Extend fail2ban config for gitea
This commit is contained in:
parent
45eb1526dc
commit
a5acf870fe
|
@ -3,10 +3,7 @@
|
||||||
imports = [ ./traefik.nix ./fail2ban.nix ];
|
imports = [ ./traefik.nix ./fail2ban.nix ];
|
||||||
services.gitea = {
|
services.gitea = {
|
||||||
enable = true;
|
enable = true;
|
||||||
settings = {
|
settings.server = { DOMAIN = "git.xenia.me.uk"; SSH_PORT = 2222; };
|
||||||
server = { DOMAIN = "git.xenia.me.uk"; SSH_PORT = 2222; };
|
|
||||||
log.MODE = "file";
|
|
||||||
};
|
|
||||||
appName = "Gitea";
|
appName = "Gitea";
|
||||||
};
|
};
|
||||||
networking.firewall.allowedTCPPorts = [ 80 443 2222 ];
|
networking.firewall.allowedTCPPorts = [ 80 443 2222 ];
|
||||||
|
@ -14,7 +11,10 @@
|
||||||
routers.gitea = { rule = "Host(`git.xenia.me.uk`)"; service = "gitea-websecure"; tls = { certResolver = "default"; }; };
|
routers.gitea = { rule = "Host(`git.xenia.me.uk`)"; service = "gitea-websecure"; tls = { certResolver = "default"; }; };
|
||||||
services.gitea-websecure.loadBalancer.servers = [{ url = "http://localhost:3000"; }];
|
services.gitea-websecure.loadBalancer.servers = [{ url = "http://localhost:3000"; }];
|
||||||
};
|
};
|
||||||
# services.fail2ban.jails.gitea = ''
|
services.fail2ban.jails.gitea = ''
|
||||||
#
|
enabled = true
|
||||||
# '';
|
filter = sshd
|
||||||
|
ports = 2222
|
||||||
|
backend = systemd
|
||||||
|
'';
|
||||||
}
|
}
|
||||||
|
|
Loading…
Reference in a new issue