diff --git a/readme.md b/readme.md index c2bae73..6ba1189 100644 --- a/readme.md +++ b/readme.md @@ -7,16 +7,32 @@ Allegedly can - Tail PLC ops to stdout: `allegedly tail | jq` - Export PLC ops to weekly gzipped bundles: `allegdly bundle --dest ./some-folder` - Dump bundled ops to stdout FAST: `allegedly backfill --source-workers 6 | pv -l > /ops-unordered.jsonl` -- Wrap the reference PLC server and run it as a mirror: +- Wrap the reference PLC server and run it as a mirror, copying ops from upstream: ```bash + allegedly mirror \ + --wrap "http://127.0.0.1:3000" \ + --wrap-pg "postgresql://user:pass@pg-host:5432/plc-db" + ``` + +- Wrap a plc server, maximalist edition: + + ```bash + # put sensitive values in environment so they don't leak via process name. export ALLEGEDLY_WRAP_PG="postgresql://user:pass@pg-host:5432/plc-db" - allegedly --upstream "https://plc.directory" mirror \ - --bind "0.0.0.0:8000" \ - --wrap "http://127.0.0.1:3000" - ``` -(add `--help` to any command for more info about it) + # sudo to bind :80 + :443 for acme tls, but it's better to give user net cap. + # will try to autoprovision cert for "plc.wtf" from letsencrypt staging. + sudo allegedly mirror \ + --upstream "https://plc.directory" \ + --wrap "http://127.0.0.1:3000" \ + --acme-domain "plc.wtf" \ + --acme-cache-dir ./acme-cache \ + --acme-directory-url "https://acme-staging-v02.api.letsencrypt.org/directory" + ``` + + +add `--help` to any command for more info about it ## install diff --git a/src/mirror.rs b/src/mirror.rs index 00b2342..47f6cc9 100644 --- a/src/mirror.rs +++ b/src/mirror.rs @@ -230,6 +230,8 @@ pub async fn serve(upstream: &Url, plc: Url, listen: ListenConf) -> std::io::Res auto_cert = auto_cert.domain(domain); } let auto_cert = auto_cert.build().expect("acme config to build"); + + run_insecure_notice(); run(app, TcpListener::bind("0.0.0.0:443").acme(auto_cert)).await } ListenConf::Bind(addr) => run(app, TcpListener::bind(addr)).await, @@ -246,3 +248,29 @@ where .run(app) .await } + +/// kick off a tiny little server on a tokio task to tell people to use 443 +fn run_insecure_notice() { + #[handler] + fn oop_plz_be_secure() -> (StatusCode, String) { + ( + StatusCode::BAD_REQUEST, + format!( + r#"{} + +You probably want to change your request to use HTTPS instead of HTTP. +"#, + logo("mirror (tls on 443 please)") + ), + ) + } + + let app = Route::new().at("/", get(oop_plz_be_secure)).with(Tracing); + let listener = TcpListener::bind("0.0.0.0:80"); + tokio::task::spawn(async move { + Server::new(listener) + .name("allegedly (mirror:80 helper)") + .run(app) + .await + }); +}