tv: modularize nginx

This commit is contained in:
tv 2015-06-22 18:20:25 +02:00
parent f2c8dbe4d1
commit 964855f30b
6 changed files with 121 additions and 72 deletions

View File

@ -6,10 +6,16 @@ let
cfg = config.services.git; cfg = config.services.git;
location = lib.nameValuePair; # TODO this is also in modules/wu/default.nix
isPublicRepo = getAttr "public"; # TODO this is also in ./default.nix isPublicRepo = getAttr "public"; # TODO this is also in ./default.nix
in in
{ {
imports = [
../../tv/nginx
];
config = mkIf cfg.cgit { config = mkIf cfg.cgit {
users.extraUsers = lib.singleton { users.extraUsers = lib.singleton {
@ -66,46 +72,26 @@ in
'') (filter isPublicRepo (attrValues cfg.repos))} '') (filter isPublicRepo (attrValues cfg.repos))}
''; '';
# TODO modular nginx configuration tv.nginx = {
services.nginx = enable = true;
let retiolum-locations = [
name = config.networking.hostName; (location "/cgit/" ''
qname = "${name}.retiolum"; include ${pkgs.nginx}/conf/fastcgi_params;
in fastcgi_param SCRIPT_FILENAME ${pkgs.cgit}/cgit/cgit.cgi;
{ fastcgi_split_path_info ^(/cgit/?)(.+)$;
enable = true; fastcgi_param PATH_INFO $fastcgi_path_info;
httpConfig = '' fastcgi_param QUERY_STRING $args;
include ${pkgs.nginx}/conf/mime.types; fastcgi_param HTTP_HOST $server_name;
default_type application/octet-stream; fastcgi_pass unix:${config.services.fcgiwrap.socketAddress};
sendfile on; '')
keepalive_timeout 65; (location "= /cgit" ''
gzip on; return 301 /cgit/;
server { '')
listen 80; (location "/cgit-static/" ''
server_name ${name} ${qname} localhost; root ${pkgs.cgit}/cgit;
root ${pkgs.cgit}/cgit; rewrite ^/cgit-static(/.*)$ $1 break;
'')
location /cgit-static { ];
rewrite ^/cgit-static(/.*)$ $1 break; };
#expires 30d;
}
location /cgit {
include ${pkgs.nginx}/conf/fastcgi_params;
fastcgi_param SCRIPT_FILENAME $document_root/cgit.cgi;
#fastcgi_param PATH_INFO $uri;
fastcgi_split_path_info ^(/cgit/?)(.+)$;
fastcgi_param PATH_INFO $fastcgi_path_info;
fastcgi_param QUERY_STRING $args;
fastcgi_param HTTP_HOST $server_name;
fastcgi_pass unix:${config.services.fcgiwrap.socketAddress};
}
location / {
return 404;
}
}
'';
};
}; };
} }

View File

@ -1,30 +0,0 @@
{ config, pkgs, ... }:
{
services.nginx =
let
name = config.networking.hostName;
qname = "${name}.retiolum";
in
{
enable = true;
httpConfig = ''
sendfile on;
server {
listen 80;
server_name ${name} ${qname} localhost;
root /srv/http/${name};
location ~ ^/~(.+?)(/.*)?$ {
alias /home/$1/public_html$2;
}
}
types {
text/css css;
text/html html;
image/svg+xml svg;
}
default_type text/html;
charset utf-8;
'';
};
}

View File

@ -0,0 +1,49 @@
{ cfg, config, lib, pkgs, ... }:
let
inherit (lib) concatStrings replaceChars;
indent = replaceChars ["\n"] ["\n "];
to-location = { name, value }: ''
location ${name} {
${indent value}
}
'';
in
{
services.nginx =
let
name = config.services.retiolum.name;
qname = "${name}.retiolum";
in
assert config.services.retiolum.enable;
{
enable = true;
httpConfig = ''
include ${pkgs.nginx}/conf/mime.types;
default_type application/octet-stream;
sendfile on;
keepalive_timeout 65;
gzip on;
server {
listen 80 default_server;
server_name _;
location / {
return 404;
}
}
server {
listen 80;
server_name ${name} ${qname};
${indent (concatStrings (map to-location cfg.retiolum-locations))}
location / {
return 404;
}
}
'';
};
}

View File

@ -0,0 +1,11 @@
arg@{ config, pkgs, lib, ... }:
let
cfg = config.tv.nginx;
arg' = arg // { inherit cfg; };
in
{
options.tv.nginx = import ./options.nix arg';
config = lib.mkIf cfg.enable (import ./config.nix arg');
}

View File

@ -0,0 +1,21 @@
{ lib, ... }:
let
inherit (lib) mkOption types;
in
{
enable = mkOption {
type = types.bool;
default = false;
description = "Enable nginx.";
};
retiolum-locations = mkOption {
type = with types; listOf (attrsOf str);
default = [];
description = ''
TODO
'';
};
}

View File

@ -4,6 +4,8 @@ let
lib = import ../../lib { lib = pkgs.lib; inherit pkgs; }; lib = import ../../lib { lib = pkgs.lib; inherit pkgs; };
inherit (lib) majmin; inherit (lib) majmin;
location = pkgs.lib.nameValuePair; # TODO this is also in modules/tv/git/cgit.nix
in in
{ {
@ -12,7 +14,6 @@ in
../common/nixpkgs.nix ../common/nixpkgs.nix
../tv/base.nix ../tv/base.nix
../tv/exim-retiolum.nix ../tv/exim-retiolum.nix
../tv/nginx.nix
../tv/retiolum.nix ../tv/retiolum.nix
../tv/sanitize.nix ../tv/sanitize.nix
../tv/smartd.nix ../tv/smartd.nix
@ -33,6 +34,17 @@ in
]; ];
}; };
} }
{
imports = [ ../tv/nginx ];
tv.nginx = {
enable = true;
retiolum-locations = [
(location "~ ^/~(.+?)(/.*)?\$" ''
alias /home/$1/public_html$2;
'')
];
};
}
]; ];
nix.maxJobs = 8; nix.maxJobs = 8;