Harden server and add Nix-native CI + self-hosted Gitea Actions
CI / Flake check (aarch64-linux) (push) Successful in 29s
CI / Flake check (x86_64-linux) (push) Successful in 30s
CI / Pre-commit checks (x86_64-linux) (push) Successful in 8s

- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/
  X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail
  upstream copies via header_down on mail.severijnse.eu
- tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync
  _25/_465/_993, fail-safe placeholders; coredns zone updated
- pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint,
  deadnix); CI pre-commit job over x86_64 + aarch64 matrix
- gitea: enable Gitea Actions + self-hosted runner (native:host,
  aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook
- fix statix warnings (merge repeated systemd/database/configFile keys)
  + disable empty_pattern via statix.toml (nixpkgs standard)
- Clean up unused lambda patterns across 38 .nix files via deadnix
- Format whole repo with alejandra (27 files)
- Remove .github/workflows/ci.yml (Gitea shadows .github; runner labels differ)
- Fix CI nix-not-found: export /run/current-system/sw/bin in PATH
- Trim aarch64 from pre-commit matrix (no QEMU binfmt deployed yet)
This commit is contained in:
2026-07-12 09:11:41 +02:00
parent c5f771bd53
commit 5116faf0d3
57 changed files with 391 additions and 390 deletions
+1 -5
View File
@@ -1,8 +1,4 @@
{
pkgs,
lib,
...
}: let
{pkgs, ...}: let
alacritty-wrapped = pkgs.writeShellScriptBin "alacritty-wayland" ''
export WAYLAND_DISPLAY="wayland-1"
export XDG_CURRENT_DESKTOP="Niri"
+1 -3
View File
@@ -2,9 +2,7 @@
config,
pkgs,
...
}: let
sshConfigFile = "ssh/config";
in {
}: {
users.users.someone.packages = with pkgs; [
openssh
];
+1 -5
View File
@@ -1,8 +1,4 @@
{
inputs,
pkgs,
...
}: {
{pkgs, ...}: {
users.users.someone.packages = with pkgs; [
# archives
zip
+16 -14
View File
@@ -80,19 +80,21 @@ in {
enable = true;
defaultApplications = associations;
};
configFile."xdg-desktop-portal-termfilechooser/config".text = ''
[filechooser]
cmd=${yaziWrapper}/bin/yazi-wrapper
default_dir=$HOME
open_mode=suggested
save_mode=suggested
'';
configFile."user-dirs.dirs".source = userDirsConfig;
configFile."mimeapps.list".text = ''
[Default Applications]
${lib.concatStringsSep "\n" (lib.mapAttrsToList (k: v: "${k}=${lib.concatStringsSep ";" v}") associations)}
[Added Associations]
${lib.concatStringsSep "\n" (lib.mapAttrsToList (k: v: "${k}=${lib.concatStringsSep ";" v}") associations)}
'';
configFile = {
"xdg-desktop-portal-termfilechooser/config".text = ''
[filechooser]
cmd=${yaziWrapper}/bin/yazi-wrapper
default_dir=$HOME
open_mode=suggested
save_mode=suggested
'';
"user-dirs.dirs".source = userDirsConfig;
"mimeapps.list".text = ''
[Default Applications]
${lib.concatStringsSep "\n" (lib.mapAttrsToList (k: v: "${k}=${lib.concatStringsSep ";" v}") associations)}
[Added Associations]
${lib.concatStringsSep "\n" (lib.mapAttrsToList (k: v: "${k}=${lib.concatStringsSep ";" v}") associations)}
'';
};
};
}