summaryrefslogtreecommitdiff
path: root/modules/xnet/gitserver
diff options
context:
space:
mode:
Diffstat (limited to 'modules/xnet/gitserver')
-rw-r--r--modules/xnet/gitserver/default.nix53
-rw-r--r--modules/xnet/gitserver/gitweb.nix74
2 files changed, 127 insertions, 0 deletions
diff --git a/modules/xnet/gitserver/default.nix b/modules/xnet/gitserver/default.nix
new file mode 100644
index 0000000..5e04398
--- /dev/null
+++ b/modules/xnet/gitserver/default.nix
@@ -0,0 +1,53 @@
+{ config, lib, pkgs, ... }:
+let
+ cfg = config.xnet.gitServer;
+ inherit (lib) mkOption mkIf types;
+in
+{
+ imports = [ ./gitweb.nix ];
+
+ options.xnet.gitServer = {
+ enable = mkOption {
+ type = types.bool;
+ default = false;
+ description = "Serve git repos over SSH.";
+ };
+
+ path = mkOption {
+ type = types.path;
+ default = "/persist/repo/git";
+ description = "Directory where repos will be stored.";
+ };
+
+ keys = mkOption {
+ type = types.listOf types.str;
+ description = "SSH public keys used for git operations.";
+ };
+ };
+
+ config = mkIf cfg.enable {
+ users.users.git = {
+ group = "git";
+ initialPassword = "";
+ isSystemUser = true;
+ home = cfg.path;
+ createHome = true;
+ shell = "${pkgs.git}/bin/git-shell";
+ openssh.authorizedKeys.keys = cfg.keys;
+ };
+
+ users.groups.git = { };
+
+ programs.git = {
+ enable = true;
+ config = {
+ init = {
+ defaultBranch = "master";
+ };
+ safe = {
+ directory = "*";
+ };
+ };
+ };
+ };
+}
diff --git a/modules/xnet/gitserver/gitweb.nix b/modules/xnet/gitserver/gitweb.nix
new file mode 100644
index 0000000..c3696ab
--- /dev/null
+++ b/modules/xnet/gitserver/gitweb.nix
@@ -0,0 +1,74 @@
+{ config, lib, pkgs, ... }:
+let
+ cfg = config.xnet.gitServer.gitweb;
+ inherit (lib) mkOption mkIf types;
+in
+{
+ options.xnet.gitServer.gitweb = {
+ enable = mkOption {
+ type = types.bool;
+ default = false;
+ description = "Enable web interface to git repos.";
+ };
+
+ hostName = mkOption {
+ type = types.str;
+ default = "src.web.4kb.net";
+ description = "Hostname the webUI is served from.";
+ };
+ };
+
+ config = mkIf cfg.enable {
+ xnet.nginx.enable = true;
+
+ services.cgit.main = {
+ enable = true;
+ scanPath = config.xnet.gitServer.path;
+ package = pkgs.cgit-pink;
+ nginx = {
+ virtualHost = cfg.hostName;
+ location = "/";
+ };
+ extraConfig = ''
+ mimetype.gif=image/gif
+ mimetype.html=text/html
+ mimetype.jpeg=image/jpeg
+ mimetype.jpg=image/jpeg
+ mimetype.pdf=application/pdf
+ mimetype.png=image/png
+ mimetype.svg=image/svg+xml
+ readme=:readme
+ readme=:readme.md
+ readme=:readme.txt
+ readme=:README
+ readme=:README.md
+ readme=:README.txt
+ '';
+ settings = {
+ about-filter = "${pkgs.cgit-pink}/lib/cgit/filters/about-formatting.sh";
+ clone-url = "https://${cfg.hostName}/$CGIT_REPO_URL git@${cfg.hostName}:$CGIT_REPO_URL";
+ enable-commit-graph = true;
+ enable-http-clone = false;
+ enable-index-links = true;
+ enable-remote-branches = true;
+ remove-suffix = true;
+ robots = "noindex, nofollow";
+ root-desc = "What I cannot create, I do not understand";
+ root-title = cfg.hostName;
+ section-from-path = true;
+ snapshots = "tar.gz tar.bz2 zip";
+ };
+ };
+
+ # required for rendering markdown readme
+ environment.systemPackages = with pkgs; [
+ python312
+ python312Packages.markdown
+ ];
+
+ # services.nginx.virtualHosts."${cfg.gitweb.hostName}" = {
+ # useACMEHost = "4kb.net";
+ # addSSL = true;
+ # };
+ };
+}