Harden server and add Nix-native CI + self-hosted Gitea Actions
- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/ X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail upstream copies via header_down on mail.severijnse.eu - tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync _25/_465/_993, fail-safe placeholders; coredns zone updated - pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint, deadnix); CI pre-commit job over x86_64 + aarch64 matrix - gitea: enable Gitea Actions + self-hosted runner (native:host, aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook - fix statix warnings (merge repeated systemd/database/configFile keys) + disable empty_pattern via statix.toml (nixpkgs standard) - Clean up unused lambda patterns across 38 .nix files via deadnix - Format whole repo with alejandra (27 files) - Remove .github/workflows/ci.yml (Gitea shadows .github; runner labels differ) - Fix CI nix-not-found: export /run/current-system/sw/bin in PATH - Trim aarch64 from pre-commit matrix (no QEMU binfmt deployed yet)
This commit is contained in:
@@ -5,7 +5,7 @@
|
||||
inputs.flake-parts.lib.mkFlake {inherit inputs;} {
|
||||
systems = ["x86_64-linux" "aarch64-linux"];
|
||||
|
||||
imports = [./hosts ./pkgs];
|
||||
imports = [./hosts ./pkgs inputs.git-hooks-nix.flakeModule];
|
||||
|
||||
perSystem = {
|
||||
config,
|
||||
@@ -21,6 +21,37 @@
|
||||
};
|
||||
# Nix Formatter
|
||||
formatter = pkgs.alejandra;
|
||||
|
||||
# Pre-commit hooks (flake-parts module from cachix/git-hooks.nix).
|
||||
# `nix build .#checks.<system>.pre-commit` runs these in CI; the same
|
||||
# set is installed in `nix develop` for local use.
|
||||
# alejandra.settings.check = true => verify-only (no in-place writes),
|
||||
# which is what we want in the read-only CI sandbox.
|
||||
pre-commit.settings.hooks = {
|
||||
alejandra = {
|
||||
enable = true;
|
||||
settings.check = true;
|
||||
};
|
||||
statix = {
|
||||
enable = true;
|
||||
# hardware-configuration.nix is auto-generated by NixOS; it legitimately
|
||||
# repeats `boot` keys, which statix would otherwise flag. Exclude it here.
|
||||
settings.ignore = ["hardware-configuration.nix"];
|
||||
# Lint config (statix.toml at repo root). Disables `empty_pattern`, which
|
||||
# flags the standard NixOS `{ ... }:` module pattern that nixpkgs likewise
|
||||
# permits.
|
||||
settings.config = "./statix.toml";
|
||||
};
|
||||
deadnix.enable = true;
|
||||
actionlint.enable = true;
|
||||
trim-trailing-whitespace.enable = true;
|
||||
end-of-file-fixer.enable = true;
|
||||
check-yaml.enable = true;
|
||||
check-toml.enable = true;
|
||||
check-added-large-files.enable = true;
|
||||
check-merge-conflicts.enable = true;
|
||||
detect-private-keys.enable = true;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
@@ -40,6 +71,14 @@
|
||||
inputs.nixpkgs-lib.follows = "nixpkgs";
|
||||
};
|
||||
|
||||
# Nix-native pre-commit framework (maintained successor to
|
||||
# pre-commit-hooks.nix). Follows our nixpkgs to avoid version skew
|
||||
# with the rest of the flake.
|
||||
git-hooks-nix = {
|
||||
url = "github:cachix/git-hooks.nix";
|
||||
inputs.nixpkgs.follows = "nixpkgs";
|
||||
};
|
||||
|
||||
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
|
||||
|
||||
# rest of inputs, alphabetical order
|
||||
|
||||
Reference in New Issue
Block a user