}];
services.duplyBackup.profiles.gitolite = {
rootDir = cfg.gitoliteDir;
+ remotes = [ "eriomem" "ovh" ];
};
networking.firewall.allowedTCPPorts = [ 9418 ];
+ secrets.keys = [{
+ dest = "gitolite/ldap_password";
+ user = "gitolite";
+ group = "gitolite";
+ permissions = "0400";
+ text = config.myEnv.tools.gitolite.ldap.password;
+ }];
+
services.gitDaemon = {
enable = true;
user = "gitolite";
} ''
makeWrapper "${./gitolite_ldap_groups.sh}" "$out" \
--prefix PATH : ${lib.makeBinPath deps} \
- --set LDAP_PASS ${pkgs.lib.escapeShellArg config.myEnv.tools.gitolite.ldap.password}
+ --set LDAP_PASS_PATH ${config.secrets.fullPaths."gitolite/ldap_password"}
'';
in {
deps = [ "users" ];
};
users.users.wwwrun.extraGroups = [ "gitolite" ];
+ users.users.gitolite.extraGroups = [ "keys" ];
users.users.gitolite.packages = let
python-packages = python-packages: with python-packages; [