2024-03-01 22:15:55 +01:00
|
|
|
{
|
2024-10-23 12:19:46 +02:00
|
|
|
config,
|
|
|
|
pkgs,
|
|
|
|
lib,
|
|
|
|
...
|
|
|
|
}: let
|
|
|
|
domain = "git.sondell.org";
|
|
|
|
# derp = "hi";
|
|
|
|
in {
|
2024-03-01 22:15:55 +01:00
|
|
|
services.forgejo = {
|
|
|
|
enable = true;
|
2024-04-30 10:37:55 +02:00
|
|
|
stateDir = "/pool/var/lib/forgejo";
|
2024-03-01 22:15:55 +01:00
|
|
|
settings = {
|
|
|
|
service = {
|
2024-10-23 12:19:46 +02:00
|
|
|
DISABLE_REGISTRATION = true;
|
2024-03-01 22:15:55 +01:00
|
|
|
};
|
|
|
|
server = {
|
|
|
|
ROOT_URL = "https://${domain}/";
|
|
|
|
LANDING_PAGE = "explore";
|
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
2025-01-07 12:17:50 +01:00
|
|
|
services.restic.backups = {
|
|
|
|
"forgejo" = {
|
|
|
|
passwordFile = "/etc/nixos/.secrets/restic_pw";
|
|
|
|
repository = "sftp:Glenn@nas:/home/back/vaultwarden/restic";
|
|
|
|
initialize = true;
|
|
|
|
paths = [
|
|
|
|
"/var/lib/forgejo"
|
|
|
|
];
|
|
|
|
user = "root";
|
|
|
|
timerConfig.OnCalendar = "02:05";
|
|
|
|
pruneOpts = [
|
|
|
|
"--keep-daily 10"
|
|
|
|
"--keep-weekly 5"
|
|
|
|
"--keep-monthly 12"
|
|
|
|
"--keep-yearly 75"
|
|
|
|
];
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
2024-10-23 12:19:46 +02:00
|
|
|
environment.systemPackages = let
|
|
|
|
cfg = config.services.forgejo;
|
|
|
|
forgejo-cli = pkgs.writeScriptBin "forgejo-cli" ''
|
|
|
|
#!${pkgs.runtimeShell}
|
|
|
|
cd ${cfg.stateDir}
|
|
|
|
sudo=exec
|
|
|
|
if [[ "$USER" != forgejo ]]; then
|
|
|
|
sudo='exec /run/wrappers/bin/sudo -u ${cfg.user} -g ${cfg.group} --preserve-env=GITEA_WORK_DIR --preserve-env=GITEA_CUSTOM'
|
|
|
|
fi
|
|
|
|
# Note that these variable names will change
|
|
|
|
export GITEA_WORK_DIR=${cfg.stateDir}
|
|
|
|
export GITEA_CUSTOM=${cfg.customDir}
|
|
|
|
$sudo ${lib.getExe cfg.package} "$@"
|
|
|
|
'';
|
|
|
|
in [
|
|
|
|
forgejo-cli
|
|
|
|
];
|
|
|
|
|
2024-03-01 22:15:55 +01:00
|
|
|
services.nginx = {
|
|
|
|
appendHttpConfig = ''
|
|
|
|
map $uri $forgejo_access_log {
|
|
|
|
default 1;
|
|
|
|
/api/actions/runner.v1.RunnerService/FetchTask 0;
|
|
|
|
}
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
services.nginx.virtualHosts.${domain} = {
|
|
|
|
locations."/" = {
|
|
|
|
proxyPass = "http://localhost:3000/";
|
|
|
|
};
|
|
|
|
};
|
|
|
|
}
|