Harden server and add Nix-native CI + self-hosted Gitea Actions
CI / flake-check (aarch64-linux) (push) Failing after 8s
CI / flake-check (x86_64-linux) (push) Failing after 2s
CI / pre-commit (aarch64-linux) (push) Failing after 2s
CI / pre-commit (x86_64-linux) (push) Failing after 2s

- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/
  X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail
  upstream copies via header_down on mail.severijnse.eu
- tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync
  _25/_465/_993, fail-safe placeholders; coredns zone updated
- pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint,
  ...); CI pre-commit job over x86_64 + aarch64 matrix
- gitea: enable Gitea Actions + self-hosted runner (native:host,
  aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook
- fix statix warnings (merge repeated systemd/database/configFile keys,
  inherit, bool-compare guards); add missing trailing newlines
This commit is contained in:
2026-07-12 00:05:13 +02:00
parent c5f771bd53
commit 7ed54e51a2
23 changed files with 336 additions and 147 deletions
+1 -1
View File
@@ -7,4 +7,4 @@
"NEWS.md": "11866"
},
"version": 8
}
}
+1 -1
View File
@@ -1,3 +1,3 @@
indent_type = "Spaces"
indent_width = 2
column_width = 120
column_width = 120
+5 -4
View File
@@ -36,10 +36,11 @@
(
if typeOf element == "null"
then "null"
else if element == false
then "false"
else if element == true
then "true"
else if typeOf element == "bool"
then
if element
then "true"
else "false"
else if typeOf element == "string"
then ''"${sanitizeString element}"''
else toString element
+1 -1
View File
@@ -8,7 +8,7 @@
binds = import ./_binds.nix {inherit pkgs;};
rules = import ./_rules.nix;
finalConfig = toKDL.generate "niri-config.kdl" (settings // {binds = binds;} // rules);
finalConfig = toKDL.generate "niri-config.kdl" (settings // {inherit binds;} // rules);
in {
environment.sessionVariables = {
NIRI_CONFIG = "$HOME/.config/niri/config.kdl";
+16 -14
View File
@@ -80,19 +80,21 @@ in {
enable = true;
defaultApplications = associations;
};
configFile."xdg-desktop-portal-termfilechooser/config".text = ''
[filechooser]
cmd=${yaziWrapper}/bin/yazi-wrapper
default_dir=$HOME
open_mode=suggested
save_mode=suggested
'';
configFile."user-dirs.dirs".source = userDirsConfig;
configFile."mimeapps.list".text = ''
[Default Applications]
${lib.concatStringsSep "\n" (lib.mapAttrsToList (k: v: "${k}=${lib.concatStringsSep ";" v}") associations)}
[Added Associations]
${lib.concatStringsSep "\n" (lib.mapAttrsToList (k: v: "${k}=${lib.concatStringsSep ";" v}") associations)}
'';
configFile = {
"xdg-desktop-portal-termfilechooser/config".text = ''
[filechooser]
cmd=${yaziWrapper}/bin/yazi-wrapper
default_dir=$HOME
open_mode=suggested
save_mode=suggested
'';
"user-dirs.dirs".source = userDirsConfig;
"mimeapps.list".text = ''
[Default Applications]
${lib.concatStringsSep "\n" (lib.mapAttrsToList (k: v: "${k}=${lib.concatStringsSep ";" v}") associations)}
[Added Associations]
${lib.concatStringsSep "\n" (lib.mapAttrsToList (k: v: "${k}=${lib.concatStringsSep ";" v}") associations)}
'';
};
};
}