forgejo prod: email verification, ssh keys

This commit is contained in:
bogale 2026-09-27 22:17:56 +09:00
commit e94686a940
2 changed files with 47 additions and 44 deletions

View file

@ -23,13 +23,18 @@ in {
enable = true; enable = true;
enableSubmissions = true; enableSubmissions = true;
virtualMapType = "regexp"; virtualMapType = "regexp";
virtual = "/.*@bogaledev.ru/ mail@bogaledev.ru";
mapFiles.smtp_passwd = "/secrets/smtp_passwd"; mapFiles.smtp_passwd = "/secrets/smtp_passwd";
virtual = "/.*@bogaledev.ru/ mail@bogaledev.ru";
submissionsOptions = {
smtpd_tls_wrappermode = true;
smtpd_sasl_auth_enable = "yes";
milter_macro_daemon_name = "ORIGINATING";
smtpd_client_restrictions = "permit_sasl_authenticated,reject";
};
settings.main = { settings.main = {
smtpd_sasl_type = "dovecot"; smtpd_sasl_type = "dovecot";
smtp_tls_wrappermode = true; smtp_tls_wrappermode = true;
smtp_sasl_auth_enable = true; smtp_sasl_auth_enable = true;
smtpd_tls_wrappermode = true;
smtpd_sasl_auth_enable = true; smtpd_sasl_auth_enable = true;
smtp_tls_security_level = "verify"; smtp_tls_security_level = "verify";
relayhost = [ "smtp.resend.com:2465" ]; relayhost = [ "smtp.resend.com:2465" ];
@ -38,10 +43,7 @@ in {
smtp_sasl_tls_security_options = "noanonymous"; smtp_sasl_tls_security_options = "noanonymous";
smtp_sasl_password_maps = "hash:/etc/postfix/smtp_passwd"; smtp_sasl_password_maps = "hash:/etc/postfix/smtp_passwd";
virtual_transport = "lmtp:unix:${postfixDir}/dovecot-lmtp"; virtual_transport = "lmtp:unix:${postfixDir}/dovecot-lmtp";
smtpd_tls_chain_files = [ smtpd_tls_chain_files = [ "${sslCertDir}/key.pem" "${sslCertDir}/fullchain.pem" ];
"${sslCertDir}/key.pem"
"${sslCertDir}/fullchain.pem"
];
}; };
}; };
dovecot2 = { dovecot2 = {
@ -69,30 +71,18 @@ in {
user = "postfix"; user = "postfix";
group = "postfix"; group = "postfix";
}; };
"namespace inbox" = { "namespace inbox" = let
mailbox = name: {
auto = "create";
mailbox_special_use = "\\${name}";
};
in {
inbox = true; inbox = true;
"mailbox Sent" = { "mailbox Sent" = mailbox "Sent";
auto = "subscribe"; "mailbox Archive" = mailbox "Archive";
mailbox_special_use = "Sent"; "mailbox Flagged" = mailbox "Flagged";
}; "mailbox Junk" = mailbox "Junk" // { mailbox_autoexpunge = "45d"; };
"mailbox Archive" = { "mailbox Trash" = mailbox "Trash" // { mailbox_autoexpunge = "45d"; };
auto = "create";
mailbox_special_use = "\\Archive";
};
"mailbox Important" = {
auto = "subscribe";
mailbox_special_use = "\\Flagged";
};
"mailbox Spam" = {
auto = "create";
mailbox_autoexpunge = "45d";
mailbox_special_use = "\\Junk";
};
"mailbox Trash" = {
auto = "create";
mailbox_autoexpunge = "45d";
mailbox_special_use = "\\Trash";
};
}; };
}; };
}; };

View file

@ -27,19 +27,6 @@
ensureDBOwnership = true; ensureDBOwnership = true;
} ]; } ];
}; };
forgejo = {
enable = true;
database.type = "postgres";
dump = {
enable = true;
type = "tar.zst";
};
settings.server = {
SSH_PORT = 2235;
HTTP_PORT = 8039;
ROOT_URL = "https://bogaledev.ru/git/";
};
};
phpfpm.pools.php = { phpfpm.pools.php = {
user = "php"; user = "php";
group = "php"; group = "php";
@ -58,7 +45,7 @@
package = pkgs.vaultwarden-postgresql; package = pkgs.vaultwarden-postgresql;
environmentFile = "/secrets/vw-token.env"; environmentFile = "/secrets/vw-token.env";
config = { config = {
ROCKET_PORT = 8032; ROCKET_PORT = 46151;
SIGNUPS_ALLOWED = false; SIGNUPS_ALLOWED = false;
TRASH_AUTO_DELETE_DAYS = 90; TRASH_AUTO_DELETE_DAYS = 90;
PASSWORD_HINTS_ALLOWED = false; PASSWORD_HINTS_ALLOWED = false;
@ -66,6 +53,32 @@
DOMAIN = "https://bogaledev.ru/vw/"; DOMAIN = "https://bogaledev.ru/vw/";
}; };
}; };
forgejo = {
enable = true;
database.type = "postgres";
dump = {
enable = true;
type = "tar.zst";
};
settings = {
service = {
ENABLE_CAPTCHA = true;
REGISTER_EMAIL_CONFIRM = true;
};
server = {
SSH_PORT = 32831;
PROTOCOL = "http+unix";
ROOT_URL = "https://bogaledev.ru/git/";
HTTP_ADDR = "/run/forgejo/forgejo.sock";
};
mailer = {
ENABLED = true;
SMTP_PORT = 25;
SMTP_ADDR = "localhost";
FROM = "Forgejo <forgejo@bogaledev.ru>";
};
};
};
nginx.virtualHosts."bogaledev.ru" = let nginx.virtualHosts."bogaledev.ru" = let
phpPool = '' phpPool = ''
index index.php index.html; index index.php index.html;
@ -92,8 +105,8 @@
''; '';
locations = { locations = {
"/".extraConfig = phpPool; "/".extraConfig = phpPool;
"/git/".proxyPass = "http://127.0.0.1:8039/";
"/local/".extraConfig = "${phpPool} ${localNetworks}"; "/local/".extraConfig = "${phpPool} ${localNetworks}";
"/git/".proxyPass = "http://unix:/run/forgejo/forgejo.sock:/";
"/local/net/".extraConfig = '' "/local/net/".extraConfig = ''
allow fc01::/64; allow fc01::/64;
allow 10.1.0.0/16; allow 10.1.0.0/16;
@ -102,7 +115,7 @@
"/vw/" = { "/vw/" = {
proxyWebsockets = true; proxyWebsockets = true;
extraConfig = localNetworks; extraConfig = localNetworks;
proxyPass = "http://127.0.0.1:8032"; proxyPass = "http://localhost:46151";
}; };
}; };
}; };