summaryrefslogtreecommitdiff
path: root/roles/git/templates/nginx/git.joeac.net.conf
diff options
context:
space:
mode:
authorJoe Carstairs <me@joeac.net>2026-08-25 22:40:31 +0100
committerJoe Carstairs <me@joeac.net>2026-08-25 22:40:31 +0100
commita697431cedc9bb005f38d209c18657db4f31a596 (patch)
tree470213f17ae6161a3c7f494027ebef9448932b4f /roles/git/templates/nginx/git.joeac.net.conf
parent001a480ba1ea8327434873b59a00d8352c1a61c6 (diff)
serves git over https:// and git://
Diffstat (limited to 'roles/git/templates/nginx/git.joeac.net.conf')
-rw-r--r--roles/git/templates/nginx/git.joeac.net.conf42
1 files changed, 42 insertions, 0 deletions
diff --git a/roles/git/templates/nginx/git.joeac.net.conf b/roles/git/templates/nginx/git.joeac.net.conf
new file mode 100644
index 0000000..e09a655
--- /dev/null
+++ b/roles/git/templates/nginx/git.joeac.net.conf
@@ -0,0 +1,42 @@
+server {
+ listen {{ services.git.port }};
+ listen [::]:{{ services.git.port }};
+ server_name {{ ( subdomains | selectattr('service', 'eq', 'git') | first ).full_domain }};
+
+ root /usr/share/webapps/cgit;
+ try_files $uri @cgit;
+
+ access_log /var/log/nginx/git.joeac.net/access.log;
+ error_log /var/log/nginx/git.joeac.net/error.log;
+
+ location ~ /(.+)/(HEAD|info/refs|objects|git-upload-pack|git-receive-pack) {
+ if (-f /srv/git/$1/git-daemon-export-ok) {
+ set $auth_basic "private-write repository";
+ }
+ if (!-f /srv/git/$1/git-daemon-export-ok) {
+ set $auth_basic "private repository";
+ }
+ if ($arg_service != git-receive-pack) {
+ set $auth_basic off;
+ }
+ auth_basic $auth_basic;
+ auth_basic_user_file .htpasswd;
+ include fastcgi_params;
+ fastcgi_param SCRIPT_FILENAME /usr/libexec/git-core/git-http-backend;
+ fastcgi_param PATH_INFO $uri;
+ fastcgi_param GIT_PROJECT_ROOT /srv/git;
+ fastcgi_param GIT_HTTP_EXPORT_ALL 1;
+ fastcgi_param REMOTE_USER $remote_user;
+ fastcgi_param HOME /srv/git;
+ fastcgi_pass unix:{{ fcgiwrap_socket }};
+ }
+
+ location @cgit {
+ include fastcgi_params;
+ fastcgi_param SCRIPT_FILENAME /usr/share/webapps/cgit/cgit.cgi;
+ fastcgi_param PATH_INFO $uri;
+ fastcgi_param QUERY_STRING $args;
+ fastcgi_param HTTP_HOST $server_name;
+ fastcgi_pass unix:{{ fcgiwrap_socket }};
+ }
+}