diff --git a/hosts/profiles/gitea/default.nix b/hosts/profiles/gitea/default.nix index 26eea47..b35a307 100644 --- a/hosts/profiles/gitea/default.nix +++ b/hosts/profiles/gitea/default.nix @@ -1,4 +1,10 @@ -{ self, config, lib, pkgs, ... }: +{ + self, + config, + lib, + pkgs, + ... +}: { age.secrets.gitea-dbpass.file = "${self}/secrets/gitea-dbpass.age"; @@ -55,7 +61,7 @@ isSystemUser = true; }; - users.groups.gitea = {}; + users.groups.gitea = { }; environment.systemPackages = [ pkgs.pandoc ]; services.postgresql = { @@ -69,27 +75,82 @@ # gitea-users postgres gitea # ''; ensureDatabases = [ "gitea" ]; - ensureUsers = [{ - name = "gitea"; - ensureDBOwnership = true; - }]; + ensureUsers = [ + { + name = "gitea"; + ensureDBOwnership = true; + } + ]; # TODO - # initialScript + # initialScript # set password for gitea user }; + # Anubis proof-of-work bot protection in front of Forgejo + services.anubis.instances."gitea" = { + settings = { + TARGET = "http://localhost:3001"; + BIND = "/run/anubis/anubis-gitea/anubis.sock"; + METRICS_BIND = "/run/anubis/anubis-gitea/metrics.sock"; + }; + botPolicy = { + bots = [ + # Allow git CLI clients through without challenge + { + name = "git-client"; + user_agent_regex = "^git/"; + action = "ALLOW"; + } + # Allow Go module fetches (go get) + { + name = "go-http-client"; + user_agent_regex = "^Go-http-client"; + action = "ALLOW"; + } + # Allow well-known paths and static assets + { + name = "well-known"; + path_regex = "^/.well-known/.*$"; + action = "ALLOW"; + } + { + name = "favicon"; + path_regex = "^/favicon\\.ico$"; + action = "ALLOW"; + } + { + name = "robots-txt"; + path_regex = "^/robots\\.txt$"; + action = "ALLOW"; + } + # Challenge browser-like user agents (scrapers, bots pretending to be browsers) + { + name = "generic-browser"; + user_agent_regex = "Mozilla"; + action = "CHALLENGE"; + } + ]; + }; + }; + + # nginx needs access to the Anubis unix socket + users.users.nginx.extraGroups = [ config.users.groups.anubis.name ]; + services.nginx = { - enable = true; # Enable Nginx + enable = true; recommendedGzipSettings = true; recommendedOptimisation = true; recommendedProxySettings = true; recommendedTlsSettings = true; virtualHosts."git.sealight.xyz" = { - # Gitea hostname - enableACME = true; # Use ACME certs - forceSSL = true; # Force SSL - locations."/".proxyPass = "http://localhost:3001/"; # Proxy Gitea + enableACME = true; + forceSSL = true; + locations."/".proxyPass = "http://unix:${config.services.anubis.instances.gitea.settings.BIND}"; }; }; - networking.firewall.allowedTCPPorts = [ 80 443 22 ]; + networking.firewall.allowedTCPPorts = [ + 80 + 443 + 22 + ]; }