From 5725918a201f6a50f6acd3bcd1640ad6776919a3 Mon Sep 17 00:00:00 2001 From: bogale Date: Wed, 23 Sep 2026 11:28:13 +0900 Subject: [PATCH] forgejo --- common.nix | 1 - home/common.nix | 7 +---- server/configuration.nix | 55 ++++++++++++++++++++++++++++++---------- 3 files changed, 42 insertions(+), 21 deletions(-) diff --git a/common.nix b/common.nix index ce72039..9f3d29d 100644 --- a/common.nix +++ b/common.nix @@ -51,7 +51,6 @@ environment.systemPackages = with pkgs; [ sbctl ]; - systemd.tmpfiles.rules = [ "d /srv/tftp 0755 root root -" ]; services = { logind.settings.Login.HandleLidSwitch = "ignore"; nginx = { diff --git a/home/common.nix b/home/common.nix index c3730c0..113d1dc 100644 --- a/home/common.nix +++ b/home/common.nix @@ -1,11 +1,6 @@ { config, pkgs, ... }: { - home = { - stateVersion = "26.05"; - packages = with pkgs; [ - gh - ]; - }; + home.stateVersion = "26.05"; services.ssh-agent.enable = true; programs = { home-manager.enable = true; diff --git a/server/configuration.nix b/server/configuration.nix index a3d924a..ca52c6e 100644 --- a/server/configuration.nix +++ b/server/configuration.nix @@ -1,12 +1,23 @@ { config, lib, pkgs, ... }: { imports = [ ../common.nix ./hardware-configuration.nix ]; - boot.kernelParams = [ "memmap=0x4000%0xbfb76000-4" "memmap=0x4000%0xbfb7a000-4" ]; + boot.kernelParams = [ + "consoleblank=30" + "memmap=0x4000%0xbfb76000-4" + "memmap=0x4000%0xbfb7a000-4" + ]; users = { - groups.vmail.gid = 1819; + groups = { + php = { }; + vmail.gid = 1819; + }; users = { nginx.extraGroups = [ "acme" ]; root.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow" ]; + php = { + group = "php"; + isSystemUser = true; + }; vmail = { uid = 1819; group = "vmail"; @@ -71,15 +82,16 @@ failures=0 else failures=$(($(cat /run/network.failures)+1)) - if [ $failures -ge 3 ]; then - systemctl restart NetworkManager.service - failures=0 - fi fi - echo $failures > /run/network.failures - if [ $failures -ge 0 ]; then + if [ $failures -gt 0 ]; then echo "<5>failures = $failures" fi + if [ $failures -ge 3 ]; then + echo "<5>restarting NetworkManager" + systemctl restart NetworkManager.service + failures=0 + fi + echo $failures > /run/network.failures ''; }; }; @@ -92,9 +104,20 @@ settings.PasswordAuthentication = false; }; postgresql.enable = true; - phpfpm.pools.main = { - user = "nginx"; - group = "nginx"; + forgejo = { + enable = true; + database.type = "postgres"; + settings = { + service.DISABLE_REGISTRATION = true; + server = { + HTTP_PORT = 8039; + ROOT_URL = "https://bogaledev.ru/git/"; + }; + }; + }; + phpfpm.pools.default = { + user = "php"; + group = "php"; settings = { "pm" = "ondemand"; "pm.max_children" = 8; @@ -109,6 +132,7 @@ package = pkgs.vaultwarden-postgresql; environmentFile = "/secrets/vaultwarden.env"; config = { + ROCKET_PORT = 8032; SIGNUPS_ALLOWED = false; TRASH_AUTO_DELETE_DAYS = 90; PASSWORD_HINTS_ALLOWED = false; @@ -126,16 +150,19 @@ locations = { "/".index = "index.php index.html"; "~ \\.php$".extraConfig = '' - fastcgi_pass unix:${config.services.phpfpm.pools.main.socket}; + fastcgi_pass unix:${config.services.phpfpm.pools.default.socket}; ''; - "/vw" = { - proxyPass = "http://127.0.0.1:8000"; + "/git/".proxyPass = "http://127.0.0.1:8039/"; + "/vw/" = { proxyWebsockets = true; + proxyPass = "http://127.0.0.1:8032"; extraConfig = '' allow fc00::/64; allow fc01::/64; + allow fc02::/64; allow 10.0.0.0/24; allow 10.1.0.0/24; + allow 10.2.0.0/24; deny all; ''; };