This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| computing:hpb-talk [2026/10/10 05:12] – oemb1905 | computing:hpb-talk [2026/10/10 05:21] (current) – oemb1905 | ||
|---|---|---|---|
| Line 49: | Line 49: | ||
| ==== 2. Quadlet ==== | ==== 2. Quadlet ==== | ||
| - | Create the quadlet for monitoring and starting/ | + | Create the quadlet for monitoring and starting/ |
| - | + | ||
| - | File: '' | + | |
| < | < | ||
| - | systemctl --user disable --now container-talk-hpb.service 2>/ | ||
| - | rm -f ~/ | ||
| - | podman rm -f talk-hpb | ||
| - | |||
| mkdir -p ~/ | mkdir -p ~/ | ||
| cat > ~/ | cat > ~/ | ||
| Line 87: | Line 81: | ||
| sleep 25 | sleep 25 | ||
| </ | </ | ||
| - | |||
| - | '' | ||
| ==== 3. Extra Nextcloud backends (after every start) ==== | ==== 3. Extra Nextcloud backends (after every start) ==== | ||
| - | '' | + | |
| + | The HPB container can only be built with one endpoint when it is updated, so the following is needed to add xx amount of endpoints to use the HPB with: | ||
| < | < | ||
| Line 104: | Line 97: | ||
| </ | </ | ||
| - | Expected: | + | When you run this, you get something like: |
| < | < | ||
| Line 124: | Line 117: | ||
| ==== 4. Verify ==== | ==== 4. Verify ==== | ||
| + | |||
| + | Once your back-ends are all specified, let's verify the service is healthy and the api endpoint is reachable: | ||
| + | |||
| < | < | ||
| systemctl --user is-active container-talk-hpb.service | systemctl --user is-active container-talk-hpb.service | ||
| Line 130: | Line 126: | ||
| </ | </ | ||
| - | Expect | + | We should see something like '' |
| ==== 5. Upgrade script ==== | ==== 5. Upgrade script ==== | ||
| - | ''/ | + | |
| + | Let's create an upgrade script at '' | ||
| < | < | ||
| #!/bin/bash | #!/bin/bash | ||
| set -euo pipefail | set -euo pipefail | ||
| + | export XDG_RUNTIME_DIR=/ | ||
| + | export DBUS_SESSION_BUS_ADDRESS=unix: | ||
| podman pull ghcr.io/ | podman pull ghcr.io/ | ||
| Line 159: | Line 158: | ||
| </ | </ | ||
| - | Run it as '' | + | If your curl output is unhealthy, stop and debug before proceeding. |
| - | < | + | ==== 6. Apache reverse proxy (root) ==== |
| - | su - worker -c '/ | + | |
| - | </ | + | |
| - | Do not ''sudo -u worker'' | + | We can now setup our reverse proxy and associated virtual hosts and Let's Encrypt cert: |
| - | ==== 6. Apache reverse proxy (root) ==== | ||
| < | < | ||
| - | a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl | + | sudo a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl authz_host |
| + | sudo certbot certonly --apache -d talk.haacksnetworking.org | ||
| </ | </ | ||
| - | ''/ | + | Inside |
| < | < | ||
| Line 180: | Line 177: | ||
| RewriteRule ^ https:// | RewriteRule ^ https:// | ||
| </ | </ | ||
| + | </ | ||
| + | And, inside the TLS virtual host, '' | ||
| + | |||
| + | < | ||
| < | < | ||
| ServerName talk.haacksnetworking.org | ServerName talk.haacksnetworking.org | ||
| Line 201: | Line 202: | ||
| </ | </ | ||
| </ | </ | ||
| + | |||
| + | Once the virtual hosts are built, let's enable it, check the config, and then check the endpoint. | ||
| < | < | ||
| Line 209: | Line 212: | ||
| </ | </ | ||
| - | Clients use '' | + | Check your output and make sure everything is accessible and running. If not, debug until it works. FYI, the endpoint for clients is '' |
| - | ==== Facts ==== | ||
| - | * | ||
| - | --- // | + | --- // |