haproxy

Direct /postdeploy to the webhook container, POST only Direct / to the wiki container, GET, HEAD only

certbot

Run manually once with an ansble 'creates' directive via docker, mounting /etc/letsencrypt. Spec –cert-name to 'this' so we don't have to hard code domains in the scripts

Wiki

Push to dockerhub Filter everything except GET at haproxy with the appropriate acl Mount the /var/run/repos/wiki dir at /wiki

webmisc

Dunno.

DO

createdroplet -t permanent -t wiki -i centos-7-x64 -r lon1 -n wiki-lon1