mnemo_cards/tools/deploy/deploy-vscode-nginx.sh
2025-11-23 03:00:32 +03:00

315 lines
9.4 KiB
Bash
Executable file

#!/bin/bash
# Script to deploy VSCode nginx configuration to the server
set -e
SERVER_IP="147.45.152.129"
SERVER_USER="root"
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
PROJECT_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)"
echo "🚀 Deploying nginx configurations to server..."
echo "Server: $SERVER_IP"
echo ""
# Function to generate nginx configuration for a service
generate_nginx_config() {
local domain=$1
local upstream_port=$2
local service_name=$3
local rate_limit_zone=$4
local rate_limit_burst=$5
cat << EOF
# Nginx configuration for $domain
# Generated by deploy script
server {
listen 80;
server_name $domain;
return 301 https://\$server_name\$request_uri;
}
server {
listen 443 ssl http2;
server_name $domain;
# SSL configuration
ssl_certificate /etc/letsencrypt/live/mnemo-cards.online/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/mnemo-cards.online/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers HIGH:!aNULL:!MD5;
# Security headers
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
# Client settings
client_max_body_size 100M;
EOF
# Add rate limiting for VSCode
if [ "$service_name" = "vscode" ]; then
cat << EOF
# Rate limiting for VSCode
limit_req zone=$rate_limit_zone burst=$rate_limit_burst nodelay;
# Static files - no rate limiting
location ~ ^/(static|out|node_modules)/ {
proxy_pass http://127.0.0.1:$upstream_port;
proxy_set_header Host \$host;
proxy_set_header X-Real-IP \$remote_addr;
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto \$scheme;
proxy_cache_valid 200 1h;
add_header Cache-Control "public, max-age=3600";
proxy_connect_timeout 60s;
proxy_send_timeout 60s;
proxy_read_timeout 60s;
}
# Static file extensions - no rate limiting
location ~ \.(js|css|woff|woff2|ttf|eot|png|jpg|jpeg|gif|svg|ico|webp|map|json)$ {
proxy_pass http://127.0.0.1:$upstream_port;
proxy_set_header Host \$host;
proxy_set_header X-Real-IP \$remote_addr;
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto \$scheme;
proxy_cache_valid 200 1h;
add_header Cache-Control "public, max-age=3600";
proxy_connect_timeout 60s;
proxy_send_timeout 60s;
proxy_read_timeout 60s;
}
# Special rate limiting for login attempts
location /login {
limit_req zone=vscode_login burst=2 nodelay;
proxy_pass http://127.0.0.1:$upstream_port;
proxy_set_header Host \$host;
proxy_set_header X-Real-IP \$remote_addr;
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto \$scheme;
proxy_http_version 1.1;
proxy_set_header Upgrade \$http_upgrade;
proxy_set_header Connection "upgrade";
proxy_connect_timeout 60s;
proxy_send_timeout 60s;
proxy_read_timeout 60s;
proxy_buffering off;
proxy_request_buffering off;
}
EOF
fi
# Main proxy location
cat << EOF
# Proxy to $service_name
EOF
if [ "$service_name" = "vscode" ]; then
cat << EOF
location / {
limit_req zone=$rate_limit_zone burst=$rate_limit_burst nodelay;
EOF
else
cat << EOF
location / {
EOF
fi
cat << EOF
proxy_pass http://127.0.0.1:$upstream_port;
proxy_set_header Host \$host;
proxy_set_header X-Real-IP \$remote_addr;
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto \$scheme;
proxy_http_version 1.1;
proxy_set_header Upgrade \$http_upgrade;
proxy_set_header Connection "upgrade";
proxy_connect_timeout 60s;
proxy_send_timeout 60s;
proxy_read_timeout 60s;
proxy_buffering off;
proxy_request_buffering off;
}
# Gzip compression
echo " gzip on;"
echo " gzip_vary on;"
echo " gzip_min_length 1024;"
echo " gzip_proxied expired no-cache no-store private auth;"
echo " gzip_types text/plain text/css text/xml text/javascript application/x-javascript application/xml+rss application/javascript;"
echo ""
echo " # Security - deny access to hidden files"
echo " location ~ /\. {"
echo " deny all;"
echo " }"
echo "}"
}
# Generate configurations for all services
echo "📝 Generating nginx configurations..."
# VSCode configuration
generate_nginx_config "vscode.mnemo-cards.online" "8443" "vscode" "vscode_general" "50" > /tmp/vscode-nginx.conf
# Forgejo configuration
generate_nginx_config "code.mnemo-cards.online" "3000" "forgejo" "" "" > /tmp/forgejo-nginx.conf
# Main web app configuration
cat > /tmp/mnemo_cards_main-nginx.conf << 'EOF'
server {
listen 80;
server_name mnemo-cards.online www.mnemo-cards.online;
return 301 https://$server_name$request_uri;
}
server {
listen 443 ssl http2;
server_name mnemo-cards.online www.mnemo-cards.online;
ssl_certificate /etc/letsencrypt/live/mnemo-cards.online/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/mnemo-cards.online/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers HIGH:!aNULL:!MD5;
# Security headers
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
# Client settings
client_max_body_size 1000M;
root /var/www/mnemo_cards;
index index.html;
location / {
try_files $uri $uri/ /index.html;
}
location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg|woff|woff2|ttf|eot)$ {
expires 1y;
add_header Cache-Control "public, immutable";
}
# ACME challenge for certificate renewal
location /.well-known/acme-challenge/ {
root /var/www/html;
try_files $uri =404;
}
# Gzip compression
gzip on;
gzip_vary on;
gzip_min_length 1024;
gzip_proxied expired no-cache no-store private auth;
gzip_types text/plain text/css text/xml text/javascript application/x-javascript application/xml+rss application/javascript;
# Security - deny access to hidden files
location ~ /\. {
deny all;
}
}
EOF
echo "📤 Uploading configurations to server..."
scp /tmp/vscode-nginx.conf "$SERVER_USER@$SERVER_IP:/tmp/"
scp /tmp/forgejo-nginx.conf "$SERVER_USER@$SERVER_IP:/tmp/"
scp /tmp/mnemo_cards_main-nginx.conf "$SERVER_USER@$SERVER_IP:/tmp/"
echo ""
echo "⚙️ Installing configurations on server..."
ssh "$SERVER_USER@$SERVER_IP" << 'ENDSSH'
set -e
echo "🛑 Stopping nginx service..."
systemctl stop nginx
echo "🧹 Cleaning up old configurations..."
rm -f /etc/nginx/sites-enabled/vscode*
rm -f /etc/nginx/sites-enabled/forgejo*
rm -f /etc/nginx/sites-enabled/mnemo_cards*
echo "📋 Installing new configurations..."
mv /tmp/vscode-nginx.conf /etc/nginx/sites-available/vscode.mnemo-cards.online
mv /tmp/forgejo-nginx.conf /etc/nginx/sites-available/code.mnemo-cards.online
mv /tmp/mnemo_cards_main-nginx.conf /etc/nginx/sites-available/mnemo-cards.online
echo "🔗 Creating symbolic links..."
ln -sf /etc/nginx/sites-available/vscode.mnemo-cards.online /etc/nginx/sites-enabled/
ln -sf /etc/nginx/sites-available/code.mnemo-cards.online /etc/nginx/sites-enabled/
ln -sf /etc/nginx/sites-available/mnemo-cards.online /etc/nginx/sites-enabled/
echo "✅ Configurations installed"
echo ""
echo "📊 Checking nginx configuration syntax..."
if /usr/sbin/nginx -t; then
echo "✅ Configuration syntax is valid"
else
echo "❌ Configuration syntax error!"
echo "Restoring previous configurations..."
systemctl start nginx
exit 1
fi
echo ""
echo "🔄 Starting nginx service..."
systemctl start nginx
if systemctl is-active --quiet nginx; then
echo "✅ nginx started successfully"
else
echo "❌ nginx failed to start!"
systemctl status nginx --no-pager
exit 1
fi
echo ""
echo "📊 Checking SSL certificates..."
if [ -d "/etc/letsencrypt/live/mnemo-cards.online" ]; then
echo "✅ Let's Encrypt certificates found"
# Ensure correct permissions
chmod 755 /etc/letsencrypt/archive
chmod 755 /etc/letsencrypt/live
find /etc/letsencrypt -type d -exec chmod 755 {} \;
find /etc/letsencrypt -type f -exec chmod 644 {} \;
chmod 600 /etc/letsencrypt/archive/mnemo-cards.online/privkey*.pem
chmod 600 /etc/letsencrypt/live/mnemo-cards.online/privkey.pem
else
echo "⚠️ Let's Encrypt certificates not found"
fi
ENDSSH
echo ""
echo "✅ Done!"
echo ""
echo "🌐 Services should now be accessible at:"
echo " https://mnemo-cards.online/ (main web app)"
echo " https://code.mnemo-cards.online/ (Forgejo)"
echo " https://vscode.mnemo-cards.online/ (VSCode Server)"
echo ""
echo "🔑 VSCode Password: AGktOidxrah1KVC0"