From a13fb60da18e16c20c7a160eac6a9f700058e55a Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Mon, 23 Dec 2024 13:36:27 -0800 Subject: Stripped down git hosting with cgit and git-shell Advantages over Gitea (and most other git forges): - Arbitrary repository hierarchies. - Repository aliases with symlinks. - No metadata to keep synchronized with repositories; simple automation. Create new repos like: $ sudo -u git git init --bare -b main /srv/git/2025/calmux.git Ideally we would not require authentication for whitelisted public repos. This is difficult with oauth2-proxy because to disable auth_request we need a new location clause which does not "inherit" the FastCGI configuration. Perhaps we could use cgit's built-in auth-filter. Considered gitolite instead of git-shell (which would allow multiuser authentication). This probably requires configuring each repo which complicates automation. --- hostnix/elmo/git.nix | 33 ++++++++++++++++++++++----------- 1 file changed, 22 insertions(+), 11 deletions(-) (limited to 'hostnix/elmo') diff --git a/hostnix/elmo/git.nix b/hostnix/elmo/git.nix index c032b5d..5084aae 100644 --- a/hostnix/elmo/git.nix +++ b/hostnix/elmo/git.nix @@ -1,23 +1,34 @@ -{ ... }: +{ pkgs, ... }: { - services.gitea = { + users.users.git = { + isSystemUser = true; + group = "git"; + home = "/srv/git"; + createHome = true; + homeMode = "755"; # allow nginx (and world) to read + shell = "${pkgs.git}/bin/git-shell"; + openssh.authorizedKeys.keys = [ + "restrict ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDHcqQDnH0LcUWFV+cd9aABfM55+72UAn1ZY5x5bHwPL4IEgT1nagbi1X3FwCJkh2rEcDsHl4FflcNfh+IyU2VyuQfRIXl7CKP040ovXmPVzgU8JiEDrrRebpZ7aHCKk+4Q6cJ8dzAI1sRogVyYrV0hLB4yeMnVexkIcsQMt5pXQ1zodlzHfW1W7OWQDbKjIyh4pv1KJ/IIjiBIt7l+OCqi7wZK4ubmxyMhmZx1xpRC5mz2/29Mpt+1VgCmxC7Hv1SG7yu+U0s4eJ3kbzFKNcZ/bCYqFxK48dT66qhS3qZFg09omumG8IbEUcx+WqM1V7WhiJYig9x5ovmMToQXTJ5uxLtcovnxO/53IgwV7INvmr8+NhD+LlkQfSjjUAW09bhVj9sKIW2bbrIxlOT8z6CQY9zGXNXi8u1oxPt3Q7d3rMxoWhWnr2l3Ok7OIkWooOK3e0NdhgIAxZKlYJAmIYaX391sGTyiuwUy96mg5JcYsLYMfkEg/Sv+2vQp8kkvB0E= joe@sparky" + ]; + }; + + users.groups.git = {}; + + services.cgit."git.mou.fo" = { enable = true; + scanPath = "/srv/git"; settings = { - server = { - ROOT_URL = "https://git.mou.fo/"; - PROTOCOL = "http+unix"; - DISABLE_REGISTRATION = true; - }; - session = { - COOKIE_SECURE = true; - }; + section-from-path = -1; + about-filter = "${pkgs.cgit}/lib/cgit/filters/about-formatting.sh"; + source-filter = "${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py"; }; }; services.nginx.virtualHosts."git.mou.fo" = { enableACME = true; forceSSL = true; - locations."/".proxyPass = "http://unix:/run/gitea/gitea.sock"; }; + + services.oauth2-proxy.nginx.virtualHosts = { "git.mou.fo" = {}; }; } -- cgit v1.3.1