cmc/dotfiles

Using GNU Stow to manage my dotfiles. config dotfiles macos stow

Commit 0c68f866ef

0c68f866ef5823b23877188c4057a00d913bc115

parent: 565e8c2db8

Verified · cmc

cmc <hello@cleberg.net> · 2026-08-03 05:41 UTC

chore: cleanup

Layout: unified · split

linux/nginx/etc/nginx/conf.d/piped.conf added +74
@@ -0,0 +1,74 @@
1# Piped -- Host-based router on 127.0.0.1:8077
2#
3# WHY THIS EXISTS: the Cloudflare tunnel routes all three Piped hostnames to
4# localhost:8077 --
5# piped.krz.sh -> :8077
6# pipedapi.krz.sh -> :8077 (should be the backend)
7# pipedproxy.krz.sh -> :8077 (should be the media proxy)
8# so the API and media-proxy hostnames landed on the frontend and Piped was
9# broken. The frontend advertises BACKEND_HOSTNAME=pipedapi.krz.sh to browsers,
10# so every API call failed.
11#
12# The tidier fix is two edits in the Cloudflare dashboard (point pipedapi at
13# :8078 and pipedproxy at :8079). This file fixes it server-side instead, and
14# is harmless if the dashboard is corrected later -- the tunnel would simply
15# reach the containers directly and these blocks would go unused.
16#
17# Ports: frontend :8076 (moved from :8077), backend :8078, media proxy :8079.
18#
19# NOTE: custom.d/basic.conf is deliberately NOT included. Its Permissions-Policy
20# sets fullscreen=(), which would stop videos going fullscreen.
21
22# Frontend. default_server so the Tor onion for piped (which targets :8077 with
23# a .onion Host header) also lands here.
24server {
25 listen 127.0.0.1:8077 default_server;
26 server_name piped.krz.sh;
27
28 location / {
29 proxy_pass http://127.0.0.1:8076;
30 proxy_set_header Host $host;
31 proxy_set_header X-Real-IP $remote_addr;
32 proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
33 proxy_set_header X-Forwarded-Proto $scheme;
34 proxy_http_version 1.1;
35 }
36}
37
38# Backend API.
39server {
40 listen 127.0.0.1:8077;
41 server_name pipedapi.krz.sh;
42
43 location / {
44 proxy_pass http://127.0.0.1:8078;
45 proxy_set_header Host $host;
46 proxy_set_header X-Real-IP $remote_addr;
47 proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
48 proxy_set_header X-Forwarded-Proto $scheme;
49 proxy_http_version 1.1;
50 # The backend emits its own CORS headers; do not add or override any
51 # here or the browser will reject the API responses.
52 proxy_read_timeout 120;
53 }
54}
55
56# Media proxy. Streams video, so no buffering and generous timeouts.
57server {
58 listen 127.0.0.1:8077;
59 server_name pipedproxy.krz.sh;
60
61 location / {
62 proxy_pass http://127.0.0.1:8079;
63 proxy_set_header Host $host;
64 proxy_set_header X-Real-IP $remote_addr;
65 proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
66 proxy_set_header X-Forwarded-Proto $scheme;
67 proxy_http_version 1.1;
68
69 proxy_buffering off;
70 proxy_request_buffering off;
71 proxy_read_timeout 300;
72 proxy_send_timeout 300;
73 }
74}
linux/nginx/etc/nginx/nginx.conf +13 −1
@@ -41,7 +41,19 @@ events {
41# Default: logs/error.log error 41# Default: logs/error.log error
42# https://nginx.org/en/docs/ngx_core_module.html#error_log 42# https://nginx.org/en/docs/ngx_core_module.html#error_log
43# error_log /var/log/nginx/error.log warn; 43# error_log /var/log/nginx/error.log warn;
44error_log /dev/null emerg; 44#
45# emerg-only, to stderr -> systemd captures it into journald, which is RAM-only
46# on this host (Storage=volatile), so nothing lands on disk and nothing survives
47# a reboot.
48#
49# This was /dev/null, which discarded the one class of message that says the
50# server is broken. That cost real diagnostic time twice on 2026-08-03: a reload
51# that silently failed to rebind sockets, and the certbot failures. emerg
52# messages are startup/bind/shutdown faults and carry no visitor data, so
53# keeping them costs nothing in privacy terms.
54#
55# Read with: journalctl -u nginx
56error_log stderr emerg;
45 57
46# The file storing the process ID of the main process 58# The file storing the process ID of the main process
47# Default: logs/nginx.pid 59# Default: logs/nginx.pid