Duplicated logic and styling that had drifted apart is unified: the gesture-sharing check, the hostile spell list, the enchanted test, the plan limits, and the shared button, link, field and disabled styles. Dead plumbing is gone: the always-true implemented flag, the unread cast length, an unreachable guard, an impossible time-stop condition, the unused sequence formatter and utility class, the template placeholder. The counter-spell tests now put a counter-spell in front of a spell, the test helpers live in one file, and the resolver's sections are numbered in order. The deploy script's cache headers now do what its comment says, and the README describes the screen rather than listing features in the order they arrived. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
69 lines
2.2 KiB
Bash
Executable File
69 lines
2.2 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# One-time droplet setup. Run ON the droplet as root:
|
|
# bash setup-droplet.sh 'hands.kestrelsnest.social, waving-hands.<droplet-ip>.sslip.io'
|
|
# The argument is the Caddy site address line: one name, or several
|
|
# separated by commas. Every name must already resolve to this droplet.
|
|
# Waving Hands is a static site: Caddy serves the built files and terminates
|
|
# TLS. There is no application process to install or supervise.
|
|
set -euo pipefail
|
|
HOST="${1:?usage: setup-droplet.sh <hostname>}"
|
|
|
|
apt-get update -q
|
|
apt-get install -qy curl rsync
|
|
|
|
# Caddy (auto-HTTPS)
|
|
apt-get install -qy debian-keyring debian-archive-keyring apt-transport-https
|
|
curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/gpg.key' \
|
|
| gpg --dearmor -o /usr/share/keyrings/caddy-stable-archive-keyring.gpg
|
|
curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/debian.deb.txt' \
|
|
| tee /etc/apt/sources.list.d/caddy-stable.list
|
|
apt-get update -q && apt-get install -qy caddy
|
|
|
|
# Site directory, readable by Caddy.
|
|
mkdir -p /opt/waving-hands/build
|
|
chown -R root:caddy /opt/waving-hands
|
|
chmod -R g+rX /opt/waving-hands
|
|
|
|
# Caddy vhost: auto-TLS, security headers, static files. SvelteKit writes
|
|
# each route as <route>.html, so /rules is tried as /rules.html before
|
|
# falling back to the app shell. Hashed assets under _app/immutable are
|
|
# cached for a year; every other response is revalidated so a deploy shows
|
|
# up on the next load. The two header matchers are disjoint, so their order
|
|
# does not matter.
|
|
cat > /etc/caddy/Caddyfile <<CADDY
|
|
$HOST
|
|
|
|
root * /opt/waving-hands/build
|
|
encode gzip zstd
|
|
|
|
header {
|
|
Strict-Transport-Security "max-age=31536000"
|
|
X-Content-Type-Options "nosniff"
|
|
X-Frame-Options "DENY"
|
|
Referrer-Policy "no-referrer"
|
|
}
|
|
@immutable path /_app/immutable/*
|
|
header @immutable Cache-Control "public, max-age=31536000, immutable"
|
|
@mutable not path /_app/immutable/*
|
|
header @mutable Cache-Control "no-cache"
|
|
|
|
log {
|
|
output file /var/lib/caddy/access.log {
|
|
roll_size 10MiB
|
|
roll_keep 30
|
|
}
|
|
}
|
|
|
|
try_files {path} {path}.html /index.html
|
|
file_server
|
|
CADDY
|
|
systemctl reload caddy
|
|
|
|
# Firewall: ssh + web only.
|
|
ufw allow OpenSSH
|
|
ufw allow 80/tcp
|
|
ufw allow 443/tcp
|
|
ufw --force enable
|
|
|
|
echo "droplet ready: now run deploy/deploy.sh <ip> from your machine"
|