diff --git a/projects/timapta.md b/projects/timapta.md new file mode 100644 index 0000000..2e07d2f --- /dev/null +++ b/projects/timapta.md @@ -0,0 +1,97 @@ +# TIMAPTA — Tybee Island Maritime Academy PTA + +**Project owner:** Greyson's mom (PTA project) +**Status:** LIVE (initial deployment) +**Deployed:** 2026-08-12 + +## Summary + +Public-facing website + email for the newly formed Tybee Island Maritime Academy +PTA. Domains `timapta.org` and `ptatima.org` registered at Cloudflare. `timapta.org` +serves the site from app3 (nginx); `ptatima.org` 301-forwards to it. Email runs on +MXroute with branded `mail.` and `webmail.` subdomains. + +## Domain & DNS (Cloudflare) + +| Record | Type | Value | Purpose | +|---|---|---|---| +| `timapta.org` | A | 152.53.241.111 | app3 site (grey-cloud) | +| `www.timapta.org` | A | 152.53.241.111 | app3 site | +| `ptatima.org` | A (proxied) + Page Rule | 301 → `https://timapta.org/$1` | forward | +| `www.ptatima.org` | A (proxied) + Page Rule | 301 → `https://timapta.org/$1` | forward | +| `mail.timapta.org` | CNAME | heracles.mxrouting.net | IMAP/SMTP hostname | +| `webmail.timapta.org` | A | 152.53.192.33 (Core) | Caddy 302 → Roundcube | + +Cloudflare zone IDs: +- timapta.org: `92d1512d07b72142551aa5306fbacb2a` +- ptatima.org: `fe443f33606d319a35eeb473403371fe` + +## Email (MXroute) + +- **Server:** heracles.mxrouting.net (DirectAdmin API :2222) +- **Domain added:** timapta.org (via verification TXT `_da-verify-3ab1b283c7c6bb0074352d3264ede51a` → `domain-verified`) +- **Mailbox:** `contact@timapta.org` (quota 500 MB) + +DNS records created in Cloudflare: + +| Record | Type | Name | Value | +|---|---|---|---| +| MX 10 | MX | `timapta.org` | heracles.mxrouting.net | +| MX 20 | MX | `timapta.org` | heracles-relay.mxrouting.net | +| SPF | TXT | `timapta.org` | `v=spf1 include:mxroute.com -all` | +| DKIM | TXT | `x._domainkey.timapta.org` | `v=DKIM1; k=rsa; p=...` (410-char key) | +| DMARC | TXT | `_dmarc.timapta.org` | `v=DMARC1; p=none; rua=mailto:contact@timapta.org` | + +**Credentials:** +- `contact@timapta.org` password: stored at `/root/timapta-contact-pass.txt` + (`IQrZwW0YpaLQlwOuGLcY`) — pending move to Vaultwarden. + +## Website (app3, nginx) + +- **Docroot:** `/home/ippadmin/htdocs/timapta.org/` +- **nginx config:** `/etc/nginx/sites-available/timapta.org.conf` (symlinked into sites-enabled) +- **SSL:** Let's Encrypt (certbot webroot), `timapta.org` + `www.timapta.org`, expires 2026-11-10, auto-renew +- **Structure:** HTTP + `www` → 301 to `https://timapta.org/`; apex serves static files + +Site files: +- `index.html` — landing page (mission, membership/volunteer/fundraising/events cards, contact form) +- `assets/logo.svg` — vector emblem (sun, waves, lighthouse, sand + TIMAPTA wordmark) +- `assets/logo.png` — raster copy (512x512) + +## Contact Form + +- Uses FormSubmit.co (`https://formsubmit.co/contact@timapta.org`), POST, table template, no captcha. +- **Activation required:** the first real submission triggers a confirmation email to + `contact@timapta.org`. Someone must click the link once to activate the endpoint. +- Alternative (unused): native mailto link in footer. + +## PTA Functionality Research (summary) + +Standard public-facing PTA sites include: mission/vision statement, membership join +call-to-action, volunteer signup, fundraising drives/events, event calendar, +teacher-appreciation programs, board/leadership roster, contact form. Built the +foundation with mission + four capability cards + contact form; calendar, membership +dues, and leadership roster are natural next additions once the board provides +real names, meeting schedule, and a phone/address. + +## Open Items / Next Steps + +- [ ] Move `contact@timapta.org` password into Vaultwarden +- [ ] Activate FormSubmit endpoint (first submission + click confirmation) +- [ ] Add real phone number + mailing address once PTA provides them +- [ ] Add board/leadership roster + event calendar when available +- [ ] Replace placeholder logo if the PTA commissions branded artwork + +## Notes / Pitfalls + +- app3 uses nginx (CloudPanel layout, per-user `/home//htdocs` docroots), NOT + Caddy. Caddy only runs on Core (152.53.192.33), which is why the webmail redirect + lives there. +- `ptatima.org` forward required a proxied dummy A record so the Cloudflare Page Rule + can intercept before routing. +- MXroute domain-add requires a `_da-verify-*` TXT record; the add fails until that + TXT is propagated (checked via `dig @1.1.1.1`). +- DKIM key arrives split across quoted lines from `CMD_API_DNS_CONTROL`; concatenate + all quoted strings into one unbroken value. +- Caddyfile global block must remain first; insert new site blocks after it (anchor on + an existing `# -- ... --` comment), not at line 1.