git-pages.services.default: init

Co-authored-by: Tom Oostveen <tomoostveen.06@gmail.com>
Co-authored-by: Bart Oostveen <bart@bartoostveen.nl>
Signed-off-by: phanirithvij <phanirithvij2000@gmail.com>
This commit is contained in:
phanirithvij
2026-08-19 20:59:11 +05:30
parent 68233f87c1
commit 775afc1dbc
5 changed files with 207 additions and 1 deletions

View File

@@ -24,6 +24,7 @@ let
"<imports = [ pkgs.autopush-rs.services.autoendpoint ]>" =
fakeSubmodule pkgs.autopush-rs.services.autoendpoint;
"<imports = [ pkgs.ghostunnel.services.default ]>" = fakeSubmodule pkgs.ghostunnel.services.default;
"<imports = [ pkgs.git-pages.services.default ]>" = fakeSubmodule pkgs.git-pages.services.default;
"<imports = [ pkgs.ktls-utils.services.default ]>" = fakeSubmodule pkgs.ktls-utils.services.default;
"<imports = [ pkgs.php.services.default ]>" = fakeSubmodule pkgs.php.services.default;
"<imports = [ pkgs.snid.services.default ]>" = fakeSubmodule pkgs.snid.services.default;

View File

@@ -697,6 +697,7 @@ in
geth = runTest ./geth.nix;
ghostunnel = runTest ./ghostunnel.nix;
ghostunnel-modular = runTest ./ghostunnel-modular.nix;
git-pages-modular = runTest ./git-pages.nix;
gitdaemon = runTest ./gitdaemon.nix;
gitea = import ./gitea.nix {
inherit pkgs runTest;

65
nixos/tests/git-pages.nix Normal file
View File

@@ -0,0 +1,65 @@
{ pkgs, ... }:
{
name = "git-pages-modular-service";
nodes.machine = { pkgs, ... }: {
environment.systemPackages = [ pkgs.curl ];
system.services.git-pages = {
imports = [ pkgs.git-pages.services.default ];
git-pages = {
settings.server = {
pages = "tcp/:3000";
caddy = "tcp/:3001";
metrics = "tcp/:3002";
};
};
systemd.service.environment.PAGES_INSECURE = "1";
};
services.caddy = {
enable = true;
configFile = pkgs.writeText "Caddyfile" ''
{
admin off
persist_config off
auto_https disable_redirects
on_demand_tls {
permission http http://localhost:3001
}
}
https://, http:// {
tls {
on_demand
}
reverse_proxy http://localhost:3000
}
'';
};
networking.firewall.allowedTCPPorts = [ 80 ];
};
testScript =
let
testSite = pkgs.runCommand "git-pages-testsite.tar" { } ''
echo It works! > index.html
tar cvf $out index.html
'';
in
''
start_all()
machine.wait_for_unit("caddy.service")
machine.wait_for_open_port(80)
machine.wait_for_unit("git-pages.service")
machine.wait_for_open_port(3001)
machine.wait_for_open_port(3002)
machine.fail("curl -f http://localhost/.git-pages/health")
machine.succeed("curl -f http://localhost/ -X PUT --data-binary @${testSite} --header 'Content-Type: application/x-tar'")
machine.wait_until_succeeds("test -f /var/lib/git-pages/data/site/localhost/.index")
machine.succeed("curl -f http://localhost/.git-pages/health")
machine.succeed("curl -f http://localhost/ | grep -F 'It works!'")
machine.succeed("curl -f http://localhost:3002/metrics")
'';
}

View File

@@ -2,8 +2,12 @@
lib,
buildGoModule,
fetchFromCodeberg,
fetchpatch,
nix-update-script,
versionCheckHook,
formats,
coreutils,
nixosTests,
}:
buildGoModule (finalAttrs: {
@@ -18,6 +22,16 @@ buildGoModule (finalAttrs: {
hash = "sha256-4yQ3RRJbOfMaqjJJ6CRRN7TuaYY8ScLXxMZPd4tWPwk=";
};
patches = [
# bugfix to avoid creating parent directory on start
# remove when https://codeberg.org/git-pages/git-pages/pulls/258 is available in the release
(fetchpatch {
name = "mkdirall-parent-dir-create.patch";
url = "https://codeberg.org/git-pages/git-pages/commit/507e57edbcfc0ec933a877bf26b1756ca0a61870.patch";
hash = "sha256-1CjU4yGmDOmYsxo3U44Cg2xLJkrmUOX5ZXTycdLs6OE=";
})
];
subPackages = [ "." ];
vendorHash = "sha256-NNIkzgRki2rtCVUnnhT44rEBcMZYiJPmsXySpxiHYR0=";
@@ -31,7 +45,16 @@ buildGoModule (finalAttrs: {
nativeInstallCheckInputs = [ versionCheckHook ];
versionCheckProgramArg = "-version";
passthru.updateScript = nix-update-script { };
passthru = {
tests = { inherit (nixosTests) git-pages-modular; };
updateScript = nix-update-script { };
services.default = {
imports = [
(lib.modules.importApply ./service.nix { inherit formats coreutils; })
];
git-pages.package = finalAttrs.finalPackage;
};
};
meta = {
description = "Scalable static site server for Git forges (like GitHub Pages or Netlify";

View File

@@ -0,0 +1,116 @@
# Non-module dependencies (`importApply`)
{ formats, coreutils }:
{
config,
lib,
options,
name,
...
}:
let
cfg = config.git-pages;
settingsFormat = formats.toml { };
configFile = "git-pages.toml";
configOutPath = config.configData.${configFile}.path;
in
{
_class = "service";
meta.maintainers = with lib.maintainers; [
dtomvan
phanirithvij
];
options.git-pages = {
package = lib.mkOption {
description = "Package to use for git-pages";
defaultText = "The git-pages package that provided this module.";
type = lib.types.package;
};
secretFile = lib.mkOption {
description = ''
File that contains secrets for the git-pages config.
If values in this file are set, any options specified take priority over the options set in
{option}`git-pages.settings`.
::: {.note}
See the [git-pages documentation](https://git-pages.org/running-a-server/#configuration) on
secrets and environment variables.
:::
'';
default = null;
type = lib.types.nullOr lib.types.str;
};
settings = lib.mkOption {
type = settingsFormat.type;
description = ''
Settings to set in config.toml.
::: {.note}
See the [git-pages documentation](https://git-pages.org/running-a-server/#configuration) on configuring the server.
:::
'';
default = { };
};
};
config = {
git-pages.settings.storage.fs.root = lib.mkDefault "/var/lib/${name}/data";
process.argv = [
(lib.getExe cfg.package)
"-config"
configOutPath
];
configData."${configFile}".source = settingsFormat.generate configFile cfg.settings;
}
// lib.optionalAttrs (options ? systemd) {
systemd.service = {
description = "Forge-agnostic static site server";
documentation = [ "https://git-pages.org/running-a-server/" ];
after = [ "network.target" ];
wants = [ "network.target" ];
wantedBy = [ "multi-user.target" ];
restartTriggers = [ config.configData."${configFile}".source ];
serviceConfig = {
Restart = "always";
StateDirectory = name;
WorkingDirectory = "%S/${name}";
BindReadOnlyPaths = [ configOutPath ];
LoadCredential = lib.optional (cfg.secretFile != null) "secrets.toml:${cfg.secretFile}";
User = name;
DynamicUser = true;
# systemd service hardening
ProtectHome = true;
MemoryDenyWriteExecute = true;
PrivateDevices = true;
PrivateTmp = true;
ProtectSystem = "strict";
ProtectControlGroups = true;
RestrictSUIDSGID = true;
RestrictRealtime = true;
RestrictAddressFamilies = "AF_INET AF_INET6 AF_UNIX";
RestrictNamespaces = true;
LockPersonality = true;
ProtectKernelLogs = true;
ProtectKernelTunables = true;
ProtectHostname = true;
ProtectKernelModules = true;
PrivateUsers = true;
ProtectClock = true;
SystemCallArchitectures = "native";
SystemCallErrorNumber = "EPERM";
SystemCallFilter = "@system-service";
};
};
};
}