Files
waving-hands/deploy/setup-droplet.sh
T
Eric WagonerandClaude Fable 5.1 5de352db43 Credibility pass: one conflict check, one hostile list, one set of chrome
Duplicated logic and styling that had drifted apart is unified: the
gesture-sharing check, the hostile spell list, the enchanted test, the
plan limits, and the shared button, link, field and disabled styles.
Dead plumbing is gone: the always-true implemented flag, the unread
cast length, an unreachable guard, an impossible time-stop condition,
the unused sequence formatter and utility class, the template
placeholder. The counter-spell tests now put a counter-spell in front
of a spell, the test helpers live in one file, and the resolver's
sections are numbered in order. The deploy script's cache headers now
do what its comment says, and the README describes the screen rather
than listing features in the order they arrived.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-22 16:37:54 -04:00

69 lines
2.2 KiB
Bash
Executable File

#!/usr/bin/env bash
# One-time droplet setup. Run ON the droplet as root:
# bash setup-droplet.sh 'hands.kestrelsnest.social, waving-hands.<droplet-ip>.sslip.io'
# The argument is the Caddy site address line: one name, or several
# separated by commas. Every name must already resolve to this droplet.
# Waving Hands is a static site: Caddy serves the built files and terminates
# TLS. There is no application process to install or supervise.
set -euo pipefail
HOST="${1:?usage: setup-droplet.sh <hostname>}"
apt-get update -q
apt-get install -qy curl rsync
# Caddy (auto-HTTPS)
apt-get install -qy debian-keyring debian-archive-keyring apt-transport-https
curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/gpg.key' \
| gpg --dearmor -o /usr/share/keyrings/caddy-stable-archive-keyring.gpg
curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/debian.deb.txt' \
| tee /etc/apt/sources.list.d/caddy-stable.list
apt-get update -q && apt-get install -qy caddy
# Site directory, readable by Caddy.
mkdir -p /opt/waving-hands/build
chown -R root:caddy /opt/waving-hands
chmod -R g+rX /opt/waving-hands
# Caddy vhost: auto-TLS, security headers, static files. SvelteKit writes
# each route as <route>.html, so /rules is tried as /rules.html before
# falling back to the app shell. Hashed assets under _app/immutable are
# cached for a year; every other response is revalidated so a deploy shows
# up on the next load. The two header matchers are disjoint, so their order
# does not matter.
cat > /etc/caddy/Caddyfile <<CADDY
$HOST
root * /opt/waving-hands/build
encode gzip zstd
header {
Strict-Transport-Security "max-age=31536000"
X-Content-Type-Options "nosniff"
X-Frame-Options "DENY"
Referrer-Policy "no-referrer"
}
@immutable path /_app/immutable/*
header @immutable Cache-Control "public, max-age=31536000, immutable"
@mutable not path /_app/immutable/*
header @mutable Cache-Control "no-cache"
log {
output file /var/lib/caddy/access.log {
roll_size 10MiB
roll_keep 30
}
}
try_files {path} {path}.html /index.html
file_server
CADDY
systemctl reload caddy
# Firewall: ssh + web only.
ufw allow OpenSSH
ufw allow 80/tcp
ufw allow 443/tcp
ufw --force enable
echo "droplet ready: now run deploy/deploy.sh <ip> from your machine"