Follow-up to #121: the repo line still used the live codename + "main", but
the openresty.org Debian tree only publishes up to bookworm (no trixie) and
uses the "openresty" component, not "main". Verified against the repo:
/package/debian/dists/ -> bookworm bullseye buster jessie stretch (no trixie)
bookworm Release -> Components: openresty
/package/ubuntu/dists/ -> noble jammy focal ... ; Components: main
So:
- Debian: distro = host codename when published (jessie..bookworm), else
bookworm (binary-compatible with trixie, same OpenSSL 3 era); component
"openresty".
- Ubuntu/Mint: distro = host codename; component "main" (unchanged).
Produces the working line on a trixie host:
deb [...] http://openresty.org/package/debian bookworm openresty
docs/installation.md manual steps updated to match.
Co-authored-by: Claude <noreply@anthropic.com>
Two issues on Debian 13 (Trixie):
1. apt's sequoia GPG backend now rejects SHA-1 signatures, and the OpenResty
repo signing key is still SHA-1 — so `apt-get update` fails to verify the
repo. When /usr/share/apt/default-sequoia.config is present (Debian 13+),
install a back-end override that extends the SHA-1 acceptance window to
2028 (the OpenResty key is expected to rotate to a stronger algorithm;
revisit before then). No-op on older Debian/Ubuntu. Idempotent on re-run.
2. The repo path was hardcoded to /package/ubuntu with the host codename,
which worked on older Debian by coincidence. trixie lives under
/package/debian, so pick the tree by distro ID (debian -> /package/debian,
else -> /package/ubuntu).
docs/installation.md: mirror both changes in the manual install steps, with a
note that install.sh applies the sequoia override automatically.
Co-authored-by: Claude <noreply@anthropic.com>
Every proxied request flows through one shared OpenResty location whose
behavior is chosen at request time from the host's Redis hash. Add per-host
controls as new Host fields enforced in Lua rather than static nginx config
(which can't key off a per-request variable):
- Rate limiting: per-client-IP token bucket via resty.limit.req
(ratelimit_enabled/rate/burst), backed by a new `ratelimit` shared dict.
- Response caching: opt-in per host via a global proxy_cache zone gated by
$skip_cache (respcache_enabled). Off by default; upstream Cache-Control
still honored.
- Custom/security headers: req_headers (upstream) + resp_headers (client) and
hsts_enabled, applied in access/header_filter phases.
- IP allow/deny CIDR lists via resty.ipmatcher (deny wins; non-empty allow is
default-deny).
New ops/nginx_conf/hostfeatures.lua holds the enforcement; proxy.conf's
access_by_lua string becomes a block that calls it, plus a header_filter block.
nodejs/utils/host_features.js is the pure, unit-tested normalize/validate layer
(header/CIDR parsing, range clamping, injection-safe values) applied in
routes/host.js and mirrored by the hosts.ejs edit form. install.sh gains the
ipmatcher rock, the cache dir, and the hostfeatures.lua symlink.
Per-host cache TTL is intentionally deferred (global default only) — see the
plan's limitations.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The installer is meant to be run by CI/CD with no human writes on prod, so
updates should mirror the repo exactly rather than refuse on local drift:
- Replace `git pull --ff-only` with fetch + `checkout -B origin/$BRANCH` +
`reset --hard` + `clean -fd` so the box always matches origin/$BRANCH.
- Set GIT_TERMINAL_PROMPT=0 so a missing/expired credential fails fast in CI
instead of hanging on a prompt.
- npm ci --omit=dev (lockfile, production-only) with a plain-install fallback.
- Allow REPO_URL / REPO_DIR / BRANCH to be overridden from the environment.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Rework the installer so it doubles as an updater:
- Idempotent throughout: `install -d` for dirs, apt source lists rewritten
in place, `gpg --dearmor --yes`, fallback cert generated only if missing,
repo cloned or fast-forwarded, and `ln -sfn` symlinks.
- Config is now symlinked straight from the checked-out repo instead of
wget-ing raw files from GitHub. /etc/openresty/{nginx.conf,autossl.conf,
sites-enabled/000-proxy}, the targetinfo.lua lualib, and the systemd unit
all point at $REPO_DIR/ops, so an update is just `git pull` + reload with
no re-copying. This also drops the external t42-common raw-file
dependency (autossl.conf / proxy.conf now come from this repo).
- Validate `openresty -t` before reloading so a bad config can't take the
proxy down; reload if running else restart.
- Fix prior bugs: stray `curl sudo apt-get update`, duplicate openssl cert
line, and `cd ../nodejs` (now cd $REPO_DIR/nodejs). Require root; add a
BRANCH override (default master).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>