Harden server and add Nix-native CI + self-hosted Gitea Actions
- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/ X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail upstream copies via header_down on mail.severijnse.eu - tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync _25/_465/_993, fail-safe placeholders; coredns zone updated - pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint, ...); CI pre-commit job over x86_64 + aarch64 matrix - gitea: enable Gitea Actions + self-hosted runner (native:host, aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook - fix statix warnings (merge repeated systemd/database/configFile keys, inherit, bool-compare guards); add missing trailing newlines
This commit is contained in:
@@ -35,14 +35,14 @@
|
||||
statix = {
|
||||
enable = true;
|
||||
# hardware-configuration.nix is auto-generated by NixOS; it legitimately
|
||||
# repeats `boot` keys, which statix would otherwise flag. Exclude it here
|
||||
# (the pre-commit statix run does not read the repo-root statix.toml).
|
||||
# repeats `boot` keys, which statix would otherwise flag. Exclude it here.
|
||||
settings.ignore = ["hardware-configuration.nix"];
|
||||
# Lint config (statix.toml at repo root). Disables `empty_pattern`, which
|
||||
# flags the standard NixOS `{ ... }:` module pattern that nixpkgs likewise
|
||||
# permits.
|
||||
settings.config = "./statix.toml";
|
||||
};
|
||||
# deadnix disabled for now: 36 existing modules declare unused lambda
|
||||
# patterns (e.g. `config`/`lib`/`pkgs`/`inputs` in args). Re-enable once
|
||||
# that cleanup lands so `nix build .#checks.<system>.pre-commit` stays green.
|
||||
deadnix.enable = false;
|
||||
deadnix.enable = true;
|
||||
actionlint.enable = true;
|
||||
trim-trailing-whitespace.enable = true;
|
||||
end-of-file-fixer.enable = true;
|
||||
|
||||
Reference in New Issue
Block a user