configuration.nix/hosts/wynne/services/apps/forgejo.nix

77 lines
2 KiB
Nix
Raw Normal View History

{ pkgs, config, lib, ... }:
2024-09-23 20:48:06 +05:30
let
cfg = config.services.forgejo;
2024-11-19 23:35:28 +05:30
domainName = "git.ironyofprivacy.org";
2024-09-23 20:48:06 +05:30
in
{
sops.secrets = {
"forgejo/runner_registration_token_file" = {
mode = "400";
owner = config.users.users.root.name;
group = config.users.users.root.group;
};
};
2024-09-23 20:48:06 +05:30
services = {
gitea-actions-runner = {
package = pkgs.forgejo-runner;
instances = {
2024-10-31 10:57:42 +05:30
x86_64-runner = {
enable = true;
2024-10-31 10:57:42 +05:30
name = "x86_64-runner";
labels = [
2024-10-31 10:57:42 +05:30
"docker:docker://ubuntu:latest"
"x86_64-docker:docker://ubuntu:latest"
"linux:docker://ubuntu:latest"
"x86_64-linux:docker://ubuntu:latest"
];
tokenFile = config.sops.secrets."forgejo/runner_registration_token_file".path;
2024-10-31 10:57:42 +05:30
url = "https://${domainName}";
2024-11-01 13:55:29 +05:30
settings = {
log.level = "info";
cache = {
2024-11-03 19:37:12 +05:30
enabled = false;
2024-11-01 13:55:29 +05:30
};
};
};
};
};
2024-09-23 20:48:06 +05:30
forgejo = {
enable = true;
package = pkgs.forgejo;
2024-09-23 20:48:06 +05:30
stateDir = "/mnt/data/Forgejo";
settings = {
database = {
DB_TYPE = lib.mkForce "postgres";
HOST = "127.0.0.1:5432";
USER = cfg.database.user;
NAME = cfg.database.name;
};
server = {
ROOT_URL = "https://${domainName}";
PROTOCOL = "http";
2024-10-29 09:54:38 +05:30
DISABLE_SSH = false;
START_SSH_SERVER = true;
BUILTIN_SSH_SERVER_USER = "forge";
2024-11-19 23:35:28 +05:30
SSH_PORT = 22;
SSH_LISTEN_PORT = 2222;
2024-10-29 09:54:38 +05:30
SSH_LISTEN_HOST = "10.10.10.13";
HTTP_ADDR = "10.10.10.13";
2024-09-23 20:48:06 +05:30
HTTP_PORT = 3000;
DOMAIN = domainName;
};
2024-11-21 11:24:18 +05:30
log = {
LEVEL = "Warn";
"logger.router.MODE" = "";
};
2024-09-23 20:48:06 +05:30
session = {
COOKIE_SECURE = true;
};
service = {
DISABLE_REGISTRATION = true;
};
};
database.createDatabase = true;
};
};
}