Setup gitlab on VM

Move GitLab to the VM
Slight tweaks to the configuration to make it better (such as binding to
0.0.0.0 for Nginx)
This commit is contained in:
Greg Hellings
2025-04-14 17:55:07 -05:00
parent a56077efca
commit 8a0a386ae6
5 changed files with 305 additions and 3 deletions
Binary file not shown.
Generated
+3 -3
View File
@@ -616,11 +616,11 @@
},
"nixunstable": {
"locked": {
"lastModified": 1744098102,
"narHash": "sha256-tzCdyIJj9AjysC3OuKA+tMD/kDEDAF9mICPDU7ix0JA=",
"lastModified": 1744463964,
"narHash": "sha256-LWqduOgLHCFxiTNYi3Uj5Lgz0SR+Xhw3kr/3Xd0GPTM=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "c8cd81426f45942bb2906d5ed2fe21d2f19d95b7",
"rev": "2631b0b7abcea6e640ce31cd78ea58910d31e650",
"type": "github"
},
"original": {
+1
View File
@@ -64,6 +64,7 @@ rec {
jeremiah = unstable { name = "jeremiah"; };
isaiah = unstable { name = "isaiah"; };
vm-gitlab = vm { name = "vm-gitlab"; };
vm-jellyfin = vm { name = "vm-jellyfin"; };
jellyfin = vm-jellyfin;
vm-matrix = vm { name = "vm-matrix"; };
+256
View File
@@ -0,0 +1,256 @@
# Edit this configuration file to define what should be installed on
# your system. Help is available in the configuration.nix(5) man page
# and in the NixOS manual (accessible by running nixos-help).
{
config,
pkgs,
lib,
...
}:
let
registryPort = 5000;
vpnIp = "100.91.131.66";
containerIp = "192.168.200.2";
in
{
imports =
[ # Include the results of the hardware scan.
./hardware-configuration.nix
];
age.secrets =
let
cfg = n: {
file = ../../secrets/gitlab/${n}.age;
owner = "gitlab";
group = "gitlab";
mode = "0444";
};
in
{
gitlab-secret = cfg "secret";
gitlab-otp = cfg "otp";
gitlab-db = cfg "db";
gitlab-jws = cfg "jws";
gitlab-key = cfg "key";
gitlab-cert = cfg "cert";
minio_access_key_id = {
file = ../../secrets/minio_access_key_id.age;
owner = "gitlab";
group = "gitlab";
mode = "0444";
};
minio_secret_access_key = {
file = ../../secrets/minio_secret_access_key.age;
owner = "gitlab";
group = "gitlab";
mode = "0444";
};
};
greg.proxies =
let
t = {
target = "http://unix:/run/gitlab/gitlab-workhorse.socket";
extraConfig = ''
proxy_set_header X-Forwarded-Proto https;
proxy_set_header X-Forwarded-Ssl on;
client_max_body_size 10000m;
'';
};
in
{
"${containerIp}" = t;
"${vpnIp}" = t;
"git.thehellings.lan" = t;
};
greg.backup.jobs.nas-backup = {
src = "/var/gitlab/state/backup/";
dest = "gitlab";
id = "container-gitlab";
};
greg = {
home = true;
tailscale.enable = true;
};
networking = {
hostName = "vm-gitlab"; # Define your hostname.
firewall.allowedTCPPorts = [
80
registryPort
];
};
services = {
# Fetch the SSL certificates for nginx to use
cron = {
enable = true;
systemCronJobs = [
"0 0 1 */2 * cd /etc/certs && tailscale cert gitlab.shire-zebra.ts.net && chown nginx * && systemctl reload nginx"
];
};
gitlab = {
enable = true;
backup = {
keepTime = 288;
startAt = [ "03:00" ];
};
host = "src.thehellings.com";
https = true;
port = 443;
extraConfig = {
gitlab = {
trustedProxies = [
"${vpnIp}/32" # The container itself
"100.115.57.8/32" # Public server's IP
];
};
};
initialRootEmail = "greg@thehellings.com";
initialRootPasswordFile = pkgs.writeText "initialRootPassword" "root_password";
pages = {
enable = true;
settings.pages-domain = "pages.thehellings.com";
};
puma = {
threadsMax = 6;
threadsMin = 2;
workers = 6;
};
redisUrl = "unix:${config.services.redis.servers.gitlab.unixSocket}";
registry = {
enable = true;
certFile = config.age.secrets.gitlab-cert.path;
keyFile = config.age.secrets.gitlab-key.path;
externalAddress = "registry.thehellings.com";
externalPort = 443;
};
secrets = {
secretFile = config.age.secrets.gitlab-secret.path;
otpFile = config.age.secrets.gitlab-otp.path;
dbFile = config.age.secrets.gitlab-db.path;
jwsFile = config.age.secrets.gitlab-jws.path;
};
extraConfig = {
object_store = {
enabled = true;
proxy_download = true; # Tell them to reach out to object storage themselves!
connection = {
provider = "AWS";
endpoint = "http://s3.thehellings.lan:9000";
region = "us-east-1";
aws_access_key_id = {
_secret = config.age.secrets.minio_access_key_id.path;
};
aws_secret_access_key = {
_secret = config.age.secrets.minio_secret_access_key.path;
};
path_style = true; # True for MinIO
aws_signature_version = 2;
};
#storage_options = ...;
objects = builtins.listToAttrs (
builtins.map
(
x: lib.attrsets.nameValuePair x { bucket = "gitlab-${builtins.replaceStrings [ "_" ] [ "-" ] x}"; }
)
[
"artifacts"
"ci_secure_files"
"dependency_proxy"
"external_diffs"
"lfs"
"packages"
"pages"
"terraform_state"
"uploads"
]
);
};
};
};
nginx = {
clientMaxBodySize = "25000m";
virtualHosts."gitlab.shire-zebra.ts.net" = {
listen = [
{
addr = "0.0.0.0";
port = registryPort;
ssl = true;
}
];
locations."/" = {
proxyPass = "http://127.0.0.1:4567/";
recommendedProxySettings = true;
};
extraConfig = ''
ssl_certificate /etc/certs/gitlab.shire-zebra.ts.net.crt ;
ssl_certificate_key /etc/certs/gitlab.shire-zebra.ts.net.key ;
client_max_body_size 10000m ;
'';
};
};
openssh.enable = true;
logrotate = {
enable = true;
settings = {
"/var/lib/postgresql/*/log/*.log" = {
enable = true;
compress = true;
compresscmd = "${pkgs.xz}/bin/xz";
};
};
};
postgresql = {
enable = true;
checkConfig = true;
ensureDatabases = [ "gitlab" ];
ensureUsers = [
{
name = "gitlab";
ensureDBOwnership = true;
}
];
settings = {
log_connections = true;
log_statement = "all";
logging_collector = true;
log_filename = "postgresql.log";
};
};
redis.servers.gitlab = {
enable = true;
};
resolved.enable = true;
};
# Do not start nginx until we have tailscaled up and running, so it can bind
# to the 100.* addresses
systemd.services = {
nginx = rec {
after = [ "network-online.target" ];
requires = [ "network-online.target" ];
wants = after;
serviceConfig = {
RestartMaxDelaySec = "30s";
RestartSteps = "5";
};
};
tailscaled.partOf = [ "network-online.target" ];
};
system.stateVersion = lib.mkForce "24.11";
}
@@ -0,0 +1,45 @@
# Do not modify this file! It was generated by nixos-generate-config
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{ config, lib, pkgs, modulesPath, ... }:
{
imports =
[ (modulesPath + "/profiles/qemu-guest.nix")
];
# Bootloader.
boot = {
extraModulePackages = [ ];
initrd = {
availableKernelModules = [ "uhci_hcd" "ehci_pci" "ahci" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ];
kernelModules = [ ];
};
loader = {
efi.canTouchEfiVariables = true;
systemd-boot.enable = true;
};
};
fileSystems."/" =
{ device = "/dev/disk/by-uuid/507251f1-efe7-448d-8de8-91ee582a9afb";
fsType = "ext4";
};
fileSystems."/boot" =
{ device = "/dev/disk/by-uuid/7115-EFA6";
fsType = "vfat";
options = [ "fmask=0077" "dmask=0077" ];
};
swapDevices = [ ];
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's
# still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true;
# networking.interfaces.enp6s18.useDHCP = lib.mkDefault true;
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
}