forgejo prod: email verification, ssh keys
This commit is contained in:
parent
41a59e7d5c
commit
b970685e0e
2 changed files with 41 additions and 26 deletions
|
|
@ -27,19 +27,6 @@
|
|||
ensureDBOwnership = true;
|
||||
} ];
|
||||
};
|
||||
forgejo = {
|
||||
enable = true;
|
||||
database.type = "postgres";
|
||||
dump = {
|
||||
enable = true;
|
||||
type = "tar.zst";
|
||||
};
|
||||
settings.server = {
|
||||
SSH_PORT = 2235;
|
||||
HTTP_PORT = 8039;
|
||||
ROOT_URL = "https://bogaledev.ru/git/";
|
||||
};
|
||||
};
|
||||
phpfpm.pools.php = {
|
||||
user = "php";
|
||||
group = "php";
|
||||
|
|
@ -58,7 +45,7 @@
|
|||
package = pkgs.vaultwarden-postgresql;
|
||||
environmentFile = "/secrets/vw-token.env";
|
||||
config = {
|
||||
ROCKET_PORT = 8032;
|
||||
ROCKET_PORT = 46151;
|
||||
SIGNUPS_ALLOWED = false;
|
||||
TRASH_AUTO_DELETE_DAYS = 90;
|
||||
PASSWORD_HINTS_ALLOWED = false;
|
||||
|
|
@ -66,6 +53,32 @@
|
|||
DOMAIN = "https://bogaledev.ru/vw/";
|
||||
};
|
||||
};
|
||||
forgejo = {
|
||||
enable = true;
|
||||
database.type = "postgres";
|
||||
dump = {
|
||||
enable = true;
|
||||
type = "tar.zst";
|
||||
};
|
||||
settings = {
|
||||
service = {
|
||||
ENABLE_CAPTCHA = true;
|
||||
REGISTER_EMAIL_CONFIRM = true;
|
||||
};
|
||||
server = {
|
||||
SSH_PORT = 32831;
|
||||
PROTOCOL = "http+unix";
|
||||
ROOT_URL = "https://bogaledev.ru/git/";
|
||||
HTTP_ADDR = "/run/forgejo/forgejo.sock";
|
||||
};
|
||||
mailer = {
|
||||
ENABLED = true;
|
||||
SMTP_PORT = 25;
|
||||
SMTP_ADDR = "localhost";
|
||||
FROM = "Forgejo <forgejo@bogaledev.ru>";
|
||||
};
|
||||
};
|
||||
};
|
||||
nginx.virtualHosts."bogaledev.ru" = let
|
||||
phpPool = ''
|
||||
index index.php index.html;
|
||||
|
|
@ -92,8 +105,8 @@
|
|||
'';
|
||||
locations = {
|
||||
"/".extraConfig = phpPool;
|
||||
"/git/".proxyPass = "http://127.0.0.1:8039/";
|
||||
"/local/".extraConfig = "${phpPool} ${localNetworks}";
|
||||
"/git/".proxyPass = "http://unix:/run/forgejo/forgejo.sock:/";
|
||||
"/local/net/".extraConfig = ''
|
||||
allow fc01::/64;
|
||||
allow 10.1.0.0/16;
|
||||
|
|
@ -102,7 +115,7 @@
|
|||
"/vw/" = {
|
||||
proxyWebsockets = true;
|
||||
extraConfig = localNetworks;
|
||||
proxyPass = "http://127.0.0.1:8032";
|
||||
proxyPass = "http://localhost:46151";
|
||||
};
|
||||
};
|
||||
};
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue