Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -42,3 +42,6 @@ node_modules/
# editor settings and extension recommendations
/.vscode/*
!/.vscode/extensions.json

# Ignore key files for decrypting credentials and more.
/config/credentials/*.key
4 changes: 3 additions & 1 deletion .kamal/secrets
Original file line number Diff line number Diff line change
Expand Up @@ -17,4 +17,6 @@
# KAMAL_REGISTRY_PASSWORD=$KAMAL_REGISTRY_PASSWORD

# Improve security by using a password manager. Never check config/master.key into git!
RAILS_MASTER_KEY=$(cat config/master.key)
RAILS_MASTER_KEY=$(cat config/credentials/production.key)

KAMAL_REGISTRY_PASSWORD=$(aws ecr get-login-password --region us-east-2)
4 changes: 0 additions & 4 deletions config/application.rb
Original file line number Diff line number Diff line change
Expand Up @@ -11,10 +11,6 @@ class Application < Rails::Application
# Initialize configuration defaults for originally generated Rails version.
config.load_defaults 8.1

# Please, add to the `ignore` list any other `lib` subdirectories that do
# not contain `.rb` files, or that should not be reloaded or eager loaded.
# Common ones are `templates`, `generators`, or `middleware`, for example.
config.autoload_lib(ignore: %w[assets tasks])

# Configuration for the application, engines, and railties goes here.
#
Expand Down
1 change: 1 addition & 0 deletions config/credentials/production.yml.enc
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
YRbgODceieITQZQ4gZ93Sc3FjtSxKAjbD3GXsuf8dNNAd2Spk0ygswjRuTmX7XOwC0fIY39YbvVujEm+molWhcT5pIjDWTfJ3a2SmZ9KNJ/yoI2AR+ZxC9snFLUBGM8qzLT2Z8dCVXdXz4UhL9Gv8hxfIfUuSsTvYewN4DRCwqjOhtIk6XEuAoUZ1jbYsi5X+SyhELsuIUQdeTsF4kzZr/snuHxpvvyWb8LZFjPOm7lRb/y682YCLhFb3cZTbOwtq9fBfJY5EwEBmasMxbGE5XJrGhxy8XCw9E9OY6WsGt+0xERcDoBkLuHyYpzEyD8WL/JMIGFA1Pp+6hMRIhoJA6Wq9fldsFoifEF7My3+sr6jPF+gh53u1V+9Fd4rdfPizzms/Zj2q3qvE0P4Def6c4bOEMA5DeVPW1d9jpVC5kf/8QwDyfa8A5tsYldkcBZ0TT7TwXTYMoSajYfv3Ns84ZxAxzuDpXbL7FJgozpIFQ+NPLiIFXzCDfUSrw==--i8jvjzgTiUXOf0Bi--1Hx7dqQgCMYZG1eKu83quw==
35 changes: 22 additions & 13 deletions config/deploy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ image: endsideout
# Deploy to these servers.
servers:
web:
- 192.168.0.1
- 18.117.181.111
# job:
# hosts:
# - 192.168.0.1
Expand All @@ -20,21 +20,25 @@ servers:
#
# Don't use this when deploying to multiple web servers (then you have to terminate SSL at your load balancer).
#
# proxy:
# ssl: true
# host: app.example.com
proxy:
ssl: false
forward_headers: true # the ALB handles the SSL termination, so we need to forward the headers to Rails for correct URL generation.

# Where you keep your container images.
registry:
# Alternatives: hub.docker.com / registry.digitalocean.com / ghcr.io / ...
server: localhost:5555
# We set up an ECR because
# - push/pull of images with kamal over SSH was not working over the RfG event wifi
# - it should be fairly inexpensive for our expected use (famous last AWS words, I suppose)
server: 024757002197.dkr.ecr.us-east-2.amazonaws.com
# server: localhost:5555

# Needed for authenticated registries.
# username: your-user
username: AWS

# Always use an access token rather than real password when possible.
# password:
# - KAMAL_REGISTRY_PASSWORD
password:
- KAMAL_REGISTRY_PASSWORD

# Inject ENV variables into containers (secrets come from .kamal/secrets).
env:
Expand Down Expand Up @@ -78,21 +82,26 @@ asset_path: /rails/public/assets

# Configure the image builder.
builder:
arch: amd64
arch:
- amd64
# - arm64


# # Build image via remote server (useful for faster amd64 builds on arm64 computers)
# remote: ssh://docker@docker-builder-server
#
# # Pass arguments and secrets to the Docker build process
# args:
# RUBY_VERSION: ruby-4.0.6
# secrets:
secrets:
# - GITHUB_TOKEN
# - RAILS_MASTER_KEY
- RAILS_MASTER_KEY

# Use a different ssh user than root
# ssh:
# user: app
ssh:
user: ec2-user
keys: ["~/.ssh/2026rfg-staging.pem"]


# Use accessory services (secrets come from .kamal/secrets).
# accessories:
Expand Down
19 changes: 9 additions & 10 deletions config/environments/production.rb
Original file line number Diff line number Diff line change
Expand Up @@ -25,13 +25,13 @@
config.active_storage.service = :local

# Assume all access to the app is happening through a SSL-terminating reverse proxy.
# config.assume_ssl = true
config.assume_ssl = true

# Force all access to the app over SSL, use Strict-Transport-Security, and use secure cookies.
# config.force_ssl = true
config.force_ssl = true

# Skip http-to-https redirect for the default health check endpoint.
# config.ssl_options = { redirect: { exclude: ->(request) { request.path == "/up" } } }
config.ssl_options = { redirect: { exclude: ->(request) { request.path == "/up" } } }

# Log to STDOUT with the current request id as a default log tag.
config.log_tags = [ :request_id ]
Expand All @@ -58,7 +58,7 @@
# config.action_mailer.raise_delivery_errors = false

# Set host to be used by links generated in mailer templates.
config.action_mailer.default_url_options = { host: "example.com" }
config.action_mailer.default_url_options = { host: "staging-classroom.endsideout.org", protocol: "https" }

# Specify outgoing SMTP server. Remember to add smtp/* credentials via bin/rails credentials:edit.
# config.action_mailer.smtp_settings = {
Expand All @@ -80,11 +80,10 @@
config.active_record.attributes_for_inspect = [ :id ]

# Enable DNS rebinding protection and other `Host` header attacks.
# config.hosts = [
# "example.com", # Allow requests from example.com
# /.*\.example\.com/ # Allow requests from subdomains like `www.example.com`
# ]
#
config.hosts = [
"staging-classroom.endsideout.org"
]

# Skip DNS rebinding protection for the default health check endpoint.
# config.host_authorization = { exclude: ->(request) { request.path == "/up" } }
config.host_authorization = { exclude: ->(request) { request.path == "/up" } }
end
Loading