- Remove app submodules (hub/scraper/tools/llm-api/plugins) — apps are now standalone repos with their own flake.nix + deploy.yml CI - Delete monorepo CI: nix-build.yml matrix, update-submodule.yml, lint, security, flakehub-publish — replaced by infra-only caddy-deploy.yml - Sync Caddyfile.prod with live /etc/caddy/Caddyfile (add wiki. + mcp. blocks) - Prune legacy Docker/Traefik/Dapr/NATS/otel + scripts/root tooling - Docs: rename ADR 0001 superseded, add ADR 0003 (repo rename + split CI), update add-new-app, infra README, troubleshooting
2.6 KiB
2.6 KiB
Asepharyana Infra
Reverse-proxy & infrastructure config for orangevps (45.127.35.244).
Status (2026-08-28): Repo ini dulunya monorepo
asepharyana-hubdengan submodule aplikasi. Kini murni repo infra: Caddy reverse proxy (source of truth), firewall, drop-in systemd, dan docs. Build + deploy tiap aplikasi pindah ke repo masing-masing (self-contained CI).
Repositori Aplikasi (self-contained build & deploy)
| Repo | Deskripsi | Deploy unit |
|---|---|---|
asepharyana/hub |
Portfolio SPA (Next.js, port 4003, dashboard) | hub |
asepharyana/scraper |
Rust/Axum scraper API (port 4091) | scraper |
asepharyana/tools |
Tools: Rust gateway/workers + Next.js frontend (3500/3501) | tools-gateway, tools-workers, tools-frontend |
asepharyana/llm-api |
Rust LLM API (llama.cpp, port 8080) | llm-api |
Tiap repo punya flake.nix + .github/workflows/deploy.yml sendiri:
nix build .#<pkg> → nix copy ssh:// → nix-env --profile → systemctl restart.
Push ke main (atau workflow_dispatch) langsung deploy; tidak ada lagi pointer submodule.
Infra di Repo Ini
| Path | Isi |
|---|---|
infra/caddy/Caddyfile.prod |
Source of truth /etc/caddy/Caddyfile (auto-deploy via CI) |
infra/firewall/firewall.sh |
deny-by-default iptables (SSH/80/443/4013/Tailscale/TCPShield) |
infra/firewall/99-*.conf |
sysctl hardenings |
infra/prometheus/targets.yml |
file_sd targets |
infra/systemd/scraper-otel.conf |
drop-in OTEL untuk scraper service |
docs/ |
arsitektur + operasional (VPS) |
CI/CD
| Workflow | Trigger | Aksi |
|---|---|---|
caddy-deploy.yml |
push main menyentuh infra/**, atau manual |
sync Caddyfile.prod → /etc/caddy/Caddyfile → reload → verifikasi rute |
Local Setup / Snapshot VPS
# Clone infra repo
git clone https://github.com/asepharyana/infra.git
# Diff config live vs repo
diff /etc/caddy/Caddyfile infra/caddy/Caddyfile.prod
# Koneksi VPS (public)
ssh code@45.127.35.244
Menambahkan Service Baru / Subdomain
- Aplikasi punya repo sendiri +
deploy.yml(lihat template di repo app yang ada). - Registrasi unit systemd di VPS (manual/ops) → app jalan di port lokal.
- Tambah site block di
infra/caddy/Caddyfile.prod(polaimport proxy <port>) → push → CI reload Caddy. - (Opsional) Tambah unit ke
MONITORED_UNITSdashboard hub di repoasepharyana/hub.
Lihat docs/add-new-app.md untuk detail.