2023-05-17 17:10:18 +01:00
|
|
|
{...}: {
|
|
|
|
imports = [./traefik.nix ./fail2ban.nix];
|
2023-05-16 11:04:48 +01:00
|
|
|
services.gitea = {
|
|
|
|
enable = true;
|
2023-05-16 15:45:02 +01:00
|
|
|
settings = {
|
|
|
|
server = {
|
|
|
|
ROOT_URL = "https://git.xenia.me.uk";
|
|
|
|
DOMAIN = "git.xenia.me.uk";
|
2023-05-25 17:05:25 +01:00
|
|
|
START_SSH_SERVER = true;
|
|
|
|
SSH_DOMAIN = "git.xenia.me.uk";
|
2023-05-16 15:45:02 +01:00
|
|
|
SSH_PORT = 2222;
|
2023-05-25 17:05:25 +01:00
|
|
|
SSH_LISTEN_PORT = 30922;
|
2023-05-16 15:45:02 +01:00
|
|
|
};
|
|
|
|
service.DISABLE_REGISTRATION = true;
|
2023-05-19 11:46:43 +01:00
|
|
|
ui = {
|
2023-05-19 12:03:52 +01:00
|
|
|
THEMES = "auto,gitea,arc-green,catppuccin-latte-lavender,catppuccin-frappe-lavender,catppuccin-macchiato-lavender,catppuccin-mocha-lavender";
|
2023-05-19 11:46:43 +01:00
|
|
|
};
|
2023-05-16 15:42:05 +01:00
|
|
|
};
|
2023-05-16 11:04:48 +01:00
|
|
|
appName = "Gitea";
|
|
|
|
};
|
2023-05-25 17:05:25 +01:00
|
|
|
services.traefik.dynamicConfigOptions = {
|
|
|
|
http = {
|
|
|
|
routers.gitea = {
|
|
|
|
rule = "Host(`git.xenia.me.uk`)";
|
|
|
|
entryPoints = ["http" "https"];
|
|
|
|
service = "gitea-websecure";
|
|
|
|
tls = {certResolver = "default";};
|
|
|
|
};
|
|
|
|
services.gitea-websecure.loadBalancer.servers = [{url = "http://localhost:3000";}];
|
|
|
|
};
|
|
|
|
tcp = {
|
|
|
|
routers.gitea-ssh = {
|
|
|
|
rule = "HostSNI(`git.xenia.me.uk`)";
|
|
|
|
entryPoints = ["ssh"];
|
|
|
|
service = "gitea-sshservice";
|
|
|
|
tls = {certResolver = "default";};
|
|
|
|
};
|
|
|
|
routers.gitea-ssh-local = {
|
|
|
|
rule = "ClientIP(`192.168.0.0/16`)";
|
|
|
|
entryPoints = ["ssh"];
|
|
|
|
service = "gitea-sshservice";
|
|
|
|
};
|
|
|
|
services.gitea-sshservice.loadBalancer.servers = [{address = "localhost:30922";}];
|
2023-05-17 17:10:18 +01:00
|
|
|
};
|
2023-05-11 11:54:42 +01:00
|
|
|
};
|
2023-05-16 11:31:36 +01:00
|
|
|
services.fail2ban.jails.gitea = ''
|
|
|
|
enabled = true
|
|
|
|
filter = sshd
|
2023-05-25 17:05:25 +01:00
|
|
|
ports = 30922
|
2023-05-16 11:31:36 +01:00
|
|
|
backend = systemd
|
|
|
|
'';
|
2023-05-11 11:54:42 +01:00
|
|
|
}
|