Commit fd10a8a033
Verified · cmc
Layout: unified · split
linux/nginx/etc/nginx/conf.d/git.conf added +91
| @@ -0,0 +1,91 @@ | |||
| 1 | # git.krz.sh -- cgit (fcgiwrap) | ||
| 2 | # Cloudflare Tunnel ingress: git.krz.sh -> http://localhost:10046 | ||
| 3 | # Repos are scanned from /git (scan-path in /etc/cgitrc). | ||
| 4 | |||
| 5 | server { | ||
| 6 | listen 10046; | ||
| 7 | server_name git.krz.sh; | ||
| 8 | error_log /var/log/nginx/git.krz.sh.error.log; | ||
| 9 | |||
| 10 | include custom.d/basic.conf; | ||
| 11 | include custom.d/security/strict-transport-security.conf; | ||
| 12 | include custom.d/security/permissions-policy.conf; | ||
| 13 | |||
| 14 | # The shared CSP (default-src 'self', no style-src) breaks cgit: the | ||
| 15 | # pygments source-filter writes an inline <style> block into every blob | ||
| 16 | # view, and the commit graph uses inline styles. Scope 'unsafe-inline' | ||
| 17 | # to styles only, on this vhost only. | ||
| 18 | add_header Content-Security-Policy "default-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; base-uri 'none'; form-action 'self'; frame-ancestors 'none'; object-src 'none'; upgrade-insecure-requests" always; | ||
| 19 | |||
| 20 | root /usr/share/cgit; | ||
| 21 | port_in_redirect off; | ||
| 22 | |||
| 23 | # Serve cgit's static assets directly rather than through the CGI. | ||
| 24 | location /cgit-css/ { | ||
| 25 | alias /usr/share/cgit/; | ||
| 26 | expires 30d; | ||
| 27 | } | ||
| 28 | |||
| 29 | # Site branding (logo + favicon). Served from this origin on purpose: | ||
| 30 | # the CSP above allows img-src 'self' only, so pulling these from the | ||
| 31 | # img.* vhost would be blocked. Only the two white wordmarks are | ||
| 32 | # world-readable in that directory; the purple variants are not. | ||
| 33 | location /assets/ { | ||
| 34 | alias /var/www/img/krz/; | ||
| 35 | expires 30d; | ||
| 36 | } | ||
| 37 | |||
| 38 | # --- Smart HTTP: read-only clone/fetch -------------------------------- | ||
| 39 | # Anonymous push is never allowed. Refuse receive-pack explicitly so it | ||
| 40 | # fails loudly instead of falling through to cgit and 404ing. | ||
| 41 | location ~ ^/.+\.git/git-receive-pack$ { | ||
| 42 | return 403; | ||
| 43 | } | ||
| 44 | |||
| 45 | # These paths belong to git, not cgit. None of them collide with cgit's | ||
| 46 | # own repo pages (cgit uses /refs/, /tree/, /plain/, ... not /info/refs | ||
| 47 | # or /objects/). | ||
| 48 | location ~ ^/.+\.git/(HEAD|info/refs|objects/.*|git-upload-pack)$ { | ||
| 49 | include fastcgi_params; | ||
| 50 | |||
| 51 | fastcgi_pass unix:/run/fcgiwrap.socket; | ||
| 52 | fastcgi_param SCRIPT_FILENAME /usr/lib/git-core/git-http-backend; | ||
| 53 | fastcgi_param GIT_PROJECT_ROOT /git; | ||
| 54 | fastcgi_param GIT_HTTP_EXPORT_ALL 1; | ||
| 55 | fastcgi_param PATH_INFO $uri; | ||
| 56 | fastcgi_param QUERY_STRING $args; | ||
| 57 | |||
| 58 | # /git is owned by uid 1001, which maps to no account on this host, | ||
| 59 | # so git rejects every repo as "dubious ownership". Scope the | ||
| 60 | # exception to this backend via env instead of relaxing the check | ||
| 61 | # globally in /etc/gitconfig. Note: git 2.43 does not support path | ||
| 62 | # globs here, so "*" is the only working value. | ||
| 63 | fastcgi_param GIT_CONFIG_COUNT 1; | ||
| 64 | fastcgi_param GIT_CONFIG_KEY_0 safe.directory; | ||
| 65 | fastcgi_param GIT_CONFIG_VALUE_0 "*"; | ||
| 66 | |||
| 67 | # Clones stream large packfiles -- don't spool them to disk first. | ||
| 68 | fastcgi_buffering off; | ||
| 69 | fastcgi_read_timeout 900; | ||
| 70 | client_max_body_size 64m; | ||
| 71 | } | ||
| 72 | |||
| 73 | location / { | ||
| 74 | try_files $uri @cgit; | ||
| 75 | } | ||
| 76 | |||
| 77 | location @cgit { | ||
| 78 | include fastcgi_params; | ||
| 79 | |||
| 80 | fastcgi_pass unix:/run/fcgiwrap.socket; | ||
| 81 | fastcgi_param SCRIPT_FILENAME /usr/lib/cgit/cgit.cgi; | ||
| 82 | fastcgi_param PATH_INFO $uri; | ||
| 83 | fastcgi_param QUERY_STRING $args; | ||
| 84 | fastcgi_param HTTP_HOST $host; | ||
| 85 | |||
| 86 | # Snapshot tarballs of large repos can take a while to stream. | ||
| 87 | fastcgi_read_timeout 300; | ||
| 88 | fastcgi_buffer_size 128k; | ||
| 89 | fastcgi_buffers 16 64k; | ||
| 90 | } | ||
| 91 | } | ||