From dc9be0b7c103b7b12c76f13cde1ee7e0f237259c Mon Sep 17 00:00:00 2001 From: Nick Van Doorn Date: Mon, 16 Aug 2021 08:15:04 +0000 Subject: Initial commit --- cgit.nix | 132 +++++++++++++++++++++++++++++++++++++++++ configuration.nix | 143 +++++++++++++++++++++++++++++++++++++++++++++ hardware-configuration.nix | 30 ++++++++++ 3 files changed, 305 insertions(+) create mode 100644 cgit.nix create mode 100644 configuration.nix create mode 100644 hardware-configuration.nix diff --git a/cgit.nix b/cgit.nix new file mode 100644 index 0000000..5391f3a --- /dev/null +++ b/cgit.nix @@ -0,0 +1,132 @@ +{ config, lib, pkgs, ... }: + +with lib; +let + globalConfig = config; + settingsFormat = { + type = with lib.types; let + value = oneOf [ int str ] // { + description = "INI-like atom (int or string)"; + }; + values = coercedTo value lib.singleton (listOf value) // { + description = value.description + " or a list of them for duplicate keys"; + }; + in + attrsOf (values); + generate = name: values: + pkgs.writeText name (lib.generators.toKeyValue { listsAsDuplicateKeys = true; } values); + }; +in +{ + options.services.nginx.virtualHosts = mkOption { + type = types.attrsOf (types.submodule ({ config, ... }: + let + cfg = config.cgit; + + # These are the global options for this submodule, but for nicer UX they + # are inlined into the freeform settings. Hence they MUST NOT INTERSECT + # with any settings from cgitrc! + options = { + enable = mkEnableOption "cgit"; + + location = mkOption { + default = "/"; + type = types.str; + description = '' + Location to serve cgit on. + ''; + }; + }; + + # Remove the global options for serialization into cgitrc + settings = removeAttrs cfg (attrNames options); + in + { + options.cgit = mkOption { + type = types.submodule { + freeformType = settingsFormat.type; + inherit options; + config = { + css = mkDefault "/cgit.css"; + logo = mkDefault "/cgit.png"; + favicon = mkDefault "/favicon.ico"; + }; + }; + default = { }; + example = literalExample '' + { + enable = true; + virtual-root = "/"; + source-filter = "''${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py"; + about-filter = "''${pkgs.cgit}/lib/cgit/filters/about-formatting.sh"; + cache-size = 1000; + scan-path = "/srv/git"; + include = [ + (builtins.toFile "cgitrc-extra-1" ''' + # Anything that has to be in a particular order + ''') + (builtins.toFile "cgitrc-extra-2" ''' + # Anything that has to be in a particular order + ''') + ]; + } + ''; + description = '' + Verbatim contents of the cgit runtime configuration file. Documentation + (with cgitrc example file) is available in "man cgitrc". Or online: + http://git.zx2c4.com/cgit/tree/cgitrc.5.txt + ''; + }; + + config = let + location = removeSuffix "/" cfg.location; + in mkIf cfg.enable { + + locations."${location}/" = { + root = "${pkgs.cgit}/cgit/"; + tryFiles = "$uri @cgit"; + }; + locations."~ ^${location}/(cgit.(css|png)|favicon.ico|robots.txt)$" = { + alias = "${pkgs.cgit}/cgit/$1"; + }; + locations."@cgit" = { + extraConfig = '' + include ${pkgs.nginx}/conf/fastcgi_params; + fastcgi_param CGIT_CONFIG ${settingsFormat.generate "cgitrc" settings}; + fastcgi_param SCRIPT_FILENAME ${pkgs.cgit}/cgit/cgit.cgi; + fastcgi_param QUERY_STRING $args; + fastcgi_param HTTP_HOST $server_name; + fastcgi_pass unix:${globalConfig.services.fcgiwrap.socketAddress}; + '' + ( + if cfg.location == "/" + then + '' + fastcgi_param PATH_INFO $uri; + '' + else + '' + fastcgi_split_path_info ^(${location}/)(/?.+)$; + fastcgi_param PATH_INFO $fastcgi_path_info; + '' + ); + }; + }; + + })); + }; + + config = + let + vhosts = config.services.nginx.virtualHosts; + in + mkIf (any (name: vhosts.${name}.cgit.enable) (attrNames vhosts)) { + # make the cgitrc manpage available + environment.systemPackages = [ pkgs.cgit ]; + + services.fcgiwrap.enable = true; + }; + + meta = { + maintainers = with lib.maintainers; [ afix-space hmenke ]; + }; +} diff --git a/configuration.nix b/configuration.nix new file mode 100644 index 0000000..d21044a --- /dev/null +++ b/configuration.nix @@ -0,0 +1,143 @@ +# Edit this configuration file to define what should be installed on +# your system. Help is available in the configuration.nix(5) man page +# and in the NixOS manual (accessible by running ‘nixos-help’). + +{ config, pkgs, ... }: + +{ + imports = + [ # Include the results of the hardware scan. + ./hardware-configuration.nix + ./cgit.nix + ]; + + # Use the GRUB 2 boot loader. + boot.loader.grub.enable = true; + boot.loader.grub.version = 2; + # boot.loader.grub.efiSupport = true; + # boot.loader.grub.efiInstallAsRemovable = true; + # boot.loader.efi.efiSysMountPoint = "/boot/efi"; + # Define on which hard drive you want to install Grub. + boot.loader.grub.device = "/dev/sda"; # or "nodev" for efi only + + nixpkgs.config.allowUnfree = true; + networking.hostName = "nvd-vps"; # Define your hostname. + # networking.wireless.enable = true; # Enables wireless support via wpa_supplicant. + + # Set your time zone. + # time.timeZone = "Europe/Amsterdam"; + + # The global useDHCP flag is deprecated, therefore explicitly set to false here. + # Per-interface useDHCP will be mandatory in the future, so this generated config + # replicates the default behaviour. + networking.useDHCP = false; + networking.interfaces.ens3.useDHCP = true; + + services.deluge.enable = true; + services.deluge.web.enable = true; + services.fcgiwrap.enable = true; + services.nginx.enable = true; + security.acme.email = "vandoorn.nick@gmail.com"; + security.acme.acceptTerms = true; + services.nginx.virtualHosts."deluge.nvandoorn.com" = { + enableACME = true; + forceSSL = true; + locations."/".proxyPass = "http://localhost:8112"; + }; + services.nginx.virtualHosts."git.nvandoorn.com" = { + enableACME = true; + forceSSL = true; + cgit = { + enable = true; + virtual-root = "/"; + scan-path = "/srv/git"; + root-title = "nvd-git"; + root-desc = "Nicholas Van Doorn's personal Git server"; + include = [ + (builtins.toFile "cgitrc-extra-2" '' + enable-http-clone=1 + '') + ]; + }; + }; + services.nginx.virtualHosts."nvandoorn.com" = { + enableACME = true; + forceSSL = true; + root = "/var/www/nvandoorn.com"; + }; + + # Configure network proxy if necessary + # networking.proxy.default = "http://user:password@proxy:port/"; + # networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain"; + + # Select internationalisation properties. + # i18n.defaultLocale = "en_US.UTF-8"; + # console = { + # font = "Lat2-Terminus16"; + # keyMap = "us"; + # }; + + # Enable the X11 windowing system. + # services.xserver.enable = true; + + # Configure keymap in X11 + # services.xserver.layout = "us"; + # services.xserver.xkbOptions = "eurosign:e"; + + # Enable CUPS to print documents. + # services.printing.enable = true; + + # Enable sound. + # sound.enable = true; + # hardware.pulseaudio.enable = true; + + # Enable touchpad support (enabled default in most desktopManager). + # services.xserver.libinput.enable = true; + + # Define a user account. Don't forget to set a password with ‘passwd’. + users.users.nick = { + isNormalUser = true; + extraGroups = [ "wheel" ]; # Enable ‘sudo’ for the user. + }; + + # List packages installed in system profile. To search, run: + # $ nix search wget + environment.systemPackages = with pkgs; [ + vim # Do not forget to add an editor to edit configuration.nix! The Nano editor is also installed by default. + wget + cgit + neofetch + htop + bottom + thttpd + ffmpeg + git + ]; + + # Some programs need SUID wrappers, can be configured further or are + # started in user sessions. + # programs.mtr.enable = true; + # programs.gnupg.agent = { + # enable = true; + # enableSSHSupport = true; + # }; + + # List services that you want to enable: + + # Enable the OpenSSH daemon. + services.openssh.enable = true; + + # Open ports in the firewall. + # networking.firewall.allowedTCPPorts = [ ... ]; + # networking.firewall.allowedUDPPorts = [ ... ]; + # Or disable the firewall altogether. + networking.firewall.enable = false; + + # This value determines the NixOS release from which the default + # settings for stateful data, like file locations and database versions + # on your system were taken. It‘s perfectly fine and recommended to leave + # this value at the release version of the first install of this system. + # Before changing this value read the documentation for this option + # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html). + system.stateVersion = "21.11"; # Did you read the comment? +} diff --git a/hardware-configuration.nix b/hardware-configuration.nix new file mode 100644 index 0000000..a45320f --- /dev/null +++ b/hardware-configuration.nix @@ -0,0 +1,30 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + +{ + imports = + [ (modulesPath + "/profiles/qemu-guest.nix") + ]; + + boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = + { device = "/dev/disk/by-uuid/5e5668c1-6227-4e75-82e5-56072a8efb3b"; + fsType = "ext4"; + }; + + fileSystems."/mnt/remote" = + { device = "/dev/disk/by-uuid/8b4d81d3-94ef-4592-81a5-233d34b29359"; + fsType = "ext4"; + }; + + swapDevices = + [ { device = "/dev/disk/by-uuid/9bf7dfac-5e8c-4829-bfb8-6ff9a45e4803"; } + ]; + +} -- cgit v1.2.3