forgejo prod: email verification, ssh keys
This commit is contained in:
parent
41a59e7d5c
commit
e94686a940
2 changed files with 47 additions and 44 deletions
|
|
@ -23,13 +23,18 @@ in {
|
||||||
enable = true;
|
enable = true;
|
||||||
enableSubmissions = true;
|
enableSubmissions = true;
|
||||||
virtualMapType = "regexp";
|
virtualMapType = "regexp";
|
||||||
virtual = "/.*@bogaledev.ru/ mail@bogaledev.ru";
|
|
||||||
mapFiles.smtp_passwd = "/secrets/smtp_passwd";
|
mapFiles.smtp_passwd = "/secrets/smtp_passwd";
|
||||||
|
virtual = "/.*@bogaledev.ru/ mail@bogaledev.ru";
|
||||||
|
submissionsOptions = {
|
||||||
|
smtpd_tls_wrappermode = true;
|
||||||
|
smtpd_sasl_auth_enable = "yes";
|
||||||
|
milter_macro_daemon_name = "ORIGINATING";
|
||||||
|
smtpd_client_restrictions = "permit_sasl_authenticated,reject";
|
||||||
|
};
|
||||||
settings.main = {
|
settings.main = {
|
||||||
smtpd_sasl_type = "dovecot";
|
smtpd_sasl_type = "dovecot";
|
||||||
smtp_tls_wrappermode = true;
|
smtp_tls_wrappermode = true;
|
||||||
smtp_sasl_auth_enable = true;
|
smtp_sasl_auth_enable = true;
|
||||||
smtpd_tls_wrappermode = true;
|
|
||||||
smtpd_sasl_auth_enable = true;
|
smtpd_sasl_auth_enable = true;
|
||||||
smtp_tls_security_level = "verify";
|
smtp_tls_security_level = "verify";
|
||||||
relayhost = [ "smtp.resend.com:2465" ];
|
relayhost = [ "smtp.resend.com:2465" ];
|
||||||
|
|
@ -38,10 +43,7 @@ in {
|
||||||
smtp_sasl_tls_security_options = "noanonymous";
|
smtp_sasl_tls_security_options = "noanonymous";
|
||||||
smtp_sasl_password_maps = "hash:/etc/postfix/smtp_passwd";
|
smtp_sasl_password_maps = "hash:/etc/postfix/smtp_passwd";
|
||||||
virtual_transport = "lmtp:unix:${postfixDir}/dovecot-lmtp";
|
virtual_transport = "lmtp:unix:${postfixDir}/dovecot-lmtp";
|
||||||
smtpd_tls_chain_files = [
|
smtpd_tls_chain_files = [ "${sslCertDir}/key.pem" "${sslCertDir}/fullchain.pem" ];
|
||||||
"${sslCertDir}/key.pem"
|
|
||||||
"${sslCertDir}/fullchain.pem"
|
|
||||||
];
|
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
dovecot2 = {
|
dovecot2 = {
|
||||||
|
|
@ -69,30 +71,18 @@ in {
|
||||||
user = "postfix";
|
user = "postfix";
|
||||||
group = "postfix";
|
group = "postfix";
|
||||||
};
|
};
|
||||||
"namespace inbox" = {
|
"namespace inbox" = let
|
||||||
|
mailbox = name: {
|
||||||
|
auto = "create";
|
||||||
|
mailbox_special_use = "\\${name}";
|
||||||
|
};
|
||||||
|
in {
|
||||||
inbox = true;
|
inbox = true;
|
||||||
"mailbox Sent" = {
|
"mailbox Sent" = mailbox "Sent";
|
||||||
auto = "subscribe";
|
"mailbox Archive" = mailbox "Archive";
|
||||||
mailbox_special_use = "Sent";
|
"mailbox Flagged" = mailbox "Flagged";
|
||||||
};
|
"mailbox Junk" = mailbox "Junk" // { mailbox_autoexpunge = "45d"; };
|
||||||
"mailbox Archive" = {
|
"mailbox Trash" = mailbox "Trash" // { mailbox_autoexpunge = "45d"; };
|
||||||
auto = "create";
|
|
||||||
mailbox_special_use = "\\Archive";
|
|
||||||
};
|
|
||||||
"mailbox Important" = {
|
|
||||||
auto = "subscribe";
|
|
||||||
mailbox_special_use = "\\Flagged";
|
|
||||||
};
|
|
||||||
"mailbox Spam" = {
|
|
||||||
auto = "create";
|
|
||||||
mailbox_autoexpunge = "45d";
|
|
||||||
mailbox_special_use = "\\Junk";
|
|
||||||
};
|
|
||||||
"mailbox Trash" = {
|
|
||||||
auto = "create";
|
|
||||||
mailbox_autoexpunge = "45d";
|
|
||||||
mailbox_special_use = "\\Trash";
|
|
||||||
};
|
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
|
||||||
|
|
@ -27,19 +27,6 @@
|
||||||
ensureDBOwnership = true;
|
ensureDBOwnership = true;
|
||||||
} ];
|
} ];
|
||||||
};
|
};
|
||||||
forgejo = {
|
|
||||||
enable = true;
|
|
||||||
database.type = "postgres";
|
|
||||||
dump = {
|
|
||||||
enable = true;
|
|
||||||
type = "tar.zst";
|
|
||||||
};
|
|
||||||
settings.server = {
|
|
||||||
SSH_PORT = 2235;
|
|
||||||
HTTP_PORT = 8039;
|
|
||||||
ROOT_URL = "https://bogaledev.ru/git/";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
phpfpm.pools.php = {
|
phpfpm.pools.php = {
|
||||||
user = "php";
|
user = "php";
|
||||||
group = "php";
|
group = "php";
|
||||||
|
|
@ -58,7 +45,7 @@
|
||||||
package = pkgs.vaultwarden-postgresql;
|
package = pkgs.vaultwarden-postgresql;
|
||||||
environmentFile = "/secrets/vw-token.env";
|
environmentFile = "/secrets/vw-token.env";
|
||||||
config = {
|
config = {
|
||||||
ROCKET_PORT = 8032;
|
ROCKET_PORT = 46151;
|
||||||
SIGNUPS_ALLOWED = false;
|
SIGNUPS_ALLOWED = false;
|
||||||
TRASH_AUTO_DELETE_DAYS = 90;
|
TRASH_AUTO_DELETE_DAYS = 90;
|
||||||
PASSWORD_HINTS_ALLOWED = false;
|
PASSWORD_HINTS_ALLOWED = false;
|
||||||
|
|
@ -66,6 +53,32 @@
|
||||||
DOMAIN = "https://bogaledev.ru/vw/";
|
DOMAIN = "https://bogaledev.ru/vw/";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
forgejo = {
|
||||||
|
enable = true;
|
||||||
|
database.type = "postgres";
|
||||||
|
dump = {
|
||||||
|
enable = true;
|
||||||
|
type = "tar.zst";
|
||||||
|
};
|
||||||
|
settings = {
|
||||||
|
service = {
|
||||||
|
ENABLE_CAPTCHA = true;
|
||||||
|
REGISTER_EMAIL_CONFIRM = true;
|
||||||
|
};
|
||||||
|
server = {
|
||||||
|
SSH_PORT = 32831;
|
||||||
|
PROTOCOL = "http+unix";
|
||||||
|
ROOT_URL = "https://bogaledev.ru/git/";
|
||||||
|
HTTP_ADDR = "/run/forgejo/forgejo.sock";
|
||||||
|
};
|
||||||
|
mailer = {
|
||||||
|
ENABLED = true;
|
||||||
|
SMTP_PORT = 25;
|
||||||
|
SMTP_ADDR = "localhost";
|
||||||
|
FROM = "Forgejo <forgejo@bogaledev.ru>";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
nginx.virtualHosts."bogaledev.ru" = let
|
nginx.virtualHosts."bogaledev.ru" = let
|
||||||
phpPool = ''
|
phpPool = ''
|
||||||
index index.php index.html;
|
index index.php index.html;
|
||||||
|
|
@ -92,8 +105,8 @@
|
||||||
'';
|
'';
|
||||||
locations = {
|
locations = {
|
||||||
"/".extraConfig = phpPool;
|
"/".extraConfig = phpPool;
|
||||||
"/git/".proxyPass = "http://127.0.0.1:8039/";
|
|
||||||
"/local/".extraConfig = "${phpPool} ${localNetworks}";
|
"/local/".extraConfig = "${phpPool} ${localNetworks}";
|
||||||
|
"/git/".proxyPass = "http://unix:/run/forgejo/forgejo.sock:/";
|
||||||
"/local/net/".extraConfig = ''
|
"/local/net/".extraConfig = ''
|
||||||
allow fc01::/64;
|
allow fc01::/64;
|
||||||
allow 10.1.0.0/16;
|
allow 10.1.0.0/16;
|
||||||
|
|
@ -102,7 +115,7 @@
|
||||||
"/vw/" = {
|
"/vw/" = {
|
||||||
proxyWebsockets = true;
|
proxyWebsockets = true;
|
||||||
extraConfig = localNetworks;
|
extraConfig = localNetworks;
|
||||||
proxyPass = "http://127.0.0.1:8032";
|
proxyPass = "http://localhost:46151";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue