in
{
nixpkgs.config.packageOverrides = oldpkgs: rec {
- gitolite = nixpkgs_unstable.gitolite;
+ gitolite = oldpkgs.gitolite.overrideAttrs(old: rec {
+ name = "gitolite-${version}";
+ version = "3.6.10";
+ src = pkgs.fetchFromGitHub {
+ owner = "sitaramc";
+ repo = "gitolite";
+ rev = "v${version}";
+ sha256 = "0p2697mn6rwm03ndlv7q137zczai82n41aplq1g006ii7f12xy8h";
+ };
+ });
gitweb = oldpkgs.gitweb.overrideAttrs(old: {
installPhase = old.installPhase + ''
cp -r ${./packages/gitweb} $out/gitweb-theme;
cmakeFlags = old.cmakeFlags ++ [ "-DWITH_AUTHENTICATION_PAM=ON" ];
buildInputs = old.buildInputs ++ [ pkgs.pam ];
});
+ goaccess = oldpkgs.goaccess.overrideAttrs(old: rec {
+ name = "goaccess-${version}";
+ version = "1.3";
+ src = pkgs.fetchurl {
+ url = "https://tar.goaccess.io/${name}.tar.gz";
+ sha256 = "16vv3pj7pbraq173wlxa89jjsd279004j4kgzlrsk1dz4if5qxwc";
+ };
+ configureFlags = old.configureFlags ++ [ "--enable-tcb=btree" ];
+ buildInputs = old.buildInputs ++ [ pkgs.tokyocabinet pkgs.bzip2 ];
+ });
};
networking = {
in [
pkgs.telnet
pkgs.vim
+ pkgs.goaccess
occ
];
security.acme.certs = {
+ # /!\ To create a new certificate, add first the domain to an
+ # existing certificate, deploy, and then use it in httpd.
"eldiron" = {
webroot = "/var/lib/acme/acme-challenge";
email = "ismael@bouya.org";
"connexionswing.immae.eu" = null;
"sandetludo.immae.eu" = null;
"cloud.immae.eu" = null;
+ "ludivine.immae.eu" = null;
+ "dev.aten.pro" = null;
+ "piedsjaloux.immae.eu" = null;
+ };
+ };
+ "ludivinecassal" = {
+ webroot = "/var/lib/acme/acme-challenge";
+ email = "ismael@bouya.org";
+ domain = "ludivinecassal.com";
+ plugins = [ "cert.pem" "chain.pem" "fullchain.pem" "full.pem" "key.pem" "account_key.json" ];
+ postRun = ''
+ systemctl reload httpd.service
+ '';
+ extraDomains = {
+ "www.ludivinecassal.com" = null;
+ };
+ };
+ "aten" = {
+ webroot = "/var/lib/acme/acme-challenge";
+ email = "ismael@bouya.org";
+ domain = "aten.pro";
+ plugins = [ "cert.pem" "chain.pem" "fullchain.pem" "full.pem" "key.pem" "account_key.json" ];
+ postRun = ''
+ systemctl reload httpd.service
+ '';
+ extraDomains = {
+ "www.aten.pro" = null;
+ };
+ };
+ "piedsjaloux" = {
+ webroot = "/var/lib/acme/acme-challenge";
+ email = "ismael@bouya.org";
+ domain = "piedsjaloux.fr";
+ plugins = [ "cert.pem" "chain.pem" "fullchain.pem" "full.pem" "key.pem" "account_key.json" ];
+ postRun = ''
+ systemctl reload httpd.service
+ '';
+ extraDomains = {
+ "www.piedsjaloux.fr" = null;
};
};
# "connexionswing" = {
adminer = mypkgs.adminer.phpFpm.pool;
connexionswing_dev = mypkgs.connexionswing_dev.phpFpm.pool;
connexionswing_prod = mypkgs.connexionswing_prod.phpFpm.pool;
+ ludivinecassal_dev = mypkgs.ludivinecassal_dev.phpFpm.pool;
+ ludivinecassal_prod = mypkgs.ludivinecassal_prod.phpFpm.pool;
+ piedsjaloux_dev = mypkgs.piedsjaloux_dev.phpFpm.pool;
+ piedsjaloux_prod = mypkgs.piedsjaloux_prod.phpFpm.pool;
+ aten_dev = mypkgs.aten_dev.phpFpm.pool;
+ aten_prod = mypkgs.aten_prod.phpFpm.pool;
nextcloud = mypkgs.nextcloud.phpFpm.pool;
mantisbt = mypkgs.mantisbt.phpFpm.pool;
};
system.activationScripts = {
connexionswing_dev = mypkgs.connexionswing_dev.activationScript;
connexionswing_prod = mypkgs.connexionswing_prod.activationScript;
+ ludivinecassal_dev = mypkgs.ludivinecassal_dev.activationScript;
+ ludivinecassal_prod = mypkgs.ludivinecassal_prod.activationScript;
+ piedsjaloux_dev = mypkgs.piedsjaloux_dev.activationScript;
+ piedsjaloux_prod = mypkgs.piedsjaloux_prod.activationScript;
+ aten_dev = mypkgs.aten_dev.activationScript;
+ aten_prod = mypkgs.aten_prod.activationScript;
nextcloud = mypkgs.nextcloud.activationScript;
httpd = ''
install -d -m 0755 /var/lib/acme/acme-challenge
fi
'';
};
+ goaccess = ''
+ mkdir -p /var/lib/goaccess
+ mkdir -p /var/lib/goaccess/aten.pro
+ mkdir -p /var/lib/goaccess/ludivinecassal.com
+ mkdir -p /var/lib/goaccess/piedsjaloux.fr
+ '';
};
environment.etc."ssh/ldap_authorized_keys" = let
AuthBasicProvider ldap
</IfModule>
</Macro>
+
+ <Macro Stats %{domain}>
+ Alias /awstats /var/lib/goaccess/%{domain}
+ <Directory /var/lib/goaccess/%{domain}>
+ DirectoryIndex index.html
+ AllowOverride None
+ Require all granted
+ </Directory>
+ <Location /awstats>
+ Use LDAPConnect
+ Require ldap-group cn=%{domain},ou=stats,cn=httpd,ou=services,dc=immae,dc=eu
+ </Location>
+ </Macro>
'';
};
http2 = {
customLog = {
modules = [];
extraConfig = ''
- LogFormat "%v %h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\" %p" combinedVhost
+ LogFormat "%v:%p %h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combinedVhost
'';
};
};
mypkgs.nextcloud.apache.modules ++
mypkgs.connexionswing_dev.apache.modules ++
mypkgs.connexionswing_prod.apache.modules ++
+ mypkgs.ludivinecassal_dev.apache.modules ++
+ mypkgs.ludivinecassal_prod.apache.modules ++
+ mypkgs.piedsjaloux_dev.apache.modules ++
+ mypkgs.piedsjaloux_prod.apache.modules ++
+ mypkgs.aten_dev.apache.modules ++
+ mypkgs.aten_prod.apache.modules ++
mypkgs.ympd.apache.modules ++
mypkgs.git.web.apache.modules ++
mypkgs.mantisbt.apache.modules ++
mypkgs.connexionswing_dev.apache.vhostConf
];
})
+ (withConf "eldiron" // {
+ hostName = "ludivine.immae.eu";
+ documentRoot = mypkgs.ludivinecassal_dev.webRoot;
+ extraConfig = builtins.concatStringsSep "\n" [
+ mypkgs.ludivinecassal_dev.apache.vhostConf
+ ];
+ })
+ (withConf "ludivinecassal" // {
+ hostName = "ludivinecassal.com";
+ serverAliases = [ "www.ludivinecassal.com" ];
+ documentRoot = mypkgs.ludivinecassal_prod.webRoot;
+ extraConfig = builtins.concatStringsSep "\n" [
+ mypkgs.ludivinecassal_prod.apache.vhostConf
+ ];
+ })
+ (withConf "eldiron" // {
+ hostName = "piedsjaloux.immae.eu";
+ documentRoot = mypkgs.piedsjaloux_dev.webRoot;
+ extraConfig = builtins.concatStringsSep "\n" [
+ mypkgs.piedsjaloux_dev.apache.vhostConf
+ ];
+ })
+ (withConf "piedsjaloux" // {
+ hostName = "piedsjaloux.fr";
+ serverAliases = [ "www.piedsjaloux.fr" ];
+ documentRoot = mypkgs.piedsjaloux_prod.webRoot;
+ extraConfig = builtins.concatStringsSep "\n" [
+ mypkgs.piedsjaloux_prod.apache.vhostConf
+ ];
+ })
+ (withConf "eldiron" // {
+ hostName = "dev.aten.pro";
+ documentRoot = mypkgs.aten_dev.webRoot;
+ extraConfig = builtins.concatStringsSep "\n" [
+ mypkgs.aten_dev.apache.vhostConf
+ ];
+ })
+ (withConf "aten" // {
+ hostName = "aten.pro";
+ serverAliases = [ "www.aten.pro" ];
+ documentRoot = mypkgs.aten_prod.webRoot;
+ extraConfig = builtins.concatStringsSep "\n" [
+ mypkgs.aten_prod.apache.vhostConf
+ ];
+ })
(withConf "eldiron" // {
hostName = "cloud.immae.eu";
documentRoot = mypkgs.nextcloud.webRoot;
#host all all all pam
'';
};
+
+ services.cron = {
+ enable = true;
+ systemCronJobs = let
+ stats = domain: conf: "${pkgs.gnused}/bin/sed -n '/\\['$(LC_ALL=C ${pkgs.coreutils}/bin/date -d yesterday +'%d\\/%b\\/%Y')'/ p' /var/log/httpd/access_log-${domain} | ${pkgs.goaccess}/bin/goaccess -o /var/lib/goaccess/${domain}/index.html -p ${conf}";
+ in [
+ "5 0 * * * root ${stats "aten.pro" ./packages/aten_goaccess.conf}"
+ "5 0 * * * root ${stats "ludivinecassal.com" ./packages/ludivinecassal_goaccess.conf}"
+ "5 0 * * * root ${stats "piedsjaloux.fr" ./packages/piedsjaloux_goaccess.conf}"
+ ];
+ };
};
}