Extend fail2ban config for gitea

This commit is contained in:
Evie Litherland-Smith 2023-05-16 11:31:36 +01:00
parent 45eb1526dc
commit a5acf870fe

View file

@ -3,10 +3,7 @@
imports = [ ./traefik.nix ./fail2ban.nix ]; imports = [ ./traefik.nix ./fail2ban.nix ];
services.gitea = { services.gitea = {
enable = true; enable = true;
settings = { settings.server = { DOMAIN = "git.xenia.me.uk"; SSH_PORT = 2222; };
server = { DOMAIN = "git.xenia.me.uk"; SSH_PORT = 2222; };
log.MODE = "file";
};
appName = "Gitea"; appName = "Gitea";
}; };
networking.firewall.allowedTCPPorts = [ 80 443 2222 ]; networking.firewall.allowedTCPPorts = [ 80 443 2222 ];
@ -14,7 +11,10 @@
routers.gitea = { rule = "Host(`git.xenia.me.uk`)"; service = "gitea-websecure"; tls = { certResolver = "default"; }; }; routers.gitea = { rule = "Host(`git.xenia.me.uk`)"; service = "gitea-websecure"; tls = { certResolver = "default"; }; };
services.gitea-websecure.loadBalancer.servers = [{ url = "http://localhost:3000"; }]; services.gitea-websecure.loadBalancer.servers = [{ url = "http://localhost:3000"; }];
}; };
# services.fail2ban.jails.gitea = '' services.fail2ban.jails.gitea = ''
# enabled = true
# ''; filter = sshd
ports = 2222
backend = systemd
'';
} }