nomad
created pr with
8.1
cmds
checkout latest patchset:
ssh pr.in0rdr.ch print 8 | git am -3checkout any patchset in a patch request:
ssh pr.in0rdr.ch print 8.[rev] | git am -3add changes to patch request:
git format-patch main --stdout | ssh pr.in0rdr.ch pr add 8
Patchset
8.1
feat(git): anubis sidecar
Andreas Gruhler
→ feat: RemoteIPProxyProtocol
2026-03-27Andreas Gruhler
fix: add podman net to trusted proxies
2026-03-30Andreas Gruhler
fix: ServerName in vHost
2026-03-31Andreas Gruhler
feat: change RemoteIPInternalProxy
2026-04-01Andreas Gruhler
feat: change RemoteIPInternalProxy
2026-04-01Andreas Gruhler
2026-04-01
feat: RemoteIPProxyProtocol
Andreas Gruhler
2026-03-30Semantic diff summary
0 added,
0 modified,
0 signature changed,
0 removed
across 0 analyzed files
(2 files skipped: unsupported file type)
+15
-13
hcl/default/git/git.nomad
#
| ... | ... | @@ -36,17 +34,20 @@ job "git" { | |
| 36 | 34 | } | |
| 37 | 35 | ||
| 38 | 36 | network { | |
| 39 | - | port "anubis" { | |
| 40 | - | static = 44328 | |
| 41 | - | to = 8923 | |
| 42 | - | } | |
| 43 | - | port "stagit" { | |
| 44 | - | to = 443 | |
| 45 | - | } | |
| 46 | 37 | port "smarthttp" { | |
| 47 | 38 | to = 443 | |
| 48 | 39 | static = 44318 | |
| 49 | 40 | } | |
| 41 | + | port "stagithttps" { | |
| 42 | + | static = 44328 | |
| 43 | + | to = 443 | |
| 44 | + | } | |
| 45 | + | port "stagithttp" { | |
| 46 | + | to = 80 | |
| 47 | + | } | |
| 48 | + | port "anubis" { | |
| 49 | + | to = 8923 | |
| 50 | + | } | |
| 50 | 51 | } | |
| 51 | 52 | ||
| 52 | 53 | task "smarthttp" { |
| ... | ... | @@ -93,7 +94,7 @@ job "git" { | |
| 93 | 94 | config { | |
| 94 | 95 | image = "127.0.0.1:5000/git:latest" | |
| 95 | 96 | force_pull = true | |
| 96 | - | ports = ["stagit"] | |
| 97 | + | ports = ["stagithttp", "stagithttps"] | |
| 97 | 98 | volumes = [ | |
| 98 | 99 | # mount the templated config from the task directory to the container | |
| 99 | 100 | "local/stagit.conf:/etc/apache2/conf.d/stagit.conf", |
| ... | ... | @@ -129,7 +130,8 @@ job "git" { | |
| 129 | 130 | driver = "podman" | |
| 130 | 131 | ||
| 131 | 132 | config { | |
| 132 | - | image = "docker://ghcr.io/techarohq/anubis:v1.15.0" | |
| 133 | + | image = "docker://ghcr.io/techarohq/anubis:v1.25.0" | |
| 134 | + | ports = ["anubis"] | |
| 133 | 135 | volumes = [ | |
| 134 | 136 | # mount the templated config from the task directory to the container | |
| 135 | 137 | "local/challenge-any.yml:/etc/anubis/challenge-any.yml", |
| ... | ... | @@ -146,7 +148,7 @@ job "git" { | |
| 146 | 148 | env = true | |
| 147 | 149 | data = <<EOT | |
| 148 | 150 | DIFFICULTY=4 | |
| 149 | - | TARGET=http://{{ env "NOMAD_ADDR_stagit" }} | |
| 151 | + | TARGET=http://{{ env "NOMAD_ADDR_stagithttp" }} | |
| 150 | 152 | HS512_SECRET="{{with secret "kv/anubis"}}{{index .Data.data.HS512_SECRET}}{{end}}" | |
| 151 | 153 | COOKIE_DYNAMIC_DOMAIN=True | |
| 152 | 154 | POLICY_FNAME=/etc/anubis/challenge-any.yml |
+38
-12
hcl/default/git/templates/stagit.conf.tmpl
#
| ... | ... | @@ -1,16 +1,42 @@ | |
| 1 | - | <VirtualHost *:443> | |
| 2 | - | DocumentRoot /var/www/localhost/htdocs | |
| 3 | - | ServerName code.in0rdr.ch | |
| 4 | - | ||
| 5 | 1 | ErrorLog /dev/stderr | |
| 6 | 2 | TransferLog /dev/stdout | |
| 3 | + | ServerName code.in0rdr.ch | |
| 4 | + | ||
| 5 | + | LogFormat "%{X-Forwarded-For}i %h %l %u %t \"%r\" %>s %b" common | |
| 6 | + | ||
| 7 | + | # HTTPS listener that forwards to Anubis | |
| 8 | + | <IfModule mod_proxy.c> | |
| 9 | + | <VirtualHost *:443> | |
| 10 | + | SSLCertificateFile "/etc/letsencrypt/live/code.in0rdr.ch/fullchain.pem" | |
| 11 | + | SSLCertificateKeyFile "/etc/letsencrypt/live/code.in0rdr.ch/privkey.pem" | |
| 12 | + | ||
| 13 | + | # Haproxy sends real ip (send-proxy) | |
| 14 | + | # https://www.haproxy.com/documentation/haproxy-configuration-manual/latest/#send-proxy | |
| 15 | + | # https://httpd.apache.org/docs/2.4/mod/mod_remoteip.html#remoteipproxyprotocol | |
| 16 | + | RemoteIPProxyProtocol On | |
| 17 | + | RemoteIPInternalProxy 10.0.0.1/24 | |
| 18 | + | ||
| 19 | + | # These headers need to be set or else Anubis will | |
| 20 | + | # throw an "admin misconfiguration" error. | |
| 21 | + | # https://anubis.techaro.lol/docs/admin/environments/apache | |
| 22 | + | RequestHeader set X-Real-Ip expr=%{REMOTE_ADDR} | |
| 23 | + | RequestHeader set X-Forwarded-Proto "https" | |
| 24 | + | RequestHeader set X-Http-Version "%{SERVER_PROTOCOL}s" | |
| 25 | + | ProxyPreserveHost On | |
| 26 | + | ProxyRequests Off | |
| 27 | + | ProxyVia Off | |
| 28 | + | ||
| 29 | + | ProxyPass / http://{{ env "NOMAD_ADDR_anubis" }}/ | |
| 30 | + | ProxyPassReverse / http://{{ env "NOMAD_ADDR_anubis" }}/ | |
| 31 | + | </VirtualHost> | |
| 32 | + | </IfModule> | |
| 33 | + | ||
| 34 | + | <VirtualHost *:80> | |
| 35 | + | DocumentRoot /var/www/localhost/htdocs | |
| 7 | 36 | ||
| 8 | - | SSLCertificateFile "/etc/letsencrypt/live/code.in0rdr.ch/fullchain.pem" | |
| 9 | - | SSLCertificateKeyFile "/etc/letsencrypt/live/code.in0rdr.ch/privkey.pem" | |
| 10 | - | ||
| 11 | - | <Directory /var/www/localhost/htdocs> | |
| 12 | - | Order allow,deny | |
| 13 | - | Allow from all | |
| 14 | - | Require all granted | |
| 15 | - | </Directory> | |
| 37 | + | <Directory /var/www/localhost/htdocs> | |
| 38 | + | Order allow,deny | |
| 39 | + | Allow from all | |
| 40 | + | Require all granted | |
| 41 | + | </Directory> | |
| 16 | 42 | </VirtualHost> |