Files
nixos-config/servers/hetzner/modules/services/gitea.nix
T
jory 7ed54e51a2
CI / flake-check (aarch64-linux) (push) Failing after 8s
CI / flake-check (x86_64-linux) (push) Failing after 2s
CI / pre-commit (aarch64-linux) (push) Failing after 2s
CI / pre-commit (x86_64-linux) (push) Failing after 2s
Harden server and add Nix-native CI + self-hosted Gitea Actions
- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/
  X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail
  upstream copies via header_down on mail.severijnse.eu
- tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync
  _25/_465/_993, fail-safe placeholders; coredns zone updated
- pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint,
  ...); CI pre-commit job over x86_64 + aarch64 matrix
- gitea: enable Gitea Actions + self-hosted runner (native:host,
  aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook
- fix statix warnings (merge repeated systemd/database/configFile keys,
  inherit, bool-compare guards); add missing trailing newlines
2026-07-12 00:05:13 +02:00

106 lines
3.2 KiB
Nix

{
config,
pkgs,
lib,
unstablePkgs,
...
}: {
services = {
postgresql = {
enable = true;
package = pkgs.postgresql_14;
ensureDatabases = ["gitea"];
ensureUsers = [
{
name = "gitea";
ensureDBOwnership = true;
}
];
};
gitea = {
enable = true;
package = unstablePkgs.gitea;
database = {
type = "postgres";
name = "gitea";
user = "gitea";
};
appName = "Jory's Git";
lfs.enable = true;
settings = {
server = {
DOMAIN = "git.severijnse.eu";
ROOT_URL = "https://git.severijnse.eu/";
HTTP_PORT = 3000;
SSH_PORT = 222;
SSH_LISTEN_PORT = 2222;
START_SSH_SERVER = true;
SSH_USER = "git";
BUILTIN_SSH_SERVER_USER = "git";
LANDING_PAGE = "explore";
};
service = {
DISABLE_REGISTRATION = true;
REQUIRE_SIGNIN_VIEW = false;
};
repository = {
DEFAULT_BRANCH = "main";
};
actions = {
ENABLED = true;
};
};
};
gitea-actions-runner = {
# nixos-24-05's gitea-actions-runner module hardcodes bin/act_runner,
# but the current upstream package (1.0.3, matching gitea 1.26) ships
# bin/gitea-runner. Wrap it so both names resolve.
package = pkgs.runCommand "gitea-actions-runner-wrapped" {} ''
mkdir -p $out/bin
ln -s ${unstablePkgs.gitea-actions-runner}/bin/gitea-runner $out/bin/act_runner
'';
instances.default = {
enable = true;
name = "hetzner";
url = "https://git.severijnse.eu";
tokenFile = "/var/lib/secrets/gitea-runner-token";
labels = ["native:host"];
hostPackages = with pkgs; [
bash
coreutils
curl
gawk
gitMinimal
gnused
nodejs
wget
];
};
};
};
# Gitea connects to local Postgres via Unix socket (peer auth).
# No password needed — the socket is at /run/postgresql by default.
# createDatabase = true ensures the DB + user are set up automatically.
# Gitea built-in SSH server: listens on high port 2222 (no privileged-cap needed),
# while clone URLs advertise port 222. Firewall redirects 222 -> 2222.
networking.firewall.allowedTCPPorts = [222 2222];
# Redirect external git SSH (222) to Gitea's internal listener (2222)
networking.firewall.extraCommands = ''
${pkgs.nftables}/bin/nft add table inet gitea-redirect 2>/dev/null || true
${pkgs.nftables}/bin/nft flush chain inet gitea-redirect prerouting 2>/dev/null || true
${pkgs.nftables}/bin/nft add chain inet gitea-redirect prerouting '{ type nat hook prerouting priority dstnat; }' 2>/dev/null || true
${pkgs.nftables}/bin/nft add rule inet gitea-redirect prerouting tcp dport 222 redirect to :2222 2>/dev/null || true
'';
# --- Gitea Actions self-hosted CI runner ---
# Jobs install their own Nix inside the runner (official installer,
# --no-daemon) so no system Nix daemon / nix-users group is needed.
# aarch64 builds run under QEMU user-emulation via boot.binfmt below.
boot.binfmt.emulatedSystems = ["aarch64-linux"];
}