cryodev/modules/nixos/forgejo/default.nix
steffen 5ba78886d2 Add SD image pipeline, documentation overhaul, and fix module issues
- Add automatic SD image builds for Raspberry Pi via Forgejo Actions
- Enable binfmt emulation on cryodev-main for aarch64 cross-builds
- Add sd-image.nix module to cryodev-pi configuration
- Create comprehensive docs/ structure with installation guides
- Split installation docs into: first-install (server), reinstall, new-client (Pi)
- Add lib/utils.nix and apps/rebuild from synix
- Fix headplane module for new upstream API (tale/headplane)
- Fix various module issues (mailserver stateVersion, option conflicts)
- Add placeholder secrets.yaml files for both hosts
- Remove old INSTRUCTIONS.md (content moved to docs/)
2026-03-11 08:41:58 +01:00

63 lines
1.5 KiB
Nix

{
config,
lib,
...
}:
let
cfg = config.services.forgejo;
inherit (cfg) settings;
inherit (lib)
getExe
head
mkDefault
mkIf
;
in
{
config = mkIf cfg.enable {
services.forgejo = {
database.type = mkDefault "postgres";
lfs.enable = mkDefault true;
settings = {
server = {
DOMAIN = mkDefault "git.${config.networking.domain}";
PROTOCOL = mkDefault "http";
ROOT_URL = mkDefault "https://${settings.server.DOMAIN}/";
HTTP_ADDR = mkDefault "0.0.0.0";
HTTP_PORT = mkDefault 3456;
SSH_PORT = mkDefault (head config.services.openssh.ports);
};
service = {
DISABLE_REGISTRATION = mkDefault true;
};
ui = {
DEFAULT_THEME = mkDefault "forgejo-dark";
};
actions = {
ENABLED = mkDefault true;
};
mailer = {
ENABLED = mkDefault false;
SMTP_ADDR = mkDefault "mail.${config.networking.domain}";
FROM = mkDefault "git@${settings.server.DOMAIN}";
USER = mkDefault "git@${settings.server.DOMAIN}";
};
};
secrets = {
mailer.PASSWD = mkIf settings.mailer.ENABLED config.sops.secrets."forgejo/mail-pw".path;
};
};
environment.shellAliases = {
forgejo = "sudo -u ${cfg.user} ${getExe cfg.package} --config ${cfg.stateDir}/custom/conf/app.ini";
};
sops.secrets."forgejo/mail-pw" = mkIf settings.mailer.ENABLED {
owner = cfg.user;
group = cfg.group;
mode = "0400";
};
};
}