summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorNick Van Doorn <vandoorn.nick@gmail.com>2021-08-16 08:15:04 +0000
committerNick Van Doorn <nick@nv.delivery>2022-07-04 14:03:24 -0700
commitdc9be0b7c103b7b12c76f13cde1ee7e0f237259c (patch)
tree5550989a74738ffc8e70ea3200bcd4e585d8983e
Initial commit
-rw-r--r--cgit.nix132
-rw-r--r--configuration.nix143
-rw-r--r--hardware-configuration.nix30
3 files changed, 305 insertions, 0 deletions
diff --git a/cgit.nix b/cgit.nix
new file mode 100644
index 0000000..5391f3a
--- /dev/null
+++ b/cgit.nix
@@ -0,0 +1,132 @@
+{ config, lib, pkgs, ... }:
+
+with lib;
+let
+ globalConfig = config;
+ settingsFormat = {
+ type = with lib.types; let
+ value = oneOf [ int str ] // {
+ description = "INI-like atom (int or string)";
+ };
+ values = coercedTo value lib.singleton (listOf value) // {
+ description = value.description + " or a list of them for duplicate keys";
+ };
+ in
+ attrsOf (values);
+ generate = name: values:
+ pkgs.writeText name (lib.generators.toKeyValue { listsAsDuplicateKeys = true; } values);
+ };
+in
+{
+ options.services.nginx.virtualHosts = mkOption {
+ type = types.attrsOf (types.submodule ({ config, ... }:
+ let
+ cfg = config.cgit;
+
+ # These are the global options for this submodule, but for nicer UX they
+ # are inlined into the freeform settings. Hence they MUST NOT INTERSECT
+ # with any settings from cgitrc!
+ options = {
+ enable = mkEnableOption "cgit";
+
+ location = mkOption {
+ default = "/";
+ type = types.str;
+ description = ''
+ Location to serve cgit on.
+ '';
+ };
+ };
+
+ # Remove the global options for serialization into cgitrc
+ settings = removeAttrs cfg (attrNames options);
+ in
+ {
+ options.cgit = mkOption {
+ type = types.submodule {
+ freeformType = settingsFormat.type;
+ inherit options;
+ config = {
+ css = mkDefault "/cgit.css";
+ logo = mkDefault "/cgit.png";
+ favicon = mkDefault "/favicon.ico";
+ };
+ };
+ default = { };
+ example = literalExample ''
+ {
+ enable = true;
+ virtual-root = "/";
+ source-filter = "''${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py";
+ about-filter = "''${pkgs.cgit}/lib/cgit/filters/about-formatting.sh";
+ cache-size = 1000;
+ scan-path = "/srv/git";
+ include = [
+ (builtins.toFile "cgitrc-extra-1" '''
+ # Anything that has to be in a particular order
+ ''')
+ (builtins.toFile "cgitrc-extra-2" '''
+ # Anything that has to be in a particular order
+ ''')
+ ];
+ }
+ '';
+ description = ''
+ Verbatim contents of the cgit runtime configuration file. Documentation
+ (with cgitrc example file) is available in "man cgitrc". Or online:
+ http://git.zx2c4.com/cgit/tree/cgitrc.5.txt
+ '';
+ };
+
+ config = let
+ location = removeSuffix "/" cfg.location;
+ in mkIf cfg.enable {
+
+ locations."${location}/" = {
+ root = "${pkgs.cgit}/cgit/";
+ tryFiles = "$uri @cgit";
+ };
+ locations."~ ^${location}/(cgit.(css|png)|favicon.ico|robots.txt)$" = {
+ alias = "${pkgs.cgit}/cgit/$1";
+ };
+ locations."@cgit" = {
+ extraConfig = ''
+ include ${pkgs.nginx}/conf/fastcgi_params;
+ fastcgi_param CGIT_CONFIG ${settingsFormat.generate "cgitrc" settings};
+ fastcgi_param SCRIPT_FILENAME ${pkgs.cgit}/cgit/cgit.cgi;
+ fastcgi_param QUERY_STRING $args;
+ fastcgi_param HTTP_HOST $server_name;
+ fastcgi_pass unix:${globalConfig.services.fcgiwrap.socketAddress};
+ '' + (
+ if cfg.location == "/"
+ then
+ ''
+ fastcgi_param PATH_INFO $uri;
+ ''
+ else
+ ''
+ fastcgi_split_path_info ^(${location}/)(/?.+)$;
+ fastcgi_param PATH_INFO $fastcgi_path_info;
+ ''
+ );
+ };
+ };
+
+ }));
+ };
+
+ config =
+ let
+ vhosts = config.services.nginx.virtualHosts;
+ in
+ mkIf (any (name: vhosts.${name}.cgit.enable) (attrNames vhosts)) {
+ # make the cgitrc manpage available
+ environment.systemPackages = [ pkgs.cgit ];
+
+ services.fcgiwrap.enable = true;
+ };
+
+ meta = {
+ maintainers = with lib.maintainers; [ afix-space hmenke ];
+ };
+}
diff --git a/configuration.nix b/configuration.nix
new file mode 100644
index 0000000..d21044a
--- /dev/null
+++ b/configuration.nix
@@ -0,0 +1,143 @@
+# Edit this configuration file to define what should be installed on
+# your system. Help is available in the configuration.nix(5) man page
+# and in the NixOS manual (accessible by running ‘nixos-help’).
+
+{ config, pkgs, ... }:
+
+{
+ imports =
+ [ # Include the results of the hardware scan.
+ ./hardware-configuration.nix
+ ./cgit.nix
+ ];
+
+ # Use the GRUB 2 boot loader.
+ boot.loader.grub.enable = true;
+ boot.loader.grub.version = 2;
+ # boot.loader.grub.efiSupport = true;
+ # boot.loader.grub.efiInstallAsRemovable = true;
+ # boot.loader.efi.efiSysMountPoint = "/boot/efi";
+ # Define on which hard drive you want to install Grub.
+ boot.loader.grub.device = "/dev/sda"; # or "nodev" for efi only
+
+ nixpkgs.config.allowUnfree = true;
+ networking.hostName = "nvd-vps"; # Define your hostname.
+ # networking.wireless.enable = true; # Enables wireless support via wpa_supplicant.
+
+ # Set your time zone.
+ # time.timeZone = "Europe/Amsterdam";
+
+ # The global useDHCP flag is deprecated, therefore explicitly set to false here.
+ # Per-interface useDHCP will be mandatory in the future, so this generated config
+ # replicates the default behaviour.
+ networking.useDHCP = false;
+ networking.interfaces.ens3.useDHCP = true;
+
+ services.deluge.enable = true;
+ services.deluge.web.enable = true;
+ services.fcgiwrap.enable = true;
+ services.nginx.enable = true;
+ security.acme.email = "vandoorn.nick@gmail.com";
+ security.acme.acceptTerms = true;
+ services.nginx.virtualHosts."deluge.nvandoorn.com" = {
+ enableACME = true;
+ forceSSL = true;
+ locations."/".proxyPass = "http://localhost:8112";
+ };
+ services.nginx.virtualHosts."git.nvandoorn.com" = {
+ enableACME = true;
+ forceSSL = true;
+ cgit = {
+ enable = true;
+ virtual-root = "/";
+ scan-path = "/srv/git";
+ root-title = "nvd-git";
+ root-desc = "Nicholas Van Doorn's personal Git server";
+ include = [
+ (builtins.toFile "cgitrc-extra-2" ''
+ enable-http-clone=1
+ '')
+ ];
+ };
+ };
+ services.nginx.virtualHosts."nvandoorn.com" = {
+ enableACME = true;
+ forceSSL = true;
+ root = "/var/www/nvandoorn.com";
+ };
+
+ # Configure network proxy if necessary
+ # networking.proxy.default = "http://user:password@proxy:port/";
+ # networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain";
+
+ # Select internationalisation properties.
+ # i18n.defaultLocale = "en_US.UTF-8";
+ # console = {
+ # font = "Lat2-Terminus16";
+ # keyMap = "us";
+ # };
+
+ # Enable the X11 windowing system.
+ # services.xserver.enable = true;
+
+ # Configure keymap in X11
+ # services.xserver.layout = "us";
+ # services.xserver.xkbOptions = "eurosign:e";
+
+ # Enable CUPS to print documents.
+ # services.printing.enable = true;
+
+ # Enable sound.
+ # sound.enable = true;
+ # hardware.pulseaudio.enable = true;
+
+ # Enable touchpad support (enabled default in most desktopManager).
+ # services.xserver.libinput.enable = true;
+
+ # Define a user account. Don't forget to set a password with ‘passwd’.
+ users.users.nick = {
+ isNormalUser = true;
+ extraGroups = [ "wheel" ]; # Enable ‘sudo’ for the user.
+ };
+
+ # List packages installed in system profile. To search, run:
+ # $ nix search wget
+ environment.systemPackages = with pkgs; [
+ vim # Do not forget to add an editor to edit configuration.nix! The Nano editor is also installed by default.
+ wget
+ cgit
+ neofetch
+ htop
+ bottom
+ thttpd
+ ffmpeg
+ git
+ ];
+
+ # Some programs need SUID wrappers, can be configured further or are
+ # started in user sessions.
+ # programs.mtr.enable = true;
+ # programs.gnupg.agent = {
+ # enable = true;
+ # enableSSHSupport = true;
+ # };
+
+ # List services that you want to enable:
+
+ # Enable the OpenSSH daemon.
+ services.openssh.enable = true;
+
+ # Open ports in the firewall.
+ # networking.firewall.allowedTCPPorts = [ ... ];
+ # networking.firewall.allowedUDPPorts = [ ... ];
+ # Or disable the firewall altogether.
+ networking.firewall.enable = false;
+
+ # This value determines the NixOS release from which the default
+ # settings for stateful data, like file locations and database versions
+ # on your system were taken. It‘s perfectly fine and recommended to leave
+ # this value at the release version of the first install of this system.
+ # Before changing this value read the documentation for this option
+ # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
+ system.stateVersion = "21.11"; # Did you read the comment?
+}
diff --git a/hardware-configuration.nix b/hardware-configuration.nix
new file mode 100644
index 0000000..a45320f
--- /dev/null
+++ b/hardware-configuration.nix
@@ -0,0 +1,30 @@
+# Do not modify this file! It was generated by ‘nixos-generate-config’
+# and may be overwritten by future invocations. Please make changes
+# to /etc/nixos/configuration.nix instead.
+{ config, lib, pkgs, modulesPath, ... }:
+
+{
+ imports =
+ [ (modulesPath + "/profiles/qemu-guest.nix")
+ ];
+
+ boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ];
+ boot.initrd.kernelModules = [ ];
+ boot.kernelModules = [ ];
+ boot.extraModulePackages = [ ];
+
+ fileSystems."/" =
+ { device = "/dev/disk/by-uuid/5e5668c1-6227-4e75-82e5-56072a8efb3b";
+ fsType = "ext4";
+ };
+
+ fileSystems."/mnt/remote" =
+ { device = "/dev/disk/by-uuid/8b4d81d3-94ef-4592-81a5-233d34b29359";
+ fsType = "ext4";
+ };
+
+ swapDevices =
+ [ { device = "/dev/disk/by-uuid/9bf7dfac-5e8c-4829-bfb8-6ff9a45e4803"; }
+ ];
+
+}