nomad
created pr with
9.1
cmds
checkout latest patchset:
ssh pr.in0rdr.ch print 9 | git am -3checkout any patchset in a patch request:
ssh pr.in0rdr.ch print 9.[rev] | git am -3add changes to patch request:
git format-patch main --stdout | ssh pr.in0rdr.ch pr add 9
Patchset
9.1
feat(git): anubis sidecar
Andreas Gruhler
2026-03-27* https://board.in0rdr.ch/task/133
Semantic diff summary
0 added,
0 modified,
0 signature changed,
0 removed
across 0 analyzed files
(3 files skipped: unsupported file type)
+49
-5
hcl/default/git/git.nomad
#
| ... | ... | @@ -32,14 +34,20 @@ job "git" { | |
| 32 | 34 | } | |
| 33 | 35 | ||
| 34 | 36 | network { | |
| 35 | - | port "stagit" { | |
| 36 | - | to = 443 | |
| 37 | - | static = 44328 | |
| 38 | - | } | |
| 39 | 37 | port "smarthttp" { | |
| 40 | 38 | to = 443 | |
| 41 | 39 | static = 44318 | |
| 42 | 40 | } | |
| 41 | + | port "stagithttps" { | |
| 42 | + | static = 44328 | |
| 43 | + | to = 443 | |
| 44 | + | } | |
| 45 | + | port "stagithttp" { | |
| 46 | + | to = 80 | |
| 47 | + | } | |
| 48 | + | port "anubis" { | |
| 49 | + | to = 8923 | |
| 50 | + | } | |
| 43 | 51 | } | |
| 44 | 52 | ||
| 45 | 53 | task "smarthttp" { |
| ... | ... | @@ -86,7 +94,7 @@ job "git" { | |
| 86 | 94 | config { | |
| 87 | 95 | image = "127.0.0.1:5000/git:latest" | |
| 88 | 96 | force_pull = true | |
| 89 | - | ports = ["stagit"] | |
| 97 | + | ports = ["stagithttp", "stagithttps"] | |
| 90 | 98 | volumes = [ | |
| 91 | 99 | # mount the templated config from the task directory to the container | |
| 92 | 100 | "local/stagit.conf:/etc/apache2/conf.d/stagit.conf", |
| ... | ... | @@ -117,5 +125,41 @@ job "git" { | |
| 117 | 125 | cpu = 100 | |
| 118 | 126 | } | |
| 119 | 127 | } | |
| 128 | + | ||
| 129 | + | task "anubis" { | |
| 130 | + | driver = "podman" | |
| 131 | + | ||
| 132 | + | config { | |
| 133 | + | image = "docker://ghcr.io/techarohq/anubis:v1.25.0" | |
| 134 | + | ports = ["anubis"] | |
| 135 | + | volumes = [ | |
| 136 | + | # mount the templated config from the task directory to the container | |
| 137 | + | "local/challenge-any.yml:/etc/anubis/challenge-any.yml", | |
| 138 | + | ] | |
| 139 | + | } | |
| 140 | + | ||
| 141 | + | template { | |
| 142 | + | destination = "${NOMAD_TASK_DIR}/challenge-any.yml" | |
| 143 | + | data = file("./templates/challenge-any.yml.tmpl") | |
| 144 | + | } | |
| 145 | + | ||
| 146 | + | template { | |
| 147 | + | destination = "${NOMAD_SECRETS_DIR}/default.env" | |
| 148 | + | env = true | |
| 149 | + | data = <<EOT | |
| 150 | + | DIFFICULTY=4 | |
| 151 | + | TARGET=http://{{ env "NOMAD_ADDR_stagithttp" }} | |
| 152 | + | HS512_SECRET="{{with secret "kv/anubis"}}{{index .Data.data.HS512_SECRET}}{{end}}" | |
| 153 | + | COOKIE_DYNAMIC_DOMAIN=True | |
| 154 | + | POLICY_FNAME=/etc/anubis/challenge-any.yml | |
| 155 | + | EOT | |
| 156 | + | } | |
| 157 | + | ||
| 158 | + | resources { | |
| 159 | + | memory = 128 | |
| 160 | + | memory_max = 256 | |
| 161 | + | cpu = 200 | |
| 162 | + | } | |
| 163 | + | } | |
| 120 | 164 | } | |
| 121 | 165 | } |
+12
-0
hcl/default/git/templates/challenge-any.yml.tmpl
#
+45
-12
hcl/default/git/templates/stagit.conf.tmpl
#
| ... | ... | @@ -1,16 +1,49 @@ | |
| 1 | - | <VirtualHost *:443> | |
| 2 | - | DocumentRoot /var/www/localhost/htdocs | |
| 3 | - | ServerName code.in0rdr.ch | |
| 4 | - | ||
| 5 | 1 | ErrorLog /dev/stderr | |
| 6 | 2 | TransferLog /dev/stdout | |
| 7 | 3 | ||
| 8 | - | SSLCertificateFile "/etc/letsencrypt/live/code.in0rdr.ch/fullchain.pem" | |
| 9 | - | SSLCertificateKeyFile "/etc/letsencrypt/live/code.in0rdr.ch/privkey.pem" | |
| 10 | - | ||
| 11 | - | <Directory /var/www/localhost/htdocs> | |
| 12 | - | Order allow,deny | |
| 13 | - | Allow from all | |
| 14 | - | Require all granted | |
| 15 | - | </Directory> | |
| 4 | + | LogFormat "%{X-Real-Ip}i %h %l %u %t \"%r\" %>s %b" common | |
| 5 | + | ||
| 6 | + | # HTTPS listener that forwards to Anubis | |
| 7 | + | <IfModule mod_proxy.c> | |
| 8 | + | <VirtualHost *:443> | |
| 9 | + | ServerName code.in0rdr.ch | |
| 10 | + | SSLCertificateFile "/etc/letsencrypt/live/code.in0rdr.ch/fullchain.pem" | |
| 11 | + | SSLCertificateKeyFile "/etc/letsencrypt/live/code.in0rdr.ch/privkey.pem" | |
| 12 | + | ||
| 13 | + | # HAProxy sends real ip (send-proxy) | |
| 14 | + | # https://www.haproxy.com/documentation/haproxy-configuration-manual/latest/#send-proxy | |
| 15 | + | # https://httpd.apache.org/docs/2.4/mod/mod_remoteip.html#remoteipproxyprotocol | |
| 16 | + | RemoteIPProxyProtocol On | |
| 17 | + | ||
| 18 | + | # These headers need to be set or else Anubis will | |
| 19 | + | # throw an "admin misconfiguration" error. | |
| 20 | + | # https://anubis.techaro.lol/docs/admin/environments/apache | |
| 21 | + | RequestHeader set X-Real-Ip expr=%{REMOTE_ADDR} | |
| 22 | + | RequestHeader set X-Forwarded-Proto "https" | |
| 23 | + | RequestHeader set X-Http-Version "%{SERVER_PROTOCOL}s" | |
| 24 | + | ProxyPreserveHost On | |
| 25 | + | ProxyRequests Off | |
| 26 | + | ProxyVia Off | |
| 27 | + | ||
| 28 | + | ProxyPass / http://{{ env "NOMAD_ADDR_anubis" }}/ | |
| 29 | + | ProxyPassReverse / http://{{ env "NOMAD_ADDR_anubis" }}/ | |
| 30 | + | </VirtualHost> | |
| 31 | + | </IfModule> | |
| 32 | + | ||
| 33 | + | <VirtualHost *:80> | |
| 34 | + | DocumentRoot /var/www/localhost/htdocs | |
| 35 | + | ||
| 36 | + | # HAProxy and Podman default bridge network | |
| 37 | + | # https://docs.podman.io/en/stable/markdown/podman-network.1.html | |
| 38 | + | RemoteIPHeader X-Real-Ip | |
| 39 | + | RemoteIPTrustedProxy 127.0.0.1/32 | |
| 40 | + | RemoteIPInternalProxy 10.0.0.0/24 | |
| 41 | + | RemoteIPInternalProxy 10.0.0.1 | |
| 42 | + | RemoteIPInternalProxy 10.88.0.1 | |
| 43 | + | ||
| 44 | + | <Directory /var/www/localhost/htdocs> | |
| 45 | + | Order allow,deny | |
| 46 | + | Allow from all | |
| 47 | + | Require all granted | |
| 48 | + | </Directory> | |
| 16 | 49 | </VirtualHost> |