75d10385d7030f4c4962eb86ada6c93be37b60ee
A fail2ban jail running inside a service's own LXC only ever sees this proxy's tailnet IP as the connection source, so it would end up banning the proxy itself. Detection needs to stay at the service's application log; banning needs to happen here, at the edge where public connections terminate. Adds a generic imtcp listener (port RSYSLOG_PORT, default 5514) that routes anything unclaimed by a later 50-<service>.conf into /var/log/remote/<sender-hostname>.log, plus logrotate with copytruncate so fail2ban never loses its file descriptor. No service-specific routing yet — that's one 50-<service>.conf per service, documented here for the next issue to follow. Refs #20
infra-scripts
Public infrastructure deployment scripts designed to be executed directly via curl | bash.
Philosophy
These scripts automate the deployment of personal infrastructure components. They are:
- Self-contained: No external dependencies beyond standard Debian packages
- Idempotent-ish: Safe to re-run (where possible)
- Curl-friendly: Designed for one-liner deployment from a fresh server
- Multi-OS: Supports Debian and Alpine-based deployments, chosen per-script based on that service's requirements
- Loopback by default: Services bind to
127.0.0.1; Tailscale handles the reverse proxy and TLS termination - Log hygiene: Every long-running service ships with a
logrotateconfig (no unbounded log files) - Console auto-login: Proxmox LXCs are configured for root auto-login on
tty1(fastpct enterand Web UI shell access) - Keep it simple: One script per service, plain bash, no frameworks — readability over cleverness
Available Scripts
| Script | Description | Usage |
|---|---|---|
proxy/install.sh |
Reverse proxy with Tailscale + Nginx Proxy Manager | curl -fsSL https://gitea.arnodo.fr/Damien/infra-scripts/raw/branch/main/proxy/install.sh | bash |
netlab/install.sh |
Network lab with ContainerLab | curl -fsSL https://gitea.arnodo.fr/Damien/infra-scripts/raw/branch/main/netlab/install.sh | bash |
gitea-runner/install.sh |
Gitea Act Runner on Alpine LXC (Proxmox) | bash -c "$(curl -fsSL https://gitea.arnodo.fr/Damien/infra-scripts/raw/branch/main/gitea-runner/install.sh)" |
openbao/install.sh |
OpenBao secrets manager on Alpine LXC (Proxmox) | bash -c "$(curl -fsSL https://gitea.arnodo.fr/Damien/infra-scripts/raw/branch/main/openbao/install.sh)" |
komodo/install.sh |
Komodo (Docker + MongoDB) on Alpine VM | bash -c "$(curl -fsSL https://gitea.arnodo.fr/Damien/infra-scripts/raw/branch/main/komodo/install.sh)" |
Requirements
- Fresh Debian 12/13 installation (proxy, netlab) or Proxmox VE host (gitea-runner, openbao) or Alpine VM (komodo)
- User with sudo privileges (do not run as root) — except gitea-runner, openbao, and komodo which run as root
- Internet access
Languages
Shell
100%