nomad

created pr with 9.1 on 2026-06-25 · by 84351313
cmds
checkout latest patchset:
ssh pr.in0rdr.ch print 9 | git am -3
checkout any patchset in a patch request:
ssh pr.in0rdr.ch print 9.[rev] | git am -3
add changes to patch request:
git format-patch main --stdout | ssh pr.in0rdr.ch pr add 9

Patchset 9.1 on 2026-06-25 · commit 718331c

feat(git): anubis sidecar
Andreas Gruhler 2026-03-27
* https://board.in0rdr.ch/task/133
Semantic diff summary
0 added, 0 modified, 0 signature changed, 0 removed across 0 analyzed files (3 files skipped: unsupported file type)
+49 -5 hcl/default/git/git.nomad #
......@@ -1,6 +1,8 @@
11 job "git" {
22 datacenters = ["dc1"]
33
4+ vault {}
5+
46 priority = 80
57
68 constraint {
......@@ -32,14 +34,20 @@ job "git" {
3234 }
3335
3436 network {
35- port "stagit" {
36- to = 443
37- static = 44328
38- }
3937 port "smarthttp" {
4038 to = 443
4139 static = 44318
4240 }
41+ port "stagithttps" {
42+ static = 44328
43+ to = 443
44+ }
45+ port "stagithttp" {
46+ to = 80
47+ }
48+ port "anubis" {
49+ to = 8923
50+ }
4351 }
4452
4553 task "smarthttp" {
......@@ -86,7 +94,7 @@ job "git" {
8694 config {
8795 image = "127.0.0.1:5000/git:latest"
8896 force_pull = true
89- ports = ["stagit"]
97+ ports = ["stagithttp", "stagithttps"]
9098 volumes = [
9199 # mount the templated config from the task directory to the container
92100 "local/stagit.conf:/etc/apache2/conf.d/stagit.conf",
......@@ -117,5 +125,41 @@ job "git" {
117125 cpu = 100
118126 }
119127 }
128+
129+ task "anubis" {
130+ driver = "podman"
131+
132+ config {
133+ image = "docker://ghcr.io/techarohq/anubis:v1.25.0"
134+ ports = ["anubis"]
135+ volumes = [
136+ # mount the templated config from the task directory to the container
137+ "local/challenge-any.yml:/etc/anubis/challenge-any.yml",
138+ ]
139+ }
140+
141+ template {
142+ destination = "${NOMAD_TASK_DIR}/challenge-any.yml"
143+ data = file("./templates/challenge-any.yml.tmpl")
144+ }
145+
146+ template {
147+ destination = "${NOMAD_SECRETS_DIR}/default.env"
148+ env = true
149+ data = <<EOT
150+DIFFICULTY=4
151+TARGET=http://{{ env "NOMAD_ADDR_stagithttp" }}
152+HS512_SECRET="{{with secret "kv/anubis"}}{{index .Data.data.HS512_SECRET}}{{end}}"
153+COOKIE_DYNAMIC_DOMAIN=True
154+POLICY_FNAME=/etc/anubis/challenge-any.yml
155+EOT
156+ }
157+
158+ resources {
159+ memory = 128
160+ memory_max = 256
161+ cpu = 200
162+ }
163+ }
120164 }
121165 }
+12 -0 hcl/default/git/templates/challenge-any.yml.tmpl #
......@@ -0,0 +1,12 @@
1+bots:
2+ - name: any
3+ action: CHALLENGE
4+ user_agent_regex: .*
5+
6+status_codes:
7+ CHALLENGE: 403
8+ DENY: 403
9+
10+thresholds: []
11+
12+dnsbl: false
+45 -12 hcl/default/git/templates/stagit.conf.tmpl #
......@@ -1,16 +1,49 @@
1-<VirtualHost *:443>
2-DocumentRoot /var/www/localhost/htdocs
3-ServerName code.in0rdr.ch
4-
51 ErrorLog /dev/stderr
62 TransferLog /dev/stdout
73
8-SSLCertificateFile "/etc/letsencrypt/live/code.in0rdr.ch/fullchain.pem"
9-SSLCertificateKeyFile "/etc/letsencrypt/live/code.in0rdr.ch/privkey.pem"
10-
11-<Directory /var/www/localhost/htdocs>
12- Order allow,deny
13- Allow from all
14- Require all granted
15-</Directory>
4+LogFormat "%{X-Real-Ip}i %h %l %u %t \"%r\" %>s %b" common
5+
6+# HTTPS listener that forwards to Anubis
7+<IfModule mod_proxy.c>
8+ <VirtualHost *:443>
9+ ServerName code.in0rdr.ch
10+ SSLCertificateFile "/etc/letsencrypt/live/code.in0rdr.ch/fullchain.pem"
11+ SSLCertificateKeyFile "/etc/letsencrypt/live/code.in0rdr.ch/privkey.pem"
12+
13+ # HAProxy sends real ip (send-proxy)
14+ # https://www.haproxy.com/documentation/haproxy-configuration-manual/latest/#send-proxy
15+ # https://httpd.apache.org/docs/2.4/mod/mod_remoteip.html#remoteipproxyprotocol
16+ RemoteIPProxyProtocol On
17+
18+ # These headers need to be set or else Anubis will
19+ # throw an "admin misconfiguration" error.
20+ # https://anubis.techaro.lol/docs/admin/environments/apache
21+ RequestHeader set X-Real-Ip expr=%{REMOTE_ADDR}
22+ RequestHeader set X-Forwarded-Proto "https"
23+ RequestHeader set X-Http-Version "%{SERVER_PROTOCOL}s"
24+ ProxyPreserveHost On
25+ ProxyRequests Off
26+ ProxyVia Off
27+
28+ ProxyPass / http://{{ env "NOMAD_ADDR_anubis" }}/
29+ ProxyPassReverse / http://{{ env "NOMAD_ADDR_anubis" }}/
30+ </VirtualHost>
31+</IfModule>
32+
33+<VirtualHost *:80>
34+ DocumentRoot /var/www/localhost/htdocs
35+
36+ # HAProxy and Podman default bridge network
37+ # https://docs.podman.io/en/stable/markdown/podman-network.1.html
38+ RemoteIPHeader X-Real-Ip
39+ RemoteIPTrustedProxy 127.0.0.1/32
40+ RemoteIPInternalProxy 10.0.0.0/24
41+ RemoteIPInternalProxy 10.0.0.1
42+ RemoteIPInternalProxy 10.88.0.1
43+
44+ <Directory /var/www/localhost/htdocs>
45+ Order allow,deny
46+ Allow from all
47+ Require all granted
48+ </Directory>
1649 </VirtualHost>
Back to top