forgejo
This commit is contained in:
parent
0eccc75207
commit
5725918a20
3 changed files with 42 additions and 21 deletions
|
|
@ -51,7 +51,6 @@
|
||||||
environment.systemPackages = with pkgs; [
|
environment.systemPackages = with pkgs; [
|
||||||
sbctl
|
sbctl
|
||||||
];
|
];
|
||||||
systemd.tmpfiles.rules = [ "d /srv/tftp 0755 root root -" ];
|
|
||||||
services = {
|
services = {
|
||||||
logind.settings.Login.HandleLidSwitch = "ignore";
|
logind.settings.Login.HandleLidSwitch = "ignore";
|
||||||
nginx = {
|
nginx = {
|
||||||
|
|
|
||||||
|
|
@ -1,11 +1,6 @@
|
||||||
{ config, pkgs, ... }:
|
{ config, pkgs, ... }:
|
||||||
{
|
{
|
||||||
home = {
|
home.stateVersion = "26.05";
|
||||||
stateVersion = "26.05";
|
|
||||||
packages = with pkgs; [
|
|
||||||
gh
|
|
||||||
];
|
|
||||||
};
|
|
||||||
services.ssh-agent.enable = true;
|
services.ssh-agent.enable = true;
|
||||||
programs = {
|
programs = {
|
||||||
home-manager.enable = true;
|
home-manager.enable = true;
|
||||||
|
|
|
||||||
|
|
@ -1,12 +1,23 @@
|
||||||
{ config, lib, pkgs, ... }:
|
{ config, lib, pkgs, ... }:
|
||||||
{
|
{
|
||||||
imports = [ ../common.nix ./hardware-configuration.nix ];
|
imports = [ ../common.nix ./hardware-configuration.nix ];
|
||||||
boot.kernelParams = [ "memmap=0x4000%0xbfb76000-4" "memmap=0x4000%0xbfb7a000-4" ];
|
boot.kernelParams = [
|
||||||
|
"consoleblank=30"
|
||||||
|
"memmap=0x4000%0xbfb76000-4"
|
||||||
|
"memmap=0x4000%0xbfb7a000-4"
|
||||||
|
];
|
||||||
users = {
|
users = {
|
||||||
groups.vmail.gid = 1819;
|
groups = {
|
||||||
|
php = { };
|
||||||
|
vmail.gid = 1819;
|
||||||
|
};
|
||||||
users = {
|
users = {
|
||||||
nginx.extraGroups = [ "acme" ];
|
nginx.extraGroups = [ "acme" ];
|
||||||
root.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow" ];
|
root.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow" ];
|
||||||
|
php = {
|
||||||
|
group = "php";
|
||||||
|
isSystemUser = true;
|
||||||
|
};
|
||||||
vmail = {
|
vmail = {
|
||||||
uid = 1819;
|
uid = 1819;
|
||||||
group = "vmail";
|
group = "vmail";
|
||||||
|
|
@ -71,15 +82,16 @@
|
||||||
failures=0
|
failures=0
|
||||||
else
|
else
|
||||||
failures=$(($(cat /run/network.failures)+1))
|
failures=$(($(cat /run/network.failures)+1))
|
||||||
if [ $failures -ge 3 ]; then
|
|
||||||
systemctl restart NetworkManager.service
|
|
||||||
failures=0
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
echo $failures > /run/network.failures
|
if [ $failures -gt 0 ]; then
|
||||||
if [ $failures -ge 0 ]; then
|
|
||||||
echo "<5>failures = $failures"
|
echo "<5>failures = $failures"
|
||||||
fi
|
fi
|
||||||
|
if [ $failures -ge 3 ]; then
|
||||||
|
echo "<5>restarting NetworkManager"
|
||||||
|
systemctl restart NetworkManager.service
|
||||||
|
failures=0
|
||||||
|
fi
|
||||||
|
echo $failures > /run/network.failures
|
||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
@ -92,9 +104,20 @@
|
||||||
settings.PasswordAuthentication = false;
|
settings.PasswordAuthentication = false;
|
||||||
};
|
};
|
||||||
postgresql.enable = true;
|
postgresql.enable = true;
|
||||||
phpfpm.pools.main = {
|
forgejo = {
|
||||||
user = "nginx";
|
enable = true;
|
||||||
group = "nginx";
|
database.type = "postgres";
|
||||||
|
settings = {
|
||||||
|
service.DISABLE_REGISTRATION = true;
|
||||||
|
server = {
|
||||||
|
HTTP_PORT = 8039;
|
||||||
|
ROOT_URL = "https://bogaledev.ru/git/";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
phpfpm.pools.default = {
|
||||||
|
user = "php";
|
||||||
|
group = "php";
|
||||||
settings = {
|
settings = {
|
||||||
"pm" = "ondemand";
|
"pm" = "ondemand";
|
||||||
"pm.max_children" = 8;
|
"pm.max_children" = 8;
|
||||||
|
|
@ -109,6 +132,7 @@
|
||||||
package = pkgs.vaultwarden-postgresql;
|
package = pkgs.vaultwarden-postgresql;
|
||||||
environmentFile = "/secrets/vaultwarden.env";
|
environmentFile = "/secrets/vaultwarden.env";
|
||||||
config = {
|
config = {
|
||||||
|
ROCKET_PORT = 8032;
|
||||||
SIGNUPS_ALLOWED = false;
|
SIGNUPS_ALLOWED = false;
|
||||||
TRASH_AUTO_DELETE_DAYS = 90;
|
TRASH_AUTO_DELETE_DAYS = 90;
|
||||||
PASSWORD_HINTS_ALLOWED = false;
|
PASSWORD_HINTS_ALLOWED = false;
|
||||||
|
|
@ -126,16 +150,19 @@
|
||||||
locations = {
|
locations = {
|
||||||
"/".index = "index.php index.html";
|
"/".index = "index.php index.html";
|
||||||
"~ \\.php$".extraConfig = ''
|
"~ \\.php$".extraConfig = ''
|
||||||
fastcgi_pass unix:${config.services.phpfpm.pools.main.socket};
|
fastcgi_pass unix:${config.services.phpfpm.pools.default.socket};
|
||||||
'';
|
'';
|
||||||
"/vw" = {
|
"/git/".proxyPass = "http://127.0.0.1:8039/";
|
||||||
proxyPass = "http://127.0.0.1:8000";
|
"/vw/" = {
|
||||||
proxyWebsockets = true;
|
proxyWebsockets = true;
|
||||||
|
proxyPass = "http://127.0.0.1:8032";
|
||||||
extraConfig = ''
|
extraConfig = ''
|
||||||
allow fc00::/64;
|
allow fc00::/64;
|
||||||
allow fc01::/64;
|
allow fc01::/64;
|
||||||
|
allow fc02::/64;
|
||||||
allow 10.0.0.0/24;
|
allow 10.0.0.0/24;
|
||||||
allow 10.1.0.0/24;
|
allow 10.1.0.0/24;
|
||||||
|
allow 10.2.0.0/24;
|
||||||
deny all;
|
deny all;
|
||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue