diff --git a/1744358421_2025_04_11_17.9.2_gitlab_backup.tar b/1744358421_2025_04_11_17.9.2_gitlab_backup.tar deleted file mode 100644 index bc95213..0000000 Binary files a/1744358421_2025_04_11_17.9.2_gitlab_backup.tar and /dev/null differ diff --git a/flake.lock b/flake.lock index 2f94029..190e280 100644 --- a/flake.lock +++ b/flake.lock @@ -616,11 +616,11 @@ }, "nixunstable": { "locked": { - "lastModified": 1744098102, - "narHash": "sha256-tzCdyIJj9AjysC3OuKA+tMD/kDEDAF9mICPDU7ix0JA=", + "lastModified": 1744463964, + "narHash": "sha256-LWqduOgLHCFxiTNYi3Uj5Lgz0SR+Xhw3kr/3Xd0GPTM=", "owner": "nixos", "repo": "nixpkgs", - "rev": "c8cd81426f45942bb2906d5ed2fe21d2f19d95b7", + "rev": "2631b0b7abcea6e640ce31cd78ea58910d31e650", "type": "github" }, "original": { diff --git a/hosts/default.nix b/hosts/default.nix index 7be170f..2f6577a 100644 --- a/hosts/default.nix +++ b/hosts/default.nix @@ -64,6 +64,7 @@ rec { jeremiah = unstable { name = "jeremiah"; }; isaiah = unstable { name = "isaiah"; }; + vm-gitlab = vm { name = "vm-gitlab"; }; vm-jellyfin = vm { name = "vm-jellyfin"; }; jellyfin = vm-jellyfin; vm-matrix = vm { name = "vm-matrix"; }; diff --git a/hosts/vm-gitlab/default.nix b/hosts/vm-gitlab/default.nix new file mode 100644 index 0000000..e009c2d --- /dev/null +++ b/hosts/vm-gitlab/default.nix @@ -0,0 +1,256 @@ +# Edit this configuration file to define what should be installed on +# your system. Help is available in the configuration.nix(5) man page +# and in the NixOS manual (accessible by running ‘nixos-help’). + +{ + config, + pkgs, + lib, + ... +}: + +let + registryPort = 5000; + vpnIp = "100.91.131.66"; + containerIp = "192.168.200.2"; +in +{ + imports = + [ # Include the results of the hardware scan. + ./hardware-configuration.nix + ]; + + age.secrets = + let + cfg = n: { + file = ../../secrets/gitlab/${n}.age; + owner = "gitlab"; + group = "gitlab"; + mode = "0444"; + }; + in + { + gitlab-secret = cfg "secret"; + gitlab-otp = cfg "otp"; + gitlab-db = cfg "db"; + gitlab-jws = cfg "jws"; + gitlab-key = cfg "key"; + gitlab-cert = cfg "cert"; + + minio_access_key_id = { + file = ../../secrets/minio_access_key_id.age; + owner = "gitlab"; + group = "gitlab"; + mode = "0444"; + }; + minio_secret_access_key = { + file = ../../secrets/minio_secret_access_key.age; + owner = "gitlab"; + group = "gitlab"; + mode = "0444"; + }; + }; + + greg.proxies = + let + t = { + target = "http://unix:/run/gitlab/gitlab-workhorse.socket"; + extraConfig = '' + proxy_set_header X-Forwarded-Proto https; + proxy_set_header X-Forwarded-Ssl on; + client_max_body_size 10000m; + ''; + }; + in + { + "${containerIp}" = t; + "${vpnIp}" = t; + "git.thehellings.lan" = t; + }; + + greg.backup.jobs.nas-backup = { + src = "/var/gitlab/state/backup/"; + dest = "gitlab"; + id = "container-gitlab"; + }; + + greg = { + home = true; + tailscale.enable = true; + }; + + + networking = { + hostName = "vm-gitlab"; # Define your hostname. + firewall.allowedTCPPorts = [ + 80 + registryPort + ]; + }; + + services = { + # Fetch the SSL certificates for nginx to use + cron = { + enable = true; + systemCronJobs = [ + "0 0 1 */2 * cd /etc/certs && tailscale cert gitlab.shire-zebra.ts.net && chown nginx * && systemctl reload nginx" + ]; + }; + + gitlab = { + enable = true; + backup = { + keepTime = 288; + startAt = [ "03:00" ]; + }; + host = "src.thehellings.com"; + https = true; + port = 443; + extraConfig = { + gitlab = { + trustedProxies = [ + "${vpnIp}/32" # The container itself + "100.115.57.8/32" # Public server's IP + ]; + }; + }; + initialRootEmail = "greg@thehellings.com"; + initialRootPasswordFile = pkgs.writeText "initialRootPassword" "root_password"; + pages = { + enable = true; + settings.pages-domain = "pages.thehellings.com"; + }; + puma = { + threadsMax = 6; + threadsMin = 2; + workers = 6; + }; + redisUrl = "unix:${config.services.redis.servers.gitlab.unixSocket}"; + registry = { + enable = true; + certFile = config.age.secrets.gitlab-cert.path; + keyFile = config.age.secrets.gitlab-key.path; + externalAddress = "registry.thehellings.com"; + externalPort = 443; + }; + secrets = { + secretFile = config.age.secrets.gitlab-secret.path; + otpFile = config.age.secrets.gitlab-otp.path; + dbFile = config.age.secrets.gitlab-db.path; + jwsFile = config.age.secrets.gitlab-jws.path; + }; + + extraConfig = { + object_store = { + enabled = true; + proxy_download = true; # Tell them to reach out to object storage themselves! + connection = { + provider = "AWS"; + endpoint = "http://s3.thehellings.lan:9000"; + region = "us-east-1"; + aws_access_key_id = { + _secret = config.age.secrets.minio_access_key_id.path; + }; + aws_secret_access_key = { + _secret = config.age.secrets.minio_secret_access_key.path; + }; + path_style = true; # True for MinIO + aws_signature_version = 2; + }; + #storage_options = ...; + objects = builtins.listToAttrs ( + builtins.map + ( + x: lib.attrsets.nameValuePair x { bucket = "gitlab-${builtins.replaceStrings [ "_" ] [ "-" ] x}"; } + ) + [ + "artifacts" + "ci_secure_files" + "dependency_proxy" + "external_diffs" + "lfs" + "packages" + "pages" + "terraform_state" + "uploads" + ] + ); + }; + }; + }; + + nginx = { + clientMaxBodySize = "25000m"; + virtualHosts."gitlab.shire-zebra.ts.net" = { + listen = [ + { + addr = "0.0.0.0"; + port = registryPort; + ssl = true; + } + ]; + locations."/" = { + proxyPass = "http://127.0.0.1:4567/"; + recommendedProxySettings = true; + }; + extraConfig = '' + ssl_certificate /etc/certs/gitlab.shire-zebra.ts.net.crt ; + ssl_certificate_key /etc/certs/gitlab.shire-zebra.ts.net.key ; + client_max_body_size 10000m ; + ''; + }; + }; + + openssh.enable = true; + + logrotate = { + enable = true; + settings = { + "/var/lib/postgresql/*/log/*.log" = { + enable = true; + compress = true; + compresscmd = "${pkgs.xz}/bin/xz"; + }; + }; + }; + + postgresql = { + enable = true; + checkConfig = true; + ensureDatabases = [ "gitlab" ]; + ensureUsers = [ + { + name = "gitlab"; + ensureDBOwnership = true; + } + ]; + settings = { + log_connections = true; + log_statement = "all"; + logging_collector = true; + log_filename = "postgresql.log"; + }; + }; + + redis.servers.gitlab = { + enable = true; + }; + resolved.enable = true; + }; + + # Do not start nginx until we have tailscaled up and running, so it can bind + # to the 100.* addresses + systemd.services = { + nginx = rec { + after = [ "network-online.target" ]; + requires = [ "network-online.target" ]; + wants = after; + serviceConfig = { + RestartMaxDelaySec = "30s"; + RestartSteps = "5"; + }; + }; + tailscaled.partOf = [ "network-online.target" ]; + }; + system.stateVersion = lib.mkForce "24.11"; +} diff --git a/hosts/vm-gitlab/hardware-configuration.nix b/hosts/vm-gitlab/hardware-configuration.nix new file mode 100644 index 0000000..dd7e4cf --- /dev/null +++ b/hosts/vm-gitlab/hardware-configuration.nix @@ -0,0 +1,45 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + +{ + imports = + [ (modulesPath + "/profiles/qemu-guest.nix") + ]; + + # Bootloader. + boot = { + extraModulePackages = [ ]; + initrd = { + availableKernelModules = [ "uhci_hcd" "ehci_pci" "ahci" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ]; + kernelModules = [ ]; + }; + loader = { + efi.canTouchEfiVariables = true; + systemd-boot.enable = true; + }; + }; + + fileSystems."/" = + { device = "/dev/disk/by-uuid/507251f1-efe7-448d-8de8-91ee582a9afb"; + fsType = "ext4"; + }; + + fileSystems."/boot" = + { device = "/dev/disk/by-uuid/7115-EFA6"; + fsType = "vfat"; + options = [ "fmask=0077" "dmask=0077" ]; + }; + + swapDevices = [ ]; + + # Enables DHCP on each ethernet and wireless interface. In case of scripted networking + # (the default) this is the recommended approach. When using systemd-networkd it's + # still possible to use this option, but it's recommended to use it in conjunction + # with explicit per-interface declarations with `networking.interfaces..useDHCP`. + networking.useDHCP = lib.mkDefault true; + # networking.interfaces.enp6s18.useDHCP = lib.mkDefault true; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; +}