chore: retire the per-client domain setup (plan step 9); addresses → bonamin.net

- remove setup-ssl.sh (mkcert IP certs) - superseded by install.sh's
  self-signed cert and the backend-managed TLS identity
- manager: "Waiter Domain (παλιό σύστημα)" - shown only for sites that
  still have one
- .env.example: REGISTRY=registry.bonamin.net and
  CLOUD_URL=https://xenia-api.bonamin.net (it pointed at the admin panel,
  xenia-admin, even before the domain move); install.sh points to the
  sysadmin panel at xenia-admin.bonamin.net
- pack README registry example updated
Proxy config unchanged (HTTPS domain blocks stay so not-yet-migrated sites
keep working until their visit).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-28 19:06:45 +03:00
co-authored by Claude Opus 5.5
parent d82a254cdb
commit 251cac9807
5 changed files with 6 additions and 72 deletions
+2 -2
View File
@@ -1,11 +1,11 @@
# Registry
REGISTRY=registry.bonamin.gr
REGISTRY=registry.bonamin.net
VERSION=0.1.0
# Backend runtime secrets (get SITE_ID and SITE_KEY from the sysadmin panel)
SITE_ID=your-site-id
SITE_KEY=your-site-key
CLOUD_URL=https://xenia-admin.bonamin.gr
CLOUD_URL=https://xenia-api.bonamin.net
SECRET_KEY=generate-with-openssl-rand-hex-32
LICENSE_GRACE_HOURS=24
+1 -1
View File
@@ -101,7 +101,7 @@ cd waiter_pwa; npm run lint
# Build release images (VERSION comes from .env). See the parent's DEPLOYMENT_GUIDE.md.
docker compose -f docker-compose.yml -f docker-compose.dev.yml build
docker push registry.bonamin.gr/pos-backend:<ver> # + pos-waiter, pos-manager
docker push registry.bonamin.net/pos-backend:<ver> # + pos-waiter, pos-manager
```
## Native Android app (waiter_pwa)
+1 -1
View File
@@ -61,7 +61,7 @@ if [ ! -f "$SCRIPT_DIR/.env" ]; then
echo " A .env file has been created from .env.example."
echo " You must fill in SITE_ID, SITE_KEY, and SECRET_KEY before starting."
echo ""
echo " Get SITE_ID and SITE_KEY from: https://xenia-admin.bonamin.gr"
echo " Get SITE_ID and SITE_KEY from: https://xenia-admin.bonamin.net"
echo " Generate SECRET_KEY with: openssl rand -hex 32"
echo ""
@@ -557,7 +557,8 @@ export default function AppInfoTab() {
)}
{status?.waiter_domain && (
<>
<div className="text-gray-500">Waiter Domain</div>
{/* Retired per-client domain setup (plan step 9): shown only for sites that still have one */}
<div className="text-gray-500">Waiter Domain (παλιό σύστημα)</div>
<div className="flex items-center gap-2 flex-wrap">
<span className="font-medium text-gray-800 text-xs font-mono break-all">{status.waiter_domain}</span>
<button
-67
View File
@@ -1,67 +0,0 @@
#!/bin/bash
# Run this once on the server machine to generate SSL certificates.
# Requires mkcert: https://github.com/FiloSottile/mkcert
#
# After running this script, install the CA on each device that needs
# to access the system (phones, tablets, other PCs).
#
# Usage: bash setup-ssl.sh [SERVER_IP]
# Example: bash setup-ssl.sh 192.168.1.50
set -e
SERVER_IP="${1:-$(hostname -I | awk '{print $1}')}"
CERT_DIR="$(dirname "$0")/certs"
echo "Setting up SSL for IP: $SERVER_IP"
echo "Certificates will be saved to: $CERT_DIR"
# Install mkcert if not present
if ! command -v mkcert &> /dev/null; then
echo "Installing mkcert..."
if command -v apt-get &> /dev/null; then
sudo apt-get update -q && sudo apt-get install -y mkcert libnss3-tools
elif command -v brew &> /dev/null; then
brew install mkcert nss
else
echo "ERROR: Please install mkcert manually: https://github.com/FiloSottile/mkcert"
exit 1
fi
fi
# Install the local CA (makes this machine trust its own certs)
mkcert -install
# Generate the certificate for this machine's IP (and localhost for dev)
mkdir -p "$CERT_DIR"
mkcert \
-cert-file "$CERT_DIR/cert.pem" \
-key-file "$CERT_DIR/key.pem" \
"$SERVER_IP" \
"localhost" \
"127.0.0.1"
echo ""
echo "Done! Certificates saved to $CERT_DIR"
echo ""
echo "======================================================"
echo " NEXT STEP: Install the CA on each device"
echo "======================================================"
echo ""
echo "The CA certificate is at:"
mkcert -CAROOT
echo ""
echo "On Android phones:"
echo " 1. Copy the 'rootCA.pem' file from the path above to the phone"
echo " 2. Settings > Security > Install certificate > CA certificate"
echo " 3. Select the rootCA.pem file"
echo ""
echo "On Windows PCs:"
echo " 1. Copy rootCA.pem and rename to rootCA.crt"
echo " 2. Double-click it > Install Certificate > Local Machine"
echo " 3. Place in: Trusted Root Certification Authorities"
echo ""
echo "The apps will then be accessible at:"
echo " Waiter PWA: https://$SERVER_IP"
echo " Manager Dashboard: https://$SERVER_IP:4443"
echo "======================================================"