aboutsummaryrefslogtreecommitdiff
path: root/modules/cgit.nix
diff options
context:
space:
mode:
authorKaran Jayachandra <mail@karanjayachandra.com>2026-07-18 23:04:53 +0200
committerKaran Jayachandra <mail@karanjayachandra.com>2026-07-18 23:04:53 +0200
commit9ceddb33272e5fca6382c1b4dec2074bd1167738 (patch)
treecac68c1bdc90c9ab618e4fdb4c8eb65d27d9a647 /modules/cgit.nix
parent718a79f8de2a55f2ab83cac7e8595cd3916ed486 (diff)
Simplify config and add AdGuard DoH/DoT support
- Replace the hand-rolled Podman OCI container for Actual Budget with the native services.actual module (available in the pinned nixpkgs release); the container never actually had a backend enabled, so it likely never ran. - Collapse cgit's Caddy routing to a single reverse proxy - the smart-HTTP git backend was already served on the same nginx vhost/port as cgit itself, so the separate /git/* -> 8085 route was dead and pointed at a port nothing listened on. - Drop the unused kvm-intel kernel module from the guest hardware profile, and rename disko's misleadingly-named ESP partition (it's ext4, not a real EFI System Partition). - Point common.nix's disabled autoUpgrade flake URL at this repo's own cgit hosting instead of a generic GitHub placeholder. - Add AdGuard Home DNS-over-TLS (853) and DNS-over-HTTPS (8443) support, backed by an independent ACME certificate (modules/acme.nix) issued via a webroot Caddy serves on port 80. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Diffstat (limited to 'modules/cgit.nix')
-rw-r--r--modules/cgit.nix14
1 files changed, 8 insertions, 6 deletions
diff --git a/modules/cgit.nix b/modules/cgit.nix
index 058fc79..de15e08 100644
--- a/modules/cgit.nix
+++ b/modules/cgit.nix
@@ -8,12 +8,14 @@
# - git clone/pull over HTTPS: public, read-only via git-http-backend
# - git push: SSH only, using the "git" user + your authorized keys
#
-# Caddy routes:
-# /git/* -> fcgiwrap serving git-http-backend (port 8085 via nginx shim)
-# /* -> cgit (port 8086 via nginx shim)
-#
-# Both cgit and git-http-backend are served through a minimal nginx instance
-# bound to localhost, which Caddy then reverse-proxies.
+# The NixOS cgit module serves both cgit browsing and git-http-backend
+# (clone/pull, via gitHttpBackend.enable which defaults to true) on the
+# *same* nginx vhost/location - nginx tells them apart by matching the
+# request path against a regex (.../info/refs|git-upload-pack for the
+# smart-HTTP protocol), not by a separate port. That combined vhost is
+# bound to localhost:8086 below, and Caddy reverse-proxies everything
+# for git.karanj.com straight to it. Only git-upload-pack is wired up, so
+# push over HTTP is impossible regardless - push stays SSH-only.
{
# Dedicated git user for SSH push access
users.users.git = {