postgres configured

This commit is contained in:
bogale 2026-09-26 16:42:02 +09:00
commit d2b59d97cb
5 changed files with 57 additions and 30 deletions

View file

@ -51,6 +51,18 @@
jq jq
sbctl sbctl
]; ];
programs = {
git = {
enable = true;
config = {
init.defaultbranch = "main";
user = {
name = "bogale";
email = "git@bogaledev.ru";
};
};
};
};
services = { services = {
logind.settings.Login.HandleLidSwitch = "ignore"; logind.settings.Login.HandleLidSwitch = "ignore";
nginx = { nginx = {

View file

@ -12,16 +12,6 @@
historyControl = [ "ignoreboth" ]; historyControl = [ "ignoreboth" ];
shellAliases = { la = "ls -lAtr"; }; shellAliases = { la = "ls -lAtr"; };
}; };
git = {
enable = true;
settings = {
init.defaultbranch = "main";
user = {
name = "bogale";
email = "git@bogaledev.ru";
};
};
};
neovim = { neovim = {
enable = true; enable = true;
defaultEditor = true; defaultEditor = true;

1
marks
View file

@ -12,5 +12,4 @@ nixos-install --flake "/mnt/etc/nixos#nixos" --no-channel-copy --no-root-passwd
systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=0+2+7 <LUKS_DEV> systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=0+2+7 <LUKS_DEV>
todo: todo:
- mediawiki
- email tracking - email tracking

View file

@ -46,18 +46,22 @@
LogLevelMax = "notice"; LogLevelMax = "notice";
}; };
script = '' script = ''
if [ ! -e /run/network.failures ] || \ if [ ! -e /run/network.failures ] || [ ! -e /run/network.limit ] || \
${pkgs.iputils}/bin/ping -c 1 -W 3 1.1.1.1; then ${pkgs.curl}/bin/curl --head --max-time 3 https://www.google.com; then
limit=3
failures=0 failures=0
else else
limit=$(cat /run/network.limit)
failures=$((1+$(cat /run/network.failures))) failures=$((1+$(cat /run/network.failures)))
echo "<5>failures = $failures" echo "<5>failures = $failures"
fi fi
if [ $failures -ge 3 ]; then if [ $failures -ge $limit ]; then
echo "<4>restarting NetworkManager" echo "<4>restarting NetworkManager"
systemctl restart NetworkManager.service systemctl restart NetworkManager.service
[ $limit -lt 60 ] && limit=$((4*$limit/3))
failures=0 failures=0
fi fi
echo $limit > /run/network.limit
echo $failures > /run/network.failures echo $failures > /run/network.failures
''; '';
}; };

View file

@ -14,16 +14,18 @@
services = let services = let
sslCertDir = config.security.acme.certs."bogaledev.ru".directory; sslCertDir = config.security.acme.certs."bogaledev.ru".directory;
in { in {
postgresql.enable = true; postgresqlBackup = {
phpfpm.pools.default = { enable = true;
user = "php"; compression = "none";
group = "php"; databases = [ "php" "forgejo" "vaultwarden" ];
settings = {
"pm" = "ondemand";
"pm.max_children" = 8;
"listen.owner" = "nginx";
"listen.group" = "nginx";
}; };
postgresql = {
enable = true;
ensureDatabases = [ "php" ];
ensureUsers = [ {
name = "php";
ensureDBOwnership = true;
} ];
}; };
forgejo = { forgejo = {
enable = true; enable = true;
@ -36,6 +38,17 @@
}; };
}; };
}; };
phpfpm.pools.php = {
user = "php";
group = "php";
phpEnv = { PATH = "/run/current-system/sw/bin"; };
settings = {
"pm" = "ondemand";
"pm.max_children" = 8;
"listen.owner" = "nginx";
"listen.group" = "nginx";
};
};
vaultwarden = { vaultwarden = {
enable = true; enable = true;
dbBackend = "postgresql"; dbBackend = "postgresql";
@ -52,9 +65,9 @@
}; };
}; };
nginx.virtualHosts."bogaledev.ru" = let nginx.virtualHosts."bogaledev.ru" = let
phpPool = pool: '' phpPool = ''
location ~ \.php$ { location ~ \.php$ {
fastcgi_pass unix:${config.services.phpfpm.pools.${pool}.socket}; fastcgi_pass unix:${config.services.phpfpm.pools.php.socket};
} }
''; '';
localNetworks = '' localNetworks = ''
@ -70,16 +83,25 @@
forceSSL = true; forceSSL = true;
root = "/srv/http"; root = "/srv/http";
useACMEHost = "bogaledev.ru"; useACMEHost = "bogaledev.ru";
extraConfig = ''add_header Alt-Svc 'h3=":443"; ma=86400' always;''; extraConfig = ''
add_header Alt-Svc 'h3=":443"; ma=2592000' always;
add_header X-Content-Type-Options "nosniff" always;
'';
locations = { locations = {
"/app/".extraConfig = phpPool "default"; "/" = {
"/git/".proxyPass = "http://127.0.0.1:8039/"; extraConfig = phpPool;
"/local/".extraConfig = ''${phpPool "default"} ${localNetworks}''; index = "index.php index.html";
};
"/local/" = {
extraConfig = "${phpPool} ${localNetworks}";
index = "index.php index.html";
};
"/local/net/".extraConfig = '' "/local/net/".extraConfig = ''
allow fc01::/64; allow fc01::/64;
allow 10.1.0.0/16; allow 10.1.0.0/16;
deny all; deny all;
''; '';
"/git/".proxyPass = "http://127.0.0.1:8039/";
"/vw/" = { "/vw/" = {
proxyWebsockets = true; proxyWebsockets = true;
extraConfig = localNetworks; extraConfig = localNetworks;