diff options
| author | Joe Carstairs <me@joeac.net> | 2026-08-25 22:40:31 +0100 |
|---|---|---|
| committer | Joe Carstairs <me@joeac.net> | 2026-08-25 22:40:31 +0100 |
| commit | a697431cedc9bb005f38d209c18657db4f31a596 (patch) | |
| tree | 470213f17ae6161a3c7f494027ebef9448932b4f /roles/git/templates | |
| parent | 001a480ba1ea8327434873b59a00d8352c1a61c6 (diff) | |
serves git over https:// and git://
Diffstat (limited to 'roles/git/templates')
| -rw-r--r-- | roles/git/templates/nginx/cgit.conf | 20 | ||||
| -rw-r--r-- | roles/git/templates/nginx/git.joeac.net.conf | 42 |
2 files changed, 42 insertions, 20 deletions
diff --git a/roles/git/templates/nginx/cgit.conf b/roles/git/templates/nginx/cgit.conf deleted file mode 100644 index 7d29608..0000000 --- a/roles/git/templates/nginx/cgit.conf +++ /dev/null @@ -1,20 +0,0 @@ -server { - listen {{ services.git.port }}; - listen [::]:{{ services.git.port }}; - server_name {{ ( subdomains | selectattr('service', 'eq', 'git') | first ).full_domain }}; - - root /usr/share/webapps/cgit; - try_files $uri @cgit; - - access_log /var/log/nginx/git.joeac.net/access.log; - error_log /var/log/nginx/git.joeac.net/error.log; - - location @cgit { - include fastcgi_params; - fastcgi_param SCRIPT_FILENAME /usr/share/webapps/cgit/cgit.cgi; - fastcgi_param PATH_INFO $uri; - fastcgi_param QUERY_STRING $args; - fastcgi_param HTTP_HOST $server_name; - fastcgi_pass unix:/run/fcgiwrap/fcgiwrap.sock; - } -} diff --git a/roles/git/templates/nginx/git.joeac.net.conf b/roles/git/templates/nginx/git.joeac.net.conf new file mode 100644 index 0000000..e09a655 --- /dev/null +++ b/roles/git/templates/nginx/git.joeac.net.conf @@ -0,0 +1,42 @@ +server { + listen {{ services.git.port }}; + listen [::]:{{ services.git.port }}; + server_name {{ ( subdomains | selectattr('service', 'eq', 'git') | first ).full_domain }}; + + root /usr/share/webapps/cgit; + try_files $uri @cgit; + + access_log /var/log/nginx/git.joeac.net/access.log; + error_log /var/log/nginx/git.joeac.net/error.log; + + location ~ /(.+)/(HEAD|info/refs|objects|git-upload-pack|git-receive-pack) { + if (-f /srv/git/$1/git-daemon-export-ok) { + set $auth_basic "private-write repository"; + } + if (!-f /srv/git/$1/git-daemon-export-ok) { + set $auth_basic "private repository"; + } + if ($arg_service != git-receive-pack) { + set $auth_basic off; + } + auth_basic $auth_basic; + auth_basic_user_file .htpasswd; + include fastcgi_params; + fastcgi_param SCRIPT_FILENAME /usr/libexec/git-core/git-http-backend; + fastcgi_param PATH_INFO $uri; + fastcgi_param GIT_PROJECT_ROOT /srv/git; + fastcgi_param GIT_HTTP_EXPORT_ALL 1; + fastcgi_param REMOTE_USER $remote_user; + fastcgi_param HOME /srv/git; + fastcgi_pass unix:{{ fcgiwrap_socket }}; + } + + location @cgit { + include fastcgi_params; + fastcgi_param SCRIPT_FILENAME /usr/share/webapps/cgit/cgit.cgi; + fastcgi_param PATH_INFO $uri; + fastcgi_param QUERY_STRING $args; + fastcgi_param HTTP_HOST $server_name; + fastcgi_pass unix:{{ fcgiwrap_socket }}; + } +} |
