From 50fae6ee55042b91841717133a42944c106fad5c Mon Sep 17 00:00:00 2001 From: patrick-scho Date: Wed, 3 Dec 2025 18:24:26 +0100 Subject: add container to flake --- flake.nix | 90 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 90 insertions(+) diff --git a/flake.nix b/flake.nix index 2248cce..04d7293 100644 --- a/flake.nix +++ b/flake.nix @@ -45,6 +45,96 @@ }) { } ) { }; }); + nixosConfigurations.container = nixpkgs.lib.nixosSystem { + system = "x86_64-linux"; + modules = + [ ({ pkgs, ... }: { + boot.isContainer = true; + + nix.settings.experimental-features = [ "nix-command" "flakes" ]; + + system.stateVersion = "26.05"; + + networking.useDHCP = false; + networking.firewall.allowedTCPPorts = [ 22 80 ]; + + services.openssh.enable = true; + users.users.root.openssh.authorizedKeys.keys = [ "${builtins.readFile "/home/ps/.ssh/id_ed25519.pub"}" ]; + + users.users.git = { + isSystemUser = true; + group = "git"; + home = "/srv/git"; + createHome = true; + # homeMode = "750"; + shell = "${pkgs.git}/bin/git-shell"; + openssh.authorizedKeys.keys = [ "${builtins.readFile "/home/ps/.ssh/id_ed25519.pub"}" ]; + packages = [ pkgs.git ]; + }; + users.groups.git = {}; + + services.fcgiwrap.instances.cgit = { + process.user = "git"; + process.group = "root"; + socket.user = "caddy"; + socket.group = "caddy"; + }; + + services.caddy.enable = true; + services.caddy.extraConfig = '' + http://10.233.2.2 { + handle_path /git/* { + handle_path /static/* { + file_server { + root ${self.packages.${pkgs.stdenv.hostPlatform.system}.default}/cgit + } + } + handle { + reverse_proxy unix//run/fcgiwrap-cgit.sock { + transport fastcgi { + env CGIT_CONFIG ${pkgs.writeText "cgitrc" '' + snapshots=tar tar.gz zip + enable-git-config=1 + enable-index-owner=0 + enable-log-filecount=1 + enable-log-linecount=1 + section-from-path=1 + virtual-root=/git + css=/git/static/cgit.css + logo=/git/static/cgit.png + favicon=/git/static/favicon.ico + module-link=/git/%s/commit/?id=%s + clone-url=https://$HTTP_HOST/git/$CGIT_REPO_URL git://$HTTP_HOST/$CGIT_REPO_URL git@$HTTP_HOST:$CGIT_REPO_URL + noplainemail=1 + repository-sort=age + about-filter=${pkgs.writeShellScript "markdown-filter" '' + echo '