From 165b5e6e1e0180b012a37ad95f7aa841e2377f0d Mon Sep 17 00:00:00 2001 From: Ben Sherriff Date: Sat, 12 Apr 2025 08:57:27 -0400 Subject: [PATCH] Fixed ca cert issue on api --- .env | 22 +- Makefile | 6 +- api/Dockerfile | 2 +- api/src/main.rs | 9 +- api/src/metars/model.rs | 2 +- bruno/bruno.json | 16 +- bruno/environments/Localhost.bru | 5 +- docker-compose.yml | 21 +- httpd/Dockerfile | 4 - httpd/aviation.conf | 21 - httpd/httpd.conf | 554 -------------------------- nginx/Dockerfile | 3 + nginx/nginx.conf | 34 ++ nginx/templates/default.conf.template | 56 +++ scripts/generate_cert.sh | 69 +++- ui/src/App.tsx | 9 +- 16 files changed, 211 insertions(+), 622 deletions(-) delete mode 100644 httpd/Dockerfile delete mode 100644 httpd/aviation.conf delete mode 100644 httpd/httpd.conf create mode 100644 nginx/Dockerfile create mode 100644 nginx/nginx.conf create mode 100644 nginx/templates/default.conf.template diff --git a/.env b/.env index 69f6034..5f2dbe8 100644 --- a/.env +++ b/.env @@ -1,11 +1,12 @@ RUST_LOG=warn,api=info -HTTPD_DOMAIN=localhost -HTTPD_PROTOCOL=http -HTTPD_PORT=8080 -HTTPD_MINIO_HOST=host.docker.internal -HTTPD_API_HOST=host.docker.internal -HTTPD_UI_HOST=host.docker.internal +NGINX_HOST=localhost +NGINX_PROTOCOL=https +NGINX_HTTP_PORT=8080 +NGINX_HTTPS_PORT=8443 +NGINX_MINIO_HOST=host.docker.internal +NGINX_API_HOST=host.docker.internal +NGINX_UI_HOST=host.docker.internal POSTGRES_HOST=localhost POSTGRES_USER=aviation @@ -23,7 +24,7 @@ MINIO_BUCKET=aviation MINIO_PROTOCOL=http MINIO_PORT=9000 MINIO_PORT_INTERNAL=9001 -MINIO_BROWSER_REDIRECT_URL=${HTTPD_PROTOCOL}://${HTTPD_DOMAIN}:${HTTPD_PORT}/minio/ +MINIO_BROWSER_REDIRECT_URL=${NGINX_PROTOCOL}://${NGINX_HOST}:${NGINX_HTTPS_PORT}/minio/ UI_PROTOCOL=http UI_PORT=3000 @@ -32,7 +33,12 @@ API_PROTOCOL=http API_HOST=0.0.0.0 API_PORT=5000 -VITE_API_URL=${HTTPD_PROTOCOL}://${HTTPD_DOMAIN}:${HTTPD_PORT}/api +SSL_CA_NAME=ca +SSL_CA_PATH=../ssl/${SSL_CA_NAME}.pem +SSL_CERT_PATH=../ssl/localhost.crt +SSL_CERT_KEY_PATH=../ssl/localhost.key + +VITE_API_URL=${NGINX_PROTOCOL}://${NGINX_HOST}:${NGINX_HTTPS_PORT}/api ENVIRONMENT=development ADMIN_EMAIL=admin@example.com diff --git a/Makefile b/Makefile index 316e6c6..e81552c 100644 --- a/Makefile +++ b/Makefile @@ -96,7 +96,7 @@ docker-refresh: docker-clean up-backend ## Refresh the database refresh: docker-refresh build: version=$(if $(v),$(v),latest) -build: folder=$(if $(f),$(f),httpd) +build: folder=$(if $(f),$(f),nginx) build: image=aviation-${folder}:${version} build: ## Build a specific docker image (`make build f=httpd`) docker buildx build \ @@ -110,6 +110,6 @@ build: ## Build a specific docker image (`make build f=httpd`) docker-build: build -cert: domain=$(if $(d),$(d),aviation.bensherriff.com) +cert: domain=$(if $(d),$(d),${NGINX_HOST}) cert: ## Generate a cert for the given domain - @./scripts/generate_cert.sh ${domain} + ./scripts/generate_cert.sh ${domain} diff --git a/api/Dockerfile b/api/Dockerfile index 1d5c83e..3ad5ad1 100644 --- a/api/Dockerfile +++ b/api/Dockerfile @@ -16,7 +16,7 @@ RUN cargo build --release # ========= FROM debian:bookworm-slim AS runtime WORKDIR /api -RUN apt-get update && apt-get install -y openssl libpq-dev +RUN apt-get update && apt-get install -y openssl libpq-dev ca-certificates USER root COPY --from=builder /builder/target/release/api /usr/local/bin/api diff --git a/api/src/main.rs b/api/src/main.rs index 097b551..1c47102 100644 --- a/api/src/main.rs +++ b/api/src/main.rs @@ -3,6 +3,7 @@ use std::time::Duration; use actix_cors::Cors; use actix_web::{App, HttpServer, middleware::Logger, web}; use dotenv::from_filename; +use reqwest::Certificate; use crate::auth::hash; use crate::users::{User, ADMIN_ROLE}; @@ -57,10 +58,14 @@ async fn main() -> Result<(), Box> { } } + let certificate_path = env::var("SSL_CA_PATH")?; + let certificate_data = std::fs::read(certificate_path)?; + let certificate = Certificate::from_pem(&certificate_data)?; + let client = reqwest::Client::builder() .timeout(Duration::from_secs(10)) - .no_proxy() - .danger_accept_invalid_certs(true) + .add_root_certificate(certificate) + .tls_built_in_root_certs(true) .build() .expect("Failed to create reqwest client"); diff --git a/api/src/metars/model.rs b/api/src/metars/model.rs index 72e70bd..766e95d 100644 --- a/api/src/metars/model.rs +++ b/api/src/metars/model.rs @@ -847,7 +847,7 @@ impl Metar { } async fn get_remote_metars(client: &Client, icaos: &[&str]) -> ApiResult> { - let base_url = std::env::var("AVIATION_WEATHER_URL").expect("GOV_API_URL must be set"); + let base_url = std::env::var("AVIATION_WEATHER_URL").expect("AVIATION_WEATHER_URL must be set"); // Query the remote API for the missing METAR data 10 at a time let icao_chunks = icaos .chunks(10) diff --git a/bruno/bruno.json b/bruno/bruno.json index e5e59ad..03175b5 100644 --- a/bruno/bruno.json +++ b/bruno/bruno.json @@ -5,5 +5,19 @@ "ignore": [ "node_modules", ".git" - ] + ], + "size": 0.0026407241821289062, + "filesCount": 14, + "clientCertificates": { + "enabled": true, + "certs": [ + { + "domain": "localhost", + "type": "cert", + "certFilePath": "../ssl/localhost.crt", + "keyFilePath": "../ssl/localhost.key", + "passphrase": "" + } + ] + } } \ No newline at end of file diff --git a/bruno/environments/Localhost.bru b/bruno/environments/Localhost.bru index 4796118..4fc287e 100644 --- a/bruno/environments/Localhost.bru +++ b/bruno/environments/Localhost.bru @@ -1,6 +1,3 @@ vars { - BASE_URL: http://localhost:8080 - ~BASE_URL: http://localhost:5000 - ~BASE_URL: http://127.0.0.1:5000 - ~BASE_URL: http://[::1]:5000 + BASE_URL: https://localhost:8443 } diff --git a/docker-compose.yml b/docker-compose.yml index 05fd805..9afbc35 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -9,15 +9,23 @@ x-restart: &default_restart name: aviation services: - httpd: - image: aviation-httpd:latest - container_name: aviation-httpd + nginx: +# image: nginx + image: aviation-nginx:latest + container_name: aviation-nginx build: - context: ./httpd + context: ./nginx dockerfile: Dockerfile env_file: *env + environment: + SSL_CERT_PATH: /etc/nginx/ssl/localhost.crt + SSL_CERT_KEY_PATH: /etc/nginx/ssl/localhost.key + NGINX_HOST: ${NGINX_HOST:-localhost} ports: - - "${HTTPD_PORT:-8080}:80" + - "${NGINX_HTTP_PORT:-8080}:80" + - "${NGINX_HTTPS_PORT:-8443}:443" + volumes: + - ./ssl:/etc/nginx/ssl/ networks: - frontend - backend @@ -89,12 +97,15 @@ services: env_file: *env environment: API_HOST: 0.0.0.0 + SSL_CA_PATH: /ssl/ca.pem POSTGRES_HOST: aviation-postgres POSTGRES_PORT: 5432 REDIS_HOST: aviation-redis REDIS_PORT: 6379 MINIO_HOST: aviation-minio MINIO_PORT: 9000 + volumes: + - ./ssl:/ssl ports: - "${API_PORT:-5000}:5000" depends_on: diff --git a/httpd/Dockerfile b/httpd/Dockerfile deleted file mode 100644 index c6586ad..0000000 --- a/httpd/Dockerfile +++ /dev/null @@ -1,4 +0,0 @@ -FROM httpd:2.4 - -COPY httpd.conf /usr/local/apache2/conf/httpd.conf -COPY aviation.conf /usr/local/apache2/conf/extra/aviation.conf \ No newline at end of file diff --git a/httpd/aviation.conf b/httpd/aviation.conf deleted file mode 100644 index e6629c3..0000000 --- a/httpd/aviation.conf +++ /dev/null @@ -1,21 +0,0 @@ - - ServerName aviation.bensherriff.com - - ProxyPreserveHost On - LogLevel warn - - #SSLEngine on - #SSLCertificateFile /path/to/your/cert.pem - #SSLCertificateKeyFile /path/to/your/privkey.pem - - #Protocols h2 http/1.1 - - ProxyPass "/api" "${API_PROTOCOL}://${HTTPD_API_HOST}:${API_PORT}/api" - ProxyPassReverse "/api" "${API_PROTOCOL}://${HTTPD_API_HOST}:${API_PORT}/api" - - ProxyPass "/minio" "${MINIO_PROTOCOL}://${HTTPD_MINIO_HOST}:${MINIO_PORT_INTERNAL}" - ProxyPassReverse "/minio" "${MINIO_PROTOCOL}://${HTTPD_MINIO_HOST}:${MINIO_PORT_INTERNAL}" - - ProxyPass "/" "${UI_PROTOCOL}://${HTTPD_UI_HOST}:${UI_PORT}/" - ProxyPassReverse "/" "${UI_PROTOCOL}://${HTTPD_UI_HOST}:${UI_PORT}/" - \ No newline at end of file diff --git a/httpd/httpd.conf b/httpd/httpd.conf deleted file mode 100644 index 7816f0f..0000000 --- a/httpd/httpd.conf +++ /dev/null @@ -1,554 +0,0 @@ -# -# This is the main Apache HTTP server configuration file. It contains the -# configuration directives that give the server its instructions. -# See for detailed information. -# In particular, see -# -# for a discussion of each configuration directive. -# -# Do NOT simply read the instructions in here without understanding -# what they do. They're here only as hints or reminders. If you are unsure -# consult the online docs. You have been warned. -# -# Configuration and logfile names: If the filenames you specify for many -# of the server's control files begin with "/" (or "drive:/" for Win32), the -# server will use that explicit path. If the filenames do *not* begin -# with "/", the value of ServerRoot is prepended -- so "logs/access_log" -# with ServerRoot set to "/usr/local/apache2" will be interpreted by the -# server as "/usr/local/apache2/logs/access_log", whereas "/logs/access_log" -# will be interpreted as '/logs/access_log'. - -# -# ServerRoot: The top of the directory tree under which the server's -# configuration, error, and log files are kept. -# -# Do not add a slash at the end of the directory path. If you point -# ServerRoot at a non-local disk, be sure to specify a local disk on the -# Mutex directive, if file-based mutexes are used. If you wish to share the -# same ServerRoot for multiple httpd daemons, you will need to change at -# least PidFile. -# -ServerRoot "/usr/local/apache2" - -# -# Mutex: Allows you to set the mutex mechanism and mutex file directory -# for individual mutexes, or change the global defaults -# -# Uncomment and change the directory if mutexes are file-based and the default -# mutex file directory is not on a local disk or is not appropriate for some -# other reason. -# -# Mutex default:logs - -# -# Listen: Allows you to bind Apache to specific IP addresses and/or -# ports, instead of the default. See also the -# directive. -# -# Change this to Listen on specific IP addresses as shown below to -# prevent Apache from glomming onto all bound IP addresses. -# -#Listen 12.34.56.78:80 -Listen 80 - -# -# Dynamic Shared Object (DSO) Support -# -# To be able to use the functionality of a module which was built as a DSO you -# have to place corresponding `LoadModule' lines at this location so the -# directives contained in it are actually available _before_ they are used. -# Statically compiled modules (those listed by `httpd -l') do not need -# to be loaded here. -# -# Example: -# LoadModule foo_module modules/mod_foo.so -# -LoadModule mpm_event_module modules/mod_mpm_event.so -#LoadModule mpm_prefork_module modules/mod_mpm_prefork.so -#LoadModule mpm_worker_module modules/mod_mpm_worker.so -LoadModule authn_file_module modules/mod_authn_file.so -#LoadModule authn_dbm_module modules/mod_authn_dbm.so -#LoadModule authn_anon_module modules/mod_authn_anon.so -#LoadModule authn_dbd_module modules/mod_authn_dbd.so -#LoadModule authn_socache_module modules/mod_authn_socache.so -LoadModule authn_core_module modules/mod_authn_core.so -LoadModule authz_host_module modules/mod_authz_host.so -LoadModule authz_groupfile_module modules/mod_authz_groupfile.so -LoadModule authz_user_module modules/mod_authz_user.so -#LoadModule authz_dbm_module modules/mod_authz_dbm.so -#LoadModule authz_owner_module modules/mod_authz_owner.so -#LoadModule authz_dbd_module modules/mod_authz_dbd.so -LoadModule authz_core_module modules/mod_authz_core.so -#LoadModule authnz_ldap_module modules/mod_authnz_ldap.so -#LoadModule authnz_fcgi_module modules/mod_authnz_fcgi.so -LoadModule access_compat_module modules/mod_access_compat.so -LoadModule auth_basic_module modules/mod_auth_basic.so -#LoadModule auth_form_module modules/mod_auth_form.so -#LoadModule auth_digest_module modules/mod_auth_digest.so -#LoadModule allowmethods_module modules/mod_allowmethods.so -#LoadModule isapi_module modules/mod_isapi.so -#LoadModule file_cache_module modules/mod_file_cache.so -#LoadModule cache_module modules/mod_cache.so -#LoadModule cache_disk_module modules/mod_cache_disk.so -#LoadModule cache_socache_module modules/mod_cache_socache.so -#LoadModule socache_shmcb_module modules/mod_socache_shmcb.so -#LoadModule socache_dbm_module modules/mod_socache_dbm.so -#LoadModule socache_memcache_module modules/mod_socache_memcache.so -#LoadModule socache_redis_module modules/mod_socache_redis.so -#LoadModule watchdog_module modules/mod_watchdog.so -#LoadModule macro_module modules/mod_macro.so -#LoadModule dbd_module modules/mod_dbd.so -#LoadModule bucketeer_module modules/mod_bucketeer.so -#LoadModule dumpio_module modules/mod_dumpio.so -#LoadModule echo_module modules/mod_echo.so -#LoadModule example_hooks_module modules/mod_example_hooks.so -#LoadModule case_filter_module modules/mod_case_filter.so -#LoadModule case_filter_in_module modules/mod_case_filter_in.so -#LoadModule example_ipc_module modules/mod_example_ipc.so -#LoadModule buffer_module modules/mod_buffer.so -#LoadModule data_module modules/mod_data.so -#LoadModule ratelimit_module modules/mod_ratelimit.so -LoadModule reqtimeout_module modules/mod_reqtimeout.so -#LoadModule ext_filter_module modules/mod_ext_filter.so -#LoadModule request_module modules/mod_request.so -#LoadModule include_module modules/mod_include.so -LoadModule filter_module modules/mod_filter.so -#LoadModule reflector_module modules/mod_reflector.so -#LoadModule substitute_module modules/mod_substitute.so -#LoadModule sed_module modules/mod_sed.so -#LoadModule charset_lite_module modules/mod_charset_lite.so -#LoadModule deflate_module modules/mod_deflate.so -#LoadModule xml2enc_module modules/mod_xml2enc.so -#LoadModule proxy_html_module modules/mod_proxy_html.so -#LoadModule brotli_module modules/mod_brotli.so -LoadModule mime_module modules/mod_mime.so -#LoadModule ldap_module modules/mod_ldap.so -LoadModule log_config_module modules/mod_log_config.so -#LoadModule log_debug_module modules/mod_log_debug.so -#LoadModule log_forensic_module modules/mod_log_forensic.so -#LoadModule logio_module modules/mod_logio.so -#LoadModule lua_module modules/mod_lua.so -LoadModule env_module modules/mod_env.so -#LoadModule mime_magic_module modules/mod_mime_magic.so -#LoadModule cern_meta_module modules/mod_cern_meta.so -#LoadModule expires_module modules/mod_expires.so -LoadModule headers_module modules/mod_headers.so -#LoadModule ident_module modules/mod_ident.so -#LoadModule usertrack_module modules/mod_usertrack.so -#LoadModule unique_id_module modules/mod_unique_id.so -LoadModule setenvif_module modules/mod_setenvif.so -LoadModule version_module modules/mod_version.so -#LoadModule remoteip_module modules/mod_remoteip.so -LoadModule proxy_module modules/mod_proxy.so -#LoadModule proxy_connect_module modules/mod_proxy_connect.so -#LoadModule proxy_ftp_module modules/mod_proxy_ftp.so -LoadModule proxy_http_module modules/mod_proxy_http.so -#LoadModule proxy_fcgi_module modules/mod_proxy_fcgi.so -#LoadModule proxy_scgi_module modules/mod_proxy_scgi.so -#LoadModule proxy_uwsgi_module modules/mod_proxy_uwsgi.so -#LoadModule proxy_fdpass_module modules/mod_proxy_fdpass.so -#LoadModule proxy_wstunnel_module modules/mod_proxy_wstunnel.so -#LoadModule proxy_ajp_module modules/mod_proxy_ajp.so -#LoadModule proxy_balancer_module modules/mod_proxy_balancer.so -#LoadModule proxy_express_module modules/mod_proxy_express.so -#LoadModule proxy_hcheck_module modules/mod_proxy_hcheck.so -#LoadModule session_module modules/mod_session.so -#LoadModule session_cookie_module modules/mod_session_cookie.so -#LoadModule session_crypto_module modules/mod_session_crypto.so -#LoadModule session_dbd_module modules/mod_session_dbd.so -#LoadModule slotmem_shm_module modules/mod_slotmem_shm.so -#LoadModule slotmem_plain_module modules/mod_slotmem_plain.so -#LoadModule ssl_module modules/mod_ssl.so -#LoadModule optional_hook_export_module modules/mod_optional_hook_export.so -#LoadModule optional_hook_import_module modules/mod_optional_hook_import.so -#LoadModule optional_fn_import_module modules/mod_optional_fn_import.so -#LoadModule optional_fn_export_module modules/mod_optional_fn_export.so -#LoadModule dialup_module modules/mod_dialup.so -#LoadModule http2_module modules/mod_http2.so -#LoadModule proxy_http2_module modules/mod_proxy_http2.so -#LoadModule md_module modules/mod_md.so -#LoadModule lbmethod_byrequests_module modules/mod_lbmethod_byrequests.so -#LoadModule lbmethod_bytraffic_module modules/mod_lbmethod_bytraffic.so -#LoadModule lbmethod_bybusyness_module modules/mod_lbmethod_bybusyness.so -#LoadModule lbmethod_heartbeat_module modules/mod_lbmethod_heartbeat.so -LoadModule unixd_module modules/mod_unixd.so -#LoadModule heartbeat_module modules/mod_heartbeat.so -#LoadModule heartmonitor_module modules/mod_heartmonitor.so -#LoadModule dav_module modules/mod_dav.so -LoadModule status_module modules/mod_status.so -LoadModule autoindex_module modules/mod_autoindex.so -#LoadModule asis_module modules/mod_asis.so -#LoadModule info_module modules/mod_info.so -#LoadModule suexec_module modules/mod_suexec.so - - #LoadModule cgid_module modules/mod_cgid.so - - - #LoadModule cgi_module modules/mod_cgi.so - -#LoadModule dav_fs_module modules/mod_dav_fs.so -#LoadModule dav_lock_module modules/mod_dav_lock.so -#LoadModule vhost_alias_module modules/mod_vhost_alias.so -#LoadModule negotiation_module modules/mod_negotiation.so -LoadModule dir_module modules/mod_dir.so -#LoadModule imagemap_module modules/mod_imagemap.so -#LoadModule actions_module modules/mod_actions.so -#LoadModule speling_module modules/mod_speling.so -#LoadModule userdir_module modules/mod_userdir.so -LoadModule alias_module modules/mod_alias.so -#LoadModule rewrite_module modules/mod_rewrite.so - - -# -# If you wish httpd to run as a different user or group, you must run -# httpd as root initially and it will switch. -# -# User/Group: The name (or #number) of the user/group to run httpd as. -# It is usually good practice to create a dedicated user and group for -# running httpd, as with most system services. -# -User www-data -Group www-data - - - -# 'Main' server configuration -# -# The directives in this section set up the values used by the 'main' -# server, which responds to any requests that aren't handled by a -# definition. These values also provide defaults for -# any containers you may define later in the file. -# -# All of these directives may appear inside containers, -# in which case these default settings will be overridden for the -# virtual host being defined. -# - -# -# ServerAdmin: Your address, where problems with the server should be -# e-mailed. This address appears on some server-generated pages, such -# as error documents. e.g. admin@your-domain.com -# -ServerAdmin ben@bensherrif.com - -# -# ServerName gives the name and port that the server uses to identify itself. -# This can often be determined automatically, but we recommend you specify -# it explicitly to prevent problems during startup. -# -# If your host doesn't have a registered DNS name, enter its IP address here. -# -#ServerName www.example.com:80 -ServerName localhost - -# -# Deny access to the entirety of your server's filesystem. You must -# explicitly permit access to web content directories in other -# blocks below. -# - - AllowOverride none - Require all denied - - -# -# Note that from this point forward you must specifically allow -# particular features to be enabled - so if something's not working as -# you might expect, make sure that you have specifically enabled it -# below. -# - -# -# DocumentRoot: The directory out of which you will serve your -# documents. By default, all requests are taken from this directory, but -# symbolic links and aliases may be used to point to other locations. -# -DocumentRoot "/usr/local/apache2/htdocs" - - # - # Possible values for the Options directive are "None", "All", - # or any combination of: - # Indexes Includes FollowSymLinks SymLinksifOwnerMatch ExecCGI MultiViews - # - # Note that "MultiViews" must be named *explicitly* --- "Options All" - # doesn't give it to you. - # - # The Options directive is both complicated and important. Please see - # http://httpd.apache.org/docs/2.4/mod/core.html#options - # for more information. - # - Options Indexes FollowSymLinks - - # - # AllowOverride controls what directives may be placed in .htaccess files. - # It can be "All", "None", or any combination of the keywords: - # AllowOverride FileInfo AuthConfig Limit - # - AllowOverride None - - # - # Controls who can get stuff from this server. - # - Require all granted - - -# -# DirectoryIndex: sets the file that Apache will serve if a directory -# is requested. -# - - DirectoryIndex index.html - - -# -# The following lines prevent .htaccess and .htpasswd files from being -# viewed by Web clients. -# - - Require all denied - - -# -# ErrorLog: The location of the error log file. -# If you do not specify an ErrorLog directive within a -# container, error messages relating to that virtual host will be -# logged here. If you *do* define an error logfile for a -# container, that host's errors will be logged there and not here. -# -ErrorLog /proc/self/fd/2 - -# -# LogLevel: Control the number of messages logged to the error_log. -# Possible values include: debug, info, notice, warn, error, crit, -# alert, emerg. -# -LogLevel warn - - - # - # The following directives define some format nicknames for use with - # a CustomLog directive (see below). - # - LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined - LogFormat "%h %l %u %t \"%r\" %>s %b" common - - - # You need to enable mod_logio.c to use %I and %O - LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\" %I %O" combinedio - - - # - # The location and format of the access logfile (Common Logfile Format). - # If you do not define any access logfiles within a - # container, they will be logged here. Contrariwise, if you *do* - # define per- access logfiles, transactions will be - # logged therein and *not* in this file. - # - CustomLog /proc/self/fd/1 common - - # - # If you prefer a logfile with access, agent, and referer information - # (Combined Logfile Format) you can use the following directive. - # - #CustomLog "logs/access_log" combined - - - - # - # Redirect: Allows you to tell clients about documents that used to - # exist in your server's namespace, but do not anymore. The client - # will make a new request for the document at its new location. - # Example: - # Redirect permanent /foo http://www.example.com/bar - - # - # Alias: Maps web paths into filesystem paths and is used to - # access content that does not live under the DocumentRoot. - # Example: - # Alias /webpath /full/filesystem/path - # - # If you include a trailing / on /webpath then the server will - # require it to be present in the URL. You will also likely - # need to provide a section to allow access to - # the filesystem path. - - # - # ScriptAlias: This controls which directories contain server scripts. - # ScriptAliases are essentially the same as Aliases, except that - # documents in the target directory are treated as applications and - # run by the server when requested rather than as documents sent to the - # client. The same rules about trailing "/" apply to ScriptAlias - # directives as to Alias. - # - ScriptAlias /cgi-bin/ "/usr/local/apache2/cgi-bin/" - - - - - # - # ScriptSock: On threaded servers, designate the path to the UNIX - # socket used to communicate with the CGI daemon of mod_cgid. - # - #Scriptsock cgisock - - -# -# "/usr/local/apache2/cgi-bin" should be changed to whatever your ScriptAliased -# CGI directory exists, if you have that configured. -# - - AllowOverride None - Options None - Require all granted - - - - # - # Avoid passing HTTP_PROXY environment to CGI's on this or any proxied - # backend servers which have lingering "httpoxy" defects. - # 'Proxy' request header is undefined by the IETF, not listed by IANA - # - RequestHeader unset Proxy early - - - - # - # TypesConfig points to the file containing the list of mappings from - # filename extension to MIME-type. - # - TypesConfig conf/mime.types - - # - # AddType allows you to add to or override the MIME configuration - # file specified in TypesConfig for specific file types. - # - #AddType application/x-gzip .tgz - # - # AddEncoding allows you to have certain browsers uncompress - # information on the fly. Note: Not all browsers support this. - # - #AddEncoding x-compress .Z - #AddEncoding x-gzip .gz .tgz - # - # If the AddEncoding directives above are commented-out, then you - # probably should define those extensions to indicate media types: - # - AddType application/x-compress .Z - AddType application/x-gzip .gz .tgz - - # - # AddHandler allows you to map certain file extensions to "handlers": - # actions unrelated to filetype. These can be either built into the server - # or added with the Action directive (see below) - # - # To use CGI scripts outside of ScriptAliased directories: - # (You will also need to add "ExecCGI" to the "Options" directive.) - # - #AddHandler cgi-script .cgi - - # For type maps (negotiated resources): - #AddHandler type-map var - - # - # Filters allow you to process content before it is sent to the client. - # - # To parse .shtml files for server-side includes (SSI): - # (You will also need to add "Includes" to the "Options" directive.) - # - #AddType text/html .shtml - #AddOutputFilter INCLUDES .shtml - - -# -# The mod_mime_magic module allows the server to use various hints from the -# contents of the file itself to determine its type. The MIMEMagicFile -# directive tells the module where the hint definitions are located. -# -#MIMEMagicFile conf/magic - -# -# Customizable error responses come in three flavors: -# 1) plain text 2) local redirects 3) external redirects -# -# Some examples: -#ErrorDocument 500 "The server made a boo boo." -#ErrorDocument 404 /missing.html -#ErrorDocument 404 "/cgi-bin/missing_handler.pl" -#ErrorDocument 402 http://www.example.com/subscription_info.html -# - -# -# MaxRanges: Maximum number of Ranges in a request before -# returning the entire resource, or one of the special -# values 'default', 'none' or 'unlimited'. -# Default setting is to accept 200 Ranges. -#MaxRanges unlimited - -# -# EnableMMAP and EnableSendfile: On systems that support it, -# memory-mapping or the sendfile syscall may be used to deliver -# files. This usually improves server performance, but must -# be turned off when serving from networked-mounted -# filesystems or if support for these functions is otherwise -# broken on your system. -# Defaults: EnableMMAP On, EnableSendfile Off -# -#EnableMMAP off -#EnableSendfile on - -# Supplemental configuration -# -# The configuration files in the conf/extra/ directory can be -# included to add extra features or to modify the default configuration of -# the server, or you may simply copy their contents here and change as -# necessary. - -# Server-pool management (MPM specific) -#Include conf/extra/httpd-mpm.conf - -# Multi-language error messages -#Include conf/extra/httpd-multilang-errordoc.conf - -# Fancy directory listings -#Include conf/extra/httpd-autoindex.conf - -# Language settings -#Include conf/extra/httpd-languages.conf - -# User home directories -#Include conf/extra/httpd-userdir.conf - -# Real-time info on requests and configuration -#Include conf/extra/httpd-info.conf - -# Virtual hosts -#Include conf/extra/httpd-vhosts.conf - -# Local access to the Apache HTTP Server Manual -#Include conf/extra/httpd-manual.conf - -# Distributed authoring and versioning (WebDAV) -#Include conf/extra/httpd-dav.conf - -# Various default settings -#Include conf/extra/httpd-default.conf - -Include conf/extra/aviation.conf - -# Configure mod_proxy_html to understand HTML4/XHTML1 - -Include conf/extra/proxy-html.conf - - -# Secure (SSL/TLS) connections -#Include conf/extra/httpd-ssl.conf -# -# Note: The following must must be present to support -# starting without SSL on platforms with no /dev/random equivalent -# but a statically compiled-in mod_ssl. -# - -SSLRandomSeed startup builtin -SSLRandomSeed connect builtin - - diff --git a/nginx/Dockerfile b/nginx/Dockerfile new file mode 100644 index 0000000..abaeb12 --- /dev/null +++ b/nginx/Dockerfile @@ -0,0 +1,3 @@ +FROM nginx +COPY nginx.conf /etc/nginx/nginx.conf +COPY templates/ /etc/nginx/templates/ diff --git a/nginx/nginx.conf b/nginx/nginx.conf new file mode 100644 index 0000000..261ac58 --- /dev/null +++ b/nginx/nginx.conf @@ -0,0 +1,34 @@ +user nginx; +worker_processes auto; + +error_log /var/log/nginx/error.log notice; +pid /var/run/nginx.pid; + + +events { + worker_connections 1024; +} + + +http { + include /etc/nginx/mime.types; + default_type application/octet-stream; + + log_format main '$remote_addr - $remote_user [$time_local] "$request" ' + '$status $body_bytes_sent "$http_referer" ' + '"$http_user_agent" "$http_x_forwarded_for"'; + + access_log /var/log/nginx/access.log main; + + sendfile on; + #tcp_nopush on; + + keepalive_timeout 65; + + #gzip on; + + # Set client limit to 100 MB + client_max_body_size 100M; + + include /etc/nginx/conf.d/*.conf; +} diff --git a/nginx/templates/default.conf.template b/nginx/templates/default.conf.template new file mode 100644 index 0000000..3536c34 --- /dev/null +++ b/nginx/templates/default.conf.template @@ -0,0 +1,56 @@ +# HTTP server configuration +server { + listen 80; + listen [::]:80; + server_name ${NGINX_HOST}; + + # Redirect all incoming requests to HTTPS + return 301 https://$host:${NGINX_HTTPS_PORT}$request_uri; +} + +# HTTPS server configuration +server { + listen 443 ssl; + listen [::]:443 ssl; + server_name ${NGINX_HOST}; + + # SSL settings + ssl_certificate ${SSL_CERT_PATH}; + ssl_certificate_key ${SSL_CERT_KEY_PATH}; + + # Optional: SSL session settings and ciphers (adjust as required) + #ssl_session_cache shared:SSL:10m; + #ssl_session_timeout 10m; + #ssl_ciphers HIGH:!aNULL:!MD5; + #ssl_prefer_server_ciphers on; + + location /api/ { + proxy_pass ${API_PROTOCOL}://${NGINX_API_HOST}:${API_PORT}/api/; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + } + + location /minio/ { + proxy_pass ${MINIO_PROTOCOL}://${NGINX_MINIO_HOST}:${MINIO_PORT_INTERNAL}/; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + } + + # Reverse proxy for the UI and default catch-all + location / { + proxy_pass ${UI_PROTOCOL}://${NGINX_UI_HOST}:${UI_PORT}/; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + } + + error_page 500 502 503 504 /50x.html; + location = /50x.html { + root /usr/share/nginx/html; + } +} diff --git a/scripts/generate_cert.sh b/scripts/generate_cert.sh index 985abbf..3a42d74 100755 --- a/scripts/generate_cert.sh +++ b/scripts/generate_cert.sh @@ -13,20 +13,59 @@ SSL_DIR="./ssl" # Create directory if it doesn't exist mkdir -p "$SSL_DIR" -KEY_PATH="${SSL_DIR}/${DOMAIN}.key" -CRT_PATH="${SSL_DIR}/${DOMAIN}.crt" +# Define CA file names +CA_KEY="${SSL_DIR}/${SSL_CA_NAME}.key" +CA_CERT="${SSL_DIR}/${SSL_CA_NAME}.pem" -echo "Generating self-signed certificate for ${DOMAIN}..." - -openssl req -x509 -nodes -days ${DAYS} -newkey rsa:2048 \ - -keyout "${KEY_PATH}" \ - -out "${CRT_PATH}" \ - -subj "/CN=${DOMAIN}" - -if [ $? -eq 0 ]; then - echo "Successfully generated certificate:" - echo "Private Key: ${KEY_PATH}" - echo "Certificate: ${CRT_PATH}" +# Check if CA files exist; if not, generate them. +if [ ! -f "$CA_KEY" ] || [ ! -f "$CA_CERT" ]; then + echo "Generating CA key and self-signed CA certificate..." + openssl genrsa -out "$CA_KEY" 4096 + if [ $? -ne 0 ]; then + echo "Failed to generate CA key" + exit 1 + fi + openssl req -x509 -new -nodes -key "$CA_KEY" -sha256 -days 1024 -out "$CA_CERT" -subj "/CN=My Custom CA" + if [ $? -ne 0 ]; then + echo "Failed to generate CA certificate" + exit 1 + fi + echo "CA generated successfully:" else - echo "Certificate generation failed." -fi \ No newline at end of file + echo "Existing CA:" +fi +echo " CA Private Key: $CA_KEY" +echo " CA Certificate: $CA_CERT" + +# Define domain file names +DOMAIN_KEY="${SSL_DIR}/${DOMAIN}.key" +DOMAIN_CSR="${SSL_DIR}/${DOMAIN}.csr" +DOMAIN_CERT="${SSL_DIR}/${DOMAIN}.crt" + +echo "Generating private key for domain ${DOMAIN}..." +openssl genrsa -out "$DOMAIN_KEY" 2048 +if [ $? -ne 0 ]; then + echo "Failed to generate domain key" + exit 1 +fi + +echo "Generating CSR for domain ${DOMAIN}..." +openssl req -new -key "$DOMAIN_KEY" -out "$DOMAIN_CSR" -subj "/CN=${DOMAIN}" +if [ $? -ne 0 ]; then + echo "Failed to generate CSR for ${DOMAIN}" + exit 1 +fi + +echo "Signing certificate for ${DOMAIN} using our CA..." +openssl x509 -req -in "$DOMAIN_CSR" -CA "$CA_CERT" -CAkey "$CA_KEY" -CAcreateserial -out "$DOMAIN_CERT" -days $DAYS -sha256 +if [ $? -ne 0 ]; then + echo "Failed to sign certificate for ${DOMAIN}" + exit 1 +fi + +echo "Successfully generated the following files:" +echo " CA Private Key: $CA_KEY" +echo " CA Certificate: $CA_CERT" +echo " Domain Private Key: $DOMAIN_KEY" +echo " Domain Certificate: $DOMAIN_CERT" +echo " Domain Certificate Signing Request: $DOMAIN_CSR" diff --git a/ui/src/App.tsx b/ui/src/App.tsx index 80da655..8bf8a1c 100644 --- a/ui/src/App.tsx +++ b/ui/src/App.tsx @@ -12,8 +12,9 @@ import { useEffect, useState } from 'react'; import { Airport } from '@lib/airport.types.ts'; import AirportDrawer from '@components/AirportDrawer.tsx'; import { getWeatherMapUrl } from '@lib/rainViewer.ts'; -import { IconRadar } from '@tabler/icons-react'; +// import { IconRadar } from '@tabler/icons-react'; import Cookies from 'js-cookie'; +import { UnstyledButton } from '@mantine/core'; // Fix Leaflet's default icon path issues with Webpack // eslint-disable-next-line @typescript-eslint/ban-ts-comment // @ts-expect-error @@ -101,11 +102,13 @@ function App() { - + > + Radar + );