forgejo
This commit is contained in:
parent
0eccc75207
commit
5725918a20
3 changed files with 42 additions and 21 deletions
|
|
@ -51,7 +51,6 @@
|
|||
environment.systemPackages = with pkgs; [
|
||||
sbctl
|
||||
];
|
||||
systemd.tmpfiles.rules = [ "d /srv/tftp 0755 root root -" ];
|
||||
services = {
|
||||
logind.settings.Login.HandleLidSwitch = "ignore";
|
||||
nginx = {
|
||||
|
|
|
|||
|
|
@ -1,11 +1,6 @@
|
|||
{ config, pkgs, ... }:
|
||||
{
|
||||
home = {
|
||||
stateVersion = "26.05";
|
||||
packages = with pkgs; [
|
||||
gh
|
||||
];
|
||||
};
|
||||
home.stateVersion = "26.05";
|
||||
services.ssh-agent.enable = true;
|
||||
programs = {
|
||||
home-manager.enable = true;
|
||||
|
|
|
|||
|
|
@ -1,12 +1,23 @@
|
|||
{ config, lib, pkgs, ... }:
|
||||
{
|
||||
imports = [ ../common.nix ./hardware-configuration.nix ];
|
||||
boot.kernelParams = [ "memmap=0x4000%0xbfb76000-4" "memmap=0x4000%0xbfb7a000-4" ];
|
||||
boot.kernelParams = [
|
||||
"consoleblank=30"
|
||||
"memmap=0x4000%0xbfb76000-4"
|
||||
"memmap=0x4000%0xbfb7a000-4"
|
||||
];
|
||||
users = {
|
||||
groups.vmail.gid = 1819;
|
||||
groups = {
|
||||
php = { };
|
||||
vmail.gid = 1819;
|
||||
};
|
||||
users = {
|
||||
nginx.extraGroups = [ "acme" ];
|
||||
root.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow" ];
|
||||
php = {
|
||||
group = "php";
|
||||
isSystemUser = true;
|
||||
};
|
||||
vmail = {
|
||||
uid = 1819;
|
||||
group = "vmail";
|
||||
|
|
@ -71,15 +82,16 @@
|
|||
failures=0
|
||||
else
|
||||
failures=$(($(cat /run/network.failures)+1))
|
||||
fi
|
||||
if [ $failures -gt 0 ]; then
|
||||
echo "<5>failures = $failures"
|
||||
fi
|
||||
if [ $failures -ge 3 ]; then
|
||||
echo "<5>restarting NetworkManager"
|
||||
systemctl restart NetworkManager.service
|
||||
failures=0
|
||||
fi
|
||||
fi
|
||||
echo $failures > /run/network.failures
|
||||
if [ $failures -ge 0 ]; then
|
||||
echo "<5>failures = $failures"
|
||||
fi
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
|
@ -92,9 +104,20 @@
|
|||
settings.PasswordAuthentication = false;
|
||||
};
|
||||
postgresql.enable = true;
|
||||
phpfpm.pools.main = {
|
||||
user = "nginx";
|
||||
group = "nginx";
|
||||
forgejo = {
|
||||
enable = true;
|
||||
database.type = "postgres";
|
||||
settings = {
|
||||
service.DISABLE_REGISTRATION = true;
|
||||
server = {
|
||||
HTTP_PORT = 8039;
|
||||
ROOT_URL = "https://bogaledev.ru/git/";
|
||||
};
|
||||
};
|
||||
};
|
||||
phpfpm.pools.default = {
|
||||
user = "php";
|
||||
group = "php";
|
||||
settings = {
|
||||
"pm" = "ondemand";
|
||||
"pm.max_children" = 8;
|
||||
|
|
@ -109,6 +132,7 @@
|
|||
package = pkgs.vaultwarden-postgresql;
|
||||
environmentFile = "/secrets/vaultwarden.env";
|
||||
config = {
|
||||
ROCKET_PORT = 8032;
|
||||
SIGNUPS_ALLOWED = false;
|
||||
TRASH_AUTO_DELETE_DAYS = 90;
|
||||
PASSWORD_HINTS_ALLOWED = false;
|
||||
|
|
@ -126,16 +150,19 @@
|
|||
locations = {
|
||||
"/".index = "index.php index.html";
|
||||
"~ \\.php$".extraConfig = ''
|
||||
fastcgi_pass unix:${config.services.phpfpm.pools.main.socket};
|
||||
fastcgi_pass unix:${config.services.phpfpm.pools.default.socket};
|
||||
'';
|
||||
"/vw" = {
|
||||
proxyPass = "http://127.0.0.1:8000";
|
||||
"/git/".proxyPass = "http://127.0.0.1:8039/";
|
||||
"/vw/" = {
|
||||
proxyWebsockets = true;
|
||||
proxyPass = "http://127.0.0.1:8032";
|
||||
extraConfig = ''
|
||||
allow fc00::/64;
|
||||
allow fc01::/64;
|
||||
allow fc02::/64;
|
||||
allow 10.0.0.0/24;
|
||||
allow 10.1.0.0/24;
|
||||
allow 10.2.0.0/24;
|
||||
deny all;
|
||||
'';
|
||||
};
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue