Adapted from the black-candle-technologies/infrastructure repository docs.
Shared VPS infrastructure configuration. Contains only safe-to-track config; it intentionally excludes real .env files, Docker volumes, Caddy certificates, backups, and private keys.
| Service | Location | Notes |
|---|---|---|
| Caddy | /srv/infrastructure/caddy |
Public ports 80/443, external proxy network |
| PostgreSQL | /srv/infrastructure/postgres |
Named postgres_data volume, internal postgres network only |
| Redis | /srv/infrastructure/redis |
Named redis_data volume, internal redis network only |
| Authelia | /srv/infrastructure/authelia |
Central one-factor login portal at auth.lanebucher.com, on proxy + postgres + redis networks |
Start/restart each service with docker compose up -d in its directory. Inspect with docker compose logs -f.
compose.yml and attach the app service.postgres: host postgres, port 5432, application-specific database/user.redis: host redis, port 6379, password from the protected Redis .env.proxy; Caddy then targets service-name:port.Rules: never create a database/role until an application needs one. Never add ports: to PostgreSQL or Redis. Authelia is the established example (own PG role/database, Redis database 1, nothing exposed).
All new public applications are protected by default: keep the app port private, attach to proxy, and use the (authelia) Caddy snippet in caddy/Caddyfile before reverse_proxy. auth.lanebucher.com is the sole login-portal exception and must not import that snippet. Any other exception needs a documented reason in both the app README and Caddyfile.
/srv/dev/code-server is a separately deployed browser IDE. Its only persistent host mounts are /srv/dev/home and /srv/dev/workspace. It must never receive /var/run/docker.sock, production /srv mounts, privileged mode, host networking, or production datastore-network access.
scripts/backup.sh creates PostgreSQL dumps, Caddy/Redis/PostgreSQL volume archives, and a protected archive of /srv configuration. Retains 14 days in /srv/backups. Local copies protect against accidental deletion or failed updates only; implement encrypted offsite copying before treating backups as disaster recovery.
Test restoration in an isolated environment before relying on a backup. Caddy's data volume includes TLS private material and config archives include .env files, so backups are sensitive.
Ubuntu unattended upgrades install security updates daily (automatic reboot disabled; schedule maintenance reboots when /var/run/reboot-required exists). Docker uses json-file logging with 10 MiB files, three files per container. Journald/rsyslog manage normal system logs.
docs/BLACK_CANDLE_CI.md documents black-candle-vps-01, the org-level GitHub Actions runner:
black-candle-ci is available to private repos only (a public fork PR could execute untrusted code on a self-hosted runner).self-hosted, Linux, X64 plus black-candle, ci, vps. One job at a time.blackcandle-ci Unix account: no sudo, no Docker, no production SSH keys, no access to /root, /srv/infrastructure, production .env files, or the Docker socket. Everything beneath /srv/black-candle-ci.CPUQuota=300%, MemoryHigh=4G, MemoryMax=5G, TasksMax=512.UMask=0077, PrivateTmp=true, NoNewPrivileges=true.