2021-03-01 15:27:18 +01:00
|
|
|
{ config, lib, pkgs, ... }:
|
2021-02-21 13:04:36 +01:00
|
|
|
let
|
|
|
|
cfg = config.services.gitea;
|
|
|
|
in
|
|
|
|
{
|
2021-03-01 15:27:18 +01:00
|
|
|
sops.secrets.gitea-mail = {
|
|
|
|
owner = cfg.user;
|
|
|
|
sopsFile = ../secrets.yaml;
|
|
|
|
};
|
|
|
|
systemd.services.gitea.serviceConfig.SupplementaryGroups = lib.singleton "keys";
|
2021-02-21 13:04:36 +01:00
|
|
|
|
|
|
|
services.gitea = {
|
|
|
|
enable = true;
|
|
|
|
|
|
|
|
appName = "sbrudergit";
|
|
|
|
lfs = {
|
|
|
|
enable = true;
|
|
|
|
};
|
|
|
|
database.type = "postgres";
|
2021-03-01 15:27:18 +01:00
|
|
|
mailerPasswordFile = config.sops.secrets.gitea-mail.path;
|
2021-02-21 13:04:36 +01:00
|
|
|
settings = {
|
|
|
|
mailer = {
|
|
|
|
ENABLED = true;
|
|
|
|
HOST = "vueko.sbruder.de:587";
|
|
|
|
FROM = "gitea@sbruder.de";
|
|
|
|
USER = "gitea@sbruder.de";
|
|
|
|
};
|
|
|
|
avatar = {
|
|
|
|
DISABLE_GRAVATAR = true;
|
|
|
|
};
|
|
|
|
server = {
|
2023-05-30 11:51:53 +02:00
|
|
|
# http server
|
|
|
|
DOMAIN = "git.sbruder.de";
|
|
|
|
PROTOCOL = "http+unix";
|
|
|
|
ROOT_URL = "https://git.sbruder.de/";
|
|
|
|
|
2021-02-21 13:04:36 +01:00
|
|
|
# privacy
|
|
|
|
DISABLE_ROUTER_LOG = true;
|
|
|
|
OFFLINE_MODE = true;
|
|
|
|
|
|
|
|
# internal ssh server
|
|
|
|
BUILTIN_SSH_SERVER_USER = "git";
|
|
|
|
START_SSH_SERVER = true;
|
2022-12-10 15:15:11 +01:00
|
|
|
SSH_PORT = 2022;
|
2021-04-04 11:18:34 +02:00
|
|
|
SSH_SERVER_HOST_KEYS = "ssh/gitea.ed25519,ssh/gitea.rsa";
|
2021-02-21 13:04:36 +01:00
|
|
|
};
|
|
|
|
service = {
|
2023-10-08 21:36:33 +02:00
|
|
|
DEFAULT_ALLOW_CREATE_ORGANIZATION = false;
|
2021-02-21 13:04:36 +01:00
|
|
|
DEFAULT_KEEP_EMAIL_PRIVATE = true;
|
|
|
|
ENABLE_NOTIFY_MAIL = true;
|
|
|
|
NO_REPLY_ADDRESS = "users.git.sbruder.de";
|
|
|
|
REGISTER_EMAIL_CONFIRM = true;
|
|
|
|
};
|
2021-04-19 14:35:42 +02:00
|
|
|
session = {
|
|
|
|
PROVIDER = "file";
|
2022-12-10 15:15:11 +01:00
|
|
|
COOKIE_SECURE = true;
|
|
|
|
};
|
|
|
|
log = {
|
|
|
|
LEVEL = "Warn";
|
2021-04-19 14:35:42 +02:00
|
|
|
};
|
2021-02-21 13:04:36 +01:00
|
|
|
};
|
|
|
|
};
|
|
|
|
|
2022-12-10 15:15:11 +01:00
|
|
|
networking.firewall.allowedTCPPorts = [ cfg.settings.server.SSH_PORT ];
|
2021-02-21 13:04:36 +01:00
|
|
|
|
|
|
|
services.nginx.virtualHosts."git.sbruder.de" = {
|
|
|
|
enableACME = true;
|
|
|
|
forceSSL = true;
|
|
|
|
|
|
|
|
locations."/" = {
|
|
|
|
proxyPass = "http://unix:/run/gitea/gitea.sock";
|
|
|
|
};
|
2022-01-21 18:17:31 +01:00
|
|
|
|
|
|
|
extraConfig = ''
|
|
|
|
client_max_body_size 1G; # Git LFS
|
|
|
|
'';
|
2021-02-21 13:04:36 +01:00
|
|
|
};
|
|
|
|
}
|