This commit is contained in:
bogale 2026-09-23 11:28:13 +09:00
commit 5725918a20
3 changed files with 42 additions and 21 deletions

View file

@ -51,7 +51,6 @@
environment.systemPackages = with pkgs; [ environment.systemPackages = with pkgs; [
sbctl sbctl
]; ];
systemd.tmpfiles.rules = [ "d /srv/tftp 0755 root root -" ];
services = { services = {
logind.settings.Login.HandleLidSwitch = "ignore"; logind.settings.Login.HandleLidSwitch = "ignore";
nginx = { nginx = {

View file

@ -1,11 +1,6 @@
{ config, pkgs, ... }: { config, pkgs, ... }:
{ {
home = { home.stateVersion = "26.05";
stateVersion = "26.05";
packages = with pkgs; [
gh
];
};
services.ssh-agent.enable = true; services.ssh-agent.enable = true;
programs = { programs = {
home-manager.enable = true; home-manager.enable = true;

View file

@ -1,12 +1,23 @@
{ config, lib, pkgs, ... }: { config, lib, pkgs, ... }:
{ {
imports = [ ../common.nix ./hardware-configuration.nix ]; imports = [ ../common.nix ./hardware-configuration.nix ];
boot.kernelParams = [ "memmap=0x4000%0xbfb76000-4" "memmap=0x4000%0xbfb7a000-4" ]; boot.kernelParams = [
"consoleblank=30"
"memmap=0x4000%0xbfb76000-4"
"memmap=0x4000%0xbfb7a000-4"
];
users = { users = {
groups.vmail.gid = 1819; groups = {
php = { };
vmail.gid = 1819;
};
users = { users = {
nginx.extraGroups = [ "acme" ]; nginx.extraGroups = [ "acme" ];
root.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow" ]; root.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow" ];
php = {
group = "php";
isSystemUser = true;
};
vmail = { vmail = {
uid = 1819; uid = 1819;
group = "vmail"; group = "vmail";
@ -71,15 +82,16 @@
failures=0 failures=0
else else
failures=$(($(cat /run/network.failures)+1)) failures=$(($(cat /run/network.failures)+1))
fi
if [ $failures -gt 0 ]; then
echo "<5>failures = $failures"
fi
if [ $failures -ge 3 ]; then if [ $failures -ge 3 ]; then
echo "<5>restarting NetworkManager"
systemctl restart NetworkManager.service systemctl restart NetworkManager.service
failures=0 failures=0
fi fi
fi
echo $failures > /run/network.failures echo $failures > /run/network.failures
if [ $failures -ge 0 ]; then
echo "<5>failures = $failures"
fi
''; '';
}; };
}; };
@ -92,9 +104,20 @@
settings.PasswordAuthentication = false; settings.PasswordAuthentication = false;
}; };
postgresql.enable = true; postgresql.enable = true;
phpfpm.pools.main = { forgejo = {
user = "nginx"; enable = true;
group = "nginx"; database.type = "postgres";
settings = {
service.DISABLE_REGISTRATION = true;
server = {
HTTP_PORT = 8039;
ROOT_URL = "https://bogaledev.ru/git/";
};
};
};
phpfpm.pools.default = {
user = "php";
group = "php";
settings = { settings = {
"pm" = "ondemand"; "pm" = "ondemand";
"pm.max_children" = 8; "pm.max_children" = 8;
@ -109,6 +132,7 @@
package = pkgs.vaultwarden-postgresql; package = pkgs.vaultwarden-postgresql;
environmentFile = "/secrets/vaultwarden.env"; environmentFile = "/secrets/vaultwarden.env";
config = { config = {
ROCKET_PORT = 8032;
SIGNUPS_ALLOWED = false; SIGNUPS_ALLOWED = false;
TRASH_AUTO_DELETE_DAYS = 90; TRASH_AUTO_DELETE_DAYS = 90;
PASSWORD_HINTS_ALLOWED = false; PASSWORD_HINTS_ALLOWED = false;
@ -126,16 +150,19 @@
locations = { locations = {
"/".index = "index.php index.html"; "/".index = "index.php index.html";
"~ \\.php$".extraConfig = '' "~ \\.php$".extraConfig = ''
fastcgi_pass unix:${config.services.phpfpm.pools.main.socket}; fastcgi_pass unix:${config.services.phpfpm.pools.default.socket};
''; '';
"/vw" = { "/git/".proxyPass = "http://127.0.0.1:8039/";
proxyPass = "http://127.0.0.1:8000"; "/vw/" = {
proxyWebsockets = true; proxyWebsockets = true;
proxyPass = "http://127.0.0.1:8032";
extraConfig = '' extraConfig = ''
allow fc00::/64; allow fc00::/64;
allow fc01::/64; allow fc01::/64;
allow fc02::/64;
allow 10.0.0.0/24; allow 10.0.0.0/24;
allow 10.1.0.0/24; allow 10.1.0.0/24;
allow 10.2.0.0/24;
deny all; deny all;
''; '';
}; };