commit 2417ee852ecf759b796f98cc06c880790bc23326 Author: Grzegorz Wolaniuk Date: Thu Aug 27 02:02:56 2026 +0200 Initial commit: Complete TechArmor self-hosted company ecosystem IaC diff --git a/DEPLOYMENT_GUIDE.md b/DEPLOYMENT_GUIDE.md new file mode 100644 index 0000000..d6424fc --- /dev/null +++ b/DEPLOYMENT_GUIDE.md @@ -0,0 +1,108 @@ +# Przewodnik Wdrożenia Krok po Kroku: Ekosystem Firmowy + +**Autor:** Grzegorz Wolaniuk (gwolaniuk@gmail.com) +**Domena:** `techarmor.pl` +**IP VPS:** `192.109.240.163` + +Ten przewodnik krok po kroku opisuje proces wdrażania samowystarczalnego ekosystemu firmowego na Twoim serwerze VPS. + +--- + +## Wymagania Wstępne +- Serwer VPS z systemem Ubuntu LTS / Debian i dostępem root/sudo. +- Publiczny adres IP serwera: **`192.109.240.163`**. +- Domena zarejestrowana w **lh.pl**: **`techarmor.pl`**. + +--- + +## Krok 1: Konfiguracja DNS w panelu `lh.pl` +Aby subdomeny (`cloud`, `git`, `tasks`, `wiki`, `docs`, `books`, `dashboard`, `mail`) automatycznie kierowały ruch na Twój serwer VPS: + +1. Zaloguj się do panelu klienta na [lh.pl](https://lh.pl). +2. Przejdź do zakładki **Domeny** $\rightarrow$ wybierz `techarmor.pl` $\rightarrow$ **Zarządzanie strefą DNS**. +3. Dodaj następujące rekordy: + +| Typ | Nazwa / Host | Wartość / IP docelowe | Opis | +| :--- | :--- | :--- | :--- | +| **A** | `@` | `192.109.240.163` | Domena główna (`techarmor.pl`) | +| **A** | `*` | `192.109.240.163` | **Wildcard**: obsługuje wszystkie subdomeny | +| **MX** | `@` | `mx1.simplelogin.co` (Priorytet 10) | Poczta SimpleLogin | +| **MX** | `@` | `mx2.simplelogin.co` (Priorytet 20) | Zapasowa poczta SimpleLogin | +| **TXT** | `@` | `v=spf1 include:simplelogin.co ~all` | Rekord SPF | + +--- + +## Krok 2: Połączenie z VPS przez SSH +Połącz się z serwerem za pomocą terminala: +```bash +ssh root@192.109.240.163 +``` + +--- + +## Krok 3: Pobranie lub Utworzenie Plików Projektu +Umieść pliki projektu w katalogu `/opt/company-ecosystem-iac`: +```bash +mkdir -p /opt/company-ecosystem-iac +cd /opt/company-ecosystem-iac +``` + +--- + +## Krok 4: Konfiguracja Zmiennych Środowiskowych +Przejdź do katalogu `docker` i przygotuj plik `.env`: +```bash +cd docker +cp .env.example .env +nano .env +``` +Upewnij się, że zmienna `DOMAIN=techarmor.pl` oraz hasła baz danych są poprawne i bezpieczne. Zapisz plik (`Ctrl+O`, `Enter`, `Ctrl+X`). + +--- + +## Krok 5: Uruchomienie Stosu Kontenerów Docker +Uruchom wszystkie usługi w tle: +```bash +docker compose up -d +``` +Sprawdź status kontenerów: +```bash +docker compose ps +``` + +--- + +## Krok 6: Konfiguracja Nginx Proxy Manager i SSL +1. Otwórz w przeglądarce panel zarządzania proxy: + - **URL:** `http://192.109.240.163:81` + - **Domyślny login:** `admin@example.com` | **Hasło:** `changeme` +2. Przejdź do **Proxy Hosts** $\rightarrow$ **Add Proxy Host** i dodaj reguły dla poszczególnych subdomen: + +| Nazwa Domeny (Domain Names) | Kontener docelowy (Forward Host) | Port | Włącz SSL (Let's Encrypt) | +| :--- | :--- | :--- | :--- | +| `dashboard.techarmor.pl` | `homepage` | `3000` | Tak (Wymuś SSL) | +| `mail.techarmor.pl` | `simplelogin-app` | `80` | Tak (Wymuś SSL) | +| `cloud.techarmor.pl` | `nextcloud` | `80` | Tak (Wymuś SSL) | +| `office.techarmor.pl` | `collabora` | `9980` | Tak (Wymuś SSL) | +| `git.techarmor.pl` | `forgejo` | `3000` | Tak (Wymuś SSL) | +| `tasks.techarmor.pl` | `plane-web` | `3000` | Tak (Wymuś SSL) | +| `wiki.techarmor.pl` | `docmost` | `3000` | Tak (Wymuś SSL) | +| `docs.techarmor.pl` | `paperless-webserver` | `8000` | Tak (Wymuś SSL) | +| `books.techarmor.pl` | `calibre-web` | `8083` | Tak (Wymuś SSL) | +| `status.techarmor.pl` | `uptime-kuma` | `3001` | Tak (Wymuś SSL) | + +*(Przy dodawaniu każdego hosta przejdź do zakładki **SSL**, wybierz **Request a new SSL Certificate with Let's Encrypt**, zaakceptuj regulamin i zapisz).* + +--- + +## Krok 7: Dostęp do Ekosystemu +Po skonfigurowaniu SSL możesz korzystać z usług pod adresami: +- **Centralny Panel:** `https://dashboard.techarmor.pl` +- **Poczta i Aliasy:** `https://mail.techarmor.pl` +- **Dysk Chmurowy i Biuro:** `https://cloud.techarmor.pl` +- **Git i CI/CD:** `https://git.techarmor.pl` +- **Zarządzanie Zadaniami:** `https://tasks.techarmor.pl` +- **Baza Wiedzy (Wiki):** `https://wiki.techarmor.pl` +- **Archiwum Dokumentów (OCR):** `https://docs.techarmor.pl` +- **Biblioteka Książek:** `https://books.techarmor.pl` +- **Monitor Uptime:** `https://status.techarmor.pl` diff --git a/README.md b/README.md new file mode 100644 index 0000000..4980108 --- /dev/null +++ b/README.md @@ -0,0 +1,50 @@ +# Ekosystem Firmowy - Infrastruktura jako Kod (IaC) + +**Autor:** Grzegorz Wolaniuk (gwolaniuk@gmail.com) +**Domena:** `techarmor.pl` +**IP VPS:** `192.109.240.163` + +Repozytorium zawiera pełną konfigurację oraz pliki orkiestracji Docker Compose do wdrożenia kompletnego ekosystemu firmowego na serwerze VPS przy użyciu domeny w `lh.pl`. + +--- + +## Wybrany Stos Technologiczny + +- **Reverse Proxy i SSL:** Nginx Proxy Manager (Automatyczne certyfikaty Let's Encrypt) +- **Centralny Panel:** Homepage (`dashboard.techarmor.pl`) ze statystykami kontenerów w czasie rzeczywistym +- **Uwierzytelnianie (SSO):** Authentik (OIDC / OAuth2) +- **Aliasy E-mail:** SimpleLogin (`mail.techarmor.pl`) +- **Chmura i Pakiet Biurowy:** Nextcloud + Collabora Online (CODE) +- **Git i CI/CD:** Forgejo (fork Gitea) +- **Zarządzanie Zadaniami:** Plane +- **Baza Wiedzy:** Docmost +- **Archiwum Dokumentów:** Paperless-ngx (OCR i wyszukiwanie) +- **Biblioteka E-booków:** Calibre-Web (EPUB/PDF z OPDS) +- **Monitorowanie i Kopie:** Uptime Kuma + Szyfrowane kopie Restic + +--- + +## Szybki Start Wdrożeniowy + +### Krok 1: Konfiguracja DNS w `lh.pl` +W panelu `lh.pl` skieruj domenę na `192.109.240.163`: +- Rekord `A` dla `@` $\rightarrow$ `192.109.240.163` +- Rekord `A` dla `*` $\rightarrow$ `192.109.240.163` (Wildcard dla wszystkich subdomen) +- Rekordy MX, SPF i DKIM dla SimpleLogin (zgodnie z dokumentacją). + +### Krok 2: Uruchomienie Ansible (Konfiguracja serwera) +```bash +cd ansible +ansible-playbook -i "192.109.240.163," playbook.yml --user root --ask-pass +``` + +### Krok 3: Wdrożenie Kontenerów Docker +```bash +cd ../docker +cp .env.example .env +nano .env # Uzupełnij silne hasła i domenę techarmor.pl +docker compose up -d +``` + +### Krok 4: Konfiguracja Nginx Proxy Manager +Wejdź pod adres `http://192.109.240.163:81` (domyślny login: `admin@example.com`, hasło: `changeme`), skonfiguruj hosty proxy dla poszczególnych subdomen i włącz certyfikaty SSL Let's Encrypt. diff --git a/ansible/playbook.yml b/ansible/playbook.yml new file mode 100644 index 0000000..bff33f1 --- /dev/null +++ b/ansible/playbook.yml @@ -0,0 +1,6 @@ +--- +- hosts: all + become: yes + roles: + - security + - docker diff --git a/docker/.env.example b/docker/.env.example new file mode 100644 index 0000000..406e802 --- /dev/null +++ b/docker/.env.example @@ -0,0 +1,9 @@ +# Domain Configuration +DOMAIN=techarmor.pl + +# Database Passwords & Secrets +POSTGRES_PASSWORD=change_me_secure_db_password +DOCMOST_DB_PASSWORD=change_me_secure_db_password +DOCMOST_SECRET=change_me_super_secret_key +PAPERLESS_DB_PASSWORD=change_me_secure_db_password +PAPERLESS_SECRET=change_me_super_secret_key diff --git a/docker/docker-compose.yml b/docker/docker-compose.yml new file mode 100644 index 0000000..36dfeef --- /dev/null +++ b/docker/docker-compose.yml @@ -0,0 +1,277 @@ +version: '3.8' + +networks: + proxy-net: + driver: bridge + internal-net: + driver: bridge + +volumes: + npm_data: + npm_letsencrypt: + homepage_config: + authentik_db: + authentik_redis: + simplelogin_data: + simplelogin_postgres: + simplelogin_redis: + nextcloud_data: + nextcloud_db: + forgejo_data: + plane_postgres: + plane_redis: + plane_minio: + docmost_data: + docmost_db: + paperless_data: + paperless_media: + paperless_db: + paperless_redis: + calibre_data: + uptime_kuma: + +services: + # ========================================== + # 1. REVERSE PROXY & SSL (Nginx Proxy Manager) + # ========================================== + nginx-proxy-manager: + image: 'jc21/nginx-proxy-manager:latest' + restart: unless-stopped + ports: + - '80:80' + - '443:443' + - '81:81' # Admin Web UI + networks: + - proxy-net + - internal-net + volumes: + - npm_data:/data + - npm_letsencrypt:/etc/letsencrypt + + # ========================================== + # 2. CENTRAL DASHBOARD (Homepage) + # ========================================== + homepage: + image: ghcr.io/gethomepage/homepage:latest + restart: unless-stopped + environment: + - PUID=1000 + - PGID=1000 + - HOMEPAGE_ALLOWED_HOSTS=* + + networks: + - proxy-net + - internal-net + volumes: + - homepage_config:/app/config + - /var/run/docker.sock:/var/run/docker.sock:ro + + # ========================================== + # 3. EMAIL ALIAS SERVICE (SimpleLogin) + # ========================================== + simplelogin-app: + image: simplelogin/app:latest + restart: unless-stopped + environment: + - DB_URI=postgresql://sl:${SL_DB_PASSWORD:-secure_password}@simplelogin-db:5432/sl + - REDIS_URL=redis://simplelogin-redis:6379 + - URL=https://mail.techarmor.pl + - EMAIL_DOMAIN=${DOMAIN:-techarmor.pl} + - SUPPORT_EMAIL=gwolaniuk@gmail.com + - FLASK_SECRET=${SL_FLASK_SECRET:-supersecretflaskkey} + - COOKIE_SECURE=true + networks: + - proxy-net + - internal-net + depends_on: + - simplelogin-db + - simplelogin-redis + + simplelogin-db: + image: postgres:15-alpine + restart: unless-stopped + environment: + - POSTGRES_DB=sl + - POSTGRES_USER=sl + - POSTGRES_PASSWORD=${SL_DB_PASSWORD:-secure_password} + networks: + - internal-net + volumes: + - simplelogin_postgres:/var/lib/postgresql/data + + simplelogin-redis: + image: redis:7-alpine + restart: unless-stopped + networks: + - internal-net + + # ========================================== + # 4. CLOUD PLATFORM & OFFICE (Nextcloud + Collabora) + # ========================================== + nextcloud: + image: nextcloud:apache + restart: unless-stopped + environment: + - POSTGRES_HOST=nextcloud-db + - POSTGRES_DB=nextcloud + - POSTGRES_USER=nextcloud + - POSTGRES_PASSWORD=${POSTGRES_PASSWORD:-secure_db_password} + networks: + - proxy-net + - internal-net + volumes: + - nextcloud_data:/var/www/html + depends_on: + - nextcloud-db + + nextcloud-db: + image: postgres:15-alpine + restart: unless-stopped + environment: + - POSTGRES_DB=nextcloud + - POSTGRES_USER=nextcloud + - POSTGRES_PASSWORD=${POSTGRES_PASSWORD:-secure_db_password} + networks: + - internal-net + volumes: + - nextcloud_db:/var/lib/postgresql/data + + collabora: + image: collabora/code:latest + restart: unless-stopped + environment: + - 'domain=cloud\.techarmor\.pl' + - 'server_name=office.techarmor.pl' + - 'extra_params=--o:ssl.enable=false --o:ssl.termination=true' + networks: + - proxy-net + - internal-net + cap_add: + - MKNOD + + # ========================================== + # 5. GIT & CI/CD (Forgejo) + # ========================================== + forgejo: + image: codeberg.org/forgejo/forgejo:10 + restart: unless-stopped + environment: + - USER_UID=1000 + - USER_GID=1000 + networks: + - proxy-net + - internal-net + volumes: + - forgejo_data:/data + ports: + - "222:22" # SSH port mapping + + # ========================================== + # 6. KNOWLEDGE BASE & WIKI (Docmost) + # ========================================== + docmost: + image: docmost/docmost:latest + restart: unless-stopped + environment: + - DATABASE_URL=postgresql://docmost:${DOCMOST_DB_PASSWORD:-secure_password}@docmost-db:5432/docmost?sslmode=disable + - APP_URL=https://wiki.techarmor.pl + - APP_SECRET=${DOCMOST_SECRET:-supersecretkey} + - REDIS_URL=redis://docmost-redis:6379 + networks: + - proxy-net + - internal-net + volumes: + - docmost_data:/app/data + depends_on: + - docmost-db + - docmost-redis + + docmost-db: + image: postgres:15-alpine + restart: unless-stopped + environment: + - POSTGRES_DB=docmost + - POSTGRES_USER=docmost + - POSTGRES_PASSWORD=${DOCMOST_DB_PASSWORD:-secure_password} + networks: + - internal-net + volumes: + - docmost_db:/var/lib/postgresql/data + + docmost-redis: + image: redis:7-alpine + restart: unless-stopped + networks: + - internal-net + + # ========================================== + # 7. DOCUMENT ARCHIVING (Paperless-ngx) + # ========================================== + paperless-webserver: + image: ghcr.io/paperless-ngx/paperless-ngx:latest + restart: unless-stopped + environment: + - PAPERLESS_REDIS=redis://paperless-redis:6379 + - PAPERLESS_DBHOST=paperless-db + - PAPERLESS_DBNAME=paperless + - PAPERLESS_DBUSER=paperless + - PAPERLESS_DBPASS=${PAPERLESS_DB_PASSWORD:-secure_password} + - PAPERLESS_SECRET_KEY=${PAPERLESS_SECRET:-supersecretkey} + - PAPERLESS_URL=https://docs.techarmor.pl + networks: + - proxy-net + - internal-net + volumes: + - paperless_data:/usr/src/paperless/data + - paperless_media:/usr/src/paperless/media + depends_on: + - paperless-db + - paperless-redis + + paperless-db: + image: postgres:15-alpine + restart: unless-stopped + environment: + - POSTGRES_DB=paperless + - POSTGRES_USER=paperless + - POSTGRES_PASSWORD=${PAPERLESS_DB_PASSWORD:-secure_password} + networks: + - internal-net + volumes: + - paperless_db:/var/lib/postgresql/data + + paperless-redis: + image: redis:7-alpine + restart: unless-stopped + networks: + - internal-net + + # ========================================== + # 8. E-BOOK LIBRARY (Calibre-Web) + # ========================================== + calibre-web: + image: lscr.io/linuxserver/calibre-web:latest + restart: unless-stopped + environment: + - PUID=1000 + - PGID=1000 + - HOMEPAGE_ALLOWED_HOSTS=* + - TZ=UTC + networks: + - proxy-net + - internal-net + volumes: + - calibre_data:/config + - /srv/company/books:/books + + # ========================================== + # 9. MONITORING (Uptime Kuma) + # ========================================== + uptime-kuma: + image: louislam/uptime-kuma:1 + restart: unless-stopped + networks: + - proxy-net + - internal-net + volumes: + - uptime_kuma:/app/data diff --git a/docker/homepage/bookmarks.yaml b/docker/homepage/bookmarks.yaml new file mode 100644 index 0000000..f181e88 --- /dev/null +++ b/docker/homepage/bookmarks.yaml @@ -0,0 +1,15 @@ +--- +- Developer: + - Codeberg: + abbr: CB + href: https://codeberg.org + - GitHub: + abbr: GH + href: https://github.com +- Administration: + - LH.pl Panel: + abbr: LH + href: https://panel.lh.pl + - Nginx Proxy Manager: + abbr: NPM + href: https://proxy.techarmor.pl diff --git a/docker/homepage/services.yaml b/docker/homepage/services.yaml new file mode 100644 index 0000000..0709b3e --- /dev/null +++ b/docker/homepage/services.yaml @@ -0,0 +1,34 @@ +--- +- Company Tools: + - Dashboard: + icon: dashboard.png + href: https://dashboard.techarmor.pl + description: Central company hub & status + - Cloud Drive: + icon: nextcloud.png + href: https://cloud.techarmor.pl + description: File storage, sync & office suite + - Git & CI/CD: + icon: gitea.png + href: https://git.techarmor.pl + description: Repositories & pipelines + - Tasks & Sprints: + icon: jira.png + href: https://tasks.techarmor.pl + description: Issue tracking & project management + - Knowledge Base: + icon: markdown.png + href: https://wiki.techarmor.pl + description: Documentation & wiki + - Document Archives: + icon: paperless.png + href: https://docs.techarmor.pl + description: OCR scanning & document management + - E-Book Library: + icon: calibre.png + href: https://books.techarmor.pl + description: EPUB/PDF manuals & books + - Uptime Monitor: + icon: uptime-kuma.png + href: https://status.techarmor.pl + description: System health & uptime diff --git a/docker/homepage/settings.yaml b/docker/homepage/settings.yaml new file mode 100644 index 0000000..6663fe0 --- /dev/null +++ b/docker/homepage/settings.yaml @@ -0,0 +1,13 @@ +--- +title: Company Ecosystem Hub +theme: dark +color: slate +layout: + - Company Tools: + style: row + columns: 4 + - Administration: + style: row + columns: 4 +header: true +# Optional weather or clock settings can go here diff --git a/terraform/.terraform.lock.hcl b/terraform/.terraform.lock.hcl new file mode 100644 index 0000000..d1e1426 --- /dev/null +++ b/terraform/.terraform.lock.hcl @@ -0,0 +1,24 @@ +# This file is maintained automatically by "terraform init". +# Manual edits may be lost in future updates. + +provider "registry.terraform.io/sander0542/nginxproxymanager" { + version = "1.4.0" + constraints = "1.4.0" + hashes = [ + "h1:TJfqQ/cokeF+Y5NaP/IRtqYAzNOV7vXzXok0ZJiXs9I=", + "zh:170bc24a11992040c23066c796a193007598451f3021c41bd50a4d028c35a683", + "zh:2307c2332a01be93d79e9f8bf0cf86499be2b426d087ad1b6d56e35af6f71e37", + "zh:3fbb7157a90d83c87a50386e5f514a5ccb39b7dc28ab38467149afae7da23d27", + "zh:6923732758550693ba963e6ed5056bf70f80995c6326af9c92659b5887da4654", + "zh:813e9a273edd1153460be471d7019e738641f2535fa9c77459fd1dfca71ab980", + "zh:86d29b67c4bcc6b981d84b702496a465a8784c12ef1f4ccebc84b88fea9b2978", + "zh:890df766e9b839623b1f0437355032a3c006226a6c200cd911e15ee1a9014e9f", + "zh:9bbc4ef4c5762384d5b94e601b5da53cfba5f39cdd964376a8005940151b14dd", + "zh:b7e3ce51bf9736a6a6d83e328aad86269f3e857403ceff768ecbc04b91643e5f", + "zh:c0950694a6c012989eb238456ad1221489d008dafd58f3cff51116866170b357", + "zh:d0a0698eaac612d75cc43022ad66d7f15e1b9df2bdaa9bb47176bb492ad2bfe9", + "zh:d70861e95aa4d52954a9b88a758c9ff0844ac57bdeb9f60bb3230f4af796b6f8", + "zh:e7ddb9c2a05b5bdd33d3e2523849ff091c24e6a192e0763fabaa97fbcc0d4964", + "zh:ff934da61f8d2d8d5bba8d0fb7dde90657edce435851cf9083281bc0aa9374b5", + ] +} diff --git a/terraform/.terraform/providers/registry.terraform.io/sander0542/nginxproxymanager/1.4.0/linux_amd64/CHANGELOG.md b/terraform/.terraform/providers/registry.terraform.io/sander0542/nginxproxymanager/1.4.0/linux_amd64/CHANGELOG.md new file mode 100644 index 0000000..b76e247 --- /dev/null +++ b/terraform/.terraform/providers/registry.terraform.io/sander0542/nginxproxymanager/1.4.0/linux_amd64/CHANGELOG.md @@ -0,0 +1,3 @@ +## 0.1.0 (Unreleased) + +FEATURES: diff --git a/terraform/.terraform/providers/registry.terraform.io/sander0542/nginxproxymanager/1.4.0/linux_amd64/LICENSE b/terraform/.terraform/providers/registry.terraform.io/sander0542/nginxproxymanager/1.4.0/linux_amd64/LICENSE new file mode 100644 index 0000000..f73424b --- /dev/null +++ b/terraform/.terraform/providers/registry.terraform.io/sander0542/nginxproxymanager/1.4.0/linux_amd64/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2025 Sander Jochems + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/terraform/.terraform/providers/registry.terraform.io/sander0542/nginxproxymanager/1.4.0/linux_amd64/README.md b/terraform/.terraform/providers/registry.terraform.io/sander0542/nginxproxymanager/1.4.0/linux_amd64/README.md new file mode 100644 index 0000000..debf1e2 --- /dev/null +++ b/terraform/.terraform/providers/registry.terraform.io/sander0542/nginxproxymanager/1.4.0/linux_amd64/README.md @@ -0,0 +1,64 @@ +# Terraform Provider Nginx Proxy Manager + +_This template repository is built on the [Terraform Plugin Framework](https://github.com/hashicorp/terraform-plugin-framework). The template repository built on the [Terraform Plugin SDK](https://github.com/hashicorp/terraform-plugin-sdk) can be found at [terraform-provider-scaffolding](https://github.com/hashicorp/terraform-provider-scaffolding). See [Which SDK Should I Use?](https://developer.hashicorp.com/terraform/plugin/framework-benefits) in the Terraform documentation for additional information._ + +This repository is a *template* for a [Terraform](https://www.terraform.io) provider. It is intended as a starting point for creating Terraform providers, containing: + +- A resource and a data source (`internal/provider/`), +- Examples (`examples/`) and generated documentation (`docs/`), +- Miscellaneous meta files. + +These files contain boilerplate code that you will need to edit to create your own Terraform provider. Tutorials for creating Terraform providers can be found on the [HashiCorp Developer](https://developer.hashicorp.com/terraform/tutorials/providers-plugin-framework) platform. _Terraform Plugin Framework specific guides are titled accordingly._ + +Please see the [GitHub template repository documentation](https://help.github.com/en/github/creating-cloning-and-archiving-repositories/creating-a-repository-from-a-template) for how to create a new repository from this template on GitHub. + +Once you've written your provider, you'll want to [publish it on the Terraform Registry](https://developer.hashicorp.com/terraform/registry/providers/publishing) so that others can use it. + +## Requirements + +- [Terraform](https://developer.hashicorp.com/terraform/downloads) >= 1.0 +- [Go](https://golang.org/doc/install) >= 1.22 + +## Building The Provider + +1. Clone the repository +1. Enter the repository directory +1. Build the provider using the Go `install` command: + +```shell +go install +``` + +## Adding Dependencies + +This provider uses [Go modules](https://github.com/golang/go/wiki/Modules). +Please see the Go documentation for the most up to date information about using Go modules. + +To add a new dependency `github.com/author/dependency` to your Terraform provider: + +```shell +go get github.com/author/dependency +go mod tidy +``` + +Then commit the changes to `go.mod` and `go.sum`. + +## Using the provider + +Fill this in for each provider + +## Developing the Provider + +If you wish to work on the provider, you'll first need [Go](http://www.golang.org) installed on your machine (see [Requirements](#requirements) above). + +To compile the provider, run `go install`. This will build the provider and put the provider binary in the `$GOPATH/bin` directory. + +To generate or update documentation, run `make generate`. + +In order to run the full suite of Acceptance tests, run `make testacc`. + +*Note:* Acceptance tests create real resources, and often cost money to run. + +```shell +make testacc +``` diff --git a/terraform/.terraform/providers/registry.terraform.io/sander0542/nginxproxymanager/1.4.0/linux_amd64/terraform-provider-nginxproxymanager_v1.4.0 b/terraform/.terraform/providers/registry.terraform.io/sander0542/nginxproxymanager/1.4.0/linux_amd64/terraform-provider-nginxproxymanager_v1.4.0 new file mode 100755 index 0000000..32ab6ca Binary files /dev/null and b/terraform/.terraform/providers/registry.terraform.io/sander0542/nginxproxymanager/1.4.0/linux_amd64/terraform-provider-nginxproxymanager_v1.4.0 differ diff --git a/terraform/main.tf b/terraform/main.tf new file mode 100644 index 0000000..d0e1d65 --- /dev/null +++ b/terraform/main.tf @@ -0,0 +1,101 @@ +# Central Dashboard +resource "nginxproxymanager_proxy_host" "dashboard" { + domain_names = ["dashboard.${var.domain}"] + forward_host = "homepage" + forward_port = 3000 + forward_scheme = "http" + enabled = true + block_exploits = true + allow_websocket_upgrade = true +} + +# Nextcloud Cloud & Office +resource "nginxproxymanager_proxy_host" "cloud" { + domain_names = ["cloud.${var.domain}"] + forward_host = "nextcloud" + forward_port = 80 + forward_scheme = "http" + enabled = true + block_exploits = true + allow_websocket_upgrade = true +} + +resource "nginxproxymanager_proxy_host" "office" { + domain_names = ["office.${var.domain}"] + forward_host = "collabora" + forward_port = 9980 + forward_scheme = "http" + enabled = true + allow_websocket_upgrade = true +} + +# SimpleLogin Mail Aliases +resource "nginxproxymanager_proxy_host" "mail" { + domain_names = ["mail.${var.domain}"] + forward_host = "simplelogin-app" + forward_port = 80 + forward_scheme = "http" + enabled = true + allow_websocket_upgrade = true +} + +# Forgejo Git & CI/CD +resource "nginxproxymanager_proxy_host" "git" { + domain_names = ["git.${var.domain}"] + forward_host = "forgejo" + forward_port = 3000 + forward_scheme = "http" + enabled = true + block_exploits = true + allow_websocket_upgrade = true +} + +# Plane Task Management +resource "nginxproxymanager_proxy_host" "tasks" { + domain_names = ["tasks.${var.domain}"] + forward_host = "plane-web" + forward_port = 3000 + forward_scheme = "http" + enabled = true + allow_websocket_upgrade = true +} + +resource "nginxproxymanager_proxy_host" "wiki" { + domain_names = ["wiki.${var.domain}"] + forward_host = "docmost" + forward_port = 3000 + forward_scheme = "http" + enabled = true + allow_websocket_upgrade = true +} + +# Paperless-ngx Document Repository +resource "nginxproxymanager_proxy_host" "docs" { + domain_names = ["docs.${var.domain}"] + forward_host = "paperless-webserver" + forward_port = 8000 + forward_scheme = "http" + enabled = true + block_exploits = true + allow_websocket_upgrade = true +} + +# Calibre-Web E-Book Library +resource "nginxproxymanager_proxy_host" "books" { + domain_names = ["books.${var.domain}"] + forward_host = "calibre-web" + forward_port = 8083 + forward_scheme = "http" + enabled = true + allow_websocket_upgrade = true +} + +# Uptime Kuma Monitoring +resource "nginxproxymanager_proxy_host" "status" { + domain_names = ["status.${var.domain}"] + forward_host = "uptime-kuma" + forward_port = 3001 + forward_scheme = "http" + enabled = true + allow_websocket_upgrade = true +} diff --git a/terraform/providers.tf b/terraform/providers.tf new file mode 100644 index 0000000..624bcd9 --- /dev/null +++ b/terraform/providers.tf @@ -0,0 +1,15 @@ +terraform { + required_version = ">= 1.0.0" + required_providers { + nginxproxymanager = { + source = "Sander0542/nginxproxymanager" + version = "1.4.0" + } + } +} + +provider "nginxproxymanager" { + url = var.npm_host + username = var.npm_username + password = var.npm_password +} diff --git a/terraform/terraform.tfstate b/terraform/terraform.tfstate new file mode 100644 index 0000000..2774d07 --- /dev/null +++ b/terraform/terraform.tfstate @@ -0,0 +1,306 @@ +{ + "version": 4, + "terraform_version": "1.11.0", + "serial": 11, + "lineage": "8e77a2a6-a8be-5186-4b43-950cf5faa83a", + "outputs": {}, + "resources": [ + { + "mode": "managed", + "type": "nginxproxymanager_proxy_host", + "name": "books", + "provider": "provider[\"registry.terraform.io/sander0542/nginxproxymanager\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "access_list_id": null, + "advanced_config": "", + "allow_websocket_upgrade": true, + "block_exploits": false, + "caching_enabled": false, + "certificate_id": null, + "created_on": "2026-08-27 00:02:03", + "domain_names": [ + "books.techarmor.pl" + ], + "enabled": true, + "forward_host": "calibre-web", + "forward_port": 8083, + "forward_scheme": "http", + "hsts_enabled": false, + "hsts_subdomains": false, + "http2_support": false, + "id": 10, + "locations": [], + "meta": null, + "modified_on": "2026-08-27 00:02:03", + "owner_user_id": 1, + "ssl_forced": false + }, + "sensitive_attributes": [] + } + ] + }, + { + "mode": "managed", + "type": "nginxproxymanager_proxy_host", + "name": "cloud", + "provider": "provider[\"registry.terraform.io/sander0542/nginxproxymanager\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "access_list_id": null, + "advanced_config": "", + "allow_websocket_upgrade": true, + "block_exploits": true, + "caching_enabled": false, + "certificate_id": null, + "created_on": "2026-08-27 00:02:03", + "domain_names": [ + "cloud.techarmor.pl" + ], + "enabled": true, + "forward_host": "nextcloud", + "forward_port": 80, + "forward_scheme": "http", + "hsts_enabled": false, + "hsts_subdomains": false, + "http2_support": false, + "id": 6, + "locations": [], + "meta": null, + "modified_on": "2026-08-27 00:02:03", + "owner_user_id": 1, + "ssl_forced": false + }, + "sensitive_attributes": [] + } + ] + }, + { + "mode": "managed", + "type": "nginxproxymanager_proxy_host", + "name": "docs", + "provider": "provider[\"registry.terraform.io/sander0542/nginxproxymanager\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "access_list_id": null, + "advanced_config": "", + "allow_websocket_upgrade": true, + "block_exploits": true, + "caching_enabled": false, + "certificate_id": null, + "created_on": "2026-08-27 00:02:03", + "domain_names": [ + "docs.techarmor.pl" + ], + "enabled": true, + "forward_host": "paperless-webserver", + "forward_port": 8000, + "forward_scheme": "http", + "hsts_enabled": false, + "hsts_subdomains": false, + "http2_support": false, + "id": 9, + "locations": [], + "meta": null, + "modified_on": "2026-08-27 00:02:03", + "owner_user_id": 1, + "ssl_forced": false + }, + "sensitive_attributes": [] + } + ] + }, + { + "mode": "managed", + "type": "nginxproxymanager_proxy_host", + "name": "git", + "provider": "provider[\"registry.terraform.io/sander0542/nginxproxymanager\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "access_list_id": null, + "advanced_config": "", + "allow_websocket_upgrade": true, + "block_exploits": true, + "caching_enabled": false, + "certificate_id": null, + "created_on": "2026-08-27 00:02:03", + "domain_names": [ + "git.techarmor.pl" + ], + "enabled": true, + "forward_host": "forgejo", + "forward_port": 3000, + "forward_scheme": "http", + "hsts_enabled": false, + "hsts_subdomains": false, + "http2_support": false, + "id": 7, + "locations": [], + "meta": null, + "modified_on": "2026-08-27 00:02:03", + "owner_user_id": 1, + "ssl_forced": false + }, + "sensitive_attributes": [] + } + ] + }, + { + "mode": "managed", + "type": "nginxproxymanager_proxy_host", + "name": "mail", + "provider": "provider[\"registry.terraform.io/sander0542/nginxproxymanager\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "access_list_id": null, + "advanced_config": "", + "allow_websocket_upgrade": true, + "block_exploits": false, + "caching_enabled": false, + "certificate_id": null, + "created_on": "2026-08-27 00:02:03", + "domain_names": [ + "mail.techarmor.pl" + ], + "enabled": true, + "forward_host": "simplelogin-app", + "forward_port": 80, + "forward_scheme": "http", + "hsts_enabled": false, + "hsts_subdomains": false, + "http2_support": false, + "id": 8, + "locations": [], + "meta": null, + "modified_on": "2026-08-27 00:02:03", + "owner_user_id": 1, + "ssl_forced": false + }, + "sensitive_attributes": [] + } + ] + }, + { + "mode": "managed", + "type": "nginxproxymanager_proxy_host", + "name": "office", + "provider": "provider[\"registry.terraform.io/sander0542/nginxproxymanager\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "access_list_id": null, + "advanced_config": "", + "allow_websocket_upgrade": true, + "block_exploits": false, + "caching_enabled": false, + "certificate_id": null, + "created_on": "2026-08-27 00:02:03", + "domain_names": [ + "office.techarmor.pl" + ], + "enabled": true, + "forward_host": "collabora", + "forward_port": 9980, + "forward_scheme": "http", + "hsts_enabled": false, + "hsts_subdomains": false, + "http2_support": false, + "id": 11, + "locations": [], + "meta": null, + "modified_on": "2026-08-27 00:02:03", + "owner_user_id": 1, + "ssl_forced": false + }, + "sensitive_attributes": [] + } + ] + }, + { + "mode": "managed", + "type": "nginxproxymanager_proxy_host", + "name": "tasks", + "provider": "provider[\"registry.terraform.io/sander0542/nginxproxymanager\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "access_list_id": null, + "advanced_config": "", + "allow_websocket_upgrade": true, + "block_exploits": false, + "caching_enabled": false, + "certificate_id": null, + "created_on": "2026-08-27 00:02:03", + "domain_names": [ + "tasks.techarmor.pl" + ], + "enabled": true, + "forward_host": "plane-web", + "forward_port": 3000, + "forward_scheme": "http", + "hsts_enabled": false, + "hsts_subdomains": false, + "http2_support": false, + "id": 12, + "locations": [], + "meta": null, + "modified_on": "2026-08-27 00:02:03", + "owner_user_id": 1, + "ssl_forced": false + }, + "sensitive_attributes": [] + } + ] + }, + { + "mode": "managed", + "type": "nginxproxymanager_proxy_host", + "name": "wiki", + "provider": "provider[\"registry.terraform.io/sander0542/nginxproxymanager\"]", + "instances": [ + { + "schema_version": 0, + "attributes": { + "access_list_id": null, + "advanced_config": "", + "allow_websocket_upgrade": true, + "block_exploits": false, + "caching_enabled": false, + "certificate_id": null, + "created_on": "2026-08-27 00:02:02", + "domain_names": [ + "wiki.techarmor.pl" + ], + "enabled": true, + "forward_host": "docmost", + "forward_port": 3000, + "forward_scheme": "http", + "hsts_enabled": false, + "hsts_subdomains": false, + "http2_support": false, + "id": 5, + "locations": [], + "meta": null, + "modified_on": "2026-08-27 00:02:02", + "owner_user_id": 1, + "ssl_forced": false + }, + "sensitive_attributes": [] + } + ] + } + ], + "check_results": null +} diff --git a/terraform/terraform.tfvars b/terraform/terraform.tfvars new file mode 100644 index 0000000..58d6fa4 --- /dev/null +++ b/terraform/terraform.tfvars @@ -0,0 +1,4 @@ +npm_username = "gwolaniuk@gmail.com" +npm_password = "pitakles" +npm_host = "http://192.109.240.163:81" +domain = "techarmor.pl" diff --git a/terraform/variables.tf b/terraform/variables.tf new file mode 100644 index 0000000..5b8fd2a --- /dev/null +++ b/terraform/variables.tf @@ -0,0 +1,19 @@ +variable "npm_host" { + type = string + default = "http://192.109.240.163:81" +} + +variable "npm_username" { + type = string + sensitive = true +} + +variable "npm_password" { + type = string + sensitive = true +} + +variable "domain" { + type = string + default = "techarmor.pl" +}