mirror of
https://git.pvv.ntnu.no/Drift/pvv-nixos-config.git
synced 2026-08-11 05:42:33 +02:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3bcb178ae7 |
@@ -1,25 +1,70 @@
|
|||||||
{ lib, ... }:
|
{ lib, ... }:
|
||||||
{
|
{
|
||||||
services.nginx.virtualHosts = lib.genAttrs [
|
# TODO: move this to base so that all virtualHosts take effect on their respecitve hosts
|
||||||
"pvv.ntnu.no"
|
|
||||||
"www.pvv.ntnu.no"
|
|
||||||
"pvv.org"
|
|
||||||
"www.pvv.org"
|
|
||||||
] (_: {
|
|
||||||
locations = {
|
|
||||||
"^~ /.well-known/" = {
|
|
||||||
alias = (toString ./root) + "/";
|
|
||||||
};
|
|
||||||
|
|
||||||
# Proxy the matrix well-known files
|
# NOTE: automatically hosting well-known files by looping over all existing `virtualHosts`
|
||||||
# Host has be set before proxy_pass
|
# unfortunately causes infinite recursuion due to submodule usage within the nginx
|
||||||
# The header must be set so nginx on the other side routes it to the right place
|
# module. For now, the easiest solution was to manually specify a list of virtualHosts
|
||||||
"^~ /.well-known/matrix/" = {
|
# here, but it would be nice to find a better solution in the future.
|
||||||
|
services.nginx.virtualHosts = lib.mkMerge [
|
||||||
|
(lib.genAttrs [
|
||||||
|
"pvv.ntnu.no"
|
||||||
|
"pvv.org"
|
||||||
|
|
||||||
|
"www.pvv.ntnu.no"
|
||||||
|
"www.pvv.org"
|
||||||
|
"www2.pvv.ntnu.no"
|
||||||
|
"www2.pvv.org"
|
||||||
|
|
||||||
|
# NOTE: this list is probably not complete
|
||||||
|
"alps.pvv.ntnu.no"
|
||||||
|
"chat.pvv.ntnu.no"
|
||||||
|
"grafana.pvv.ntnu.no"
|
||||||
|
"status.pvv.ntnu.no"
|
||||||
|
"matrix.pvv.ntnu.no"
|
||||||
|
"mirrors.pvv.ntnu.no"
|
||||||
|
"pages.pvv.ntnu.no"
|
||||||
|
"ooye.pvv.ntnu.no"
|
||||||
|
"ooye.pvv.ntnu.no"
|
||||||
|
"dav.pvv.ntnu.no"
|
||||||
|
"git.pvv.ntnu.no"
|
||||||
|
"idp.pvv.ntnu.no"
|
||||||
|
"minecraft.pvv.ntnu.no"
|
||||||
|
"pw.pvv.ntnu.no"
|
||||||
|
"snappymail.pvv.ntnu.no"
|
||||||
|
"webmail.pvv.ntnu.no"
|
||||||
|
"wiki.pvv.ntnu.no"
|
||||||
|
] (_: {
|
||||||
|
locations."^~ /.well-known/security.txt" = {
|
||||||
|
alias = toString ./root/security.txt;
|
||||||
|
};
|
||||||
|
}))
|
||||||
|
|
||||||
|
(lib.genAttrs [
|
||||||
|
"pvv.ntnu.no"
|
||||||
|
"pvv.org"
|
||||||
|
"mail.pvv.ntnu.no"
|
||||||
|
"mail.pvv.org"
|
||||||
|
"smtp.pvv.ntnu.no"
|
||||||
|
"smtp.pvv.org"
|
||||||
|
] (_: {
|
||||||
|
locations."^~ /.well-known/autoconfig/mail/" = {
|
||||||
|
root = toString ./root/autoconfig/mail;
|
||||||
|
};
|
||||||
|
}))
|
||||||
|
|
||||||
|
(lib.genAttrs [
|
||||||
|
"pvv.ntnu.no"
|
||||||
|
"pvv.org"
|
||||||
|
"www.pvv.ntnu.no"
|
||||||
|
"www.pvv.org"
|
||||||
|
] (_: {
|
||||||
|
locations."^~ /.well-known/matrix/" = {
|
||||||
extraConfig = ''
|
extraConfig = ''
|
||||||
proxy_set_header Host matrix.pvv.ntnu.no;
|
proxy_set_header Host matrix.pvv.ntnu.no;
|
||||||
proxy_pass https://matrix.pvv.ntnu.no/.well-known/matrix/;
|
proxy_pass https://matrix.pvv.ntnu.no/.well-known/matrix/;
|
||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
};
|
}))
|
||||||
});
|
];
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -41,38 +41,24 @@ in
|
|||||||
path = with pkgs; [
|
path = with pkgs; [
|
||||||
cfg.package
|
cfg.package
|
||||||
coreutils
|
coreutils
|
||||||
diffutils
|
|
||||||
zstd
|
zstd
|
||||||
];
|
];
|
||||||
|
|
||||||
script = ''
|
script = let
|
||||||
|
rotations = 2;
|
||||||
|
in ''
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
dump() {
|
OUT_FILE="$STATE_DIRECTORY/mysql-dump-$(date --iso-8601).sql.zst"
|
||||||
local name="$1" out tmp
|
|
||||||
out="$STATE_DIRECTORY/$name.sql.zst"
|
|
||||||
tmp="$out.tmp"
|
|
||||||
shift
|
|
||||||
"$@" | zstd -9 --rsyncable -f -o "$tmp"
|
|
||||||
if cmp -s "$tmp" "$out" 2>/dev/null; then
|
|
||||||
rm -f "$tmp"
|
|
||||||
else
|
|
||||||
mv -f "$tmp" "$out"
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
declare -A keep
|
mysqldump --all-databases | zstd --compress -9 --rsyncable -o "$OUT_FILE"
|
||||||
while IFS= read -r db; do
|
|
||||||
[ -n "$db" ] || continue
|
|
||||||
dump "$db" mysqldump --skip-dump-date --databases "$db"
|
|
||||||
keep["$db.sql.zst"]=1
|
|
||||||
done < <(mysql -N -e 'SHOW DATABASES' | grep -vE '^(information_schema|performance_schema)$')
|
|
||||||
|
|
||||||
# drop dumps of databases that no longer exist
|
# NOTE: this needs to be a hardlink for rrsync to allow sending it
|
||||||
for f in "$STATE_DIRECTORY"/*.sql.zst; do
|
rm "$STATE_DIRECTORY/mysql-dump-latest.sql.zst" ||:
|
||||||
[ -e "$f" ] || continue
|
ln -T "$OUT_FILE" "$STATE_DIRECTORY/mysql-dump-latest.sql.zst"
|
||||||
base="$(basename "$f")"
|
|
||||||
[ -n "''${keep[$base]:-}" ] || rm -f "$f"
|
while [ "$(find "$STATE_DIRECTORY" -type f -printf '.' | wc -c)" -gt '${toString (rotations + 1)}' ]; do
|
||||||
|
rm "$(find "$STATE_DIRECTORY" -type f -printf '%T+ %p\n' | sort | head -n 1 | cut -d' ' -f2)"
|
||||||
done
|
done
|
||||||
'';
|
'';
|
||||||
|
|
||||||
|
|||||||
@@ -41,42 +41,25 @@ in
|
|||||||
|
|
||||||
path = with pkgs; [
|
path = with pkgs; [
|
||||||
coreutils
|
coreutils
|
||||||
diffutils
|
|
||||||
zstd
|
zstd
|
||||||
cfg.package
|
cfg.package
|
||||||
];
|
];
|
||||||
|
|
||||||
script = ''
|
script = let
|
||||||
|
rotations = 2;
|
||||||
|
in ''
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
dump() {
|
OUT_FILE="$STATE_DIRECTORY/postgresql-dump-$(date --iso-8601).sql.zst"
|
||||||
local name="$1" out tmp
|
|
||||||
out="$STATE_DIRECTORY/$name.sql.zst"
|
|
||||||
tmp="$out.tmp"
|
|
||||||
shift
|
|
||||||
"$@" | zstd -9 --rsyncable -f -o "$tmp"
|
|
||||||
if cmp -s "$tmp" "$out" 2>/dev/null; then
|
|
||||||
rm -f "$tmp"
|
|
||||||
else
|
|
||||||
mv -f "$tmp" "$out"
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
declare -A keep
|
pg_dumpall -U postgres | zstd --compress -9 --rsyncable -o "$OUT_FILE"
|
||||||
dump globals pg_dumpall -U postgres --globals-only --restrict-key=backup
|
|
||||||
keep[globals.sql.zst]=1
|
|
||||||
|
|
||||||
while IFS= read -r db; do
|
# NOTE: this needs to be a hardlink for rrsync to allow sending it
|
||||||
[ -n "$db" ] || continue
|
rm "$STATE_DIRECTORY/postgresql-dump-latest.sql.zst" ||:
|
||||||
dump "$db" pg_dump -U postgres -C -d "$db" --restrict-key=backup
|
ln -T "$OUT_FILE" "$STATE_DIRECTORY/postgresql-dump-latest.sql.zst"
|
||||||
keep["$db.sql.zst"]=1
|
|
||||||
done < <(psql -U postgres -tAc "SELECT datname FROM pg_database WHERE datallowconn ORDER BY datname")
|
|
||||||
|
|
||||||
# drop dumps of databases that no longer exist
|
while [ "$(find "$STATE_DIRECTORY" -type f -printf '.' | wc -c)" -gt '${toString (rotations + 1)}' ]; do
|
||||||
for f in "$STATE_DIRECTORY"/*.sql.zst; do
|
rm "$(find "$STATE_DIRECTORY" -type f -printf '%T+ %p\n' | sort | head -n 1 | cut -d' ' -f2)"
|
||||||
[ -e "$f" ] || continue
|
|
||||||
base="$(basename "$f")"
|
|
||||||
[ -n "''${keep[$base]:-}" ] || rm -f "$f"
|
|
||||||
done
|
done
|
||||||
'';
|
'';
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user