Harden server and add Nix-native CI + self-hosted Gitea Actions
- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/ X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail upstream copies via header_down on mail.severijnse.eu - tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync _25/_465/_993, fail-safe placeholders; coredns zone updated - pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint, ...); CI pre-commit job over x86_64 + aarch64 matrix - gitea: enable Gitea Actions + self-hosted runner (native:host, aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook - fix statix warnings (merge repeated systemd/database/configFile keys, inherit, bool-compare guards); add missing trailing newlines
This commit is contained in:
@@ -5,50 +5,85 @@
|
||||
unstablePkgs,
|
||||
...
|
||||
}: {
|
||||
services.postgresql = {
|
||||
enable = true;
|
||||
package = pkgs.postgresql_14;
|
||||
ensureDatabases = ["gitea"];
|
||||
ensureUsers = [
|
||||
{
|
||||
services = {
|
||||
postgresql = {
|
||||
enable = true;
|
||||
package = pkgs.postgresql_14;
|
||||
ensureDatabases = ["gitea"];
|
||||
ensureUsers = [
|
||||
{
|
||||
name = "gitea";
|
||||
ensureDBOwnership = true;
|
||||
}
|
||||
];
|
||||
};
|
||||
|
||||
gitea = {
|
||||
enable = true;
|
||||
package = unstablePkgs.gitea;
|
||||
database = {
|
||||
type = "postgres";
|
||||
name = "gitea";
|
||||
ensureDBOwnership = true;
|
||||
}
|
||||
];
|
||||
user = "gitea";
|
||||
};
|
||||
appName = "Jory's Git";
|
||||
lfs.enable = true;
|
||||
settings = {
|
||||
server = {
|
||||
DOMAIN = "git.severijnse.eu";
|
||||
ROOT_URL = "https://git.severijnse.eu/";
|
||||
HTTP_PORT = 3000;
|
||||
SSH_PORT = 222;
|
||||
SSH_LISTEN_PORT = 2222;
|
||||
START_SSH_SERVER = true;
|
||||
SSH_USER = "git";
|
||||
BUILTIN_SSH_SERVER_USER = "git";
|
||||
LANDING_PAGE = "explore";
|
||||
};
|
||||
service = {
|
||||
DISABLE_REGISTRATION = true;
|
||||
REQUIRE_SIGNIN_VIEW = false;
|
||||
};
|
||||
repository = {
|
||||
DEFAULT_BRANCH = "main";
|
||||
};
|
||||
actions = {
|
||||
ENABLED = true;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
gitea-actions-runner = {
|
||||
# nixos-24-05's gitea-actions-runner module hardcodes bin/act_runner,
|
||||
# but the current upstream package (1.0.3, matching gitea 1.26) ships
|
||||
# bin/gitea-runner. Wrap it so both names resolve.
|
||||
package = pkgs.runCommand "gitea-actions-runner-wrapped" {} ''
|
||||
mkdir -p $out/bin
|
||||
ln -s ${unstablePkgs.gitea-actions-runner}/bin/gitea-runner $out/bin/act_runner
|
||||
'';
|
||||
instances.default = {
|
||||
enable = true;
|
||||
name = "hetzner";
|
||||
url = "https://git.severijnse.eu";
|
||||
tokenFile = "/var/lib/secrets/gitea-runner-token";
|
||||
labels = ["native:host"];
|
||||
hostPackages = with pkgs; [
|
||||
bash
|
||||
coreutils
|
||||
curl
|
||||
gawk
|
||||
gitMinimal
|
||||
gnused
|
||||
nodejs
|
||||
wget
|
||||
];
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
# Gitea connects to local Postgres via Unix socket (peer auth).
|
||||
# No password needed — the socket is at /run/postgresql by default.
|
||||
# createDatabase = true ensures the DB + user are set up automatically.
|
||||
services.gitea = {
|
||||
enable = true;
|
||||
package = unstablePkgs.gitea;
|
||||
database.type = "postgres";
|
||||
database.name = "gitea";
|
||||
database.user = "gitea";
|
||||
appName = "Jory's Git";
|
||||
lfs.enable = true;
|
||||
settings = {
|
||||
server = {
|
||||
DOMAIN = "git.severijnse.eu";
|
||||
ROOT_URL = "https://git.severijnse.eu/";
|
||||
HTTP_PORT = 3000;
|
||||
SSH_PORT = 222;
|
||||
SSH_LISTEN_PORT = 2222;
|
||||
START_SSH_SERVER = true;
|
||||
SSH_USER = "git";
|
||||
BUILTIN_SSH_SERVER_USER = "git";
|
||||
LANDING_PAGE = "explore";
|
||||
};
|
||||
service = {
|
||||
DISABLE_REGISTRATION = true;
|
||||
REQUIRE_SIGNIN_VIEW = false;
|
||||
};
|
||||
repository = {
|
||||
DEFAULT_BRANCH = "main";
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
# Gitea built-in SSH server: listens on high port 2222 (no privileged-cap needed),
|
||||
# while clone URLs advertise port 222. Firewall redirects 222 -> 2222.
|
||||
@@ -61,4 +96,10 @@
|
||||
${pkgs.nftables}/bin/nft add chain inet gitea-redirect prerouting '{ type nat hook prerouting priority dstnat; }' 2>/dev/null || true
|
||||
${pkgs.nftables}/bin/nft add rule inet gitea-redirect prerouting tcp dport 222 redirect to :2222 2>/dev/null || true
|
||||
'';
|
||||
|
||||
# --- Gitea Actions self-hosted CI runner ---
|
||||
# Jobs install their own Nix inside the runner (official installer,
|
||||
# --no-daemon) so no system Nix daemon / nix-users group is needed.
|
||||
# aarch64 builds run under QEMU user-emulation via boot.binfmt below.
|
||||
boot.binfmt.emulatedSystems = ["aarch64-linux"];
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user