Tell Gitlab to use Minio
This commit is contained in:
@@ -13,6 +13,19 @@ in {
|
|||||||
gitlab-jws = cfg "jws";
|
gitlab-jws = cfg "jws";
|
||||||
gitlab-key = cfg "key";
|
gitlab-key = cfg "key";
|
||||||
gitlab-cert = cfg "cert";
|
gitlab-cert = cfg "cert";
|
||||||
|
|
||||||
|
minio_access_key_id = {
|
||||||
|
file = ../../secrets/minio_access_key_id.age;
|
||||||
|
owner = "gitlab";
|
||||||
|
group = "gitlab";
|
||||||
|
mode = "0444";
|
||||||
|
};
|
||||||
|
minio_secret_access_key = {
|
||||||
|
file = ../../secrets/minio_secret_access_key.age;
|
||||||
|
owner = "gitlab";
|
||||||
|
group = "gitlab";
|
||||||
|
mode = "0444";
|
||||||
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
networking.firewall.allowedTCPPorts = [ 80 registryPort ];
|
networking.firewall.allowedTCPPorts = [ 80 registryPort ];
|
||||||
@@ -86,6 +99,34 @@ in {
|
|||||||
dbFile = config.age.secrets.gitlab-db.path;
|
dbFile = config.age.secrets.gitlab-db.path;
|
||||||
jwsFile = config.age.secrets.gitlab-jws.path;
|
jwsFile = config.age.secrets.gitlab-jws.path;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
extraConfig = {
|
||||||
|
object_store = {
|
||||||
|
enabled = true;
|
||||||
|
proxy_download = false; # Tell them to reach out to object storage themselves!
|
||||||
|
connection = {
|
||||||
|
provider = "AWS";
|
||||||
|
endpoint = "http://s3.thehellings.lan:9000";
|
||||||
|
region = "us-east-1";
|
||||||
|
aws_access_key_id = { _secret = config.age.secrets.minio_access_key_id.path; };
|
||||||
|
aws_secret_access_key = { _secret = config.age.secrets.minio_secret_access_key.path; };
|
||||||
|
path_style = true; # True for MinIO
|
||||||
|
aws_signature_version = 2;
|
||||||
|
};
|
||||||
|
#storage_options = ...;
|
||||||
|
objects = builtins.listToAttrs ( builtins.map (x: lib.attrsets.nameValuePair x { bucket = "gitlab-${builtins.replaceStrings [ "_" ] [ "-" ] x}"; }) [
|
||||||
|
"artifacts"
|
||||||
|
"ci_secure_files"
|
||||||
|
"dependency_proxy"
|
||||||
|
"external_diffs"
|
||||||
|
"lfs"
|
||||||
|
"packages"
|
||||||
|
"pages"
|
||||||
|
"terraform_state"
|
||||||
|
"uploads"
|
||||||
|
]);
|
||||||
|
};
|
||||||
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
nginx.virtualHosts."gitlab.shire-zebra.ts.net" = {
|
nginx.virtualHosts."gitlab.shire-zebra.ts.net" = {
|
||||||
@@ -147,6 +188,9 @@ in {
|
|||||||
"network.target"
|
"network.target"
|
||||||
"network-online.target"
|
"network-online.target"
|
||||||
];
|
];
|
||||||
|
preStart = ''
|
||||||
|
sleep 5 # tailscaled is up before it's ACTUALLY up... try waiting?
|
||||||
|
'';
|
||||||
};
|
};
|
||||||
system.stateVersion = lib.mkForce "24.05";
|
system.stateVersion = lib.mkForce "24.05";
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -65,6 +65,7 @@ in {
|
|||||||
config = ((import ./container-runner.nix) {
|
config = ((import ./container-runner.nix) {
|
||||||
inherit inputs overlays;
|
inherit inputs overlays;
|
||||||
name = "shell";
|
name = "shell";
|
||||||
|
extra.virtualisation.podman.enable = true;
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -96,13 +97,13 @@ in {
|
|||||||
"koalaman/shellcheck:*"
|
"koalaman/shellcheck:*"
|
||||||
|
|
||||||
"registry.gitlab.com/gitlab-org/*"
|
"registry.gitlab.com/gitlab-org/*"
|
||||||
"registry.thehellings.com/*"
|
"registry.thehellings.com/*/*/*:*"
|
||||||
"gitlab.shire-zebra.ts.net:5000/*:*"
|
"gitlab.shire-zebra.ts.net:5000/*/*/*:*"
|
||||||
];
|
];
|
||||||
dockerAllowedServices = [
|
dockerAllowedServices = [
|
||||||
"docker:*"
|
"docker:*"
|
||||||
"registry.thehellings.com/*"
|
"registry.thehellings.com/*/*/*:*"
|
||||||
"gitlab.shire-zebra.ts.net:5000/*:*"
|
"gitlab.shire-zebra.ts.net:5000/*/*/*:*"
|
||||||
];
|
];
|
||||||
dockerPrivileged = true;
|
dockerPrivileged = true;
|
||||||
dockerVolumes = [
|
dockerVolumes = [
|
||||||
|
|||||||
Reference in New Issue
Block a user