Fix gitlab. Again
This commit is contained in:
@@ -6,7 +6,7 @@ let
|
|||||||
in
|
in
|
||||||
{
|
{
|
||||||
greg.proxies."${srcDomain}" = {
|
greg.proxies."${srcDomain}" = {
|
||||||
target = "http://git.thehellings.lan";
|
target = "http://vm-gitlab.shire-zebra.ts.net";
|
||||||
ssl = true;
|
ssl = true;
|
||||||
genAliases = false;
|
genAliases = false;
|
||||||
extraConfig = ''
|
extraConfig = ''
|
||||||
@@ -16,7 +16,7 @@ in
|
|||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
greg.proxies."registry.thehellings.com" = {
|
greg.proxies."registry.thehellings.com" = {
|
||||||
target = "https://registry.thehellings.lan:5000";
|
target = "https://vm-gitlab.shire-zebra.ts.net:5000";
|
||||||
ssl = true;
|
ssl = true;
|
||||||
genAliases = false;
|
genAliases = false;
|
||||||
extraConfig = "client_max_body_size 25000m;";
|
extraConfig = "client_max_body_size 25000m;";
|
||||||
@@ -44,7 +44,7 @@ in
|
|||||||
" bind *:${toString sshPort}"
|
" bind *:${toString sshPort}"
|
||||||
" timeout client 1h"
|
" timeout client 1h"
|
||||||
" mode tcp"
|
" mode tcp"
|
||||||
" server git-thehellings-lan git.thehellings.lan:22"
|
" server git-thehellings-lan vm-gitlab.shire-zebra.ts.net:22"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
+20
-33
@@ -11,12 +11,10 @@
|
|||||||
|
|
||||||
let
|
let
|
||||||
registryPort = 5000;
|
registryPort = 5000;
|
||||||
vpnIp = "100.91.131.66";
|
vpnIp = "100.117.28.111";
|
||||||
containerIp = "192.168.200.2";
|
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
imports = [
|
imports = [
|
||||||
# Include the results of the hardware scan.
|
|
||||||
./hardware-configuration.nix
|
./hardware-configuration.nix
|
||||||
];
|
];
|
||||||
|
|
||||||
@@ -55,30 +53,12 @@ in
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
greg.proxies =
|
|
||||||
let
|
|
||||||
t = {
|
|
||||||
target = "http://unix:/run/gitlab/gitlab-workhorse.socket";
|
|
||||||
extraConfig = ''
|
|
||||||
proxy_set_header X-Forwarded-Proto https;
|
|
||||||
proxy_set_header X-Forwarded-Ssl on;
|
|
||||||
client_max_body_size 10000m;
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
in
|
|
||||||
{
|
|
||||||
"${containerIp}" = t;
|
|
||||||
"${vpnIp}" = t;
|
|
||||||
"git.thehellings.lan" = t;
|
|
||||||
};
|
|
||||||
|
|
||||||
greg.backup.jobs.nas-backup = {
|
|
||||||
src = "/var/gitlab/state/backup/";
|
|
||||||
dest = "gitlab";
|
|
||||||
id = "container-gitlab";
|
|
||||||
};
|
|
||||||
|
|
||||||
greg = {
|
greg = {
|
||||||
|
backup.jobs.nas-backup = {
|
||||||
|
src = "/var/gitlab/state/backup/";
|
||||||
|
dest = "gitlab";
|
||||||
|
id = "container-gitlab";
|
||||||
|
};
|
||||||
home = true;
|
home = true;
|
||||||
tailscale.enable = true;
|
tailscale.enable = true;
|
||||||
};
|
};
|
||||||
@@ -96,7 +76,7 @@ in
|
|||||||
cron = {
|
cron = {
|
||||||
enable = true;
|
enable = true;
|
||||||
systemCronJobs = [
|
systemCronJobs = [
|
||||||
"0 0 1 */2 * cd /etc/certs && tailscale cert gitlab.shire-zebra.ts.net && chown nginx * && systemctl reload nginx"
|
"0 0 1 */2 * cd /etc/certs && tailscale cert vm-gitlab.shire-zebra.ts.net && chown nginx * && systemctl reload nginx"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -114,8 +94,8 @@ in
|
|||||||
extraConfig = {
|
extraConfig = {
|
||||||
gitlab = {
|
gitlab = {
|
||||||
trustedProxies = [
|
trustedProxies = [
|
||||||
"${vpnIp}/32" # The container itself
|
"${vpnIp}/32" # The system itself
|
||||||
"100.115.57.8/32" # Public server's IP
|
"100.109.86.8/32" # Public server's IP
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
object_store = {
|
object_store = {
|
||||||
@@ -188,22 +168,29 @@ in
|
|||||||
};
|
};
|
||||||
|
|
||||||
nginx = {
|
nginx = {
|
||||||
|
enable = true;
|
||||||
clientMaxBodySize = "25000m";
|
clientMaxBodySize = "25000m";
|
||||||
virtualHosts."gitlab.shire-zebra.ts.net" = {
|
virtualHosts."vm-gitlab.shire-zebra.ts.net" = {
|
||||||
listen = [
|
listen = [
|
||||||
{
|
{
|
||||||
addr = "0.0.0.0";
|
addr = "0.0.0.0";
|
||||||
port = registryPort;
|
port = registryPort;
|
||||||
ssl = true;
|
ssl = true;
|
||||||
}
|
}
|
||||||
|
{
|
||||||
|
addr = "0.0.0.0";
|
||||||
|
port = 443;
|
||||||
|
ssl = true;
|
||||||
|
}
|
||||||
];
|
];
|
||||||
locations."/" = {
|
locations."/" = {
|
||||||
proxyPass = "http://127.0.0.1:4567/";
|
proxyPass = "http://unix:/run/gitlab/gitlab-workhorse.socket";
|
||||||
|
#proxyPass = "http://127.0.0.1:4567/";
|
||||||
recommendedProxySettings = true;
|
recommendedProxySettings = true;
|
||||||
};
|
};
|
||||||
extraConfig = ''
|
extraConfig = ''
|
||||||
ssl_certificate /etc/certs/gitlab.shire-zebra.ts.net.crt ;
|
ssl_certificate /etc/certs/vm-gitlab.shire-zebra.ts.net.crt ;
|
||||||
ssl_certificate_key /etc/certs/gitlab.shire-zebra.ts.net.key ;
|
ssl_certificate_key /etc/certs/vm-gitlab.shire-zebra.ts.net.key ;
|
||||||
client_max_body_size 10000m ;
|
client_max_body_size 10000m ;
|
||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -41,8 +41,7 @@ in
|
|||||||
]; # For home and for work machines
|
]; # For home and for work machines
|
||||||
substituters =
|
substituters =
|
||||||
(lib.optionals cfg.cache [
|
(lib.optionals cfg.cache [
|
||||||
"http://nas.thehellings.lan:9000/binary-cache/"
|
"http://chronicles.shire-zebra.ts.net:9000/binary-cache/"
|
||||||
"http://nas.home:9000/binary-cache/"
|
|
||||||
])
|
])
|
||||||
++ [
|
++ [
|
||||||
"https://ai.cachix.org"
|
"https://ai.cachix.org"
|
||||||
@@ -52,8 +51,7 @@ in
|
|||||||
"https://cache.nixos.org"
|
"https://cache.nixos.org"
|
||||||
];
|
];
|
||||||
trusted-public-keys = [
|
trusted-public-keys = [
|
||||||
"nix.thehellings.lan:0qWYHn3gGllXChhAaaxKlNZtRy6yG/XJs1RFSqV3nW8="
|
"chronicles.shire-zebra.ts.net:0qWYHn3gGllXChhAaaxKlNZtRy6yG/XJs1RFSqV3nW8="
|
||||||
"nix.home:0qWYHn3gGllXChhAaaxKlNZtRy6yG/XJs1RFSqV3nW8="
|
|
||||||
"ai.cachix.org-1:N9dzRK+alWwoKXQlnn0H6aUx0lU/mspIoz8hMvGvbbc="
|
"ai.cachix.org-1:N9dzRK+alWwoKXQlnn0H6aUx0lU/mspIoz8hMvGvbbc="
|
||||||
"nixpkgs-python.cachix.org-1:hxjI7pFxTyuTHn2NkvWCrAUcNZLNS3ZAvfYNuYifcEU="
|
"nixpkgs-python.cachix.org-1:hxjI7pFxTyuTHn2NkvWCrAUcNZLNS3ZAvfYNuYifcEU="
|
||||||
"greg-hellings.cachix.org-1:y01Jl/L5evlhxdnUW6n56AiI1k8g1wxWhTxJCe7XSco="
|
"greg-hellings.cachix.org-1:y01Jl/L5evlhxdnUW6n56AiI1k8g1wxWhTxJCe7XSco="
|
||||||
|
|||||||
Reference in New Issue
Block a user