2025-04-01 14:46:19 +00:00
|
|
|
# Edit this configuration file to define what should be installed on
|
|
|
|
# your system. Help is available in the configuration.nix(5) man page, on
|
|
|
|
# https://search.nixos.org/options and in the NixOS manual (`nixos-help`).
|
|
|
|
|
|
|
|
# NixOS-WSL specific options are documented on the NixOS-WSL repository:
|
|
|
|
# https://github.com/nix-community/NixOS-WSL
|
|
|
|
|
2025-04-24 15:23:51 +00:00
|
|
|
{
|
|
|
|
config,
|
|
|
|
lib,
|
|
|
|
pkgs,
|
|
|
|
...
|
|
|
|
}:
|
2025-04-01 14:46:19 +00:00
|
|
|
let
|
2025-04-24 15:23:51 +00:00
|
|
|
cfg = config.services.forgejo;
|
|
|
|
srv = cfg.settings.server;
|
2025-04-01 14:46:19 +00:00
|
|
|
in
|
|
|
|
{
|
2025-04-24 15:23:51 +00:00
|
|
|
imports = [
|
|
|
|
./shared/system.nix
|
|
|
|
./shared/dev_user.nix
|
|
|
|
./shared/docker.nix
|
|
|
|
./shared/ssh.nix
|
|
|
|
];
|
2025-04-03 09:48:30 +00:00
|
|
|
|
2025-05-22 10:49:23 +00:00
|
|
|
sops = {
|
2025-06-12 16:04:45 +00:00
|
|
|
defaultSopsFile = ./secrets/ssh-key.yaml;
|
2025-05-22 10:49:23 +00:00
|
|
|
age = {
|
2025-06-12 16:04:45 +00:00
|
|
|
sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
|
2025-05-22 10:49:23 +00:00
|
|
|
keyFile = "/root/.config/sops/age/keys.txt";
|
|
|
|
generateKey = true;
|
|
|
|
};
|
2025-06-12 16:04:45 +00:00
|
|
|
secrets."pipe-ssh-key" = { };
|
2025-05-22 10:49:23 +00:00
|
|
|
};
|
2025-05-05 16:04:08 +00:00
|
|
|
|
2025-06-12 16:04:45 +00:00
|
|
|
services.openssh.settings.AllowUsers = [ "pipeline" ];
|
|
|
|
|
2025-05-22 10:49:23 +00:00
|
|
|
users.users = {
|
|
|
|
# connection only via ssh key
|
|
|
|
pipeline = {
|
|
|
|
isNormalUser = true;
|
|
|
|
home = "/home/pipeline";
|
|
|
|
description = "User used by forgejo runners to connect to this system";
|
|
|
|
extraGroups = [ "docker" ];
|
|
|
|
};
|
|
|
|
};
|
2025-06-18 08:44:51 +00:00
|
|
|
|
|
|
|
services = {
|
|
|
|
mysql = {
|
|
|
|
enable = true;
|
|
|
|
package = pkgs.mariadb;
|
2025-06-19 06:28:41 +00:00
|
|
|
settings = {
|
|
|
|
mysqld = {
|
|
|
|
port = 8000;
|
|
|
|
};
|
|
|
|
};
|
2025-06-18 08:44:51 +00:00
|
|
|
};
|
|
|
|
};
|
2025-04-24 15:23:51 +00:00
|
|
|
}
|