Update fickit
This commit is contained in:
parent
a499d23149
commit
20df137eeb
12 changed files with 514 additions and 98 deletions
|
|
@ -1,6 +1,5 @@
|
|||
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDO/3qKhSUbGYZBVraFo68oScJahRDNQfG+uwDQlLv7g nemunaire@khonsou
|
||||
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDqEniilVnT/hKEpxe59KvbUoCdGvEUMoVLzwkwpzSr2MIFTddQHXDcxL7+YQhiKrd3veZgR8IWGsuCDy8lEZumpY60omgaQYbpFQHeybC/tFefsMWoHqEeV69CmriNBtVoBPQyLRWZCt0exvJ269POHfyWOJixI3yf9J1En9JV1TzEvU6J7+GV6bLXEd5WghuXxcwRVQHzwnBFXOXOkiGuOqnDix0F5WZTxo5BsM2tbK6kbsT9k4TyfBYl1gA2dqB+swrKk83F9skbPTWZAX7Z5dmJ/ZBV7u+t4lk6vbjVhjSpcD3LhoqgIVb6HfM3Pidkm5E/tA0TxCubLb+k/hZL nico.chari@gmail.com
|
||||
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDmSDalpcOjMVeQhhs8TOBbE36gkADj30lNMvmHncVzGZMQOjcLDC6dnkCuwLyEo+Ne/OAyeLLvv8YyCQpj4Ib2nqARdZYOeh622pwkUfEqlKT9umeju+TQrFNBUhkqN49vbTEbgmpxCsoRonPFgFgRncldQFD7vsNdnkGmf1KcRk5UbGI4AYWPDRJ+0uEOKjxY+GAL+r1DyeII53OXaFp+AOqGtDqaS6JrmUVk1Zj/7hX+3WZ3F1xcpYnUr6bnyU1rh7cbU+3ZEU/CYYVSJGLzm6V3ymgLas/mAAFlopXwjhiYRQgwcXKRCnijEeHwOUlDShKIYfLoMh/he0xi/R8eVLfH0HV5JDhnf2n3UxDQ5Mfl1Mbsjt2OTl4Gmd01rhQHAoWmhjPDDlGPQoGOSTdOYS5HDlv4yhfxq0QAMsTcT6uOT1gajEmbv/36KTOWc7EyT1rdg/qxHVF7UVz9EYo/gIaeMZfLaqX2gkRndFStIWVQ+kJLPZmveqIH2MVtPc0YuDvd3H6TLNrHZzMvX6+YbeP0NDU726hjwFQSeBtjEfVHib+EffVNUHRNoKhzq6IVh7/7pTILrh4dnjUvEUiZg6XEa97VYO9/ixe8ci6qBeO2HtovZh4IX1zaXSKJqcXeOBOXfhyA2BXDD/XXzLIWyV2JoojGMBiRMThs8jCYKw== panev_s@epita.fr
|
||||
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCsi6Kpm8hpYxqDlfyjjs/iWfegzXJuJUecJ+Dpl+8ZWYvKjoyU+vwSx4cqOOlduMQF4pYOgf35OywgeUXS/GuwZo86hAr1yzRBl6/SzC+K+vkQ7Ye/0E6eRUDHqq4t6eqWHqsCafm11PhCj53ibyTH6NYNBRS85Z3DKFj4SwMuIhFX6tpLoXCQFLY0zB3JzQymaX/FK48Am5rZ9BLoZFM+9jbr5yvb4u/nijdfYmcFNom0AjZOzYE3RVGAil63LyvibVHkfbJj/DAvCCtkU7B6q8YpwjFm1kbGcb4sORLAzBNv/ayJOYVxAKK3kHDxR5MBYZQ9DsYB5Tn4qU+VtRSd sysy@archlinux
|
||||
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDFyNF5TSmgyQLopCFs1+PvGnQM2P9GaERC087gbWueBvEP0s5NkPW5u10fhBHk+eUo2M/yXSgjG9+vtETddSITzoRABoXTEXnSP1REcjAeWbp3oS6+QrJQ6Fy4CR/9V5pd74d86NZ+f0nldFXgHOLk4Y2XxAOnxZZCzQPOXL8ChBEmb9vK/MxyOq4sWEPjJLQIzn/Bj/BHqBpoDmKfzq3sp9mxjXTYCcH9FDwDU0vvtPZ25r6EKtRQuVbFviTAkSawvLJtj25NEX1hrGE7oZSahbng4oSgkd/gCjsivptE5DeFLQRTqvdv6H9QyIRvT+mq1KNCBsuaCBjGwdDgWxe8nRyWAe3bUbha87rpkGRz5/+HaokKVt0cnXD1wjapByvTQDwAYVLEfpsodruGuZl26nEJqkKRH7Oxp9YxBGUO9xGJHoXJTCZUdCuKDH8QuPHYiAXZH8aqKD8EmgwTrvgFvKzDE6zF88Eb9WBPbr5MpLX2nj5UpZEyb2KDOtYAz9379dRD3jgBl7EY0OdqrfRitk3sucmgDpMQHV3C1vCW4OdZ6Pydg4LarGSTNz6cUCzRZehfxJh4XoLhHxwtGVdgAEapd9uVFDrIJAVnpW0le778x29SpPLRg0mEFCHBg0VEHLA8N8vct9QIAMf+tR/Tno89/ESNag5x7SPtOlb5Tw== vincae@vincae-Aspire-V5-561G
|
||||
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDEO91xtu/9jLPjEqFChQ7hB8jgDldN07Qh5Du35aqwFIvsKbF5RDsRDom/IxvrX+gVm2faTtxECEu+xRahw+19OsE7VPSCBr8IfvuuzoiR0zXaiGLubzx1nmAZdHESRuhPO6UqWX1FbcPkKeUDkwfKkCEUThYA600SKrPbYd+2jhFM7zw65OQq6RyLc+57ySodG+O8TjZo999kBGuhsJx+t/U9B6bjP5htDPk35eahReDeDZrAO9BYuFilyYFgd2ckf9LvqS/UHQZgj1kXFAqzZjsA9hVejN1hMJdKo9OrU9CTIiJDqEqKxGSzjguXBYa7MjpYfOcMdvdxwVRuerUl mathilde@debian
|
||||
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQC19G9HGGZevJKeoDeew2VO6hbpWI71SBqemQUvYnD+WLureahuyCZYeJCalyU9QimsUTyQp6WGqwhh8I9x+K6gss79ITOUVt6yFbmj2Hdm00qJhPElduk+Jg0dTydgeGj83FJExz37dfWTq0Sp2hb4zfxoIH/BT81M+gZpQAQ3f9DIsgHlIE+/x6wLSWOcRVCOeX4YreIVXG75HaKmpY3p2gGuHtmrmuYdgLinihARKih4IvBFOMl0oC5y2AOwZP4AXvU0amc2Pkcn+Q/vzvu0Wf8CVH2ZdywC6HUIJpF41qIDM582ddwgxK1Qj0e7CDfzYRy0ChejfKIIksTDtYB4AkGRWTQ57onxwvDrAVXFq4OP76a9nD+oz7Fowc7VbqP9llJDU8wHWavsAsvbWCcLZ86kOvbbveHgBs23/L4cPwcyA7euta3j8wcW6In+eyMVhy5vs0eQFtzh9tbApFDhCUDdZAdBN5avEpjltizMy0wpEBZynafUO+goholH3t96fdJzeF+RWyzH8po0sNEXQeFJi8gGLgkqdJwWnKnJy1gb4zkemgs8T1B0Uy6wUVFaXNKEAy7gCtIF+dlFxy2pyKar9cITNds2V8cSuw5NM4z66aNB9ONdkU3ZkFQi8nyiJAvVmVhSt9JOhjGHNbGtHeN3Gaz0qW1EtM0GAy8mIw== segharish@gmail.com
|
||||
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC1TdooqihPGLSGp9LZxU044d+ULhDb0sjoif5DsajyXH7qpVfR8K3HNs3dVcvenyZwA9+tJomEFMFTDDg+03peQ4KYLjpdtRR2wofGCjyNcRcmzcvpi428c4JBOdNxiPkBN/XaiZUJzXZL4fEqm396ZLnyfQ6ns9flKV0zJJt9C98+TXqG01H35tcQamwZMDl1KMrIGCRvywdu+wqB4Z2AkBoI+VH8t2AqXcyKi7ltGZTzbEEItFx4HqlemxgcaM86jho/WlsCvF3AHr9sDJlO93+SuX6gX4sZmRo00KJU9ss/w1FpYjX8crOlr1Ze7YUU/wmTpzzhje50ZNhSRR9R thibaut.passilly@MacBook-Pro.local
|
||||
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCWrRHAMkZolWFm3jTo0wcBUUJVNKlfO66S2z731nsiQb1r0pQjZDsZjs1YKPp92F2XncQXFUFujOPd4dNT8vkYOKLm6FeDCU8DR9omRwYQq6ZkJ65ySYCLyaKqrH9nKWb2nessAmo1lWzj+K9UmsZeV5tjguxdlpTCod7EHByrRSNTOEURzW96CDsr2IGl2h7XmUDOnMhiTn4y2Qq4sAz0BisP1Y9wBFkLgqYOAVmc+3r41W1w8oCcy2jyGaGp4Bo/mNZdHyozGrEvYXl/uJvOgdTXYufqb4oosoMLrakkEvINybyqspKKX2RNx6HitYdTYNzsZIBHKh70KIDmVvLL ron@CyberWeasley
|
||||
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCkLmYDbAHx+jCPS4XLQDwlgr1WbZ6oyHBYNOJCm8ektdHPrXUuXwjOAns+eieUdH+AS8/Jrgds31qne5wOHesA8vxilHRsJdJPZgndKntAky7xrfr9W7rYGNTBSMn7tiUBOWEg5uz5px/NTmtIdIhkDabG760yyDUNOpvm62MFNIjqixGpVWSjJvf/buKbCZVTq8Foqs40v8HwMaR4Z76Wvtl982B7BBgg1sf34XiN62Q2ej/Heqp+qxlMolTENQ+ezTZcDu39cBO/AV9FLhQ5Faz0SKPXWLz6nksvUMffWEajPnvJMnw/RjXxpW09ZAJuWoi4Xn1LDTTgToVmUu9B mike@IMiykyRo
|
||||
|
|
|
|||
|
|
@ -1,8 +1,10 @@
|
|||
default-lease-time 600;
|
||||
max-lease-time 7200;
|
||||
authoritative;
|
||||
option subnet-mask 255.255.255.0;
|
||||
option broadcast-address 172.23.42.255;
|
||||
option routers 172.23.42.254;
|
||||
option domain-name-servers 9.9.9.9, 1.1.1.1;
|
||||
option rfc3442-classless-static-routes code 121 = array of integer 8;
|
||||
option ms-classless-static-routes code 249 = array of integer 8;
|
||||
option rfc3442-classless-static-routes 32, 163, 5, 55, 58, 172, 23, 42, 1;
|
||||
|
|
|
|||
4
configs/fic-auth-demo.conf
Normal file
4
configs/fic-auth-demo.conf
Normal file
|
|
@ -0,0 +1,4 @@
|
|||
auth_basic "Restricted";
|
||||
auth_basic_user_file /srv/PKI/shared/ficpasswd;
|
||||
|
||||
set $team "$remote_user";
|
||||
188
configs/nginx-demo.conf
Normal file
188
configs/nginx-demo.conf
Normal file
|
|
@ -0,0 +1,188 @@
|
|||
proxy_cache_path /var/cache/nginx levels=1:2 keys_zone=STATIC:10m inactive=24h max_size=1g;
|
||||
proxy_connect_timeout 1s;
|
||||
|
||||
server {
|
||||
listen 80 default;
|
||||
|
||||
rewrite ^ https://$server_name$request_uri permanent;
|
||||
}
|
||||
|
||||
server {
|
||||
listen 443 default ssl http2;
|
||||
|
||||
ssl_protocols TLSv1.2 TLSv1.3;
|
||||
ssl_dhparam /etc/nginx/ssl/dhparams-4096.pem;
|
||||
ssl_prefer_server_ciphers on;
|
||||
|
||||
ssl_certificate /etc/nginx/ssl/fullchain.pem;
|
||||
ssl_certificate_key /etc/nginx/ssl/privkey.pem;
|
||||
|
||||
root /srv/htdocs-frontend/;
|
||||
|
||||
error_page 401 /welcome.html;
|
||||
error_page 403 404 /e404.html;
|
||||
error_page 413 /e413.html;
|
||||
error_page 500 502 504 /e500.html;
|
||||
|
||||
add_header Strict-Transport-Security max-age=31536000;
|
||||
|
||||
location = / {
|
||||
include fic-auth.conf;
|
||||
}
|
||||
location = /index.html {
|
||||
include fic-auth.conf;
|
||||
}
|
||||
location = /welcome.html {
|
||||
internal;
|
||||
if ($http_accept ~ "^application/json") {
|
||||
rewrite ^/(.*).html$ /$1.json;
|
||||
}
|
||||
}
|
||||
location = /e404.html {
|
||||
internal;
|
||||
if ($http_accept ~ "^application/json") {
|
||||
rewrite ^/(.*).html$ /$1.json;
|
||||
}
|
||||
}
|
||||
location = /e413.html {
|
||||
internal;
|
||||
if ($http_accept ~ "^application/json") {
|
||||
rewrite ^/(.*).html$ /$1.json;
|
||||
}
|
||||
}
|
||||
location = /e500.html {
|
||||
internal;
|
||||
if ($http_accept ~ "^application/json") {
|
||||
rewrite ^/(.*).html$ /$1.json;
|
||||
}
|
||||
}
|
||||
|
||||
location ~ ^/[A-Z] {
|
||||
include fic-auth.conf;
|
||||
|
||||
rewrite ^/.*$ /index.html;
|
||||
}
|
||||
|
||||
location /edit {
|
||||
include fic-auth.conf;
|
||||
|
||||
rewrite ^/.*$ /index.html;
|
||||
}
|
||||
location /rank {
|
||||
include fic-auth.conf;
|
||||
|
||||
rewrite ^/.*$ /index.html;
|
||||
}
|
||||
location /tags/ {
|
||||
include fic-auth.conf;
|
||||
|
||||
rewrite ^/.*$ /index.html;
|
||||
}
|
||||
location /register {
|
||||
include fic-auth.conf;
|
||||
|
||||
rewrite ^/.*$ /index.html;
|
||||
}
|
||||
location /rules {
|
||||
include fic-auth.conf;
|
||||
|
||||
rewrite ^/.*$ /index.html;
|
||||
}
|
||||
|
||||
location /files/ {
|
||||
alias /srv/FILES/;
|
||||
sendfile on;
|
||||
tcp_nodelay on;
|
||||
}
|
||||
|
||||
location /wait.json {
|
||||
include fic-auth.conf;
|
||||
|
||||
root /srv/TEAMS/$team/;
|
||||
expires epoch;
|
||||
add_header Cache-Control no-cache;
|
||||
}
|
||||
location /stats.json {
|
||||
root /srv/TEAMS/;
|
||||
expires epoch;
|
||||
add_header Cache-Control no-cache;
|
||||
}
|
||||
location /my.json {
|
||||
include fic-auth.conf;
|
||||
|
||||
root /srv/TEAMS/$team/;
|
||||
expires epoch;
|
||||
add_header Cache-Control no-cache;
|
||||
|
||||
if (!-f /srv/startingblock/started) {
|
||||
rewrite ^/.* /wait.json;
|
||||
}
|
||||
}
|
||||
location = /events.json {
|
||||
root /srv/TEAMS/;
|
||||
expires epoch;
|
||||
add_header Cache-Control no-cache;
|
||||
}
|
||||
location = /teams.json {
|
||||
root /srv/TEAMS/;
|
||||
expires epoch;
|
||||
add_header Cache-Control no-cache;
|
||||
}
|
||||
location = /themes.json {
|
||||
root /srv/TEAMS/;
|
||||
expires epoch;
|
||||
add_header Cache-Control no-cache;
|
||||
}
|
||||
location = /settings.json {
|
||||
root /srv/SETTINGS/;
|
||||
expires epoch;
|
||||
add_header X-FIC-time $msec;
|
||||
add_header Cache-Control no-cache;
|
||||
}
|
||||
|
||||
location /submit/ {
|
||||
include fic-auth.conf;
|
||||
|
||||
rewrite ^/submit/(.*)$ /submission/$team/$1 break;
|
||||
|
||||
proxy_pass http://frontend:8080/;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_redirect off;
|
||||
}
|
||||
location /submit/name {
|
||||
include fic-auth.conf;
|
||||
|
||||
rewrite ^/submit/.*$ /chname/$team break;
|
||||
|
||||
proxy_pass http://frontend:8080/;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_redirect off;
|
||||
}
|
||||
location /registration {
|
||||
include fic-auth.conf;
|
||||
|
||||
rewrite ^/registration /registration/$team break;
|
||||
|
||||
proxy_pass http://frontend:8080;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_redirect off;
|
||||
}
|
||||
location /openhint/ {
|
||||
include fic-auth.conf;
|
||||
|
||||
rewrite ^/openhint/(.*)$ /openhint/$team/$1 break;
|
||||
|
||||
proxy_pass http://frontend:8080/;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_redirect off;
|
||||
}
|
||||
location /wantchoices/ {
|
||||
include fic-auth.conf;
|
||||
|
||||
rewrite ^/wantchoices/(.*)$ /wantchoices/$team/$1 break;
|
||||
|
||||
proxy_pass http://frontend:8080/;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_redirect off;
|
||||
}
|
||||
}
|
||||
8
configs/update_imgs.sh
Normal file
8
configs/update_imgs.sh
Normal file
|
|
@ -0,0 +1,8 @@
|
|||
#!/bin/sh
|
||||
|
||||
mkdir -p /boot/imgs
|
||||
|
||||
for img in fickit-kernel fickit-boot-initrd.img fickit-frontend-squashfs.img fickit-backend-squashfs.img fickit-update-initrd.img
|
||||
do
|
||||
wget -O "/boot/imgs/${img}" "10.10.10.6/${img}"
|
||||
done
|
||||
Reference in a new issue