{"id":19633349,"url":"https://github.com/ericdriussi/host-your-own","last_synced_at":"2025-04-28T07:30:47.880Z","repository":{"id":133498891,"uuid":"469462090","full_name":"EricDriussi/host-your-own","owner":"EricDriussi","description":"[MIRROR] Ansible script to set up your self-hosting VPS.","archived":false,"fork":false,"pushed_at":"2025-04-27T19:19:01.000Z","size":327,"stargazers_count":49,"open_issues_count":0,"forks_count":4,"subscribers_count":1,"default_branch":"master","last_synced_at":"2025-04-27T20:26:10.104Z","etag":null,"topics":["ansible","ansible-playbook","fail2ban","gitea","nextcloud","nginx","searxng","self-hosted","stow","vaultwarden"],"latest_commit_sha":null,"homepage":"https://gitlab.com/ericdriussi/host-your-own","language":"Ruby","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/EricDriussi.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2022-03-13T18:42:10.000Z","updated_at":"2025-04-27T19:19:05.000Z","dependencies_parsed_at":"2024-01-20T10:35:55.145Z","dependency_job_id":"db1bad9e-dd9e-48b5-b498-75e6359fd700","html_url":"https://github.com/EricDriussi/host-your-own","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/EricDriussi%2Fhost-your-own","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/EricDriussi%2Fhost-your-own/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/EricDriussi%2Fhost-your-own/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/EricDriussi%2Fhost-your-own/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/EricDriussi","download_url":"https://codeload.github.com/EricDriussi/host-your-own/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":251271083,"owners_count":21562487,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ansible","ansible-playbook","fail2ban","gitea","nextcloud","nginx","searxng","self-hosted","stow","vaultwarden"],"created_at":"2024-11-11T12:17:07.228Z","updated_at":"2025-04-28T07:30:47.862Z","avatar_url":"https://github.com/EricDriussi.png","language":"Ruby","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Host your stuff\n\n\u003e Ansible script to self-host a bunch of services on your VPS in one go.\n\nAn Ansible playbook that sets up:\n\n- Static website server (served through HTTP and Onion land).\n- Open source, GDPR-compliant [analytics](https://github.com/umami-software/umami)\n@ `umami.domain`.\n- [Nextcloud](https://nextcloud.com/) instance @ `cloud.domain`.\n- [Vaultwarden](https://github.com/dani-garcia/vaultwarden) instance @ `vault.domain`.\n- [SearxNG](https://github.com/searxng/searxng) instance @ `searx.domain`.\n- [Gitea](https://github.com/go-gitea/gitea) instance @ `git.domain`.\n- Regular unattended backups and updates for these services.\n- HTTPS all the things.\n- Regular unattended SSL certs renewal.\n- Hardened NGINX reverse proxy.\n- Hardened SSH setup.\n- Firewall and [Fail2ban](https://github.com/fail2ban/fail2ban).\n- Regular unattended system updates.\n- [A bunch](./roles/custom/vars/main.yml) of useful CLI tools.\n- Your dotfiles set up and ready to go (using GNU-Stow).\n- Up to date [neovim](https://github.com/neovim/neovim) install (if nvim config\nis found in dotfiles).\n\n## Requirements\n\n### A Debian based VPS\n\nThe script requires a Debian based VPS.\n\nThe cheapest most basic VPS you can find should do.\n\n### Root SSH access\n\nThe machine where this script is run should have root SSH access to the VPS.\n\nRoot SSH connections will be blocked as part of the setup and\na dedicated sudo user will be used for the setup.\n\n### Domain Name - DNS setup\n\nYou **need** a valid domain name and your DNS records should be properly set up\nfor your root domain as well as for (at least) the above-mentioned subdomains.\n\n## Run\n\n1. Clone this repo\n1. Copy `.env-sample.yml` to `.env.yml` and fill in your config\n1. Run `./init.sh`\n\nYou can use the `--tags` flag to run only some of the roles:\n\n```sh\n./init.sh --tags=\"harden,nextcloud,searx\"\n```\n\nYou can check the available tags in the `run.yml` file.\n\n## Post-setup\n\nAfter the main playbook is done, you should find the Nextcloud, Gitea, SearxNG\nand Umami instances under their respective subdomains.\n\nThere should be a custom admin account already setup for Nextcloud and Gitea,\nas well as the default Umami admin user.\n\nHave a look around and make yourself at home!\n\n### Vaultwarden\n\nPublic signups are disabled by default for Vaultwarden to improve security.\n\nYou'll have to visit `vault.[your.domain.com]/admin` first, enter the\n`vaultwarden_password` defined in your `.env.yml` file, and manually\nallow your desired email address to sign up.\n\nThis behavior can be changed, and more info can be found [here](https://github.com/dani-garcia/vaultwarden/wiki/Configuration-overview).\n\n### Website\n\nYou'll find a lousy website under your root domain.\n\nIt is stored in `/home/[REMOTE_USER]/website/` and you can modify it at any time\nusing `scp` or `rsync` to upload your static website, blog or whatever else.\n\n```sh\nrsync --recursive --compress --partial --progress --times local_website/* [REMOTE_USER]@[your.domain.com]:~/website\n```\n\n#### Analytics\n\nThe default docker-compose installation process provided\nin the [Umami docs](https://umami.is/docs) is followed.\n\nYou can log in to `umami.domain` following the [official instructions](https://umami.is/docs/login).\n\nIn case you prefer something simpler, a lightly modified version of\n[this](https://github.com/woodruffw/snippets/blob/master/vbnla/vbnla) script is\navailable in `/home/[REOMTE_USER]/analytics.rb`.\nRun it as follows to extract useful information from your server:\n\n```sh\nsudo cat /var/log/nginx/acces.log | ~/analytics.rb\n```\n\n### Updates and Backups\n\nBoth the OS and the individual services are updated on a monthly basis.\n\nBackups for the services are done weekly and are stored by default under `/home/[REMOTE_USER]/backups`.\nYou can download them to you local machine with something like:\n\n```sh\nrsync --recursive --compress --partial --progress --times --rsync-path=\"sudo rsync\" [REMOTE_USER]@[your.domain.com]:~/backups local_backup_dir\n```\n\n## Why?\n\nHaving your private spot on the internet shouldn't be a luxury.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fericdriussi%2Fhost-your-own","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fericdriussi%2Fhost-your-own","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fericdriussi%2Fhost-your-own/lists"}