Commit Graph

19 Commits

Author SHA1 Message Date
mk
9f164f61ef angie(debian): pin VERSION_ID in apt repo URL — needs angie/<ID>/<VERSION_ID>/ (debian/13/dists/trixie/) not angie/<ID>/ (debian/dists/trixie/ -> 404 'no Release file') on trixie; suite stays VERSION_CODENAME
packages(debian): rm stale /etc/apt/sources.list.d/eza.list + gierens.gpg left by the pre-fix run that used the now-dead apt.fury.io PPA — otherwise 'apt-get update' keeps hitting the 401 forever even though we now install eza from GH releases
2026-07-28 07:11:22 +03:00
mk
0cfe10e387 packages(debian): fix eza+starship+zoxide installs
- eza: apt.fury.io PPA is dead (401 Unauthorized); install the single binary from the upstream GitHub release tarball (eza_x86_64-unknown-linux-gnu.tar.gz) into /usr/local/bin — no apt repo, system-wide
- starship: scrub $ARCH/$PLATFORM from the installer env — our lib/detect.sh exports ARCH=amd64, which the starship installer reuses (it checks ${ARCH-}) and skips its own amd64->x86_64 mapping, producing an unsupported 'amd64-unknown-linux-musl' target. Default bin dir is /usr/local/bin anyway
- zoxide: install system-wide (--bin-dir /usr/local/bin) instead of ~/.local/bin — when run as root the default landed in /root (wrong user for the create-user path) and wasn't on $PATH
2026-07-28 07:08:04 +03:00
mk
efdf056352 hardening(angie): default_server needs a cert on its 443 listener or 'angie -t' fails with 'no ssl_certificate defined' — generate a one-time self-signed dummy (CN=bootstrap-default, 10y) in /etc/angie/ssl so unknown-SNI clients handshake then get 444; mark listen 443 as ssl explicitly 2026-07-28 06:55:31 +03:00
mk
435d66aad2 shell-zsh: derive ZSH/ZDOTDIR from $TARGET_HOME unconditionally — ignore inherited $ZSH env var (omz exports it, which pinned paths to the old home e.g. /root while the chown step retargeted to the new user, causing 'insecure completion dirs' owned by the wrong user) 2026-07-28 06:16:45 +03:00
mk
94a0bac9f4 hardening(angie): resolve mime.types from whichever path the package ships (angie-bin=/etc/angie, Arch source=/etc/nginx via mailcap dep) — fixes 'angie -t' 'open() mime.types failed' on source path; fallback ships a minimal mime.types; ensure modules/ include dirs exist before glob 2026-07-28 06:04:57 +03:00
mk
26185978ac hardening(angie): source-angie bridge — symlink /etc/nginx/nginx.conf -> /etc/angie/angie.conf so the _on/targets layout actually loads under the source AUR package's '/usr/bin/nginx' service (angie-bin/Debian already read /etc/angie directly); backup original once 2026-07-28 05:59:08 +03:00
mk
cb0e517a7d hardening(angie): fix 'angie_user: unbound variable' under set -u — init extraction locals to empty; also read source AUR package's /etc/nginx/nginx.conf as alt stock config path 2026-07-28 05:57:44 +03:00
mk
b653191de2 angie(arch): prefer angie-bin (repackaged upstream .deb, instant) over source build; verified http_acme/ssl/v2/v3/realip all compiled in; fall back to aur/angie if bin unavailable 2026-07-28 05:53:43 +03:00
mk
ca8f01083c packages(arch): route byobu through yay (AUR-only); split official vs AUR lists so pacman --needed can't abort on a missing target; as_user prefers TARGET_USER for AUR builds 2026-07-28 05:44:45 +03:00
mk
ff9fc4db4e fix(sanity): hostname missing on minimal Arch (not in coreutils) — use uname -n with fallbacks; refresh TLS follow-up to angie-issue 2026-07-28 05:35:40 +03:00
mk
f7e4bb96d7 fix(zsh plugins): correct clone orgs — zsh-users/zsh-history-substring-search, Aloxaf/fzf-tab (were typos causing github auth prompts) 2026-07-28 05:28:20 +03:00
mk
8930e7aa76 non-interactive --yes: ask() assumes prompt default (no read); timezone defaults UTC; --username implies force-create; create-user name defaults to mk under --yes 2026-07-28 05:21:23 +03:00
mk
e7a9349292 modules: target $TARGET_USER (docker group, zsh/nvim/nvm homes, chown tree) 2026-07-28 05:05:03 +03:00
mk
8a516f039c create-user: passwordless sudo user (NOPASSWD, !tty_tickets, 7d cache) + retarget config; --create-user/--username flags 2026-07-28 05:05:03 +03:00
mk
0116ac60b3 hardening: angie config layout (_on/targets/modules) + sane root config + enable/disable helpers 2026-07-28 04:50:08 +03:00
mk
5e0e96e8e2 modules: hardening (ssh/ufw/updates/tz/hostname/swap/locale/fail2ban) + sanity report 2026-07-28 04:32:38 +03:00
mk
9f54745832 modules: zsh+omz+plugins, nvm+node LTS, nvim-minimal config clone 2026-07-28 04:32:38 +03:00
mk
f89aa8505f modules: docker engine+compose v2, angie web server 2026-07-28 04:32:38 +03:00
mk
a9ba810bbc modules: preflight + core packages (arch pacman + apt, yay, gh-release fallback) 2026-07-28 04:32:38 +03:00