From d2b59d97cbe250af30155f09723c799b4f73376e Mon Sep 17 00:00:00 2001 From: bogale Date: Sat, 26 Sep 2026 16:42:02 +0900 Subject: [PATCH] postgres configured --- common.nix | 12 ++++++++++ home/common.nix | 10 -------- marks | 1 - server/mods/sysd.nix | 10 +++++--- server/mods/web.nix | 54 +++++++++++++++++++++++++++++++------------- 5 files changed, 57 insertions(+), 30 deletions(-) diff --git a/common.nix b/common.nix index 15dbef3..e12445f 100644 --- a/common.nix +++ b/common.nix @@ -51,6 +51,18 @@ jq sbctl ]; + programs = { + git = { + enable = true; + config = { + init.defaultbranch = "main"; + user = { + name = "bogale"; + email = "git@bogaledev.ru"; + }; + }; + }; + }; services = { logind.settings.Login.HandleLidSwitch = "ignore"; nginx = { diff --git a/home/common.nix b/home/common.nix index dfc98a0..a3a1645 100644 --- a/home/common.nix +++ b/home/common.nix @@ -12,16 +12,6 @@ historyControl = [ "ignoreboth" ]; shellAliases = { la = "ls -lAtr"; }; }; - git = { - enable = true; - settings = { - init.defaultbranch = "main"; - user = { - name = "bogale"; - email = "git@bogaledev.ru"; - }; - }; - }; neovim = { enable = true; defaultEditor = true; diff --git a/marks b/marks index c489329..9b2efb0 100644 --- a/marks +++ b/marks @@ -12,5 +12,4 @@ nixos-install --flake "/mnt/etc/nixos#nixos" --no-channel-copy --no-root-passwd systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=0+2+7 todo: -- mediawiki - email tracking diff --git a/server/mods/sysd.nix b/server/mods/sysd.nix index 565825e..3d60e3f 100644 --- a/server/mods/sysd.nix +++ b/server/mods/sysd.nix @@ -46,18 +46,22 @@ LogLevelMax = "notice"; }; script = '' - if [ ! -e /run/network.failures ] || \ - ${pkgs.iputils}/bin/ping -c 1 -W 3 1.1.1.1; then + if [ ! -e /run/network.failures ] || [ ! -e /run/network.limit ] || \ + ${pkgs.curl}/bin/curl --head --max-time 3 https://www.google.com; then + limit=3 failures=0 else + limit=$(cat /run/network.limit) failures=$((1+$(cat /run/network.failures))) echo "<5>failures = $failures" fi - if [ $failures -ge 3 ]; then + if [ $failures -ge $limit ]; then echo "<4>restarting NetworkManager" systemctl restart NetworkManager.service + [ $limit -lt 60 ] && limit=$((4*$limit/3)) failures=0 fi + echo $limit > /run/network.limit echo $failures > /run/network.failures ''; }; diff --git a/server/mods/web.nix b/server/mods/web.nix index 3320a33..cf8d1b7 100644 --- a/server/mods/web.nix +++ b/server/mods/web.nix @@ -14,16 +14,18 @@ services = let sslCertDir = config.security.acme.certs."bogaledev.ru".directory; in { - postgresql.enable = true; - phpfpm.pools.default = { - user = "php"; - group = "php"; - settings = { - "pm" = "ondemand"; - "pm.max_children" = 8; - "listen.owner" = "nginx"; - "listen.group" = "nginx"; - }; + postgresqlBackup = { + enable = true; + compression = "none"; + databases = [ "php" "forgejo" "vaultwarden" ]; + }; + postgresql = { + enable = true; + ensureDatabases = [ "php" ]; + ensureUsers = [ { + name = "php"; + ensureDBOwnership = true; + } ]; }; forgejo = { enable = true; @@ -36,6 +38,17 @@ }; }; }; + phpfpm.pools.php = { + user = "php"; + group = "php"; + phpEnv = { PATH = "/run/current-system/sw/bin"; }; + settings = { + "pm" = "ondemand"; + "pm.max_children" = 8; + "listen.owner" = "nginx"; + "listen.group" = "nginx"; + }; + }; vaultwarden = { enable = true; dbBackend = "postgresql"; @@ -52,9 +65,9 @@ }; }; nginx.virtualHosts."bogaledev.ru" = let - phpPool = pool: '' + phpPool = '' location ~ \.php$ { - fastcgi_pass unix:${config.services.phpfpm.pools.${pool}.socket}; + fastcgi_pass unix:${config.services.phpfpm.pools.php.socket}; } ''; localNetworks = '' @@ -70,16 +83,25 @@ forceSSL = true; root = "/srv/http"; useACMEHost = "bogaledev.ru"; - extraConfig = ''add_header Alt-Svc 'h3=":443"; ma=86400' always;''; + extraConfig = '' + add_header Alt-Svc 'h3=":443"; ma=2592000' always; + add_header X-Content-Type-Options "nosniff" always; + ''; locations = { - "/app/".extraConfig = phpPool "default"; - "/git/".proxyPass = "http://127.0.0.1:8039/"; - "/local/".extraConfig = ''${phpPool "default"} ${localNetworks}''; + "/" = { + extraConfig = phpPool; + index = "index.php index.html"; + }; + "/local/" = { + extraConfig = "${phpPool} ${localNetworks}"; + index = "index.php index.html"; + }; "/local/net/".extraConfig = '' allow fc01::/64; allow 10.1.0.0/16; deny all; ''; + "/git/".proxyPass = "http://127.0.0.1:8039/"; "/vw/" = { proxyWebsockets = true; extraConfig = localNetworks;