151 lines
4.7 KiB
Nix
151 lines
4.7 KiB
Nix
{ ... }: {
|
|
|
|
flake.nixosModules.gitea-docker = { config, lib, pkgs, ... }: let
|
|
|
|
subdomain = "gitea";
|
|
|
|
name = "gitea";
|
|
|
|
in {
|
|
|
|
config = {
|
|
|
|
networking.firewall.allowedTCPPorts = [ 2222 ];
|
|
sops.secrets = {
|
|
"gitea/dbpass" = {};
|
|
};
|
|
|
|
sops.templates."gitea.env".content = ''
|
|
USER_UID=1000
|
|
USER_GID=1000
|
|
GITEA__database__DB_TYPE=postgres
|
|
GITEA__database__HOST=${name}-db:5432
|
|
GITEA__database__NAME=gitea
|
|
GITEA__database__USER=gitea
|
|
GITEA__database__PASSWD=${config.sops.placeholder."gitea/dbpass"}
|
|
'';
|
|
|
|
sops.templates."gitea-db.env".content = ''
|
|
POSTGRES_USER=gitea
|
|
POSTGRES_DB=gitea
|
|
POSTGRES_PASSWORD=${config.sops.placeholder."gitea/dbpass"}
|
|
'';
|
|
|
|
virtualisation.oci-containers.containers."${name}" = {
|
|
image = "docker.gitea.com/gitea:1.25.4";
|
|
|
|
# unstable, waiting for 26.05
|
|
#pull = "newer";
|
|
|
|
hostname = "${subdomain}.esotericbytes.com";
|
|
|
|
networks = [
|
|
"docker-main"
|
|
];
|
|
|
|
labels = {
|
|
"traefik.enable" = "true";
|
|
"traefik.http.routers.${name}.entrypoints" = "websecure,localsecure";
|
|
"traefik.http.routers.${name}.rule" = "Host(`${subdomain}.esotericbytes.com`)";
|
|
"traefik.http.routers.${name}.service" = "${name}";
|
|
"traefik.http.routers.${name}.tls.certResolver" = "cloudflare";
|
|
|
|
"traefik.http.services.${name}.loadbalancer.server.port" = "3000";
|
|
|
|
|
|
"traefik.tcp.routers.${name}-ssh.entrypoints" = "gitea-ssh";
|
|
"traefik.tcp.routers.${name}-ssh.rule" = "HostSNI(`*`)";
|
|
"traefik.tcp.routers.${name}-ssh.service" = "${name}-ssh";
|
|
|
|
"traefik.tcp.services.${name}-ssh.loadbalancer.server.port" = "22";
|
|
};
|
|
|
|
extraOptions = [
|
|
"--ip=192.168.101.25"
|
|
];
|
|
|
|
volumes = [
|
|
"/etc/gitea/data:/data"
|
|
];
|
|
|
|
environmentFiles = [
|
|
config.sops.templates."gitea.env".path
|
|
];
|
|
|
|
dependsOn = [
|
|
"${name}-db"
|
|
];
|
|
};
|
|
|
|
virtualisation.oci-containers.containers."${name}-db" = {
|
|
image = "docker.io/library/postgres:14";
|
|
|
|
# unstable, waiting for 26.05
|
|
#pull = "newer";
|
|
|
|
hostname = "${name}-db";
|
|
|
|
networks = [
|
|
"docker-main"
|
|
];
|
|
|
|
extraOptions = [
|
|
"--ip=192.168.101.26"
|
|
];
|
|
|
|
volumes = [
|
|
"/etc/gitea/db:/var/lib/postgresql/data"
|
|
];
|
|
|
|
environmentFiles = [
|
|
config.sops.templates."gitea-db.env".path
|
|
];
|
|
};
|
|
|
|
systemd.services."docker-gitea" = {
|
|
serviceConfig = {
|
|
Restart = lib.mkOverride 90 "always";
|
|
RestartMaxDelaySec = lib.mkOverride 90 "1m";
|
|
RestartSec = lib.mkOverride 90 "100ms";
|
|
RestartSteps = lib.mkOverride 90 9;
|
|
};
|
|
after = [
|
|
"docker-network-setup.service"
|
|
"docker-gitea-db.service"
|
|
];
|
|
requires = [
|
|
"docker-network-setup.service"
|
|
"docker-gitea-db.service"
|
|
];
|
|
partOf = [
|
|
"docker-compose-gitea-root.target"
|
|
];
|
|
wantedBy = [
|
|
"docker-compose-gitea-root.target"
|
|
];
|
|
};
|
|
|
|
systemd.services."docker-gitea-db" = {
|
|
serviceConfig = {
|
|
Restart = lib.mkOverride 90 "always";
|
|
RestartMaxDelaySec = lib.mkOverride 90 "1m";
|
|
RestartSec = lib.mkOverride 90 "100ms";
|
|
RestartSteps = lib.mkOverride 90 9;
|
|
};
|
|
after = [
|
|
"docker-network-setup.service"
|
|
];
|
|
requires = [
|
|
"docker-network-setup.service"
|
|
];
|
|
partOf = [
|
|
"docker-compose-gitea-root.target"
|
|
];
|
|
wantedBy = [
|
|
"docker-compose-gitea-root.target"
|
|
];
|
|
};
|
|
};
|
|
};
|
|
}
|