Harden server and add Nix-native CI + self-hosted Gitea Actions
CI / Flake check (aarch64-linux) (push) Successful in 32s
CI / Flake check (x86_64-linux) (push) Successful in 30s
CI / Pre-commit checks (aarch64-linux) (push) Successful in 27s
CI / Pre-commit checks (x86_64-linux) (push) Successful in 10s

- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/
  X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail
  upstream copies via header_down on mail.severijnse.eu
- tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync
  _25/_465/_993, fail-safe placeholders; coredns zone updated
- pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint,
  ...); CI pre-commit job over x86_64 + aarch64 matrix
- gitea: enable Gitea Actions + self-hosted runner (native:host,
  aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook
- fix statix warnings (merge repeated systemd/database/configFile keys,
  inherit, bool-compare guards); add missing trailing newlines
This commit is contained in:
2026-07-12 01:45:33 +02:00
parent 7ed54e51a2
commit ca4a0b23ab
41 changed files with 99 additions and 292 deletions
+4 -4
View File
@@ -1,7 +1,5 @@
{
config,
pkgs,
lib,
unstablePkgs,
...
}: {
@@ -98,8 +96,10 @@
'';
# --- Gitea Actions self-hosted CI runner ---
# Jobs install their own Nix inside the runner (official installer,
# --no-daemon) so no system Nix daemon / nix-users group is needed.
# The native runner only exposes `hostPackages` on PATH (see the list above),
# which intentionally omits Nix. CI steps export the host's system Nix
# (/run/current-system/sw/bin, i.e. Lix) onto PATH rather than installing a
# second Nix client, so the running Lix daemon is used directly.
# aarch64 builds run under QEMU user-emulation via boot.binfmt below.
boot.binfmt.emulatedSystems = ["aarch64-linux"];
}