Files
nixos-config/servers/hetzner/modules/services/watchtower.nix
T
jory ca4a0b23ab
CI / Flake check (aarch64-linux) (push) Successful in 32s
CI / Flake check (x86_64-linux) (push) Successful in 30s
CI / Pre-commit checks (aarch64-linux) (push) Successful in 27s
CI / Pre-commit checks (x86_64-linux) (push) Successful in 10s
Harden server and add Nix-native CI + self-hosted Gitea Actions
- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/
  X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail
  upstream copies via header_down on mail.severijnse.eu
- tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync
  _25/_465/_993, fail-safe placeholders; coredns zone updated
- pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint,
  ...); CI pre-commit job over x86_64 + aarch64 matrix
- gitea: enable Gitea Actions + self-hosted runner (native:host,
  aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook
- fix statix warnings (merge repeated systemd/database/configFile keys,
  inherit, bool-compare guards); add missing trailing newlines
2026-07-12 02:08:23 +02:00

18 lines
485 B
Nix

{...}: {
virtualisation.oci-containers.containers.watchtower = {
image = "ghcr.io/nicholas-fedor/watchtower:latest";
autoStart = true;
volumes = [
"/var/run/podman/podman.sock:/var/run/docker.sock:ro"
];
environment = {
WATCHTOWER_CLEANUP = "true";
WATCHTOWER_POLL_INTERVAL = "86400";
WATCHTOWER_INCLUDE_STOPPED = "true";
WATCHTOWER_REVIVE_STOPPED = "true";
TZ = "Europe/Amsterdam";
};
cmd = ["--label-enable"];
};
}