diff --git a/home/default.nix b/home/default.nix index 504e188..0de9f49 100644 --- a/home/default.nix +++ b/home/default.nix @@ -36,4 +36,5 @@ in jude = greg "jude"; isaiah = greg "isaiah"; jeremiah = greg "jeremiah"; + vm-gitlab = greg "vm-gitlab"; } diff --git a/hosts/linode/git.nix b/hosts/linode/git.nix index fdb2b41..e92d052 100644 --- a/hosts/linode/git.nix +++ b/hosts/linode/git.nix @@ -6,7 +6,7 @@ let in { greg.proxies."${srcDomain}" = { - target = "http://git.thehellings.lan"; + target = "http://vm-gitlab.shire-zebra.ts.net"; ssl = true; genAliases = false; extraConfig = '' @@ -16,7 +16,7 @@ in ''; }; greg.proxies."registry.thehellings.com" = { - target = "https://registry.thehellings.lan:5000"; + target = "https://vm-gitlab.shire-zebra.ts.net:5000"; ssl = true; genAliases = false; extraConfig = "client_max_body_size 25000m;"; @@ -44,7 +44,7 @@ in " bind *:${toString sshPort}" " timeout client 1h" " mode tcp" - " server git-thehellings-lan git.thehellings.lan:22" + " server git-thehellings-lan vm-gitlab.shire-zebra.ts.net:22" ]; }; } diff --git a/hosts/vm-gitlab/default.nix b/hosts/vm-gitlab/default.nix index 0c4a31d..c39c78b 100644 --- a/hosts/vm-gitlab/default.nix +++ b/hosts/vm-gitlab/default.nix @@ -11,12 +11,10 @@ let registryPort = 5000; - vpnIp = "100.91.131.66"; - containerIp = "192.168.200.2"; + vpnIp = "100.117.28.111"; in { imports = [ - # Include the results of the hardware scan. ./hardware-configuration.nix ]; @@ -33,6 +31,7 @@ in gitlab-secret = cfg "secret"; gitlab-otp = cfg "otp"; gitlab-db = cfg "db"; + gitlab-db-password = cfg "db-password"; gitlab-jws = cfg "jws"; gitlab-key = cfg "key"; gitlab-cert = cfg "cert"; @@ -54,30 +53,12 @@ in }; }; - greg.proxies = - let - t = { - target = "http://unix:/run/gitlab/gitlab-workhorse.socket"; - extraConfig = '' - proxy_set_header X-Forwarded-Proto https; - proxy_set_header X-Forwarded-Ssl on; - client_max_body_size 10000m; - ''; - }; - in - { - "${containerIp}" = t; - "${vpnIp}" = t; - "git.thehellings.lan" = t; - }; - - greg.backup.jobs.nas-backup = { - src = "/var/gitlab/state/backup/"; - dest = "gitlab"; - id = "container-gitlab"; - }; - greg = { + backup.jobs.nas-backup = { + src = "/var/gitlab/state/backup/"; + dest = "gitlab"; + id = "container-gitlab"; + }; home = true; tailscale.enable = true; }; @@ -95,7 +76,7 @@ in cron = { enable = true; systemCronJobs = [ - "0 0 1 */2 * cd /etc/certs && tailscale cert gitlab.shire-zebra.ts.net && chown nginx * && systemctl reload nginx" + "0 0 1 */2 * cd /etc/certs && tailscale cert vm-gitlab.shire-zebra.ts.net && chown nginx * && systemctl reload nginx" ]; }; @@ -105,47 +86,18 @@ in keepTime = 288; startAt = [ "03:00" ]; }; - host = "src.thehellings.com"; - https = true; - port = 443; + databaseHost = "postgres.kubernetes"; + databaseName = "gitlab"; + databaseUsername = "gitlab"; + databasePasswordFile = config.age.secrets.gitlab-db-password.path; + databaseCreateLocally = false; extraConfig = { gitlab = { trustedProxies = [ - "${vpnIp}/32" # The container itself - "100.115.57.8/32" # Public server's IP + "${vpnIp}/32" # The system itself + "100.109.86.8/32" # Public server's IP ]; }; - }; - initialRootEmail = "greg@thehellings.com"; - initialRootPasswordFile = pkgs.writeText "initialRootPassword" "root_password"; - pages = { - enable = true; - settings.pages-domain = "pages.thehellings.com"; - }; - puma = { - threadsMax = 6; - threadsMin = 2; - workers = 6; - }; - redisUrl = "unix:${config.services.redis.servers.gitlab.unixSocket}"; - registry = { - enable = true; - certFile = config.age.secrets.gitlab-cert.path; - keyFile = config.age.secrets.gitlab-key.path; - externalAddress = "registry.thehellings.com"; - externalPort = 443; - }; - secrets = { - activeRecordDeterministicKeyFile = config.age.secrets.gitlab-deterministic-key.path; - activeRecordPrimaryKeyFile = config.age.secrets.gitlab-primary-key.path; - activeRecordSaltFile = config.age.secrets.gitlab-salt.path; - dbFile = config.age.secrets.gitlab-db.path; - jwsFile = config.age.secrets.gitlab-jws.path; - otpFile = config.age.secrets.gitlab-otp.path; - secretFile = config.age.secrets.gitlab-secret.path; - }; - - extraConfig = { object_store = { enabled = true; proxy_download = true; # Tell them to reach out to object storage themselves! @@ -182,66 +134,78 @@ in ); }; }; + host = "src.thehellings.com"; + https = true; + initialRootEmail = "greg@thehellings.com"; + initialRootPasswordFile = pkgs.writeText "initialRootPassword" "root_password"; + pages = { + enable = true; + settings.pages-domain = "pages.thehellings.com"; + }; + port = 443; + puma = { + threadsMax = 6; + threadsMin = 2; + workers = 6; + }; + redisUrl = "unix:${config.services.redis.servers.gitlab.unixSocket}"; + registry = { + enable = true; + certFile = config.age.secrets.gitlab-cert.path; + keyFile = config.age.secrets.gitlab-key.path; + externalAddress = "registry.thehellings.com"; + externalPort = 443; + }; + secrets = { + activeRecordDeterministicKeyFile = config.age.secrets.gitlab-deterministic-key.path; + activeRecordPrimaryKeyFile = config.age.secrets.gitlab-primary-key.path; + activeRecordSaltFile = config.age.secrets.gitlab-salt.path; + dbFile = config.age.secrets.gitlab-db.path; + jwsFile = config.age.secrets.gitlab-jws.path; + otpFile = config.age.secrets.gitlab-otp.path; + secretFile = config.age.secrets.gitlab-secret.path; + }; }; nginx = { + enable = true; clientMaxBodySize = "25000m"; - virtualHosts."gitlab.shire-zebra.ts.net" = { + virtualHosts."vm-gitlab.shire-zebra.ts.net" = { listen = [ { addr = "0.0.0.0"; port = registryPort; ssl = true; } + { + addr = "0.0.0.0"; + port = 443; + ssl = true; + } ]; locations."/" = { - proxyPass = "http://127.0.0.1:4567/"; + proxyPass = "http://unix:/run/gitlab/gitlab-workhorse.socket"; + #proxyPass = "http://127.0.0.1:4567/"; recommendedProxySettings = true; }; extraConfig = '' - ssl_certificate /etc/certs/gitlab.shire-zebra.ts.net.crt ; - ssl_certificate_key /etc/certs/gitlab.shire-zebra.ts.net.key ; + ssl_certificate /etc/certs/vm-gitlab.shire-zebra.ts.net.crt ; + ssl_certificate_key /etc/certs/vm-gitlab.shire-zebra.ts.net.key ; client_max_body_size 10000m ; ''; }; }; - logrotate = { - enable = true; - settings = { - "/var/lib/postgresql/*/log/*.log" = { - enable = true; - compress = true; - compresscmd = "${pkgs.xz}/bin/xz"; - }; - }; - }; - openssh.enable = true; - postgresql = { - enable = true; - checkConfig = true; - ensureDatabases = [ "gitlab" ]; - ensureUsers = [ - { - name = "gitlab"; - ensureDBOwnership = true; - } - ]; - settings = { - log_connections = true; - log_statement = "all"; - logging_collector = true; - log_filename = "postgresql.log"; - }; - }; + postgresql.enable = true; qemuGuest.enable = true; redis.servers.gitlab = { enable = true; }; + resolved.enable = true; }; diff --git a/hosts/vm-gitlab/hardware-configuration.nix b/hosts/vm-gitlab/hardware-configuration.nix index a945d9f..ae1216c 100644 --- a/hosts/vm-gitlab/hardware-configuration.nix +++ b/hosts/vm-gitlab/hardware-configuration.nix @@ -34,12 +34,12 @@ }; fileSystems."/" = { - device = "/dev/disk/by-uuid/507251f1-efe7-448d-8de8-91ee582a9afb"; + device = "/dev/disk/by-uuid/1fdbe86e-ce6f-4af3-a876-aec35731adab"; fsType = "ext4"; }; fileSystems."/boot" = { - device = "/dev/disk/by-uuid/7115-EFA6"; + device = "/dev/disk/by-uuid/1E6A-C3BB"; fsType = "vfat"; options = [ "fmask=0077" diff --git a/modules/nix-conf.nix b/modules/nix-conf.nix index 4b4b27c..0d5d7c8 100644 --- a/modules/nix-conf.nix +++ b/modules/nix-conf.nix @@ -41,8 +41,7 @@ in ]; # For home and for work machines substituters = (lib.optionals cfg.cache [ - "http://nas.thehellings.lan:9000/binary-cache/" - "http://nas.home:9000/binary-cache/" + "http://chronicles.shire-zebra.ts.net:9000/binary-cache/" ]) ++ [ "https://ai.cachix.org" @@ -52,8 +51,7 @@ in "https://cache.nixos.org" ]; trusted-public-keys = [ - "nix.thehellings.lan:0qWYHn3gGllXChhAaaxKlNZtRy6yG/XJs1RFSqV3nW8=" - "nix.home:0qWYHn3gGllXChhAaaxKlNZtRy6yG/XJs1RFSqV3nW8=" + "chronicles.shire-zebra.ts.net:0qWYHn3gGllXChhAaaxKlNZtRy6yG/XJs1RFSqV3nW8=" "ai.cachix.org-1:N9dzRK+alWwoKXQlnn0H6aUx0lU/mspIoz8hMvGvbbc=" "nixpkgs-python.cachix.org-1:hxjI7pFxTyuTHn2NkvWCrAUcNZLNS3ZAvfYNuYifcEU=" "greg-hellings.cachix.org-1:y01Jl/L5evlhxdnUW6n56AiI1k8g1wxWhTxJCe7XSco=" diff --git a/secrets/gitlab/db-password.age b/secrets/gitlab/db-password.age new file mode 100644 index 0000000..2deed6a Binary files /dev/null and b/secrets/gitlab/db-password.age differ diff --git a/secrets/secrets.nix b/secrets/secrets.nix index 4e09c95..0282f14 100644 --- a/secrets/secrets.nix +++ b/secrets/secrets.nix @@ -87,6 +87,7 @@ in "gitlab/secret.age".publicKeys = everyone; "gitlab/otp.age".publicKeys = everyone; "gitlab/db.age".publicKeys = everyone; + "gitlab/db-password.age".publicKeys = everyone; "gitlab/jws.age".publicKeys = everyone; # openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.crt -days 365 -nodes -subj '/CN=issuer' # Then pipe the resulting files to agenix -e