Fix gitlab. Again

This commit is contained in:
Greg Hellings
2025-06-11 22:57:09 -05:00
parent e13bee750c
commit eddbf9292f
3 changed files with 25 additions and 40 deletions
+3 -3
View File
@@ -6,7 +6,7 @@ let
in in
{ {
greg.proxies."${srcDomain}" = { greg.proxies."${srcDomain}" = {
target = "http://git.thehellings.lan"; target = "http://vm-gitlab.shire-zebra.ts.net";
ssl = true; ssl = true;
genAliases = false; genAliases = false;
extraConfig = '' extraConfig = ''
@@ -16,7 +16,7 @@ in
''; '';
}; };
greg.proxies."registry.thehellings.com" = { greg.proxies."registry.thehellings.com" = {
target = "https://registry.thehellings.lan:5000"; target = "https://vm-gitlab.shire-zebra.ts.net:5000";
ssl = true; ssl = true;
genAliases = false; genAliases = false;
extraConfig = "client_max_body_size 25000m;"; extraConfig = "client_max_body_size 25000m;";
@@ -44,7 +44,7 @@ in
" bind *:${toString sshPort}" " bind *:${toString sshPort}"
" timeout client 1h" " timeout client 1h"
" mode tcp" " mode tcp"
" server git-thehellings-lan git.thehellings.lan:22" " server git-thehellings-lan vm-gitlab.shire-zebra.ts.net:22"
]; ];
}; };
} }
+17 -30
View File
@@ -11,12 +11,10 @@
let let
registryPort = 5000; registryPort = 5000;
vpnIp = "100.91.131.66"; vpnIp = "100.117.28.111";
containerIp = "192.168.200.2";
in in
{ {
imports = [ imports = [
# Include the results of the hardware scan.
./hardware-configuration.nix ./hardware-configuration.nix
]; ];
@@ -55,30 +53,12 @@ in
}; };
}; };
greg.proxies = greg = {
let backup.jobs.nas-backup = {
t = {
target = "http://unix:/run/gitlab/gitlab-workhorse.socket";
extraConfig = ''
proxy_set_header X-Forwarded-Proto https;
proxy_set_header X-Forwarded-Ssl on;
client_max_body_size 10000m;
'';
};
in
{
"${containerIp}" = t;
"${vpnIp}" = t;
"git.thehellings.lan" = t;
};
greg.backup.jobs.nas-backup = {
src = "/var/gitlab/state/backup/"; src = "/var/gitlab/state/backup/";
dest = "gitlab"; dest = "gitlab";
id = "container-gitlab"; id = "container-gitlab";
}; };
greg = {
home = true; home = true;
tailscale.enable = true; tailscale.enable = true;
}; };
@@ -96,7 +76,7 @@ in
cron = { cron = {
enable = true; enable = true;
systemCronJobs = [ systemCronJobs = [
"0 0 1 */2 * cd /etc/certs && tailscale cert gitlab.shire-zebra.ts.net && chown nginx * && systemctl reload nginx" "0 0 1 */2 * cd /etc/certs && tailscale cert vm-gitlab.shire-zebra.ts.net && chown nginx * && systemctl reload nginx"
]; ];
}; };
@@ -114,8 +94,8 @@ in
extraConfig = { extraConfig = {
gitlab = { gitlab = {
trustedProxies = [ trustedProxies = [
"${vpnIp}/32" # The container itself "${vpnIp}/32" # The system itself
"100.115.57.8/32" # Public server's IP "100.109.86.8/32" # Public server's IP
]; ];
}; };
object_store = { object_store = {
@@ -188,22 +168,29 @@ in
}; };
nginx = { nginx = {
enable = true;
clientMaxBodySize = "25000m"; clientMaxBodySize = "25000m";
virtualHosts."gitlab.shire-zebra.ts.net" = { virtualHosts."vm-gitlab.shire-zebra.ts.net" = {
listen = [ listen = [
{ {
addr = "0.0.0.0"; addr = "0.0.0.0";
port = registryPort; port = registryPort;
ssl = true; ssl = true;
} }
{
addr = "0.0.0.0";
port = 443;
ssl = true;
}
]; ];
locations."/" = { locations."/" = {
proxyPass = "http://127.0.0.1:4567/"; proxyPass = "http://unix:/run/gitlab/gitlab-workhorse.socket";
#proxyPass = "http://127.0.0.1:4567/";
recommendedProxySettings = true; recommendedProxySettings = true;
}; };
extraConfig = '' extraConfig = ''
ssl_certificate /etc/certs/gitlab.shire-zebra.ts.net.crt ; ssl_certificate /etc/certs/vm-gitlab.shire-zebra.ts.net.crt ;
ssl_certificate_key /etc/certs/gitlab.shire-zebra.ts.net.key ; ssl_certificate_key /etc/certs/vm-gitlab.shire-zebra.ts.net.key ;
client_max_body_size 10000m ; client_max_body_size 10000m ;
''; '';
}; };
+2 -4
View File
@@ -41,8 +41,7 @@ in
]; # For home and for work machines ]; # For home and for work machines
substituters = substituters =
(lib.optionals cfg.cache [ (lib.optionals cfg.cache [
"http://nas.thehellings.lan:9000/binary-cache/" "http://chronicles.shire-zebra.ts.net:9000/binary-cache/"
"http://nas.home:9000/binary-cache/"
]) ])
++ [ ++ [
"https://ai.cachix.org" "https://ai.cachix.org"
@@ -52,8 +51,7 @@ in
"https://cache.nixos.org" "https://cache.nixos.org"
]; ];
trusted-public-keys = [ trusted-public-keys = [
"nix.thehellings.lan:0qWYHn3gGllXChhAaaxKlNZtRy6yG/XJs1RFSqV3nW8=" "chronicles.shire-zebra.ts.net:0qWYHn3gGllXChhAaaxKlNZtRy6yG/XJs1RFSqV3nW8="
"nix.home:0qWYHn3gGllXChhAaaxKlNZtRy6yG/XJs1RFSqV3nW8="
"ai.cachix.org-1:N9dzRK+alWwoKXQlnn0H6aUx0lU/mspIoz8hMvGvbbc=" "ai.cachix.org-1:N9dzRK+alWwoKXQlnn0H6aUx0lU/mspIoz8hMvGvbbc="
"nixpkgs-python.cachix.org-1:hxjI7pFxTyuTHn2NkvWCrAUcNZLNS3ZAvfYNuYifcEU=" "nixpkgs-python.cachix.org-1:hxjI7pFxTyuTHn2NkvWCrAUcNZLNS3ZAvfYNuYifcEU="
"greg-hellings.cachix.org-1:y01Jl/L5evlhxdnUW6n56AiI1k8g1wxWhTxJCe7XSco=" "greg-hellings.cachix.org-1:y01Jl/L5evlhxdnUW6n56AiI1k8g1wxWhTxJCe7XSco="