commit f248a5b7b259208c2d39124cbf7f45e80c43f76d Author: q00 Date: Sun Nov 24 17:35:19 2024 +0300 first commit diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..314ddd9 --- /dev/null +++ b/Dockerfile @@ -0,0 +1,48 @@ +################################################################################ +# Build a dockerfile for Prosody XMPP server для porno4free.ru +################################################################################ + +FROM debian:12 + +MAINTAINER Prosody Developers and q00 + + +RUN rm /etc/apt/sources.list.d/* +ADD sources.list /etc/apt +# Install dependencies +RUN apt-get update \ + && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ + lsb-base \ + procps \ + adduser \ + lua-bitop \ + lua-dbi-mysql \ + lua-dbi-postgresql \ + lua-dbi-sqlite3 \ + lua-event \ + lua-expat \ + lua-filesystem \ + lua-sec \ + lua-socket \ + lua-zlib \ + lua5.3 \ + openssl \ + ca-certificates \ + ssl-cert \ + wget \ + && rm -rf /var/lib/apt/lists/* + +# Install and configure prosody +RUN wget https://prosody.im/files/prosody.sources -O /etc/apt/sources.list.d/prosody.sources \ + && apt update \ + && apt install -y prosody prosody-modules + +RUN mkdir -p /var/run/prosody && chown prosody:prosody /var/run/prosody + +#COPY ./entrypoint.sh /entrypoint.sh +#RUN chmod 755 /entrypoint.sh +#ENTRYPOINT ["/entrypoint.sh"] + +#EXPOSE 80 443 5222 5269 5347 5280 5281 +#ENV __FLUSH_LOG yes +#CMD ["prosody", "-F"] diff --git a/README.md b/README.md new file mode 100644 index 0000000..ee95194 --- /dev/null +++ b/README.md @@ -0,0 +1,2 @@ +# Dockerfile для сборки prosody в docker контейнер. +## Внимания sources.list надо самому редачить. Там локальная репа. diff --git a/build-docker.sh b/build-docker.sh new file mode 100755 index 0000000..2f1a4bf --- /dev/null +++ b/build-docker.sh @@ -0,0 +1,28 @@ +#!/bin/bash + +if [[ -z "$1" ]]; then + echo "Usage: ./build-docker.sh def_file_name version_number" + exit 1 +fi + +if [[ -z "$2" ]]; then + echo "Usage: ./build-docker.sh def_file_name version_number" + exit 1 +fi + +echo "Starting build..." +cp "$1" ./prosody.deb +docker build -t prosody/prosody:"$2" . +for i in "${@:3}"; do + echo "Also building tag $i" + docker build -t prosody/prosody:"$i" . +done +docker push prosody/prosody + +echo "Cleaning up..." +docker rmi prosody/prosody:"$2" +for i in "${@:3}"; do + echo "Also cleaning tag $i" + docker rmi prosody/prosody:"$i" +done +rm ./prosody.deb diff --git a/docker-compose.yaml b/docker-compose.yaml new file mode 100644 index 0000000..e69de29 diff --git a/entrypoint.sh b/entrypoint.sh new file mode 100755 index 0000000..81b16c5 --- /dev/null +++ b/entrypoint.sh @@ -0,0 +1,21 @@ +#!/bin/bash -e +set -e + +data_dir_owner="$(stat -c %u "/var/lib/prosody/")" +if [[ "$(id -u prosody)" != "$data_dir_owner" ]]; then + usermod -u "$data_dir_owner" prosody +fi +if [[ "$(stat -c %u /var/run/prosody/)" != "$data_dir_owner" ]]; then + chown "$data_dir_owner" /var/run/prosody/ +fi + +if [[ "$1" != "prosody" ]]; then + exec prosodyctl "$@" + exit 0; +fi + +if [[ "$LOCAL" && "$PASSWORD" && "$DOMAIN" ]]; then + prosodyctl register "$LOCAL" "$DOMAIN" "$PASSWORD" +fi + +exec setpriv --reuid=prosody --regid=prosody --init-groups "$@" diff --git a/prosody.sources b/prosody.sources new file mode 100644 index 0000000..565a3f9 --- /dev/null +++ b/prosody.sources @@ -0,0 +1,47 @@ +Suites: bookworm +Types: deb +Architectures: amd64 i386 armhf arm64 +Components: main +Uris: http://packages.prosody.im/debian +Signed-By: + -----BEGIN PGP PUBLIC KEY BLOCK----- + Version: GnuPG v1.4.11 (GNU/Linux) + + mQGiBEoXOjERBAD2ygmSdiqsRmrTqUqcGoWmTU90DrikaYb3/rwwMhSloXT9qNuD + aOdJb/LNfwhiSbKF35JHgYV4+RIdwDLv4wNqmsQH1ZYOUi3j/1O5w2LV8lG816X2 + NdGni+fGArtM68C9ZxdIDweo2V5G5StHINcKP/Cab08sUjyrrCpwO/Z5xwCg9H8L + PsFYns6RcnM7f6A6x5NHEVsEAL9RYChhkecv/+qnbDlKHOJT8TQT4S8p6RYtaZHE + XR73vvvj0P/6Lxw+tKZJqQmVpNaLXztLSNW3KfAR+Jz4SLBJoSP4uXJ5UVIUnqbp + HCUZ3BnDGeHuTplxtrYWmznE34KMks6riXoUApU/kmo8TFqh8aTEp1F/Zd9TdriQ + c0iCA/42SBlM3Ax0cbi2thHSEhUV6aCbs9R9H2Tmke0LswpUMTfxUT37b8t5ocbZ + iHoGdEVIC3ZK2Usu6IS5uhY4245iECafLUX4LF4uY17IHj713yOHZ8T9t2LAGFu9 + oxM7EEoDyVK8Jg0fRn7srBC/p7MdBD1kwVaQOnIjqjiqf3e9sLQyUHJvc29keSBJ + TSBEZWJpYW4gUGFja2FnZXMgPGRldmVsb3BlcnNAcHJvc29keS5pbT6IYAQTEQIA + IAUCShc6MQIbAwYLCQgHAwIEFQIIAwQWAgMBAh4BAheAAAoJEHOT1+Z02du11MQA + nRsq54C4D1k/s0i0Tg41h1LDbAFtAKC2g53DYE3X8jPVJVBTFeHsnkztfLkEDQRK + FzsAEBAAwd9OI2tmqS0DR3Z8vxpio0eV/0+G4OObYEzjq4Keohw8u4qGVoDO4LPB + pyseNPv6J+eu+F2ONa04L1eODPAYprzjxU6gFgt+X2u7kjERybFDXBlVHUNDQIUM + hqpVHhslLGAk1tLJ0anIVwn7Lh4ft7IZq2/LrAb5SR1sSml4q6352jwqyxsNZv71 + R+xHjVfj4SqE2FQ63YpQQQtKiPIc/u876m1bxC04KuR1buEjA0KlPHARjGW9dGf/ + SzEy4FYcuLyNPUiRRH2AJ+b8wocefpXnbKKfHs+zL0j2KApAvSiiW0MN3qvXiXV5 + aer7DVubXpzrS7VAeBJ6yzjqQTUWbYhmg2MKn6JixYI9y4w9ENGhkHcKp8RjOgdP + +hdzoyKQNSE51y1NzujQCefs85BaXKrImUvJJVziWEsTAiy0rT55+juDenjAmGlC + mCkNCTB0fbWI3HH3P6WdT3ft+jZkVuxHWTbyogGVYyVy3et29HnI+KJ4+94FbWvd + WdEOA2HD1EaPbkUtN1J39PoP0iDx0V1eKBrLGqMGXmDUAYjXBy9sEJz2CpLwzx3S + wizIgUv5hogLILassF05YB08DtLDk1EB7D+TSkBWG+G33r6DljTk5hrjWJCE1DK4 + OfwGkwV9J75mDS36eTknEn4hxt2NSDOwXD/u0KeEKrrGGBZt918AAwUP/38LeUAs + c+7HeQmuWItZvTjAeQd71ECi0G/iIO+ccGYFvIKEMMUrJZQaGJpa3h8j1Eu8usEE + +3UULn6Wl5YpiCpIBpEystxnmqn2bxaKtDdFtD43hHV/eaCQuuLKN9qmx6VspdqH + SqN+1xbtkBqIBxONBLNusafByWUs15AUxFbLYqS5dPw3PNooHGLRvLtq3prO0F2j + BLKiujpNSWG/Q6u/AbxIn3qNiYOl201bKBQiYD/xCZEQZAfJSWC+EvU0fpDrTNy+ + MArZniAGltAR4UyhJcqS3RAsB6b12ZpgreOpbTAJ3hET6bYmIwVPQfE/OfIRkZMm + jldn4zzRjMn9HiJjc/lvWJecmdzZ1NOKFCigz8luOHZeSXCS34THhi4fHZBzSKfD + FJXOmq79ouHTY0hyvVksk/tj3g7Oz3obFYDbb86XmAVlPvsmWTFO83DFS2ohA6ai + lvbRhTMOED4y5Ed5abFcfrziCTyPtZgm1OpeNibrOp85D2IzMHlqZTG/RWl5LtVU + wFSrv0OlEz2xD9RyrlIg9c4BUJNybErX1oZ08FVWQdmgff59XNNLv7bPPHYKCnaE + ou6SAY1PeEgmbONRJ6cR6dSVIMEAl8rFCIcL7jz/6S4CjMqST4D9MqDOeoDdl2Zm + ohKViNdLF+P2Oha6djBTxEjz1qhfcu7OVjGaiEkEGBECAAkFAkoXOwACGwwACgkQ + c5PX5nTZ27WmTQCg32XtVZ1E9KIPDpcpMrhV+4wpt50AnjSYtDgDGoWbRxhGDNK3 + UqwePNWL + =/y9s + -----END PGP PUBLIC KEY BLOCK----- diff --git a/prosody/.prosody.cfg.lua.kate-swp b/prosody/.prosody.cfg.lua.kate-swp new file mode 100644 index 0000000..4bee676 Binary files /dev/null and b/prosody/.prosody.cfg.lua.kate-swp differ diff --git a/prosody/prosody.cfg.lua b/prosody/prosody.cfg.lua new file mode 100755 index 0000000..4e23397 --- /dev/null +++ b/prosody/prosody.cfg.lua @@ -0,0 +1,123 @@ +admins = { "q@porno4free.ru" } +plugin_paths = {"/etc/prosody/prosody-modules"} +daemonize = false + +modules_enabled = { + + -- Generally required + "disco"; -- Service discovery + "roster"; -- Allow users to have a roster. Recommended ;) + "saslauth"; -- Authentication for clients and servers. Recommended if you want to log in. + "tls"; -- Add support for secure TLS on c2s/s2s connections + + -- Not essential, but recommended + "blocklist"; -- Allow users to block communications with other users + "bookmarks"; -- Synchronise the list of open rooms between clients + "carbons"; -- Keep multiple online clients in sync + "dialback"; -- Support for verifying remote servers using DNS + "limits"; -- Enable bandwidth limiting for XMPP connections + "pep"; -- Allow users to store public and private data in their account + "private"; -- Legacy account storage mechanism (XEP-0049) + "smacks"; -- Stream management and resumption (XEP-0198) "vcard4"; -- User profiles (stored in PEP) + "vcard_legacy"; -- Conversion between legacy vCard and PEP Avatar, vcard + + -- Nice to have + "csi_simple"; -- Simple but effective traffic optimizations for mobile devices + "invites"; -- Create and manage invites + "invites_adhoc"; -- Allow admins/users to create invitations via their client + "invites_register"; -- Allows invited users to create accounts + "ping"; -- Replies to XMPP pings with pongs + "register"; -- Allow users to register on this server using a client and change passwords + "time"; -- Let others know the time here on this server + "uptime"; -- Report how long server has been running + "version"; -- Replies to server version requests + "mam"; -- Store recent messages to allow multi-device synchronization + "turn_external"; -- Provide external STUN/TURN service for e.g. audio/video calls + -- Admin interfaces + "admin_adhoc"; -- Allows administration via an XMPP client that supports ad-hoc commands + "admin_shell"; -- Allow secure administration via 'prosodyctl shell' + "admin_telnet"; + -- HTTP modules + --"bosh"; -- Enable BOSH clients, aka "Jabber over HTTP" + "http_openmetrics"; -- for exposing metrics to stats collectors + --"websocket"; -- XMPP over WebSockets + "unknown" + + -- Other specific functionality + --"announce"; -- Send announcement to all online users + -- "groups"; -- Shared roster support + --"legacyauth"; -- Legacy authentication. Only used by some old clients and bots. + --"mimicking"; -- Prevent address spoofing + --"motd"; -- Send a message to users when they log in + --"proxy65"; -- Enables a file transfer proxy service which clients behind NAT can use + --"s2s_bidi"; -- Bi-directional server-to-server (XEP-0288) + --"server_contact_info"; -- Publish contact information for this service + --"tombstones"; -- Prevent registration of deleted accounts + --"watchregistrations"; -- Alert admins of registrations + --"welcome"; -- Welcome users who register accounts +} + +modules_disabled = { + -- "offline"; -- Store offline messages + -- "c2s"; -- Handle client connections + -- "s2s"; -- Handle server-to-server connections + -- "posix"; -- POSIX functionality, sends server to background, etc. +} +-- Auth -- +allow_unencrypted_plain_auth = true +c2s_require_encryption = false +s2s_secure_auth = true +allow_registration = false +registration_invite_only = false +authentication = "internal_hashed" + cyrus_service_name = "xmpp" + +limits = { + c2s = { + rate = "1000kb/s"; + }; + s2sin = { + rate = "3000kb/s"; + }; +} + +pidfile = "/run/prosody/prosody.pid" + +-- Arhive Message -- +--storage = "sql" -- Default is "internal" +--sql = { driver = "PostgreSQL", database = "prosody", username = "prosody", password = "okArkhipsql)(%", host = "localhost" } + +archive_expires_after = "never" + +-- TURN -- +turn_external_host = "bebrik.xyz" +turn_external_secret = "jasdkfladkjfadsklfagj12" + +-- For advanced logging see https://prosody.im/doc/logging +log = { + info = "/var/log/prosody/prosody.log"; -- Change 'info' to 'debug' for verbose logging + error = "/var/log/prosody/prosody.err"; + debug = "/var/log/prosody/prosody_debug.log"; +} +certificates = "certs" + +----------- Virtual hosts ----------- +VirtualHost "porno4free.ru" +ssl = { + key = "/etc/prosody/ssl/porno4free.ru.key"; + certificate = "/etc/prosody/ssl/porno4free.ru.fullchain.pem"; +} + +------ Components ------ +Component "chat.porno4free.ru" "muc" + modules_enabled = { "muc_mam" } + restrict_room_creation = "local" + muc_room_default_language = "ru" + muc_room_default_history_length = 228 + +Component "proxy.porno4free.ru" "proxy65" + +Component "uploads.porno4free.ru" "http_upload_external" + http_upload_external_base_url = "https://uploads.porno4free.ru/" + http_upload_external_secret = "bebra228" + http_upload_external_file_size_limit = 2147483648 diff --git a/sources.list b/sources.list new file mode 100644 index 0000000..b872a69 --- /dev/null +++ b/sources.list @@ -0,0 +1,8 @@ +deb http://192.168.1.2:8081/repository/debian-mirror bookworm main +deb-src http://192.168.1.2:8081/repository/debian-mirror bookworm main +deb http://192.168.1.2:8081/repository/debian-mirror-security bookworm-security main +deb-src http://192.168.1.2:8081/repository/debian-mirror-security bookworm-security main +deb http://192.168.1.2:8081/repository/debian-mirror bookworm-backports main +deb-src http://192.168.1.2:8081/repository/debian-mirror bookworm-backports main + +