Add VPN configuration tools and agent documentation
Created comprehensive VPN setup tooling for Peaceful Spirit L2TP/IPsec connection and enhanced agent documentation framework. VPN Configuration (PST-NW-VPN): - Setup-PST-L2TP-VPN.ps1: Automated L2TP/IPsec setup with split-tunnel and DNS - Connect-PST-VPN.ps1: Connection helper with PPP adapter detection, DNS (192.168.0.2), and route config (192.168.0.0/24) - Connect-PST-VPN-Standalone.ps1: Self-contained connection script for remote deployment - Fix-PST-VPN-Auth.ps1: Authentication troubleshooting for CHAP/MSChapv2 - Diagnose-VPN-Interface.ps1: Comprehensive VPN interface and routing diagnostic - Quick-Test-VPN.ps1: Fast connectivity verification (DNS/router/routes) - Add-PST-VPN-Route-Manual.ps1: Manual route configuration helper - vpn-connect.bat, vpn-disconnect.bat: Simple batch file shortcuts - OpenVPN config files (Windows-compatible, abandoned for L2TP) Key VPN Implementation Details: - L2TP creates PPP adapter with connection name as interface description - UniFi auto-configures DNS (192.168.0.2) but requires manual route to 192.168.0.0/24 - Split-tunnel enabled (only remote traffic through VPN) - All-user connection for pre-login auto-connect via scheduled task - Authentication: CHAP + MSChapv2 for UniFi compatibility Agent Documentation: - AGENT_QUICK_REFERENCE.md: Quick reference for all specialized agents - documentation-squire.md: Documentation and task management specialist agent - Updated all agent markdown files with standardized formatting Project Organization: - Moved conversation logs to dedicated directories (guru-connect-conversation-logs, guru-rmm-conversation-logs) - Cleaned up old session JSONL files from projects/msp-tools/ - Added guru-connect infrastructure (agent, dashboard, proto, scripts, .gitea workflows) - Added guru-rmm server components and deployment configs Technical Notes: - VPN IP pool: 192.168.4.x (client gets 192.168.4.6) - Remote network: 192.168.0.0/24 (router at 192.168.0.10) - PSK: rrClvnmUeXEFo90Ol+z7tfsAZHeSK6w7 - Credentials: pst-admin / 24Hearts$ Files: 15 VPN scripts, 2 agent docs, conversation log reorganization, guru-connect/guru-rmm infrastructure additions Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
This commit is contained in:
69
projects/msp-tools/guru-rmm/server/Dockerfile
Normal file
69
projects/msp-tools/guru-rmm/server/Dockerfile
Normal file
@@ -0,0 +1,69 @@
|
||||
# GuruRMM Server Dockerfile
|
||||
# Multi-stage build for minimal image size
|
||||
|
||||
# ============================================
|
||||
# Build Stage
|
||||
# ============================================
|
||||
FROM rust:1.85-alpine AS builder
|
||||
|
||||
# Install build dependencies
|
||||
RUN apk add --no-cache musl-dev openssl-dev openssl-libs-static pkgconfig
|
||||
|
||||
# Create app directory
|
||||
WORKDIR /app
|
||||
|
||||
# Copy manifests first for better caching
|
||||
COPY Cargo.toml Cargo.lock* ./
|
||||
|
||||
# Create dummy src to build dependencies
|
||||
RUN mkdir src && echo "fn main() {}" > src/main.rs
|
||||
|
||||
# Pin home crate to version compatible with Rust 1.85 (0.5.12 requires Rust 1.88)
|
||||
RUN cargo update home --precise 0.5.9
|
||||
|
||||
# Build dependencies only (this layer will be cached)
|
||||
RUN cargo build --release && rm -rf src target/release/deps/gururmm*
|
||||
|
||||
# Copy actual source code
|
||||
COPY src ./src
|
||||
COPY migrations ./migrations
|
||||
|
||||
# Build the actual application
|
||||
RUN cargo build --release
|
||||
|
||||
# ============================================
|
||||
# Runtime Stage
|
||||
# ============================================
|
||||
FROM alpine:3.19
|
||||
|
||||
# Install runtime dependencies
|
||||
RUN apk add --no-cache ca-certificates libgcc
|
||||
|
||||
# Create non-root user
|
||||
RUN addgroup -g 1000 gururmm && \
|
||||
adduser -u 1000 -G gururmm -s /bin/sh -D gururmm
|
||||
|
||||
# Create app directory
|
||||
WORKDIR /app
|
||||
|
||||
# Copy binary from builder
|
||||
COPY --from=builder /app/target/release/gururmm-server /app/gururmm-server
|
||||
|
||||
# Copy migrations (for runtime migrations)
|
||||
COPY --from=builder /app/migrations /app/migrations
|
||||
|
||||
# Set ownership
|
||||
RUN chown -R gururmm:gururmm /app
|
||||
|
||||
# Switch to non-root user
|
||||
USER gururmm
|
||||
|
||||
# Expose port
|
||||
EXPOSE 3001
|
||||
|
||||
# Health check (use 127.0.0.1 instead of localhost to avoid IPv6 issues)
|
||||
HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \
|
||||
CMD wget --no-verbose --tries=1 --spider http://127.0.0.1:3001/health || exit 1
|
||||
|
||||
# Run the server
|
||||
CMD ["/app/gururmm-server"]
|
||||
Reference in New Issue
Block a user