Browse Source

Algne import: hetzner serveri Docker konteinerite konfiguratsioonid

- cms/ — drupal, hugo, nginx, wordpress
- db/ — adminer, mariadb, postgis, postgres, redis
- other/ — nominatim, ojs
- R/ — r-studio, shiny
- server/ — gogs, ldap, mailserver, memcached, nginx_www, opencloud, openvpn, portainer, registry, traefik, webdav
root 1 month ago
commit
fba35a4cbe
100 changed files with 4694 additions and 0 deletions
  1. 55 0
      .gitignore
  2. 6 0
      LOEMIND.txt
  3. 66 0
      R/r-studio/r-studio/LOEMIND.txt
  4. 21 0
      R/r-studio/r-studio/cleanup.sh
  5. 71 0
      R/r-studio/r-studio/docker-compose.yml
  6. 18 0
      R/r-studio/r-studio/run.sh
  7. 13 0
      R/r-studio/r-studio/scripts/cron.sh
  8. 39 0
      R/shiny/paberkrohv/LOEMIND.txt
  9. 21 0
      R/shiny/paberkrohv/cleanup.sh
  10. 79 0
      R/shiny/paberkrohv/docker-compose.yml
  11. 15 0
      R/shiny/paberkrohv/docker/Dockerfile
  12. 28 0
      R/shiny/paberkrohv/run.sh
  13. 128 0
      cms/drupal/docker-compose.yml
  14. 23 0
      cms/drupal/merbond/LOEMIND.txt
  15. 21 0
      cms/drupal/merbond/cleanup.sh
  16. 54 0
      cms/drupal/merbond/drupal.yml
  17. 54 0
      cms/drupal/merbond/drupal.yml.251027
  18. 53 0
      cms/drupal/merbond/drupal.yml.xxx
  19. 18 0
      cms/drupal/merbond/run.sh
  20. 39 0
      cms/drupal/mustikas/LOEMIND.txt
  21. 1 0
      cms/drupal/mustikas/account.conf
  22. 2 0
      cms/drupal/mustikas/ca/acme-v02.api.letsencrypt.org/ca.conf
  23. 21 0
      cms/drupal/mustikas/cleanup.sh
  24. 59 0
      cms/drupal/mustikas/drupal.yml
  25. 80 0
      cms/drupal/mustikas/drupal.yml.xxx
  26. 12 0
      cms/drupal/mustikas/http.header
  27. 27 0
      cms/drupal/mustikas/mustikas.maastikuarhitekt.ee/ca.cer
  28. 58 0
      cms/drupal/mustikas/mustikas.maastikuarhitekt.ee/fullchain.cer
  29. 31 0
      cms/drupal/mustikas/mustikas.maastikuarhitekt.ee/mustikas.maastikuarhitekt.ee.cer
  30. 15 0
      cms/drupal/mustikas/mustikas.maastikuarhitekt.ee/mustikas.maastikuarhitekt.ee.conf
  31. 8 0
      cms/drupal/mustikas/mustikas.maastikuarhitekt.ee/mustikas.maastikuarhitekt.ee.csr.conf
  32. 18 0
      cms/drupal/mustikas/run.sh
  33. 25 0
      cms/drupal/mustikas/sertifikaatide_genereerimine.sh
  34. 23 0
      cms/drupal/see1/LOEMIND.txt
  35. 21 0
      cms/drupal/see1/cleanup.sh
  36. 54 0
      cms/drupal/see1/drupal.yml
  37. 27 0
      cms/drupal/see1/run.sh
  38. 23 0
      cms/drupal/terminator/LOEMIND.txt
  39. 21 0
      cms/drupal/terminator/cleanup.sh
  40. 56 0
      cms/drupal/terminator/drupal.yml
  41. 23 0
      cms/drupal/terminator/run.sh
  42. 17 0
      cms/drupal/terminator/scripts/composer_install.sh
  43. 0 0
      cms/hugo/hartwig/LOEMIND.txt
  44. 20 0
      cms/hugo/hartwig/cleanup.sh
  45. 28 0
      cms/hugo/hartwig/docker-compose.yml
  46. 40 0
      cms/hugo/hartwig/hugo.yml
  47. 18 0
      cms/hugo/hartwig/run.sh
  48. 0 0
      cms/nginx/www/LOEMIND.txt
  49. 21 0
      cms/nginx/www/cleanup.sh
  50. 70 0
      cms/nginx/www/docker-compose.yml
  51. 67 0
      cms/nginx/www/docker-compose.yml.xxx
  52. 19 0
      cms/nginx/www/run.sh
  53. 14 0
      cms/wordpress/nuudi/LOEMIND.txt
  54. 21 0
      cms/wordpress/nuudi/cleanup.sh
  55. 44 0
      cms/wordpress/nuudi/docker-compose.yml
  56. 18 0
      cms/wordpress/nuudi/run.sh
  57. 73 0
      cms/wordpress/nuudi/wordpress.yml
  58. 3 0
      db/adminer/LOEMIND.txt
  59. 34 0
      db/adminer/adminer.yml
  60. 20 0
      db/adminer/cleanup.sh
  61. 27 0
      db/adminer/docker-compose.yml
  62. 4 0
      db/adminer/run.sh
  63. 16 0
      db/mariadb/KUIDAS_ALUSTADA.txt
  64. 53 0
      db/mariadb/LOEMIND.txt
  65. 20 0
      db/mariadb/cleanup.sh
  66. 106 0
      db/mariadb/first_time_run.sh
  67. 135 0
      db/mariadb/mariadb.yml
  68. 5 0
      db/mariadb/run.sh
  69. 54 0
      db/mariadb_simple/docker-compose.yml
  70. 62 0
      db/mariadb_simple/init.sql
  71. 24 0
      db/postgis/LOEMIND.txt
  72. 20 0
      db/postgis/cleanup.sh
  73. 201 0
      db/postgis/postgis.yml
  74. 209 0
      db/postgis/postgis.yml.xxx
  75. 18 0
      db/postgis/run.sh
  76. 42 0
      db/postgres_simple/docker-compose.yml
  77. 1 0
      db/redis/LOEMIND.txt
  78. 22 0
      db/redis/cleanup.sh
  79. 27 0
      db/redis/docker-compose.yml
  80. 10 0
      db/redis/run.sh
  81. 5 0
      db/run.sh
  82. 13 0
      linux_scripts.sh
  83. 55 0
      other/nominatim/LOEMIND.txt
  84. 21 0
      other/nominatim/cleanup.sh
  85. 24 0
      other/nominatim/conf/LOEMIND.txt
  86. 105 0
      other/nominatim/conf/pg_hba.conf
  87. 104 0
      other/nominatim/conf/pg_hba.conf.backup
  88. 53 0
      other/nominatim/docker-compose.yml
  89. 57 0
      other/nominatim/run.sh
  90. 8 0
      other/ojs/LOEMIND.txt
  91. 22 0
      other/ojs/cleanup.sh
  92. 31 0
      other/ojs/config/htaccess
  93. 34 0
      other/ojs/config/ojs.conf
  94. 530 0
      other/ojs/config/ojs.config.inc
  95. 1 0
      other/ojs/config/php.custom.ini
  96. 20 0
      other/ojs/config/supervisord.conf
  97. 532 0
      other/ojs/configs/config_inc_php_v2
  98. 2 0
      other/ojs/configs/custom_ini
  99. 32 0
      other/ojs/configs/htaccess
  100. 35 0
      other/ojs/configs/ojs_conf

+ 55 - 0
.gitignore

@@ -0,0 +1,55 @@
+# Docker
+**/archive/
+**/state/
+**/data/
+**/cache/
+**/repo/
+**/backups/
+
+# Env
+.env
+!.env.example
+
+# Editor
+*.swp
+*.swo
+*~
+.DS_Store
+Thumbs.db
+.idea/
+.vscode/
+
+# Logs
+*.log
+*.logs
+
+# Tundlikud failid
+*.key
+*.pem
+*.csr
+**/.secrets/
+**/account.json
+**/account.key
+**/id_ed25519
+**/id_ed25519.pub
+
+# Python
+__pycache__/
+*.py[cod]
+*.so
+
+# OS
+lost+found/
+
+# Kasutusest eemaldatud
+x_kasutusest_väljas/
+
+# Traefik SSL sertifikaadid (sisaldab privaatvõtmeid)
+server/traefik/certs/letsencrypt/acme.json
+
+# Juhuslikud logid ja väljundid
+**/logi.txt
+**/vastused.txt
+
+# Embedded git repo
+other/nominatim/nominatim-docker/

+ 6 - 0
LOEMIND.txt

@@ -0,0 +1,6 @@
+# history limit
+docker swarm update --task-history-limit 2
+
+# obtain worker token
+docker swarm join-token worker
+

+ 66 - 0
R/r-studio/r-studio/LOEMIND.txt

@@ -0,0 +1,66 @@
+# !!!!!!!!!!
+
+# Uue rocker image juures vajalikud installimised.
+cont_name=shiny-r-studio
+docker exec -ti -u 0 ${cont_name} sh -c ' \
+apt-get update && \
+apt-get install -y --no-install-recommends \
+libpq-dev libcairo2-dev libxt-dev libxml2 libxml2-dev \
+libglpk-dev imagemagick'
+
+# imageJ installimine
+# Lae all Fiji.app https://imagej.net/Fiji/Downloads
+fiji_name=fiji-linux64-20170530.zip
+wget https://downloads.imagej.net/fiji/Life-Line/${fiji_name}
+unzip ${fiji_name}
+ln -s Fiji.app/ImageJ-linux64 ImageJ-linux64
+
+# test https://imagej.net/Scripting_Headless
+./ImageJ-linux64 --ij2 --headless
+
+
+# Proovi käsk piltide konvertimiseks
+ImageJ-linux64  --headless --console -macro ./ijm/RunBatch.ijm 'img/'
+
+
+## -------------- vana versioon ------------------
+# Kui V8 shiny's ei tööta
+cont_name=shiny-r-studio
+docker exec -ti -u 0 ${cont_name} sh -c ' \
+printf "deb http://archive.debian.org/debian/ jessie main\ndeb-src http://archive.debian.org/debian/ jessie main\ndeb http://security.debian.org/debian-security/ jessie/updates main\ndeb-src http://security.debian.org/debian-security/ jessie/updates main" > /etc/apt/sources.list && \
+apt-get update && \
+apt-get install -y --no-install-recommends  --force-yes \
+libv8-dev libnlopt-dev libgeos-dev'
+
+# V8 paketi installimiseks Ubuntu 20.04 korral arvutis uthp
+sudo apt-get install libssl1.1=1.1.1f-1ubuntu2
+sudo apt-get install libnode-dev
+#
+
+
+## Täiendused !!!!
+
+docker exec -ti shiny-r-studio bash -c "
+  apt update
+  apt -y upgrade
+  apt install -y iputils-ping libpq-dev postgresql-client build-essential pkg-config libssl-dev \
+  libcairo2 libcairo2-dev libxt-dev libx11-dev libfreetype6-dev libharfbuzz-dev libpng-dev \
+  libjpeg-dev libtiff5-dev nano netcat-traditional iproute2 libxml2-dev curl zlib1g-dev libicu-dev \
+  libreadline-dev libblas-dev liblapack-dev gfortran libglpk-dev cmake ninja-build \
+  libbz2-dev liblzma-dev libpcre2-dev libcurl4-openssl-dev libsqlite3-dev libspatialite-dev \
+  gdal-bin libgdal-dev libgeos-dev libgeos++-dev proj-bin libproj-dev libudunits2-dev   
+  apt -y autoremove
+"
+
+docker exec -ti shiny-r-studio bash -c "
+# units (vajab libudunits2-dev)
+sudo bash -lc 'R -q -e \"install.packages(\"units\", repos=\"https://cloud.r-project.org\", Ncpus=parallel::detectCores())\"'
+# sf (kasutab GDAL/GEOS/PROJ)
+sudo bash -lc 'R -q -e \"install.packages(\"sf\", repos=\"https://cloud.r-project.org\", Ncpus=parallel::detectCores())\"'
+# lwgeom (vajab liblwgeom-dev + sf)
+sudo bash -lc 'R -q -e \"install.packages(\"lwgeom\", repos=\"https://cloud.r-project.org\", Ncpus=parallel::detectCores())\"'
+# lõpuks stplanr
+sudo bash -lc 'R -q -e \"install.packages(\"stplanr\", repos=\"https://cloud.r-project.org\", Ncpus=parallel::detectCores())\"'
+"
+
+

+ 21 - 0
R/r-studio/r-studio/cleanup.sh

@@ -0,0 +1,21 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+echo "Cleaning up..."
+
+docker compose -p "shiny" -f docker-compose.yml down
+
+
+exit 0

+ 71 - 0
R/r-studio/r-studio/docker-compose.yml

@@ -0,0 +1,71 @@
+version: '3.4'
+# docker run --rm -p 8787:8787 -e USER=ardo -e PASSWORD=ardo rocker/rstudio
+services:
+  r-studio:
+    restart: always
+    image: rocker/rstudio
+#    image: mikkelkrogsholm/rstudio:stable
+    container_name: shiny-r-studio
+    environment:
+      - USER=ardo
+      - PASSWORD=tRJMAHLfDSoYWrGufz9O
+      - ADD=shiny
+    volumes:
+      - r-packages:/usr/local/lib/R/site-library
+      - r-studio-home:/home/ardo/rstudio
+      - shiny_paberkrohv-apps:/home/ardo/shiny-apps
+#      - shiny_luise19-apps:/home/ardo/luise19
+#      - shiny_luise20-apps:/home/ardo/luise20
+      - shiny_miki-apps:/home/ardo/miki
+      - shiny_chocko-apps:/home/ardo/chocko
+      - r-studio-backups:/srv/backups
+      - /etc/localtime:/etc/localtime
+    networks:
+      - traefik-external
+      - db-external
+#    ports:
+#      - 8006:3838
+    labels:
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-external
+      - traefik.constraint-label=traefik-external
+      - traefik.http.routers.shiny-r-studio-http.middlewares=http-to-https
+      - traefik.http.routers.shiny-r-studio-https.rule=Host(`r-studio.odamus.com`)
+      - traefik.http.routers.shiny-r-studio-https.entrypoints=websecure
+      - traefik.http.routers.shiny-r-studio-http.rule=Host(`r-studio.odamus.com`)
+      - traefik.http.routers.shiny-r-studio-http.entrypoints=web
+      - "traefik.http.routers.shiny-r-studio-https.tls.certresolver=mychallenge"
+      - traefik.http.services.shiny-r-studio.loadbalancer.server.port=8787
+#    depends_on:
+#      - node
+#      - primary
+
+volumes:
+  r-packages:
+    name: r-packages
+    external: true
+  shiny_paberkrohv-apps:
+    name: shiny_paberkrohv-apps
+    external: true
+#  shiny_luise19-apps:
+#    name: shiny_luise19-apps
+#    external: true
+#  shiny_luise20-apps:
+#    name: shiny_luise20-apps
+#    external: true
+  shiny_miki-apps:
+    name: shiny_miki-apps
+    external: true
+  shiny_chocko-apps:
+    name: shiny_chocko-apps
+    external: true
+  r-studio-home:
+  r-studio-backups:
+networks:
+  traefik-external:
+    external:
+      name: traefik-external
+  db-external:
+    external:
+      name: db-external
+ 

+ 18 - 0
R/r-studio/r-studio/run.sh

@@ -0,0 +1,18 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+docker compose -p "shiny" -f docker-compose.yml up -d
+
+exit 0

+ 13 - 0
R/r-studio/r-studio/scripts/cron.sh

@@ -0,0 +1,13 @@
+#!/bin/bash
+# Sünkroonimise skripti lisamine cron-i.
+
+echo "Sünkroonimine ........"
+
+cont_name=shiny-r-studio
+docker exec -t -u 0 ${cont_name} sh -c ' \
+chmod 0777 -R /home/ardo/.R/gargle/gargle-oauth/; \
+cd /home/ardo/rstudio/filipiinid/postgres_googlesheet_sync; \
+chmod 0777 -R ../postgres_googlesheet_sync/; \
+ls -la; \
+Rscript sync_files/myfitness_sync.R;
+'

+ 39 - 0
R/shiny/paberkrohv/LOEMIND.txt

@@ -0,0 +1,39 @@
+# !!!!!!!!!!
+
+
+# Uue rocker image juures vajalikud installimised.
+cont_name=shiny-paberkrohv
+docker exec -ti -u 0 ${cont_name} sh -c ' \
+apt-get update && \
+apt-get install -y --no-install-recommends \
+libpq-dev libcairo2-dev libxt-dev libxml2 libxml2-dev \
+libglpk-dev imagemagick'
+
+
+## -------------- vana versioon ------------------
+# Kui V8 shiny's ei tööta
+cont_name=shiny-paberkrohv
+docker exec -ti -u 0 ${cont_name} sh -c ' \
+printf "deb http://archive.debian.org/debian/ jessie main\ndeb-src http://archive.debian.org/debian/ jessie main\ndeb http://security.debian.org/debian-security/ jessie/updates main\ndeb-src http://security.debian.org/debian-security/ jessie/updates main" > /etc/apt/sources.list && \
+apt-get update && \
+apt-get install -y --no-install-recommends  --force-yes \
+libv8-dev'
+
+# V8 paketi installimiseks Ubuntu 20.04 korral arvutis uthp
+sudo apt-get install libssl1.1=1.1.1f-1ubuntu2
+sudo apt-get install libnode-dev
+#
+
+## ---------------------------------------------
+## Ühistransport + fotodelt kujundi arvutamin
+docker exec -ti shiny-paberkrohv bash -c "
+  apt update
+  apt -y upgrade
+  apt install -y iputils-ping libpq-dev postgresql-client build-essential pkg-config libssl-dev \
+  libcairo2 libcairo2-dev libxt-dev libx11-dev libfreetype6-dev libharfbuzz-dev libpng-dev \
+  libjpeg-dev libtiff5-dev nano netcat-traditional iproute2 libxml2-dev curl zlib1g-dev libicu-dev \
+  libreadline-dev libblas-dev liblapack-dev gfortran libglpk-dev cmake ninja-build \
+  libbz2-dev liblzma-dev libpcre2-dev libcurl4-openssl-dev libsqlite3-dev libspatialite-dev \
+  gdal-bin libgdal-dev libgeos-dev libgeos++-dev proj-bin libproj-dev libudunits2-dev 
+  apt -y autoremove
+"

+ 21 - 0
R/shiny/paberkrohv/cleanup.sh

@@ -0,0 +1,21 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+echo "Cleaning up..."
+
+docker compose -p "shiny" -f docker-compose.yml down
+
+
+exit 0

+ 79 - 0
R/shiny/paberkrohv/docker-compose.yml

@@ -0,0 +1,79 @@
+services:
+  paberkrohv:
+    restart: always
+    image: shiny-paberkrohv:local
+    container_name: shiny-paberkrohv
+    volumes:
+      - r-packages:/usr/local/lib/R/site-library
+      - shiny_paberkrohv-apps:/srv/shiny-server
+      - shiny_paberkrohv-logs:/var/log
+      - shiny_paberkrohv-conf:/etc/shiny-server
+      - shiny_paberkrohv-backups:/srv/backups
+      - /etc/localtime:/etc/localtime
+    networks:
+      - traefik-external
+      - db-external
+      - db-migration
+    labels:
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-external
+      - traefik.constraint-label=traefik-external
+      - traefik.http.routers.shiny-paberkrohv-http.middlewares=http-to-https
+      - traefik.http.routers.shiny-paberkrohv-https.rule=Host(`r-shiny.odamus.com`)
+      - traefik.http.routers.shiny-paberkrohv-https.entrypoints=websecure
+      - traefik.http.routers.shiny-paberkrohv-http.rule=Host(`r-shiny.odamus.com`)
+      - traefik.http.routers.shiny-paberkrohv-http.entrypoints=web
+      - "traefik.http.routers.shiny-paberkrohv-https.tls.certresolver=mychallenge"
+      - traefik.http.services.shiny-paberkrohv.loadbalancer.server.port=3838
+
+  tudengitele:
+    restart: always
+    image: rocker/shiny
+    container_name: shiny-tudengitele
+    volumes:
+      - r-packages:/usr/local/lib/R/site-library
+      - tudengitele-apps:/srv/shiny-server
+      - tudengitele-logs:/var/log
+      - tudengitele-conf:/etc/shiny-server
+      - tudengitele-backups:/srv/backups
+      - /etc/localtime:/etc/localtime
+    networks:
+      - traefik-external
+      - db-external
+    labels:
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-external
+      - traefik.constraint-label=traefik-external
+      - traefik.http.routers.shiny-tudengitele-http.middlewares=http-to-https
+      - traefik.http.routers.shiny-tudengitele-https.rule=Host(`paberkrohv.odamus.com`)
+      - traefik.http.routers.shiny-tudengitele-https.entrypoints=websecure
+      - traefik.http.routers.shiny-tudengitele-http.rule=Host(`paberkrohv.odamus.com`)
+      - traefik.http.routers.shiny-tudengitele-http.entrypoints=web
+      - "traefik.http.routers.shiny-tudengitele-https.tls.certresolver=mychallenge"
+      - traefik.http.services.shiny-tudengitele.loadbalancer.server.port=3838
+
+volumes:
+  r-packages:
+    name: r-packages
+    external: true
+  shiny_paberkrohv-apps:
+    external: true
+  shiny_paberkrohv-conf:
+    external: true
+  shiny_paberkrohv-backups:
+    external: true
+  shiny_paberkrohv-logs:
+    external: true
+  tudengitele-apps:
+  tudengitele-conf:
+  tudengitele-backups:
+  tudengitele-logs:
+networks:
+  traefik-external:
+    external: true
+    name: traefik-external
+  db-external:
+    external: true
+    name: db-external
+  db-migration:
+    external: true

+ 15 - 0
R/shiny/paberkrohv/docker/Dockerfile

@@ -0,0 +1,15 @@
+FROM rocker/shiny
+
+RUN apt-get update -qq \
+    && apt-get install -y -qq \
+        libpq5 \
+        libxml2 \
+        libfftw3-3 \
+        libglpk40 \
+        libgsl23 \
+        libmysqlclient21 \
+        libsodium23 \
+        libudunits2-0 \
+        libproj15 \
+        libgeos-c1v5 \
+    && rm -rf /var/lib/apt/lists/*

+ 28 - 0
R/shiny/paberkrohv/run.sh

@@ -0,0 +1,28 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+docker compose -p "shiny" -f docker-compose.yml up -d
+
+sleep 2
+
+# Uue rocker image juures vajalikud installimised.
+cont_name=shiny-paberkrohv
+docker exec -ti -u 0 ${cont_name} sh -c ' \
+apt-get update && \
+apt-get install -y --no-install-recommends \
+libpq-dev libcairo2-dev libxt-dev libxml2'
+
+
+exit 0

+ 128 - 0
cms/drupal/docker-compose.yml

@@ -0,0 +1,128 @@
+services:
+  mustikas:
+    image: registry.odamus.com/drupal/drupal_7_rong:latest
+    container_name: drupal_mustikas
+    restart: unless-stopped
+    volumes:
+      - drupal_mustikas-1-html:/var/www/html
+      - drupal_mustikas-1-backups:/root/drush-backups
+      - /etc/localtime:/etc/localtime
+    networks:
+      - traefik-network
+      - db-migration
+    labels:
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-network
+      - traefik.constraint-label=traefik-network
+      - traefik.http.routers.drupal-emal-http.middlewares=http-to-https
+      - traefik.http.routers.drupal-emal-https.rule=Host(`emal.odamus.com`) || Host(`mustikas.odamus.com`) || Host(`mustikas.maastikuarhitekt.ee`)
+      - traefik.http.routers.drupal-emal-https.entrypoints=websecure
+      - traefik.http.routers.drupal-emal-http.rule=Host(`emal.odamus.com`) || Host(`mustikas.odamus.com`) || Host(`mustikas.maastikuarhitekt.ee`)
+      - traefik.http.routers.drupal-emal-http.entrypoints=web
+      - "traefik.http.routers.drupal-emal-https.tls.certresolver=mychallenge"
+      - traefik.http.services.drupal-emal.loadbalancer.server.port=80
+
+  merbond:
+    image: registry.odamus.com/drupal/drupal_7_rong:latest
+    container_name: drupal_merbond
+    restart: unless-stopped
+    volumes:
+      - drupal_merbond-1-html:/var/www/html
+      - drupal_merbond-1-backups:/root/drush-backups
+      - /etc/localtime:/etc/localtime
+    networks:
+      - traefik-network
+      - db-migration
+    labels:
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-network
+      - traefik.constraint-label=traefik-network
+      - traefik.http.routers.drupal-merbond-http.middlewares=http-to-https
+      - traefik.http.routers.drupal-merbond-https.rule=Host(`merbond.odamus.com`)
+      - traefik.http.routers.drupal-merbond-https.entrypoints=websecure
+      - traefik.http.routers.drupal-merbond-http.rule=Host(`merbond.odamus.com`)
+      - traefik.http.routers.drupal-merbond-http.entrypoints=web
+      - "traefik.http.routers.drupal-merbond-https.tls.certresolver=mychallenge"
+      - traefik.http.services.drupal-merbond.loadbalancer.server.port=80
+
+  see1:
+    image: drupal:9
+    container_name: drupal_see1
+    restart: unless-stopped
+    volumes:
+      - drupal_see1-1-modules:/var/www/html/modules
+      - drupal_see1-1-profile:/var/www/html/profiles
+      - drupal_see1-1-sites:/var/www/html/sites
+      - drupal_see1-1-theme:/var/www/html/themes
+      - /etc/localtime:/etc/localtime
+    networks:
+      - traefik-network
+      - db-migration
+    labels:
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-network
+      - traefik.constraint-label=traefik-network
+      - traefik.http.routers.drupal-see1-http.middlewares=http-to-https
+      - traefik.http.routers.drupal-see1-https.rule=Host(`www.see1.ee`)
+      - traefik.http.routers.drupal-see1-https.entrypoints=websecure
+      - traefik.http.routers.drupal-see1-http.rule=Host(`www.see1.ee`)
+      - traefik.http.routers.drupal-see1-http.entrypoints=web
+      - "traefik.http.routers.drupal-see1-https.tls.certresolver=mychallenge"
+      - traefik.http.services.drupal-see1.loadbalancer.server.port=80
+
+  terminator:
+    image: drupal:8-apache
+    container_name: drupal_terminator
+    restart: unless-stopped
+    volumes:
+      - drupal_terminator-1-modules:/var/www/html/modules
+      - drupal_terminator-1-profile:/var/www/html/profiles
+      - drupal_terminator-1-sites:/var/www/html/sites
+      - drupal_terminator-1-theme:/var/www/html/themes
+      - /etc/localtime:/etc/localtime
+    networks:
+      - traefik-network
+      - db-migration
+    labels:
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-network
+      - traefik.constraint-label=traefik-network
+      - traefik.http.routers.drupal-terminator-http.middlewares=http-to-https
+      - traefik.http.routers.drupal-terminator-https.rule=Host(`terminator.odamus.com`)
+      - traefik.http.routers.drupal-terminator-https.entrypoints=websecure
+      - traefik.http.routers.drupal-terminator-http.rule=Host(`terminator.odamus.com`)
+      - traefik.http.routers.drupal-terminator-http.entrypoints=web
+      - "traefik.http.routers.drupal-terminator-https.tls.certresolver=mychallenge"
+      - traefik.http.services.drupal-terminator.loadbalancer.server.port=80
+
+volumes:
+  drupal_mustikas-1-html:
+    external: true
+  drupal_mustikas-1-backups:
+    external: true
+  drupal_merbond-1-html:
+    external: true
+  drupal_merbond-1-backups:
+    external: true
+  drupal_see1-1-modules:
+    external: true
+  drupal_see1-1-profile:
+    external: true
+  drupal_see1-1-sites:
+    external: true
+  drupal_see1-1-theme:
+    external: true
+  drupal_terminator-1-modules:
+    external: true
+  drupal_terminator-1-profile:
+    external: true
+  drupal_terminator-1-sites:
+    external: true
+  drupal_terminator-1-theme:
+    external: true
+
+networks:
+  traefik-network:
+    external: true
+  db-migration:
+    external: true

+ 23 - 0
cms/drupal/merbond/LOEMIND.txt

@@ -0,0 +1,23 @@
+
+apt update
+apt -y install curl git unzip vim wget && \
+apt-get clean
+# Drupali tuuma install
+composer install
+# To see which versions of Drupal core are available, use this command
+composer show drupal/recommended-project --all
+#Check for available Drupal core and module updates:
+composer outdated drupal/*
+# All of your modules and themes can be updated along with Drupal core via:
+composer update
+
+
+# Mooduli install
+php -d memory_limit=-1 `which composer` require 'drupal/masquerade' --update-no-dev  --update-with-all-dependencies
+# SMTP
+php -d memory_limit=-1 `which composer` require 'phpmailer/phpmailer' --update-no-dev
+php -d memory_limit=-1 `which composer` require 'drupal/smtp' --update-no-dev --update-with-all-dependencies
+# Theme
+php -d memory_limit=-1 `which composer` require 'drupal/d8w3css' --update-no-dev --update-with-all-dependencies
+#composer remove 'drupal/d8w3css' --update-with-dependencies
+

+ 21 - 0
cms/drupal/merbond/cleanup.sh

@@ -0,0 +1,21 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+echo "Cleaning up..."
+
+#docker stack rm drupal
+docker service rm drupal_merbond
+
+exit 0

+ 54 - 0
cms/drupal/merbond/drupal.yml

@@ -0,0 +1,54 @@
+version: '3.4'
+services:
+  merbond:
+#    depends_on:
+#      - node
+    deploy:
+      replicas: 1
+      mode: replicated
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == hetzner
+#      resources:
+#        limits:
+#          cpus: '0.5'
+#          memory: 256M #1024M
+#        reservations:
+#          cpus: '0.5'
+#          memory: 256M
+    image: registry.odamus.com/drupal/drupal_7_rong:latest
+#    ports:
+#      - 8006:80
+    labels:
+      traefik.http.services.drupal-merbond.loadbalancer.server.port: '80'
+      traefik.http.routers.drupal-merbond-https.tls.certresolver: mychallenge
+      traefik.http.routers.drupal-merbond-http.entrypoints: web
+      traefik.http.routers.drupal-merbond-https.entrypoints: websecure
+      traefik.http.routers.drupal-merbond-http.middlewares: http-to-https
+      traefik.http.routers.drupal-merbond-http.rule: Host(`merbond.odamus.com`)
+      traefik.constraint-label: traefik-network
+      traefik.docker.network: traefik-network
+      traefik.enable: 'true'
+      traefik.http.routers.drupal-merbond-https.rule: Host(`merbond.odamus.com`)
+    volumes:
+      - drupal_html:/var/www/html
+      - drupal_backups:/root/drush-backups
+      - /etc/localtime:/etc/localtime
+    networks:
+      - db-network
+      - traefik-network
+
+volumes:
+  drupal_html:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-html'
+    driver: local
+  drupal_backups:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-backups'
+    driver: local
+
+networks:
+  db-network:
+    external: true
+  traefik-network:
+    external: true

+ 54 - 0
cms/drupal/merbond/drupal.yml.251027

@@ -0,0 +1,54 @@
+version: '3.4'
+services:
+  merbond:
+#    depends_on:
+#      - node
+    deploy:
+      replicas: 1
+      mode: replicated
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == hetzner
+#      resources:
+#        limits:
+#          cpus: '0.5'
+#          memory: 256M #1024M
+#        reservations:
+#          cpus: '0.5'
+#          memory: 256M
+    image: registry.odamus.com/drupal/drupal_7_rong:latest
+#    ports:
+#      - 8006:80
+    labels:
+      traefik.http.services.drupal-merbond.loadbalancer.server.port: '80'
+      traefik.http.routers.drupal-merbond-https.tls.certresolver: mychallenge
+      traefik.http.routers.drupal-merbond-http.entrypoints: web
+      traefik.http.routers.drupal-merbond-https.entrypoints: websecure
+      traefik.http.routers.drupal-merbond-http.middlewares: http-to-https
+      traefik.http.routers.drupal-merbond-http.rule: Host(`merbond.odamus.com`)
+      traefik.constraint-label: traefik-network
+      traefik.docker.network: traefik-network
+      traefik.enable: 'true'
+      traefik.http.routers.drupal-merbond-https.rule: Host(`merbond.odamus.com`)
+    volumes:
+      - drupal_html:/var/www/html
+      - drupal_backups:/root/drush-backups
+      - /etc/localtime:/etc/localtime
+    networks:
+      - db-network
+      - traefik-network
+
+volumes:
+  drupal_html:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-html'
+    driver: local
+  drupal_backups:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-backups'
+    driver: local
+
+networks:
+  db-network:
+    external: true
+  traefik-network:
+    external: true

+ 53 - 0
cms/drupal/merbond/drupal.yml.xxx

@@ -0,0 +1,53 @@
+version: '3.8'
+
+services:
+  merbond:
+    image: registry.odamus.com/drupal/drupal_7_rong:latest
+#    depends_on:
+#      - node
+    networks:
+      - db-network
+      - traefik-network
+    volumes:
+      - type: volume
+        source: drupal_html
+        target: /var/www/html
+      - type: volume
+        source: drupal_backups
+        target: /root/drush-backups
+      - type: bind
+        source: /etc/localtime
+        target: /etc/localtime
+        read_only: true
+    deploy:
+      replicas: 1
+      mode: replicated
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == hetzner
+      labels:
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-network
+      - traefik.constraint-label=traefik-network
+      - traefik.http.routers.drupal-see1-http.middlewares=http-to-https
+      - traefik.http.routers.drupal-see1-https.rule=Host(`merbond.odamus.com`)
+      - traefik.http.routers.drupal-see1-https.entrypoints=websecure
+      - traefik.http.routers.drupal-see1-http.rule=Host(`merbond.odamus.com`)
+      - traefik.http.routers.drupal-see1-http.entrypoints=web
+      - "traefik.http.routers.drupal-see1-https.tls.certresolver=mychallenge"
+      - traefik.http.services.drupal-see1.loadbalancer.server.port=80
+
+volumes:
+  drupal_html:
+    name: drupal_merbond-1-html
+    external: true
+  drupal_backups:
+    name: drupal_merbond-1-backups
+    external: true
+
+networks:
+  db-network:
+    external: true
+  traefik-network:
+    external: true

+ 18 - 0
cms/drupal/merbond/run.sh

@@ -0,0 +1,18 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+docker stack deploy --compose-file=./drupal.yml drupal
+
+exit 0

+ 39 - 0
cms/drupal/mustikas/LOEMIND.txt

@@ -0,0 +1,39 @@
+## ----------- teiste domeeni hoidjate alamdomeenidele sertifikaatide genereerimine -----------
+# Dynamic configuration
+# Ardo
+
+#tls:
+#  certificates:
+#    - certFile: /letsencrypt/owngenerated/mustikas.maastikuarhitekt.ee/mustikas.maastikuarhitekt.ee.cer 
+#      keyFile: /letsencrypt/owngenerated/mustikas.maastikuarhitekt.ee/mustikas.maastikuarhitekt.ee.key 
+
+
+#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
+## See töötab
+## Vaata abiks:   https://github.com/acmesh-official/acme.sh
+## Loo saidi juurkataloogi alamkataloogid
+#!/bin/bash
+   mkdir -p /var/lib/docker/volumes/drupal_mustikas-1-html/_data/.well-known/acme-challenge
+   cd /root/.acme.sh
+   acme.sh --issue -d mustikas.maastikuarhitekt.ee -w /var/lib/docker/volumes/drupal_mustikas-1-html/_data
+   cp -R /root/.acme.sh/mustikas.maastikuarhitekt.ee/* /var/lib/docker/volumes/traefik_certs/_data/owngenerated/mustikas.maastikuarhitekt.ee/
+#   taaskäivita traefik ja vaata, et see fail on kah õiges kohas.
+   docker service update traefik_traefik
+## Sertifikaatide värskendamine
+#  toimub automaatselt iga 60 päeva järele. 
+
+## ===================== moodulite värskendamine ========================
+docker exec -ti drupal_mustikas.1.  bash
+## prepopulate mooduli mitte-uuendamine
+drush pm-updatecode --lock=prepopulate
+# drupali tuuma uuendamine
+drush up drupal
+# andmebaasi uuendamine
+drush updb
+# clear cache
+drush cc all
+# registry rebuild
+drush rr
+# moodulite uuendamine
+drush up
+

+ 1 - 0
cms/drupal/mustikas/account.conf

@@ -0,0 +1 @@
+USER_PATH='/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/usr/local/games:/snap/bin'

+ 2 - 0
cms/drupal/mustikas/ca/acme-v02.api.letsencrypt.org/ca.conf

@@ -0,0 +1,2 @@
+ACCOUNT_URL='https://acme-v02.api.letsencrypt.org/acme/acct/110071310'
+CA_KEY_HASH='1jZGQAwud61KqXCC6YUyRZzFZMS7vuhUXQF3SCb5EEY='

+ 21 - 0
cms/drupal/mustikas/cleanup.sh

@@ -0,0 +1,21 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+echo "Cleaning up..."
+
+#docker stack rm drupal
+docker service rm drupal_mustikas
+
+exit 0

+ 59 - 0
cms/drupal/mustikas/drupal.yml

@@ -0,0 +1,59 @@
+version: '3.4'
+services:
+  mustikas:
+#    depends_on:
+#      - node
+    deploy:
+      replicas: 1
+      mode: replicated
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == hetzner
+#      resources:
+#        limits:
+#          cpus: '2'
+#          memory: 1024M
+#        reservations:
+#          cpus: '0.5'
+#          memory: 256M
+
+    image: registry.odamus.com/drupal/drupal_7_rong:latest
+#    ports:
+#      - 8006:80
+    labels:
+      traefik.constraint-label: traefik-network
+      traefik.docker.network: traefik-network
+      traefik.enable: 'true'
+
+      traefik.http.services.drupal-emal.loadbalancer.server.port: '80'
+      traefik.http.routers.drupal-emal-https.tls.certresolver: mychallenge
+      traefik.http.routers.drupal-emal-http.entrypoints: web
+      traefik.http.routers.drupal-emal-https.entrypoints: websecure
+      traefik.http.routers.drupal-emal-http.middlewares: http-to-https
+#      traefik.http.routers.drupal-emal-http.rule: Host(`emal.odamus.com`)
+#      traefik.http.routers.drupal-emal-https.rule: Host(`emal.odamus.com`)
+      traefik.http.routers.drupal-emal-http.rule: Host(`emal.odamus.com`) || Host(`mustikas.odamus.com`) || Host(`mustikas.maastikuarhitekt.ee`)
+      traefik.http.routers.drupal-emal-https.rule: Host(`emal.odamus.com`) || Host(`mustikas.odamus.com`) || Host(`mustikas.maastikuarhitekt.ee`)
+
+    volumes:
+      - drupal_html:/var/www/html
+      - drupal_backups:/root/drush-backups
+      - /etc/localtime:/etc/localtime
+    networks:
+      - db-network
+      - traefik-network
+
+volumes:
+  drupal_html:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-html'
+    driver: local
+  drupal_backups:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-backups'
+    driver: local
+
+networks:
+  db-network:
+    external: true
+  traefik-network:
+    external: true

+ 80 - 0
cms/drupal/mustikas/drupal.yml.xxx

@@ -0,0 +1,80 @@
+version: '3.4'
+services:
+  mustikas:
+#    depends_on:
+#      - node
+    deploy:
+      replicas: 1
+      mode: replicated
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == hetzner
+#      resources:
+#        limits:
+#          cpus: '2'
+#          memory: 1024M
+#        reservations:
+#          cpus: '0.5'
+#          memory: 256M
+
+    image: registry.odamus.com/drupal/drupal_7_rong:latest
+#    ports:
+#      - 8006:80
+    labels:
+      traefik.constraint-label: traefik-network
+      traefik.docker.network: traefik-network
+      traefik.enable: 'true'
+
+      traefik.http.services.drupal-emal.loadbalancer.server.port: '80'
+      traefik.http.routers.drupal-emal-https.tls.certresolver: mychallenge
+      traefik.http.routers.drupal-emal-http.entrypoints: web
+      traefik.http.routers.drupal-emal-https.entrypoints: websecure
+      traefik.http.routers.drupal-emal-http.middlewares: http-to-https
+      traefik.http.routers.drupal-emal-http.rule: Host(`emal.odamus.com`)
+      traefik.http.routers.drupal-emal-https.rule: Host(`emal.odamus.com`)
+
+      ## maastikuarhitekt   
+      traefik.http.routers.drupal-mustikas-http.entrypoints: web
+      traefik.http.routers.drupal-mustikas-http.rule: Host(`mustikas.maastikuarhitekt.ee`)
+      traefik.http.routers.drupal-mustikas-http.service: drupal-mustikas@docker
+      traefik.http.routers.drupal-mustikas-http.middlewares: http-to-https
+      traefik.http.routers.drupal-mustikas-https.entrypoints: websecure
+      traefik.http.routers.drupal-mustikas-https.rule: Host(`mustikas.maastikuarhitekt.ee`)
+      traefik.http.routers.drupal-mustikas-https.service: drupal-mustikas@docker
+      traefik.http.routers.drupal-mustikas-https.tls.certresolver: mychallenge
+      traefik.http.services.drupal-mustikas.loadbalancer.server.port: '80'
+
+      ## odamus
+      traefik.http.routers.odamus-mustikas-http.entrypoints: web
+      traefik.http.routers.odamus-mustikas-http.rule: Host(`mustikas.odamus.com`)
+      traefik.http.routers.odamus-mustikas-http.service: drupal-mustikas@docker
+      traefik.http.routers.odamus-mustikas-http.middlewares: http-to-https
+      traefik.http.routers.odamus-mustikas-https.entrypoints: websecure
+      traefik.http.routers.odamus-mustikas-https.rule: Host(`mustikas.odamus.com`)
+      traefik.http.routers.odamus-mustikas-https.service: drupal-mustikas@docker
+      traefik.http.routers.odamus-mustikas-https.tls.certresolver: mychallenge
+      traefik.http.services.odamus-mustikas.loadbalancer.server.port: '80'
+
+
+    volumes:
+      - drupal_html:/var/www/html
+      - drupal_backups:/root/drush-backups
+      - /etc/localtime:/etc/localtime
+    networks:
+      - db-network
+      - traefik-network
+
+volumes:
+  drupal_html:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-html'
+    driver: local
+  drupal_backups:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-backups'
+    driver: local
+         
+networks:
+  db-network:
+    external: true
+  traefik-network:
+    external: true

+ 12 - 0
cms/drupal/mustikas/http.header

@@ -0,0 +1,12 @@
+HTTP/2 200 
+server: nginx
+date: Tue, 19 Jan 2021 19:11:40 GMT
+content-type: application/pem-certificate-chain
+content-length: 3466
+cache-control: public, max-age=0, no-cache
+link: <https://acme-v02.api.letsencrypt.org/directory>;rel="index"
+link: <https://acme-v02.api.letsencrypt.org/acme/cert/040c025aa3dedc62bc5ce5aa72adbd1b932f/1>;rel="alternate"
+replay-nonce: 0004M_xMFCgDpqH-kLs-fsa_A-PGTTb7wv287p-uDwyFP8o
+x-frame-options: DENY
+strict-transport-security: max-age=604800
+

+ 27 - 0
cms/drupal/mustikas/mustikas.maastikuarhitekt.ee/ca.cer

@@ -0,0 +1,27 @@
+
+-----BEGIN CERTIFICATE-----
+MIIEZTCCA02gAwIBAgIQQAF1BIMUpMghjISpDBbN3zANBgkqhkiG9w0BAQsFADA/
+MSQwIgYDVQQKExtEaWdpdGFsIFNpZ25hdHVyZSBUcnVzdCBDby4xFzAVBgNVBAMT
+DkRTVCBSb290IENBIFgzMB4XDTIwMTAwNzE5MjE0MFoXDTIxMDkyOTE5MjE0MFow
+MjELMAkGA1UEBhMCVVMxFjAUBgNVBAoTDUxldCdzIEVuY3J5cHQxCzAJBgNVBAMT
+AlIzMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuwIVKMz2oJTTDxLs
+jVWSw/iC8ZmmekKIp10mqrUrucVMsa+Oa/l1yKPXD0eUFFU1V4yeqKI5GfWCPEKp
+Tm71O8Mu243AsFzzWTjn7c9p8FoLG77AlCQlh/o3cbMT5xys4Zvv2+Q7RVJFlqnB
+U840yFLuta7tj95gcOKlVKu2bQ6XpUA0ayvTvGbrZjR8+muLj1cpmfgwF126cm/7
+gcWt0oZYPRfH5wm78Sv3htzB2nFd1EbjzK0lwYi8YGd1ZrPxGPeiXOZT/zqItkel
+/xMY6pgJdz+dU/nPAeX1pnAXFK9jpP+Zs5Od3FOnBv5IhR2haa4ldbsTzFID9e1R
+oYvbFQIDAQABo4IBaDCCAWQwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8E
+BAMCAYYwSwYIKwYBBQUHAQEEPzA9MDsGCCsGAQUFBzAChi9odHRwOi8vYXBwcy5p
+ZGVudHJ1c3QuY29tL3Jvb3RzL2RzdHJvb3RjYXgzLnA3YzAfBgNVHSMEGDAWgBTE
+p7Gkeyxx+tvhS5B1/8QVYIWJEDBUBgNVHSAETTBLMAgGBmeBDAECATA/BgsrBgEE
+AYLfEwEBATAwMC4GCCsGAQUFBwIBFiJodHRwOi8vY3BzLnJvb3QteDEubGV0c2Vu
+Y3J5cHQub3JnMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly9jcmwuaWRlbnRydXN0
+LmNvbS9EU1RST09UQ0FYM0NSTC5jcmwwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYf
+r52LFMLGMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjANBgkqhkiG9w0B
+AQsFAAOCAQEA2UzgyfWEiDcx27sT4rP8i2tiEmxYt0l+PAK3qB8oYevO4C5z70kH
+ejWEHx2taPDY/laBL21/WKZuNTYQHHPD5b1tXgHXbnL7KqC401dk5VvCadTQsvd8
+S8MXjohyc9z9/G2948kLjmE6Flh9dDYrVYA9x2O+hEPGOaEOa1eePynBgPayvUfL
+qjBstzLhWVQLGAkXXmNs+5ZnPBxzDJOLxhF2JIbeQAcH5H0tZrUlo5ZYyOqA7s9p
+O5b85o3AM/OJ+CktFBQtfvBhcJVd9wvlwPsk+uyOy2HI7mNxKKgsBTt375teA2Tw
+UdHkhVNcsAKX1H7GNNLOEADksd86wuoXvg==
+-----END CERTIFICATE-----

+ 58 - 0
cms/drupal/mustikas/mustikas.maastikuarhitekt.ee/fullchain.cer

@@ -0,0 +1,58 @@
+-----BEGIN CERTIFICATE-----
+MIIFPjCCBCagAwIBAgISBAwCWqPe3GK8XOWqcq29G5MvMA0GCSqGSIb3DQEBCwUA
+MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD
+EwJSMzAeFw0yMTAxMTkxODExMzlaFw0yMTA0MTkxODExMzlaMCcxJTAjBgNVBAMT
+HG11c3Rpa2FzLm1hYXN0aWt1YXJoaXRla3QuZWUwggEiMA0GCSqGSIb3DQEBAQUA
+A4IBDwAwggEKAoIBAQC/XSg9MLP1hZ4KXFdy7OmaUPXmdIiB4gD5hJ1Y/cQt5RhK
+SDJJDdn4tcA0UAiZShBX+CVk0+PFP3W5TTBQZTDqNuhDwbMqUD6XSnsL7J5pe9O5
+ldzPe04k+ox0ozCtEDe3EYIy+b5dIEOyL5evN//RwlmEKQkL6ldRJtqVyWa8EXN1
+i8OasSqUFqhlF/g24FGWX9N9e5cFSXcGSDKVL8dUk4ttk8MAfhUCNZxPXRIRFdGy
+mJCaCwmKXtvoUqOFOQI7ACgJDXGVpBA5znhmdsKTZUEQS5nARi93UYRZFzu031NW
++giYBFB9541yd2bictvty1hY87paAugYKq8wx+L3AgMBAAGjggJXMIICUzAOBgNV
+HQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMAwGA1Ud
+EwEB/wQCMAAwHQYDVR0OBBYEFAVjzs4yKxq6lPZwsRDY9oEWy6SfMB8GA1UdIwQY
+MBaAFBQusxe3WFbLrlAJQOYfr52LFMLGMFUGCCsGAQUFBwEBBEkwRzAhBggrBgEF
+BQcwAYYVaHR0cDovL3IzLm8ubGVuY3Iub3JnMCIGCCsGAQUFBzAChhZodHRwOi8v
+cjMuaS5sZW5jci5vcmcvMCcGA1UdEQQgMB6CHG11c3Rpa2FzLm1hYXN0aWt1YXJo
+aXRla3QuZWUwTAYDVR0gBEUwQzAIBgZngQwBAgEwNwYLKwYBBAGC3xMBAQEwKDAm
+BggrBgEFBQcCARYaaHR0cDovL2Nwcy5sZXRzZW5jcnlwdC5vcmcwggEEBgorBgEE
+AdZ5AgQCBIH1BIHyAPAAdgBvU3asMfAxGdiZAKRRFf93FRwR2QLBACkGjbIImjfZ
+EwAAAXccD0eYAAAEAwBHMEUCIC18jJ/GGt3LXePTKZHWXyxwIG4V/ODR/7HYyxbF
+LH2CAiEAl+8aWtEo+a6hLGRz0ABRrgCqH/0NTC5CrdR5hN1y1T4AdgD2XJQv0Xcw
+IhRUGAgwlFaO400TGTO/3wwvIAvMTvFk4wAAAXccD0fnAAAEAwBHMEUCIDOjMmKk
+P9o3LCoIueFflOABAZCC/svBKwHyTfXAfMQ2AiEA+ZitIPUOMlRCPMEIh/t+PKNe
+ebhVrAfcB5oribSW4uAwDQYJKoZIhvcNAQELBQADggEBAB+WBv6YCUkC9ehOW96g
+gZva4R1l1l2COLPYkDI1ONAt1kQobxqoUPDFx252G2TF/WKUaEc2DBCB0814+AJo
+4RTe1y2RVtkOldYlh97yLnGOzB/kQA/OLfasF9c91UOiGdOtJ6O+PPCPZ39F4qxO
+c6k0b1eXJrm6EQPKsrk5nV0etAVClxfQqQVWitZX146zVY2NjYZPJuxGAtedG/Bn
+xd3pHjusxtjPudeDEi/YYCkUy/82hfjzVOQSi6/NyQgAcZ5gYso+tPbkQPPiEvQr
+JIKAnbLu/xnSeQPLxq/irnlSRcQ351d6CEk6ZpFpSUfpNrKUhUduu5d55y9AY5Zc
+kRM=
+-----END CERTIFICATE-----
+
+-----BEGIN CERTIFICATE-----
+MIIEZTCCA02gAwIBAgIQQAF1BIMUpMghjISpDBbN3zANBgkqhkiG9w0BAQsFADA/
+MSQwIgYDVQQKExtEaWdpdGFsIFNpZ25hdHVyZSBUcnVzdCBDby4xFzAVBgNVBAMT
+DkRTVCBSb290IENBIFgzMB4XDTIwMTAwNzE5MjE0MFoXDTIxMDkyOTE5MjE0MFow
+MjELMAkGA1UEBhMCVVMxFjAUBgNVBAoTDUxldCdzIEVuY3J5cHQxCzAJBgNVBAMT
+AlIzMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuwIVKMz2oJTTDxLs
+jVWSw/iC8ZmmekKIp10mqrUrucVMsa+Oa/l1yKPXD0eUFFU1V4yeqKI5GfWCPEKp
+Tm71O8Mu243AsFzzWTjn7c9p8FoLG77AlCQlh/o3cbMT5xys4Zvv2+Q7RVJFlqnB
+U840yFLuta7tj95gcOKlVKu2bQ6XpUA0ayvTvGbrZjR8+muLj1cpmfgwF126cm/7
+gcWt0oZYPRfH5wm78Sv3htzB2nFd1EbjzK0lwYi8YGd1ZrPxGPeiXOZT/zqItkel
+/xMY6pgJdz+dU/nPAeX1pnAXFK9jpP+Zs5Od3FOnBv5IhR2haa4ldbsTzFID9e1R
+oYvbFQIDAQABo4IBaDCCAWQwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8E
+BAMCAYYwSwYIKwYBBQUHAQEEPzA9MDsGCCsGAQUFBzAChi9odHRwOi8vYXBwcy5p
+ZGVudHJ1c3QuY29tL3Jvb3RzL2RzdHJvb3RjYXgzLnA3YzAfBgNVHSMEGDAWgBTE
+p7Gkeyxx+tvhS5B1/8QVYIWJEDBUBgNVHSAETTBLMAgGBmeBDAECATA/BgsrBgEE
+AYLfEwEBATAwMC4GCCsGAQUFBwIBFiJodHRwOi8vY3BzLnJvb3QteDEubGV0c2Vu
+Y3J5cHQub3JnMDwGA1UdHwQ1MDMwMaAvoC2GK2h0dHA6Ly9jcmwuaWRlbnRydXN0
+LmNvbS9EU1RST09UQ0FYM0NSTC5jcmwwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYf
+r52LFMLGMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjANBgkqhkiG9w0B
+AQsFAAOCAQEA2UzgyfWEiDcx27sT4rP8i2tiEmxYt0l+PAK3qB8oYevO4C5z70kH
+ejWEHx2taPDY/laBL21/WKZuNTYQHHPD5b1tXgHXbnL7KqC401dk5VvCadTQsvd8
+S8MXjohyc9z9/G2948kLjmE6Flh9dDYrVYA9x2O+hEPGOaEOa1eePynBgPayvUfL
+qjBstzLhWVQLGAkXXmNs+5ZnPBxzDJOLxhF2JIbeQAcH5H0tZrUlo5ZYyOqA7s9p
+O5b85o3AM/OJ+CktFBQtfvBhcJVd9wvlwPsk+uyOy2HI7mNxKKgsBTt375teA2Tw
+UdHkhVNcsAKX1H7GNNLOEADksd86wuoXvg==
+-----END CERTIFICATE-----

+ 31 - 0
cms/drupal/mustikas/mustikas.maastikuarhitekt.ee/mustikas.maastikuarhitekt.ee.cer

@@ -0,0 +1,31 @@
+-----BEGIN CERTIFICATE-----
+MIIFPjCCBCagAwIBAgISBAwCWqPe3GK8XOWqcq29G5MvMA0GCSqGSIb3DQEBCwUA
+MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD
+EwJSMzAeFw0yMTAxMTkxODExMzlaFw0yMTA0MTkxODExMzlaMCcxJTAjBgNVBAMT
+HG11c3Rpa2FzLm1hYXN0aWt1YXJoaXRla3QuZWUwggEiMA0GCSqGSIb3DQEBAQUA
+A4IBDwAwggEKAoIBAQC/XSg9MLP1hZ4KXFdy7OmaUPXmdIiB4gD5hJ1Y/cQt5RhK
+SDJJDdn4tcA0UAiZShBX+CVk0+PFP3W5TTBQZTDqNuhDwbMqUD6XSnsL7J5pe9O5
+ldzPe04k+ox0ozCtEDe3EYIy+b5dIEOyL5evN//RwlmEKQkL6ldRJtqVyWa8EXN1
+i8OasSqUFqhlF/g24FGWX9N9e5cFSXcGSDKVL8dUk4ttk8MAfhUCNZxPXRIRFdGy
+mJCaCwmKXtvoUqOFOQI7ACgJDXGVpBA5znhmdsKTZUEQS5nARi93UYRZFzu031NW
++giYBFB9541yd2bictvty1hY87paAugYKq8wx+L3AgMBAAGjggJXMIICUzAOBgNV
+HQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMAwGA1Ud
+EwEB/wQCMAAwHQYDVR0OBBYEFAVjzs4yKxq6lPZwsRDY9oEWy6SfMB8GA1UdIwQY
+MBaAFBQusxe3WFbLrlAJQOYfr52LFMLGMFUGCCsGAQUFBwEBBEkwRzAhBggrBgEF
+BQcwAYYVaHR0cDovL3IzLm8ubGVuY3Iub3JnMCIGCCsGAQUFBzAChhZodHRwOi8v
+cjMuaS5sZW5jci5vcmcvMCcGA1UdEQQgMB6CHG11c3Rpa2FzLm1hYXN0aWt1YXJo
+aXRla3QuZWUwTAYDVR0gBEUwQzAIBgZngQwBAgEwNwYLKwYBBAGC3xMBAQEwKDAm
+BggrBgEFBQcCARYaaHR0cDovL2Nwcy5sZXRzZW5jcnlwdC5vcmcwggEEBgorBgEE
+AdZ5AgQCBIH1BIHyAPAAdgBvU3asMfAxGdiZAKRRFf93FRwR2QLBACkGjbIImjfZ
+EwAAAXccD0eYAAAEAwBHMEUCIC18jJ/GGt3LXePTKZHWXyxwIG4V/ODR/7HYyxbF
+LH2CAiEAl+8aWtEo+a6hLGRz0ABRrgCqH/0NTC5CrdR5hN1y1T4AdgD2XJQv0Xcw
+IhRUGAgwlFaO400TGTO/3wwvIAvMTvFk4wAAAXccD0fnAAAEAwBHMEUCIDOjMmKk
+P9o3LCoIueFflOABAZCC/svBKwHyTfXAfMQ2AiEA+ZitIPUOMlRCPMEIh/t+PKNe
+ebhVrAfcB5oribSW4uAwDQYJKoZIhvcNAQELBQADggEBAB+WBv6YCUkC9ehOW96g
+gZva4R1l1l2COLPYkDI1ONAt1kQobxqoUPDFx252G2TF/WKUaEc2DBCB0814+AJo
+4RTe1y2RVtkOldYlh97yLnGOzB/kQA/OLfasF9c91UOiGdOtJ6O+PPCPZ39F4qxO
+c6k0b1eXJrm6EQPKsrk5nV0etAVClxfQqQVWitZX146zVY2NjYZPJuxGAtedG/Bn
+xd3pHjusxtjPudeDEi/YYCkUy/82hfjzVOQSi6/NyQgAcZ5gYso+tPbkQPPiEvQr
+JIKAnbLu/xnSeQPLxq/irnlSRcQ351d6CEk6ZpFpSUfpNrKUhUduu5d55y9AY5Zc
+kRM=
+-----END CERTIFICATE-----

+ 15 - 0
cms/drupal/mustikas/mustikas.maastikuarhitekt.ee/mustikas.maastikuarhitekt.ee.conf

@@ -0,0 +1,15 @@
+Le_Domain='mustikas.maastikuarhitekt.ee'
+Le_Alt='no'
+Le_Webroot='/var/lib/docker/volumes/drupal_mustikas-1-html/_data'
+Le_PreHook=''
+Le_PostHook=''
+Le_RenewHook=''
+Le_API='https://acme-v02.api.letsencrypt.org/directory'
+Le_Keylength=''
+Le_OrderFinalize='https://acme-v02.api.letsencrypt.org/acme/finalize/110071310/7407443351'
+Le_LinkOrder='https://acme-v02.api.letsencrypt.org/acme/order/110071310/7407443351'
+Le_LinkCert='https://acme-v02.api.letsencrypt.org/acme/cert/040c025aa3dedc62bc5ce5aa72adbd1b932f'
+Le_CertCreateTime='1611083500'
+Le_CertCreateTimeStr='Tue Jan 19 19:11:40 UTC 2021'
+Le_NextRenewTimeStr='Sat Mar 20 19:11:40 UTC 2021'
+Le_NextRenewTime='1616181100'

+ 8 - 0
cms/drupal/mustikas/mustikas.maastikuarhitekt.ee/mustikas.maastikuarhitekt.ee.csr.conf

@@ -0,0 +1,8 @@
+[ req_distinguished_name ]
+[ req ]
+distinguished_name = req_distinguished_name
+req_extensions = v3_req
+[ v3_req ]
+
+keyUsage = nonRepudiation, digitalSignature, keyEncipherment
+subjectAltName=DNS:mustikas.maastikuarhitekt.ee

+ 18 - 0
cms/drupal/mustikas/run.sh

@@ -0,0 +1,18 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+docker stack deploy --compose-file=./drupal.yml drupal
+
+exit 0

+ 25 - 0
cms/drupal/mustikas/sertifikaatide_genereerimine.sh

@@ -0,0 +1,25 @@
+#!/bin/bash
+
+# acme.sh abil TLS sertifkaatide genereerimine ja paigutamine õigesse kohta.
+# Selleks peab html konteiner jooksma aadressil http://ldap.odamus.com/.well-known
+##
+## Acme peaks ise genereerima sertifikaadi. Lisa cron'i, et iga kuu kopeeritakse
+## sertifikaadid õigesse kohta ja taaskäivitatakse dockeri service.
+## Sertifikaatide värskendamine
+##  toimub automaatselt iga 60 päeva järele.
+
+
+
+
+## Vaata abiks:   https://github.com/acmesh-official/acme.sh
+mkdir -p /var/lib/docker/volumes/drupal_mustikas-1-html/_data/.well-known/acme-challenge
+cd /root/.acme.sh
+
+  ./acme.sh --issue -d mustikas.maastikuarhitekt.ee -w /var/lib/docker/volumes/drupal_mustikas-1-html/_data --home /var/lib/docker/volumes/traefik_certs/_data/owngenerated
+
+
+##   taaskäivita traefik ja vaata, et see fail on kah õiges kohas.
+cd /opt/containers/server/traefik
+ ./cleanup.sh && ./run.sh
+#   docker service update traefik_traefik
+cd /opt/containers/cms/drupal/mustikas

+ 23 - 0
cms/drupal/see1/LOEMIND.txt

@@ -0,0 +1,23 @@
+
+apt update
+apt -y install curl git unzip vim wget && \
+apt-get clean
+# Drupali tuuma install
+composer install
+# To see which versions of Drupal core are available, use this command
+composer show drupal/recommended-project --all
+#Check for available Drupal core and module updates:
+composer outdated drupal/*
+# All of your modules and themes can be updated along with Drupal core via:
+composer update
+
+
+# Mooduli install
+php -d memory_limit=-1 `which composer` require 'drupal/masquerade' --update-no-dev  --update-with-all-dependencies
+# SMTP
+php -d memory_limit=-1 `which composer` require 'phpmailer/phpmailer' --update-no-dev
+php -d memory_limit=-1 `which composer` require 'drupal/smtp' --update-no-dev --update-with-all-dependencies
+# Theme
+php -d memory_limit=-1 `which composer` require 'drupal/d8w3css' --update-no-dev --update-with-all-dependencies
+#composer remove 'drupal/d8w3css' --update-with-dependencies
+

+ 21 - 0
cms/drupal/see1/cleanup.sh

@@ -0,0 +1,21 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+echo "Cleaning up..."
+
+#docker stack rm drupal
+docker service rm drupal_see1
+
+exit 0

+ 54 - 0
cms/drupal/see1/drupal.yml

@@ -0,0 +1,54 @@
+version: '3.4'
+
+services:
+  see1:
+    # depends_on:       # <-- Eemaldatud (ei tööta Swarm'is)
+    #   - node
+    deploy:
+      replicas: 1
+      mode: replicated
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == hetzner
+    image: drupal:9
+    labels:
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-network
+      - traefik.constraint-label=traefik-network
+      - traefik.http.routers.drupal-see1-http.middlewares=http-to-https
+      - traefik.http.routers.drupal-see1-https.rule=Host(`www.see1.ee`)
+      - traefik.http.routers.drupal-see1-https.entrypoints=websecure
+      - traefik.http.routers.drupal-see1-http.rule=Host(`www.see1.ee`)
+      - traefik.http.routers.drupal-see1-http.entrypoints=web
+      - "traefik.http.routers.drupal-see1-https.tls.certresolver=mychallenge"
+      - traefik.http.services.drupal-see1.loadbalancer.server.port=80
+    volumes:
+      - drupal_modules:/var/www/html/modules
+      - drupal_profile:/var/www/html/profiles
+      - drupal_theme:/var/www/html/themes
+      - drupal_sites:/var/www/html/sites
+      - /etc/localtime:/etc/localtime
+    networks:
+      - db-network
+      - traefik-network
+
+volumes:
+  drupal_modules:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-modules'
+    driver: local
+  drupal_profile:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-profile'
+    driver: local
+  drupal_theme:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-theme'
+    driver: local
+  drupal_sites:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-sites'
+    driver: local
+
+networks:
+  db-network:
+    external: true
+  traefik-network:
+    external: true

+ 27 - 0
cms/drupal/see1/run.sh

@@ -0,0 +1,27 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+docker stack deploy --compose-file=./drupal.yml drupal
+
+sleep 10
+docker exec -it $(docker ps -f name=drupal_see1 -q) bash -c "apt update; \
+apt -y install curl git unzip vim wget; \
+apt-get clean;"
+docker exec -it $(docker ps -f name=drupal_see1 -q) bash -c "composer require drupal/backup_migrate --update-no-dev;"
+
+#docker exec -it $(docker ps -f name=drupal_see1 -q) bash -c "composer require phpmailer/phpmailer --update-no-dev;"
+
+
+exit 0

+ 23 - 0
cms/drupal/terminator/LOEMIND.txt

@@ -0,0 +1,23 @@
+
+apt update
+apt -y install curl git unzip vim wget && \
+apt-get clean
+# Drupali tuuma install
+composer install
+# To see which versions of Drupal core are available, use this command
+composer show drupal/recommended-project --all
+#Check for available Drupal core and module updates:
+composer outdated drupal/*
+# All of your modules and themes can be updated along with Drupal core via:
+composer update
+
+
+# Mooduli install
+php -d memory_limit=-1 `which composer` require 'drupal/masquerade' --update-no-dev  --update-with-all-dependencies
+# SMTP
+php -d memory_limit=-1 `which composer` require 'phpmailer/phpmailer' --update-no-dev
+php -d memory_limit=-1 `which composer` require 'drupal/smtp' --update-no-dev --update-with-all-dependencies
+# Theme
+php -d memory_limit=-1 `which composer` require 'drupal/d8w3css' --update-no-dev --update-with-all-dependencies
+#composer remove 'drupal/d8w3css' --update-with-dependencies
+

+ 21 - 0
cms/drupal/terminator/cleanup.sh

@@ -0,0 +1,21 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+echo "Cleaning up..."
+
+#docker stack rm drupal
+docker service rm drupal_terminator
+
+exit 0

+ 56 - 0
cms/drupal/terminator/drupal.yml

@@ -0,0 +1,56 @@
+version: '3.4'
+
+services:
+  terminator:
+    depends_on:
+      - primary
+    deploy:
+      replicas: 1
+      mode: replicated
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == hetzner
+    image: drupal:8-apache
+#    ports:
+#      - 8006:80
+    labels:
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-network
+      - traefik.constraint-label=traefik-network
+      - traefik.http.routers.drupal-terminator-http.middlewares=http-to-https
+      - traefik.http.routers.drupal-terminator-https.rule=Host(`terminator.odamus.com`)
+      - traefik.http.routers.drupal-terminator-https.entrypoints=websecure
+      - traefik.http.routers.drupal-terminator-http.rule=Host(`terminator.odamus.com`)
+      - traefik.http.routers.drupal-terminator-http.entrypoints=web
+      - "traefik.http.routers.drupal-terminator-https.tls.certresolver=mychallenge"
+      - traefik.http.services.drupal-terminator.loadbalancer.server.port=80
+    volumes:
+      - drupal_modules:/var/www/html/modules
+      - drupal_profile:/var/www/html/profiles
+      - drupal_theme:/var/www/html/themes
+      - drupal_sites:/var/www/html/sites
+      - /etc/localtime:/etc/localtime
+    networks:
+      - db-network
+      - traefik-network
+
+volumes:
+  drupal_modules:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-modules'
+    driver: local
+  drupal_profile:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-profile'
+    driver: local
+  drupal_theme:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-theme'
+    driver: local
+  drupal_sites:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-sites'
+    driver: local
+
+networks:
+  db-network:
+    external: true
+  traefik-network:
+    external: true

+ 23 - 0
cms/drupal/terminator/run.sh

@@ -0,0 +1,23 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+docker stack deploy --compose-file=./drupal.yml drupal
+
+sleep 10
+docker exec -it $(docker ps -f name=drupal_terminator -q) bash -c "composer require phpmailer/phpmailer --update-no-dev; \
+ls"
+
+exit 0
+

+ 17 - 0
cms/drupal/terminator/scripts/composer_install.sh

@@ -0,0 +1,17 @@
+#!/bin/sh
+
+EXPECTED_CHECKSUM="$(wget -q -O - https://composer.github.io/installer.sig)"
+php -r "copy('https://getcomposer.org/installer', 'composer-setup.php');"
+ACTUAL_CHECKSUM="$(php -r "echo hash_file('sha384', 'composer-setup.php');")"
+
+if [ "$EXPECTED_CHECKSUM" != "$ACTUAL_CHECKSUM" ]
+then
+    >&2 echo 'ERROR: Invalid installer checksum'
+    rm composer-setup.php
+    exit 1
+fi
+
+php composer-setup.php --quiet
+RESULT=$?
+rm composer-setup.php
+exit $RESULT

+ 0 - 0
cms/hugo/hartwig/LOEMIND.txt


+ 20 - 0
cms/hugo/hartwig/cleanup.sh

@@ -0,0 +1,20 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+echo "Cleaning up..."
+
+docker stack rm hugo
+
+exit 0

+ 28 - 0
cms/hugo/hartwig/docker-compose.yml

@@ -0,0 +1,28 @@
+services:
+  hartwig:
+    image: monachus/hugo:latest
+    container_name: hugo_hartwig
+    restart: unless-stopped
+    volumes:
+      - hugo_hartwig-1-blog:/usr/share/blog
+    networks:
+      - traefik-network
+    labels:
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-network
+      - traefik.constraint-label=traefik-network
+      - traefik.http.routers.hugo-hartwig-http.middlewares=http-to-https
+      - traefik.http.routers.hugo-hartwig-https.rule=Host(`hartwig.odamus.com`)
+      - traefik.http.routers.hugo-hartwig-https.entrypoints=websecure
+      - traefik.http.routers.hugo-hartwig-http.rule=Host(`hartwig.odamus.com`)
+      - traefik.http.routers.hugo-hartwig-http.entrypoints=web
+      - "traefik.http.routers.hugo-hartwig-https.tls.certresolver=mychallenge"
+      - traefik.http.services.hugo-hartwig.loadbalancer.server.port=1313
+
+volumes:
+  hugo_hartwig-1-blog:
+    external: true
+
+networks:
+  traefik-network:
+    external: true

+ 40 - 0
cms/hugo/hartwig/hugo.yml

@@ -0,0 +1,40 @@
+version: '3.4'
+
+services:
+  hartwig:
+    deploy:
+      replicas: 1
+      mode: replicated
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == hetzner
+    image: monachus/hugo
+    command: hugo server --bind 0.0.0.0 --port 1313
+#    ports:
+#      - 8006:1313
+    labels:
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-network
+      - traefik.constraint-label=traefik-network
+      - traefik.http.routers.hugo-hartwig-http.middlewares=http-to-https
+      - traefik.http.routers.hugo-hartwig-https.rule=Host(`hartwig.odamus.com`)
+      - traefik.http.routers.hugo-hartwig-https.entrypoints=websecure
+      - traefik.http.routers.hugo-hartwig-http.rule=Host(`hartwig.odamus.com`)
+      - traefik.http.routers.hugo-hartwig-http.entrypoints=web
+      - "traefik.http.routers.hugo-hartwig-https.tls.certresolver=mychallenge"
+      - traefik.http.services.hugo-hartwig.loadbalancer.server.port=1313
+    volumes:
+      - hugo_blog:/usr/share/blog
+#      - /etc/localtime:/etc/localtime
+    networks:
+      - traefik-network
+
+volumes:
+  hugo_blog:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-blog'
+    driver: local
+
+networks:
+  traefik-network:
+    external: true

+ 18 - 0
cms/hugo/hartwig/run.sh

@@ -0,0 +1,18 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+docker stack deploy --compose-file=./hugo.yml hugo
+
+exit 0

+ 0 - 0
cms/nginx/www/LOEMIND.txt


+ 21 - 0
cms/nginx/www/cleanup.sh

@@ -0,0 +1,21 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+echo "Cleaning up..."
+
+#docker-compose -p "nginx" -f docker-compose.yml down
+docker service rm nginx_www
+
+exit 0

+ 70 - 0
cms/nginx/www/docker-compose.yml

@@ -0,0 +1,70 @@
+version: '3.4'
+services:
+  www:
+    deploy:
+      replicas: 1
+      mode: replicated
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == hetzner
+    image: nginx
+#    container_name: nginx_www
+#    restart: "no"
+#    environment:
+    volumes:
+      - www-html:/usr/share/nginx/html:ro
+      - www-conf:/etc/nginx/conf.d:ro
+      - www-backups:/srv/backups
+      - /etc/localtime:/etc/localtime
+#    command: [nginx-debug, '-g', 'daemon off;']
+    networks:
+#      - traefik-external
+      - traefik-network
+#    ports:
+#      - "8006:80"
+    labels:
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-network
+      - traefik.constraint-label=traefik-network
+      - traefik.http.routers.nginx-www-http.middlewares=http-to-https
+      - traefik.http.routers.nginx-www-https.rule=Host(`www.odamus.com`)
+      - traefik.http.routers.nginx-www-https.entrypoints=websecure
+      - traefik.http.routers.nginx-www-http.rule=Host(`www.odamus.com`)
+      - traefik.http.routers.nginx-www-http.entrypoints=web
+      - "traefik.http.routers.nginx-www-https.tls.certresolver=mychallenge"
+      - traefik.http.services.nginx-www.loadbalancer.server.port=80
+
+      - traefik.http.routers.nginx-odamus-http.middlewares=http-to-https
+      - traefik.http.routers.nginx-odamus-https.rule=Host(`odamus.com`)
+      - traefik.http.routers.nginx-odamus-https.entrypoints=websecure
+      - traefik.http.routers.nginx-odamus-http.rule=Host(`odamus.com`)
+      - traefik.http.routers.nginx-odamus-http.entrypoints=web
+      - "traefik.http.routers.nginx-odamus-https.tls.certresolver=mychallenge"
+#      - traefik.http.services.nginx-odamus.loadbalancer.server.port=80
+      - "traefik.http.routers.nginx-odamus-http.service=nginx-www"
+      - "traefik.http.routers.nginx-odamus-https.service=nginx-www"
+
+## http redirect to www
+      - traefik.http.routers.nginx-odamus-http.middlewares=web-to-www
+      - "traefik.http.middlewares.web-to-www.redirectregex.regex=^http://(?:www.)?odamus.com/(.*)"
+      - "traefik.http.middlewares.web-to-www.redirectregex.replacement=http://www.odamus.com/$${1}"
+      - traefik.http.routers.nginx-odamus-https.middlewares=websecure-to-www
+      - "traefik.http.middlewares.websecure-to-www.redirectregex.regex=^https://(?:www.)?odamus.com/(.*)"
+      - "traefik.http.middlewares.websecure-to-www.redirectregex.replacement=https://www.odamus.com/$${1}"
+
+
+volumes:
+#  r-packages:
+#    name: r-packages
+#    external: true
+  www-html:
+  www-conf:
+  www-backups:
+networks:
+#  network:
+#  traefik-external:
+#    external:
+#      name: traefik-external
+  traefik-network:
+    external: true 

+ 67 - 0
cms/nginx/www/docker-compose.yml.xxx

@@ -0,0 +1,67 @@
+version: '3.4'
+services:
+  www:
+    deploy:
+      replicas: 1
+      mode: replicated
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == swarm
+    image: nginx
+#    container_name: nginx_www
+#    restart: "no"
+#    environment:
+    volumes:
+      - www-html:/usr/share/nginx/html:ro
+      - www-conf:/etc/nginx/conf.d:ro
+      - www-backups:/srv/backups
+      - /etc/localtime:/etc/localtime
+#    command: [nginx-debug, '-g', 'daemon off;']
+    networks:
+#      - traefik-external
+      - traefik-network
+#    ports:
+#      - "8006:80"
+    labels:
+## odamus.com
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-network
+      - traefik.constraint-label=traefik-network
+## http
+#      - traefik.http.routers.nginx-www-http.rule=Host(`www.odamus.com`) || Host(`odamus.com`)
+#      - traefik.http.routers.nginx-www-http.entrypoints=web
+## http redirect to www
+#      - "traefik.http.routers.nginx-www-http.middlewares=web-to-www-redirect"
+#      - "traefik.http.middlewares.web-to-www-redirect.redirectregex.regex=^http://(?:www.)?odamus.com/(.*)"
+#      - "traefik.http.middlewares.web-to-www-redirect.redirectregex.replacement=http://www.odamus.com/$${1}"
+## http to https
+#      - traefik.http.routers.nginx-www-http.middlewares=http-to-https
+## https
+      - traefik.http.routers.nginx-www-https.rule=Host(`www.odamus.com`) || Host(`odamus.com`)
+      - traefik.http.routers.nginx-www-https.entrypoints=websecure
+      - "traefik.http.routers.nginx-www-https.tls.certresolver=mychallenge"
+## https redirect to www
+      - "traefik.http.routers.nginx-www-https.middlewares=websecure-to-www-redirect"
+      - "traefik.http.middlewares.websecure-to-www-redirect.redirectregex.regex=^https://(?:www.)?odamus.com/(.*)"
+      - "traefik.http.middlewares.websecure-to-www-redirect.redirectregex.replacement=https://www.odamus.com/$${1}"
+## service point
+      - traefik.http.services.nginx-www.loadbalancer.server.port=80
+      - "traefik.http.routers.nginx-www-http.service=nginx-www"
+      - "traefik.http.routers.nginx-www-https.service=nginx-www"
+
+
+volumes:
+#  r-packages:
+#    name: r-packages
+#    external: true
+  www-html:
+  www-conf:
+  www-backups:
+networks:
+#  network:
+#  traefik-external:
+#    external:
+#      name: traefik-external
+  traefik-network:
+    external: true 

+ 19 - 0
cms/nginx/www/run.sh

@@ -0,0 +1,19 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+#docker-compose -p "nginx" -f docker-compose.yml up -d
+docker stack deploy --compose-file=./docker-compose.yml nginx
+
+exit 0

+ 14 - 0
cms/wordpress/nuudi/LOEMIND.txt

@@ -0,0 +1,14 @@
+docker service ps wordpress_nuudi
+
+# Lisa .htacess faili read:
+# ardo
+php_value upload_max_filesize 128M
+php_value post_max_size 128M
+php_value max_execution_time 300
+php_value max_input_time 300
+
+
+
+
+## !!! Selleks, et https ühendus tööle hakkaks tuleb:
+## - administreerimise menüüst "shop parameters" -> "general" -> "enable ssl" ja "enable ssl on all pages"

+ 21 - 0
cms/wordpress/nuudi/cleanup.sh

@@ -0,0 +1,21 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+echo "Cleaning up..."
+
+#docker stack rm wordpress
+docker service rm wordpress_nuudi
+
+exit 0

+ 44 - 0
cms/wordpress/nuudi/docker-compose.yml

@@ -0,0 +1,44 @@
+services:
+  nuudi:
+    image: wordpress:latest
+    container_name: wordpress_nuudi
+    restart: unless-stopped
+    environment:
+      - WORDPRESS_DB_HOST=mariadb_simple:3306
+      - WORDPRESS_DB_USER=wp_nuudi
+      - WORDPRESS_DB_PASSWORD=OiS9lpzCynHKusjak97s6DgenDU
+      - WORDPRESS_DB_NAME=wp_nuudi
+      - TZ=Europe/Tallinn
+    volumes:
+      - wordpress_nuudi-1-data:/var/www/html
+      - wordpress_nuudi-1-backups:/srv/backups
+      - /etc/localtime:/etc/localtime
+    networks:
+      - traefik-network
+      - db-migration
+    labels:
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-network
+      - traefik.constraint-label=traefik-network
+      - traefik.http.routers.wp-nuudi-http.middlewares=http-to-https
+      - traefik.http.routers.wp-nuudi-http.rule=Host(`www.nuuditalu.ee`) || Host(`nuuditalu.ee`)
+      - traefik.http.routers.wp-nuudi-http.entrypoints=web
+      - traefik.http.routers.wp-nuudi-https.rule=Host(`www.nuuditalu.ee`) || Host(`nuuditalu.ee`)
+      - traefik.http.routers.wp-nuudi-https.entrypoints=websecure
+      - traefik.http.routers.wp-nuudi-https.middlewares=https-to-www-redirect
+      - "traefik.http.routers.wp-nuudi-https.tls.certresolver=mychallenge"
+      - "traefik.http.middlewares.https-to-www-redirect.redirectregex.regex=^https://(?:www.)?nuuditalu.ee/(.*)"
+      - "traefik.http.middlewares.https-to-www-redirect.redirectregex.replacement=https://www.nuuditalu.ee/$${1}"
+      - traefik.http.services.wp-nuudi.loadbalancer.server.port=80
+
+volumes:
+  wordpress_nuudi-1-data:
+    external: true
+  wordpress_nuudi-1-backups:
+    external: true
+
+networks:
+  traefik-network:
+    external: true
+  db-migration:
+    external: true

+ 18 - 0
cms/wordpress/nuudi/run.sh

@@ -0,0 +1,18 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+docker stack deploy --compose-file=./wordpress.yml wordpress
+
+exit 0

+ 73 - 0
cms/wordpress/nuudi/wordpress.yml

@@ -0,0 +1,73 @@
+version: '3.4'
+
+services:
+  nuudi:
+#    depends_on:
+#      - node
+    deploy:
+      replicas: 1
+      mode: replicated
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == hetzner
+    image: wordpress
+#    ports:
+#      - 8090:80
+    labels:
+      - traefik.enable=true
+      - traefik.docker.network=traefik-network
+      - traefik.constraint-label=traefik-network
+      - traefik.http.routers.wp-nuudi-http.middlewares=http-to-https
+      - traefik.http.routers.wp-nuudi-https.rule=Host(`www.nuuditalu.ee`) || Host(`nuuditalu.ee`)
+      - traefik.http.routers.wp-nuudi-https.entrypoints=websecure
+      - traefik.http.routers.wp-nuudi-http.rule=Host(`www.nuuditalu.ee`) || Host(`nuuditalu.ee`)
+      - traefik.http.routers.wp-nuudi-http.entrypoints=web
+      - traefik.http.routers.wp-nuudi-https.tls.certresolver=mychallenge
+      - traefik.http.services.wp-nuudi.loadbalancer.server.port=80
+## https redirect to www
+      - "traefik.http.routers.wp-nuudi-https.middlewares=https-to-www-redirect"
+      - "traefik.http.middlewares.https-to-www-redirect.redirectregex.regex=^https://(?:www.)?nuuditalu.ee/(.*)"
+      - "traefik.http.middlewares.https-to-www-redirect.redirectregex.replacement=https://www.nuuditalu.ee/$${1}"
+## service point
+#      - "traefik.http.routers.nginx-www-http.service=nginx-www"
+#      - "traefik.http.routers.nginx-www-https.service=nginx-www"
+
+
+    volumes:
+      - wordpress:/var/www/html
+      - /etc/localtime:/etc/localtime
+#      - "/etc/timezone:/etc/timezone:ro"
+#      - "/etc/localtime:/etc/localtime:ro"
+      - backups:/srv/backups
+    networks:
+      - db-network
+      - traefik-network
+    environment:
+      - WORDPRESS_DB_HOST=node:3306
+      - WORDPRESS_DB_USER=wp_nuudi
+      - WORDPRESS_DB_PASSWORD=OiS9lpzCynHKusjak97s6DgenDU
+      - WORDPRESS_DB_NAME=wp_nuudi
+  #    NODE_ADDRESS: ^10.0.*.*
+      - TZ="Europe/Tallinn"
+
+volumes:
+  wordpress:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-data'
+    driver: local
+  backups:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-backups'
+    driver: local
+
+
+networks:
+  db-network:
+    external: true
+  traefik-network:
+    external: true
+
+
+## ------------------- mysql käsud --------------------------
+## 1. logi nod konteinerisse sisse
+# SHOW GRANTS FOR 'user'@'%';
+# GRANT ALL PRIVILEGES ON * . * TO 'user'@'%';

+ 3 - 0
db/adminer/LOEMIND.txt

@@ -0,0 +1,3 @@
+# service loomine yaml abil
+docker stack deploy --compose-file=adminer.yml adminer
+

+ 34 - 0
db/adminer/adminer.yml

@@ -0,0 +1,34 @@
+version: '3.4'
+services:
+
+  adminer:
+    image: adminer
+#    ports:
+#      - 8005:8080
+    networks:
+      - traefik-network
+      - db-network
+    volumes:
+      - /etc/localtime:/etc/localtime
+    deploy:
+      placement:
+        constraints:
+          - node.hostname == hetzner
+    labels:
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-network
+      - traefik.constraint-label=traefik-network
+      - traefik.http.routers.adminer-http.middlewares=http-to-https
+      - traefik.http.routers.adminer-https.rule=Host(`adminer.odamus.com`)
+      - traefik.http.routers.adminer-https.entrypoints=websecure
+      - traefik.http.routers.adminer-http.rule=Host(`adminer.odamus.com`)
+      - traefik.http.routers.adminer-http.entrypoints=web
+      - "traefik.http.routers.adminer-https.tls.certresolver=mychallenge"
+      - traefik.http.services.adminer.loadbalancer.server.port=8080
+#      - traefik.http.services.galera.loadbalancer.server.port=8080
+
+networks:
+  traefik-network:
+    external: true
+  db-network:
+    external: true

+ 20 - 0
db/adminer/cleanup.sh

@@ -0,0 +1,20 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+echo "Cleaning up..."
+
+docker stack rm adminer
+
+exit 0

+ 27 - 0
db/adminer/docker-compose.yml

@@ -0,0 +1,27 @@
+services:
+  adminer:
+    image: adminer:4.8.1-standalone
+    container_name: adminer_adminer
+    restart: unless-stopped
+    environment:
+      - ADMINER_DEFAULT_SERVER=mariadb_simple
+    networks:
+      - traefik-network
+      - db-migration
+    labels:
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-network
+      - traefik.constraint-label=traefik-network
+      - traefik.http.routers.adminer-http.middlewares=http-to-https
+      - traefik.http.routers.adminer-https.rule=Host(`adminer.odamus.com`)
+      - traefik.http.routers.adminer-https.entrypoints=websecure
+      - traefik.http.routers.adminer-http.rule=Host(`adminer.odamus.com`)
+      - traefik.http.routers.adminer-http.entrypoints=web
+      - "traefik.http.routers.adminer-https.tls.certresolver=mychallenge"
+      - traefik.http.services.adminer.loadbalancer.server.port=8080
+
+networks:
+  traefik-network:
+    external: true
+  db-migration:
+    external: true

+ 4 - 0
db/adminer/run.sh

@@ -0,0 +1,4 @@
+#!/bin/bash
+
+# Deploy docker service.
+docker stack deploy --compose-file=adminer.yml adminer

+ 16 - 0
db/mariadb/KUIDAS_ALUSTADA.txt

@@ -0,0 +1,16 @@
+#!/bin/bash
+## ------------ mine SEED konteinerisse sisse -------------
+# Esmalt paki lahti *.sql.gz kujul olev fail
+gzip -d swarm_db_backup_mysql-2020-10-28T10.10.sql.gz
+# Impordi backup mysql andmebaasi
+mysql < swarm_db_backup_mysql-2020-10-28T10.10.sql
+
+## ----------- swarmis käivita ---------------
+# Seejärel lisa node konteinerid
+docker service scale mariadb_node=2
+# Seejärel eemalda seed konteiner
+docker service scale mariadb_seed=0
+# Seejärel lisa node konteinerid
+docker service scale mariadb_node=3
+# ----------- KÕIK ------------
+

+ 53 - 0
db/mariadb/LOEMIND.txt

@@ -0,0 +1,53 @@
+# https://github.com/colinmollenhour/mariadb-galera-swarm/tree/master/examples/swarm
+# Loome kataloogi salsõnade jaoks
+mkdir -p .secrets
+# Salasõnade genereerimine
+openssl rand -base64 32 > .secrets/xtrabackup_password
+openssl rand -base64 32 > .secrets/mysql_password
+openssl rand -base64 32 > .secrets/mysql_root_password
+
+# Create services
+docker stack deploy -c mariadb.yml mariadb
+
+docker service ls
+# (wait for `mariadb_seed` to be healthy)
+docker service scale mariadb_node=2
+# (wait for both `mariadb_node` instances to be healthy)
+docker service scale mariadb_seed=0
+docker service scale mariadb_node=3
+
+# ---------------------- mysql käsud ---------------------------
+# Kõikide õiguste omandamine kasutajale 'user'
+docker exec -it $(docker ps -f name=mariadb_node.1 -q) mysql -e"GRANT ALL PRIVILEGES ON * . * TO 'user'@'%';"
+# Kasutaja user õiguste vaatamine
+docker exec -it $(docker ps -f name=mariadb_node.1 -q) mysql -e"SHOW GRANTS FOR 'user'@'%';"
+
+# ------------ Töö andmebaasis ---------------
+# väljast logimine
+docker exec -it $(docker ps -f name=mariadb_node.1 -q) mysql
+# Igaks juhuks aname kasutajale user kõikidele tabelitele juurdepääsu,
+# et konteiner dbclient saaks backup'i teha
+GRANT ALL PRIVILEGES ON *.* TO 'user'@'%';
+FLUSH PRIVILEGES;
+
+# konteineri sees logimine
+mysql -h localhost
+# andmebaasi laadimine
+mysql ab_nimi < /srv/backups/EMAL-2020-10-26T14-31-22.mysql
+# seejärel lisa kasutaja ja õigused. Näiteks:
+CREATE USER 'dr_mustikas'@'%'  IDENTIFIED BY 'ucKlFMQYkC5eXyf' ;
+GRANT SELECT, INSERT, UPDATE, DELETE, CREATE, DROP, INDEX,
+ALTER, CREATE TEMPORARY TABLES, LOCK TABLES, delete history
+ON dr_mustikas.*
+TO 'dr_mustikas'@'%';
+
+# 
+# Vaata konfi faile
+docker exec $(docker ps -q -f name=mariadb_node) ls /etc/mysql/
+docker exec $(docker ps -q -f name=mariadb_node) ls /etc/mysql/conf.d/
+docker exec $(docker ps -q -f name=mariadb_node) cat /etc/mysql/conf.d/docker.cnf
+
+docker exec $(docker ps -q -f name=mariadb_seed) ls /etc/mysql/
+## ----------------- Vaja teha ---------------------
+# Kataloog /etc/mysql/ tuua eraldi volume sisse
+

+ 20 - 0
db/mariadb/cleanup.sh

@@ -0,0 +1,20 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+echo "Cleaning up..."
+
+docker stack rm mariadb
+
+exit 0

+ 106 - 0
db/mariadb/first_time_run.sh

@@ -0,0 +1,106 @@
+#!/bin/bash
+# Deploy docker service.
+docker stack deploy -c mariadb.yml mariadb
+
+# Read functions
+source /opt/linux/scripts/functions/docker/check_container_healthy.sh
+source /opt/linux/scripts/functions/docker/array_count_unique.sh
+
+# Load mariadb-seed service
+echo "--------- mariadb_seed health check -----------"
+unset health_status; counter=1; condition1=0; condition2=0
+while [[ $condition1 != 1 ]] ||  [[ $condition2 != healthy  ]]
+do
+   echo "$counter. sek"
+   counter=$(( $counter + 1 ))
+   sleep 1
+  # mariadb_seed health.status kontroll
+  res=$(check_container_healthy mariadb_seed)
+  IFS=' ' read -r -a health_status <<< "$res"; # declare -p health_status;
+
+  # 1. condition1
+  condition1=$(array_count_unique ${health_status[@]})
+  echo "Erinevate elementide arv SEED vektoris: $condition1"
+  # 2. condition2
+  condition2=${health_status[0]}
+  echo "Health Status SEED vektoris: ${condition2[0]}"
+done
+sleep 2
+
+# Load mariadb_node service
+echo "--------- mariadb_node health check -----------"
+unset health_status; counter=1; condition1=0; condition2=0
+while [[ $condition1 != 1 ]] ||  [[ $condition2 != healthy  ]]
+do
+   echo "$counter. sek"
+   counter=$(( $counter + 1 ))
+   sleep 1
+  # mariadb_node health.status kontroll
+  res=$(check_container_healthy mariadb_node)
+  IFS=' ' read -r -a health_status <<< "$res"; # declare -p health_status;
+
+  # 1. condition1
+  condition1=$(array_count_unique ${health_status[@]})
+  echo "Erinevate elementide arv NODE vektoris: $condition1"
+  # 2. condition2
+  condition2=${health_status[0]}
+  echo "Health Status NODE vektoris: ${condition2[0]}"
+done
+
+# Increace mariadb_node replices to 2
+echo "--------- mariadb_node scale to 2 -----------"
+docker service scale $(docker service ls -f name=mariadb_node -q)=2
+
+# Check mariadb_node status to decreace mariadb_seed replices to 0
+echo "--------- mariadb_node health check -----------"
+unset health_status; counter=1; condition1=0; condition2=0
+while [[ $condition1 != 1 ]] ||  [[ $condition2 != healthy  ]]
+do
+   echo "$counter. sek"
+   counter=$(( $counter + 1 ))
+   sleep 1
+  # mariadb_node health.status kontroll
+  res=$(check_container_healthy mariadb_node)
+  IFS=' ' read -r -a health_status <<< "$res"; # declare -p health_status;
+
+  # 1. condition1
+  condition1=$(array_count_unique ${health_status[@]})
+  echo "Erinevate elementide arv NODE vektoris: $condition1"
+  # 2. condition2
+  condition2=${health_status[0]}
+  echo "Health Status NODE vektoris: ${condition2[0]}"
+done
+sleep 2
+
+# Decreace mariadb_seed replices to 0.
+echo "--------- mariadb_seed scale to 0 -----------"
+docker service scale $(docker service ls -f name=mariadb_seed -q)=0
+
+
+# Check mariadb_seed status to icreace mariadb_node replices to 3
+echo "--------- mariadb_seed health check -----------"
+unset health_status; counter=1; condition1=0; condition2=0
+while [[ $condition1 != 3 ]] ||  [[ $condition2 != no  ]]
+do
+   echo "$counter. sek"
+   counter=$(( $counter + 1 ))
+   sleep 1
+  # mariadb_seed health.status kontroll
+  res=$(check_container_healthy mariadb_seed)
+  IFS=' ' read -r -a health_status <<< "$res"; # declare -p health_status;
+
+  # 1. condition1
+  condition1=$(array_count_unique ${health_status[@]})
+  echo "Erinevate elementide arv SEED vektoris: $condition1"
+  # 2. condition2
+  condition2=${health_status[0]}
+  echo "Health Status SEED vektoris: ${condition2[0]}"
+done
+sleep 2
+
+# Increace mariadb_node replices to 3
+echo "--------- mariadb_node scale to 3 -----------"
+docker service scale $(docker service ls -f name=mariadb_node -q)=3
+
+# End 
+echo "------------------- End --------------------"

+ 135 - 0
db/mariadb/mariadb.yml

@@ -0,0 +1,135 @@
+version: '3.4'
+
+services:
+  seed:
+    image: colinmollenhour/mariadb-galera-swarm:10.4.11-2020-01-06
+    environment:
+      - XTRABACKUP_PASSWORD_FILE=/run/secrets/xtrabackup_password
+      - MYSQL_USER=user
+      - MYSQL_PASSWORD_FILE=/run/secrets/mysql_password
+      - MYSQL_DATABASE=drupal
+      - MYSQL_ROOT_PASSWORD_FILE=/run/secrets/mysql_root_password
+      - NODE_ADDRESS=^10.0.*.*
+    networks:
+      - db-network
+    command: seed
+    volumes:
+      - mysql-data:/var/lib/mysql
+      - mariadb_backups:/srv/backups
+      - mariadb_conf:/etc/mysql
+      - /etc/localtime:/etc/localtime
+    secrets:
+      - xtrabackup_password
+      - mysql_password
+      - mysql_root_password
+    deploy:
+      mode: replicated
+      replicas: 1
+      resources:
+        limits:
+          cpus: '1'
+          memory: 1024M
+        reservations:
+          cpus: '1'
+          memory: 1024M
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == hetzner  # <-- Vale oli siin
+
+  node:
+    image: colinmollenhour/mariadb-galera-swarm:10.4.11-2020-01-06
+    ports:
+      - target: 3306
+        published: 3306
+        protocol: tcp
+        mode: ingress
+    environment:
+      - XTRABACKUP_PASSWORD_FILE=/run/secrets/xtrabackup_password
+      - NODE_ADDRESS=^10.0.*.*
+      - HEALTHY_WHILE_BOOTING=1
+    networks:
+      - db-network
+    command: node tasks.seed,tasks.node
+    volumes:
+      - mysql-data:/var/lib/mysql
+      - mariadb_backups:/srv/backups
+      - mariadb_conf:/etc/mysql
+      - /etc/localtime:/etc/localtime
+    secrets:
+      - xtrabackup_password
+    deploy:
+      mode: replicated
+      replicas: 1
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == hetzner  # <-- Parandi see "swarm" -> "hetzner"
+
+  dbclient:
+    image: alpine
+    # depends_on:        # <-- Eemalda
+    #   - node
+    environment:
+      - BACKUP_ENABLED=1
+      - BACKUP_INTERVAL=86400
+      - BACKUP_PATH=/srv/backups
+      - BACKUP_FILENAME=swarm_db_backup_mysql
+      - MYSQL_USER=user
+      - MYSQL_PASSWORD_FILE=/run/secrets/mysql_password
+    secrets:
+      - mysql_password
+    networks:
+      - db-network
+    entrypoint: |
+      sh -c 'sh -s << EOF
+      apk add --no-cache mysql-client
+      while true
+      do
+        if [ $$BACKUP_ENABLED == 1 ]
+        then
+          sleep 1800
+          echo "Starting backup"
+          mkdir -p $$BACKUP_PATH/$$(date +%F)
+          echo "$$(date +%FT%H.%m) - Making Backup to : $$BACKUP_PATH/$$(date +%F)/$$BACKUP_FILENAME-$$(date +%FT%H.%m).sql.gz"
+          mariadb-dump --skip-ssl -u $$MYSQL_USER -p`cat $$MYSQL_PASSWORD_FILE` -h node --all-databases | gzip > $$BACKUP_PATH/$$(date +%F)/$$BACKUP_FILENAME-$$(date +%FT%H.%m).sql.gz
+          find $$BACKUP_PATH -mtime 7 -delete
+          echo "Next backup will be at "
+          echo $$(date -d@"$$(( `date +%s`+$$BACKUP_INTERVAL))" +%F" "%H:%m)
+          sleep $$BACKUP_INTERVAL
+        fi
+      done
+      EOF'
+    volumes:
+      - mariadb_backups:/srv/backups
+      - /etc/localtime:/etc/localtime
+    deploy:
+      mode: replicated
+      replicas: 1
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == hetzner  # <-- Parandi see "swarm" -> "hetzner"
+
+volumes:
+  mysql-data:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-data'
+    driver: local
+  mariadb_backups:
+    name: mariadb_backups
+    external: true
+  mariadb_conf:
+    name: mariadb_conf
+    external: true
+
+networks:
+  db-network:
+    external: true
+
+secrets:
+  xtrabackup_password:
+    file: .secrets/xtrabackup_password
+  mysql_password:
+    file: .secrets/mysql_password
+  mysql_root_password:
+    file: .secrets/mysql_root_password

+ 5 - 0
db/mariadb/run.sh

@@ -0,0 +1,5 @@
+#!/bin/bash
+# Deploy docker service.
+docker stack deploy -c mariadb.yml mariadb
+
+exit 0;

+ 54 - 0
db/mariadb_simple/docker-compose.yml

@@ -0,0 +1,54 @@
+services:
+  mariadb:
+    image: mariadb:10.4
+    container_name: mariadb_simple
+    restart: unless-stopped
+    ports:
+      - "0.0.0.0:3306:3306"
+    environment:
+      - MYSQL_ROOT_PASSWORD_FILE=/run/secrets/mysql_root_password
+    volumes:
+      - mariadb_simple_data:/var/lib/mysql
+      - /etc/localtime:/etc/localtime
+      - /var/backups/mysql:/backups
+    secrets:
+      - mysql_root_password
+    networks:
+      - default
+      - db-migration
+    command: >
+      --character-set-server=utf8mb4
+      --collation-server=utf8mb4_unicode_ci
+      --max-connections=200
+      --innodb-buffer-pool-size=256M
+      --max-allowed-packet=16M
+      --sql-mode=STRICT_TRANS_TABLES,ERROR_FOR_DIVISION_BY_ZERO,NO_AUTO_CREATE_USER,NO_ENGINE_SUBSTITUTION
+      --slow-query-log=1
+      --long-query-time=5
+      --skip-name-resolve
+      --innodb-rollback-on-timeout=ON
+      --lock-wait-timeout=60
+    healthcheck:
+      test: ["CMD", "healthcheck.sh", "--connect", "--innodb_initialized"]
+      interval: 10s
+      timeout: 5s
+      retries: 5
+    logging:
+      driver: "json-file"
+      options:
+        max-size: "10m"
+        max-file: "3"
+
+volumes:
+  mariadb_simple_data:
+    name: mariadb_simple_data
+
+secrets:
+  mysql_root_password:
+    file: .secrets/mysql_root_password
+
+networks:
+  default:
+    name: mariadb_simple_default
+  db-migration:
+    external: true

+ 62 - 0
db/mariadb_simple/init.sql

@@ -0,0 +1,62 @@
+CREATE DATABASE IF NOT EXISTS dr_mustikas
+  CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
+CREATE DATABASE IF NOT EXISTS dr_see1
+  CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
+CREATE DATABASE IF NOT EXISTS dr_merbond
+  CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
+CREATE DATABASE IF NOT EXISTS ojs_acta
+  CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
+CREATE DATABASE IF NOT EXISTS wp_nuudi
+  CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
+CREATE DATABASE IF NOT EXISTS dr_kaie
+  CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
+CREATE DATABASE IF NOT EXISTS dr_bussikeskus
+  CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
+CREATE DATABASE IF NOT EXISTS dr_test9
+  CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
+
+CREATE USER IF NOT EXISTS 'user'@'%'
+  IDENTIFIED BY PASSWORD '*4286C2189656155D2C4DFE0216D0186BCCB25824';
+GRANT ALL PRIVILEGES ON *.* TO 'user'@'%' WITH GRANT OPTION;
+
+CREATE USER IF NOT EXISTS 'dr_mustikas'@'%'
+  IDENTIFIED BY PASSWORD '*BAB0FFDC26C46E0006D98D6AE9C6F3F06E8348DD';
+GRANT SELECT, INSERT, UPDATE, DELETE, CREATE, DROP, INDEX, ALTER,
+  CREATE TEMPORARY TABLES, LOCK TABLES ON dr_mustikas.* TO 'dr_mustikas'@'%';
+
+CREATE USER IF NOT EXISTS 'dr_merbond'@'%'
+  IDENTIFIED BY PASSWORD '*408ED883AD85EEBED26085B86DBF18D416A3D98F';
+GRANT SELECT, INSERT, UPDATE, DELETE, CREATE, DROP, INDEX, ALTER,
+  CREATE TEMPORARY TABLES, LOCK TABLES ON dr_merbond.* TO 'dr_merbond'@'%';
+
+CREATE USER IF NOT EXISTS 'dr_see1'@'%'
+  IDENTIFIED BY PASSWORD '*519679367F136081079A40CCE600BDE099D86612';
+GRANT SELECT, INSERT, UPDATE, DELETE, CREATE, DROP, INDEX, ALTER,
+  CREATE TEMPORARY TABLES, LOCK TABLES ON dr_see1.* TO 'dr_see1'@'%';
+
+CREATE USER IF NOT EXISTS 'dr_kaie'@'%'
+  IDENTIFIED BY PASSWORD '*0B637EDD1560AB519DE6D3AD181BAAAB662F9890';
+GRANT SELECT, INSERT, UPDATE, DELETE, CREATE, DROP, INDEX, ALTER,
+  CREATE TEMPORARY TABLES, LOCK TABLES ON dr_kaie.* TO 'dr_kaie'@'%';
+
+CREATE USER IF NOT EXISTS 'dr_bussikeskus'@'%'
+  IDENTIFIED BY PASSWORD '*0B637EDD1560AB519DE6D3AD181BAAAB662F9890';
+GRANT SELECT, INSERT, UPDATE, DELETE, CREATE, DROP, INDEX, ALTER,
+  CREATE TEMPORARY TABLES, LOCK TABLES ON dr_bussikeskus.* TO 'dr_bussikeskus'@'%';
+
+CREATE USER IF NOT EXISTS 'dr_test9'@'%'
+  IDENTIFIED BY PASSWORD '*61EC257D9C5D3E23C9362856C530ADD843A0BACE';
+GRANT SELECT, INSERT, UPDATE, DELETE, CREATE, DROP, INDEX, ALTER,
+  CREATE TEMPORARY TABLES, LOCK TABLES ON dr_test9.* TO 'dr_test9'@'%';
+
+CREATE USER IF NOT EXISTS 'wp_nuudi'@'%'
+  IDENTIFIED BY PASSWORD '*8D72AD81EF30B6091B3D8EE1603D1EE02F4A2C85';
+GRANT SELECT, INSERT, UPDATE, DELETE, CREATE, DROP, INDEX, ALTER,
+  CREATE TEMPORARY TABLES, LOCK TABLES ON wp_nuudi.* TO 'wp_nuudi'@'%';
+
+CREATE USER IF NOT EXISTS 'ojs_acta'@'%'
+  IDENTIFIED BY PASSWORD '*7934F7DD176B90395C27530BB4D427A633F94936';
+GRANT SELECT, INSERT, UPDATE, DELETE, CREATE, DROP, REFERENCES, INDEX, ALTER,
+  CREATE VIEW, SHOW VIEW, TRIGGER ON ojs_acta.* TO 'ojs_acta'@'%' WITH GRANT OPTION;
+
+FLUSH PRIVILEGES;

+ 24 - 0
db/postgis/LOEMIND.txt

@@ -0,0 +1,24 @@
+# Päringud konteinerist
+# Postgis'i õiguste ja konfi faili asukoht
+docker exec  $(docker ps -q -f name=postgis_primary) psql -U postgres -c "SELECT * FROM pg_hba_file_rules;"
+docker exec  $(docker ps -q -f name=postgis_primary) psql -U postgres -c "SHOW hba_file;"
+
+
+
+## --------------------------------------------------------------
+# https://info.crunchydata.com/blog/easy-postgresql-cluster-recipe-using-docker-1.12
+# https://github.com/CrunchyData/crunchy-containers/blob/master/examples/docker/swarm-service/docker-compose.yml
+docker service ps master
+docker service ps replica
+# Given the PostgreSQL replica service is named replica, you can scale up the number of replica containers by running this command:
+docker service scale replica=2
+docker service ls
+
+
+
+mkdir -p .secrets
+openssl rand -base64 32 > .secrets/postgis_primary_user_password
+openssl rand -base64 32 > .secrets/postgis_user_password
+openssl rand -base64 32 > .secrets/postgis_root_password
+docker stack deploy -c postgis.yml postgis
+docker service ls

+ 20 - 0
db/postgis/cleanup.sh

@@ -0,0 +1,20 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+echo "Cleaning up..."
+
+docker stack rm postgis
+
+exit 0

+ 201 - 0
db/postgis/postgis.yml

@@ -0,0 +1,201 @@
+# https://hub.docker.com/r/crunchydata/crunchy-postgres-gis/tags
+services:
+  primary:
+    hostname: 'primary'
+    ports:
+      - target: 5432
+        published: 5432
+        protocol: tcp
+        mode: ingress
+    image: crunchydata/crunchy-postgres-gis:centos7-12.4-3.0-4.4.1
+    environment:
+      - PGHOST=/tmp
+      - MAX_CONNECTIONS=30
+      - MAX_WAL_SENDERS=5
+      - PG_MODE=primary
+      - PG_PRIMARY_USER=primaryuser
+      - PG_PRIMARY_PASSWORD=C9DNCIqtQ8x8f0aROyWnC9DNCIqtQ8x8f0aROyWn
+      - PG_DATABASE=testdb
+      - PG_USER=testuser
+      - PG_PASSWORD=xPQ6Quhtk2hQefcIJobAr1Nm9icXjf
+      - PG_ROOT_PASSWORD=R36aVTUKgOWgawMRvSVqZ4LfYWswZc
+      - PG_PRIMARY_PORT=5432
+    volumes:
+      - pg-primary-vol:/pgdata
+      - pg-primary-vol-pgconf:/pgconf
+      - pg-primary-vol-pgwal:/pgwal
+      - pg-primary-vol-recover:/recover
+      - pg-primary-vol-sshd:/sshd
+      - pg-primary-vol-backrestrepo:/backrestrepo
+      - backups:/srv/backups
+#    ports:
+#    - "5432"
+    networks:
+      - db-network
+      - db-external
+    deploy:
+      replicas: 1
+      mode: replicated
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == hetzner
+
+  replica:
+    hostname: 'replica'
+    image: crunchydata/crunchy-postgres-gis:centos7-12.4-3.0-4.4.1
+    environment:
+      - PGHOST=/tmp
+      - MAX_CONNECTIONS=30
+      - MAX_WAL_SENDERS=5
+      - PG_MODE=replica
+      - PG_PRIMARY_HOST=primary
+      - PG_PRIMARY_PORT=5432
+      - PG_PRIMARY_USER=primaryuser
+      - PG_PRIMARY_PASSWORD=C9DNCIqtQ8x8f0aROyWnC9DNCIqtQ8x8f0aROyWn
+      - PG_DATABASE=testdb
+      - PG_USER=testuser
+      - PG_PASSWORD=xPQ6Quhtk2hQefcIJobAr1Nm9icXjf
+      - PG_ROOT_PASSWORD=R36aVTUKgOWgawMRvSVqZ4LfYWswZc
+    volumes:
+      - pg-replica-vol:/pgdata
+      - pg-replica-vol-pgconf:/pgconf
+      - pg-replica-vol-pgwal:/pgwal
+      - pg-replica-vol-recover:/recover
+      - pg-replica-vol-sshd:/sshd
+      - pg-replica-vol-backrestrepo:/backrestrepo
+      - backups:/srv/backups
+    networks:
+      - db-network
+      - db-external
+    deploy:
+      replicas: 1
+      mode: replicated
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == hetzner
+
+  dbclient:
+    image: alpine
+    environment:
+      - BACKUP_ENABLED=1
+      - BACKUP_INTERVAL=86400
+      - BACKUP_PATH=/srv/backups
+      - BACKUP_FILENAME=swarm_db_backup_postgis
+      - PG_PRIMARY_USER=primaryuser
+      - PG_PRIMARY_PASSWORD=C9DNCIqtQ8x8f0aROyWnC9DNCIqtQ8x8f0aROyWn
+      - PG_USER=testuser
+      - PG_PASSWORD=xPQ6Quhtk2hQefcIJobAr1Nm9icXjf
+      - PG_ROOT_PASSWORD=R36aVTUKgOWgawMRvSVqZ4LfYWswZc
+    networks:
+      - db-network
+    entrypoint:
+      - /bin/sh
+      - -c
+      - |
+        apk add --no-cache postgresql-client
+
+        # Ootame, et andmebaas oleks valmis
+        echo "Waiting for database..."
+        until PGPASSWORD=$${PG_ROOT_PASSWORD} pg_isready -h primary -U postgres; do
+          echo "Database unavailable - sleeping"
+          sleep 5
+        done
+        echo "Database is ready!"
+
+        while true; do
+          if [ $${BACKUP_ENABLED} -eq 1 ]; then
+            echo "Starting backup at $$(date)"
+            mkdir -p $${BACKUP_PATH}/$$(date +%F)
+
+            TIMESTAMP=$$(date +%FT%H-%M)
+            BACKUP_FILE="$${BACKUP_PATH}/$$(date +%F)/$${BACKUP_FILENAME}-$${TIMESTAMP}.sql.gz"
+
+            echo "Making backup to: $${BACKUP_FILE}"
+
+            export PGPASSWORD=$${PG_ROOT_PASSWORD}
+            pg_dumpall -U postgres -h primary --exclude-database=osm_estonia --exclude-database=transport --exclude-database=postgres | gzip > $${BACKUP_FILE}
+
+            if [ $$? -eq 0 ]; then
+              echo "Backup completed successfully"
+              ls -lh $${BACKUP_FILE}
+            else
+              echo "ERROR: Backup failed!"
+            fi
+
+            # Kustuta vanad varundused (vanemad kui 7 päeva)
+            echo "Cleaning up old backups..."
+            find $${BACKUP_PATH} -type f -name "*.sql.gz" -mtime +7 -delete
+
+            # Arvuta järgmise varukoopia aeg
+            NEXT_TIME=$$(( $$(date +%s) + $${BACKUP_INTERVAL} ))
+            NEXT_BACKUP=$$(date -d @$${NEXT_TIME} '+%F %H:%M' 2>/dev/null || date -r $${NEXT_TIME} '+%F %H:%M')
+            echo "Next backup scheduled at: $${NEXT_BACKUP}"
+
+            sleep $${BACKUP_INTERVAL}
+          else
+            echo "Backup is disabled"
+            sleep 3600
+          fi
+        done
+    volumes:
+      - backups:/srv/backups
+      - /etc/localtime:/etc/localtime
+    deploy:
+      mode: replicated
+      replicas: 1
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == hetzner
+
+
+networks:
+#  crunchynet:
+  db-network:
+    external: true
+  db-external:
+    external: true
+
+
+volumes:
+#  dbclient:
+  backups:
+  pg-primary-vol:
+#    name: '{{.Service.Name}}-{{.Task.Slot}}-pgdata'
+    driver: local
+  pg-primary-vol-pgconf:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-pgconf'
+    driver: local
+  pg-primary-vol-pgwal:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-pgwal'
+    driver: local
+  pg-primary-vol-recover:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-recover'
+    driver: local
+  pg-primary-vol-sshd:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-sshd'
+    driver: local
+  pg-primary-vol-backrestrepo:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-backrestrepo'
+    driver: local
+
+  pg-replica-vol:
+#    name: '{{.Service.Name}}-{{.Task.Slot}}-pgdata'
+    driver: local
+  pg-replica-vol-pgconf:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-pgconf'
+    driver: local
+  pg-replica-vol-pgwal:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-pgwal'
+    driver: local
+  pg-replica-vol-recover:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-recover'
+    driver: local
+  pg-replica-vol-sshd:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-sshd'
+    driver: local
+  pg-replica-vol-backrestrepo:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-backrestrepo'
+    driver: local

+ 209 - 0
db/postgis/postgis.yml.xxx

@@ -0,0 +1,209 @@
+# https://hub.docker.com/r/crunchydata/crunchy-postgres-gis/tags
+---
+version: "3.4"
+
+services:
+  primary:
+    hostname: 'primary'
+    ports:
+      - target: 5432
+        published: 5432
+        protocol: tcp
+#        mode: host
+        mode: ingress
+    image: crunchydata/crunchy-postgres-gis:centos7-12.4-3.0-4.4.1
+    environment:
+      - PGHOST=/tmp
+      - MAX_CONNECTIONS=30
+      - MAX_WAL_SENDERS=5
+      - PG_MODE=primary
+      - PG_PRIMARY_USER=primaryuser
+      - PG_PRIMARY_PASSWORD=C9DNCIqtQ8x8f0aROyWnC9DNCIqtQ8x8f0aROyWn
+      - PG_DATABASE=testdb
+      - PG_USER=testuser
+      - PG_PASSWORD=xPQ6Quhtk2hQefcIJobAr1Nm9icXjf
+      - PG_ROOT_PASSWORD=R36aVTUKgOWgawMRvSVqZ4LfYWswZc
+      - PG_PRIMARY_PORT=5432
+    volumes:
+      - pg-primary-vol:/pgdata
+      - pg-primary-vol-pgconf:/pgconf
+      - pg-primary-vol-pgwal:/pgwal
+      - pg-primary-vol-recover:/recover
+      - pg-primary-vol-sshd:/sshd
+      - pg-primary-vol-backrestrepo:/backrestrepo
+      - backups:/srv/backups
+#    ports:
+#    - "5432"
+    networks:
+#    - crunchynet
+#    - galera_galera_network
+      - db-network
+      - db-external
+    deploy:
+      replicas: 1
+      mode: replicated
+      placement:
+        constraints:
+#        - node.labels.type == primary
+          - node.role == manager
+          - node.hostname == hetzner
+  replica:
+    image: crunchydata/crunchy-postgres-gis:centos7-12.4-3.0-4.4.1
+    environment:
+      - PGHOST=/tmp
+      - MAX_CONNECTIONS=30
+      - MAX_WAL_SENDERS=5
+      - PG_MODE=replica
+      - PG_PRIMARY_HOST=primary
+      - PG_PRIMARY_PORT=5432
+      - PG_PRIMARY_USER=primaryuser
+      - PG_PRIMARY_PASSWORD=C9DNCIqtQ8x8f0aROyWnC9DNCIqtQ8x8f0aROyWn
+      - PG_DATABASE=testdb
+      - PG_USER=testuser
+      - PG_PASSWORD=xPQ6Quhtk2hQefcIJobAr1Nm9icXjf
+      - PG_ROOT_PASSWORD=R36aVTUKgOWgawMRvSVqZ4LfYWswZc
+    volumes:
+      - pg-replica-vol:/pgdata
+      - pg-replica-vol-pgconf:/pgconf
+      - pg-replica-vol-pgwal:/pgwal
+      - pg-replica-vol-recover:/recover
+      - pg-replica-vol-sshd:/sshd
+      - pg-replica-vol-backrestrepo:/backrestrepo
+      - backups:/srv/backups
+#    ports:
+#    - "5432"
+    networks:
+      - db-network
+      - db-external
+    deploy:
+      replicas: 1
+      mode: replicated
+      placement:
+        constraints:
+#        - node.labels.type != primary
+          - node.role == manager
+          - node.hostname == hetzner
+
+  dbclient:
+    image: alpine
+    environment:
+      - BACKUP_ENABLED=1
+      - BACKUP_INTERVAL=86400
+      - BACKUP_PATH=/srv/backups
+      - BACKUP_FILENAME=swarm_db_backup_postgis
+      - PG_PRIMARY_USER=primaryuser
+      - PG_PRIMARY_PASSWORD=C9DNCIqtQ8x8f0aROyWnC9DNCIqtQ8x8f0aROyWn
+      - PG_USER=testuser
+      - PG_PASSWORD=xPQ6Quhtk2hQefcIJobAr1Nm9icXjf
+      - PG_ROOT_PASSWORD=R36aVTUKgOWgawMRvSVqZ4LfYWswZc
+    networks:
+      - db-network
+    entrypoint:
+      - /bin/sh
+      - -c
+      - |
+        apk add --no-cache postgresql-client
+
+        # Ootame, et andmebaas oleks valmis
+        echo "Waiting for database..."
+        until PGPASSWORD=$${PG_ROOT_PASSWORD} pg_isready -h primary -U postgres; do
+          echo "Database unavailable - sleeping"
+          sleep 5
+        done
+        echo "Database is ready!"
+
+        while true; do
+          if [ $${BACKUP_ENABLED} -eq 1 ]; then
+            echo "Starting backup at $$(date)"
+            mkdir -p $${BACKUP_PATH}/$$(date +%F)
+
+            TIMESTAMP=$$(date +%FT%H-%M)
+            BACKUP_FILE="$${BACKUP_PATH}/$$(date +%F)/$${BACKUP_FILENAME}-$${TIMESTAMP}.sql.gz"
+
+            echo "Making backup to: $${BACKUP_FILE}"
+
+            export PGPASSWORD=$${PG_ROOT_PASSWORD}
+            pg_dumpall -U postgres -h primary --exclude-database=osm_estonia --exclude-database=transport --exclude-database=postgres | gzip > $${BACKUP_FILE}
+
+            if [ $$? -eq 0 ]; then
+              echo "Backup completed successfully"
+              ls -lh $${BACKUP_FILE}
+            else
+              echo "ERROR: Backup failed!"
+            fi
+
+            # Kustuta vanad varundused (vanemad kui 7 päeva)
+            echo "Cleaning up old backups..."
+            find $${BACKUP_PATH} -type f -name "*.sql.gz" -mtime +7 -delete
+
+            # Arvuta järgmise varukoopia aeg
+            NEXT_TIME=$$(( $$(date +%s) + $${BACKUP_INTERVAL} ))
+            NEXT_BACKUP=$$(date -d @$${NEXT_TIME} '+%F %H:%M' 2>/dev/null || date -r $${NEXT_TIME} '+%F %H:%M')
+            echo "Next backup scheduled at: $${NEXT_BACKUP}"
+
+            sleep $${BACKUP_INTERVAL}
+          else
+            echo "Backup is disabled"
+            sleep 3600
+          fi
+        done
+    volumes:
+      - backups:/srv/backups
+      - /etc/localtime:/etc/localtime
+    deploy:
+      mode: replicated
+      replicas: 1
+      placement:
+        constraints:
+          - node.role == manager
+          - node.hostname == hetzner
+
+
+networks:
+#  crunchynet:
+  db-network:
+    external: true
+  db-external:
+    external: true
+
+
+volumes:
+#  dbclient:
+  backups:
+  pg-primary-vol:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-pgdata'
+    driver: local
+  pg-primary-vol-pgconf:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-pgconf'
+    driver: local
+  pg-primary-vol-pgwal:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-pgwal'
+    driver: local
+  pg-primary-vol-recover:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-recover'
+    driver: local
+  pg-primary-vol-sshd:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-sshd'
+    driver: local
+  pg-primary-vol-backrestrepo:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-backrestrepo'
+    driver: local
+
+  pg-replica-vol:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-pgdata'
+    driver: local
+  pg-replica-vol-pgconf:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-pgconf'
+    driver: local
+  pg-replica-vol-pgwal:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-pgwal'
+    driver: local
+  pg-replica-vol-recover:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-recover'
+    driver: local
+  pg-replica-vol-sshd:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-sshd'
+    driver: local
+  pg-replica-vol-backrestrepo:
+    name: '{{.Service.Name}}-{{.Task.Slot}}-backrestrepo'
+    driver: local

+ 18 - 0
db/postgis/run.sh

@@ -0,0 +1,18 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+docker stack deploy --compose-file=./postgis.yml postgis
+
+exit 0

+ 42 - 0
db/postgres_simple/docker-compose.yml

@@ -0,0 +1,42 @@
+services:
+  postgres:
+    image: postgis/postgis:16-3.4
+    container_name: postgres_simple
+    restart: unless-stopped
+    ports:
+      - "0.0.0.0:5432:5432"
+    environment:
+      - POSTGRES_PASSWORD_FILE=/run/secrets/postgres_root_password
+    volumes:
+      - postgres_simple_data:/var/lib/postgresql/data
+      - /etc/localtime:/etc/localtime
+      - /var/backups/postgres:/backups
+    secrets:
+      - postgres_root_password
+    networks:
+      - default
+      - db-migration
+    healthcheck:
+      test: ["CMD", "pg_isready", "-U", "postgres"]
+      interval: 10s
+      timeout: 5s
+      retries: 5
+    logging:
+      driver: "json-file"
+      options:
+        max-size: "10m"
+        max-file: "3"
+
+volumes:
+  postgres_simple_data:
+    name: postgres_simple_data
+
+secrets:
+  postgres_root_password:
+    file: .secrets/postgres_root_password
+
+networks:
+  default:
+    name: postgres_simple_default
+  db-migration:
+    external: true

+ 1 - 0
db/redis/LOEMIND.txt

@@ -0,0 +1 @@
+# https://hub.docker.com/r/morrisjobke/webdav/

+ 22 - 0
db/redis/cleanup.sh

@@ -0,0 +1,22 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+echo "Cleaning up..."
+
+docker stack rm redis
+#docker stop webdav &&  docker rm -fv webdav
+
+
+exit 0

+ 27 - 0
db/redis/docker-compose.yml

@@ -0,0 +1,27 @@
+services:
+  redis:
+    image: redis:alpine
+    container_name: redis_redis
+    restart: unless-stopped
+    command: redis-server --appendonly yes
+    hostname: redis
+    volumes:
+      - redis_db:/data
+      - redis_backup:/srv/backups
+      - /etc/localtime:/etc/localtime
+    networks:
+      - traefik-network
+      - traefik-external
+
+volumes:
+  redis_db:
+    external: true
+  redis_backup:
+    external: true
+
+networks:
+  traefik-network:
+    external: true
+  traefik-external:
+    external: true
+    name: traefik-external

+ 10 - 0
db/redis/run.sh

@@ -0,0 +1,10 @@
+#!/bin/bash
+
+# Deploy docker service.
+docker stack deploy --compose-file=docker-compose.yml redis
+
+# docker-compose up -d
+#docker-compose -p "webdav" -f docker-compose.yml up -d
+
+exit 0
+

+ 5 - 0
db/run.sh

@@ -0,0 +1,5 @@
+#!/bin/bash
+
+# Create network for databases.
+docker network create -d overlay db-network
+docker network create -d overlay --attachable db-external

+ 13 - 0
linux_scripts.sh

@@ -0,0 +1,13 @@
+#!/bina/bash
+
+# kataloogi suurused sorteeritult
+du -hs * | sort -h
+
+# kustuta postgis'i replica failid, mis on vanemad kui 15 p.
+# enne vaata, kui palju ruumi failid võtavad
+du -hs /var/lib/docker/volumes/* | sort -h
+find /var/lib/docker/volumes/postgis_replica-1-pgdata/_data/* -mtime +15 -exec rm -rf {} \;
+
+
+# To check the memory utilization, among other things, we can use the command:
+docker stats  $(docker ps -f name=gitlab_gitlab -q) 

+ 55 - 0
other/nominatim/LOEMIND.txt

@@ -0,0 +1,55 @@
+
+# nominatim image'i loomine
+git clone https://github.com/mediagis/nominatim-docker.git
+cd nominatim-docker/3.5/
+docker build -t nominatim .
+
+# Eesti andmebaas
+mkdir -p /opt/containers/other/nominatim/data
+cd /opt/containers/other/nominatim/data
+# wget http://download.geofabrik.de/europe/estonia-latest.osm.pbf -O data/estonia-latest.osm.pbf
+# andmebaasi initsialiseerimine
+docker run -t -v /opt/containers/other/nominatim/data:/data nominatim  sh /app/init.sh /data/estonia-latest.osm.pbf postgresdata 2
+
+
+# Andmete kopeerimine docker volume'i asukohta.
+rm -rf /var/lib/docker/volumes/nominatim_postgresdata/_data/*
+cp -R /opt/containers/other/nominatim/data/postgresdata/* /var/lib/docker/volumes/nominatim_postgresdata/_data/
+chown systemd-resolve:systemd-network -R /var/lib/docker/volumes/nominatim_postgresdata/_data/*
+
+cp /srv/backups/pg_hba.conf /etc/postgresql/12/main/pg_hba.conf
+cp /srv/backups/postgresql.conf /etc/postgresql/12/main/postgresql.conf
+
+	
+docker run --restart=always -p 6432:5432 -p 7070:8080 -d --name nominatim \
+  -v nominatim_postgresdata:/var/lib/postgresql/12/main nominatim bash /app/start.sh
+
+# Postgres andmebaasi logimine
+docker exec -ti nominatim sudo -u postgres psql
+# Database list
+\l
+# User list
+\password nominatim
+ALTER USER nominatim WITH PASSWORD 'CJ13ua8WZtquJhTLlcBvxmCEzW4Hq0';
+
+# Lubame postgres kasutajale juurdeoääsu andmebaasidele
+cp /etc/postgresql/12/main/pg_hba.conf /var/lib/postgresql/12/main/pg_hba.conf.etc
+cp /var/lib/postgresql/12/main/pg_hba.conf /etc/postgresql/12/main/
+cp /data/local.php /app/src/build/settings/
+# restart
+
+# ---------- database update -----------
+docker exec -it nominatim sudo -u postgres ./src/build/utils/update.php --help
+# The following command will keep your database constantly up to date:
+docker exec -it nominatim  cp /data/local.php ./src/build/settings/local.php
+docker exec -it nominatim sudo -u postgres ./src/build/utils/update.php --import-osmosis-all
+
+
+# !!!!!!!!!!!!!!!!!
+# Ära tee porte lahti. Krüptokaevandajad võtavad muidu kontrolli üle.
+# run.sh skripti sai sisse kirjutatud read, et ilma salasõnata ei saa host'i kaudu sisse
+# Vist peaks olema lahendatud krüptokaevandajate probleem.
+
+# Kontrolli konfiguratsiooni pg_hba.conf 
+docker exec nominatim cat /var/lib/postgresql/12/main/pg_hba.conf | tail -n 20
+

+ 21 - 0
other/nominatim/cleanup.sh

@@ -0,0 +1,21 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+echo "Cleaning up..."
+
+docker compose -p "nominatim" -f docker-compose.yml down
+
+
+exit 0

+ 24 - 0
other/nominatim/conf/LOEMIND.txt

@@ -0,0 +1,24 @@
+# 1. Peata konteiner
+docker stop nominatim
+
+# 2. Kopeeri config välja
+docker cp nominatim:/etc/postgresql/12/main/pg_hba.conf ./pg_hba.conf.backup
+
+# 3. Loo uus turvalisem fail (üleval näidatud)
+nano pg_hba.conf
+
+# 4. Kopeeri tagasi
+docker start nominatim
+sleep 5
+docker cp ./pg_hba.conf nominatim:/etc/postgresql/12/main/pg_hba.conf
+docker exec nominatim bash -c "chown postgres:postgres /etc/postgresql/12/main/pg_hba.conf;"
+
+# 5. Reload
+docker exec nominatim su - postgres -c "psql -c 'SELECT pg_reload_conf();'"
+
+# 6. Kontrolli
+#docker exec nominatim psql -U postgres -c "SELECT * FROM pg_hba_file_rules;"
+docker exec nominatim su - postgres -c "psql -c 'SELECT * FROM pg_hba_file_rules;'"
+
+# Kontrolli kas kasutatakse õiget conf faili
+docker exec nominatim su - postgres -c "psql -c 'SHOW hba_file;'"

+ 105 - 0
other/nominatim/conf/pg_hba.conf

@@ -0,0 +1,105 @@
+# PostgreSQL Client Authentication Configuration File
+# ===================================================
+#
+# Refer to the "Client Authentication" section in the PostgreSQL
+# documentation for a complete description of this file.  A short
+# synopsis follows.
+#
+# This file controls: which hosts are allowed to connect, how clients
+# are authenticated, which PostgreSQL user names they can use, which
+# databases they can access.  Records take one of these forms:
+#
+# local         DATABASE  USER  METHOD  [OPTIONS]
+# host          DATABASE  USER  ADDRESS  METHOD  [OPTIONS]
+# hostssl       DATABASE  USER  ADDRESS  METHOD  [OPTIONS]
+# hostnossl     DATABASE  USER  ADDRESS  METHOD  [OPTIONS]
+# hostgssenc    DATABASE  USER  ADDRESS  METHOD  [OPTIONS]
+# hostnogssenc  DATABASE  USER  ADDRESS  METHOD  [OPTIONS]
+#
+# (The uppercase items must be replaced by actual values.)
+#
+# The first field is the connection type: "local" is a Unix-domain
+# socket, "host" is either a plain or SSL-encrypted TCP/IP socket,
+# "hostssl" is an SSL-encrypted TCP/IP socket, and "hostnossl" is a
+# non-SSL TCP/IP socket.  Similarly, "hostgssenc" uses a
+# GSSAPI-encrypted TCP/IP socket, while "hostnogssenc" uses a
+# non-GSSAPI socket.
+#
+# DATABASE can be "all", "sameuser", "samerole", "replication", a
+# database name, or a comma-separated list thereof. The "all"
+# keyword does not match "replication". Access to replication
+# must be enabled in a separate record (see example below).
+#
+# USER can be "all", a user name, a group name prefixed with "+", or a
+# comma-separated list thereof.  In both the DATABASE and USER fields
+# you can also write a file name prefixed with "@" to include names
+# from a separate file.
+#
+# ADDRESS specifies the set of hosts the record matches.  It can be a
+# host name, or it is made up of an IP address and a CIDR mask that is
+# an integer (between 0 and 32 (IPv4) or 128 (IPv6) inclusive) that
+# specifies the number of significant bits in the mask.  A host name
+# that starts with a dot (.) matches a suffix of the actual host name.
+# Alternatively, you can write an IP address and netmask in separate
+# columns to specify the set of hosts.  Instead of a CIDR-address, you
+# can write "samehost" to match any of the server's own IP addresses,
+# or "samenet" to match any address in any subnet that the server is
+# directly connected to.
+#
+# METHOD can be "trust", "reject", "md5", "password", "scram-sha-256",
+# "gss", "sspi", "ident", "peer", "pam", "ldap", "radius" or "cert".
+# Note that "password" sends passwords in clear text; "md5" or
+# "scram-sha-256" are preferred since they send encrypted passwords.
+#
+# OPTIONS are a set of options for the authentication in the format
+# NAME=VALUE.  The available options depend on the different
+# authentication methods -- refer to the "Client Authentication"
+# section in the documentation for a list of which options are
+# available for which authentication methods.
+#
+# Database and user names containing spaces, commas, quotes and other
+# special characters must be quoted.  Quoting one of the keywords
+# "all", "sameuser", "samerole" or "replication" makes the name lose
+# its special character, and just match a database or username with
+# that name.
+#
+# This file is read on server startup and when the server receives a
+# SIGHUP signal.  If you edit the file on a running system, you have to
+# SIGHUP the server for the changes to take effect, run "pg_ctl reload",
+# or execute "SELECT pg_reload_conf()".
+#
+# Put your actual configuration here
+# ----------------------------------
+#
+# If you want to allow non-local connections, you need to add more
+# "host" records.  In that case you will also need to make PostgreSQL
+# listen on a non-local interface via the listen_addresses
+# configuration parameter, or via the -i or -h command line switches.
+
+
+
+
+# DO NOT DISABLE!
+# If you change this first entry you will need to make sure that the
+# database superuser can access the database using some other method.
+# Noninteractive access to all databases is required during automatic
+# maintenance (custom daily cronjobs, replication, and similar tasks).
+#
+# Database administrative login by Unix domain socket
+local   all             postgres                                peer
+
+# TYPE  DATABASE        USER            ADDRESS                 METHOD
+
+# "local" is for Unix domain socket connections only
+local   all             all                                     peer
+# IPv4 local connections:
+host    all             all             127.0.0.1/32            md5
+# IPv6 local connections:
+host    all             all             ::1/128                 md5
+# Allow replication connections from localhost, by a user with the
+# replication privilege.
+local   replication     all                                     peer
+host    replication     all             127.0.0.1/32            md5
+host    replication     all             ::1/128                 md5
+#host all  all    100.64.0.0/10  md5
+host all  all    0.0.0.0/0  md5

+ 104 - 0
other/nominatim/conf/pg_hba.conf.backup

@@ -0,0 +1,104 @@
+# PostgreSQL Client Authentication Configuration File
+# ===================================================
+#
+# Refer to the "Client Authentication" section in the PostgreSQL
+# documentation for a complete description of this file.  A short
+# synopsis follows.
+#
+# This file controls: which hosts are allowed to connect, how clients
+# are authenticated, which PostgreSQL user names they can use, which
+# databases they can access.  Records take one of these forms:
+#
+# local         DATABASE  USER  METHOD  [OPTIONS]
+# host          DATABASE  USER  ADDRESS  METHOD  [OPTIONS]
+# hostssl       DATABASE  USER  ADDRESS  METHOD  [OPTIONS]
+# hostnossl     DATABASE  USER  ADDRESS  METHOD  [OPTIONS]
+# hostgssenc    DATABASE  USER  ADDRESS  METHOD  [OPTIONS]
+# hostnogssenc  DATABASE  USER  ADDRESS  METHOD  [OPTIONS]
+#
+# (The uppercase items must be replaced by actual values.)
+#
+# The first field is the connection type: "local" is a Unix-domain
+# socket, "host" is either a plain or SSL-encrypted TCP/IP socket,
+# "hostssl" is an SSL-encrypted TCP/IP socket, and "hostnossl" is a
+# non-SSL TCP/IP socket.  Similarly, "hostgssenc" uses a
+# GSSAPI-encrypted TCP/IP socket, while "hostnogssenc" uses a
+# non-GSSAPI socket.
+#
+# DATABASE can be "all", "sameuser", "samerole", "replication", a
+# database name, or a comma-separated list thereof. The "all"
+# keyword does not match "replication". Access to replication
+# must be enabled in a separate record (see example below).
+#
+# USER can be "all", a user name, a group name prefixed with "+", or a
+# comma-separated list thereof.  In both the DATABASE and USER fields
+# you can also write a file name prefixed with "@" to include names
+# from a separate file.
+#
+# ADDRESS specifies the set of hosts the record matches.  It can be a
+# host name, or it is made up of an IP address and a CIDR mask that is
+# an integer (between 0 and 32 (IPv4) or 128 (IPv6) inclusive) that
+# specifies the number of significant bits in the mask.  A host name
+# that starts with a dot (.) matches a suffix of the actual host name.
+# Alternatively, you can write an IP address and netmask in separate
+# columns to specify the set of hosts.  Instead of a CIDR-address, you
+# can write "samehost" to match any of the server's own IP addresses,
+# or "samenet" to match any address in any subnet that the server is
+# directly connected to.
+#
+# METHOD can be "trust", "reject", "md5", "password", "scram-sha-256",
+# "gss", "sspi", "ident", "peer", "pam", "ldap", "radius" or "cert".
+# Note that "password" sends passwords in clear text; "md5" or
+# "scram-sha-256" are preferred since they send encrypted passwords.
+#
+# OPTIONS are a set of options for the authentication in the format
+# NAME=VALUE.  The available options depend on the different
+# authentication methods -- refer to the "Client Authentication"
+# section in the documentation for a list of which options are
+# available for which authentication methods.
+#
+# Database and user names containing spaces, commas, quotes and other
+# special characters must be quoted.  Quoting one of the keywords
+# "all", "sameuser", "samerole" or "replication" makes the name lose
+# its special character, and just match a database or username with
+# that name.
+#
+# This file is read on server startup and when the server receives a
+# SIGHUP signal.  If you edit the file on a running system, you have to
+# SIGHUP the server for the changes to take effect, run "pg_ctl reload",
+# or execute "SELECT pg_reload_conf()".
+#
+# Put your actual configuration here
+# ----------------------------------
+#
+# If you want to allow non-local connections, you need to add more
+# "host" records.  In that case you will also need to make PostgreSQL
+# listen on a non-local interface via the listen_addresses
+# configuration parameter, or via the -i or -h command line switches.
+
+
+
+
+# DO NOT DISABLE!
+# If you change this first entry you will need to make sure that the
+# database superuser can access the database using some other method.
+# Noninteractive access to all databases is required during automatic
+# maintenance (custom daily cronjobs, replication, and similar tasks).
+#
+# Database administrative login by Unix domain socket
+local   all             postgres                                peer
+
+# TYPE  DATABASE        USER            ADDRESS                 METHOD
+
+# "local" is for Unix domain socket connections only
+local   all             all                                     peer
+# IPv4 local connections:
+host    all             all             127.0.0.1/32            md5
+# IPv6 local connections:
+host    all             all             ::1/128                 md5
+# Allow replication connections from localhost, by a user with the
+# replication privilege.
+local   replication     all                                     peer
+host    replication     all             127.0.0.1/32            md5
+host    replication     all             ::1/128                 md5
+host all  all    0.0.0.0/0  trust

+ 53 - 0
other/nominatim/docker-compose.yml

@@ -0,0 +1,53 @@
+services:
+# ========= geokodeerimine ja -dekodeerimine ===========
+  nominatim:
+#    image: mediagis/nominatim:4.4
+    image: nominatim
+    hostname: 'nominatim'
+    command: bash /app/start.sh
+    container_name: nominatim
+    restart: always
+#    user: "999:999"  # Add this line
+#    stop_signal: SIGINT                 # Fast Shutdown mode
+#    environment:
+    volumes:
+      - postgresdata:/var/lib/postgresql/12/main
+      - conf:/data
+      - backups:/srv/backups
+      - /etc/localtime:/etc/localtime
+    networks:
+      - traefik-external
+      - db-external
+    ports:
+#      - "7070:8080"
+      - "6432:5432"
+#      - "127.0.0.1:6432:5432"  # Ainult localhost juurdepääs
+#      - "0.0.0.0:6432:5432"  # Kuulab KÕIGIL liidestel
+    labels:
+      - "traefik.enable=true"
+      - traefik.docker.network=traefik-external
+      - traefik.constraint-label=traefik-external
+      # ee.odamus.com
+      - traefik.http.routers.nominatim-ee-http.middlewares=http-to-https
+      - traefik.http.routers.nominatim-ee-https.rule=Host(`ee.odamus.com`)
+      - traefik.http.routers.nominatim-ee-https.entrypoints=websecure
+      - traefik.http.routers.nominatim-ee-http.rule=Host(`ee.odamus.com`)
+      - traefik.http.routers.nominatim-ee-http.entrypoints=web
+      - "traefik.http.routers.nominatim-ee-https.tls.certresolver=mychallenge"
+      - traefik.http.services.nominatim-ee.loadbalancer.server.port=8080
+
+
+volumes:
+#  r-packages:
+#    name: r-packages
+#    external: true
+  postgresdata:
+  conf:
+  backups:
+networks:
+  network:
+  traefik-external:
+    external: true
+  db-external:
+    external: true
+

+ 57 - 0
other/nominatim/run.sh

@@ -0,0 +1,57 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+docker compose -p "nominatim" -f docker-compose.yml up -d
+
+docker exec -u root nominatim bash -c "
+  echo 'ssl = off' >> /etc/postgresql/12/main/postgresql.conf && \
+  chown -R postgres:postgres /etc/postgresql/12/main/ && \
+
+  # PostgreSQL andmed
+  chown -R postgres:postgres /var/lib/postgresql/12/main && \
+  chmod 700 /var/lib/postgresql/12/main && \
+
+  # PostgreSQL konfiguratsioon
+  chown -R postgres:postgres /etc/postgresql/12/main && \
+
+  # Logikataloog
+  mkdir -p /var/log/postgresql && \
+  chown -R postgres:postgres /var/log/postgresql && \
+
+  # SSL võti
+  chgrp ssl-cert /etc/ssl/private/ssl-cert-snakeoil.key && \
+  chmod 640 /etc/ssl/private/ssl-cert-snakeoil.key && \
+
+  # Run
+  mkdir -p /var/run/postgresql/12-main.pg_stat_tmp && \
+  chown -R postgres:postgres /var/run/postgresql && \
+  chmod -R 775 /var/run/postgresql
+"
+
+# Kopeeri tagasi
+docker cp conf/pg_hba.conf nominatim:/etc/postgresql/12/main/pg_hba.conf
+docker exec nominatim bash -c "chown postgres:postgres /etc/postgresql/12/main/pg_hba.conf;"
+docker restart nominatim
+sleep 5
+# 5. Reload
+docker exec nominatim su - postgres -c "psql -c 'SELECT pg_reload_conf();'"
+# 6. Kontrolli
+docker exec nominatim su - postgres -c "psql -c 'SELECT * FROM pg_hba_file_rules;'"
+# Kontrolli kas kasutatakse õiget conf faili
+docker exec nominatim su - postgres -c "psql -c 'SHOW hba_file;'"
+
+#docker restart nominatim
+
+exit 0

+ 8 - 0
other/ojs/LOEMIND.txt

@@ -0,0 +1,8 @@
+## OJS (Open Journal Systems) - PKP - Container/Docker
+# https://github.com/lucasdiedrich/ojs
+
+# --------- Upgrading OJS ---------------
+docker exec -it ojs /usr/local/bin/ojs-upgrade
+
+# acess log
+docker exec -ti $(docker  ps -f name=ojs_acta.1 -q) tail -f /var/log/apache2/access.log

+ 22 - 0
other/ojs/cleanup.sh

@@ -0,0 +1,22 @@
+#!/bin/bash
+
+# Copyright 2016 - 2020 Crunchy Data Solutions, Inc.
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+echo "Cleaning up..."
+
+docker stack rm ojs
+#docker stop ojs &&  docker rm -fv ojs
+
+
+exit 0

+ 31 - 0
other/ojs/config/htaccess

@@ -0,0 +1,31 @@
+RewriteEngine on
+RewriteCond %{SCRIPT_FILENAME} !-d
+RewriteCond %{SCRIPT_FILENAME} !-f
+RewriteCond $1 !^(index\.php)
+RewriteRule ^(.*)$ index.php/$1 [L]
+
+
+#RewriteCond %{HTTPS} off
+#RewriteCond %{HTTP_HOST} ^maastikuarhitektuur\.ee$ [NC]
+#RewriteRule ^ https://www.maastikuarhitektuur.ee%{REQUEST_URI} [R=302,L]
+
+
+# Redirect www to non-www
+#RewriteEngine on
+#RewriteBase /
+#RewriteCond %{HTTP_HOST} ^www\.(.*)$ [NC]
+#RewriteRule ^(.*)$ http://%1/$1 [R=301,L]
+
+# Redirect non-www to www
+#RewriteEngine On
+#RewriteBase /
+#RewriteCond %{HTTP_HOST} !^www\. [NC]
+#RewriteRule ^(.*)$ http://www.%{HTTP_HOST}/$1 [R=301,L]
+
+#RewriteCond %{HTTPS} off
+#RewriteCond %{HTTP_HOST} !^www\.(.*)$ [NC]
+#RewriteRule ^(.*)$ http://www.%{HTTP_HOST}/$1 [R=301,L]
+
+#RewriteCond %{HTTPS} on
+#RewriteCond %{HTTP_HOST} !^www\.(.*)$ [NC]
+#RewriteRule ^(.*)$ https://www.%{HTTP_HOST}/$1 [R=301,L]

+ 34 - 0
other/ojs/config/ojs.conf

@@ -0,0 +1,34 @@
+LoadModule slotmem_shm_module modules/mod_slotmem_shm.so
+LoadModule rewrite_module modules/mod_rewrite.so
+LoadModule expires_module modules/mod_expires.so
+
+
+PassEnv HTTPS
+
+ServerName www.maastikuarhitektuur.ee
+DocumentRoot /var/www/html
+	
+RewriteEngine on
+<Directory /var/www/html>
+	Options FollowSymLinks
+	AllowOverride all
+	Allow from all
+
+	# This removes index.php from the url
+	RewriteCond %{REQUEST_FILENAME} !-d 
+	RewriteCond %{REQUEST_FILENAME} !-f 
+	RewriteRule ^(.*)$ index.php/$1 [QSA,L]
+</Directory>
+
+
+# ardo: acme.sh jaoks sertifikaadi uuendamiseks
+   Alias /.well-known "/var/www/html/public/.well-known"
+    <Directory "/var/www/html/public/.well-known/acme-challenge">
+    Order allow,deny
+    Allow from all
+    Require all granted
+    </Directory>
+
+
+ErrorLog  /var/log/apache2/error.log  
+CustomLog  /var/log/apache2/access.log combined

+ 530 - 0
other/ojs/config/ojs.config.inc

@@ -0,0 +1,530 @@
+; <?php exit(); // DO NOT DELETE ?>
+; DO NOT DELETE THE ABOVE LINE!!!
+; Doing so will expose this configuration file through your web site!
+;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+
+;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+;
+; config.TEMPLATE.inc.php
+;
+; Copyright (c) 2014-2019 Simon Fraser University
+; Copyright (c) 2003-2019 John Willinsky
+; Distributed under the GNU GPL v2. For full terms see the file docs/COPYING.
+;
+; OJS Configuration settings.
+; Rename config.TEMPLATE.inc.php to config.inc.php to use.
+;
+;
+;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+
+
+;;;;;;;;;;;;;;;;;;;;
+; General Settings ;
+;;;;;;;;;;;;;;;;;;;;
+
+[general]
+; Set this to On once the system has been installed
+; (This is generally done automatically by the installer)
+installed = On
+
+; The canonical URL to the OJS installation (excluding the trailing slash)
+base_url = "https://www.maastikuarhitektuur.ee"
+;base_url = "https://acta.odamus.com"
+
+; Session cookie name
+session_cookie_name = OJSSID
+
+; Session cookie path; if not specified, defaults to the detected base path
+; session_cookie_path = /
+
+; Number of days to save login cookie for if user selects to remember
+; (set to 0 to force expiration at end of current session)
+session_lifetime = 30
+
+; Enable support for running scheduled tasks
+; Set this to On if you have set up the scheduled tasks script to
+; execute periodically
+scheduled_tasks = Off
+
+; Site time zone
+; Please refer to lib/pkp/registry/timeZones.xml for a full list of supported
+; time zones.
+; I.e.:
+; <entry key="Europe/Amsterdam" name="Amsterdam" />
+; time_zone="Amsterdam"
+time_zone = "UTC"
+
+; Short and long date formats
+date_format_trunc = "%m-%d"
+date_format_short = "%Y-%m-%d"
+date_format_long = "%B %e, %Y"
+datetime_format_short = "%Y-%m-%d %I:%M %p"
+datetime_format_long = "%B %e, %Y - %I:%M %p"
+time_format = "%I:%M %p"
+
+; Use URL parameters instead of CGI PATH_INFO. This is useful for
+; broken server setups that don't support the PATH_INFO environment
+; variable.
+disable_path_info = Off
+
+; Use fopen(...) for URL-based reads. Modern versions of dspace
+; will not accept requests using fopen, as it does not provide a
+; User Agent, so this option is disabled by default. If this feature
+; is disabled by PHP's configuration, this setting will be ignored.
+allow_url_fopen = Off
+
+; Base URL override settings: Entries like the following examples can
+; be used to override the base URLs used by OJS. If you want to use a
+; proxy to rewrite URLs to OJS, configure your proxy's URL here.
+; Syntax: base_url[journal_path] = http://www.myUrl.com
+; To override URLs that aren't part of a particular journal, use a
+; journal_path of "index".
+; Examples:
+; base_url[index] = http://www.myUrl.com
+; base_url[myJournal] = http://www.myUrl.com/myJournal
+; base_url[myOtherJournal] = http://myOtherJournal.myUrl.com
+
+; Generate RESTful URLs using mod_rewrite.  This requires the
+; rewrite directive to be enabled in your .htaccess or httpd.conf.
+; See FAQ for more details.
+restful_urls = On
+
+; Allow the X_FORWARDED_FOR header to override the REMOTE_ADDR as the source IP
+; Set this to "On" if you are behind a reverse proxy and you control the X_FORWARDED_FOR
+; Warning: This defaults to "On" if unset for backwards compatibility.
+trust_x_forwarded_for = Off
+
+; Allow javascript files to be served through a content delivery network (set to off to use local files)
+enable_cdn = Off
+
+; Set the maximum number of citation checking processes that may run in parallel.
+; Too high a value can increase server load and lead to too many parallel outgoing
+; requests to citation checking web services. Too low a value can lead to significantly
+; slower citation checking performance. A reasonable value is probably between 3
+; and 10. The more your connection bandwidth allows the better.
+citation_checking_max_processes = 3
+
+; Display a message on the site admin and journal manager user home pages if there is an upgrade available
+show_upgrade_warning = On
+
+; Set the following parameter to off if you want to work with the uncompiled (non-minified) JavaScript
+; source for debugging or if you are working off a development branch without compiled JavaScript.
+enable_minified = On
+
+; Provide a unique site ID and OAI base URL to PKP for statistics and security
+; alert purposes only.
+enable_beacon = Off
+
+; Set this to "On" if you would like to only have a single, site-wide Privacy
+; Statement, rather than a separate Privacy Statement for each journal. Setting
+; this to "Off" will allow you to enter a site-wide Privacy Statement as well
+; as separate Privacy Statements for each journal.
+sitewide_privacy_statement = Off
+
+
+;;;;;;;;;;;;;;;;;;;;;
+; Database Settings ;
+;;;;;;;;;;;;;;;;;;;;;
+
+[database]
+
+driver = mysqli
+host = node
+username = ojs_acta
+password = R36aVTUKgOWgawMRvSVqZ4LfYWswZc
+name = ojs_acta
+; Set the non-standard port and/or socket, if used
+; port = 3306
+; unix_socket = /var/run/mysqld/mysqld.sock
+
+; Enable persistent connections
+persistent = Off
+
+; Enable database debug output (very verbose!)
+debug = Off
+
+;;;;;;;;;;;;;;;;;;
+; Cache Settings ;
+;;;;;;;;;;;;;;;;;;
+
+[cache]
+
+; Choose the type of object data caching to use. Options are:
+; - memcache: Use the memcache server configured below
+; - xcache: Use the xcache variable store
+; - apc: Use the APC variable store
+; - none: Use no caching.
+object_cache = none
+
+; Enable memcache support
+memcache_hostname = localhost
+memcache_port = 11211
+
+; For site visitors who are not logged in, many pages are often entirely
+; static (e.g. About, the home page, etc). If the option below is enabled,
+; these pages will be cached in local flat files for the number of hours
+; specified in the web_cache_hours option. This will cut down on server
+; overhead for many requests, but should be used with caution because:
+; 1) Things like journal metadata changes will not be reflected in cached
+;    data until the cache expires or is cleared, and
+; 2) This caching WILL NOT RESPECT DOMAIN-BASED SUBSCRIPTIONS.
+; However, for situations like hosting high-volume open access journals, it's
+; an easy way of decreasing server load.
+;
+; When using web_cache, configure a tool to periodically clear out cache files
+; such as CRON. For example, configure it to run the following command:
+; find .../ojs/cache -maxdepth 1 -name wc-\*.html -mtime +1 -exec rm "{}" ";"
+web_cache = Off
+web_cache_hours = 1
+
+
+;;;;;;;;;;;;;;;;;;;;;;;;;
+; Localization Settings ;
+;;;;;;;;;;;;;;;;;;;;;;;;;
+
+[i18n]
+
+; Default locale
+locale = en_US
+
+; Client output/input character set
+client_charset = utf-8
+
+; Database connection character set
+; Must be set to "Off" if not supported by the database server
+; If enabled, must be the same character set as "client_charset"
+; (although the actual name may differ slightly depending on the server)
+connection_charset = utf8
+
+; Database storage character set
+; Must be set to "Off" if not supported by the database server
+database_charset = utf8
+
+
+;;;;;;;;;;;;;;;;;
+; File Settings ;
+;;;;;;;;;;;;;;;;;
+
+[files]
+
+; Complete path to directory to store uploaded files
+; (This directory should not be directly web-accessible)
+; Windows users should use forward slashes
+files_dir = /var/www/files
+
+; Path to the directory to store public uploaded files
+; (This directory should be web-accessible and the specified path
+; should be relative to the base OJS directory)
+; Windows users should use forward slashes
+public_files_dir = public
+
+; Permissions mask for created files and directories
+umask = 0022
+
+; The minimum percentage similarity between filenames that should be considered
+; a possible revision
+filename_revision_match = 70
+
+
+;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+; Fileinfo (MIME) Settings ;
+;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+
+[finfo]
+; mime_database_path = /etc/magic.mime
+
+
+;;;;;;;;;;;;;;;;;;;;;
+; Security Settings ;
+;;;;;;;;;;;;;;;;;;;;;
+
+[security]
+
+; Force SSL connections site-wide
+force_ssl = On
+
+; Force SSL connections for login only
+force_login_ssl = On
+
+; This check will invalidate a session if the user's IP address changes.
+; Enabling this option provides some amount of additional security, but may
+; cause problems for users behind a proxy farm (e.g., AOL).
+session_check_ip = On
+
+; The encryption (hashing) algorithm to use for encrypting user passwords
+; Valid values are: md5, sha1
+; NOTE: This hashing method is deprecated, but necessary to permit gradual
+; migration of old password hashes.
+encryption = sha1
+
+; The unique salt to use for generating password reset hashes
+salt = "hCNUqKWbPDbFnYcLTpVQHE5YXqWklC"
+
+; The unique secret used for encoding and decoding API keys
+api_key_secret = "j32VIm6QTOvTMnZ1YF4DpJRV07wQhR"
+
+; The number of seconds before a password reset hash expires (defaults to 7200 / 2 hours)
+reset_seconds = 7200
+
+; Allowed HTML tags for fields that permit restricted HTML.
+; Use e.g. "img[src,alt],p" to allow "src" and "alt" attributes to the "img"
+; tag, and also to permit the "p" paragraph tag. Unspecified attributes will be
+; stripped.
+allowed_html = "a[href|target|title],em,strong,cite,code,ul,ol,li[class],dl,dt,dd,b,i,u,img[src|alt],sup,sub,br,p"
+
+;Is implicit authentication enabled or not
+
+;implicit_auth = On
+
+;Implicit Auth Header Variables
+
+;implicit_auth_header_first_name = HTTP_GIVENNAME
+;implicit_auth_header_last_name = HTTP_SN
+;implicit_auth_header_email = HTTP_MAIL
+;implicit_auth_header_phone = HTTP_TELEPHONENUMBER
+;implicit_auth_header_initials = HTTP_METADATA_INITIALS
+;implicit_auth_header_mailing_address = HTTP_METADATA_HOMEPOSTALADDRESS
+;implicit_auth_header_uin = HTTP_UID
+
+; A space delimited list of uins to make admin
+;implicit_auth_admin_list = "jdoe@email.ca jshmo@email.ca"
+
+; URL of the implicit auth 'Way Finder' page. See pages/login/LoginHandler.inc.php for usage.
+
+;implicit_auth_wayf_url = "/Shibboleth.sso/wayf"
+
+
+
+;;;;;;;;;;;;;;;;;;
+; Email Settings ;
+;;;;;;;;;;;;;;;;;;
+
+[email]
+
+; Use SMTP for sending mail instead of mail()
+; smtp = On
+;smtp = On
+;smtp_server = smtp.gmail.com
+;smtp_username = "architecturaenaturalis@gmail.com"
+;smtp_password = "Arhitektuuronilus?"
+;smtp_port = 465
+;smtp_auth = ssl
+;forced_from_address = architecturaenaturalis@gmail.com
+;allow_envelope_sender = On
+;default_envelope_sender = architecturaenaturalis@gmail.com
+;force_default_envelope_sender = On
+
+
+
+smtp = On
+smtp_server = mail.odamus.com
+smtp_port = 587
+smtp_auth = tls
+smtp_username = bounce@odamus.com
+smtp_password = xbUAST4ePTom74LYoE2a
+;forced_from_address = no-reply@odamus.com
+forced_from_name = "Acta Architecturae Naturalis"
+allow_envelope_sender = On
+default_envelope_sender = bounce@odamus.com
+force_default_envelope_sender = On
+
+
+
+; SMTP server settings
+; smtp_server = mail.example.com
+; smtp_port = 25
+
+; Enable SMTP authentication
+; Supported mechanisms: ssl, tls
+; smtp_auth = ssl
+; smtp_username = username
+; smtp_password = password
+
+; Allow envelope sender to be specified
+; (may not be possible with some server configurations)
+; allow_envelope_sender = Off
+
+; Default envelope sender to use if none is specified elsewhere
+; default_envelope_sender = my_address@my_host.com
+
+; Force the default envelope sender (if present)
+; This is useful if setting up a site-wide no-reply address
+; The reply-to field will be set with the reply-to or from address.
+; force_default_envelope_sender = Off
+
+; Force a DMARC compliant from header (RFC5322.From)
+; If any of your users have email addresses in domains not under your control
+; you may need to set this to be compliant with DMARC policies published by
+; those 3rd party domains.
+; Setting this will move the users address into the reply-to field and the
+; from field wil be rewritten with the default_envelope_sender.
+; To use this you must set force_default_enveloper_sender = On and
+; default_envelope_sender must be set to a valid address in a domain you own.
+; force_dmarc_compliant_from = Off
+
+; The display name to use with a DMARC compliant from header
+; By default the DMARC compliant from will have an empty name but this can
+; be changed by adding a text here.
+; You can use '%n' to insert the users name from the original from header
+; and '%s' to insert the localized sitename.
+; dmarc_compliant_from_displayname = '%n via %s'
+
+; Amount of time required between attempts to send non-editorial emails
+; in seconds. This can be used to help prevent email relaying via OJS.
+time_between_emails = 3600
+
+; Maximum number of recipients that can be included in a single email
+; (either as To:, Cc:, or Bcc: addresses) for a non-privileged user
+max_recipients = 10
+
+; If enabled, email addresses must be validated before login is possible.
+require_validation = Off
+
+; Maximum number of days before an unvalidated account expires and is deleted
+validation_timeout = 14
+
+
+;;;;;;;;;;;;;;;;;;;
+; Search Settings ;
+;;;;;;;;;;;;;;;;;;;
+
+[search]
+
+; Minimum indexed word length
+min_word_length = 3
+
+; The maximum number of search results fetched per keyword. These results
+; are fetched and merged to provide results for searches with several keywords.
+results_per_keyword = 500
+
+; The number of hours for which keyword search results are cached.
+result_cache_hours = 1
+
+; Paths to helper programs for indexing non-text files.
+; Programs are assumed to output the converted text to stdout, and "%s" is
+; replaced by the file argument.
+; Note that using full paths to the binaries is recommended.
+; Uncomment applicable lines to enable (at most one per file type).
+; Additional "index[MIME_TYPE]" lines can be added for any mime type to be
+; indexed.
+
+; PDF
+; index[application/pdf] = "/usr/bin/pstotext -enc UTF-8 -nopgbrk %s - | /usr/bin/tr '[:cntrl:]' ' '"
+; index[application/pdf] = "/usr/bin/pdftotext -enc UTF-8 -nopgbrk %s - | /usr/bin/tr '[:cntrl:]' ' '"
+
+; PostScript
+; index[application/postscript] = "/usr/bin/pstotext -enc UTF-8 -nopgbrk %s - | /usr/bin/tr '[:cntrl:]' ' '"
+; index[application/postscript] = "/usr/bin/ps2ascii %s | /usr/bin/tr '[:cntrl:]' ' '"
+
+; Microsoft Word
+; index[application/msword] = "/usr/bin/antiword %s"
+; index[application/msword] = "/usr/bin/catdoc %s"
+
+
+;;;;;;;;;;;;;;;;
+; OAI Settings ;
+;;;;;;;;;;;;;;;;
+
+[oai]
+
+; Enable OAI front-end to the site
+oai = On
+
+; OAI Repository identifier
+repository_id = 
+
+; Maximum number of records per request to serve via OAI
+oai_max_records = 100
+
+;;;;;;;;;;;;;;;;;;;;;;
+; Interface Settings ;
+;;;;;;;;;;;;;;;;;;;;;;
+
+[interface]
+
+; Number of items to display per page; can be overridden on a per-journal basis
+items_per_page = 25
+
+; Number of page links to display; can be overridden on a per-journal basis
+page_links = 10
+
+
+;;;;;;;;;;;;;;;;;;;;
+; Captcha Settings ;
+;;;;;;;;;;;;;;;;;;;;
+
+[captcha]
+
+; Whether or not to enable ReCaptcha
+recaptcha = off
+
+; Public key for reCaptcha (see http://www.google.com/recaptcha)
+recaptcha_public_key = your_public_key
+
+; Private key for reCaptcha (see http://www.google.com/recaptcha)
+recaptcha_private_key = your_private_key
+
+; Whether or not to use Captcha on user registration
+captcha_on_register = on
+
+
+;;;;;;;;;;;;;;;;;;;;;
+; External Commands ;
+;;;;;;;;;;;;;;;;;;;;;
+
+[cli]
+
+; These are paths to (optional) external binaries used in
+; certain plug-ins or advanced program features.
+
+; Using full paths to the binaries is recommended.
+
+; perl (used in paracite citation parser)
+perl = /usr/bin/perl
+
+; tar (used in backup plugin, translation packaging)
+tar = /bin/tar
+
+; On systems that do not have libxsl/xslt libraries installed, or for those who
+; require a specific XSLT processor, you may enter the complete path to the
+; XSLT renderer tool, with any required arguments. Use %xsl to substitute the
+; location of the XSL stylesheet file, and %xml for the location of the XML
+; source file; eg:
+; /usr/bin/java -jar ~/java/xalan.jar -HTML -IN %xml -XSL %xsl
+xslt_command = ""
+
+;;;;;;;;;;;;;;;;;;
+; Proxy Settings ;
+;;;;;;;;;;;;;;;;;;
+
+[proxy]
+
+; Note that allow_url_fopen must be set to Off before these proxy settings
+; will take effect.
+
+; The HTTP proxy configuration to use
+; http_host = localhost
+; http_port = 80
+; proxy_username = username
+; proxy_password = password
+
+
+;;;;;;;;;;;;;;;;;;
+; Debug Settings ;
+;;;;;;;;;;;;;;;;;;
+
+[debug]
+
+; Display a stack trace when a fatal error occurs.
+; Note that this may expose private information and should be disabled
+; for any production system.
+show_stacktrace = Off
+
+; Display an error message when something goes wrong.
+display_errors = Off
+
+; Display deprecation warnings
+deprecation_warnings = Off
+
+; Log web service request information for debugging
+log_web_service_info = Off

+ 1 - 0
other/ojs/config/php.custom.ini

@@ -0,0 +1 @@
+//

+ 20 - 0
other/ojs/config/supervisord.conf

@@ -0,0 +1,20 @@
+[supervisord]
+user=root
+nodaemon=true
+loglevel=info
+pidfile=/run/supervisord/supervisord.pid
+logfile=/var/log/supervisord.log
+
+[supervisorctl]
+serverurl=unix:///tmp/supervisor.sock
+
+[program:checkstart]
+command=/usr/local/bin/ojs-pre-start
+
+[program:crond]
+command=/usr/sbin/crond -f -L /var/log/cron/cron.log
+autorestart=true
+
+[program:apache]
+command=/usr/sbin/httpd -f /etc/apache2/httpd.conf -DFOREGROUND
+autorestart=true

+ 532 - 0
other/ojs/configs/config_inc_php_v2

@@ -0,0 +1,532 @@
+; <?php exit(); // DO NOT DELETE ?>
+; DO NOT DELETE THE ABOVE LINE!!!
+; Doing so will expose this configuration file through your web site!
+;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+
+;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+;
+; config.TEMPLATE.inc.php
+;
+; Copyright (c) 2014-2019 Simon Fraser University
+; Copyright (c) 2003-2019 John Willinsky
+; Distributed under the GNU GPL v2. For full terms see the file docs/COPYING.
+;
+; OJS Configuration settings.
+; Rename config.TEMPLATE.inc.php to config.inc.php to use.
+;
+;
+;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+
+
+;;;;;;;;;;;;;;;;;;;;
+; General Settings ;
+;;;;;;;;;;;;;;;;;;;;
+
+[general]
+; Set this to On once the system has been installed
+; (This is generally done automatically by the installer)
+installed = On
+
+; The canonical URL to the OJS installation (excluding the trailing slash)
+base_url = "https://www.maastikuarhitektuur.ee"
+;base_url = "https://acta.odamus.com"
+
+; Session cookie name
+session_cookie_name = OJSSID
+
+; Session cookie path; if not specified, defaults to the detected base path
+; session_cookie_path = /
+
+; Number of days to save login cookie for if user selects to remember
+; (set to 0 to force expiration at end of current session)
+session_lifetime = 30
+
+; Enable support for running scheduled tasks
+; Set this to On if you have set up the scheduled tasks script to
+; execute periodically
+scheduled_tasks = Off
+
+; Site time zone
+; Please refer to lib/pkp/registry/timeZones.xml for a full list of supported
+; time zones.
+; I.e.:
+; <entry key="Europe/Amsterdam" name="Amsterdam" />
+; time_zone="Amsterdam"
+time_zone = "UTC"
+
+; Short and long date formats
+date_format_trunc = "%m-%d"
+date_format_short = "%Y-%m-%d"
+date_format_long = "%B %e, %Y"
+datetime_format_short = "%Y-%m-%d %I:%M %p"
+datetime_format_long = "%B %e, %Y - %I:%M %p"
+time_format = "%I:%M %p"
+
+; Use URL parameters instead of CGI PATH_INFO. This is useful for
+; broken server setups that don't support the PATH_INFO environment
+; variable.
+disable_path_info = Off
+
+; Use fopen(...) for URL-based reads. Modern versions of dspace
+; will not accept requests using fopen, as it does not provide a
+; User Agent, so this option is disabled by default. If this feature
+; is disabled by PHP's configuration, this setting will be ignored.
+allow_url_fopen = Off
+
+; Base URL override settings: Entries like the following examples can
+; be used to override the base URLs used by OJS. If you want to use a
+; proxy to rewrite URLs to OJS, configure your proxy's URL here.
+; Syntax: base_url[journal_path] = http://www.myUrl.com
+; To override URLs that aren't part of a particular journal, use a
+; journal_path of "index".
+; Examples:
+; base_url[index] = http://www.myUrl.com
+; base_url[myJournal] = http://www.myUrl.com/myJournal
+; base_url[myOtherJournal] = http://myOtherJournal.myUrl.com
+
+; Generate RESTful URLs using mod_rewrite.  This requires the
+; rewrite directive to be enabled in your .htaccess or httpd.conf.
+; See FAQ for more details.
+restful_urls = On
+
+; Allow the X_FORWARDED_FOR header to override the REMOTE_ADDR as the source IP
+; Set this to "On" if you are behind a reverse proxy and you control the X_FORWARDED_FOR
+; Warning: This defaults to "On" if unset for backwards compatibility.
+trust_x_forwarded_for = Off
+
+; Allow javascript files to be served through a content delivery network (set to off to use local files)
+enable_cdn = Off
+
+; Set the maximum number of citation checking processes that may run in parallel.
+; Too high a value can increase server load and lead to too many parallel outgoing
+; requests to citation checking web services. Too low a value can lead to significantly
+; slower citation checking performance. A reasonable value is probably between 3
+; and 10. The more your connection bandwidth allows the better.
+citation_checking_max_processes = 3
+
+; Display a message on the site admin and journal manager user home pages if there is an upgrade available
+show_upgrade_warning = On
+
+; Set the following parameter to off if you want to work with the uncompiled (non-minified) JavaScript
+; source for debugging or if you are working off a development branch without compiled JavaScript.
+enable_minified = On
+
+; Provide a unique site ID and OAI base URL to PKP for statistics and security
+; alert purposes only.
+enable_beacon = Off
+
+; Set this to "On" if you would like to only have a single, site-wide Privacy
+; Statement, rather than a separate Privacy Statement for each journal. Setting
+; this to "Off" will allow you to enter a site-wide Privacy Statement as well
+; as separate Privacy Statements for each journal.
+sitewide_privacy_statement = Off
+
+
+;;;;;;;;;;;;;;;;;;;;;
+; Database Settings ;
+;;;;;;;;;;;;;;;;;;;;;
+
+[database]
+
+driver = mysqli
+host = mariadb_simple
+username = ojs_acta
+password = R36aVTUKgOWgawMRvSVqZ4LfYWswZc
+name = ojs_acta
+; Set the non-standard port and/or socket, if used
+; port = 3306
+; unix_socket = /var/run/mysqld/mysqld.sock
+
+; Enable persistent connections
+persistent = Off
+
+; Enable database debug output (very verbose!)
+debug = Off
+
+;;;;;;;;;;;;;;;;;;
+; Cache Settings ;
+;;;;;;;;;;;;;;;;;;
+
+[cache]
+
+; Choose the type of object data caching to use. Options are:
+; - memcache: Use the memcache server configured below
+; - xcache: Use the xcache variable store
+; - apc: Use the APC variable store
+; - none: Use no caching.
+object_cache = none
+
+; Enable memcache support
+memcache_hostname = localhost
+memcache_port = 11211
+
+; For site visitors who are not logged in, many pages are often entirely
+; static (e.g. About, the home page, etc). If the option below is enabled,
+; these pages will be cached in local flat files for the number of hours
+; specified in the web_cache_hours option. This will cut down on server
+; overhead for many requests, but should be used with caution because:
+; 1) Things like journal metadata changes will not be reflected in cached
+;    data until the cache expires or is cleared, and
+; 2) This caching WILL NOT RESPECT DOMAIN-BASED SUBSCRIPTIONS.
+; However, for situations like hosting high-volume open access journals, it's
+; an easy way of decreasing server load.
+;
+; When using web_cache, configure a tool to periodically clear out cache files
+; such as CRON. For example, configure it to run the following command:
+; find .../ojs/cache -maxdepth 1 -name wc-\*.html -mtime +1 -exec rm "{}" ";"
+web_cache = Off
+web_cache_hours = 1
+
+
+;;;;;;;;;;;;;;;;;;;;;;;;;
+; Localization Settings ;
+;;;;;;;;;;;;;;;;;;;;;;;;;
+
+[i18n]
+
+; Default locale
+locale = en_US
+
+; Client output/input character set
+client_charset = utf-8
+
+; Database connection character set
+; Must be set to "Off" if not supported by the database server
+; If enabled, must be the same character set as "client_charset"
+; (although the actual name may differ slightly depending on the server)
+connection_charset = utf8
+
+; Database storage character set
+; Must be set to "Off" if not supported by the database server
+database_charset = utf8
+
+
+;;;;;;;;;;;;;;;;;
+; File Settings ;
+;;;;;;;;;;;;;;;;;
+
+[files]
+
+; Complete path to directory to store uploaded files
+; (This directory should not be directly web-accessible)
+; Windows users should use forward slashes
+files_dir = /var/www/files
+
+; Path to the directory to store public uploaded files
+; (This directory should be web-accessible and the specified path
+; should be relative to the base OJS directory)
+; Windows users should use forward slashes
+public_files_dir = public
+
+; Permissions mask for created files and directories
+umask = 0022
+
+; The minimum percentage similarity between filenames that should be considered
+; a possible revision
+filename_revision_match = 70
+
+
+;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+; Fileinfo (MIME) Settings ;
+;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+
+[finfo]
+; mime_database_path = /etc/magic.mime
+
+
+;;;;;;;;;;;;;;;;;;;;;
+; Security Settings ;
+;;;;;;;;;;;;;;;;;;;;;
+
+[security]
+
+; Force SSL connections site-wide
+force_ssl = On
+
+; Force SSL connections for login only
+force_login_ssl = On
+
+; This check will invalidate a session if the user's IP address changes.
+; Enabling this option provides some amount of additional security, but may
+; cause problems for users behind a proxy farm (e.g., AOL).
+session_check_ip = On
+
+; The encryption (hashing) algorithm to use for encrypting user passwords
+; Valid values are: md5, sha1
+; NOTE: This hashing method is deprecated, but necessary to permit gradual
+; migration of old password hashes.
+encryption = sha1
+
+; The unique salt to use for generating password reset hashes
+salt = "hCNUqKWbPDbFnYcLTpVQHE5YXqWklC"
+
+; The unique secret used for encoding and decoding API keys
+api_key_secret = "j32VIm6QTOvTMnZ1YF4DpJRV07wQhR"
+
+; The number of seconds before a password reset hash expires (defaults to 7200 / 2 hours)
+reset_seconds = 7200
+
+; Allowed HTML tags for fields that permit restricted HTML.
+; Use e.g. "img[src,alt],p" to allow "src" and "alt" attributes to the "img"
+; tag, and also to permit the "p" paragraph tag. Unspecified attributes will be
+; stripped.
+allowed_html = "a[href|target|title],em,strong,cite,code,ul,ol,li[class],dl,dt,dd,b,i,u,img[src|alt],sup,sub,br,p"
+
+;Is implicit authentication enabled or not
+
+;implicit_auth = On
+
+;Implicit Auth Header Variables
+
+;implicit_auth_header_first_name = HTTP_GIVENNAME
+;implicit_auth_header_last_name = HTTP_SN
+;implicit_auth_header_email = HTTP_MAIL
+;implicit_auth_header_phone = HTTP_TELEPHONENUMBER
+;implicit_auth_header_initials = HTTP_METADATA_INITIALS
+;implicit_auth_header_mailing_address = HTTP_METADATA_HOMEPOSTALADDRESS
+;implicit_auth_header_uin = HTTP_UID
+
+; A space delimited list of uins to make admin
+;implicit_auth_admin_list = "jdoe@email.ca jshmo@email.ca"
+
+; URL of the implicit auth 'Way Finder' page. See pages/login/LoginHandler.inc.php for usage.
+
+;implicit_auth_wayf_url = "/Shibboleth.sso/wayf"
+
+
+
+;;;;;;;;;;;;;;;;;;
+; Email Settings ;
+;;;;;;;;;;;;;;;;;;
+
+[email]
+
+; Use SMTP for sending mail instead of mail()
+; smtp = On
+;smtp = On
+;smtp_server = smtp.gmail.com
+;smtp_username = "architecturaenaturalis@gmail.com"
+;smtp_password = "Arhitektuuronilus?"
+;smtp_port = 465
+;smtp_auth = ssl
+;forced_from_address = architecturaenaturalis@gmail.com
+;allow_envelope_sender = On
+;default_envelope_sender = architecturaenaturalis@gmail.com
+;force_default_envelope_sender = On
+
+
+
+smtp = On
+smtp_server = mail.odamus.com
+smtp_port = 587
+smtp_auth = tls
+smtp_username = bounce@odamus.com
+smtp_password = xbUAST4ePTom74LYoE2a
+;forced_from_address = no-reply@odamus.com
+forced_from_name = "Acta Architecturae Naturalis"
+allow_envelope_sender = On
+default_envelope_sender = bounce@odamus.com
+force_default_envelope_sender = On
+
+
+
+; SMTP server settings
+; smtp_server = mail.example.com
+; smtp_port = 25
+
+; Enable SMTP authentication
+; Supported mechanisms: ssl, tls
+; smtp_auth = ssl
+; smtp_username = username
+; smtp_password = password
+
+; Allow envelope sender to be specified
+; (may not be possible with some server configurations)
+; allow_envelope_sender = Off
+
+; Default envelope sender to use if none is specified elsewhere
+; default_envelope_sender = my_address@my_host.com
+
+; Force the default envelope sender (if present)
+; This is useful if setting up a site-wide no-reply address
+; The reply-to field will be set with the reply-to or from address.
+; force_default_envelope_sender = Off
+
+; Force a DMARC compliant from header (RFC5322.From)
+; If any of your users have email addresses in domains not under your control
+; you may need to set this to be compliant with DMARC policies published by
+; those 3rd party domains.
+; Setting this will move the users address into the reply-to field and the
+; from field wil be rewritten with the default_envelope_sender.
+; To use this you must set force_default_enveloper_sender = On and
+; default_envelope_sender must be set to a valid address in a domain you own.
+; force_dmarc_compliant_from = Off
+
+; The display name to use with a DMARC compliant from header
+; By default the DMARC compliant from will have an empty name but this can
+; be changed by adding a text here.
+; You can use '%n' to insert the users name from the original from header
+; and '%s' to insert the localized sitename.
+; dmarc_compliant_from_displayname = '%n via %s'
+
+; Amount of time required between attempts to send non-editorial emails
+; in seconds. This can be used to help prevent email relaying via OJS.
+time_between_emails = 3600
+
+; Maximum number of recipients that can be included in a single email
+; (either as To:, Cc:, or Bcc: addresses) for a non-privileged user
+max_recipients = 10
+
+; If enabled, email addresses must be validated before login is possible.
+require_validation = Off
+
+; Maximum number of days before an unvalidated account expires and is deleted
+validation_timeout = 14
+
+
+;;;;;;;;;;;;;;;;;;;
+; Search Settings ;
+;;;;;;;;;;;;;;;;;;;
+
+[search]
+
+; Minimum indexed word length
+min_word_length = 3
+
+; The maximum number of search results fetched per keyword. These results
+; are fetched and merged to provide results for searches with several keywords.
+results_per_keyword = 500
+
+; The number of hours for which keyword search results are cached.
+result_cache_hours = 1
+
+; Paths to helper programs for indexing non-text files.
+; Programs are assumed to output the converted text to stdout, and "%s" is
+; replaced by the file argument.
+; Note that using full paths to the binaries is recommended.
+; Uncomment applicable lines to enable (at most one per file type).
+; Additional "index[MIME_TYPE]" lines can be added for any mime type to be
+; indexed.
+
+; PDF
+; index[application/pdf] = "/usr/bin/pstotext -enc UTF-8 -nopgbrk %s - | /usr/bin/tr '[:cntrl:]' ' '"
+; index[application/pdf] = "/usr/bin/pdftotext -enc UTF-8 -nopgbrk %s - | /usr/bin/tr '[:cntrl:]' ' '"
+
+; PostScript
+; index[application/postscript] = "/usr/bin/pstotext -enc UTF-8 -nopgbrk %s - | /usr/bin/tr '[:cntrl:]' ' '"
+; index[application/postscript] = "/usr/bin/ps2ascii %s | /usr/bin/tr '[:cntrl:]' ' '"
+
+; Microsoft Word
+; index[application/msword] = "/usr/bin/antiword %s"
+; index[application/msword] = "/usr/bin/catdoc %s"
+
+
+;;;;;;;;;;;;;;;;
+; OAI Settings ;
+;;;;;;;;;;;;;;;;
+
+[oai]
+
+; Enable OAI front-end to the site
+oai = On
+
+; OAI Repository identifier
+repository_id = 
+
+; Maximum number of records per request to serve via OAI
+oai_max_records = 100
+
+;;;;;;;;;;;;;;;;;;;;;;
+; Interface Settings ;
+;;;;;;;;;;;;;;;;;;;;;;
+
+[interface]
+
+; Number of items to display per page; can be overridden on a per-journal basis
+items_per_page = 25
+
+; Number of page links to display; can be overridden on a per-journal basis
+page_links = 10
+
+
+;;;;;;;;;;;;;;;;;;;;
+; Captcha Settings ;
+;;;;;;;;;;;;;;;;;;;;
+
+[captcha]
+
+; Whether or not to enable ReCaptcha
+recaptcha = off
+
+; Public key for reCaptcha (see http://www.google.com/recaptcha)
+recaptcha_public_key = your_public_key
+
+; Private key for reCaptcha (see http://www.google.com/recaptcha)
+recaptcha_private_key = your_private_key
+
+; Whether or not to use Captcha on user registration
+captcha_on_register = on
+
+
+;;;;;;;;;;;;;;;;;;;;;
+; External Commands ;
+;;;;;;;;;;;;;;;;;;;;;
+
+[cli]
+
+; These are paths to (optional) external binaries used in
+; certain plug-ins or advanced program features.
+
+; Using full paths to the binaries is recommended.
+
+; perl (used in paracite citation parser)
+perl = /usr/bin/perl
+
+; tar (used in backup plugin, translation packaging)
+tar = /bin/tar
+
+; On systems that do not have libxsl/xslt libraries installed, or for those who
+; require a specific XSLT processor, you may enter the complete path to the
+; XSLT renderer tool, with any required arguments. Use %xsl to substitute the
+; location of the XSL stylesheet file, and %xml for the location of the XML
+; source file; eg:
+; /usr/bin/java -jar ~/java/xalan.jar -HTML -IN %xml -XSL %xsl
+xslt_command = ""
+
+;;;;;;;;;;;;;;;;;;
+; Proxy Settings ;
+;;;;;;;;;;;;;;;;;;
+
+[proxy]
+
+; Note that allow_url_fopen must be set to Off before these proxy settings
+; will take effect.
+
+; The HTTP proxy configuration to use
+; http_host = localhost
+; http_port = 80
+; proxy_username = username
+; proxy_password = password
+
+
+;;;;;;;;;;;;;;;;;;
+; Debug Settings ;
+;;;;;;;;;;;;;;;;;;
+
+[debug]
+
+; Display a stack trace when a fatal error occurs.
+; Note that this may expose private information and should be disabled
+; for any production system.
+show_stacktrace = Off
+
+; Display an error message when something goes wrong.
+display_errors = Off
+
+; Display deprecation warnings
+deprecation_warnings = Off
+
+; Log web service request information for debugging
+log_web_service_info = Off
+
+

+ 2 - 0
other/ojs/configs/custom_ini

@@ -0,0 +1,2 @@
+//
+

+ 32 - 0
other/ojs/configs/htaccess

@@ -0,0 +1,32 @@
+RewriteEngine on
+RewriteCond %{SCRIPT_FILENAME} !-d
+RewriteCond %{SCRIPT_FILENAME} !-f
+RewriteCond $1 !^(index\.php)
+RewriteRule ^(.*)$ index.php/$1 [L]
+
+
+#RewriteCond %{HTTPS} off
+#RewriteCond %{HTTP_HOST} ^maastikuarhitektuur\.ee$ [NC]
+#RewriteRule ^ https://www.maastikuarhitektuur.ee%{REQUEST_URI} [R=302,L]
+
+
+# Redirect www to non-www
+#RewriteEngine on
+#RewriteBase /
+#RewriteCond %{HTTP_HOST} ^www\.(.*)$ [NC]
+#RewriteRule ^(.*)$ http://%1/$1 [R=301,L]
+
+# Redirect non-www to www
+#RewriteEngine On
+#RewriteBase /
+#RewriteCond %{HTTP_HOST} !^www\. [NC]
+#RewriteRule ^(.*)$ http://www.%{HTTP_HOST}/$1 [R=301,L]
+
+#RewriteCond %{HTTPS} off
+#RewriteCond %{HTTP_HOST} !^www\.(.*)$ [NC]
+#RewriteRule ^(.*)$ http://www.%{HTTP_HOST}/$1 [R=301,L]
+
+#RewriteCond %{HTTPS} on
+#RewriteCond %{HTTP_HOST} !^www\.(.*)$ [NC]
+#RewriteRule ^(.*)$ https://www.%{HTTP_HOST}/$1 [R=301,L]
+

+ 35 - 0
other/ojs/configs/ojs_conf

@@ -0,0 +1,35 @@
+LoadModule slotmem_shm_module modules/mod_slotmem_shm.so
+LoadModule rewrite_module modules/mod_rewrite.so
+LoadModule expires_module modules/mod_expires.so
+
+
+PassEnv HTTPS
+
+ServerName www.maastikuarhitektuur.ee
+DocumentRoot /var/www/html
+	
+RewriteEngine on
+<Directory /var/www/html>
+	Options FollowSymLinks
+	AllowOverride all
+	Allow from all
+
+	# This removes index.php from the url
+	RewriteCond %{REQUEST_FILENAME} !-d 
+	RewriteCond %{REQUEST_FILENAME} !-f 
+	RewriteRule ^(.*)$ index.php/$1 [QSA,L]
+</Directory>
+
+
+# ardo: acme.sh jaoks sertifikaadi uuendamiseks
+   Alias /.well-known "/var/www/html/public/.well-known"
+    <Directory "/var/www/html/public/.well-known/acme-challenge">
+    Order allow,deny
+    Allow from all
+    Require all granted
+    </Directory>
+
+
+ErrorLog  /var/log/apache2/error.log  
+CustomLog  /var/log/apache2/access.log combined
+

Some files were not shown because too many files changed in this diff