From fecffc33f0acc6675420c8d13b982372dc84f367 Mon Sep 17 00:00:00 2001 From: Beda Schmid Date: Mon, 17 Aug 2026 20:55:32 +0000 Subject: [PATCH] Reset history to current sanitized state --- .gitignore | 415 ++++++++++++++++++ LICENSE | 24 + README.md | 30 ++ clickhouse_config/disable_cgroup_observer.xml | 3 + clickhouse_config/enable_json.xml | 5 + clickhouse_config/logging_rules.xml | 14 + clickhouse_config/network.xml | 3 + clickhouse_config/user_logging.xml | 8 + docker-compose.yml | 91 ++++ 9 files changed, 593 insertions(+) create mode 100644 .gitignore create mode 100644 LICENSE create mode 100644 README.md create mode 100644 clickhouse_config/disable_cgroup_observer.xml create mode 100644 clickhouse_config/enable_json.xml create mode 100644 clickhouse_config/logging_rules.xml create mode 100644 clickhouse_config/network.xml create mode 100644 clickhouse_config/user_logging.xml create mode 100644 docker-compose.yml diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..adc15fb --- /dev/null +++ b/.gitignore @@ -0,0 +1,415 @@ +.env +clickhouse-data/ +postgres-data +# ---> VisualStudio +## Ignore Visual Studio temporary files, build results, and +## files generated by popular Visual Studio add-ons. +## +## Get latest from https://github.com/github/gitignore/blob/main/VisualStudio.gitignore + +# User-specific files +*.rsuser +*.suo +*.user +*.userosscache +*.sln.docstates + +# User-specific files (MonoDevelop/Xamarin Studio) +*.userprefs + +# Mono auto generated files +mono_crash.* + +# Build results +[Dd]ebug/ +[Dd]ebugPublic/ +[Rr]elease/ +[Rr]eleases/ +x64/ +x86/ +[Ww][Ii][Nn]32/ +[Aa][Rr][Mm]/ +[Aa][Rr][Mm]64/ +bld/ +[Bb]in/ +[Oo]bj/ +[Ll]og/ +[Ll]ogs/ + +# Visual Studio 2015/2017 cache/options directory +.vs/ +# Uncomment if you have tasks that create the project's static files in wwwroot +#wwwroot/ + +# Visual Studio 2017 auto generated files +Generated\ Files/ + +# MSTest test Results +[Tt]est[Rr]esult*/ +[Bb]uild[Ll]og.* + +# NUnit +*.VisualState.xml +TestResult.xml +nunit-*.xml + +# Build Results of an ATL Project +[Dd]ebugPS/ +[Rr]eleasePS/ +dlldata.c + +# Benchmark Results +BenchmarkDotNet.Artifacts/ + +# .NET Core +project.lock.json +project.fragment.lock.json +artifacts/ + +# ASP.NET Scaffolding +ScaffoldingReadMe.txt + +# StyleCop +StyleCopReport.xml + +# Files built by Visual Studio +*_i.c +*_p.c +*_h.h +*.ilk +*.meta +*.obj +*.iobj +*.pch +*.pdb +*.ipdb +*.pgc +*.pgd +*.rsp +# but not Directory.Build.rsp, as it configures directory-level build defaults +!Directory.Build.rsp +*.sbr +*.tlb +*.tli +*.tlh +*.tmp +*.tmp_proj +*_wpftmp.csproj +*.log +*.tlog +*.vspscc +*.vssscc +.builds +*.pidb +*.svclog +*.scc + +# Chutzpah Test files +_Chutzpah* + +# Visual C++ cache files +ipch/ +*.aps +*.ncb +*.opendb +*.opensdf +*.sdf +*.cachefile +*.VC.db +*.VC.VC.opendb + +# Visual Studio profiler +*.psess +*.vsp +*.vspx +*.sap + +# Visual Studio Trace Files +*.e2e + +# TFS 2012 Local Workspace +$tf/ + +# Guidance Automation Toolkit +*.gpState + +# ReSharper is a .NET coding add-in +_ReSharper*/ +*.[Rr]e[Ss]harper +*.DotSettings.user + +# TeamCity is a build add-in +_TeamCity* + +# DotCover is a Code Coverage Tool +*.dotCover + +# AxoCover is a Code Coverage Tool +.axoCover/* +!.axoCover/settings.json + +# Coverlet is a free, cross platform Code Coverage Tool +coverage*.json +coverage*.xml +coverage*.info + +# Visual Studio code coverage results +*.coverage +*.coveragexml + +# NCrunch +_NCrunch_* +.*crunch*.local.xml +nCrunchTemp_* + +# MightyMoose +*.mm.* +AutoTest.Net/ + +# Web workbench (sass) +.sass-cache/ + +# Installshield output folder +[Ee]xpress/ + +# DocProject is a documentation generator add-in +DocProject/buildhelp/ +DocProject/Help/*.HxT +DocProject/Help/*.HxC +DocProject/Help/*.hhc +DocProject/Help/*.hhk +DocProject/Help/*.hhp +DocProject/Help/Html2 +DocProject/Help/html + +# Click-Once directory +publish/ + +# Publish Web Output +*.[Pp]ublish.xml +*.azurePubxml +# Note: Comment the next line if you want to checkin your web deploy settings, +# but database connection strings (with potential passwords) will be unencrypted +*.pubxml +*.publishproj + +# Microsoft Azure Web App publish settings. Comment the next line if you want to +# checkin your Azure Web App publish settings, but sensitive information contained +# in these scripts will be unencrypted +PublishScripts/ + +# NuGet Packages +*.nupkg +# NuGet Symbol Packages +*.snupkg +# The packages folder can be ignored because of Package Restore +**/[Pp]ackages/* +# except build/, which is used as an MSBuild target. +!**/[Pp]ackages/build/ +# Uncomment if necessary however generally it will be regenerated when needed +#!**/[Pp]ackages/repositories.config +# NuGet v3's project.json files produces more ignorable files +*.nuget.props +*.nuget.targets + +# Microsoft Azure Build Output +csx/ +*.build.csdef + +# Microsoft Azure Emulator +ecf/ +rcf/ + +# Windows Store app package directories and files +AppPackages/ +BundleArtifacts/ +Package.StoreAssociation.xml +_pkginfo.txt +*.appx +*.appxbundle +*.appxupload + +# Visual Studio cache files +# files ending in .cache can be ignored +*.[Cc]ache +# but keep track of directories ending in .cache +!?*.[Cc]ache/ + +# Others +ClientBin/ +~$* +*~ +*.dbmdl +*.dbproj.schemaview +*.jfm +*.pfx +*.publishsettings +orleans.codegen.cs + +# Including strong name files can present a security risk +# (https://github.com/github/gitignore/pull/2483#issue-259490424) +#*.snk + +# Since there are multiple workflows, uncomment next line to ignore bower_components +# (https://github.com/github/gitignore/pull/1529#issuecomment-104372622) +#bower_components/ + +# RIA/Silverlight projects +Generated_Code/ + +# Backup & report files from converting an old project file +# to a newer Visual Studio version. Backup files are not needed, +# because we have git ;-) +_UpgradeReport_Files/ +Backup*/ +UpgradeLog*.XML +UpgradeLog*.htm +ServiceFabricBackup/ +*.rptproj.bak + +# SQL Server files +*.mdf +*.ldf +*.ndf + +# Business Intelligence projects +*.rdl.data +*.bim.layout +*.bim_*.settings +*.rptproj.rsuser +*- [Bb]ackup.rdl +*- [Bb]ackup ([0-9]).rdl +*- [Bb]ackup ([0-9][0-9]).rdl + +# Microsoft Fakes +FakesAssemblies/ + +# GhostDoc plugin setting file +*.GhostDoc.xml + +# Node.js Tools for Visual Studio +.ntvs_analysis.dat +node_modules/ + +# Visual Studio 6 build log +*.plg + +# Visual Studio 6 workspace options file +*.opt + +# Visual Studio 6 auto-generated workspace file (contains which files were open etc.) +*.vbw + +# Visual Studio 6 auto-generated project file (contains which files were open etc.) +*.vbp + +# Visual Studio 6 workspace and project file (working project files containing files to include in project) +*.dsw +*.dsp + +# Visual Studio 6 technical files +*.ncb +*.aps + +# Visual Studio LightSwitch build output +**/*.HTMLClient/GeneratedArtifacts +**/*.DesktopClient/GeneratedArtifacts +**/*.DesktopClient/ModelManifest.xml +**/*.Server/GeneratedArtifacts +**/*.Server/ModelManifest.xml +_Pvt_Extensions + +# Paket dependency manager +.paket/paket.exe +paket-files/ + +# FAKE - F# Make +.fake/ + +# CodeRush personal settings +.cr/personal + +# Python Tools for Visual Studio (PTVS) +__pycache__/ +*.pyc + +# Cake - Uncomment if you are using it +# tools/** +# !tools/packages.config + +# Tabs Studio +*.tss + +# Telerik's JustMock configuration file +*.jmconfig + +# BizTalk build output +*.btp.cs +*.btm.cs +*.odx.cs +*.xsd.cs + +# OpenCover UI analysis results +OpenCover/ + +# Azure Stream Analytics local run output +ASALocalRun/ + +# MSBuild Binary and Structured Log +*.binlog + +# NVidia Nsight GPU debugger configuration file +*.nvuser + +# MFractors (Xamarin productivity tool) working folder +.mfractor/ + +# Local History for Visual Studio +.localhistory/ + +# Visual Studio History (VSHistory) files +.vshistory/ + +# BeatPulse healthcheck temp database +healthchecksdb + +# Backup folder for Package Reference Convert tool in Visual Studio 2017 +MigrationBackup/ + +# Ionide (cross platform F# VS Code tools) working folder +.ionide/ + +# Fody - auto-generated XML schema +FodyWeavers.xsd + +# VS Code files for those working on multiple tools +.vscode/* +!.vscode/settings.json +!.vscode/tasks.json +!.vscode/launch.json +!.vscode/extensions.json +*.code-workspace + +# Local History for Visual Studio Code +.history/ + +# Windows Installer files from build outputs +*.cab +*.msi +*.msix +*.msm +*.msp + +# JetBrains Rider +*.sln.iml + +# BEGIN reset-history environment exclusions +.env +.env.* +*.env +*.env.* +!.env.example +!.env.*.example +!*.env.example +!*.env.*.example +# END reset-history environment exclusions diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..efb9808 --- /dev/null +++ b/LICENSE @@ -0,0 +1,24 @@ +This is free and unencumbered software released into the public domain. + +Anyone is free to copy, modify, publish, use, compile, sell, or +distribute this software, either in source code form or as a compiled +binary, for any purpose, commercial or non-commercial, and by any +means. + +In jurisdictions that recognize copyright laws, the author or authors +of this software dedicate any and all copyright interest in the +software to the public domain. We make this dedication for the benefit +of the public at large and to the detriment of our heirs and +successors. We intend this dedication to be an overt act of +relinquishment in perpetuity of all present and future rights to this +software under copyright law. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. +IN NO EVENT SHALL THE AUTHORS BE LIABLE FOR ANY CLAIM, DAMAGES OR +OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, +ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR +OTHER DEALINGS IN THE SOFTWARE. + +For more information, please refer to diff --git a/README.md b/README.md new file mode 100644 index 0000000..aefb14e --- /dev/null +++ b/README.md @@ -0,0 +1,30 @@ +# Rybbit + +Rybbit is a self-hosted web and product analytics platform backed by ClickHouse +and PostgreSQL. + +## Deployment layout + +- **Compose:** `/srv/docker/rybbit/docker-compose.yml` +- **Static configuration/source:** `/srv/docker/rybbit/clickhouse_config` +- **Non-secret environment:** the public base URL, signup policy, service endpoints, and runtime mode are declared in +Compose; there is no project-local `.env` +- **Secrets:** `/srv/docker/secrets/rybbit/.env` +- **NVMe application state:** `/srv/appdata/rybbit/clickhouse` and `/srv/appdata/rybbit/postgres` +- **Bulk HDD data:** none +- **Other mounts:** none + +Secrets are never committed to this repository. The central secret environment +is supplied to the ClickHouse, PostgreSQL, and backend services and defines +`CLICKHOUSE_DB`, `CLICKHOUSE_USER`, `CLICKHOUSE_PASSWORD`, `POSTGRES_DB`, +`POSTGRES_USER`, `POSTGRES_PASSWORD`, and `BETTER_AUTH_SECRET`. + +## Dependencies and recovery + +- **Networks/dependencies:** the backend depends on healthy ClickHouse and PostgreSQL services, uses the external +`npm_proxy` network at `192.168.98.20`, and shares the private `internal` network with both databases; the client +depends on the backend, uses `npm_proxy` at `192.168.98.21`, and also joins `internal` +- **Back up:** `/srv/appdata/rybbit/clickhouse`, `/srv/appdata/rybbit/postgres`, and the separately protected Rybbit +secret environment +- **Re-creatable:** the four service containers and the project-scoped `internal` network; no persistent cache is +declared diff --git a/clickhouse_config/disable_cgroup_observer.xml b/clickhouse_config/disable_cgroup_observer.xml new file mode 100644 index 0000000..a7868b1 --- /dev/null +++ b/clickhouse_config/disable_cgroup_observer.xml @@ -0,0 +1,3 @@ + + 0 + diff --git a/clickhouse_config/enable_json.xml b/clickhouse_config/enable_json.xml new file mode 100644 index 0000000..c05e767 --- /dev/null +++ b/clickhouse_config/enable_json.xml @@ -0,0 +1,5 @@ + + + 1 + + diff --git a/clickhouse_config/logging_rules.xml b/clickhouse_config/logging_rules.xml new file mode 100644 index 0000000..7ef619f --- /dev/null +++ b/clickhouse_config/logging_rules.xml @@ -0,0 +1,14 @@ + + + error + true + + + + + + + + + + diff --git a/clickhouse_config/network.xml b/clickhouse_config/network.xml new file mode 100644 index 0000000..7eb0a5c --- /dev/null +++ b/clickhouse_config/network.xml @@ -0,0 +1,3 @@ + + 0.0.0.0 + diff --git a/clickhouse_config/user_logging.xml b/clickhouse_config/user_logging.xml new file mode 100644 index 0000000..9a9a1ab --- /dev/null +++ b/clickhouse_config/user_logging.xml @@ -0,0 +1,8 @@ + + + + 0 + 0 + + + diff --git a/docker-compose.yml b/docker-compose.yml new file mode 100644 index 0000000..858442b --- /dev/null +++ b/docker-compose.yml @@ -0,0 +1,91 @@ +services: + rybbit_clickhouse: + mem_limit: 2g + memswap_limit: 3g + container_name: rybbit_clickhouse + image: clickhouse/clickhouse-server:25.4.2 + volumes: + - /srv/appdata/rybbit/clickhouse:/var/lib/clickhouse + - ./clickhouse_config:/etc/clickhouse-server/config.d:ro + env_file: + - /srv/docker/secrets/rybbit/.env + healthcheck: + test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://localhost:8123/ping"] + interval: 3s + timeout: 5s + retries: 5 + start_period: 10s + restart: unless-stopped + networks: + - internal + tmpfs: + - /sys + + rybbit_postgres: + image: postgres:17.4 + container_name: rybbit_postgres + env_file: + - /srv/docker/secrets/rybbit/.env + volumes: + - /srv/appdata/rybbit/postgres:/var/lib/postgresql/data + healthcheck: + test: ["CMD-SHELL", "pg_isready -U $${POSTGRES_USER} -d $${POSTGRES_DB}"] + interval: 3s + timeout: 5s + retries: 5 + start_period: 10s + restart: unless-stopped + networks: + - internal + + rybbit_backend: + mem_limit: 1g + memswap_limit: 1.5g + image: ghcr.io/rybbit-io/rybbit-backend:latest + container_name: rybbit_backend + env_file: + - /srv/docker/secrets/rybbit/.env + environment: + - NODE_ENV=production + - CLICKHOUSE_HOST=http://rybbit_clickhouse:8123 + - POSTGRES_HOST=rybbit_postgres + - POSTGRES_PORT=5432 + - BASE_URL=https://analytics.yoonect.com + - DISABLE_SIGNUP=true + depends_on: + rybbit_clickhouse: + condition: service_healthy + rybbit_postgres: + condition: service_healthy + healthcheck: + test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://127.0.0.1:3001/api/health"] + interval: 3s + timeout: 5s + retries: 5 + start_period: 10s + restart: unless-stopped + networks: + internal: + npm_proxy: + ipv4_address: 192.168.98.20 + + rybbit_client: + image: ghcr.io/rybbit-io/rybbit-client:latest + container_name: rybbit_client + environment: + - NODE_ENV=production + - NEXT_PUBLIC_BACKEND_URL=https://analytics.yoonect.com + - NEXT_PUBLIC_DISABLE_SIGNUP=true + depends_on: + - rybbit_backend + restart: unless-stopped + networks: + internal: + npm_proxy: + ipv4_address: 192.168.98.21 + +networks: + internal: + driver: bridge + npm_proxy: + external: true