diff --git a/production/peertube/docker-compose.yml b/production/peertube/docker-compose.yml new file mode 100644 index 0000000..0a15f96 --- /dev/null +++ b/production/peertube/docker-compose.yml @@ -0,0 +1,61 @@ +version: '2.2' + +services: + peertube: + image: chocobozzz/peertube:production-buster + restart: always + hostname: peertube + container_name: peertube + volumes: + - ./peertube/config/default.yaml:/config/production.yaml:ro + - ./peertube/storage:/app/storage + expose: + - 9000 + cpus: 1 +# cpu_shares: 512 + networks: + mynet: + ipv4_address: 172.115.0.101 + haraka: + + postgres: + image: postgres:11 + hostname: postgres-peertube + container_name: postgres-peertube + restart: always + environment: + - POSTGRES_DB=peertube_dev + - POSTGRES_USER=peertube + - POSTGRES_PASSWORD=p33rtub3. + volumes: + - ./data:/var/lib/postgresql/data + expose: + - 5432 + networks: + mynet: + ipv4_address: 172.115.0.102 + + redis: + image: redis:alpine + hostname: redis-peertube + container_name: redis-peertube + restart: always + volumes: + - ./redis:/data + expose: + - 6379 + networks: + mynet: + ipv4_address: 172.115.0.103 + +networks: + mynet: + driver: bridge + ipam: + config: + - subnet: 172.115.0.0/24 + + haraka: + external: + name: harakawildduck_mynet + diff --git a/production/peertube/peertube/config/custom-environment-variables.yaml b/production/peertube/peertube/config/custom-environment-variables.yaml new file mode 100644 index 0000000..bd4ac12 --- /dev/null +++ b/production/peertube/peertube/config/custom-environment-variables.yaml @@ -0,0 +1,113 @@ +webserver: + hostname: "PEERTUBE_WEBSERVER_HOSTNAME" + port: + __name: "PEERTUBE_WEBSERVER_PORT" + __format: "json" + https: + __name: "PEERTUBE_WEBSERVER_HTTPS" + __format: "json" + +trust_proxy: + __name: "PEERTUBE_TRUST_PROXY" + __format: "json" + +database: + hostname: "PEERTUBE_DB_HOSTNAME" + port: + __name: "PEERTUBE_DB_PORT" + __format: "json" + suffix: "PEERTUBE_DB_SUFFIX" + username: "PEERTUBE_DB_USERNAME" + password: "PEERTUBE_DB_PASSWORD" + +redis: + hostname: "PEERTUBE_REDIS_HOSTNAME" + port: + __name: "PEERTUBE_REDIS_PORT" + __format: "json" + auth: "PEERTUBE_REDIS_AUTH" + +smtp: + hostname: "PEERTUBE_SMTP_HOSTNAME" + port: + __name: "PEERTUBE_SMTP_PORT" + __format: "json" + username: "PEERTUBE_SMTP_USERNAME" + password: "PEERTUBE_SMTP_PASSWORD" + tls: + __name: "PEERTUBE_SMTP_TLS" + __format: "json" + disable_starttls: + __name: "PEERTUBE_SMTP_DISABLE_STARTTLS" + __format: "json" + from_address: "PEERTUBE_SMTP_FROM" + +user: + video_quota: + __name: "PEERTUBE_USER_VIDEO_QUOTA" + __format: "json" + +admin: + email: "PEERTUBE_ADMIN_EMAIL" + +contact_form: + enabled: + __name: "PEERTUBE_CONTACT_FORM_ENABLED" + __format: "json" + +signup: + enabled: + __name: "PEERTUBE_SIGNUP_ENABLED" + __format: "json" + limit: + __name: "PEERTUBE_SIGNUP_LIMIT" + __format: "json" + +search: + remote_uri: + users: + __name: "PEERTUBE_SEARCH_REMOTEURI_USERS" + __format: "json" + anonymous: + __name: "PEERTUBE_SEARCH_REMOTEURI_ANONYMOUS" + __format: "json" + +import: + videos: + http: + enabled: + __name: "PEERTUBE_IMPORT_VIDEOS_HTTP" + __format: "json" + torrent: + enabled: + __name: "PEERTUBE_IMPORT_VIDEOS_TORRENT" + __format: "json" + +transcoding: + enabled: + __name: "PEERTUBE_TRANSCODING_ENABLED" + __format: "json" + threads: + __name: "PEERTUBE_TRANSCODING_THREADS" + __format: "json" + resolutions: + 240p: + __name: "PEERTUBE_TRANSCODING_240P" + __format: "json" + 360p: + __name: "PEERTUBE_TRANSCODING_360P" + __format: "json" + 480p: + __name: "PEERTUBE_TRANSCODING_480P" + __format: "json" + 720p: + __name: "PEERTUBE_TRANSCODING_720P" + __format: "json" + 1080: + __name: "PEERTUBE_TRANSCODING_1080P" + __format: "json" + +instance: + name: "PEERTUBE_INSTANCE_NAME" + description: "PEERTUBE_INSTANCE_DESCRIPTION" + terms: "PEERTUBE_INSTANCE_TERMS" diff --git a/production/peertube/peertube/config/default.yaml b/production/peertube/peertube/config/default.yaml new file mode 100644 index 0000000..96603f3 --- /dev/null +++ b/production/peertube/peertube/config/default.yaml @@ -0,0 +1,247 @@ +# /!\ YOU SHOULD NOT UPDATE THIS FILE, USE production.yaml instead /!\ # + +listen: + hostname: '172.115.0.101' + port: 9000 + +webserver: + https: true + hostname: 'peertube.hatthieves.es' + port: 443 + +rates_limit: + login: + # 15 attempts in 5 min + window: 5 minutes + max: 15 + ask_send_email: + # 3 attempts in 5 min + window: 5 minutes + max: 3 + +# Proxies to trust to get real client IP +# If you run PeerTube just behind a local proxy (nginx), keep 'loopback' +# If you run PeerTube behind a remote proxy, add the proxy IP address (or subnet) +trust_proxy: + - 'loopback' + +# Your database name will be "peertube"+database.suffix +database: + hostname: '172.115.0.102' + port: 5432 + suffix: '_dev' + username: 'peertube' + password: 'p33rtub3.' + pool: + max: 5 + +# You can also specify a 'socket' path to a unix socket but first need to +# comment out hostname and port +redis: + hostname: '172.115.0.103' + port: 6379 + auth: null + db: 0 + +smtp: + hostname: smtp.hatthieves.es + port: 587 + username: peertube@hatthieves.es + password: p33rtub3. + tls: true + disable_starttls: false + ca_file: null # Used for self signed certificates + from_address: 'peertube@hatthieves.es' + +# From the project root directory +storage: + tmp: 'storage/tmp/' # Used to download data (imports etc), store uploaded files before processing... + avatars: 'storage/avatars/' + videos: 'storage/videos/' + streaming_playlists: 'storage/streaming-playlists/' + redundancy: 'storage/redundancy/' + logs: 'storage/logs/' + previews: 'storage/previews/' + thumbnails: 'storage/thumbnails/' + torrents: 'storage/torrents/' + captions: 'storage/captions/' + cache: 'storage/cache/' + +log: + level: 'info' # debug/info/warning/error + +search: + # Add ability to fetch remote videos/actors by their URI, that may not be federated with your instance + # If enabled, the associated group will be able to "escape" from the instance follows + # That means they will be able to follow channels, watch videos, list videos of non followed instances + remote_uri: + users: true + anonymous: false + +trending: + videos: + interval_days: 7 # Compute trending videos for the last x days + +# Cache remote videos on your server, to help other instances to broadcast the video +# You can define multiple caches using different sizes/strategies +# Once you have defined your strategies, choose which instances you want to cache in admin -> manage follows -> following +redundancy: + videos: + check_interval: '1 hour' # How often you want to check new videos to cache + strategies: # Just uncomment strategies you want +# - +# size: '10GB' +# # Minimum time the video must remain in the cache. Only accept values > 10 hours (to not overload remote instances) +# min_lifetime: '48 hours' +# strategy: 'most-views' # Cache videos that have the most views +# - +# size: '10GB' +# # Minimum time the video must remain in the cache. Only accept values > 10 hours (to not overload remote instances) +# min_lifetime: '48 hours' +# strategy: 'trending' # Cache trending videos +# - +# size: '10GB' +# # Minimum time the video must remain in the cache. Only accept values > 10 hours (to not overload remote instances) +# min_lifetime: '48 hours' +# strategy: 'recently-added' # Cache recently added videos +# min_views: 10 # Having at least x views + +csp: + enabled: false + report_only: true # CSP directives are still being tested, so disable the report only mode at your own risk! + report_uri: + +tracker: + # If you disable the tracker, you disable the P2P aspect of PeerTube + enabled: true + # Only handle requests on your videos. + # If you set this to false it means you have a public tracker. + # Then, it is possible that clients overload your instance with external torrents + private: true + # Reject peers that do a lot of announces (could improve privacy of TCP/UDP peers) + reject_too_many_announces: false + +history: + videos: + # If you want to limit users videos history + # -1 means there is no limitations + # Other values could be '6 months' or '30 days' etc (PeerTube will periodically delete old entries from database) + max_age: -1 + +views: + videos: + # PeerTube creates a database entry every hour for each video to track views over a period of time + # This is used in particular by the Trending page + # PeerTube could remove old remote video views if you want to reduce your database size (video view counter will not be altered) + # -1 means no cleanup + # Other values could be '6 months' or '30 days' etc (PeerTube will periodically delete old entries from database) + remote: + max_age: -1 + +cache: + previews: + size: 500 # Max number of previews you want to cache + captions: + size: 500 # Max number of video captions/subtitles you want to cache + +admin: + # Used to generate the root user at first startup + # And to receive emails from the contact form + email: 'webmaster@hatthieves.es' + +contact_form: + enabled: true + +signup: + enabled: false + limit: 10 # When the limit is reached, registrations are disabled. -1 == unlimited + requires_email_verification: true + filters: + cidr: # You can specify CIDR ranges to whitelist (empty = no filtering) or blacklist + whitelist: [] + blacklist: [] + +user: + # Default value of maximum video BYTES the user can upload (does not take into account transcoded files). + # -1 == unlimited + video_quota: -1 + video_quota_daily: -1 + +# If enabled, the video will be transcoded to mp4 (x264) with "faststart" flag +# In addition, if some resolutions are enabled the mp4 video file will be transcoded to these new resolutions. +# Please, do not disable transcoding since many uploaded videos will not work +transcoding: + enabled: true + # Allow your users to upload .mkv, .mov, .avi, .flv videos + allow_additional_extensions: true + threads: 1 + resolutions: # Only created if the original video has a higher resolution, uses more storage! + 240p: false + 360p: false + 480p: false + 720p: false + 1080p: false + # /!\ EXPERIMENTAL /!\ + # /!\ Requires ffmpeg >= 4 + # Generate HLS playlists and fragmented MP4 files. Better playback than with WebTorrent: + # * Resolution change is smoother + # * Faster playback in particular with long videos + # * More stable playback (less bugs/infinite loading) + # /!\ Multiplies videos storage by 2 /!\ + hls: + enabled: false + +import: + # Add ability for your users to import remote videos (from YouTube, torrent...) + videos: + http: # Classic HTTP or all sites supported by youtube-dl https://rg3.github.io/youtube-dl/supportedsites.html + enabled: true + torrent: # Magnet URI or torrent file (use classic TCP/UDP/WebSeed to download the file) + enabled: true + +auto_blacklist: + # New videos automatically blacklisted so moderators can review before publishing + videos: + of_users: + enabled: false + +instance: + name: 'HatThieves/PeerTube' + short_description: 'PeerTube, a federated (ActivityPub) video streaming platform using P2P (BitTorrent) directly in the web browser with WebTorrent and Angular.' + description: 'Welcome to this PeerTube instance!' # Support markdown + terms: 'No terms for now.' # Support markdown + default_client_route: '/videos/trending' + # Whether or not the instance is dedicated to NSFW content + # Enabling it will allow other administrators to know that you are mainly federating sensitive content + # Moreover, the NSFW checkbox on video upload will be automatically checked by default + is_nsfw: false + # By default, "do_not_list" or "blur" or "display" NSFW videos + # Could be overridden per user with a setting + default_nsfw_policy: 'do_not_list' + customizations: + javascript: '' # Directly your JavaScript code (without