able to follow along even if you don't know - Ruby, just treat it as pseudocode then find a CGI library for your - language. - </p> - <h3>The working example</h3> - <p> - Our working example will be the Lazy Calculator. Yeah, you're probably - tired of seeing calculator examples in every programming tutorial, but - have you ever implemented one that takes the weekends off? - </p> - <p> - Here's how it will work. When in a browser you submit a request to your - website like - </p> - <pre><code>example.com/calculator.html?a=10&b=32</code></pre> - <p> - you will receive a page with the result of the addition of 10 and 32: - 42. - </p> - <p> - <i>Unless</i> you send your request on a weekend. Then the website will - respond with - </p> - <pre><code>I don't get paid to work on weekends! Come back Monday.</code></pre> - <p> - This example will show a few things that CGI scripts can do that you - wouldn't have been able to get using just file hosting in your - web server: - <ul> - <li> getting inputs from the user; </li> - <li> - getting external information (here just the system time, but you - could imagine instead connecting to a database); - </li> - <li> using the above to create dynamic output. </li> - </ul> - <h3>The code</h3> - <p> - Here's an implementation of the lazy calculator as a Ruby CGI script: - </p> - <pre><code>#!/bin/env ruby -require 'cgi' -require 'date' -cgi = CGI.new -today = Date::today -a = cgi["a"].to_i -b = cgi["b"].to_i -if today.saturday? || today.sunday? - cgi.out do - "I don't get paid to work on weekends! Come back Monday." - end -else - cgi.out do - (a + b).to_s - end -end</code></pre> - <p> - Let's go through what's happening here. - </p> - <h3>The shebang line</h3> - <p> - CGI works by pointing your web server to an executable program. A Ruby - or Python script by itself is not immediately executable by a computer. - But on Unix-like systems you can specify the program that will be able - to execute your file in its first line if it starts with <code>#!</code> - (known as the shebang; read more about it on - <a href="https://en.wikipedia.org/wiki/Shebang_(Unix)">Wikipedia</a>). - </p> - <p> - So if you're going to be using a scripting language, you'll probably - need the appropriate shebang line at the top of your script. If you use - a compiled language, you'll just point your web server to the compiled - executable binary. - </p> - <h3>Query parameters</h3> - <p> - The next interesting lines of code are where we set the variables - <code>a</code> and <code>b</code>. Here we are getting user inputs from - the request. - </p> - <p> - In the example request we mentioned above - (<code>example.com/calculator.html?a=10&b=32</code>), the part - starting from the question mark, <code>?a=10&b=32</code>, is the - <i>query string</i>. This is how users can submit parameters with their - web requests. Usually these parameters are set by e.g. a form on your - website, but in our simple example we'll be just manually manipulating - the URL. - </p> - <p> - The query string contains key-value pairs. The Ruby CGI library makes - them available in the <code>CGI</code> object it provides. We just need - to index it with the desired key, and we'll get the corresponding value. - </p> - <h3>Wrapping it up</h3> - <p> - The remaining parts of the code should be pretty self-explanatory. We - get today's date, check if it's a Saturday or a Sunday, and depending on - that, we instruct the CGI library to output either the answer, or a - "come back later" message. - </p> - <p> - The Ruby library by default returns an HTML response, so we really - should have wrapped our outputs in some <code>html</code>, - <code>body</code>, etc. tags. Alternatively, we could have specified - that the response is just plain text with - </p> - <pre><code>cgi.out 'text/plain' do</code></pre> - <p> - In general, your CGI library will probably have ways of specifying all - sorts of HTTP response headers, like status code, content type, etc. - </p> - <h2>Making it work</h2> - <p> - We have a CGI script, now let's point our web server to it. - </p> - <h3>Installing FastCGI</h3> - <p> - If you're using Nginx, install <code>fcgiwrap</code>: - </p> - <pre><code>apt install fcgiwrap</code></pre> - <p> - This installs the necessary packages for Nginx to use FastCGI — a - layer between your web server and CGI script that allows for faster - handling of scripts than if the web server had to handle it all by - itself. - </p> - <p> - Other web servers will probably have a similarly simple way of enabling - FastCGI, or you can look into other methods for launching CGI scripts. - </p> - <h3>Nginx configuration</h3> - <p> - In the configuration file for your website, add something like the - following: - </p> -<pre><code>location /calculator.html { - include fastcgi_params; - fastcgi_param SCRIPT_FILENAME /usr/local/bin/lazy-calculator.rb; - fastcgi_param QUERY_STRING $query_string; - fastcgi_pass unix:/run/fcgiwrap.socket; -}</code></pre> - <p> - <code>fastcgi_param</code> directives specify various parameters for - FastCGI. <code>SCRIPT_FILENAME</code> should point to your executable. - For <code>QUERY_STRING</code>, we just copy Nginx's - <code>$query_string</code> variable. You might want to pass other - information to your CGI script as well, see for example - <a href="https://wiki.debian.org/nginx/FastCGI">the Debian wiki</a> for - a more detailed example, including pointing to an entire directory of - CGI scripts, rather than adding each one by hand to your web server - config. - </p> - <h2>Contribution</h2> - <ul> - <li>Martin Chrzanowski -- <a href="https://m-chrzan.xyz">website</a>, <a href="https://m-chrzan.xyz/donate.html">donate</a></li> - </ul> - </main> - -]]></description> -</item> - - -<item> -<title>XMPP Server (Prosody)</title> -<guid>https://landchad.net/xmpp.html</guid> -<link>https://landchad.net/xmpp.html</link> -<pubDate>Wed, 21 Jul 2021 22:58:21 -0400</pubDate> -<description><![CDATA[ - <header><h1>XMPP Server (Prosody)</h1></header> - - <main> - <img class=titleimg src="pix/xmpp.svg" alt="XMPP Logo and Icon"> - <p>XMPP is a fantastically simple protocol that's usually used as a messenger. - It's highly extensible, - better than IRC, - lighter and more decentralized and Matrix - and Telegram and normie social media can't hold a candle to it. - </p> - <p> - XMPP is so decentralized and extensible that there are many <em>different</em> XMPP servers. - Here, let's set up an <a href="https://prosody.im/">Prosody</a> XMPP server. - </p> - <h2>Installation</h2> - <p> - Prosody is in the Debian repositories, so we can easily install it on our server with the following command: - </p> - <pre><code>apt install prosody</code></pre> -<h2>Configuration</h2> -<p> -The Prosody configuration file is in <code>/etc/prosody/prosody.cfg.lua</code>. -To set it all up, we will be changing several things. -</p> -<h3>Setting Admins</h3> -<p> -Let's go ahead and set who our admin(s) will be. -Find the line that says <code>admins = { }</code> and to this we can specify one or more server admins. -</p> -<pre><code># To add one admin: -admins = { "chad@example.org" } -# We can add more than one by separating them by commas. (This file is written in Lua.) -admins = { "chad@example.org", "chadmin@example.org" }</code></pre> -<p> -Note that we have not created these accounts yet, we will do this <a href=#user>below</a>. -</p> -<h3>Set the Server URL</h3> -<p> -Find the line <code>VirtualHost "localhost"</code> and replace <code>localhost</code> with your domain. -In our case, we will have <code>VirtualHost "example.org"</code> -</p> -<h3>Multi-User Chats</h3> -<p> -Most people will probably want the ability to have chats with more than two users. -This is easily enough to enable. -In the config file, add the following: -</p> -<pre><code>Component "<strong>chat.example.org</strong>" "muc" - modules_enabled = { "muc_mam" } - restrict_room_creation = "admin"</code></pre> -<p> -On the first line, you must have a separate subdomain for your multi-user chats. -I use the <code>chat.</code> subdomain, but some use <code>muc.</code>. -Anything if possible. -</p> -<p> -The second line is important because it prevents non-admins from creating and squatting rooms on your server. -The only situation where you might not want that is if you indend to open a general public chat system for people you don't know. -</p> -<aside> -<p> -Read more about the <code>muc</code> plugin on the Prosody documentation page <a href="https://prosody.im/doc/modules/mod_muc">here</a>. -</p> -</aside> -<h3>End-to-end Encryption</h3> -<p> -Importantly, we'll want end-to-end encryption enabled for user privacy. -</p> -<p> -Find the array beginning with <code>modules_enabled</code>. -This includes a list of modules to be used. -Add -<code>"omemo_all_access";</code> to that list. -Additionally, be sure to change the module <code>pep</code> to <code>pep_simple</code> or this will cause a conflict.</p> -<p> -This module is not installed by default, -but you can easily download it by running the following command on the command prompt -to download and install the module to the correct directory. -</p> -<pre class=wide><code>curl -sL https://hg.prosody.im/prosody-modules/raw-file/785389a2d2b3/mod_omemo_all_access/mod_omemo_all_access.lua > /usr/lib/prosody/modules/mod_omemo_all_access.lua</code></pre> -<h3>Other things to check</h3> -<p>Check the config file for other settings you might want to change. -For example, if you want to run a general public XMPP server, you can allow anyone to create an account by changing <code>allow_registration</code> to <code>true</code>. -</p> -<h2>Certificates</h2> -<p> -Obviously, we want to have client-to-server and server-to-server encryption. -Nowadays, use can use Certbot to generate certificates and use a convenient command below <code>prosodyctl</code> to import them. -</p> -<p> -<strong>If you have multi-user chat enabled, be sure to get a certificate for that subdomain as well.</strong> -Include the <code>--nginx</code> option assuming you have an Nginx server running. -</p> -<pre><code>certbot -d <strong>chat.example.org</strong> --nginx</code></pre> -<p> -Once you have the certificates for encryption, run the following to import them into Prosody. -</p> -<pre><code>prosodyctl --root cert import /etc/letsencrypt/live/</code></pre> -<p> -Note that you might get an error that a certificate has not been found if your <code>muc</code> subdomain and your main domain share a certificate. -It should still work, this is just notifying you that no specific -</p> -<p> -For user privacy, we will definitely want to install and enable encryption with OMEMO. -</p> -<h2 id=user>Creating users/admins manually</h2> -<p> -Let's manually create the admin user we prepared for above. -Note that you can indeed do this in your XMPP client if you have not disabled registration, but this is how it is done on the command line: -</p> -<pre><code>prosodyctl adduser <strong>chad@example.org</strong></code></pre> -<p>This will prompt you to create a password as well.</p> -<h2>Make changes active</h2> -<p> -With any system service, use <code>systemctl reload</code> or <code>systemctl restart</code> to make the new settings active: -</p> -<pre><code>systemctl restart prosody</code></pre> -<h2>Using your Server!</h2> -<p> -Once your server is set up, you just need an XMPP client to use your new and secure chat system. -</p> -<ul> - <li>GNU/Linux: <a href="https://dino.im/">Dino</a> or <a href="https://gajim.org/">Gajim</a></li> - <li>Windows: <a href="https://gajim.org/">Gajim</a> also runs on Windows.</li> - <li>Android: <a href="https://conversations.im/">Conversations.im</a></li> - <li>Mac/iOS: <a href="https://monal.im/">Monal IM</a> or <a href="https://siskin.im/">Siskin</a> for iOS alone</li> - <li>command-line (GNU/Linux, MacOS, Windows): <a href="https://profanity-im.github.io/">Profanity</a></li> - <li><a href="https://xmpp.org/software/clients.html">See a more complete list kept by XMPP</a></li> -</ul> -<p> -Install whichever of these clients you want on your computer or phone and you can log into your new XMPP server with the account you made. -Note that if you enabled public registration, anyone can create an account on your server through one of these clients. -</p> -<h3>Account addresses</h3> -<p> -XMPP account addressed look just like email addresses: <code><strong>username@example.org</strong></code>. -You can message any account on any XMPP server on the internet with that format. -</p> -<h3>Note on MUCs (multi-user chats)</h3> -<p> -Remember that MUCs are kept on a separate subdomain that we created and should've gotten a certificate for above, for example, <code><strong>muc.example.org</strong></code>. -Chatrooms are created and referred to in the following format: <code><strong>#chatroomname@muc.example.org</strong></code>. -</p> - </main> - -]]></description> -</item> - - -<item> -<title>Setting up RSS Bridge</title> -<guid>https://landchad.net/rss-bridge.html</guid> -<link>https://landchad.net/rss-bridge.html</link> -<pubDate>Mon, 05 Jul 2021 18:11:15 -0400</pubDate> -<description><![CDATA[ - <header><h1>Setting up RSS Bridge</h1></header> - - <main> - <p>RSS Bridge is a useful utility you can use to help you avoid the big tech sites, like Facebook and Twitter, which instead of the feed you usually would see, will be a based and minimalist RSS feed. </p> - <p>You'll need a server or VPS. Nearly any Operating system is supported but for this tutorial I'm gonna presume you're using a Debian-based OS. You'll also need a domain name pointing to your server's IP address <a href="https://landchad.net/dns.html">which is explained in this tutorial.</a> - </p> -<h2>Installation</h2> -<h3>Setting Up and Configuring</h3> -<p>First things first you'll need to make sure that you've hardened you SSH so that password authentication is disabled and you'll also want to setup Fail2Ban. -There's a great tutorial on how to do this <a href="https://landchad.net/sshkeys.html">which can be read here.</a> -</p> -<p> -Next we'll install the required packages: -</p> -<pre><code>apt install -y curl unzip nginx certbot php-fpm php-mysql php-cli php7.3-mbstring php7.3-curl php7.3-xml php7.3-sqlite3 php7.3-json</code></pre> -<p>We now have to create the website configuration file. Create/open the a file below:</p> -<pre><code>nano /etc/nginx/sites-available/rss-bridge</code></pre> -<p>And add the following content:</p> -<pre><code>server { - root /var/www/rss-bridge; - index index.php index.html index.htm index.nginx-debian.html; - server_name rss-bridge.<strong>example.org</strong>; - location / { - try_files $uri $uri/ =404; - } - location ~ \.php$ { - include snippets/fastcgi-php.conf; - fastcgi_pass unix:/var/run/php/php7.3-fpm.sock; - } - location ~ /\.ht { - deny all; - } -} -</code></pre> -<p>After you have saved the file, you need to create a symlink so the server actually will read the file.</p> -<pre><code>ln -s /etc/nginx/sites-available/rss-bridge /etc/nginx/sites-enabled/rss-bridge</code></pre> -<p>Then we have to create the folder where the service will reside in.</p> -<pre><code>mkdir -p /var/www/rss-bridge -cd /var/www/rss-bridge -</code></pre> -<p>Lets download the latest version of RSS-Bridge in the directory.</p> -<p>The newest version can be found <a href="https://github.com/RSS-Bridge/rss-bridge/releases">here</a>, at the time of writing that is "RSS-Bridge 2021-04-25."</p> - <pre><code>wget https://github.com/RSS-Bridge/rss-bridge/archive/refs/tags/<strong>2021-04-25.zip</strong></code></pre> -<p>Unzip the file:</p> -<pre><code>unzip <strong>2021-04-25.zip</strong></code></pre> -<p>This will create a directory called rss-bridge-version-number, we now want to move all the file contents of the newly created directory to the one we are in</p> -<pre><code>mv <strong>rss-bridge-2021-04-25</strong>/* . -rm -rf <strong>rss-bridge-2021-04-25 2021-04-25.zip</strong> -</code></pre> -<p>Now all we need to do is grant read/write permissions and reload the web server.</p> -<pre><code>chown -R www-data:www-data /var/www/rss-bridge -systemctl reload nginx -</code></pre> -<p>That's it, you should now have a working rss-bridge installed. But you should definately get an SSL certifcate installed <a href="https://landchad.net/certbot.html">which is done briefly here</a>.</p> -<ul> - <li><a href="https://handskemager.xyz">handskemager.xyz</a></li> - <li>Bitcoin: <code class=crypto>bc1qhfjgwjzksf2auqjefwpvq20wvyugq3lhqgkxvu</code></li> - <li>Monero: <code class=crypto>88cPx6Gzv5RWRRJLstUt6hACF1BRKPp1RMka1ukyu2iuHT7iqzkNfMogYq3YdDAC8AAYRqmqQMkCgBXiwdD5Dvqw3LsPGLU</code></li> -</ul> - </main> - -]]></description> -</item> - - -<item> -<title>Rsync: Upload and Sync Files and Websites</title> -<guid>https://landchad.net/rsync.html</guid> -<link>https://landchad.net/rsync.html</link> -<pubDate>Sat, 03 Jul 2021 08:58:29 -0400</pubDate> -<description><![CDATA[ -<header><h1>Rsync: Upload and Sync Files and Websites</h1></header> -<main> - <p>rsync is a simple way to copy files and folders between your local computer and server.</p> - <p>It not only makes file-transfer easy, but it allows you to build and maintain your website offline, then easily upload it to the proper directory on your server so you don't need to constantly be logged into your server to modify your site.</p> -<h2 id="installing-rsync">Installing rsync</h2> -<p>Run the following on your server <em>and</em> on your local machine.</p> -<pre><code>apt install rsync</code></pre> -<h2 id="uploading-files-with-rsync">Uploading files with rsync</h2> -<p>From your local machine you can upload files to your server like this:</p> -<pre><code>rsync -ruvzP <strong>/path/to/file</strong> <strong>root@example.org:/path/on/the/server</strong></code></pre> -<p>You will be prompted for the root password and then uploading will commence.</p> -<p>If you omit <strong>root@</strong>, rsync will not attempt to log in as root, but whatever your local username is.</p> -<h3>Options to rsync</h3> -<p>In this command, we give several options to rsync:</p> -<ul> - <li><code>-r</code> – run recurssively (include directories)</li> - <li><code>-u</code> – update files (do not reupload files that are not changed since last upload)</li> - <li><code>-v</code> – visual, show files uploaded</li> - <li><code>-z</code> – compress files for upload</li> - <li><code>-P</code> – if uploading a large file and upload breaks, pick up where we left off rather than reuploading the entire file</li> -</ul> -<p>Avoid using the commonly used <code>-a</code> option when uploading. It changes can transfer your local machine's user and group permissions to your server, which might cause breakage.</p> -<h3>Scriptability</h3> -<p>It's a good idea to build your website offline, then make an rsync script or bash alias like the one above to upload the edited files when you have made updates.</p> -<h3>Password-less authentication</h3> -<p>To avoid having to manually input your password each upload, you can set up <a href="sshkeys.html">SSH keys</a> to securely idenitify yourself and computer as a trusted.</p> -<h3>Picky trailing slashes</h3> -<p>rsync is very particular about trailing slashes. This is useful, but can be confusing to some new users. Suppose we run the following wanting to mirror our offline copy of our website in the directory we use on our server (<code>/var/www/websitefiles/</code>):</p> -<pre><code>rsync -ruvzP ~/<strong>websitefiles/</strong> root@example.org:/var/www/<strong>websitefiles/</strong></code></pre> -<p>This will <em>not actually do quite what we want</em>. It will take our local <code>websitefiles</code> directory and put it <em>inside</em> <code>websitefiles</code> on the remote machine, ending up with: <code>/var/www/websitefiles/websitefiles</code>.</p> -<p>Instead, remove the trailing slash from the remote server location:</p> -<pre><code>rsync -ruvzP ~/<strong>websitefiles/</strong> root@example.org:/var/www/<strong>websitefiles</strong></code></pre> -<p><code>websitefiles/</code> has been replaced with <code>websitefiles</code>, and this will do what we want.</p> -<h2 id="downloading-file-with-rsync">Downloading files with rsync</h2> -<p>You may just as easily download files and directories from your server with rsync:</p> -<pre><code>rsync -urvzP <strong>root@example.org:/path/to/file</strong> <strong>/path/to/file</strong></code></pre> -<h2 id="contribution">Contribution</h2> -<ul><li>el3ctr0lyte: <a href="https://github.com/el3ctr0lyte">github</a>, XMR: <code class=crypto>86DBJdiG83ZDea6kJgsbVN5tMae5ScfuhJ3PihEMTHatCrGEw2gctyUB92V2fz4R4YhwRaQeAGL5M4gPRXvVvtkULJi4ayk</code></li><li>Substantial revisions by <a href="https://lukesmith.xyz">Luke</a></li></ul> -</main> -]]></description> -</item> - - -<item> -<title>Setup a Pleroma Server</title> -<guid>https://landchad.net/pleroma.html</guid> -<link>https://landchad.net/pleroma.html</link> -<pubDate>Fri, 02 Jul 2021 09:14:32 -0400</pubDate> -<description><![CDATA[ - <header><h1>Setup a Pleroma Server</h1></header> - - <main> - <p>Hopefully by now you won't have to be sold on the invasive practices that social media companies conduct. Websites such as Facebook and Twitter aquire so much data on users that they often know more about you than you know about yourself. -The simple solution to this is to not use social media. However, that just isn't an option for most people. So the next best thing is to setup a self-hosted and federalised social media site so that you have full control over your data. -I've previously made<a href="https://www.youtube.com/watch?v=l7mVsLSsotU"> a video showing all the steps in depth if you want to check it out.</a> If you run into any issues I suggest you look at the video. -</p> - <p>You'll need a server or VPS. Nearly any Operating system is supported but for this tutorial I'm gonna presume you're using a Debian-based OS. You'll also need a domain name pointing to your server's IP address <a href="https://landchad.net/dns.html">which is explained in this tutorial.</a> - </p> -<h2>Installation</h2> -<h3>Setting Up and Configuring</h3> -<p>First things first you'll need to make sure that you've hardened you SSH so that password authentication is disabled and you'll also want to setup Fail2Ban. -There's a great tutorial on how to do this <a href="https://landchad.net/sshkeys.html">which can be read here.</a> -</p> -<p> -Next we'll install the required packages: -</p> -<pre><code>apt install -y curl unzip libncurses5 postgresql postgresql-contrib nginx certbot libmagic-dev</code></pre> -<p> -You can manually configure postgreSQL to suit your system better. <a href="https://docs-develop.pleroma.social/backend/configuration/postgresql/">Check out the documentation here</a> and then run the below command: -</p> -<pre><code>systemctl restart postgresql</code></pre> -<h3>Installing the Pleroma App</h3> -<h4>First as the root user</h4> -<p> -Pleroma is not in the Debian app repositories, so we will install it manually. -First create the Pleroma user by running the below command: -</p> -<pre><code>useradd -m -s /bin/bash -d /opt/pleroma pleroma</code></pre> -<p> -Then, still as root, we will create the required directories and give the Pleroma user ownership of them. -</p> -<pre><code>mkdir -p /var/lib/pleroma/uploads -chown -R pleroma /var/lib/pleroma -mkdir -p /var/lib/pleroma/static -chown -R pleroma /var/lib/pleroma -mkdir -p /etc/pleroma -chown -R pleroma /etc/pleroma</code></pre> -<h4>Now, as the new Pleroma user</h4> -<p> -Now run <code>su -l pleroma</code> to login as the Pleroma user. -Now use the <code>curl</code> command below to download the Pleroma software and unzip it. -</p> -<pre><code>curl 'https://git.pleroma.social/api/v4/projects/2/jobs/artifacts/stable/download?job=<strong>amd64</strong>' -o /tmp/pleroma.zip -unzip /tmp/pleroma.zip -d /tmp/</code></pre> -<aside><p>Note that we are downloading the <strong>amd64</strong> version here. If you know you have a different CPU architecture, replace that with whatever your architecture is.</p></aside> -<pre><code>mv /tmp/release/* /opt/pleroma -rmdir /tmp/release -rm /tmp/pleroma.zip -./bin/pleroma_ctl instance gen --output /etc/pleroma/config.exs --output-psql /tmp/setup_db.psql</code></pre> -<p>We need to briefly return to the root user so we can run the following command (via the postgres user) to set up the database. -Type <code>ctrl-d</code> or run <code>exit</code> to return to the root user, then run: -</p> -<pre><code>su postgres -s $SHELL -lc "psql -f /tmp/setup_db.psql"</code></pre> -<p>Then return to the pleroma user with <code>su -l pleroma</code> and we will test to see that Pleroma can run:</p> -<pre><code>./bin/pleroma_ctl migrate -./bin/pleroma daemon</code></pre> -<p> -That will initialize Pleroma. It might take as long as a minute to get started, so wait a bit, then run the following: -</p> -<pre><code>curl http://localhost:4000/api/v1/instance</code></pre> -<p>If everything is working, this command will give you a long line of messy output. If it is not, you will get a connection error message. -Once it is working successfully, stop the Pleroma daemon and we will interface Pleroma with the web server.</p> -<pre><code>./bin/pleroma stop</code></pre> -<h3>Setup and Configure Nginx</h3> -<p> -Return again to the root user. Let's copy Pleroma's Nginx configuration file from the template given in the installation and enable it: -</p> -<pre><code>cp /opt/pleroma/installation/pleroma.nginx /etc/nginx/sites-available/pleroma.conf -ln -s /etc/nginx/sites-available/pleroma.conf /etc/nginx/sites-enabled/pleroma.conf</code></pre> -<p>Edit the <code>etc/nginx/sites-available/pleroma.conf</code> file and replace <strong>example.tld</strong> with your domain name.</p> -<p> -We now have to get a SSL certificate to enable encryption, since we have a model configuration that already includes SSL information, -just check the brief <a href="standalone.html">the standalone certificate page</a> to get the needed certificate. -Once you've got your cert setup, copy over the Nginx configuration with the below command: -</p> -<p> -Once everything, including your Cerbot certificate is ready, simply reload Nginx with this command: -</p> -<pre><code>systemctl reload nginx</code></pre> -<h3>Setting up the service</h3> -<p> -Pleroma itself runs on a SystemD service similar to other things running on your server like Nginx. To start the service up run the below commands: -</p> -<pre><code>cp /opt/pleroma/installation/pleroma.service /etc/systemd/system/pleroma.service -systemctl start pleroma -systemctl enable pleroma</code></pre> -<p> -If everything worked then when you go to your domain in the web browser you should see a bare-bones Pleroma instance. -</p> -<h3>Creating an Admin User</h3> -<p>You'll be able to create new accounts on the Pleroma instance in the login section on the website but the easiest way to setup an admin account is with the CLI. Simply run the below command replaced with your username: -</p> -<pre><code>su -l pleroma -./bin/pleroma_ctl user new <strong>username</strong> <strong>username</strong>@<strong>example.org</strong> --admin</code></pre> -<p> -If you run into any issues then <a href="https://docs-develop.pleroma.social/backend/installation/otp_en/">feel free to checkout the documentation</a> or send me an email or message. My details are below. -</p> -<ul> - <li><a href="https://biasedriot.co">biasedriot.co</a></li> - <li><a href="https://www.youtube.com/channel/UCehh50T6qtDpt_kEUF33GJw">youtube</a></li> - <li>Bitcoin: <code class=crypto>1Dmn9jEtWAhdLk1HHWkUVNeDdAaBCwNajm</code></li> - <li>Monero: <code>84Y4FZiTbLeR5qc1fBrBhB1yq5agKtEdoixq2w1ysXJv486MiBCz3czGT15bqeXDPpdLoNyF93inxY3BCk6g8mrDMNKoArS</code></li> -</ul> - </main> - -]]></description> -</item> - - -<item> -<title>Certbot on Standalone Domains and Subdomains</title> -<guid>https://landchad.net/standalone.html</guid> -<link>https://landchad.net/standalone.html</link> -<pubDate>Fri, 02 Jul 2021 09:14:29 -0400</pubDate> -<description><![CDATA[ - <header><h1>Certbot on Standalone Domains and Subdomains</h1></header> - - <main> - <p>The command <code>certbot --nginx</code> will take an unencrypted website on an Nginx configuration file, get a certificate for it and change the configuration to use that certificate and thus HTTPS.</p> - <p>Sometimes, however, you are given an Nginx configuration template that already has encryption/HTTPS, so running the automated <code>certbot --nginx</code> is not possible, as it will simply give an error saying that the certicate that Nginx is looking for doesn't already exist and thus the Nginx config is broken.</p> - <p>So suppose you want to get a certificate for <strong>pleroma.example.org</strong> because you are installing Pleroma and the configuration file presupposes a certificate. - In this case you would want to run this:</p> - <pre><code>systemctl stop nginx -certbot certonly --standalone -d <strong>pleroma.example.org</strong> -systemctl start nginx</code></pre> - <p>What we do here is temporarily turn of Nginx, then run a <code>certonly</code> subcommand that generates a certificate for the domain without changing or caring about the Nginx configuration. Then we reactivate Nginx, thus turning back on our webserver.</p> - <p>The reason we deactivate Nginx is that it uses the ports that Certbot will want to bind to, and thus we must temporarily turn Nginx off to let Certbot use those ports. (What it actually does is spin up a dummy webserver that doesn't need to think about the Nginx configuration.)</p> - <p>This is just a little note of something that might confuse people, but the three commands above should suffice. If your site is still managed by Nginx, it should still be able to renew with simple <code>certbot renew --nginx</code> without a problem.</p> - </main> - -]]></description> -</item> - - -<item> -<title>Using UFW as a Firewall</title> -<guid>https://landchad.net/ufw.html</guid> -<link>https://landchad.net/ufw.html</link> -<pubDate>Thu, 01 Jul 2021 16:58:11 -0400</pubDate> -<description><![CDATA[ - <header><h1>Using UFW as a Firewall</h1></header> - - <main> - <p> - <strong>Uncomplicated Firewall</strong> (UFW) is a front-facing program for the more involved <code>iptables</code> firewall program installed in most GNU/Linux distributions. - We can use <code>ufw</code> to restrict machines on the internet to only access the services (SSH, websites etc) you want them to, but it can also be used to prevent programs on the computer itself from accesing parts of the internet it shouldn't. - </p> - <h2 id="how-to-get-it">How to Get It</h2> - <p>Log into your server by pulling up a terminal and typing:</p> - <pre><code>ssh root@<strong>example.org</strong></code></pre> - <p> - This command will attempt to log into your server and run a remote shell. - If you leave the settings default, it should prompt you for your password, and you can just copy or type in the password from Vultr's site. - </p> - <p> - Some VPS providers automatically install <code>ufw</code>, but if you do not have it installed already, install it in the typical way: - </p> - <pre><code>apt install ufw</code></pre> - <h2 id="first-time-setup">First-Time Setup</h2> - <p>You can check the status of <code>ufw</code> right now by running:</p> - <pre><code>ufw status</code></pre> - <p>Without any changes, it should report back <code>Status: inactive</code>. Let's set it up so that only connections to SSH (standardized at port 22) are allowed in, and then enable the firewall:</p> - <aside> - <strong>Careful!</strong> Enabling <code>ufw</code> without allowing SSH will block you from remoting to your server. - Double-check that you have allowed SSH, and if you have changed the default SSH port, put in <em>that</em> number instead. - </aside> - <pre><code>ufw default deny incoming # block all incoming connections by default -ufw allow in ssh # or: ufw allow in 22 -ufw enable</code></pre> - <aside> - <code>ufw</code> has an internal list of protocols applications, and the ports used by them. - In this case, it knwos SSH is on port 22. - We'll go more in detail how to view all protocols <code>ufw</code> knows about. - By default, when you allow an incoming port, it allows that port both on IPv4 and IPv6. - </aside> - <p> - With the firewall enabled and allowing only SSH in, all other ports are prortected from incoming requests. - To view all your rules, run: - </p> - <pre><code>ufw status verbose</code></pre> - <p>A firewall that allows to connect to SSH and their website may look like:</p> - <pre><code>Status: active -Logging: on (low) -Default: deny (incoming), allow (outgoing), deny (routed) -New profiles: skip -To Action From --- ------ ---- -22 (SSH) ALLOW IN Anywhere -80,443/tcp (WWW Full) ALLOW IN Anywhere -22 (SSH (v6)) ALLOW IN Anywhere (v6) -80,443/tcp (WWW Full (v6)) ALLOW IN Anywhere (v6)</code></pre> - <p>If you want to delete e.g. the 'WWW Full' rule, run:</p> - <pre><code>ufw delete allow in 'WWW Full' -ufw reload</pre></code> - <h2 id="enabling-common-services">Enabling Common Services</h2> - <p> - You have blocked all incoming ports but SSH, which means no outsiders would be able to access other services, like an email server or your website. - You should look at the ports your services are open on and enable them individually. - Here is a list of a few common services: - </p> - <h3>Opening Port Numbers</h3> - <p>Suppose you install <a href="gemini.html">a Gemini server</a>, which must broadcast on port 1965. By default <code>ufw</code> blocks all incoming connections on all ports, so whenever you install a new service like this you will have to tell <code>ufw</code> to enable the desired port:</p> - <pre><code>ufw allow 1985</code></pre> - <h3>Websites: HTTP and HTTPS</h3> - <p>HTTP uses port 80 and HTTPS uses port 443. We can enable them like this:</p> - <pre><code>ufw allow 80 -ufw allow 443</code></pre> - <p>But <code>ufw</code> additionally knows the typical ports of common serives, so you can also run this:</p> - <pre><code>ufw allow http -ufw allow https</code></pre> - <p>And that will do the same thing. There are also other abbreviations for common port lists:</p> - <pre><code>ufw allow in 'WWW Full'</code></pre> - <p>To see these other "apps" that <code>ufw</code> knows by default, run <code>ufw app list</code></p> - <h3>Email: IMAP, POP3, and SMTP</h3> - <pre><code>ufw allow in IMAPS -ufw allow in POP3 -ufw allow in SMTP -ufw allow in 'Postfix SMTPS' -ufw allow in 'Mail Submission'</pre></code> - <h2 id="fine-tuning-rules">Fine-Tuning Rules</h2> - <p>Instead of denying all ports by default, you may want to deny (ignores incoming requests) or reject (explicitly tells requests they're not allowed):</p> - <pre><code>ufw default allow in -ufw deny in <strong>PORT</strong> -ufw reject in <strong>PORT</strong> -ufw reload</code></pre> - <p>You can add rules to comments to remember what they are there for:</p> - <pre><code>ufw allow in <strong>PORT</strong> comment 'Secret SSH' -ufw reload -ufw status verbose</code></pre> - <p>Output:</p> - <pre><code>To Action From --- ------ ---- -<strong>PORT</strong> ALLOW IN Anywhere # Secret SSH -<strong>PORT</strong> (v6) ALLOW IN Anywhere (v6) # Secret SSH</pre></code> - <p>To deny outgoing ports:</p> - <pre><code>ufw deny out <strong>PORT</strong></code></pre> - <p>Ratelimiting is useful to protect against brute-force login attacks, like in SSH. Only IPv4 is supported for now. Enable it by running:</p> - <pre><code>ufw limit <strong>PORT</strong>/tcp</code></pre> - <p>To blocklist IP addresses:</p> - <pre><code>ufw deny from <strong>IP_ADDRESS</strong></code></pre> - <p>To read more what you can do with <code>ufw</code>, run:</p> - <pre><code>man ufw</code></pre> - <h2 id="recovering-from-losing-ssh">Recovering SSH</h2> - <p> - If you have accidentally firewalled yourself from logging on your computer, you can recover access by using your VPS's virtual console. - On Vultr, this is on your VPS's menu. To the right of the server name, It is the leftmost icon that looks like a monitor. - </p> - <a href="pix/ssh-01.png"><img src="pix/ssh-01.png" alt="View Console"></a> - <p>Log in through there, and disable ufw by typing:</p> - <pre><code>ufw disable</code></pre> - <h2 id="further-reading">Further Reading</h2> - <ul> - <li><a href="https://wiki.ubuntu.com/UncomplicatedFirewall">Ubuntu Wiki: UncomplicatedFirewall</a></li> - <li><a href="https://help.ubuntu.com/community/Gufw">Gufw (Graphical UFW)</a></li> - <li><code>man ufw</code></li> - </ul> - <strong>Contributor</strong> - <a href="https://shunter.xyz">shunter.xyz</a> - </main> - -]]></description> -</item> - - -<item> -<title>Creating Your Own Chat Server With IRC</title> -<guid>https://landchad.net/irc.html</guid> -<link>https://landchad.net/irc.html</link> -<pubDate>Thu, 01 Jul 2021 16:28:32 -0400</pubDate> -<description><![CDATA[ - <header><h1>Creating Your Own Chat Server With IRC</h1></header> - - <main> - <img class=titleimg src="pix/irc.svg"> - <p> - Creating your own chat server for you and your friends is easy, and you don't have to rely on a complicated system to get started. - IRC is an old but gold protocol, and has clients for basically every operating system made since the 80s, with many powerful modern ones on Linux, Mac, and Windows. - </p> - <p> - Having a chat server for you and your friends makes it impossible for a group of arbitrarily appointed moderators to deplatform you for wrong-think, and gives you greater freedom of communication. - </p> - <h2 id="installing">Installing an IRCd</h2> - <p> - An IRCd is short for "IRC daemon", which just means an IRC server. - The most easy IRCd to setup is <a href="https://ergo.chat/">Ergo</a>. - </p> - <p> - The first thing you need to do is create a new user for the server to be run by. - This is good practice for installing software/servers manually, as it give you more fine-grained control over which permissions the application has. - </p> -<pre><code>useradd -m ergo -s /bin/bash</code></pre> - <p> - Next, we want to switch to our newly created <code>ergo</code> user and create the server directory. - </p> -<pre><code>sudo -i -u ergo -mkdir server</code></pre> - <p> - You can find the latest release of Ergo on its GitHub <a href="https://github.com/ergochat/ergo/releases/latest">latest release</a> page.<br> - There are several platforms available, but you want to choose Linux, most likely <code>linux-x86_64</code>.<br> - Once you have selected the correct package, copy its URL and replace <code><i><release url></i></code> with the package URL (still as the <code>ergo</code> user): - </p> -<pre><code>wget https://github.com/ergochat/ergo/releases/download/v2.7.0/ergo-2.7.0-linux-x86_64.tar.gz -tar -xf ergo-2.7.0-linux-x86_64.tar.gz -mv ergo-2.7.0-linux-x86_64/* -rm -r ergo-2.7.0-linux-x86_64*</code></pre> - <p>Executing <code>ls -l</code> should now yield something like this:</p> -<pre><code>-rw-r--r-- 1 ergo ergo 118825 Jun 8 00:51 CHANGELOG.md --rw-r--r-- 1 ergo ergo 1983 May 31 01:48 README --rw-r--r-- 1 ergo ergo 41440 Jun 8 00:42 default.yaml -drwxr-xr-x 2 ergo ergo 4096 Jul 1 09:01 docs --rwxr-xr-x 1 ergo ergo 9654272 Jun 8 00:53 ergo --rw-r--r-- 1 ergo ergo 1753 May 31 01:48 ergo.motd -drwxr-xr-x 2 ergo ergo 12288 Jul 1 09:01 languages --rw-r--r-- 1 ergo ergo 39722 Jun 8 00:42 traditional.yaml</code></pre> - <p>If you see something similar to the above, that means Ergo is installed, although not quite ready to run yet.</p> - <h2 id="configuring">Configuring Ergo</h2> - <p> - Now that Ergo is installed, you want to configure it to fit the needs of your group.<br> - The configuration in this section is tailored towards a small group of people, and less for a possibly large network, - but it should work for any size of group. - </p> - <p> - First thing, make sure you're still using the <code>ergo</code> user, and are in the <code>~/server</code> directory.<br> - If you aren't, you can run the following to get back there: - </p> -<pre><code>sudo -i -u ergo -cd ~/server</code></pre> - <p> - Next, generate certificate files for TLS: - </p> - <pre><code>./ergo mkcerts</code></pre> - <p> - Ergo comes with a default configuration file with detailed documentation that can be used to guide you through the configuration process. - This guide will help you setup the server for a typical use-case, but if you see any settings that you would like to change along the way, - go ahead and change them, as long as you know what you're doing. - </p> - <p>To start configuring, we need to copy some files:</p> -<pre><code>cp default.yaml ircd.yaml -cp ergo.motd ircd.motd</code></pre> - <p> - The next steps involve editing the newly copied <code>ircd.yaml</code> file. If you do not know how to edit text files from the comment line, - you can use <code>nano</code>, which is very simple, using arrow keys to navigate, <code>CTRL+O</code> to save, and <code>CTRL+X</code> to exit.<br> - Another option is <code>vim</code>, which is a much more powerful text editor, but has a learning curve. It is only recommended for this guide if you already know it.<br> - Lastly, you can copy the <code>ircd.yaml</code> file to a text editor on your computer and edit it with a GUI text editor of your choice. - If that is what you choose to do, you may want to just download the file from <a href="https://raw.githubusercontent.com/ergochat/ergo/master/default.yaml">Ergo's GitHub</a>, - edit it on your computer, clear the <code>ircd.yaml</code> file on the server, and then paste the contents from your computer into the blank file.<br> - No matter how you do it, the next steps assume you can edit the configuration file. - </p> - <p> - <b>Note</b>:<br> - The options highlighted in this section are not a complete overview of all options. - Instead, the options shown are the ones which are most relevant to a small network.<br> - You should read over the configuration file yourself if you are curious about everything you can change. - </p> - <h3 id="configuring-names">Network and server names</h3> - <p> - One of the first properties in the config file is network name. - You can change this to whatever you like, as it will show up as the name when you connect to the server. - </p> -<pre><code># network configuration -network: - # name of the network - name: "Land-Chat"</code></pre> - <p>Change the server name to your server's domain name.</p> -<pre><code># server configuration -server: - # server name - name: "example.org"</code></pre> - <h3 id="configuring-password">Network password</h3> - <p> - The next step is optional, depending on if you want your network password protected or not. - The benefit of password protection is fairly obvious; nobody can connect to your network unless you gave them the password. - If you're wanting to run a public network which anyone can join and create a channel, you want to skip this, but for personal setups, - it is highly recommended. - </p> - <p>Generate a password to use by executing the following:</p> - <pre><code>./ergo genpasswd</code></pre> - <p> - It will ask you to enter a password and confirm it, then you will be given a hashed password.<br> - Copy this password, and paste it into the following field (also removing the <code>#</code> before the <code>password:</code> line): - </p> -<pre><code># password to login to the server, generated using `ergo genpasswd`: -password: "<i><your hashed password></i>"</code></pre> - <h3 id="configuring-motd">Message of the day (MotD)</h3> - <p>Change the MotD (<b>M</b>essage <b>o</b>f <b>t</b>he <b>D</b>ay) file to the one you copied earlier:</p> -<pre><code># motd filename -# if you change the motd, you should move it to ircd.motd -motd: ircd.motd</code></pre> - <p>Feel free to edit <code>ircd.motd</code> to your heart's content. Its contents will be sent to clients when they connect to the network.</p> - <h3 id="configuring-ip-limits">IP limits</h3> - <p> - For security purposes, you might want to limit the amount of client connections per IP. - For a private network, 4 is likely the maximum amount of connections you will have per IP, so that is a safe value.<br> - If your network is password protected, this is less of an issue, since the only people connecting will be people who have the password. - The following is the default, but you can change it to be whichever value you like: - </p> -<pre><code># IP-based DoS protection -ip-limits: - # whether to limit the total number of concurrent connections per IP/CIDR - count: true - # maximum concurrent connections per IP/CIDR - max-concurrent-connections: 16</code></pre> - <h3 id="configuring-ip-cloaking">IP cloaking</h3> - <p> - Traditionally, IRC networks expose users' IP addresses to everyone. This is not a good practice for privacy, however. - With Ergo, IP cloaking is enable by default. You can enable or disable it if you like, and change how it looks to users.<br> - In this case, <code>netname</code> was changed to <code>"chad"</code>. - </p> -<pre><code># IP cloaking hides users' IP addresses from other users and from channel admins -# (but not from server admins), while still allowing channel admins to ban -# offending IP addresses or networks. In place of hostnames derived from reverse -# DNS, users see fake domain names like pwbs2ui4377257x8.irc. These names are -# generated deterministically from the underlying IP address, but if the underlying -# IP is not already known, it is infeasible to recover it from the cloaked name. -# If you disable this, you should probably enable lookup-hostnames in its place. -ip-cloaking: - # whether to enable IP cloaking - enabled: true - # whether to use these cloak settings (specifically, `netname` and `num-bits`) - # to produce unique hostnames for always-on clients. you can enable this even if - # you disabled IP cloaking for normal clients above. if this is disabled, - # always-on clients will all have an identical hostname (the server name). - enabled-for-always-on: true - # fake TLD at the end of the hostname, e.g., pwbs2ui4377257x8.irc - # you may want to use your network name here - netname: "chad"</code></pre> - <h3 id="configuring-hexchat-password">Password enforcement adjustments for HexChat (and possibly other clients)</h3> - <p> - Ergo offers account registration to allow users to do things like use history and bouncer features, register channels, etc.<br> - In clients such as HexChat, server password may conflict with account passwords, so the following setting should be enable if you wish to use accounts with clients such as HexChat.<br> - Note that this could under some circumstances be considered a security hazard, as a user with an account does not need to know the server password to connect, - although that user would have needed to register an account before the server had a password, and then a password would need to have been set after the fact, so this can be considered a very small concern if your setup always has had a password.<br> - Also keep in mind that this setting has no effect if your network does not even have a password at all. - </p> -<pre><code># some clients (notably Pidgin and Hexchat) offer only a single password field, -# which makes it impossible to specify a separate server password (for the PASS -# command) and SASL password. if this option is set to true, a client that -# successfully authenticates with SASL will not be required to send -# PASS as well, so it can be configured to authenticate with SASL only. -skip-server-password: true</code></pre> - <h3 id="configuring-multiclient">Multiclient, always-on clients, history, etc</h3> - <p> - Traditionally, IRC servers have no message history, and once you close your client, you cannot receive messages, and are not shown to be online at all. - Ergo includes functionality to allow users to both receive history, and keep their clients "online" even after they have left. - It also allows multiple clients to connect to the same account.<br> - If you are running a private network for friends, you should set <code>always-on</code> and <code>auto-away</code> to <code>opt-out</code>, - to have all users with accounts to appear as if they are online at all times, and be able to receive messages when they are offline.<br> - For a public network, keep everything as their default values, since you probably do not want randoms having this by default.<br> - If for some reason you do not want any of these features at all, you can set <code>enabled</code> to <code>false</code>, but this is not recommended. - Below are the recommended values for a private network (e.g. for friends) where users with accounts will be able to receive messages and history while they are offline. - </p> -<pre><code># multiclient controls whether Ergo allows multiple connections to -# attach to the same client/nickname identity; this is part of the -# functionality traditionally provided by a bouncer like ZNC -multiclient: - # when disabled, each connection must use a separate nickname (as is the - # typical behavior of IRC servers). when enabled, a new connection that - # has authenticated with SASL can associate itself with an existing - # client - enabled: true - # if this is disabled, clients have to opt in to bouncer functionality - # using nickserv or the cap system. if it's enabled, they can opt out - # via nickserv - allowed-by-default: true - # whether to allow clients that remain on the server even - # when they have no active connections. The possible values are: - # "disabled", "opt-in", "opt-out", or "mandatory". - always-on: "opt-out" - # whether to mark always-on clients away when they have no active connections: - auto-away: "opt-out" - # QUIT always-on clients from the server if they go this long without connecting - # (use 0 or omit for no expiration): - #always-on-expiration: 90d</code></pre> - <h3 id="configuring-vhosts">VHosts</h3> - <p> - IP cloaking was mentioned previously, and somewhat related to that, Ergo includes "vhost" functionality, which allows users to set a custom IP/host string. - This is mostly for cosmetic value, and does not interfere with operators being able to see actual IP addresses for banning, but if you do not want it enable for some reason, you can disable it. - </p> -<pre><code># vhosts controls the assignment of vhosts (strings displayed in place of the user's -# hostname/IP) by the HostServ service -vhosts: - # are vhosts enabled at all? - enabled: true</code></pre> - <h3 id="configuring-channels">Channels</h3> - <p> - Channels are where everyone on an IRC network talk. By default, anyone can create a channel, and anyone with an account can register one. - The difference between a normal channel and a registered one is that the registered one will preserve the operator status of the person who created, - whereas a normal channel's owner will lose operator status if they leave the channel or disconnect from the network.<br> - There are various settings for channels available, but the defaults are suitable for a private network with trust among users, or where you just want anyone to have the ability to create a channel. - Below are the default values: - </p> -<pre><code># channel options -channels: - # modes that are set when new channels are created - # +n is no-external-messages and +t is op-only-topic - # see /QUOTE HELP cmodes for more channel modes - default-modes: +nt - # how many channels can a client be in at once? - max-channels-per-client: 100 - # if this is true, new channels can only be created by operators with the - # `chanreg` operator capability - operator-only-creation: false - # channel registration - requires an account - registration: - # can users register new channels? - enabled: true - # restrict new channel registrations to operators only? - # (operators can then transfer channels to regular users using /CS TRANSFER) - operator-only: false - # how many channels can each account register? - max-channels-per-account: 15</code></pre> - <h3 id="configuring-operators">Operators (administrators, etc)</h3> - <p> - The IRC term for an administrator or another privileged user is "operator", or "oper" for short.<br> - Ergo's opers have different permissions that can be granted to them, and are defined in "classes", basically groups of permissions under a name. - For example, "chat-moderator" and "server-admin" are defined in the default configuration: - </p> -<pre><code># operator classes -oper-classes: - # chat moderator: can ban/unban users from the server, join channels, - # fix mode issues and sort out vhosts. - "chat-moderator": - # title shown in WHOIS - title: Chat Moderator - # capability names - capabilities: - - "kill" - - "ban" - - "nofakelag" - - "roleplay" - - "relaymsg" - - "vhosts" - - "sajoin" - - "samode" - - "snomasks" - # server admin: has full control of the ircd, including nickname and - # channel registrations - "server-admin": - # title shown in WHOIS - title: Server Admin - # oper class this extends from - extends: "chat-moderator" - # capability names - capabilities: - - "rehash" - - "accreg" - - "chanreg" - - "history" - - "defcon" - - "massmessage"</code></pre> - <p> - The above can be kept with their default values, but you are free to modify them or create any new classes that are appropriate for your setup.<br> - Next, let's actually create an operator account: - </p> -<pre><code># ircd operators -opers: - # default operator named 'gigachad'; log in with /OPER gigachad <password> - "gigachad": - # which capabilities this oper has access to - class: "server-admin" - # custom whois line - whois-line: is the server administrator - # custom hostname - vhost: "gigachad" - # normally, operator status is visible to unprivileged users in WHO and WHOIS - # responses. this can be disabled with 'hidden'. ('hidden' also causes the - # 'vhost' line above to be ignored.) - hidden: false - # modes are modes to auto-set upon opering-up. uncomment this to automatically - # enable snomasks ("server notification masks" that alert you to server events; - # see `/quote help snomasks` while opered-up for more information): - #modes: +is acjknoqtuxv - # operators can be authenticated either by password (with the /OPER command), - # or by certificate fingerprint, or both. if a password hash is set, then a - # password is required to oper up (e.g., /OPER dan mypassword). to generate - # the hash, use `ergo genpasswd`. - password: "<i><your oper password></i>"</code></pre> - <p> - This is a modified version of the default oper entry. The account name is "gigachad", but you can change it to anything.<br> - Replace <code><i><your oper password></i></code> with a password generated by <code>./ergo genpasswd</code>, and you will have a new oper account to use.<br> - Note that to log into an oper account, clients have to enter <code>/OPER <i><oper name></i> <i><oper password></i></code> each time they log in. - This can be automated by most clients by setting the command to be executed when the client logs in. - In the case of HexChat, you can edit your network and add the command to the <code>Connect commands</code> tab of the menu.<br> - You can copy everything from <code>"gigachad"</code> to the end of the line, paste it again, and change the name to create another oper account. - Another, less privileged example of an oper is shown as a comment below the above configuration snippet. - </p> - <h3 id="configuring-history">Chat history</h3> - <p> - Traditionally, IRC networks do not store, relay, or handle chat history in any way.<br> - On a privacy standpoint, this is a good thing, since chats are entirely ephemeral and handled by clients.<br> - On a practicality standpoint, this is a bad thing, since people have to keep a client connected 24/7 to see message history.<br> - For normalfriends, this can be a big problem, not only because having to stay online 24/7 is just annoying or infeasible, - but also because they are likely used to chat platforms that handle history for them.<br> - With this in mind, enabling history is a good idea if you want to move friends over to IRC, and will make things a lot more pleasant for private networks. - </p> - <p> - Ergo's <code>history</code> configuration group is very long, so it is encouraged to read over it yourself. - This section will go over the most important pieces of that configuration group. - </p> - <p> - History is not endless (unless you want it to be), and the amount that can be stored for channels is configurable: - </p> -<pre><code># how many channel-specific events (messages, joins, parts) should be tracked per channel? -channel-length: 2048</code></pre> - <p> - History is already enabled by default, but that just means it is being collected, not relayed by default. - To relay history to clients when they connect, change the following to the amount of messages that you think is appropriate: - </p> -<pre><code># number of messages to automatically play back on channel join (0 to disable): -autoreplay-on-join: 250</code></pre> - <p> - History older than a certain time can be configured to be deleted or be inaccessible. - The default cutoff time is 1 week, but this is configurable as well. - </p> -<pre><code> -# options to delete old messages, or prevent them from being retrieved -restrictions: - # if this is set, messages older than this cannot be retrieved by anyone - # (and will eventually be deleted from persistent storage, if that's enabled) - expire-time: 1w -</code></pre> - <p> - By default, Ergo only stores chat history in memory, so when the server restarts, all history is lost. - If you wish to have chat history persist beyond restarts, you must store it in a MySQL database: - </p> -<pre><code># options to store history messages in a persistent database (currently only MySQL). -# in order to enable any of this functionality, you must configure a MySQL server -# in the `datastore.mysql` section. -persistent: - enabled: true - # store unregistered channel messages in the persistent database? - unregistered-channels: true</code></pre> -<br> -<pre><code># connection information for MySQL (currently only used for persistent history): -mysql: - enabled: false - host: "localhost" - port: 3306 - # if socket-path is set, it will be used instead of host:port - #socket-path: "/var/run/mysqld/mysqld.sock" - user: "ergo" - password: "hunter2" - history-database: "ergo_history" - timeout: 3s - max-conns: 4 - # this may be necessary to prevent middleware from closing your connections: - #conn-max-lifetime: 180s</code></pre> - <p> - For privacy reasons, you may want to allow users to delete their own messages in history, or export their messages to JSON: - </p> -<pre><code># options to control how messages are stored and deleted: -retention: - # allow users to delete their own messages from history? - allow-individual-delete: true - # if persistent history is enabled, create additional index tables, - # allowing deletion of JSON export of an account's messages. this - # may be needed for compliance with data privacy regulations. - enable-account-indexing: true</code></pre> - <h3 id="configuring-spam">Spam reduction</h3> - <p> - Most IRC networks have measures in place to reduce chat spam. By default, "fakelag" is enabled in Ergo, and that can deal with most aggregious chat spam.<br> - If you are running a private network where user trust is high, you can disable it so that there are no limits on the speed that messages can be sent. - </p> -<pre><code># fakelag: prevents clients from spamming commands too rapidly -fakelag: - # whether to enforce fakelag - enabled: true - # time unit for counting command rates - window: 1s - # clients can send this many commands without fakelag being imposed - burst-limit: 5 - # once clients have exceeded their burst allowance, they can send only - # this many commands per `window`: - messages-per-window: 2 - # client status resets to the default state if they go this long without - # sending any commands: - cooldown: 2s</code></pre> - <h2 id="using">Starting and using your server</h3> - <p> - Now that Ergo is both installed and configured, you can actually start using it! - </p> - <h3 id="using-starting">Starting the server</h3> - <p> - First thing, make sure you're still using the <code>ergo</code> user, and are in the <code>~/server</code> directory.<br> - If you aren't, you can run the following to get back there: - </p> -<pre><code>sudo -i -u ergo -cd server</code></pre> - <p> - Starting the server is done in one command: - </p> - <pre><code>./ergo run</code></pre> - <p> - It will stay online until you close the terminal, or press CTRL+C. Don't worry, the next section goes over how to make it run like a normal server with a SystemD service.<br> - If you have not already, make sure the port <code>6697</code> is not blocked on your server. If you are using UFW as your firewall, - you need to run <code>ufw enable 6697</code> (not as the <code>ergo</code> user, of course).<br> - If you make and configuration changes while the server is running, you can apply them without restarting by typing <code>/rehash</code> as an operator. - </p> - <h3 id="using-connecting">Connecting to the server</h3> - <p> - To use IRC, you of course need an IRC client. There are many choices available, but the most widely used for Windows and Linux is <a href="https://hexchat.github.io/">HexChat</a>. - On Mac, you have a slightly nicer option with <a href="https://www.codeux.com/textual/">Textual</a>, although you have to <a href="https://github.com/Codeux-Software/Textual/#building-textual">compile it from source</a> if you want to use it for free.<br> - A more user-friendly and modern client choice is TheLounge, which is explained in the last section of this guide, if you want to look into it. - </p> - <p> - Connecting with HexChat is very easy. When you start it, you will see something like this: - </p> - <img src="pix/irc/hexchat-network-select.png" alt="HexChat network select"> - <p> - From there, you should click <code>+ Add</code> and name the server whatever you like (so you can find it on the server list).<br> - Once you have created a new server and named it, select it and click <code>Edit...</code>. - A menu will show up like the one below. Change the domain to whatever domain your server is running on, - and make sure to put in your server password if you set one. - </p> - <img src="pix/irc/hexchat-network-edit.png" alt="HexChat network edit menu"> - <p> - Once you're done editing the network, click <code>(X) Close</code>, select your network from the network list, and click <code>Connect</code>.<br> - If all is well, you should be connected! - </p> - <img src="pix/irc/hexchat-connection-complete.png" alt="HexChat connection complete"> - <p> - The process is very similar on Textual.<br> - Create a new network and connect to it. Note that it will ask if you want to connect even though the certificate is unsigned. - This is due to the self-signed certificates generated for the server, and is not a problem or security vulnerability, it is just a little annoying. - </p> - <img src="pix/irc/textual-network-edit.png" alt="Textual network edit menu"> - <h2 id="service">Surviving restarts with a SystemD service</h3> - <p> - In the beginning of the last section, Ergo was started by simply running <code>./ergo run</code>, but this is only suitable for testing. - To have a proper server setup, you need to run it as a service. This can be achieved via a SystemD service. - </p> - <p> - Before creating your service file, make sure you are in <code>~/server</code> as the <code>ergo</code> user.<br> - Once you have done that, create a file called <code>start.sh</code> with the following content: - </p> -<pre><code>#!/bin/bash -./ergo run</code></pre> - <p>Save the file, then mark it as executable:</p> - <pre><code>chmod +x start.sh</code></pre> - <p>Now, create a file called <code>ergo.service</code> with the following content:</p> -<pre><code>[Unit] -Description=Ergo IRC server -After=network.target -# If you are using MySQL for history storage, comment out the above line -# and uncomment these two instead (you must independently install and configure -# MySQL for your system): -# Wants=mysql.service -# After=network.target mysql.service -[Service] -Type=simple -User=ergo -WorkingDirectory=/home/ergo/server -ExecStart=/home/ergo/server/start.sh -ExecReload=/bin/kill -HUP $MAINPID -Restart=on-failure -LimitNOFILE=1048576 -# Uncomment this for a hidden service: -# PrivateNetwork=true -[Install] -WantedBy=multi-user.target</code></pre> - <p> - You now have your service file, but it is not installed yet. - To install it, switch to your normal user, and execute the following lines to install, enable, and start the SystemD service: - </p> -<pre><code>ln -s /home/ergo/server/ergo.service /etc/systemd/system/ergo.service -systemctl enable ergo -systemctl start ergo</code></pre> - <p>Ergo is now installed and running as a service, and will automatically start when the system boots.</p> - <h2 id="registering">Registering accounts and channels</h2> - <p> - Account and channel registration were mentioned multiple times in this guide, and are indeed very important parts of the modern IRC ecosystem. - You can connect to most IRC networks and talk without creating an account, but you will not be able to reserve your nickname or register channels, so it is important to register an account. - </p> - <h3 id="registering-accounts">Registering an account with NickServ</h3> - <p> - First, make sure you are connected to your IRC network. - Once you are, type <code>/nickserv help</code> to make sure NickServ (the registration system) is working propertly.<br> - If all is well, type the following, replacing <code><i><your password></i></code> with the password you want to use: - </p> - <pre><code>/nickserv register <i><your password></i></code></pre> - <p> - At this point, you are now registered!<br> - The final step is to configure authentication with your client. - </p> - <p>In HexChat, all that needs to be done is changing <code>Login method</code> to <code>SASL (username + password)</code>, and entering your NickServ password that you used earlier into the password field:</p> - <img src="pix/irc/hexchat-sasl.png" alt="HexChat SASL in network edit menu"> - <p> - In Textual, open up your network in the menu, and click <code>Identity</code> under <code>Server Properties</code>. - Enter your password in <code>Personal Password</code>, and check <code>Wait for identification before joining channels</code>. - </p> - <img src="pix/irc/textual-identity.png" alt="Textual identity menu"> - <p>You will now be logged into your account when you connect to your network.</p> - <h3 id="registering-channels">Registering channels with ChanServ</h3> - <p> - Once you have an account registered, you can register channels with ChanServ.<br> - To do so, join the channel you want to register, then type the following, replacing <code><i><your channel></i></code> with the name of the channel you want to register: - </p> - <pre><code>/chanserv register #<i><your channel></i></code></pre> - <p> - You are now the channel owner, and are free to appoint operators, administrators, etc for it. - When you go offline, you won't lose ownership, and you cannot be removed as the owner unless you unregister the channel later. - </p> - <h2 id="moderation">Moderation</h2> - <p> - Like any chat, there will come a point where you need to use moderation tools to keep things under control. - Many IRC setup guides do not go over moderation, so it can be stressful when operators need to actually use moderation tools.<br> - The main difference between IRC and other chat systems in terms of moderation is the difference between channel bans and network bans. - Channel ban keeps a person out of channel a channel, whereas a network ban keeps a person out of the entire network. - </p> - <h3 id="moderation-masks">Understanding masks</h3> - <p> - Bans are applied "masks", which are formatted pieces of text that contain a user's nick (username), their realname value, and their IP address or host.<br> - This is what a mask looks like: <code>nick!~nick-dude@127.0.0.1</code>.<br> - In bans, asterisks can be used as wildcards, which is useful for banning IP address ranges, patterns of nicknames, or whatever else you can think of.<br> - A ban on the nick <code>person</code>, for example, would look like this: <code>person!*@*</code>.<br> - A ban on anyone with the IP address <code>127.0.0.1</code> would look like this: <code>*!*@127.0.0.1</code> - </p> - <h3 id="moderation-real-ips">Discovering real IPs</h3> - <p> - Even if IP cloaking is enabled on your network, you can still obtain real IP addresses/hosts if you are an operator. - See the <b>Operators</b> part of the configuration section of this guide on how to become an operator.<br> - To find out a user's real IP, simply type <code>/whois</code> along with the user's nick, and you will see information about the user, along with their real IP address/host.<br> - <code>/whois</code> is not a command that is exclusive to operators, but it does not reveal as much information to non-operators. - </p> - <h3 id="moderation-network-ban">Banning someone from the network</h3> - <p> - Any netword-wide moderation action requires being an operator. See the <b>Operators</b> part of the configuration section of this guide on how to become an operator.<br> - Banning someone from the network is achieved with the <code>/kline</code> command. To see more info on the command, type <code>/helpop kline</code>.<br> - </p> - <p>To ban a nick from the network:</p> - <pre><code>/kline andkill <i><nick></i>!*@*</code></pre> - <p>To ban an IP address or host from the network:</p> - <pre><code>/kline andkill *!*@<i><IP or mask></i></code></pre> - <p>To unban a mask, you can use the <code>/unkline</code> command with the mask you want to unban.</p> - <h3 id="moderation-channel-ban">Banning someone from a channel</h3> - <p> - Channel owners, administrators, and operators can ban people from channels. - This is not the same as banning someone from the network, since it only has an effect on one channel. - Additionally, a channel operator is not the same as a network operator. - </p> - <p>To ban someone in a channel, type the following in that channel, replacing <code><i><mask></i></code> with the user's mask:</p> - <pre><code>/mode +b <i><mask></i></code></pre> - <p> - Note that this will only ban the user, not kick them immediately. - You will want to run <code>/kick</code> along with the user's nick to also kick them.<br> - To unban a user, run the command above, but replace the <code>+</code> with a <code>-</code>.<br> - You can see who is banned in a channel by typing <code>/banlist</code>. - </p> - <h3 id="moderation-muting">Muting people in a channel</h3> - <p> - By default, anyone can speak in an IRC channel. To change this, you must be a channel owner, administrator, or operator.<br> - Channels, along with users, have modes, which modify their behavior. There is a special mode for channels called <code>m</code> (moderated) which requires users to be privileged in some way to talk.<br> - To set a channel as moderated, type the following in the channel: - </p> - <pre><code>/mode +m</code></pre> - <p> - Now, users must be an owner, administrator, operator, or be voiced to talk in the channel - This be reversed by typing the command above, but changing the <code>+</code> to a <code>-</code>.<br> - To voice a user, run the following, replacing <i><nick></i> with the user's nick: - </p> - <pre><code>/mode +v <i><nick></i></code></pre> - <p>Unvoice the user by typing the above command, but replacing the <code>+</code> with a <code>-</code>.</p> - <h3 id="moderation-appointing">Appointing channel administrators and operators</h3> - <p> - Assuming you a channel owner, you can appoint both administrators and operators. - If you are only an operator, you may only appoint operators.<br> - The difference between administrator and operator is mainly that administrators cannot have their privileges taken away by operators, only owners. - To appoint an administrator, type the following, replacing <i><nick></i> with the user's nick: - </p> - <pre><code>/mode +a <i><nick></i></code></pre> - <p>To appoint an operator, type the following, replacing <i><nick></i> with the user's nick:</p> - <pre><code>/mode +o <i><nick></i></code></pre> - <p> - You can also use <code>/op</code> and <code>/deop</code> on most clients to appoint and remove an operator.<br> - To remove administrator or operator status, run either of the above commands, but replace the <code>+</code> with a <code>-</code>. - </p> - <h2 id="thelounge">Bringing modern-day features to IRC with TheLounge</h3> - <p> - A large downside to IRC as a protocol is just how old it is, and the limitations that exist because of it. - Other old protocols such as HTTP were built to be content-agnostic and versitile, but IRC was built with a very specific set of features, so it has not held up so well to contemporary chat systems.<br> - A notable thing that IRC as a protocol is missing is file uploads, and other fancy features that many other chats have.<br> - With that said, these problems can be fixed by clients, although many clients are still very primitive. - </p> - <p> - <a href="https://thelounge.chat/">TheLounge</a> is a modern self-hosted IRC web client that tries to make IRC as user-friendly as possible. - It can be the answer to many of the complaints that normalfriends may have about IRC. It runs on anything with a web browser, can be "installed" since it is a PWA (Progressive Web App), - and is optimized for both desktops and mobile devices. It keeps you logged in even when you are gone, and even supports file uploads and embeds.<br> - Effectively, it brings IRC up to the standard of most other chat systems. - </p> - <p> - If you would like to setup an instance of TheLounge for you and your friends, you can take a look at their <a href="https://thelounge.chat/docs/install-and-upgrade">installation guide</a>.<br> - It is a self-hosted web app, so you can run it for multiple people, not just yourself. - </p> - <hr> - <p><i>Written by <a href="https://termer.net/">Termer</a></i></p> - </main> - -]]></description> -</item> - - -<item> -<title>Setting up Gitea</title> -<guid>https://landchad.net/gitea.html</guid> -<link>https://landchad.net/gitea.html</link> -<pubDate>Thu, 01 Jul 2021 16:14:22 -0400</pubDate> -<description><![CDATA[ - <header><h1>Setting up Gitea</h1></header> - - <main> - <img class=titleimg src="pix/gitea.svg"> - <p>Gitea allows you to self-host your git repositories similar to <a href="git.html">bare repositories</a>, but comes with additional features that you might know from GitHub, such as issues, pull requests or multiple users. Its advantage over GitLab—another Free Software GitHub clone—is that it is much more lightweight and easier to setup.</p> - <p>Head over to <a href="https://gitea.com">gitea.com</a> to see what it looks like in practice.</p> - <p>Although Gitea is lighter than Gitlab, if you have a VPS with only 512MB of RAM, you will probably have to upgrade. Gitea is more memory-intensive than having just a bare git repository.</p> - <h2>Installing Gitea</h2> - <p>First install a few dependencies:</p> - <pre><code>apt install curl sqlite3</code></pre> - <p>Unfortunately, Gitea itself is not in the official Debian repos, so we will add a third-party repository for it.</p> - <p>Add the repo's gpg key to apt's trusted keys:</p> - <pre><code>curl -sL -o /etc/apt/trusted.gpg.d/morph027-gitea.asc https://packaging.gitlab.io/gitea/gpg.key</code></pre> - <p>Then add the actual repository to apt:</p> - <pre><code>echo "deb [arch=amd64] https://packaging.gitlab.io/gitea gitea main" > /etc/apt/sources.list.d/morph027-gitea.list</code></pre> - <p>Now we can install Gitea:<p> - <pre><code>apt update -apt install gitea</code></pre> - <p>Since apt automatically enables and starts the Gitea service, it should already be running on port <code>3000</code> on your server!</p> - <h2>Setting up a Nginx reverse proxy</h2> - <p>You should know how to generate SSL certificates and use Nginx by now. Add this to your Nginx config to proxy requests made to your git subdomain to Gitea running on port 3000:</p> - <pre><code> -server { - listen 443 ssl; - listen [::]:443 ssl; - ssl_certificate /etc/ssl/nginx/<strong>git.example.org</strong>.crt; - ssl_certificate_key /etc/ssl/nginx/<strong>git.example.org</strong>.key; - server_name <strong>git.example.org</strong>; - location / { - proxy_pass http://localhost:3000/; # The / is important! - proxy_redirect off; - proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; - } -} - </pre></code> - <p>And reload Nginx:</p> - <pre><code>systemctl reload nginx</code></pre> - <h2>Setting up Gitea</h2> - <p>If everything worked fine you should now see a setup screen when you go to your configured domain in the browser. The options should be pretty self-explanatory, it is only important to select SQLite3 and to replace the base url and SSH server domain with your own.</p> - <dl> - <dt>Database Type:</dt> - <dd>SQLite3</dd> - <dt>SSH Server Domain:</dt> - <dd><strong>git.example.org</strong></dd> - <dt>Gitea Base URL:</dt> - <dd><strong>git.example.org</strong></dd> - </dl> - <p>These and other settings can be changed in a configuration file later so don't worry about making wrong decisions right now.</p> - <p>After clicking the install button you should now be able to log into your Gitea instance with the account you just created! Explore the settings for more things to do, such as setting up your SSH keys.</p> - <p>If Gitea does not load fully and has random errors, it is possible that you need to increase your available memory on your VPS. This can usually be done on your VPS-provider's website without too much trouble.</p> - <h2>A few extras</h2> - <h3>Automatically create a new repo on push</h3> - <p>This is an incredicly useful feature for me. Open up <code>/etc/gitea/app.ini</code> and add <code>DEFAULT_PUSH_CREATE_PRIVATE = true</code> to the <code>repository</code> section like so:</p> - <img src=pix/gitea-push-create.png> - <br> - <p>If you now add a remote to a repository like this</p> - <pre><code>git remote add origin 'ssh://gitea@git.<strong>example.org</strong>/<strong>username</strong>/<strong>coolproject</strong>.git'</code></pre> - <p>and push, Gitea will automatically create a private <code>coolproject</code> repository in your account!</p> - <h3>Change tab-width</h3> - <p>By default Gitea displays tabs 8 spaces wide, however I prefer 4 spaces. We can change this!</p> - <pre><code>mkdir -p /var/lib/gitea/custom/templates/custom/</code></pre> - <p>And write this into <code>/var/lib/gitea/custom/templates/custom/header.tmpl</code>:</p> - <pre><code><style> -.tab-size-8 { - tab-size: 4 !important; - -moz-tab-size: 4 !important; -} -</style></code></pre> - <h2>Contribution</h2> - <ul> - <li><a href="https://phire.cc">phire</a></li> - </ul> - </main> - -]]></description> -</item> - - -<item> -<title>Hosting Your Own Git Repositories</title> -<guid>https://landchad.net/git.html</guid> -<link>https://landchad.net/git.html</link> -<pubDate>Thu, 01 Jul 2021 07:19:51 -0400</pubDate> -<description><![CDATA[ - <header><h1>Hosting Your Own Git Repositories</h1></header> - - <main> - <img class=titleimg src="pix/git.svg"> - <p> - Once you have your own VPS or other Internet-available server, you can - start hosting your own git repositories. The goal of this tutorial is - for you to go from</p> - <pre><code>git clone github.com/...</code></pre> - <p>to</p> - <pre><code>git clone YourLandChadDomainName.xyz/...</code></pre> - <p> - so you can cultivate your own homegrown, grass-fed code, rather than - relying on a centralized proprietary service like GitHub. - </p> - <h2>Installing git</h2> - <p> - You most likely already have it installed on your server, but if not, - run:</p> - <pre><code>apt install git</code></pre> - <p> - We don't need any additional software, <code>git</code> itself ships - with everything needed to host a remote repository! - </p> - <h2>Creating bare repositories</h2> - <p> - For each repository you want to host, you will need to manually create - what's called a "bare" repository on your server. These hold all the - commits and any other git data needed for your repository, but without - an expanded "index" in which you can just browse all the files of a - certain commit in the file system. - </p> - <p> - These repositories need to be owned by the <code>git</code> user, and - you should probably pick a directory where you will store them all. One - sane choice is under <code>/srv/git/</code>, and we will use this as the - example directory for the rest of the tutorial, but any other path will - do as well. - </p> - <h3>Become the git user and create the directory</h3> - <p> - If you're logged in to your server as root and have <code>git</code> - installed, you can become the <code>git</code> user by executing - </p> - <pre><code>su git</code></pre> - <p> - Now navigate to/create your desired directory, for example - </p> - <pre><code>cd /srv -mkdir git</code></pre> - <h3>Create the repo</h3> - <p> - Now you can create the bare repository with - </p> - <pre><code>git init --bare my-repo.git</code></pre> - <p> - By convention, bare repository names end with ".git". - </p> - <p> - Repeat the above command for any other repositories you want to host. - </p> - <h2>Syncing local repositories with your server</h2> - <h3>Set up SSH login for the git user</h3> - <p> - You will need to be able to login remotely via <code>ssh</code> as the - <code>git</code> user we've used before. To do this, you will either - need to set up a password for the <code>git</code> user by running - <code>passwd git</code>, - or copy your public SSH key from your local machine to - <code>/home/git/.ssh/authorized_keys</code>. - See the <a href="sshkeys.html">SSH keys instructional</a> for details - (just log in as <code>git</code> instead of <code>root</code>). - </p> - <h3>Syncing a new repository with your server</h3> - <p> - If you've just created a new repository on your local machine, you will - need to tell <code>git</code> where the remote repository is to be able - to sync with it (using commands like <code>git push</code> or - <code>git pull</code>). We do this by defining a "remote" for your - repository. - </p> - <p> - A remote is just a named URL remembered in your repo's configuration. So - we need a name and a URL. By convention, the "main" remote is called - "origin". The URL has the format <code>user@host:path</code>, where: - </p> - <ul> - <li> - <code>user</code> is <code>git</code>, the <code>git</code> user - we've already worked with before. - </li> - <li> - <code>host</code> is your domain name. - Alternatively you could even use your server's raw IP address. - </li> - <li> - <code>path</code> is the absolute path to the repository on the - server, in our example <code>/srv/git/my-repo.git</code> - </li> - </ul> - </p> - <p> - So, to create a new remote, run: - </p> - <pre><code>git remote add origin git@yourdomain.xyz:/srv/git/my-repo.git</code></pre> - <p> - Now you'll be able to run <code>git push origin master</code> to push - your commits or <code>git pull origin</code> to pull from the remote. - </p> - <h3>Syncing an existing repository</h3> - <p> - If you've already set up your local repository to sync with a service - like GitHub it probably already has a remote called "origin". You can - see your repo's remotes with: - </p> - <pre><code>git remote -v</code></pre> - <p> - You can follow the above instructions, substituting an arbitrary other - name other than "origin" to create a differently named remote, e.g. - </p> - <pre><code>git remote add vps git@...</code></pre> - <p> - Now you'll be able to push/pull with <code>git push vps master</code> - and <code>git pull vps</code>, respectively. - </p> - <p> - Or, to completely sever ties with your centralized git provider, first - remove the original origin with: - <code>git remote remove origin</code> - and then follow the instructions as above. - </p> - <h2>Contribution</h2> - <ul> - <li>Martin Chrzanowski -- <a href="https://m-chrzan.xyz">website</a>, <a href="https://m-chrzan.xyz/donate.html">donate</a></li> - </ul> - </main> - -]]></description> -</item> - - -<item> -<title>Requiring Passwords for Webpages (HTTP Authentication)</title> -<guid>https://landchad.net/auth.html</guid> -<link>https://landchad.net/auth.html</link> -<pubDate>Thu, 01 Jul 2021 07:19:27 -0400</pubDate> -<description><![CDATA[ - <header><h1>Requiring Passwords for Webpages</h1></header> - - <main> - <img class=titleimg src="pix/auth.svg" alt="access control with nginx"/> - <p>HTTP basic authentication will allow you to secure parts (or all) of your website with a username and password without the trouble of PHP or Javascript. - This will work with any Nginx server. - </p> - <h2>Installation</h2> - <p>We will be using the command <code>htpasswd</code> to make username and password pairs.</p> - <pre><code>apt install apache2-utils</code></pre> - <aside> - <p>The apache utils has a small username-password pair encryption tool.</p> - <p>Like the other on this site, this tutorial is for Nginx, <strong>not</strong> for Apache servers.</p> - </aside> - <p> - Now think of a username and password and remember them. - </p> - <pre><code>htpasswd -c /etc/nginx/<strong>myusers</strong> <strong>username</strong></code></pre> - <aside> - <p>The <code>-c</code> flag creates a file. You can make the path of this file anywhere outside of your webroot.</p> - <p>Obviously the username is up to you as well.</p> - </aside> - <p> - Type out your password twice to confirm. You can do this as many times as you'd like. - </p> - <p>Check out user name password pairs (the password will be securely hashed):</p> - <pre><code>cat /etc/nginx/<strong>myusers</strong></code></pre> - <h2>Nginx Config and Auth Basic</h2> - <p> - From here, we are going to edit our websites config file in <code>/etc/nginx/sites-enabled</code>. - Have in mind which folder you'd like to secure. Add something like this: - </p> - <pre><code>server { - #... - location /<strong>secret-folder </strong> { - auth_basic "What's the Password?" ; - auth_basic_user_file /etc/nginx/<strong>myusers</strong> ; - } - #... -}</code></pre> - <aside> - <h4>Huh?</h4> - <p>If you're stuck, try finding the line <code>location / {</code></p> - <p>Just below this block is where you should add the custom location block</p> - </aside> - <p>If you'd like to do the opposite, such as making the entire site private except for a public section, do this:</p> - <pre><code>server { - #... - auth_basic "What's the Password?" ; - auth_basic_user_file /etc/nginx/<strong>myusers</strong> ; - location /<strong>public</strong>/ { - #... - auth_basic off ; - } - #... -}</code></pre> - <h3>IP Addresses</h3> - <p>If passwords aren't enough we can ban an ip or accept one.</p> - <pre><code>location /api { - #... - allow 192.168.1.23:8080 ; - deny 127.0.0.1 ; -}</code></pre> - <p>If you want to check both a username and password with an ip address, use the <code>satisfy</code> directive.</p> - <pre><code>location /api { - #... - satify all ; - allow 192.168.1.23:8080 ; - deny 127.0.0.1 ; - auth_basic "What's the Password?" ; - auth_basic_user_file /etc/nginx/<strong>myusers</strong> ; -}</code></pre> - <h3>Complete Example</h3> - <pre><code>http { - server { - listen 80; - root /var/www/website ; - #... - location /<strong>secret-folder</strong> { - satisfy all ; - allow 192.168.1.3/24; - deny 127.0.0.1 ; - auth_basic "What's the Password?" ; - auth_basic_user_file /etc/nginx/<strong>myusers</strong> ; - } - } -}</code></pre> - <p> - Now check your configuration with <code>nginx -t</code> - </p> - <p>Reload nginx and you're good to go!</p> - <strong>Contributor</strong> - <a href="https://tomfasano.xyz" target="_blank">tomfasano.xyz</a> - </main> - -]]></description> -</item> - - -<item> -<title>Cronjobs</title> -<guid>https://landchad.net/cron.html</guid> -<link>https://landchad.net/cron.html</link> -<pubDate>Thu, 01 Jul 2021 07:19:04 -0400</pubDate> -<description><![CDATA[ - <header><h1>Using Cronjobs to run scheduled tasks</h1></header> - - <main> - <p> - Cron is a service that lets you run scheduled tasks. These tasks are called <strong> cronjobs. </strong> If you have already followed the initial course you will have already used cron when you set up certbot. - </p> - <h2> What tasks would I want to schedule? </h2> - <p> - You can schedule anything! Some examples of what you might have done already include: - <ul> - <li> <code> updatedb </code> to update your <code> locate </code> database </li> - <li> <code> certbot </code> to update renewing of your https certs </li> - </ul> - Some tasks that you might <em>want</em> to schedule may include: - <ul> - <li> Package updates - if you really just want to leave your server alone you can automated updating packages on your server </li> - <li> Backups - you may want to backup certain files every day and some every week, this is possible with cron </li> - </ul> - <p> - And many more, anything you can do can be turned into a cronjob. - </p> - <h2>Basic Cronjobs</h2> - <p> - This the preferred method for personal tasks and scripts, it's also the easiest to get started with. Run the command <code> crontab -e </code> to access your users crontab - </p> - <p> - Once you have figured out the command you want to run you need to figure out how often you want to run it and when. I am going to schedule my system updates once a week on at 3:30 AM on a Monday. - </p> - <p> - We now have to convert this time (Every Monday at 3:30 AM) into a cron time. Cron uses a simple but effective way of scheduling when to run things. - </p> - <p> - Crontab expressions look like this <code> * * * * * command-to-run </code> - The five elements before the command tell when the command is supposed to be run automatically. - <p> - So for our Monday at 3:30AM job we would do the following: - <p> - <pre><code> .---------------- minute (0 - 59) - | .------------- hour (0 - 23) - | | .---------- day of month (1 - 31) - | | | .------- month (1 - 12 - | | | | .---- day of week (0 - 6) - | | | | | - * * * * * -30 3 * * 1 apt -y update && apt -y upgrade</code></pre> - <h3>Some notes</h3> - <ul> - <li>On the day of the week option, Sunday is 0 and counting up from there, Saturday will be 6.</li> - <li><code>*</code> designates "everything". Our command above has a <code>*</code> in the day of month and month columns. This means it will run regardless of the day of the month or month.</li> - <li>The hour option uses 24 hour time. 3 = 3AM, while use 15 for 3PM.</li> - </ul> - <h3>More examples</h3> - <p> - Let's add another job, our backup job (for the purposes of this our backup command is just called <code> backup</code>) We want to run <code> backup </code> Every evening at 11PM, once we work out the timings for this we can add the to the same file as the above by running <code> crontab -e </code> This would mean our full crontab would look like this: - <pre><code>0 23 * * * backup</code></pre> - <h3>Consecutive times</h3> - <p> - Suppose we want a command to run every weekday. - We know we can put <code>1</code> (Monday), but we can also use <code>1-5</code> - to signify from day 1 (Monday) to day 5 (Friday). - </p> - <pre><code>0 6 * * 1-5 echo "Wakey, wakey, wagie!" >> /home/wagie/alarm</code></pre> - <p>The above <code>echo</code> command runs every Monday through Friday at 6:00AM.</p> - <h3>Non-consecutive times</h3> - <p> - We can also randomly specify non-consecutive arguments with a comma. - Suppose you have a script you want to run at the midday of the 1st, 15th, and 20th day of every month. - You can specify that my putting <code>1,15,20</code> for the day of the month argument: - </p> - <pre><code>0 12 1,15,20 * * /usr/bin/pay_bills_script</code></pre> - <h3>"Every X minutes/days/months"</h3> - <p>We can also easily run a command very several minutes or months, without specifying the specific times: - </p> - <pre><code>*/15 * * * * updatedb</code></pre> - <p> - This cronjob will run the <code>updatedb</code> command every 15 minutes. - </p> - <h3>Beware of this Rookie Mistake Though...</h3> - <p> - Suppose you want to run a script once every other month. - You might be <em>tempted</em> write this: - </p> - <pre><code>* * * */2 *</code></pre> - <p> - That might <em>feel right</em>, but this script <em>will be running once every minute during that every other month</em>. - You should specify the first two arguments, because with <code>*</code> it will be running every minute and hour! - </p> - <pre><code>0 0 1 */2 *</code></pre> - <p>This makes the command run <em>only</em> at 0:00 (12:00AM) on the first day of every two months, which is what we really want.</p> - <p> - Consult the website <a href="https://crontab.guru">crontab.guru</a> for an intuitive and interactive tester of cronjobs. - </p> - <h2>User vs. Root Cronjobs</h2> - <p> - It is important to note that user accounts all have different cronjobs. - If you have a user account <code>chad</code> and edit his crontab with <code>crontab -e</code>, - the commands you add will be run as the <code>chad</code> user, not <code>root</code> or anyone else. - </p> - <p> - Bear in mind that if you need root access to run a particular command, - you will usually want to add it as root. - </p> - <h2>System-wide cron directories</h2> - <p> - <code>crontab -e</code> is the typical interface for adding cronjobs, but it's important to at least know that system-wide jobs are often stored in the file directory. - Some programs which need cronjobs will automatically install them in the following way. - </p> - <p> - Run the command <code> ls /etc/cron* </code> you should see a list of directories and there contents. The directories should be something like the below - <ul> - <li> /etc/cron.d <em> This is a crontab like the ones that you create with </em> <code> crontab -e </code> </li> - <li> /etc/cron.hourly </li> - <li> /etc/cron.daily </li> - <li> /etc/cron.weekly </li> - <li> /etc/cron.monthly </li> - </ul> - <p> - The directories cron.{hourly,daily,weekly,monthly} are where you can put <strong> scripts </strong> to run at those times. You don't put normal cron entries here. I prefer to use these directories for system wide jobs that don't relate to an individual user. - </p> - <h2>Contribution</h2> - <ul> - <li>Mark McNally -- <a href="https://mark.mcnally.je">website</a>, <a href="https://www.youtube.com/channel/UCMiInY8BhSUtCarO6uu6i_g">Youtube</a></li> - <li>Edits and examples by Luke</li> - </ul> - </main> - -]]></description> -</item> - - -<item> -<title>Mirror your site over tor</title> -<guid>https://landchad.net/tor.html</guid> -<link>https://landchad.net/tor.html</link> -<pubDate>Thu, 01 Jul 2021 07:15:39 -0400</pubDate> -<description><![CDATA[ - <header><h1>Mirror Your Site Over Tor</h1></header> - - <main> - <img class=titleimg src="pix/tor.svg" alt="Tor logo"> - <p> - Now that you have a website, why not offer it on a private alternative such as the onion network? - </p> - <h2>Setting up Tor</h2> - <h3>Installing Tor</h3> - <p>Firstly we need to add the tor repo's to have the latest up to date version or tor.</p> - <pre><code>apt install -y apt-transport-https gpg -echo "deb https://deb.torproject.org/torproject.org buster main -deb-src https://deb.torproject.org/torproject.org buster main" > /etc/apt/sources.list.d/tor.list</code></pre> - <p>Then we need to add the gpg keys to our keyring</p> - <pre><code>curl -s https://deb.torproject.org/torproject.org/A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89.asc | gpg --import -gpg --export A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89 | apt-key add -</code></pre> - <p>Now update and install tor</p> - <pre><code>apt update -apt install tor deb.torproject.org-keyring</code></pre> - <h3>Enabling Tor</h3> - <p>Then edit the file <code>/etc/tor/torrc</code>, uncommenting the following lines:</p> - <pre><code>HiddenServiceDir /var/lib/tor/hidden_service/ -HiddenServicePort 80 127.0.0.1:80</code></pre> - <aside> - <h4>Optional: Running multiple onion services</h4> - <p>If you want to forward multiple virtual ports for a single onion - service, just add more HiddenServicePort lines (replace the 80 with any unoccupied port). - </p> - <p>If you want to run multiple onion services from the same Tor client, just add another - HiddenServiceDir line.</p> - </aside> - <p>Now start and enable tor at boot</p> - <pre><code> systemctl enable --now tor </code></pre> - <p>If the next command outputs <q>active</q> in green you're golden!</p> - <pre><code> systemctl status tor</code></pre> - <p>Now you're server is on the dark web. The following command will give you your onion address:</p> - <pre><code> cat /var/lib/tor/hidden_service/hostname</code></pre> - <h2>Adding the Nginx Config</h2> - <p> - From here, the steps are almost identical to setting up a normal website configuration file. - Follow the steps as if you were making a new website on the webserver - <a href="nginx.html">tutorial</a> up until the server block of code. Instead, paste this: - </p> - <pre><code> server { - listen 127.0.0.1:80 ; - root /var/www/<strong>landchad</strong> ; - index index.html ; - server_name <strong>your-onion-address</strong>.onion ; - }</code></pre> - <aside> - <h4>Clarification</h4> - <p>Nginx will listen on port 80 for your <em>server's</em> localhost.</p> - <p>The <code>root</code> line is the path to whichever website of yours you'd like to mirror.</p> - </aside> - <p> - From here we are almost done, all we have to do is enable the site and reload nginx which is also covered in <a href="nginx.html#enable">the webserver tutorial</a>. - </p> - <h3>Update regularly!</h3> - <p>Make sure to update Tor on a regular basis by running:</p> - <pre><code>apt update -apt install tor</code></pre> - <p><strong>Contributor</strong> - <a href="https://tomfasano.xyz" target="_blank">tomfasano.xyz</a></p> - </main> - -]]></description> -</item> - - -<item> - <title>Cryptocurrency Tutorials Completed</title> - <guid>https://landchad.net/index.html#crypto</guid> - <link>https://landchad.net/index.html#crypto</link> - <pubDate> Tue, 29 Jun 2021 08:10:31 -0400</pubDate> - <description><![CDATA[<p>There is now a set of basic tutorials on cryptocurrency wallets and concepts up. - The goal here is to allow people to receive tips for sites using all free and open source and peer-to-peer technology.</p> - - <p>More tutorials on crypto management and exchanging may be added later, but these focus simply on basic concepts and setting up wallets. They include:</p> - - <ul> - <li><a href="https://landchad.net/crypto.html">The Case for Crypto for Normal People</a></li> - <li><a href="https://landchad.net/bitcoin.html">Accepting Bitcoin</a></li> - <li><a href="https://landchad.net/monero.html">Accepting Monero</a></li> - <li><a href="https://landchad.net/openalias.html">Setting up OpenAlias for your site</a></li> - <li><a href="https://landchad.net/bat.html">Enrolling in the Basic Attention Token project</a></li> - </ul>]]></description> -</item> - -<item> - <title>Welcome to LandChad.net!</title> - <guid>https://landchad.net</guid> - <link>https://landchad.net</link> - <pubDate> Mon, 28 Jun 2021 08:21:44 -0400</pubDate> - <description><![CDATA[<p>Welcome to LandChad.net!</p> -<p>This website is for step-by-step tutorials that allow people to host and maintain their own website and other web services on the cheap or free.</p> -<p>There is already a full basic tutorial on website creation on the site <a href="https://landchad.net/index.html#basic">here</a>. -Following the tutorials can take as little as an hour, but will help you set up a VPS, and NginX server and encrypt your new webpage with Certbot.</p> -<p>Next I plan adding general info on HTML and CSS and how to manage a website.</p> -<p>More stuff like running your own email server and more will be added shortly as more articles are finalized.</p> -]]></description> -</item> - - -</channel> -</rss> diff --git a/rsync.html b/rsync.html deleted file mode 100644 index b4ca7f9..0000000 --- a/rsync.html +++ /dev/null @@ -1,55 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Rsync: Upload and Sync Files and Websites – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - -<header><h1>Rsync: Upload and Sync Files and Websites</h1></header> -<nav></nav> -<main> - <p>rsync is a simple way to copy files and folders between your local computer and server.</p> - <p>It not only makes file-transfer easy, but it allows you to build and maintain your website offline, then easily upload it to the proper directory on your server so you don't need to constantly be logged into your server to modify your site.</p> -<h2 id="installing-rsync">Installing rsync</h2> -<p>Run the following on your server <em>and</em> on your local machine.</p> -<pre><code>apt install rsync</code></pre> -<h2 id="uploading-files-with-rsync">Uploading files with rsync</h2> -<p>From your local machine you can upload files to your server like this:</p> -<pre><code>rsync -rtvzP <strong>/path/to/file</strong> <strong>root@example.org:/path/on/the/server</strong></code></pre> -<p>You will be prompted for the root password and then uploading will commence.</p> -<p>If you omit <strong>root@</strong>, rsync will not attempt to log in as root, but whatever your local username is.</p> -<h3>Options to rsync</h3> -<p>In this command, we give several options to rsync:</p> -<ul> - <li><code>-r</code> – run recurssively (include directories)</li> - <li><code>-t</code> – transfer modification times, which allows skipping files that have not been modified on future uploads</li> - <li><code>-v</code> – visual, show files uploaded</li> - <li><code>-z</code> – compress files for upload</li> - <li><code>-P</code> – if uploading a large file and upload breaks, pick up where we left off rather than reuploading the entire file</li> -</ul> -<p>Avoid using the commonly used <code>-a</code> option when uploading. It can transfers your local machine's user and group permissions to your server, which might cause breakage.</p> -<h3>Scriptability</h3> -<p>It's a good idea to build your website offline, then make an rsync script or bash alias like the one above to upload the edited files when you have made updates.</p> -<h3>Password-less authentication</h3> -<p>To avoid having to manually input your password each upload, you can set up <a href="sshkeys.html">SSH keys</a> to securely idenitify yourself and computer as a trusted.</p> -<h3>Picky trailing slashes</h3> -<p>rsync is very particular about trailing slashes. This is useful, but can be confusing to some new users. Suppose we run the following wanting to mirror our offline copy of our website in the directory we use on our server (<code>/var/www/websitefiles/</code>):</p> -<pre><code>rsync -rtvzP ~/<strong>websitefiles/</strong> root@example.org:/var/www/<strong>websitefiles/</strong></code></pre> -<p>This will <em>not actually do quite what we want</em>. It will take our local <code>websitefiles</code> directory and put it <em>inside</em> <code>websitefiles</code> on the remote machine, ending up with: <code>/var/www/websitefiles/websitefiles</code>.</p> -<p>Instead, remove the trailing slash from the remote server location:</p> -<pre><code>rsync -rtvzP ~/<strong>websitefiles/</strong> root@example.org:/var/www/<strong>websitefiles</strong></code></pre> -<p><code>websitefiles/</code> has been replaced with <code>websitefiles</code>, and this will do what we want.</p> -<h2 id="downloading-file-with-rsync">Downloading files with rsync</h2> -<p>You may just as easily download files and directories from your server with rsync:</p> -<pre><code>rsync -rtvzP <strong>root@example.org:/path/to/file</strong> <strong>/path/to/file</strong></code></pre> -<h2 id="contribution">Contribution</h2> -<ul><li>el3ctr0lyte: <a href="https://github.com/el3ctr0lyte">github</a>, XMR: <code class=crypto>86DBJdiG83ZDea6kJgsbVN5tMae5ScfuhJ3PihEMTHatCrGEw2gctyUB92V2fz4R4YhwRaQeAGL5M4gPRXvVvtkULJi4ayk</code></li><li>Substantial revisions by <a href="https://lukesmith.xyz">Luke</a></li></ul> -</main> -<footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/selfhosting.html b/selfhosting.html deleted file mode 100644 index d4596fd..0000000 --- a/selfhosting.html +++ /dev/null @@ -1,120 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Self hosting – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Self hosting</h1></header> - <nav></nav> - <main> - <h2>Introduction</h2> - <p>When you have a(n old) computer lying around, and you have cheap electricity and a good internet connection, self hosting might be a good option for you.</p> - <h3>Why would you choose selfhosting?</h3> - <ul> - <li> - You have control over the hardware, and you can upgrade your server in the future. For example: if you host a file server and your hard drive goes full, you can simply add another hard drive or upgrade it. - </li> - <li> - No bandwith limits, storage limits, etc. (some VPSes have this) - </li> - <li> - It <strong>can</strong> be cheaper than using a VPS. This only is the case if you got the server for really cheap and your electricity is cheap. - </li> - <li> - You can have a media server to consoom your content (for example with <code>Jellyfin</code>). You can technically do this on a VPS, but that will be more expensive than self hosting. If you have a media server, you can stream media from your server to more devices. (I recommend just downloading it on your device, but if you have multiple devices, this could be a good solution) - </li> - </ul> - - <h3>Downsides</h3> - <p>Some possible downsides of choosing to host at home could be:</p> - <ul> - <li> - Your ISP not approving of what you're doing. Some ISP's do not condone you hosting at home. Usually when this is the case, it could be harder if you want to forward ports, or it could be impossible to get a static IP address. Check your ISP's terms of service. Sometimes, it will say that hosting a webserver, email server, and more, is not allowed. - </li> - <li> - This can also include blocked ports. ISPs can block certain ports to the world. Sometimes ISPs only block 445/139 (which is for the better as Samba, using these ports isn't really secure and it's outdated). But some ISPs (sadly) block crucial ports like 80 and/or 443. You need to check this before trying anything. If this is the case, a way to get around it is to get another ISP or use an alternative port. A great website to check this is: <a href="https://canyouseeme.org/">canyouseeme.org</a>. You can also check if you did the port forwaring correctly here.</li> - <li> - Security. Opening your network to the public could bring security risks. For example, never open a Samba server to the public, because it's a pretty old protocol, and it has some security vulnerabilities. Be sure you are forwarding the right port, and don't just forward random ports to the internet. Also, if you are getting DDoSed, your ISP will temporarily shut down your whole internet connection. - </li> - <li> - When setting up an email server, it can be way harder to not have your email show up as spam in other's people email. If you use a VPS, this is way easier. - </li> - <li> - Space, power consumption and noise. Of course, this differs per server. - </li> - </ul> - <p>Your mileage may vary, go and check each of these points, and see if selfhosting is the right choice for you. Try and calculate your power consumption and see if your electricity cost is not too expensive.</p> - <p>For me, the upsides outweighed the downsides, which is why I chose to host at home. But, this differs with each person and scenario. Go and research what your exact situation is, before trying anything. Otherwise you'll have to face some bad surprises.</p> - <h2>Hardware</h2> - - <h3>What kind of hardware should you choose?</h3> - <p>If you pay your own electricity bill, power consumption is a big factor. Most old laptop computers are ideal in the sense that they don't use a lot of power, and if the battery still works, you have a built-in UPS! The bad thing is, most old laptop computers aren't that powerful, and they lack in upgradability. (you shouldn't really be using anything older than 2006, and I recommend at least a performance equivalant of a Core 2 CPU) - </p> - <p>If you can find an energy efficient desktop (under 100W), that is a great option. They are pretty upgradable and they don't use a lot of power. They can also be pretty cheap, but old laptops are usually cheaper. If you can afford new hardware, and are willing to build a PC, you can find really power effecient CPU/motherboard combos, and they can be cheap, for example the Celeron J3060. I recommend a low wattage power supply or an effecient one for these kinds of builds. Pico PSUs are pretty tiny and efficient solutions in these builds.</p> - <p>Of course, if you don't pay your electricity bill or cost is not a problem for you, you can use just about any old desktop (as long as it's not from the 90's, I recommend at least a Core 2 chip again, or an Athlon 64 X2).</p> - <h3>Usecases</h3> - <p>Of course, hardware choices depend on the usecase. The above recommendations I gave you work fine for e-mail server, webserver and fileserver types of applications, but they will struggle to transcode video if you are going to host a media server. You'll need a faster CPU, but also a faster GPU. As an example, the Athlon 200GE or 3000G are good and efficient choices for these builds. They are decent CPUs, but also have a built in GPU that will transcode video just fine.</p> - <p> - If you need a lot of storage, go for a case with a lot of mounts for hard drives, this way you can easily mount multiple hard drives. Pros of multiple hard drives are redundancy and speed. Cons could be that they create more heat and noise. You can't use a laptop if you want multiple drives, except if you use a hard drive caddy for the CD/DVD drive bay. Some business laptops even support RAID 1 (redundancy) and RAID 0 (speed and more storage, but you lose your files if one hard drive breaks) this way.</p> - <h2>Getting started</h2> - <h3>Installing Debian</h3> - <p>Once you have the machine, you can install the OS. I recommend Debian, as all of the guides on this website are Debian specific. Debian just werks as a server OS.</p> -</p> -<p>You'll need to burn a Debian install image onto a USB flash drive or a CD. You can download the image <a href="https://www.debian.org/CD/netinst/">here</a>, and you can also find information on how to burn the image onto a USB flash drive or CD there. -</p> -<p>While installing Debian, do not install any desktop environment. But install an SSH server when you get the chance. Also leave webserver unchecked, even if you want to use it as a webserver. You'll have a chance to install this later.</p> -<h3>Port forwaring</h3> -<p>Every time you are going to set up a new server program, you need to forward a port corresponding to that program. For example, HTTP is port 80, HTTPS is 443, etc. You need to set this up on your router's NAT settings (sometimes just called port forwarding, this differs per router). These steps differ for each router. Refer to your routers manual. A simple command to see what your servers IP address is, is to run <code>ifconfig</code> on your server. This shows a lot of network info, but it will also show your local IP address needed for port forwarding. -</p> -<p>Basic ports:</p> -<ul> - <li> - SSH: port 22 (open this port if you want to admin your server outside your network) - </li> - <li> - HTTP: port 80 (open this port if you want basic webserver functionality) - </li> - <li> - HTTPS: port 443 (you should open this port if you are setting up a webserver because encryption) - </li> - </ul> - -<h3>Static or dynamic IP address</h3> -<p>If you want to host your server at home, make sure you have a static IP address, or you can change your dynamic IP address to a static one. Refer to your router settings, some ISPs will have options on this here. If you can't find anything on this, get in touch with your ISP.</p> -<p>Once you've made sure you have a static IP address, you can find out what the IP address is with various websites. You can use a search engine to easily find this out. Write this down as you'll need it later.</p> -<p>Once you're done, you can pretty much follow every guide on this website, the only difference is that you'll need to forward the ports you'll be using for the server.</p> -<h3>Finding the ports you'll need to forward</h3> -<p>If you need to know what port you'll need to forward, there's a command for that. Just type <code>netstat -tulpn</code> in your servers command line. If you want to see the name of the programs, you need to run it as a root user. You can do this by putting <code>sudo</code> before the command.</p> -<pre><code>Local Address State PID/Program name -0.0.0.0:25 LISTEN 887/master -0.0.0.0:1883 LISTEN 22452/mosquitto -0.0.0.0:445 LISTEN 798/smbd -0.0.0.0:993 LISTEN 381/dovecot -127.0.0.1:3306 LISTEN 560/mysqld -0.0.0.0:587 LISTEN 887/master -0.0.0.0:139 LISTEN 798/smbd -127.0.1.1:12301 LISTEN 412/opendkim -0.0.0.0:143 LISTEN 381/dovecot -0.0.0.0:465 LISTEN 887/master -0.0.0.0:22 LISTEN 472/sshd -:::25 LISTEN 887/master -:::443 LISTEN 1769/apache2 -:::1883 LISTEN 22452/mosquitto -:::445 LISTEN 798/smbd</code></pre> -<p><em>Example output</em></p> - -<p>In this example, if you need to find the port number from <code>dovecot</code>, you can look for it in the <code>Program name</code> column. Then you can see in the local address column that the reported local address is <code>0.0.0.0:993</code>. You need to look for the part after the semicolon. In this case it's 993. So you'll need to forward port 993.</p> - -<span class="next"><a href="dns.html">Next: Connect Your Domain and Server</a></span> - -<hr> -<p><em>Written by <a href="https://github.com/hidde-j">hiddej</a></em> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/server.html b/server.html deleted file mode 100644 index fb5d6d5..0000000 --- a/server.html +++ /dev/null @@ -1,146 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Get a Server – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Get a Server</h1></header> - <nav></nav> - <main> - <p> - Once you have a <a href=domain.html>domain name</a>, you'll need a server to host all your website files on. - In general, a server is just a computer that is constanly broadcasting some services on the internet. - </p> - <p> - Servers connected to the internet can be extremely useful with or without proper websites attached to them. - You can be your own website, email, file-sharing service and much more. - </p> - <h2>Getting a VPS</h2> - <p> - A Virtual Personal Server (VPS) is a very cheap and easy way to get a - web server. Without you having to buy expensive equipment. There are a - lot of online businesses that have massive server farms with great - internet connection and big power bills that allow you to rent a VPS in - that farm for pocket change. - </p> - - <p> - A VPS usually costs $5 a month. Sometimes slightly more, sometimes slightly less. - That's a good price for some internet real-estate, but in truth, you can host a huge number of websites and services on a single VPS, so you get a lot more. - I might have a dozen websites, an email server, a chat server and a file-sharing services on one VPS. - </p> - - <p> - The VPS provider that I'll be using for this guide is Vultr, since that is what I use. - Vultr provides a free one-month $100 credit to anyone who starts an account through <a href="https://www.vultr.com/?ref=8384069-6G">this referral link of mine</a> - so you can play around with their services with impunity. - </p> - - <h2>Starting your server in two minutes or less</h2> - - <p> - <a href="https://www.vultr.com/?ref=8384069-6G">Start an account on Vultr</a> and let's get started. - </p> - - <p> - Vultr (and other VPS providers) usually give you a choice in where and what exactly your VPS is. - </p> - - <h4>Server Location</h4> - - <p> - In general, it doesn't <em>hugely</em> matter what physical location - you have your server in. You might theoretically want it close to - where you or your audience might be, but if you host a server in - Singapore for an American audience, they won't have to be waiting a - perceptibly longer time to load the site. - </p> - - <a href="pix/server-location.png"><img src="pix/server-location.png" alt="Pick your servers's locatio"></a> - - <p><strong>Some locations might have different abilities and plans than others. - For example, in Vultr, their New York location has optional DDOS protection and also has some cheaper $3.50 servers.</strong></p> - - <h4>Operating System/Server Type</h4> - - <a href=pix/server-type.png><img src="pix/server-type.png" alt="server type"></a> - - <p> - I especially recommend <strong>Debian 10</strong> for an operating system for your server. - Debian is the "classic" server OS and as such, <strong>I make my guides on this site for Debian 10</strong>. - If you use another OS, just know that your millage may vary in terms of you might need to change some instructions here minorly. - </p> - - <h4>Server size</h4> - - <a href=pix/server-size.png><img src="pix/server-size.png" alt="server size"></a> - - <p> - You finally have a choice in how beefy a server you want. - On Vultr, I recommend getting the cheapest option that is not IPv6 only. - </p> - - <p> - Web hosting and even moderately complicated sites do not use huge amounts of RAM or CPU power. - If you start doing more intensive stuff than hosting some webpages and an email server and such, - you can always bump up your plan on Vultr without data loss (it's not so easy to bump down). - </p> - - <h4>Additional features</h4> - - <a href=pix/server-features.png><img src="pix/server-features.png" alt="additional features"></a> - - <p> - On Vultr, there are some final checkboxes you can select additional options. - <strong>You will want to check <em>Enable IPv6</em> and also <em>Block Storage Compatible</em>.</strong> - </p> - - <p> - We will be setting up IPv6 because it's important for future-proofing your website as more of the web moves to the IPv6 protocol. - Block storage is the ability (if you want) to later rent large storage disks to connect to your VPS if desired. - You just might want that as an option, so it's worth activating now. - </p> - - <h3>Done!</h3> - - <p> - Once you select those settings, your server will automatically be deployed. - Momentarily, you will be able to see your server's IP addresses which will be used for the next brief step: - </p> - - <span class=prev><a href="domain.html">Previous: Get a domain name.</a></span> - <span class=next><a href="dns.html">Next: Connect Your Domain and Server.</a></span> - - <hr> - - <h2>More info</h2> - - <h3>VPS vs. Self-hosting</h3> - <p> - It is very possible instead of using a VPS, hooking up an old computer to the internet and attempting to host a website from that. - That can be a valid option if you can do it if you have a great internet connection and can do so without draining your power bill. - I don't recommend it because I don't (and can't) do it given my bandwidth needs. - For newbs, there are also some extra steps you have to take care of with DNS and setting up static IPs and such. - </p> - - <p> - I might write a guide on this in the future, but I don't do it myself. - </p> - - <h3>Backups</h3> - - <p> - Vultr and other VPS providers often provide the ability to make backup snapshots of your server in case of dataloss or their own error. - Backups on Vultr are free right now. - When we learn how to use <code>rsync</code>, I will recommend you to also keep your own backup of your site, or at least an offline version of it. - There's a low chance of their whole system collapsing or something, but I say it's a good idea to be hyper-precautious. - </p> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/sshkeys.html b/sshkeys.html deleted file mode 100644 index dc0160f..0000000 --- a/sshkeys.html +++ /dev/null @@ -1,172 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Log on with SSH Keys – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Log on with SSH Keys</h1></header> - <nav></nav> - <main> - <p> - Let's generate and use SSH keys on our computer. - This allows us to ensure our identity better than a password ever could. - This allows us to do two main things: - </p> - <ol> - <li><strong>Password-less login</strong>: With SSH keys, we can permanently designate our profile on our local computer as safe for our server, allowing us to bypass password verification when logging into our server.</li> - <li><strong>Prevent hacking</strong>: Since we no longer need a password to log in, we can simply deactivate password logins on our server altogether, which prevents hacking from people who may be so lucky as to guess our password!</li> - </ol> - <p> - In other words, using an SSH key to login is <strong>both safer, faster and easier</strong>. - </p> - - <p> - This is especially useful once you start making scripts on your computer that interact with your server. - You can upload files in the background, edit your spam filters or anything else from your local computer without having to input - your password each time you touch the server. - </p> - <h2>Generate an SSH key pair</h2> - <p> - Generating an SSH key is simple. Just run: - </p> - <pre><code>ssh-keygen</code></pre> - <p> - It will prompt you for several options and you can generally chose the default options in each case. - It will ask you to optionally include a password on your SSH key. - I generally recommend against this unless you happen to be using a computer where you don't have root access but someone else does (it does minimize the ease of using an SSH key in our case). - </p> - <h3>What does this SSH key do?</h3> - <p> - Now whenever you use <code>ssh</code> to log into a server, you have the public key of this SSH key pair as your identifier. - You can tell your server to trust this key and it will automatically allow password-less logins from this computer. - </p> - <h3>Backing up your key</h3> - <p> - We will do that momentarily, but first, I recommend you backup your newly generated key if you plan to use it. - If we disable logins to this one key and then lose the key, we might be locked out of our server. - </p> - <p> - I suggest copying your entire <code>~/.ssh/</code> directory (user-specific) to a USB drive and storing it securely. - You may also copy it to the same place on another computer to use the key there. - </p> - - <h2>Making your server trust your key.</h2> - - <p> - Now that you have generated an SSH key, just run the following: - </p> - - <pre><code>ssh-copy-id root@yourdomain.com</code></pre> - - <p> - The command will ask for your server's root password and log you in briefly. - What this does is that it puts your public SSH key fingerprint on your server in a file <code>/root/.ssh/authorized_keys</code>. - This file in turn allows approved SSH keys to log in without passwords. - </p> - - <aside> - <p> - Note that you can also replace <strong>root</strong> with a username of an account on the server if you had made a non-root user that you'd like to easily log into as well. - For the username <strong>user</strong>, it will also store the key in <code>/home/user/.ssh/authorized_keys</code>. - </p> - </aside> - - <p> - To test if this has worked, now try logging in normally to your server with ssh: - </p> - - <pre><code>ssh root@yourdomain.com</code></pre> - - <p> - It should now let you log in without a password prompt! - </p> - <aside class=callout> - <p> - If you find that this does not work try running the following, make sure you are in the directory where the keys where created. - </p> - <p> - <code> chmod 700 .ssh/ </code> - </p> - <code> chmod 644 .ssh/id_rsa.pub </code> - <p> - <code> chmod 600 .ssh/id_rsa </code> - </p> - <code> chmod 644 .ssh/authorized_keys </code> - <p> - For whatever reason these files due not have the correct permissions set, as ssh is very picky about correct file permissions this can cause errors. The above will fix these. - </p> - </aside> - - <h2>Disabling Password Logins for Security</h2> - - <p> - Once we have authorized ssh keys for all the devices we need, we can actually just disable password logins. - If you've ever looked at your system logs (<code>journalctl -xe</code>) you will find that there are always hundreds of random Chinese computers trying to brute force every server connected to the internet with random passwords. - They are usually unsuccessful, but let's make it <strong>impossible</strong> for them. - </p> - - <p> - Log into your server and open the <code>/etc/ssh/sshd_config</code> file. - Here we can set settings for our SSH daemon that receives SSH requests. - </p> - - <p> - Now find, uncomment or create the following three lines and set them all to <strong>no</strong>: - </p> - - <pre><code>PasswordAuthentication <strong>no</strong> -ChallengeResponseAuthentication <strong>no</strong> -UsePAM <strong>no</strong></code></pre> - - <p> - Once we've done that, we will reload our SSH daemon: - </p> - - <pre><code>systemctl reload sshd</code></pre> - - <h3>We're done!</h3> - - <p> - Now you can log in quickly and password-less-ly to your server, despite the fact that it is now more secure than ever! - </p> - <p> - With these settings, even if a hacker steals or perfectly guesses an account password, they still cannot log in without an approved SSH key! - </p> - - - <h2>What if I lose my SSH key?!</h2> - - <p> - Firstly, don't do this. Take every precaution that you have a backup. - </p> - - <p> - If this does happen, Vultr and most other VPS providers will have a way out. - Log onto their website and select the server you want to log into. - </p> - - <img src="pix/ssh-01.png" alt="vultr login"> - - <p> - In the image above, to the right of your VPS name are a series of icons. - Click on the computer screen-like icon which is the leftmost one. - </p> - - <p> - This will open up a browser window emulating a terminal and you can always login with your password here, - since logins here count as being local and they do not use SSH and therefore can indeed validate with your password even if you have disabled it over SSH. - </p> - - <p> - From here, simply reverse the settings we set above and you can log in via SSH with a password and reapprove a newly created SSH key or whatever you want to do. - </p> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/standalone.html b/standalone.html deleted file mode 100644 index c9204d8..0000000 --- a/standalone.html +++ /dev/null @@ -1,32 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Certbot on Standalone Domains and Subdomains – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Certbot on Standalone Domains and Subdomains</h1></header> - <nav></nav> - <main> - <p>The command <code>certbot --nginx</code> will take an unencrypted website on an Nginx configuration file, get a certificate for it and change the configuration to use that certificate and thus HTTPS.</p> - - <p>Sometimes, however, you are given an Nginx configuration template that already has encryption/HTTPS, so running the automated <code>certbot --nginx</code> is not possible, as it will simply give an error saying that the certicate that Nginx is looking for doesn't already exist and thus the Nginx config is broken.</p> - - <p>So suppose you want to get a certificate for <strong>pleroma.example.org</strong> because you are installing Pleroma and the configuration file presupposes a certificate. - In this case you would want to run this:</p> - - <pre><code>systemctl stop nginx -certbot certonly --standalone -d <strong>pleroma.example.org</strong> -systemctl start nginx</code></pre> - - <p>What we do here is temporarily turn of Nginx, then run a <code>certonly</code> subcommand that generates a certificate for the domain without changing or caring about the Nginx configuration. Then we reactivate Nginx, thus turning back on our webserver.</p> - <p>The reason we deactivate Nginx is that it uses the ports that Certbot will want to bind to, and thus we must temporarily turn Nginx off to let Certbot use those ports. (What it actually does is spin up a dummy webserver that doesn't need to think about the Nginx configuration.)</p> - <p>This is just a little note of something that might confuse people, but the three commands above should suffice. If your site is still managed by Nginx, it should still be able to renew with simple <code>certbot renew --nginx</code> without a problem.</p> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/favicon.ico b/static/favicon.ico Binary files differindex d8f549d..d8f549d 100644 --- a/favicon.ico +++ b/static/favicon.ico diff --git a/pix/auth.svg b/static/pix/auth.svg index 5b17192..5b17192 100644 --- a/pix/auth.svg +++ b/static/pix/auth.svg diff --git a/pix/bat.svg b/static/pix/bat.svg index 2154658..2154658 100644 --- a/pix/bat.svg +++ b/static/pix/bat.svg diff --git a/pix/bitcoin-01.png b/static/pix/bitcoin-01.png Binary files differindex 8f38d0e..8f38d0e 100644 --- a/pix/bitcoin-01.png +++ b/static/pix/bitcoin-01.png diff --git a/pix/bitcoin-02.png b/static/pix/bitcoin-02.png Binary files differindex a566a18..a566a18 100644 --- a/pix/bitcoin-02.png +++ b/static/pix/bitcoin-02.png diff --git a/pix/bitcoin-03.png b/static/pix/bitcoin-03.png Binary files differindex dd02d8d..dd02d8d 100644 --- a/pix/bitcoin-03.png +++ b/static/pix/bitcoin-03.png diff --git a/pix/bitcoin-04.png b/static/pix/bitcoin-04.png Binary files differindex 104f179..104f179 100644 --- a/pix/bitcoin-04.png +++ b/static/pix/bitcoin-04.png diff --git a/pix/btc.png b/static/pix/btc.png Binary files differindex bbe842c..bbe842c 100644 --- a/pix/btc.png +++ b/static/pix/btc.png diff --git a/pix/btc.svg b/static/pix/btc.svg index b3fd9e3..b3fd9e3 100644 --- a/pix/btc.svg +++ b/static/pix/btc.svg diff --git a/static/pix/btcpay.svg b/static/pix/btcpay.svg new file mode 100644 index 0000000..bb9f410 --- /dev/null +++ b/static/pix/btcpay.svg @@ -0,0 +1 @@ +<svg id="レイヤー_1" data-name="レイヤー 1" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 105.46 188.47"><defs><style>.cls-1{fill:#cedc21;}.cls-2{fill:#51b13e;}.cls-3{fill:#1e7a44;}.cls-4{fill:#fff;}</style></defs><title>btcpay</title><path class="cls-1" d="M117.24,247.32a11.06,11.06,0,0,1-11-11.06V69.91a11.06,11.06,0,1,1,22.11,0V236.26A11.06,11.06,0,0,1,117.24,247.32Z" transform="translate(-106.19 -58.85)"/><path class="cls-2" d="M117.25,247.32a11.06,11.06,0,0,1-4.75-21l66.66-31.64L110.69,144.2a11.05,11.05,0,1,1,13.11-17.8l83.35,61.41a11,11,0,0,1-1.82,18.88L122,246.25A10.94,10.94,0,0,1,117.25,247.32Z" transform="translate(-106.19 -58.85)"/><path class="cls-1" d="M117.25,181.93a11.05,11.05,0,0,1-6.56-20l68.47-50.45L112.5,79.89a11.05,11.05,0,0,1,9.48-20l83.35,39.56a11.05,11.05,0,0,1,1.82,18.89L123.8,179.78A11,11,0,0,1,117.25,181.93Z" transform="translate(-106.19 -58.85)"/><polygon class="cls-3" points="22.11 70.86 22.11 117.61 53.82 94.25 22.11 70.86"/><rect class="cls-4" y="51.26" width="22.11" height="53.89"/><path class="cls-1" d="M128.3,69.91a11.06,11.06,0,1,0-22.11,0V209H128.3Z" transform="translate(-106.19 -58.85)"/></svg>
\ No newline at end of file diff --git a/pix/calibre.png b/static/pix/calibre.png Binary files differindex 81adc85..81adc85 100644 --- a/pix/calibre.png +++ b/static/pix/calibre.png diff --git a/pix/calibre/calibre-1.png b/static/pix/calibre/calibre-1.png Binary files differindex cf767e0..cf767e0 100644 --- a/pix/calibre/calibre-1.png +++ b/static/pix/calibre/calibre-1.png diff --git a/pix/calibre/calibre-2.png b/static/pix/calibre/calibre-2.png Binary files differindex e0c76ba..e0c76ba 100644 --- a/pix/calibre/calibre-2.png +++ b/static/pix/calibre/calibre-2.png diff --git a/pix/certbot-01.png b/static/pix/certbot-01.png Binary files differindex 37d81f8..37d81f8 100644 --- a/pix/certbot-01.png +++ b/static/pix/certbot-01.png diff --git a/pix/certbot-02.png b/static/pix/certbot-02.png Binary files differindex 24905f8..24905f8 100644 --- a/pix/certbot-02.png +++ b/static/pix/certbot-02.png diff --git a/pix/certbot-03.png b/static/pix/certbot-03.png Binary files differindex 1a60fe9..1a60fe9 100644 --- a/pix/certbot-03.png +++ b/static/pix/certbot-03.png diff --git a/pix/cgit.svg b/static/pix/cgit.svg index 72eafa6..72eafa6 100644 --- a/pix/cgit.svg +++ b/static/pix/cgit.svg diff --git a/pix/chad.gif b/static/pix/chad.gif Binary files differindex 98b8904..98b8904 100644 --- a/pix/chad.gif +++ b/static/pix/chad.gif diff --git a/static/pix/devault.jpg b/static/pix/devault.jpg Binary files differnew file mode 100644 index 0000000..a3dc88a --- /dev/null +++ b/static/pix/devault.jpg diff --git a/static/pix/dkim-01.png b/static/pix/dkim-01.png Binary files differnew file mode 100644 index 0000000..ab8a9a4 --- /dev/null +++ b/static/pix/dkim-01.png diff --git a/pix/dns-epik.png b/static/pix/dns-epik.png Binary files differindex 33d2c40..33d2c40 100644 --- a/pix/dns-epik.png +++ b/static/pix/dns-epik.png diff --git a/pix/dns-ipv4-done.png b/static/pix/dns-ipv4-done.png Binary files differindex 1195f06..1195f06 100644 --- a/pix/dns-ipv4-done.png +++ b/static/pix/dns-ipv4-done.png diff --git a/pix/dns-ipv4.png b/static/pix/dns-ipv4.png Binary files differindex d9c14cd..d9c14cd 100644 --- a/pix/dns-ipv4.png +++ b/static/pix/dns-ipv4.png diff --git a/pix/dns-ipv6-done.png b/static/pix/dns-ipv6-done.png Binary files differindex 0559575..0559575 100644 --- a/pix/dns-ipv6-done.png +++ b/static/pix/dns-ipv6-done.png diff --git a/pix/dns-ipv6.png b/static/pix/dns-ipv6.png Binary files differindex 8fffd6a..8fffd6a 100644 --- a/pix/dns-ipv6.png +++ b/static/pix/dns-ipv6.png diff --git a/pix/dns-ping.png b/static/pix/dns-ping.png Binary files differindex f900774..f900774 100644 --- a/pix/dns-ping.png +++ b/static/pix/dns-ping.png diff --git a/pix/dns-vultr.png b/static/pix/dns-vultr.png Binary files differindex 9db0be7..9db0be7 100644 --- a/pix/dns-vultr.png +++ b/static/pix/dns-vultr.png diff --git a/pix/domain-cart.png b/static/pix/domain-cart.png Binary files differindex 7f55880..7f55880 100644 --- a/pix/domain-cart.png +++ b/static/pix/domain-cart.png diff --git a/pix/domain-search.png b/static/pix/domain-search.png Binary files differindex e99ca2a..e99ca2a 100644 --- a/pix/domain-search.png +++ b/static/pix/domain-search.png diff --git a/static/pix/ejabberd-admin.jpg b/static/pix/ejabberd-admin.jpg Binary files differnew file mode 100644 index 0000000..9bbd4ed --- /dev/null +++ b/static/pix/ejabberd-admin.jpg diff --git a/static/pix/ejabberd-login.jpg b/static/pix/ejabberd-login.jpg Binary files differnew file mode 100644 index 0000000..8904aaf --- /dev/null +++ b/static/pix/ejabberd-login.jpg diff --git a/static/pix/ejabberd.png b/static/pix/ejabberd.png Binary files differnew file mode 100644 index 0000000..694e435 --- /dev/null +++ b/static/pix/ejabberd.png diff --git a/pix/element.svg b/static/pix/element.svg index d29423e..d29423e 100644 --- a/pix/element.svg +++ b/static/pix/element.svg diff --git a/static/pix/fren_apu_tongue.png b/static/pix/fren_apu_tongue.png Binary files differnew file mode 100644 index 0000000..eb525be --- /dev/null +++ b/static/pix/fren_apu_tongue.png diff --git a/pix/git.svg b/static/pix/git.svg index 2e42bc7..2e42bc7 100644 --- a/pix/git.svg +++ b/static/pix/git.svg diff --git a/pix/gitea.svg b/static/pix/gitea.svg index 9df6b83..9df6b83 100644 --- a/pix/gitea.svg +++ b/static/pix/gitea.svg diff --git a/pix/github.svg b/static/pix/github.svg index 93af7db..93af7db 100644 --- a/pix/github.svg +++ b/static/pix/github.svg diff --git a/pix/html-01.png b/static/pix/html-01.png Binary files differindex c984971..c984971 100644 --- a/pix/html-01.png +++ b/static/pix/html-01.png diff --git a/pix/html-02.png b/static/pix/html-02.png Binary files differindex d2f70d0..d2f70d0 100644 --- a/pix/html-02.png +++ b/static/pix/html-02.png diff --git a/pix/html2-01.png b/static/pix/html2-01.png Binary files differindex b808c0e..b808c0e 100644 --- a/pix/html2-01.png +++ b/static/pix/html2-01.png diff --git a/pix/i2p.svg b/static/pix/i2p.svg index 5dc629b..5dc629b 100644 --- a/pix/i2p.svg +++ b/static/pix/i2p.svg diff --git a/static/pix/imgcompress-cat.png b/static/pix/imgcompress-cat.png Binary files differnew file mode 100644 index 0000000..7243ae8 --- /dev/null +++ b/static/pix/imgcompress-cat.png diff --git a/static/pix/imgcompress-network.png b/static/pix/imgcompress-network.png Binary files differnew file mode 100644 index 0000000..09bc401 --- /dev/null +++ b/static/pix/imgcompress-network.png diff --git a/static/pix/inok.jpg b/static/pix/inok.jpg Binary files differnew file mode 100644 index 0000000..5bf7fdb --- /dev/null +++ b/static/pix/inok.jpg diff --git a/pix/irc.svg b/static/pix/irc.svg index 0f48379..0f48379 100644 --- a/pix/irc.svg +++ b/static/pix/irc.svg diff --git a/pix/irc/hexchat-connection-complete.png b/static/pix/irc/hexchat-connection-complete.png Binary files differindex 096ae01..096ae01 100644 --- a/pix/irc/hexchat-connection-complete.png +++ b/static/pix/irc/hexchat-connection-complete.png diff --git a/pix/irc/hexchat-network-edit.png b/static/pix/irc/hexchat-network-edit.png Binary files differindex 4a0fb6f..4a0fb6f 100644 --- a/pix/irc/hexchat-network-edit.png +++ b/static/pix/irc/hexchat-network-edit.png diff --git a/pix/irc/hexchat-network-select.png b/static/pix/irc/hexchat-network-select.png Binary files differindex 9f4ffe3..9f4ffe3 100644 --- a/pix/irc/hexchat-network-select.png +++ b/static/pix/irc/hexchat-network-select.png diff --git a/pix/irc/hexchat-sasl.png b/static/pix/irc/hexchat-sasl.png Binary files differindex ce77149..ce77149 100644 --- a/pix/irc/hexchat-sasl.png +++ b/static/pix/irc/hexchat-sasl.png diff --git a/pix/irc/textual-identity.png b/static/pix/irc/textual-identity.png Binary files differindex a2fce22..a2fce22 100644 --- a/pix/irc/textual-identity.png +++ b/static/pix/irc/textual-identity.png diff --git a/pix/irc/textual-network-edit.png b/static/pix/irc/textual-network-edit.png Binary files differindex 1eb4dc7..1eb4dc7 100644 --- a/pix/irc/textual-network-edit.png +++ b/static/pix/irc/textual-network-edit.png diff --git a/pix/itoopie.svg b/static/pix/itoopie.svg index 39e430d..39e430d 100644 --- a/pix/itoopie.svg +++ b/static/pix/itoopie.svg diff --git a/pix/jitsi-01.webp b/static/pix/jitsi-01.webp Binary files differindex a71f1ae..a71f1ae 100644 --- a/pix/jitsi-01.webp +++ b/static/pix/jitsi-01.webp diff --git a/pix/jitsi.svg b/static/pix/jitsi.svg index 5a3526a..5a3526a 100644 --- a/pix/jitsi.svg +++ b/static/pix/jitsi.svg diff --git a/pix/landchad.gif b/static/pix/landchad.gif Binary files differindex 302cd26..302cd26 100644 --- a/pix/landchad.gif +++ b/static/pix/landchad.gif diff --git a/static/pix/matrix.svg b/static/pix/matrix.svg new file mode 100644 index 0000000..9a8b8dd --- /dev/null +++ b/static/pix/matrix.svg @@ -0,0 +1,48 @@ +<?xml version="1.0" encoding="utf-8"?> +<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd"> +<svg version="1.1" id="Layer_1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px" + width="793.322px" height="340.809px" viewBox="0 0 793.322 340.809" fill="#fff" enable-background="new 0 0 793.322 340.809" + xml:space="preserve"> +<path d="M10.875,9.711v321.386h23.13v7.711H1.999V2.001h32.006v7.71H10.875z"/> +<path d="M99.988,111.595v16.264h0.463c4.338-6.191,9.563-10.998,15.684-14.406c6.117-3.402,13.129-5.11,21.027-5.11 + c7.588,0,14.521,1.475,20.793,4.415c6.274,2.945,11.038,8.131,14.291,15.567c3.56-5.265,8.4-9.913,14.521-13.94 + c6.117-4.025,13.358-6.042,21.724-6.042c6.351,0,12.234,0.776,17.66,2.325c5.418,1.549,10.065,4.027,13.938,7.434 + c3.869,3.41,6.889,7.863,9.062,13.357c2.167,5.504,3.253,12.122,3.253,19.869v80.385H219.41v-68.074 + c0-4.025-0.154-7.82-0.465-11.385c-0.313-3.56-1.161-6.656-2.555-9.293c-1.395-2.631-3.45-4.724-6.157-6.274 + c-2.711-1.543-6.391-2.322-11.037-2.322s-8.403,0.896-11.269,2.671c-2.868,1.784-5.112,4.109-6.737,6.971 + c-1.626,2.869-2.711,6.12-3.252,9.762c-0.545,3.638-0.814,7.318-0.814,11.035v66.91h-32.991v-67.375c0-3.562-0.081-7.087-0.23-10.57 + c-0.158-3.487-0.814-6.7-1.978-9.645c-1.162-2.94-3.099-5.304-5.809-7.088c-2.711-1.775-6.699-2.671-11.965-2.671 + c-1.551,0-3.603,0.349-6.156,1.048c-2.556,0.697-5.036,2.016-7.435,3.949c-2.404,1.938-4.454,4.726-6.158,8.363 + c-1.705,3.642-2.556,8.402-2.556,14.287v69.701h-32.99V111.595H99.988z"/> +<path d="M273.544,129.255c3.405-5.113,7.744-9.215,13.012-12.316c5.264-3.097,11.186-5.303,17.771-6.621 + c6.582-1.315,13.205-1.976,19.865-1.976c6.042,0,12.158,0.428,18.354,1.277c6.195,0.855,11.85,2.522,16.962,4.997 + c5.111,2.477,9.292,5.926,12.546,10.338c3.253,4.414,4.879,10.262,4.879,17.543v62.494c0,5.428,0.31,10.611,0.931,15.567 + c0.615,4.959,1.701,8.676,3.251,11.153H347.66c-0.621-1.86-1.126-3.755-1.511-5.693c-0.39-1.933-0.661-3.908-0.813-5.923 + c-5.267,5.422-11.465,9.217-18.585,11.386c-7.127,2.163-14.407,3.251-21.842,3.251c-5.733,0-11.077-0.698-16.033-2.09 + c-4.958-1.395-9.293-3.562-13.01-6.51c-3.718-2.938-6.622-6.656-8.713-11.147s-3.138-9.84-3.138-16.033 + c0-6.813,1.199-12.43,3.604-16.84c2.399-4.417,5.495-7.939,9.295-10.575c3.793-2.632,8.129-4.607,13.01-5.923 + c4.878-1.315,9.795-2.358,14.752-3.137c4.957-0.772,9.835-1.393,14.638-1.857c4.801-0.466,9.062-1.164,12.779-2.093 + c3.718-0.929,6.658-2.282,8.829-4.065c2.165-1.781,3.172-4.375,3.02-7.785c0-3.56-0.58-6.389-1.742-8.479 + c-1.161-2.09-2.711-3.719-4.646-4.88c-1.937-1.161-4.183-1.936-6.737-2.325c-2.557-0.382-5.309-0.58-8.248-0.58 + c-6.506,0-11.617,1.395-15.335,4.183c-3.716,2.788-5.889,7.437-6.506,13.94h-32.991 + C268.199,140.794,270.132,134.363,273.544,129.255z M338.713,175.838c-2.09,0.696-4.337,1.275-6.736,1.741 + c-2.402,0.465-4.918,0.853-7.551,1.161c-2.635,0.313-5.268,0.698-7.899,1.163c-2.48,0.461-4.919,1.086-7.317,1.857 + c-2.404,0.779-4.495,1.822-6.274,3.138c-1.784,1.317-3.216,2.985-4.3,4.994c-1.085,2.014-1.626,4.571-1.626,7.668 + c0,2.94,0.541,5.422,1.626,7.431c1.084,2.017,2.558,3.604,4.416,4.765s4.025,1.976,6.507,2.438c2.475,0.466,5.031,0.698,7.665,0.698 + c6.505,0,11.537-1.082,15.103-3.253c3.561-2.166,6.192-4.762,7.899-7.785c1.702-3.019,2.749-6.072,3.137-9.174 + c0.384-3.097,0.58-5.576,0.58-7.434v-12.316C342.547,174.173,340.805,175.14,338.713,175.838z"/> +<path d="M463.825,111.595v22.072h-24.161v59.479c0,5.573,0.928,9.292,2.788,11.149c1.856,1.859,5.576,2.788,11.152,2.788 + c1.859,0,3.638-0.076,5.343-0.232c1.703-0.152,3.33-0.388,4.878-0.696v25.557c-2.788,0.465-5.887,0.773-9.293,0.931 + c-3.407,0.149-6.737,0.23-9.99,0.23c-5.111,0-9.953-0.35-14.521-1.048c-4.571-0.695-8.597-2.047-12.081-4.063 + c-3.486-2.011-6.236-4.88-8.248-8.597c-2.016-3.714-3.021-8.595-3.021-14.639v-70.859h-19.98v-22.072h19.98V75.583h32.992v36.012 + H463.825z"/> +<path d="M510.988,111.595V133.9h0.465c1.546-3.72,3.636-7.163,6.272-10.341c2.634-3.172,5.652-5.885,9.06-8.131 + c3.405-2.242,7.047-3.985,10.923-5.228c3.868-1.237,7.898-1.859,12.081-1.859c2.168,0,4.566,0.39,7.202,1.163v30.67 + c-1.551-0.312-3.41-0.584-5.576-0.814c-2.17-0.233-4.26-0.35-6.274-0.35c-6.041,0-11.152,1.01-15.332,3.021 + c-4.182,2.014-7.55,4.761-10.107,8.247c-2.555,3.487-4.379,7.55-5.462,12.198c-1.083,4.645-1.625,9.682-1.625,15.102v54.133h-32.991 + V111.595H510.988z"/> +<path d="M570.93,93.007V65.824h32.994v27.183H570.93z M603.924,111.595v120.117H570.93V111.595H603.924z"/> +<path d="M621.115,111.595h37.637l21.144,31.365l20.911-31.365h36.476l-39.496,56.226l44.377,63.892h-37.64l-25.093-37.87 + l-25.094,37.87h-36.938l43.213-63.193L621.115,111.595z"/> +<path d="M782.443,331.097V9.711h-23.13v-7.71h32.008v336.807h-32.008v-7.711H782.443z"/> +</svg> diff --git a/pix/monero-01.png b/static/pix/monero-01.png Binary files differindex 44f7a62..44f7a62 100644 --- a/pix/monero-01.png +++ b/static/pix/monero-01.png diff --git a/pix/monero-02.png b/static/pix/monero-02.png Binary files differindex 1ef8bbc..1ef8bbc 100644 --- a/pix/monero-02.png +++ b/static/pix/monero-02.png diff --git a/pix/monero-03.png b/static/pix/monero-03.png Binary files differindex 52bebbe..52bebbe 100644 --- a/pix/monero-03.png +++ b/static/pix/monero-03.png diff --git a/pix/monero-04.png b/static/pix/monero-04.png Binary files differindex 228734c..228734c 100644 --- a/pix/monero-04.png +++ b/static/pix/monero-04.png diff --git a/static/pix/movim.svg b/static/pix/movim.svg new file mode 100644 index 0000000..9a34dd7 --- /dev/null +++ b/static/pix/movim.svg @@ -0,0 +1,20 @@ +<?xml version="1.0" encoding="UTF-8" standalone="no"?> +<svg version="1.1" viewBox="0 0 240 240" id="svg23" sodipodi:docname="vectorial.svg" inkscape:version="1.1.2 (0a00cf5339, 2022-02-04)" inkscape:export-filename="/var/www/html/movim/public/theme/img/app/512.png" inkscape:export-xdpi="204.8" inkscape:export-ydpi="204.8" xmlns:inkscape="http://www.inkscape.org/namespaces/inkscape" xmlns:sodipodi="http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd" xmlns="http://www.w3.org/2000/svg" xmlns:svg="http://www.w3.org/2000/svg"> + <sodipodi:namedview id="namedview25" pagecolor="#505050" bordercolor="#eeeeee" borderopacity="1" inkscape:pageshadow="0" inkscape:pageopacity="0" inkscape:pagecheckerboard="0" showgrid="false" inkscape:zoom="2.08" inkscape:cx="119.95192" inkscape:cy="120.19231" inkscape:window-width="1920" inkscape:window-height="1025" inkscape:window-x="0" inkscape:window-y="0" inkscape:window-maximized="1" inkscape:current-layer="svg23"/> + <defs id="defs15"> + <filter id="c" x="-0.14247762" y="-0.24434544" width="1.2849552" height="1.4886909"> + <feGaussianBlur stdDeviation="10.686" id="feGaussianBlur2"/> + </filter> + <linearGradient id="b" x1="40" x2="200" y1="40" y2="200" gradientUnits="userSpaceOnUse"> + <stop stop-color="#345cca" offset="0" id="stop5" style="stop-color:#5452c9;stop-opacity:1"/> + <stop stop-color="#5d47c6" offset="1" id="stop7" style="stop-color:#413fb5;stop-opacity:1"/> + </linearGradient> + <linearGradient id="a" x1="125" x2="174.95" y1="65" y2="210.1" gradientUnits="userSpaceOnUse"> + <stop stop-color="#344394" offset="0" id="stop10"/> + <stop stop-color="#7c45df" offset="1" id="stop12" style="stop-color:#5553be;stop-opacity:1"/> + </linearGradient> + </defs> + <circle cx="120" cy="120" fill="url(#b)" stroke="url(#a)" stroke-width="3" id="circle17" r="110" inkscape:export-filename="/var/www/html/movim/public/theme/img/16.png" inkscape:export-xdpi="6.8899999" inkscape:export-ydpi="6.8899999"/> + <path transform="scale(.91667)" d="m112.916 82.039c-20.51 0-37.137 16.627-37.137 37.137 0 1.594 0.10688 3.1707 0.30171 4.7118-0.29375-9e-3 -0.58624-0.0232-0.88201-0.0232-17.434-7e-5 -31.567 14.133-31.567 31.567 0 17.434 14.133 31.567 31.567 31.567h122.44c14.357 0 25.996-11.639 25.996-25.996 0-14.357-11.639-25.996-25.996-25.996-0.0468 0-0.093-2.5e-4 -0.13928 0 0.0334-0.64832 0.0696-1.293 0.0696-1.9497 0-20.51-16.627-37.137-37.137-37.137-5.7242 0-11.15 1.3077-15.992 3.6209-6.5596-10.507-18.221-17.501-31.52-17.501z" fill="#332949" opacity=".45896" filter="url(#c)" id="path19"/> + <path d="m101.59 73.35c-18.232 0-33.011 14.78-33.011 33.011 0 1.4169 0.095 2.8184 0.26819 4.1883-0.26111-8e-3 -0.5211-0.0206-0.78401-0.0206-15.497-9e-5 -28.059 12.562-28.059 28.059 0 15.497 12.563 28.059 28.059 28.059h108.83c12.762 0 23.108-10.346 23.108-23.108 0-12.762-10.346-23.108-23.108-23.108-0.0416 0-0.0827-2.2e-4 -0.1238 0 0.0297-0.57629 0.0619-1.1493 0.0619-1.7331 0-18.231-14.78-33.011-33.011-33.011-5.0882 0-9.9111 1.1624-14.215 3.2186-5.8308-9.3396-16.197-15.556-28.018-15.556z" fill="#fff" id="path21"/> +</svg>
\ No newline at end of file diff --git a/pix/nextcloud.svg b/static/pix/nextcloud.svg index 6f2e1a3..6f2e1a3 100644 --- a/pix/nextcloud.svg +++ b/static/pix/nextcloud.svg diff --git a/pix/nginx-password.png b/static/pix/nginx-password.png Binary files differindex a1ae5e5..a1ae5e5 100644 --- a/pix/nginx-password.png +++ b/static/pix/nginx-password.png diff --git a/pix/nginx-website.png b/static/pix/nginx-website.png Binary files differindex 40d5236..40d5236 100644 --- a/pix/nginx-website.png +++ b/static/pix/nginx-website.png diff --git a/pix/openalias-01.png b/static/pix/openalias-01.png Binary files differindex b239634..b239634 100644 --- a/pix/openalias-01.png +++ b/static/pix/openalias-01.png diff --git a/pix/openalias-02.png b/static/pix/openalias-02.png Binary files differindex 03a45b0..03a45b0 100644 --- a/pix/openalias-02.png +++ b/static/pix/openalias-02.png diff --git a/pix/openalias-03.png b/static/pix/openalias-03.png Binary files differindex 9e2ba0b..9e2ba0b 100644 --- a/pix/openalias-03.png +++ b/static/pix/openalias-03.png diff --git a/pix/openalias-04.png b/static/pix/openalias-04.png Binary files differindex 35caf10..35caf10 100644 --- a/pix/openalias-04.png +++ b/static/pix/openalias-04.png diff --git a/pix/openalias-05.png b/static/pix/openalias-05.png Binary files differindex a435462..a435462 100644 --- a/pix/openalias-05.png +++ b/static/pix/openalias-05.png diff --git a/pix/peertube-login.jpg b/static/pix/peertube-login.jpg Binary files differindex d191cc4..d191cc4 100644 --- a/pix/peertube-login.jpg +++ b/static/pix/peertube-login.jpg diff --git a/pix/peertube.svg b/static/pix/peertube.svg index 38992a5..38992a5 100644 --- a/pix/peertube.svg +++ b/static/pix/peertube.svg diff --git a/pix/pleroma.svg b/static/pix/pleroma.svg index c92da7c..c92da7c 100644 --- a/pix/pleroma.svg +++ b/static/pix/pleroma.svg diff --git a/static/pix/prosody.svg b/static/pix/prosody.svg new file mode 100644 index 0000000..9edae9b --- /dev/null +++ b/static/pix/prosody.svg @@ -0,0 +1,9 @@ +<svg xmlns="http://www.w3.org/2000/svg" height="64" viewBox="0 0 480 480" width="64"> + <g> + <title>Prosody Logo</title> + <rect fill="#6197df" height="220" id="svg_1" rx="60" ry="60" width="220" x="10" y="10"/> + <rect fill="#f29b00" height="220" id="svg_2" rx="60" ry="60" width="220" x="10" y="240"/> + <rect fill="#f29b00" height="220" id="svg_3" rx="60" ry="60" width="220" x="240" y="10"/> + <rect fill="#6197df" height="220" id="svg_4" rx="60" ry="60" width="220" x="240" y="240"/> + </g> +</svg>
\ No newline at end of file diff --git a/static/pix/radicale.svg b/static/pix/radicale.svg new file mode 100644 index 0000000..546d3d1 --- /dev/null +++ b/static/pix/radicale.svg @@ -0,0 +1,10 @@ +<?xml version="1.0" encoding="UTF-8" standalone="no"?> +<svg width="200" height="300" xmlns="http://www.w3.org/2000/svg"> + <path fill="#a40000" d="M 186,188 C 184,98 34,105 47,192 C 59,279 130,296 130,296 C 130,296 189,277 186,188 z" /> + <path fill="#ffffff" d="M 73,238 C 119,242 140,241 177,222 C 172,270 131,288 131,288 C 131,288 88,276 74,238 z" /> + <g fill="none" stroke="#4e9a06" stroke-width="15"> + <path d="M 103,137 C 77,69 13,62 13,62" /> + <path d="M 105,136 C 105,86 37,20 37,20" /> + <path d="M 105,135 C 112,73 83,17 83,17" /> + </g> +</svg> diff --git a/pix/rainloop-1.png b/static/pix/rainloop-1.png Binary files differindex 55bf5b8..55bf5b8 100644 --- a/pix/rainloop-1.png +++ b/static/pix/rainloop-1.png diff --git a/pix/rainloop-2.png b/static/pix/rainloop-2.png Binary files differindex 5f237de..5f237de 100644 --- a/pix/rainloop-2.png +++ b/static/pix/rainloop-2.png diff --git a/static/pix/rainloop.png b/static/pix/rainloop.png Binary files differnew file mode 100644 index 0000000..93500ab --- /dev/null +++ b/static/pix/rainloop.png diff --git a/static/pix/rdns-01.png b/static/pix/rdns-01.png Binary files differnew file mode 100644 index 0000000..464bb07 --- /dev/null +++ b/static/pix/rdns-01.png diff --git a/static/pix/rdns-02.png b/static/pix/rdns-02.png Binary files differnew file mode 100644 index 0000000..35eefec --- /dev/null +++ b/static/pix/rdns-02.png diff --git a/pix/rss.svg b/static/pix/rss.svg index 35afbe2..35afbe2 100644 --- a/pix/rss.svg +++ b/static/pix/rss.svg diff --git a/static/pix/rsync.png b/static/pix/rsync.png Binary files differnew file mode 100644 index 0000000..7190b41 --- /dev/null +++ b/static/pix/rsync.png diff --git a/static/pix/searxng.svg b/static/pix/searxng.svg new file mode 100644 index 0000000..417e7ed --- /dev/null +++ b/static/pix/searxng.svg @@ -0,0 +1,19 @@ +<?xml version="1.0" encoding="UTF-8" standalone="no"?> +<svg xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:cc="http://creativecommons.org/ns#" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:svg="http://www.w3.org/2000/svg" xmlns="http://www.w3.org/2000/svg" id="svg8" version="1.1" viewBox="0 0 92 92" height="92mm" width="92mm"> + <defs id="defs2"/> + <metadata id="metadata5"> + <rdf:RDF> + <cc:Work rdf:about=""> + <dc:format>image/svg+xml</dc:format> + <dc:type rdf:resource="http://purl.org/dc/dcmitype/StillImage"/> + <dc:title/> + </cc:Work> + </rdf:RDF> + </metadata> + <g transform="translate(-40.921303,-17.416526)" id="layer1"> + <circle r="0" style="fill:none;stroke:#000000;stroke-width:12;stroke-miterlimit:4;stroke-dasharray:none;stroke-opacity:1" cy="92" cx="75" id="path3713"/> + <circle r="30" cy="53.902557" cx="75.921303" id="path834" style="fill:none;fill-opacity:1;stroke:#3050ff;stroke-width:10;stroke-miterlimit:4;stroke-dasharray:none;stroke-opacity:1"/> + <path d="m 67.514849,37.91524 a 18,18 0 0 1 21.051475,3.312407 18,18 0 0 1 3.137312,21.078282" id="path852" style="fill:none;fill-opacity:1;stroke:#3050ff;stroke-width:5;stroke-miterlimit:4;stroke-dasharray:none;stroke-opacity:1"/> + <rect transform="rotate(-46.234709)" ry="1.8669105e-13" y="122.08995" x="3.7063529" height="39.963303" width="18.846331" id="rect912" style="opacity:1;fill:#3050ff;fill-opacity:1;stroke:none;stroke-width:8;stroke-miterlimit:4;stroke-dasharray:none;stroke-opacity:1"/> + </g> +</svg>
\ No newline at end of file diff --git a/pix/server-features.png b/static/pix/server-features.png Binary files differindex 6891b46..6891b46 100644 --- a/pix/server-features.png +++ b/static/pix/server-features.png diff --git a/pix/server-location.png b/static/pix/server-location.png Binary files differindex b97e8d2..b97e8d2 100644 --- a/pix/server-location.png +++ b/static/pix/server-location.png diff --git a/pix/server-size.png b/static/pix/server-size.png Binary files differindex 39ddc33..39ddc33 100644 --- a/pix/server-size.png +++ b/static/pix/server-size.png diff --git a/pix/server-type.png b/static/pix/server-type.png Binary files differindex 188b101..188b101 100644 --- a/pix/server-type.png +++ b/static/pix/server-type.png diff --git a/static/pix/smtp-01.png b/static/pix/smtp-01.png Binary files differnew file mode 100644 index 0000000..8b023d7 --- /dev/null +++ b/static/pix/smtp-01.png diff --git a/static/pix/smtp-02.png b/static/pix/smtp-02.png Binary files differnew file mode 100644 index 0000000..82f8774 --- /dev/null +++ b/static/pix/smtp-02.png diff --git a/pix/ssh-01.png b/static/pix/ssh-01.png Binary files differindex 855f313..855f313 100644 --- a/pix/ssh-01.png +++ b/static/pix/ssh-01.png diff --git a/pix/tor.svg b/static/pix/tor.svg index 4d7eefd..4d7eefd 100644 --- a/pix/tor.svg +++ b/static/pix/tor.svg diff --git a/static/pix/webrtc.svg b/static/pix/webrtc.svg new file mode 100644 index 0000000..582a506 --- /dev/null +++ b/static/pix/webrtc.svg @@ -0,0 +1,16 @@ +<?xml version="1.0" encoding="UTF-8" standalone="no"?> +<svg width="256px" height="249px" viewBox="0 0 256 249" version="1.1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" preserveAspectRatio="xMidYMid"> + <g> + <path d="M142.076578,191.086817 C142.076578,159.280656 116.294759,133.494615 84.4885969,133.494615 C52.6782136,133.494615 26.896394,159.280656 26.896394,191.086817 C26.896394,222.892979 52.6782136,248.67902 84.4885969,248.67902 C116.294759,248.67902 142.076578,222.892979 142.076578,191.086817" fill="#FF6600" transform="translate(84.486486, 191.086817) scale(1, -1) translate(-84.486486, -191.086817) "></path> + <path d="M255.979703,110.454356 C255.979703,78.652416 230.197884,52.862153 198.391722,52.862153 C166.581339,52.862153 140.799519,78.652416 140.799519,110.454356 C140.799519,142.260518 166.581339,168.050781 198.391722,168.050781 C230.197884,168.050781 255.979703,142.260518 255.979703,110.454356" fill="#FFCC00" transform="translate(198.389611, 110.456467) scale(1, -1) translate(-198.389611, -110.456467) "></path> + <path d="M115.200498,109.176452 C115.200498,77.3745125 89.4186786,51.5842495 57.6082953,51.5842495 C25.8063553,51.5842495 0.0203140271,77.3745125 0.0203140271,109.176452 C0.0203140271,140.982614 25.8063553,166.772877 57.6082953,166.772877 C89.4186786,166.772877 115.200498,140.982614 115.200498,109.176452" fill="#0089CC" transform="translate(57.610406, 109.178563) scale(1, -1) translate(-57.610406, -109.178563) "></path> + <path d="M230.385749,191.086817 C230.385749,159.280656 204.603929,133.494615 172.789324,133.494615 C140.987384,133.494615 115.201343,159.280656 115.201343,191.086817 C115.201343,222.892979 140.987384,248.67902 172.789324,248.67902 C204.603929,248.67902 230.385749,222.892979 230.385749,191.086817" fill="#009939" transform="translate(172.793546, 191.086817) scale(1, -1) translate(-172.793546, -191.086817) "></path> + <path d="M185.592001,57.9843213 C185.592001,26.1781597 159.805959,0.392118349 127.999798,0.392118349 C96.1936359,0.392118349 70.4075946,26.1781597 70.4075946,57.9843213 C70.4075946,89.790483 96.1936359,115.576524 127.999798,115.576524 C159.805959,115.576524 185.592001,89.790483 185.592001,57.9843213" fill="#BF0000" transform="translate(127.999798, 57.984321) scale(1, -1) translate(-127.999798, -57.984321) "></path> + <path d="M140.798675,57.9788331 C140.798675,56.76721 140.904217,55.580917 140.980207,54.3861807 C166.525612,60.2796505 185.590734,83.1189569 185.590734,110.454356 C185.590734,111.665979 185.485192,112.856494 185.409202,114.05123 C159.863796,108.153539 140.798675,85.3142322 140.798675,57.9788331" fill="#FC0007" transform="translate(163.194704, 84.218705) scale(1, -1) translate(-163.194704, -84.218705) "></path> + <path d="M148.39686,162.570614 C158.322038,145.219495 176.973434,133.495881 198.394255,133.495881 C207.124696,133.495881 215.369643,135.496959 222.787141,138.975626 C212.866185,156.326744 194.214789,168.050358 172.789746,168.050358 C164.059305,168.050358 155.814358,166.049281 148.39686,162.570614" fill="#1CD306" transform="translate(185.592001, 150.773120) scale(1, -1) translate(-185.592001, -150.773120) "></path> + <path d="M115.200498,191.086817 C115.200498,177.015947 120.258075,164.139813 128.642338,154.138646 C137.018157,164.139813 142.075734,177.015947 142.075734,191.086817 C142.075734,205.157688 137.018157,218.033822 128.642338,228.034989 C120.258075,218.033822 115.200498,205.157688 115.200498,191.086817" fill="#0F7504" transform="translate(128.638116, 191.086817) scale(1, -1) translate(-128.638116, -191.086817) "></path> + <path d="M34.806984,138.212768 C41.8023132,135.190043 49.5026635,133.497148 57.6082953,133.497148 C78.818032,133.497148 97.2963396,144.992791 107.293286,162.061056 C100.297956,165.083782 92.5933844,166.772455 84.4919743,166.772455 C63.2822376,166.772455 44.7997083,155.276811 34.806984,138.212768" fill="#0C5E87" transform="translate(71.050135, 150.134801) scale(1, -1) translate(-71.050135, -150.134801) "></path> + <path d="M70.6545631,114.036032 C70.5194692,112.431792 70.4054838,110.819109 70.4054838,109.176875 C70.4054838,81.862584 89.4410536,59.044386 114.956907,53.1255861 C115.087779,54.7298257 115.201765,56.3425087 115.201765,57.9805218 C115.201765,85.2948125 96.1704167,108.121454 70.6545631,114.036032" fill="#6B0001" transform="translate(92.803624, 83.580809) scale(1, -1) translate(-92.803624, -83.580809) "></path> + <path d="M76.0304545,111.503866 L67.0213825,111.503866 C59.0677312,111.503866 52.6001125,117.950377 52.6001125,125.88292 L52.6001125,207.428953 C52.6001125,215.361496 59.0677312,221.812228 67.0213825,221.812228 L179.989405,221.812228 C187.943056,221.812228 194.406453,215.361496 194.406453,207.428953 L194.406453,125.88292 C194.406453,117.950377 187.943056,111.503866 179.989405,111.503866 L141.50454,111.503866 L64.2899534,73.6522544 L76.0304545,111.503866 L76.0304545,111.503866 Z" fill="#FFFFFF" transform="translate(123.503283, 147.732241) scale(1, -1) translate(-123.503283, -147.732241) "></path> + </g> +</svg>
\ No newline at end of file diff --git a/pix/xmpp.svg b/static/pix/xmpp.svg index c9d7536..c9d7536 100644 --- a/pix/xmpp.svg +++ b/static/pix/xmpp.svg diff --git a/pix/xmr.png b/static/pix/xmr.png Binary files differindex 00cfa96..00cfa96 100644 --- a/pix/xmr.png +++ b/static/pix/xmr.png diff --git a/pix/xmr.svg b/static/pix/xmr.svg index 002ad9b..002ad9b 100644 --- a/pix/xmr.svg +++ b/static/pix/xmr.svg diff --git a/style.css b/static/style.css index 5167903..cb6e6b9 100644 --- a/style.css +++ b/static/style.css @@ -20,15 +20,16 @@ header h1 { h2 { text-align: center ; color: deeppink ; - font-variant: small-caps; font-size: 24pt ; border-bottom: dashed #ddd 1px ; max-width: 500px ; margin: 1em auto ; + clear: both ; } h3 { color: gold ; + clear: both ; } /* "a" is for links. */ @@ -51,7 +52,6 @@ dt { * but pre is for separate code blocks. pre is also sensitive to whitespace, * unlike most of HTML. */ code { - color: lime ; border-radius: 5px ; } pre { @@ -67,7 +67,15 @@ pre { .wide { max-width: inherit ; } -p img, li img, h1 img, h2 img, h3 img, h4 img, dt img { +p img, li img, h1 img, h2 img, h3 img, h4 img, dt img, .inline { + vertical-align: middle ; + max-width: 1em; + max-height: 1em; + border: none ; + display: inline ; +} + +p img, li img, h1 img, h2 img, h3 img, h4 img, dt img, .inline { vertical-align: middle ; max-width: 1em; max-height: 1em; @@ -174,15 +182,20 @@ aside.callout { line-height: 1.3em ; max-width: 600px; margin: auto ; -} - -.ll dd { - display: inline ; + display: block ; } .ll dt { display: inline-block ; width: 6em ; + background: gray ; + max-width: 30% ; +} + +.ll dd { + display: inline ; + background: blue ; + max-width: 60% ; } .ll dd:after { @@ -244,6 +257,67 @@ aside.callout { padding: 0 1em 1em 1em ; } +#servicelist { + text-align: center ; +} + .next:before { content: "👉" ; } + +#servicelist { + padding-left: 0 ; +} + +#servicelist li { + display: inline-block ; + height: 150px ; + width: 150px ; + position: relative ; +} + +#servicelist img { + height: 80% ; + width: 80% ; + max-height: none ; + max-width: none ; + position: absolute ; + left: 50% ; + transform: translateX(-50%); +} + +#servicelist .title, #servicelist li:hover .desc { + display: block ; + position: absolute ; + color: white ; + width: 100% ; + text-align: center ; + top: 50%; + transform: translateY(-50%); + border-radius: 1em ; + font-size: large ; + +} + +.left { + width: 45% ; + float: left ; + clear: both ; +} + +.right { + width: 45% ; + float: right ; +} + +#servicelist .title { + font-size: xx-large ; + background-color: rgba(3,3,3,0.6) ; +} +#servicelist li:hover .desc { + background-color: rgba(3,3,3,0.9) ; +} + +#servicelist li:hover .title, .desc, .tags { + display: none ; +} diff --git a/template.html b/template.html deleted file mode 100644 index b7485fc..0000000 --- a/template.html +++ /dev/null @@ -1,20 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title><++> – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1><++></h1></header> - <nav></nav> - <main> - <++> - <span class=next><a href="<++>">Next:<++></a></span> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/tor.html b/tor.html deleted file mode 100644 index 4135080..0000000 --- a/tor.html +++ /dev/null @@ -1,109 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Mirror your site over Tor</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Mirror Your Site Over Tor</h1></header> - <nav></nav> - <main> - - <img class=titleimg src="pix/tor.svg" alt="Tor logo"> - <p> - Now that you have a website, why not offer it on a private alternative such as the onion network? - </p> - - <h2>Setting up Tor</h2> - - <h3>Installing Tor</h3> - - <p>Firstly we need to add the Tor repos to our system to get the latest version of Tor:</p> - <pre><code>apt install -y apt-transport-https gpg -echo "deb https://deb.torproject.org/torproject.org buster main -deb-src https://deb.torproject.org/torproject.org buster main" > /etc/apt/sources.list.d/tor.list</code></pre> - - <p>Then we need to add the gpg keys to our keyring:</p> - - <pre><code>curl -s https://deb.torproject.org/torproject.org/A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89.asc | gpg --import -gpg --export A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89 | apt-key add -</code></pre> - - <p>Now update and install Tor:</p> - - <pre><code>apt update -apt install tor deb.torproject.org-keyring</code></pre> - - <h3>Enabling Tor</h3> - - <p>Next edit the file <code>/etc/tor/torrc</code>, uncommenting the following lines:</p> - <pre><code>HiddenServiceDir /var/lib/tor/hidden_service/ -HiddenServicePort 80 127.0.0.1:80</code></pre> - <aside> - <h4>Optional: Running multiple onion services</h4> - <p>If you want to forward multiple virtual ports for a single onion - service, just add more HiddenServicePort lines (replace the 80 with any unoccupied port). - </p> - <p>If you want to run multiple onion services from the same Tor client, just add another - HiddenServiceDir line.</p> - </aside> - - <p>Now start and enable Tor at boot:</p> - <pre><code> systemctl enable --now tor </code></pre> - - <p>If the next command outputs <q>active</q> in green you're golden!</p> - <pre><code> systemctl status tor</code></pre> - - <p>Now your server is on the dark web. The following command will give you your onion address:</p> - <pre><code> cat /var/lib/tor/hidden_service/hostname</code></pre> - - <h2>Adding the Nginx Config</h2> - <p> - From here, the steps are almost identical to setting up a normal website configuration file. - Follow the steps as if you were making a new website in the webserver - <a href="nginx.html">tutorial</a> up until the server block of code. Instead, paste this: - </p> - - <pre><code> server { - listen 127.0.0.1:80 ; - root /var/www/<strong>landchad</strong> ; - index index.html ; - server_name <strong>your-onion-address</strong>.onion ; - }</code></pre> - - <aside> - <h4>Clarification</h4> - <p>Nginx will listen on port 80 for your <em>server's</em> localhost.</p> - <p>The <code>root</code> line is the path to whichever website of yours you'd like to mirror.</p> - </aside> - <p> - Now we are almost done, all we have to do is enable the site and reload nginx which, is also covered in <a href="nginx.html#enable">the webserver tutorial</a>. - </p> - - <h3>Advertise your onion service</h3> - - <p>You can add the Onion-Location header to your normal website to advertise your onion service to Tor users. On your regular site's nginx config, add the following line:</p> - <pre><code>server { - ... - add_header Onion-Location http://<strong>your-onion-address</strong>.onion$request_uri; -}</code></pre> - <p>After doing this and reloading nginx, when visiting your regular site via Tor, you should see a ".onion available" button on the address bar, which should take you to the onion service.</p> - - <h3>Update regularly!</h3> - - <p>Make sure to update Tor on a regular basis by running:</p> - <pre><code>apt update -apt install tor</code></pre> - - <h4>Note:</h4> - <p>You do <u>not</u> need to run certbot for an ssl certificate. HTTP over tor is plenty secure!</p> - - <p><strong>Contributor</strong> - <a href="https://tomfasano.co" target="_blank">tomfasano.co</a></p> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/ufw.html b/ufw.html deleted file mode 100644 index 49c33f9..0000000 --- a/ufw.html +++ /dev/null @@ -1,193 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>Using UFW as a Firewall – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>Using UFW as a Firewall</h1></header> - <nav></nav> - <main> - <p> - <strong>Uncomplicated Firewall</strong> (UFW) is a front-facing program for the more involved <code>iptables</code> firewall program installed in most GNU/Linux distributions. - We can use <code>ufw</code> to restrict machines on the internet to only access the services (SSH, websites etc) you want them to, but it can also be used to prevent programs on the computer itself from accesing parts of the internet it shouldn't. - </p> - - <h2 id="how-to-get-it">How to Get It</h2> - - <p>Log into your server by pulling up a terminal and typing:</p> - - <pre><code>ssh root@<strong>example.org</strong></code></pre> - - <p> - This command will attempt to log into your server and run a remote shell. - If you leave the settings default, it should prompt you for your password, and you can just copy or type in the password from Vultr's site. - </p> - - <p> - Some VPS providers automatically install <code>ufw</code>, but if you do not have it installed already, install it in the typical way: - </p> - - <pre><code>apt install ufw</code></pre> - - <h2 id="first-time-setup">First-Time Setup</h2> - - <p>You can check the status of <code>ufw</code> right now by running:</p> - - <pre><code>ufw status</code></pre> - - <p>Without any changes, it should report back <code>Status: inactive</code>. Let's set it up so that only connections to SSH (standardized at port 22) are allowed in, and then enable the firewall:</p> - - <aside> - <strong>Careful!</strong> Enabling <code>ufw</code> without allowing SSH will block you from remoting to your server. - Double-check that you have allowed SSH, and if you have changed the default SSH port, put in <em>that</em> number instead. - </aside> - - <pre><code>ufw default deny incoming # block all incoming connections by default -ufw allow in ssh # or: ufw allow in 22 -ufw enable</code></pre> - - <aside> - <code>ufw</code> has an internal list of protocols applications, and the ports used by them. - In this case, it knows SSH is on port 22. - We'll go more in detail how to view all protocols <code>ufw</code> knows about. - By default, when you allow an incoming port, it allows that port both on IPv4 and IPv6. - </aside> - - <p> - With the firewall enabled and allowing only SSH in, all other ports are prortected from incoming requests. - To view all your rules, run: - </p> - - <pre><code>ufw status verbose</code></pre> - - <p>A firewall that allows to connect to SSH and their website may look like:</p> - - <pre><code>Status: active -Logging: on (low) -Default: deny (incoming), allow (outgoing), deny (routed) -New profiles: skip - -To Action From --- ------ ---- -22 (SSH) ALLOW IN Anywhere -80,443/tcp (WWW Full) ALLOW IN Anywhere -22 (SSH (v6)) ALLOW IN Anywhere (v6) -80,443/tcp (WWW Full (v6)) ALLOW IN Anywhere (v6)</code></pre> - - <p>If you want to delete e.g. the 'WWW Full' rule, run:</p> - - <pre><code>ufw delete allow in 'WWW Full' -ufw reload</pre></code> - - <h2 id="enabling-common-services">Enabling Common Services</h2> - - <p> - You have blocked all incoming ports but SSH, which means no outsiders would be able to access other services, like an email server or your website. - You should look at the ports your services are open on and enable them individually. - Here is a list of a few common services: - </p> - - <h3>Opening Port Numbers</h3> - - <p>Suppose you install <a href="gemini.html">a Gemini server</a>, which must broadcast on port 1965. By default <code>ufw</code> blocks all incoming connections on all ports, so whenever you install a new service like this you will have to tell <code>ufw</code> to enable the desired port:</p> - - <pre><code>ufw allow 1985</code></pre> - - <h3>Websites: HTTP and HTTPS</h3> - - <p>HTTP uses port 80 and HTTPS uses port 443. We can enable them like this:</p> - - <pre><code>ufw allow 80 -ufw allow 443</code></pre> - - <p>But <code>ufw</code> additionally knows the typical ports of common serives, so you can also run this:</p> - - <pre><code>ufw allow http -ufw allow https</code></pre> - - <p>And that will do the same thing. There are also other abbreviations for common port lists:</p> - - <pre><code>ufw allow in 'WWW Full'</code></pre> - - - <p>To see these other "apps" that <code>ufw</code> knows by default, run <code>ufw app list</code></p> - - - <h3>Email: IMAP, POP3, and SMTP</h3> - - <pre><code>ufw allow in IMAPS -ufw allow in POP3 -ufw allow in SMTP -ufw allow in 'Postfix SMTPS' -ufw allow in 'Mail Submission'</pre></code> - - <h2 id="fine-tuning-rules">Fine-Tuning Rules</h2> - - <p>Instead of denying all ports by default, you may want to deny (ignores incoming requests) or reject (explicitly tells requests they're not allowed):</p> - - <pre><code>ufw default allow in -ufw deny in <strong>PORT</strong> -ufw reject in <strong>PORT</strong> -ufw reload</code></pre> - - <p>You can add rules to comments to remember what they are there for:</p> - - <pre><code>ufw allow in <strong>PORT</strong> comment 'Secret SSH' -ufw reload -ufw status verbose</code></pre> - - <p>Output:</p> - - <pre><code>To Action From --- ------ ---- -<strong>PORT</strong> ALLOW IN Anywhere # Secret SSH -<strong>PORT</strong> (v6) ALLOW IN Anywhere (v6) # Secret SSH</pre></code> - - <p>To deny outgoing ports:</p> - - <pre><code>ufw deny out <strong>PORT</strong></code></pre> - - <p>Ratelimiting is useful to protect against brute-force login attacks, like in SSH. Only IPv4 is supported for now. Enable it by running:</p> - - <pre><code>ufw limit <strong>PORT</strong>/tcp</code></pre> - - <p>To blocklist IP addresses:</p> - - <pre><code>ufw deny from <strong>IP_ADDRESS</strong></code></pre> - - <p>To read more what you can do with <code>ufw</code>, run:</p> - - <pre><code>man ufw</code></pre> - - <h2 id="recovering-from-losing-ssh">Recovering SSH</h2> - - <p> - If you have accidentally firewalled yourself from logging on your computer, you can recover access by using your VPS's virtual console. - On Vultr, this is on your VPS's menu. To the right of the server name, It is the leftmost icon that looks like a monitor. - </p> - - <a href="pix/ssh-01.png"><img src="pix/ssh-01.png" alt="View Console"></a> - - <p>Log in through there, and disable ufw by typing:</p> - - <pre><code>ufw disable</code></pre> - - - <h2 id="further-reading">Further Reading</h2> - - <ul> - <li><a href="https://wiki.ubuntu.com/UncomplicatedFirewall">Ubuntu Wiki: UncomplicatedFirewall</a></li> - <li><a href="https://help.ubuntu.com/community/Gufw">Gufw (Graphical UFW)</a></li> - <li><code>man ufw</code></li> - </ul> - - <strong>Contributor</strong> - <a href="https://shunter.xyz">shunter.xyz</a> - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> diff --git a/xmpp.html b/xmpp.html deleted file mode 100644 index e3f9b69..0000000 --- a/xmpp.html +++ /dev/null @@ -1,210 +0,0 @@ -<!DOCTYPE html> -<html lang=en> - <head> - <title>XMPP Server (Prosody) – LandChad.net</title> - <meta charset="utf-8"/> - <link rel="shortcut icon" href="favicon.ico" type="image/x-icon" /> - <link rel='stylesheet' type='text/css' href='style.css'> - <meta name="viewport" content="width=device-width, initial-scale=1"> - <link rel='alternate' type='application/rss+xml' title='Land Chad RSS' href='/rss.xml'> - </head> -<body> - <header><h1>XMPP Server (Prosody)</h1></header> - <nav></nav> - <main> - - <img class=titleimg src="pix/xmpp.svg" alt="XMPP Logo and Icon"> - - <p>XMPP is a fantastically simple protocol that's usually used as a messenger. - It's highly extensible, - better than IRC, - lighter and more decentralized and Matrix - and Telegram and normie social media can't hold a candle to it. - </p> - - <p> - XMPP is so decentralized and extensible that there are many <em>different</em> XMPP servers. - Here, let's set up an <a href="https://prosody.im/">Prosody</a> XMPP server. - </p> - - <h2>Installation</h2> - - <p> - Prosody is in the Debian repositories, so we can easily install it on our server with the following command: - </p> - - <pre><code>apt install prosody</code></pre> - - -<h2>Configuration</h2> - -<p> -The Prosody configuration file is in <code>/etc/prosody/prosody.cfg.lua</code>. -To set it all up, we will be changing several things. -</p> - -<h3>Setting Admins</h3> - -<p> -Let's go ahead and set who our admin(s) will be. -Find the line that says <code>admins = { }</code> and to this we can specify one or more server admins. -</p> - -<pre><code># To add one admin: -admins = { "<strong>chad@example.org</strong>" } - -# We can add more than one by separating them by commas. (This file is written in Lua.) -admins = { "<strong>chad@example.org</strong>", "<strong>chadmin@example.org</strong>" }</code></pre> - -<p> -Note that we have not created these accounts yet, we will do this <a href=#user>below</a>. -</p> - -<h3>Set the Server URL</h3> - -<p> -Find the line <code>VirtualHost "localhost"</code> and replace <code>localhost</code> with your domain. -In our case, we will have <code>VirtualHost "example.org"</code> -</p> - -<h3>Multi-User Chats</h3> - -<p> -Most people will probably want the ability to have chats with more than two users. -This is easily enough to enable. -In the config file, add the following: -</p> - -<pre><code>Component "<strong>chat.example.org</strong>" "muc" - modules_enabled = { "muc_mam" } - restrict_room_creation = "admin"</code></pre> - -<p> -On the first line, you must have a separate subdomain for your multi-user chats. -I use the <code>chat.</code> subdomain, but some use <code>muc.</code>. -Anything if possible. -</p> - -<p> -The second line is important because it prevents non-admins from creating and squatting rooms on your server. -The only situation where you might not want that is if you indend to open a general public chat system for people you don't know. -</p> - -<aside> -<p> -Read more about the <code>muc</code> plugin on the Prosody documentation page <a href="https://prosody.im/doc/modules/mod_muc">here</a>. -</p> -</aside> - -<h3>Enabling chat histories</h3> - -<p> -By default, Prosody will send out messages received only to the first available clients. -That means that if you have your desktop client turned off and your cell phone receives a message, it will <em>not</em> be available to the desktop client when you start it. -</p> - -<p>While this may be preferred in some cases, enable the MAM module (Message Archive Management) to have the server hold on messages and sync them to all clients.</p> - -<p> -Within the <code>modules_enabled</code> block, you can uncomment the <code>mam</code> line to enable it. -You can see other settings for this module <a href="https://prosody.im/doc/modules/mod_mam">here</a> like, for example, how long a server should hold on to message histories for synching. -</p> - -<p> -Note also that Prosody comes with the <code>carbons</code> activated module by default, which is related. This will send received messages to <em>all</em> active clients (your phone and desktop), although it will not save messages like MAM for clients not online or to be added later. -</p> - -<h3>Other things to check</h3> - -<p>Check the config file for other settings you might want to change. -For example, if you want to run a general public XMPP server, you can allow anyone to create an account by changing <code>allow_registration</code> to <code>true</code>. -</p> - -<h2>Certificates</h2> - -<p> -Obviously, we want to have client-to-server and server-to-server encryption. -Nowadays, use can use Certbot to generate certificates and use a convenient command below <code>prosodyctl</code> to import them. -</p> - -<p> -<strong>If you have multi-user chat enabled, be sure to get a certificate for that subdomain as well.</strong> -Include the <code>--nginx</code> option assuming you have an Nginx server running. -</p> - -<pre><code>certbot -d <strong>chat.example.org</strong> --nginx</code></pre> - -<p> -Once you have the certificates for encryption, run the following to import them into Prosody. -</p> - -<pre><code>prosodyctl --root cert import /etc/letsencrypt/live/</code></pre> - -<p> -Note that you might get an error that a certificate has not been found if your <code>muc</code> subdomain and your main domain share a certificate. -It should still work, this is just notifying you that no specific -</p> - - -<p> -For user privacy, we will definitely want to install and enable encryption with OMEMO. -</p> - -<h2 id=user>Creating users/admins manually</h2> - -<p> -Let's manually create the admin user we prepared for above. -Note that you can indeed do this in your XMPP client if you have not disabled registration, but this is how it is done on the command line: -</p> - -<pre><code>prosodyctl adduser <strong>chad@example.org</strong></code></pre> - -<p>This will prompt you to create a password as well.</p> - - -<h2>Make changes active</h2> - -<p> -With any system service, use <code>systemctl reload</code> or <code>systemctl restart</code> to make the new settings active: -</p> - -<pre><code>systemctl restart prosody</code></pre> - -<h2>Using your Server!</h2> - -<p> -Once your server is set up, you just need an XMPP client to use your new and secure chat system. -</p> - -<ul> - <li>GNU/Linux: <a href="https://dino.im/">Dino</a> or <a href="https://gajim.org/">Gajim</a></li> - <li>Windows: <a href="https://gajim.org/">Gajim</a> also runs on Windows.</li> - <li>Android: <a href="https://conversations.im/">Conversations.im</a></li> - <li>Mac/iOS: <a href="https://monal.im/">Monal IM</a> or <a href="https://siskin.im/">Siskin</a> for iOS alone</li> - <li>command-line (GNU/Linux, MacOS, Windows): <a href="https://profanity-im.github.io/">Profanity</a></li> - <li><a href="https://xmpp.org/software/clients.html">See a more complete list kept by XMPP</a></li> -</ul> - -<p> -Install whichever of these clients you want on your computer or phone and you can log into your new XMPP server with the account you made. -Note that if you enabled public registration, anyone can create an account on your server through one of these clients. -</p> - -<h3>Account addresses</h3> - -<p> -XMPP account addressed look just like email addresses: <code><strong>username@example.org</strong></code>. -You can message any account on any XMPP server on the internet with that format. -</p> - -<h3>Note on MUCs (multi-user chats)</h3> - -<p> -Remember that MUCs are kept on a separate subdomain that we created and should've gotten a certificate for above, for example, <code><strong>chat.example.org</strong></code>. -Chatrooms are created and referred to in the following format: <code><strong>#chatroomname@chat.example.org</strong></code>. -</p> - - </main> - <footer><a href="https://landchad.net">LandChad.net</a></br>Because Everyone should be an Internet LandChad.</br><a href="index.html"><li><img src="pix/chad.gif" alt="chad"></li></a><a href="rss.xml"><li><img src="pix/rss.svg" alt="RSS"></li></a><a href="donate-bitcoin.html"><li><img src="pix/btc.svg" alt="BTC"></li></a><a href="donate-monero.html"><li><img src="pix/xmr.svg" alt="XMR"></li></a><a href="https://github.com/lukesmithxyz/landchad"><li><img src="pix/git.svg" alt="Github"></li></a></footer> -</body> -</html> |
