From e13bee750cf969f550c245d0cd26226ab16aabf2 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Wed, 11 Jun 2025 21:29:20 -0500 Subject: [PATCH] Make gitlab use remote postgres --- hosts/vm-gitlab/default.nix | 101 +++++++++++++-------------------- secrets/gitlab/db-password.age | Bin 0 -> 2115 bytes secrets/secrets.nix | 1 + 3 files changed, 40 insertions(+), 62 deletions(-) create mode 100644 secrets/gitlab/db-password.age diff --git a/hosts/vm-gitlab/default.nix b/hosts/vm-gitlab/default.nix index 0c4a31d..266e281 100644 --- a/hosts/vm-gitlab/default.nix +++ b/hosts/vm-gitlab/default.nix @@ -33,6 +33,7 @@ in gitlab-secret = cfg "secret"; gitlab-otp = cfg "otp"; gitlab-db = cfg "db"; + gitlab-db-password = cfg "db-password"; gitlab-jws = cfg "jws"; gitlab-key = cfg "key"; gitlab-cert = cfg "cert"; @@ -105,9 +106,11 @@ in keepTime = 288; startAt = [ "03:00" ]; }; - host = "src.thehellings.com"; - https = true; - port = 443; + databaseHost = "postgres.kubernetes"; + databaseName = "gitlab"; + databaseUsername = "gitlab"; + databasePasswordFile = config.age.secrets.gitlab-db-password.path; + databaseCreateLocally = false; extraConfig = { gitlab = { trustedProxies = [ @@ -115,37 +118,6 @@ in "100.115.57.8/32" # Public server's IP ]; }; - }; - initialRootEmail = "greg@thehellings.com"; - initialRootPasswordFile = pkgs.writeText "initialRootPassword" "root_password"; - pages = { - enable = true; - settings.pages-domain = "pages.thehellings.com"; - }; - puma = { - threadsMax = 6; - threadsMin = 2; - workers = 6; - }; - redisUrl = "unix:${config.services.redis.servers.gitlab.unixSocket}"; - registry = { - enable = true; - certFile = config.age.secrets.gitlab-cert.path; - keyFile = config.age.secrets.gitlab-key.path; - externalAddress = "registry.thehellings.com"; - externalPort = 443; - }; - secrets = { - activeRecordDeterministicKeyFile = config.age.secrets.gitlab-deterministic-key.path; - activeRecordPrimaryKeyFile = config.age.secrets.gitlab-primary-key.path; - activeRecordSaltFile = config.age.secrets.gitlab-salt.path; - dbFile = config.age.secrets.gitlab-db.path; - jwsFile = config.age.secrets.gitlab-jws.path; - otpFile = config.age.secrets.gitlab-otp.path; - secretFile = config.age.secrets.gitlab-secret.path; - }; - - extraConfig = { object_store = { enabled = true; proxy_download = true; # Tell them to reach out to object storage themselves! @@ -182,6 +154,37 @@ in ); }; }; + host = "src.thehellings.com"; + https = true; + initialRootEmail = "greg@thehellings.com"; + initialRootPasswordFile = pkgs.writeText "initialRootPassword" "root_password"; + pages = { + enable = true; + settings.pages-domain = "pages.thehellings.com"; + }; + port = 443; + puma = { + threadsMax = 6; + threadsMin = 2; + workers = 6; + }; + redisUrl = "unix:${config.services.redis.servers.gitlab.unixSocket}"; + registry = { + enable = true; + certFile = config.age.secrets.gitlab-cert.path; + keyFile = config.age.secrets.gitlab-key.path; + externalAddress = "registry.thehellings.com"; + externalPort = 443; + }; + secrets = { + activeRecordDeterministicKeyFile = config.age.secrets.gitlab-deterministic-key.path; + activeRecordPrimaryKeyFile = config.age.secrets.gitlab-primary-key.path; + activeRecordSaltFile = config.age.secrets.gitlab-salt.path; + dbFile = config.age.secrets.gitlab-db.path; + jwsFile = config.age.secrets.gitlab-jws.path; + otpFile = config.age.secrets.gitlab-otp.path; + secretFile = config.age.secrets.gitlab-secret.path; + }; }; nginx = { @@ -206,42 +209,16 @@ in }; }; - logrotate = { - enable = true; - settings = { - "/var/lib/postgresql/*/log/*.log" = { - enable = true; - compress = true; - compresscmd = "${pkgs.xz}/bin/xz"; - }; - }; - }; - openssh.enable = true; - postgresql = { - enable = true; - checkConfig = true; - ensureDatabases = [ "gitlab" ]; - ensureUsers = [ - { - name = "gitlab"; - ensureDBOwnership = true; - } - ]; - settings = { - log_connections = true; - log_statement = "all"; - logging_collector = true; - log_filename = "postgresql.log"; - }; - }; + postgresql.enable = true; qemuGuest.enable = true; redis.servers.gitlab = { enable = true; }; + resolved.enable = true; }; diff --git a/secrets/gitlab/db-password.age b/secrets/gitlab/db-password.age new file mode 100644 index 0000000000000000000000000000000000000000..2deed6af3191bdb6abf26392f37657e4daf0a679 GIT binary patch literal 2115 zcmZYAIm`5H6$fw&3z;uq8?mqmx7oKw-XxPu_L*#x#l~!tOxBs~iG_ltg4jPcB9vTH+S!U$FIZSO^?iSW-*wJ)&i_Pt_Lj9tzdgo#*M76>b7)2mZ{Grjp?J$u zlpqiWAn_?G7l1$I1xke86p>9Yv}@qj@YdQ3nctPND^$xQS_7ensi6-mW?>TS&kH6O z9C^mhTHdip1agt(AL|77I0A17U2k{!z1D3)<17GPJZ!tf&VfSXSWA?6>W*vcXlQ}4 zSRI?OXwTVkbFAZV7^OWA&{CX^fl8lrN01~rQ9*A$F}ZV#!lR-ngFtjw5q_^V=jL+D zfl^y zaD#3VL$`w>U4+|MQ@$rA@3la=Tk!&nL_cMi=DE<8-e|?rlj9XZ$Jt1q{x&DGe({iE zGOWH#4k0V#Zmyss(uRtx>V#PH(<1Q>aZEtz+KRaEX`8d+`v)xwP}XMwryKLWBA2R> zJw1Lsw12cIq^u%rSK$^ZZ5sqwCQ%6*9LNgJ7Di-g>2h+apsVQi>LswbyHOW83a7f5 z6M#oQPCxwHYK(2i0=q=4B9W=Hc#@RTl$-e^*)u9lf|mNFj^GR0pH8Rcyi|wv-ZAi_ zRZcGX41AF{(YRM6HSWBbUd-{t8QOihMrTF)ps{9gLvkQ_3WPujLo@VohphM%JPP_s z?}a*Zosrgwp{}uCg^cYUGM8ypdqsT9uS$u#@2P6(Rr-+vLDyTQmSI?7QoohHL*ZzV_-J#xvO;!-|T9SJ+3RgdY z#4;Oa!Oiorybij#Uj{Fe=FWXTCA8amgbA#aW);?|nWM;hm5ObdJf!F*fW9T_#=wIu zg}3byv@7$Vo3~boim=Y$2ASF+fLT)VO*m~Y(&`z#AKwyOyJWUHyw_mJ8`K=|QenLo z4#GiKRT{a44sr$bjq{XnaCl;^#2#y&5{lKw52`|10dC)eWHAP+#1-z2-jg`LhLTp# z{KeN|4!I=!lhxmAMhy`g3sB=iJ(Ia>xt(DXm0veWLkfgka?%d7gx?(? z+(q`#a|f)O(!Gx5#Uh>2?2&D z207N^xmcq)0X^LuM6+;ggl5UWK6MNly_cX_4I>aE5z|MlGzRahK{&@_fStGY6Nj zK2isHb(3`Ao}LqGA8PB`#((6%<2ZrEt9y-rQA;0#%>v)aa#FW`5d}ULV-N)1?;!e%?| zJQ$o7X4uTmVDhWGdBwvtJX{d$ppg%{k}fV-!V-Ees+E*y&2bb^Q_j~L$vHtsU7B8d zR59&-*f%_Tpe_rD5XXr29^*!!;L#H9XD6|iu~N`GwL45n38Z+ruzmMRqo^aQN%i#A zcI;OUdorFPxYn!{F6Vm!p{w({9hxeSOK^C5djr_6YFoSW?bdosBVUE?{UY#pemOqY zPQ`CA_zGb{jardC{O{8*fA{-OfB4I1Km5*jJ>c8mpT7FF;PW5->+hfc;Gh5g;upXE t3izL|fANj)|M&LCf6Ra5eoC(F_kQxTFUP<6?B~Dz(w~(d|Mgd&{ttB+v339e literal 0 HcmV?d00001 diff --git a/secrets/secrets.nix b/secrets/secrets.nix index 4e09c95..0282f14 100644 --- a/secrets/secrets.nix +++ b/secrets/secrets.nix @@ -87,6 +87,7 @@ in "gitlab/secret.age".publicKeys = everyone; "gitlab/otp.age".publicKeys = everyone; "gitlab/db.age".publicKeys = everyone; + "gitlab/db-password.age".publicKeys = everyone; "gitlab/jws.age".publicKeys = everyone; # openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.crt -days 365 -nodes -subj '/CN=issuer' # Then pipe the resulting files to agenix -e