diff options
| author | Joe Mou <dev@mou.fo> | 2024-12-23 13:36:27 -0800 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2025-06-27 18:07:20 -0400 |
| commit | a13fb60da18e16c20c7a160eac6a9f700058e55a (patch) | |
| tree | 296f9269c4d74b27b4ae24efc774bb7ac14300f6 | |
| parent | 0389280b39c6945249011277f68ed1dab3cc8ba3 (diff) | |
Stripped down git hosting with cgit and git-shell
Advantages over Gitea (and most other git forges):
- Arbitrary repository hierarchies.
- Repository aliases with symlinks.
- No metadata to keep synchronized with repositories; simple automation.
Create new repos like:
$ sudo -u git git init --bare -b main /srv/git/2025/calmux.git
Ideally we would not require authentication for whitelisted public
repos. This is difficult with oauth2-proxy because to disable
auth_request we need a new location clause which does not "inherit" the
FastCGI configuration. Perhaps we could use cgit's built-in auth-filter.
Considered gitolite instead of git-shell (which would allow multiuser
authentication). This probably requires configuring each repo which
complicates automation.
| -rw-r--r-- | hostnix/elmo/git.nix | 33 |
1 files changed, 22 insertions, 11 deletions
diff --git a/hostnix/elmo/git.nix b/hostnix/elmo/git.nix index c032b5d..5084aae 100644 --- a/hostnix/elmo/git.nix +++ b/hostnix/elmo/git.nix @@ -1,23 +1,34 @@ -{ ... }: +{ pkgs, ... }: { - services.gitea = { + users.users.git = { + isSystemUser = true; + group = "git"; + home = "/srv/git"; + createHome = true; + homeMode = "755"; # allow nginx (and world) to read + shell = "${pkgs.git}/bin/git-shell"; + openssh.authorizedKeys.keys = [ + "restrict ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDHcqQDnH0LcUWFV+cd9aABfM55+72UAn1ZY5x5bHwPL4IEgT1nagbi1X3FwCJkh2rEcDsHl4FflcNfh+IyU2VyuQfRIXl7CKP040ovXmPVzgU8JiEDrrRebpZ7aHCKk+4Q6cJ8dzAI1sRogVyYrV0hLB4yeMnVexkIcsQMt5pXQ1zodlzHfW1W7OWQDbKjIyh4pv1KJ/IIjiBIt7l+OCqi7wZK4ubmxyMhmZx1xpRC5mz2/29Mpt+1VgCmxC7Hv1SG7yu+U0s4eJ3kbzFKNcZ/bCYqFxK48dT66qhS3qZFg09omumG8IbEUcx+WqM1V7WhiJYig9x5ovmMToQXTJ5uxLtcovnxO/53IgwV7INvmr8+NhD+LlkQfSjjUAW09bhVj9sKIW2bbrIxlOT8z6CQY9zGXNXi8u1oxPt3Q7d3rMxoWhWnr2l3Ok7OIkWooOK3e0NdhgIAxZKlYJAmIYaX391sGTyiuwUy96mg5JcYsLYMfkEg/Sv+2vQp8kkvB0E= joe@sparky" + ]; + }; + + users.groups.git = {}; + + services.cgit."git.mou.fo" = { enable = true; + scanPath = "/srv/git"; settings = { - server = { - ROOT_URL = "https://git.mou.fo/"; - PROTOCOL = "http+unix"; - DISABLE_REGISTRATION = true; - }; - session = { - COOKIE_SECURE = true; - }; + section-from-path = -1; + about-filter = "${pkgs.cgit}/lib/cgit/filters/about-formatting.sh"; + source-filter = "${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py"; }; }; services.nginx.virtualHosts."git.mou.fo" = { enableACME = true; forceSSL = true; - locations."/".proxyPass = "http://unix:/run/gitea/gitea.sock"; }; + + services.oauth2-proxy.nginx.virtualHosts = { "git.mou.fo" = {}; }; } |
