initial
This commit is contained in:
19
configurations/otel/collector-config.yaml
Normal file
19
configurations/otel/collector-config.yaml
Normal file
@@ -0,0 +1,19 @@
|
|||||||
|
receivers:
|
||||||
|
otlp:
|
||||||
|
protocols:
|
||||||
|
grpc:
|
||||||
|
endpoint: 0.0.0.0:4317
|
||||||
|
http:
|
||||||
|
endpoint: 0.0.0.0:4318
|
||||||
|
|
||||||
|
exporters:
|
||||||
|
debug:
|
||||||
|
verbosity: detailed
|
||||||
|
|
||||||
|
service:
|
||||||
|
extensions: []
|
||||||
|
pipelines:
|
||||||
|
traces:
|
||||||
|
receivers: [otlp]
|
||||||
|
processors: []
|
||||||
|
exporters: [debug]
|
||||||
@@ -1,55 +1,74 @@
|
|||||||
defaultEntryPoints = ["http"]
|
|
||||||
|
|
||||||
[entryPoints]
|
[entryPoints]
|
||||||
[entryPoints.whoami]
|
[entryPoints.http]
|
||||||
address = ":8088"
|
address = ":80"
|
||||||
[entryPoints.homeassistant]
|
|
||||||
address = ":8089"
|
[entryPoints.https]
|
||||||
[entryPoints.syncthing]
|
address = ":443"
|
||||||
address = ":8090"
|
[entryPoints.https.tls]
|
||||||
[entryPoints.grafana]
|
[[entryPoints.https.tls.certificates]]
|
||||||
address = ":8091"
|
certFile = "/var/lib/certificates/cert.pem"
|
||||||
[entryPoints.influxdb]
|
keyFile = "/var/lib/certificates/key.pem"
|
||||||
address = ":8092"
|
|
||||||
|
|
||||||
[file]
|
[file]
|
||||||
|
|
||||||
[backends]
|
[backends]
|
||||||
[backends.whoami]
|
[backends.whoami]
|
||||||
[backends.whoami.servers.server1]
|
[backends.whoami.servers.server1]
|
||||||
url = "http://localhost:2001"
|
url = "http://whoami:2001"
|
||||||
[backends.homeassistant]
|
|
||||||
[backends.homeassistant.servers.server1]
|
|
||||||
url = "http://10.55.8.3:8123/"
|
|
||||||
[backends.syncthing]
|
|
||||||
[backends.syncthing.servers.server1]
|
|
||||||
url = "http://10.55.8.3:8384/"
|
|
||||||
[backends.grafana]
|
[backends.grafana]
|
||||||
[backends.grafana.servers.server1]
|
[backends.grafana.servers.server1]
|
||||||
url = "http://10.55.8.3:3000/"
|
url = "http://grafana:3000"
|
||||||
|
|
||||||
|
[backends.syncthing]
|
||||||
|
[backends.syncthing.servers.server1]
|
||||||
|
url = "http://syncthing:8384"
|
||||||
|
|
||||||
|
[backends.homeassistant]
|
||||||
|
[backends.homeassistant.servers.server1]
|
||||||
|
url = "http://homeassistant:8123"
|
||||||
|
|
||||||
[backends.influxdb]
|
[backends.influxdb]
|
||||||
[backends.influxdb.servers.server1]
|
[backends.influxdb.servers.server1]
|
||||||
url = "http://10.55.8.3:8086/"
|
url = "http://influxdb:8086"
|
||||||
|
|
||||||
[frontends]
|
[frontends]
|
||||||
[frontends.whoami]
|
[frontends.whoami]
|
||||||
entryPoints = ["whoami"]
|
|
||||||
backend = "whoami"
|
backend = "whoami"
|
||||||
|
[frontends.whoami.routes.path]
|
||||||
[frontends.homeassistant]
|
rule = "Path:/whoami;ReplacePathRegex: ^/whoami(.*) /$1"
|
||||||
entryPoints = ["homeassistant"]
|
|
||||||
backend = "homeassistant"
|
|
||||||
|
|
||||||
[frontends.syncthing]
|
|
||||||
entryPoints = ["syncthing"]
|
|
||||||
backend = "syncthing"
|
|
||||||
|
|
||||||
[frontends.grafana]
|
[frontends.grafana]
|
||||||
entryPoints = ["grafana"]
|
|
||||||
backend = "grafana"
|
backend = "grafana"
|
||||||
passHostHeader = true
|
[frontends.grafana.routes.path]
|
||||||
|
rule = "Path:/grafana;ReplacePathRegex: ^/grafana(.*) /$1"
|
||||||
|
|
||||||
|
[frontends.syncthing]
|
||||||
|
backend = "syncthing"
|
||||||
|
[frontends.syncthing.routes.path]
|
||||||
|
rule = "Path:/syncthing;ReplacePathRegex: ^/syncthing(.*) /$1"
|
||||||
|
|
||||||
|
[frontends.syncthing-referrer]
|
||||||
|
backend = "syncthing"
|
||||||
|
[frontends.syncthing-referrer.routes.referrer]
|
||||||
|
rule = "HeadersRegexp: Referer, /*.syncthing"
|
||||||
|
|
||||||
|
[frontends.homeassistant]
|
||||||
|
backend = "homeassistant"
|
||||||
|
[frontends.homeassistant.routes.path]
|
||||||
|
rule = "Path:/homeassistant;ReplacePathRegex: ^/homeassistant(.*) /$1"
|
||||||
|
|
||||||
[frontends.influxdb]
|
[frontends.influxdb]
|
||||||
entryPoints = ["influxdb"]
|
|
||||||
backend = "influxdb"
|
backend = "influxdb"
|
||||||
passHostHeader = true
|
[frontends.influxdb.routes.path]
|
||||||
|
rule = "Path:/influxdb;ReplacePathRegex: ^/influxdb(.*) /$1"
|
||||||
|
|
||||||
|
[frontends.influxdb-referrer]
|
||||||
|
backend = "influxdb"
|
||||||
|
[frontends.influxdb-referrer.routes.referrer]
|
||||||
|
rule = "HeadersRegexp: Referer, /*.influxdb"
|
||||||
|
|
||||||
|
|
||||||
|
[tracing]
|
||||||
|
[tracing.otlp.http]
|
||||||
|
endpoint = "http://otel-collector:4318"
|
||||||
|
insecure = true
|
||||||
|
|||||||
@@ -1,19 +1,4 @@
|
|||||||
# General settings
|
REPO_DIR=/home/pi/repos/homeAutomation
|
||||||
INTERNAL_IP: 0.0.0.0
|
|
||||||
|
|
||||||
# Maria DB settings
|
# Make sure docker user has read/write access on this folder
|
||||||
# For testing purposes only. Please create a .env.mariadb to overwrite these variables
|
STORAGE_DIR=/tmp
|
||||||
MARIADB_ROOT_PASSWORD=testing
|
|
||||||
|
|
||||||
MARIADB_DATABASE=homeassistant
|
|
||||||
MARIADB_USER=homeassistant_user
|
|
||||||
MARIADB_PASSWORD=homeassistant_pw
|
|
||||||
|
|
||||||
GF_SECURITY_ADMIN_USER=test
|
|
||||||
GF_SECURITY_ADMIN_PASSWORD=test
|
|
||||||
GF_USERS_ALLOW_SIGN_UP=false
|
|
||||||
|
|
||||||
DOCKER_INFLUXDB_INIT_USERNAME=homeassistant
|
|
||||||
DOCKER_INFLUXDB_INIT_PASSWORD=homeassistant
|
|
||||||
DOCKER_INFLUXDB_INIT_ORG=homeassistant
|
|
||||||
DOCKER_INFLUXDB_INIT_BUCKET=homeassistant
|
|
||||||
|
|||||||
@@ -1,26 +1,36 @@
|
|||||||
version: "3.9"
|
|
||||||
services:
|
services:
|
||||||
|
whoami:
|
||||||
|
restart: unless-stopped
|
||||||
|
image: traefik/whoami
|
||||||
|
command:
|
||||||
|
- --port=2001
|
||||||
|
traefik:
|
||||||
|
restart: unless-stopped
|
||||||
|
image: "traefik:1.7.10"
|
||||||
|
volumes:
|
||||||
|
- ${REPO_DIR}/configurations/traefik/traefik.1.7.10.toml:/etc/traefik/traefik.toml
|
||||||
|
- ${STORAGE_DIR}/certificates:/var/lib/certificates
|
||||||
|
ports:
|
||||||
|
- 80:80
|
||||||
|
- 443:443
|
||||||
db:
|
db:
|
||||||
image: mariadb:latest
|
image: mariadb:latest
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
ports:
|
ports:
|
||||||
- ${INTERNAL_IP}:3306:3306
|
- 3306:3306
|
||||||
env_file:
|
env_file:
|
||||||
- .env
|
- envs/local.env
|
||||||
- .env.production
|
- envs/production.env
|
||||||
volumes:
|
volumes:
|
||||||
- /home/willem/mariadb:/var/lib/mysql
|
- ${STORAGE_DIR}/mariadb:/var/lib/mysql
|
||||||
homeassistant:
|
homeassistant:
|
||||||
image: "ghcr.io/home-assistant/home-assistant:stable"
|
image: "ghcr.io/home-assistant/home-assistant:stable"
|
||||||
ports:
|
|
||||||
- ${INTERNAL_IP}:8123:8123
|
|
||||||
volumes:
|
volumes:
|
||||||
- /home/willem/homeassistant:/config
|
- ${STORAGE_DIR}/homeassistant:/config
|
||||||
- /home/willem/repos/homeAutomation/configurations/home-assistant/configuration.production.yaml:/config/configuration.yaml
|
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
env_file:
|
env_file:
|
||||||
- .env
|
- envs/local.env
|
||||||
- .env.production
|
- envs/production.env
|
||||||
syncthing:
|
syncthing:
|
||||||
image: lscr.io/linuxserver/syncthing:latest
|
image: lscr.io/linuxserver/syncthing:latest
|
||||||
container_name: syncthing
|
container_name: syncthing
|
||||||
@@ -29,12 +39,11 @@ services:
|
|||||||
- PGID=1000
|
- PGID=1000
|
||||||
- TZ=Europe/London
|
- TZ=Europe/London
|
||||||
volumes:
|
volumes:
|
||||||
- /home/willem/syncthing:/data1
|
- ${STORAGE_DIR}/syncthing:/data1
|
||||||
ports:
|
ports:
|
||||||
- ${INTERNAL_IP}:8384:8384
|
- 22000:22000/tcp
|
||||||
- ${INTERNAL_IP}:22000:22000/tcp
|
- 22000:22000/udp
|
||||||
- ${INTERNAL_IP}:22000:22000/udp
|
- 21027:21027/udp
|
||||||
- ${INTERNAL_IP}:21027:21027/udp
|
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
node-exporter:
|
node-exporter:
|
||||||
image: prom/node-exporter:latest
|
image: prom/node-exporter:latest
|
||||||
@@ -50,14 +59,14 @@ services:
|
|||||||
- '--path.sysfs=/host/sys'
|
- '--path.sysfs=/host/sys'
|
||||||
- '--collector.filesystem.mount-points-exclude=^/(sys|proc|dev|host|etc)($$|/)'
|
- '--collector.filesystem.mount-points-exclude=^/(sys|proc|dev|host|etc)($$|/)'
|
||||||
ports:
|
ports:
|
||||||
- ${INTERNAL_IP}:9100:9100
|
- 9100:9100
|
||||||
prometheus:
|
prometheus:
|
||||||
image: prom/prometheus:latest
|
image: prom/prometheus:latest
|
||||||
container_name: prometheus
|
container_name: prometheus
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
volumes:
|
volumes:
|
||||||
- /home/willem/repos/homeAutomation/configurations/prometheus/prometheus.yml:/etc/prometheus/prometheus.yml
|
- ${REPO_DIR}/configurations/prometheus/prometheus.yml:/etc/prometheus/prometheus.yml
|
||||||
- /home/willem/prometheus:/prometheus
|
- ${STORAGE_DIR}/prometheus:/prometheus
|
||||||
command:
|
command:
|
||||||
- '--config.file=/etc/prometheus/prometheus.yml'
|
- '--config.file=/etc/prometheus/prometheus.yml'
|
||||||
- '--storage.tsdb.path=/prometheus'
|
- '--storage.tsdb.path=/prometheus'
|
||||||
@@ -65,31 +74,37 @@ services:
|
|||||||
- '--web.console.templates=/etc/prometheus/consoles'
|
- '--web.console.templates=/etc/prometheus/consoles'
|
||||||
- '--web.enable-lifecycle'
|
- '--web.enable-lifecycle'
|
||||||
ports:
|
ports:
|
||||||
- ${INTERNAL_IP}:9090:9090
|
- 9090:9090
|
||||||
grafana:
|
grafana:
|
||||||
image: grafana/grafana:latest
|
image: grafana/grafana:latest
|
||||||
ports:
|
|
||||||
- ${INTERNAL_IP}:3000:3000
|
|
||||||
volumes:
|
volumes:
|
||||||
- /home/willem/grafana:/var/lib/grafana
|
- ${STORAGE_DIR}/grafana:/var/lib/grafana
|
||||||
env_file:
|
env_file:
|
||||||
- .env
|
- envs/local.env
|
||||||
- .env.production
|
- envs/production.env
|
||||||
influxdb:
|
influxdb:
|
||||||
container_name: influxdb
|
container_name: influxdb
|
||||||
image: influxdb
|
image: influxdb
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
ports:
|
|
||||||
- ${INTERNAL_IP}:8086:8086/tcp # So we can access the WebUI
|
|
||||||
environment:
|
environment:
|
||||||
- TZ=Europe/Brussels
|
- TZ=Europe/Brussels
|
||||||
- DOCKER_INFLUXDB_INIT_MODE=setup
|
- DOCKER_INFLUXDB_INIT_MODE=setup
|
||||||
env_file:
|
env_file:
|
||||||
- .env.production
|
- envs/local.env
|
||||||
|
- envs/production.env
|
||||||
volumes:
|
volumes:
|
||||||
- /home/willem/influxdb/data:/var/lib/influxdb2
|
- ${STORAGE_DIR}/influxdb/data:/var/lib/influxdb2
|
||||||
- /home/willem/influxdb/config/:/etc/influxdb2
|
- ${STORAGE_DIR}/influxdb/config/:/etc/influxdb2
|
||||||
ulimits:
|
ulimits:
|
||||||
nofile:
|
nofile:
|
||||||
soft: 32768
|
soft: 32768
|
||||||
hard: 32768
|
hard: 32768
|
||||||
|
otel-collector:
|
||||||
|
container_name: otel-collector
|
||||||
|
image: otel/opentelemetry-collector-contrib:0.111.0
|
||||||
|
restart: unless-stopped
|
||||||
|
volumes:
|
||||||
|
- ${REPO_DIR}/configurations/otel/collector-config.yaml:/etc/otelcol-contrib/config.yaml
|
||||||
|
# Only enable if external services present
|
||||||
|
# ports:
|
||||||
|
# - 4317:4317 # OTLP gRPC receiver
|
||||||
|
|||||||
16
home-server/envs/local.env
Normal file
16
home-server/envs/local.env
Normal file
@@ -0,0 +1,16 @@
|
|||||||
|
# Maria DB settings
|
||||||
|
# For testing purposes only. Please create a .env.mariadb to overwrite these variables
|
||||||
|
MARIADB_ROOT_PASSWORD=testing
|
||||||
|
|
||||||
|
MARIADB_DATABASE=homeassistant
|
||||||
|
MARIADB_USER=homeassistant_user
|
||||||
|
MARIADB_PASSWORD=homeassistant_pw
|
||||||
|
|
||||||
|
GF_SECURITY_ADMIN_USER=test
|
||||||
|
GF_SECURITY_ADMIN_PASSWORD=test
|
||||||
|
GF_USERS_ALLOW_SIGN_UP=false
|
||||||
|
|
||||||
|
DOCKER_INFLUXDB_INIT_USERNAME=homeassistant
|
||||||
|
DOCKER_INFLUXDB_INIT_PASSWORD=homeassistant
|
||||||
|
DOCKER_INFLUXDB_INIT_ORG=homeassistant
|
||||||
|
DOCKER_INFLUXDB_INIT_BUCKET=homeassistant
|
||||||
18
home-server/envs/production.env
Normal file
18
home-server/envs/production.env
Normal file
@@ -0,0 +1,18 @@
|
|||||||
|
# Maria DB settings
|
||||||
|
# For testing purposes only. Please create a .env.mariadb to overwrite these variables
|
||||||
|
MARIADB_ROOT_PASSWORD=c8gcablGDuJH2tnbAXjPiQ==
|
||||||
|
|
||||||
|
MARIADB_DATABASE=homeassistant
|
||||||
|
MARIADB_USER=homeassistant_user
|
||||||
|
MARIADB_PASSWORD=gyxxny8gO6bzczw+ULuALA==
|
||||||
|
|
||||||
|
GF_SECURITY_ADMIN_USER=admin
|
||||||
|
GF_SECURITY_ADMIN_PASSWORD=QCpuH3Fnet7g9ywlRQ1Gtw==
|
||||||
|
GF_USERS_ALLOW_SIGN_UP=false
|
||||||
|
|
||||||
|
DOCKER_INFLUXDB_INIT_USERNAME=homeassistant
|
||||||
|
DOCKER_INFLUXDB_INIT_PASSWORD=IEOUjgdbI3XjJnmqQOPkHw==
|
||||||
|
DOCKER_INFLUXDB_INIT_ORG=homeassistant
|
||||||
|
DOCKER_INFLUXDB_INIT_BUCKET=homeassistant
|
||||||
|
|
||||||
|
REPO_DIR=/home/pi/repos/homeAutomation
|
||||||
@@ -35,3 +35,12 @@ docker compose rm db
|
|||||||
|
|
||||||
- Start the VPN client automatically after reboot
|
- Start the VPN client automatically after reboot
|
||||||
|
|
||||||
|
## Generate self signed certificates
|
||||||
|
|
||||||
|
https://stackoverflow.com/questions/10175812/how-to-generate-a-self-signed-ssl-certificate-using-openssl
|
||||||
|
|
||||||
|
> non-interactive and 10 years expiration
|
||||||
|
|
||||||
|
```bash
|
||||||
|
openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -sha256 -days 3650 -nodes -subj "/C=homeassistant/ST=Belgium/L=Deerlijk/O=Willem/OU=Willem/CN=willem" -subj '/CN=homeassistant.com'
|
||||||
|
```
|
||||||
27
home-server/install-docker.sh
Executable file
27
home-server/install-docker.sh
Executable file
@@ -0,0 +1,27 @@
|
|||||||
|
#!/usr/bin/sh
|
||||||
|
|
||||||
|
# See https://docs.docker.com/engine/install/debian/
|
||||||
|
#
|
||||||
|
# Add Docker's official GPG key:
|
||||||
|
sudo apt-get update
|
||||||
|
sudo apt-get install ca-certificates curl
|
||||||
|
sudo install -m 0755 -d /etc/apt/keyrings
|
||||||
|
sudo curl -fsSL https://download.docker.com/linux/debian/gpg -o /etc/apt/keyrings/docker.asc
|
||||||
|
sudo chmod a+r /etc/apt/keyrings/docker.asc
|
||||||
|
|
||||||
|
# Add the repository to Apt sources:
|
||||||
|
echo \
|
||||||
|
"deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/debian \
|
||||||
|
$(. /etc/os-release && echo "$VERSION_CODENAME") stable" | \
|
||||||
|
sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
|
||||||
|
sudo apt-get update
|
||||||
|
|
||||||
|
sudo apt-get install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
|
||||||
|
|
||||||
|
sudo groupadd docker
|
||||||
|
sudo usermod -aG docker $USER
|
||||||
|
|
||||||
|
newgrp docker
|
||||||
|
|
||||||
|
# Verify:
|
||||||
|
# docker run hello-world
|
||||||
Reference in New Issue
Block a user