nomad

created pr with 8.1 on 2026-06-25 · by 84351313
cmds
checkout latest patchset:
ssh pr.in0rdr.ch print 8 | git am -3
checkout any patchset in a patch request:
ssh pr.in0rdr.ch print 8.[rev] | git am -3
add changes to patch request:
git format-patch main --stdout | ssh pr.in0rdr.ch pr add 8
+15 -13 hcl/default/git/git.nomad #
......@@ -1,9 +1,7 @@
11 job "git" {
22 datacenters = ["dc1"]
33
4- vault {
5- role = "anubis"
6- }
4+ vault {}
75
86 priority = 80
97
......@@ -36,17 +34,20 @@ job "git" {
3634 }
3735
3836 network {
39- port "anubis" {
40- static = 44328
41- to = 8923
42- }
43- port "stagit" {
44- to = 443
45- }
4637 port "smarthttp" {
4738 to = 443
4839 static = 44318
4940 }
41+ port "stagithttps" {
42+ static = 44328
43+ to = 443
44+ }
45+ port "stagithttp" {
46+ to = 80
47+ }
48+ port "anubis" {
49+ to = 8923
50+ }
5051 }
5152
5253 task "smarthttp" {
......@@ -93,7 +94,7 @@ job "git" {
9394 config {
9495 image = "127.0.0.1:5000/git:latest"
9596 force_pull = true
96- ports = ["stagit"]
97+ ports = ["stagithttp", "stagithttps"]
9798 volumes = [
9899 # mount the templated config from the task directory to the container
99100 "local/stagit.conf:/etc/apache2/conf.d/stagit.conf",
......@@ -129,7 +130,8 @@ job "git" {
129130 driver = "podman"
130131
131132 config {
132- image = "docker://ghcr.io/techarohq/anubis:v1.15.0"
133+ image = "docker://ghcr.io/techarohq/anubis:v1.25.0"
134+ ports = ["anubis"]
133135 volumes = [
134136 # mount the templated config from the task directory to the container
135137 "local/challenge-any.yml:/etc/anubis/challenge-any.yml",
......@@ -146,7 +148,7 @@ job "git" {
146148 env = true
147149 data = <<EOT
148150 DIFFICULTY=4
149-TARGET=http://{{ env "NOMAD_ADDR_stagit" }}
151+TARGET=http://{{ env "NOMAD_ADDR_stagithttp" }}
150152 HS512_SECRET="{{with secret "kv/anubis"}}{{index .Data.data.HS512_SECRET}}{{end}}"
151153 COOKIE_DYNAMIC_DOMAIN=True
152154 POLICY_FNAME=/etc/anubis/challenge-any.yml
+38 -12 hcl/default/git/templates/stagit.conf.tmpl #
......@@ -1,16 +1,42 @@
1-<VirtualHost *:443>
2-DocumentRoot /var/www/localhost/htdocs
3-ServerName code.in0rdr.ch
4-
51 ErrorLog /dev/stderr
62 TransferLog /dev/stdout
3+ServerName code.in0rdr.ch
4+
5+LogFormat "%{X-Forwarded-For}i %h %l %u %t \"%r\" %>s %b" common
6+
7+# HTTPS listener that forwards to Anubis
8+<IfModule mod_proxy.c>
9+ <VirtualHost *:443>
10+ SSLCertificateFile "/etc/letsencrypt/live/code.in0rdr.ch/fullchain.pem"
11+ SSLCertificateKeyFile "/etc/letsencrypt/live/code.in0rdr.ch/privkey.pem"
12+
13+ # Haproxy sends real ip (send-proxy)
14+ # https://www.haproxy.com/documentation/haproxy-configuration-manual/latest/#send-proxy
15+ # https://httpd.apache.org/docs/2.4/mod/mod_remoteip.html#remoteipproxyprotocol
16+ RemoteIPProxyProtocol On
17+ RemoteIPInternalProxy 10.0.0.1/24
18+
19+ # These headers need to be set or else Anubis will
20+ # throw an "admin misconfiguration" error.
21+ # https://anubis.techaro.lol/docs/admin/environments/apache
22+ RequestHeader set X-Real-Ip expr=%{REMOTE_ADDR}
23+ RequestHeader set X-Forwarded-Proto "https"
24+ RequestHeader set X-Http-Version "%{SERVER_PROTOCOL}s"
25+ ProxyPreserveHost On
26+ ProxyRequests Off
27+ ProxyVia Off
28+
29+ ProxyPass / http://{{ env "NOMAD_ADDR_anubis" }}/
30+ ProxyPassReverse / http://{{ env "NOMAD_ADDR_anubis" }}/
31+ </VirtualHost>
32+</IfModule>
33+
34+<VirtualHost *:80>
35+ DocumentRoot /var/www/localhost/htdocs
736
8-SSLCertificateFile "/etc/letsencrypt/live/code.in0rdr.ch/fullchain.pem"
9-SSLCertificateKeyFile "/etc/letsencrypt/live/code.in0rdr.ch/privkey.pem"
10-
11-<Directory /var/www/localhost/htdocs>
12- Order allow,deny
13- Allow from all
14- Require all granted
15-</Directory>
37+ <Directory /var/www/localhost/htdocs>
38+ Order allow,deny
39+ Allow from all
40+ Require all granted
41+ </Directory>
1642 </VirtualHost>
Back to top