Files
infra/README.md
T
Asep Haryana 0194a865b7 refactor(infra): repurpose asepharyana-hub into infra-only reverse-proxy repo
- Remove app submodules (hub/scraper/tools/llm-api/plugins) — apps are now
  standalone repos with their own flake.nix + deploy.yml CI
- Delete monorepo CI: nix-build.yml matrix, update-submodule.yml, lint, security,
  flakehub-publish — replaced by infra-only caddy-deploy.yml
- Sync Caddyfile.prod with live /etc/caddy/Caddyfile (add wiki. + mcp. blocks)
- Prune legacy Docker/Traefik/Dapr/NATS/otel + scripts/root tooling
- Docs: rename ADR 0001 superseded, add ADR 0003 (repo rename + split CI),
  update add-new-app, infra README, troubleshooting
2026-08-27 19:44:10 +07:00

2.6 KiB

Asepharyana Infra

Reverse-proxy & infrastructure config for orangevps (45.127.35.244).

Status (2026-08-28): Repo ini dulunya monorepo asepharyana-hub dengan submodule aplikasi. Kini murni repo infra: Caddy reverse proxy (source of truth), firewall, drop-in systemd, dan docs. Build + deploy tiap aplikasi pindah ke repo masing-masing (self-contained CI).

Repositori Aplikasi (self-contained build & deploy)

Repo Deskripsi Deploy unit
asepharyana/hub Portfolio SPA (Next.js, port 4003, dashboard) hub
asepharyana/scraper Rust/Axum scraper API (port 4091) scraper
asepharyana/tools Tools: Rust gateway/workers + Next.js frontend (3500/3501) tools-gateway, tools-workers, tools-frontend
asepharyana/llm-api Rust LLM API (llama.cpp, port 8080) llm-api

Tiap repo punya flake.nix + .github/workflows/deploy.yml sendiri: nix build .#<pkg> → nix copy ssh:// → nix-env --profile → systemctl restart. Push ke main (atau workflow_dispatch) langsung deploy; tidak ada lagi pointer submodule.

Infra di Repo Ini

Path Isi
infra/caddy/Caddyfile.prod Source of truth /etc/caddy/Caddyfile (auto-deploy via CI)
infra/firewall/firewall.sh deny-by-default iptables (SSH/80/443/4013/Tailscale/TCPShield)
infra/firewall/99-*.conf sysctl hardenings
infra/prometheus/targets.yml file_sd targets
infra/systemd/scraper-otel.conf drop-in OTEL untuk scraper service
docs/ arsitektur + operasional (VPS)

CI/CD

Workflow Trigger Aksi
caddy-deploy.yml push main menyentuh infra/**, atau manual sync Caddyfile.prod → /etc/caddy/Caddyfile → reload → verifikasi rute

Local Setup / Snapshot VPS

# Clone infra repo
git clone https://github.com/asepharyana/infra.git
# Diff config live vs repo
diff /etc/caddy/Caddyfile infra/caddy/Caddyfile.prod
# Koneksi VPS (public)
ssh code@45.127.35.244

Menambahkan Service Baru / Subdomain

  1. Aplikasi punya repo sendiri + deploy.yml (lihat template di repo app yang ada).
  2. Registrasi unit systemd di VPS (manual/ops) → app jalan di port lokal.
  3. Tambah site block di infra/caddy/Caddyfile.prod (pola import proxy <port>) → push → CI reload Caddy.
  4. (Opsional) Tambah unit ke MONITORED_UNITS dashboard hub di repo asepharyana/hub.

Lihat docs/add-new-app.md untuk detail.