cmc/dotfiles

Using GNU Stow to manage my dotfiles. config dotfiles macos stow

Commit fd10a8a033

fd10a8a033e1e1c5d016968c2fbd296ec6ae1656

parent: 7bb68cb024

Verified · cmc

cmc <hello@cleberg.net> · 2026-08-02 21:49 UTC

add git.conf

Layout: unified · split

linux/nginx/etc/nginx/conf.d/git.conf added +91
@@ -0,0 +1,91 @@
1# git.krz.sh -- cgit (fcgiwrap)
2# Cloudflare Tunnel ingress: git.krz.sh -> http://localhost:10046
3# Repos are scanned from /git (scan-path in /etc/cgitrc).
4
5server {
6 listen 10046;
7 server_name git.krz.sh;
8 error_log /var/log/nginx/git.krz.sh.error.log;
9
10 include custom.d/basic.conf;
11 include custom.d/security/strict-transport-security.conf;
12 include custom.d/security/permissions-policy.conf;
13
14 # The shared CSP (default-src 'self', no style-src) breaks cgit: the
15 # pygments source-filter writes an inline <style> block into every blob
16 # view, and the commit graph uses inline styles. Scope 'unsafe-inline'
17 # to styles only, on this vhost only.
18 add_header Content-Security-Policy "default-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; base-uri 'none'; form-action 'self'; frame-ancestors 'none'; object-src 'none'; upgrade-insecure-requests" always;
19
20 root /usr/share/cgit;
21 port_in_redirect off;
22
23 # Serve cgit's static assets directly rather than through the CGI.
24 location /cgit-css/ {
25 alias /usr/share/cgit/;
26 expires 30d;
27 }
28
29 # Site branding (logo + favicon). Served from this origin on purpose:
30 # the CSP above allows img-src 'self' only, so pulling these from the
31 # img.* vhost would be blocked. Only the two white wordmarks are
32 # world-readable in that directory; the purple variants are not.
33 location /assets/ {
34 alias /var/www/img/krz/;
35 expires 30d;
36 }
37
38 # --- Smart HTTP: read-only clone/fetch --------------------------------
39 # Anonymous push is never allowed. Refuse receive-pack explicitly so it
40 # fails loudly instead of falling through to cgit and 404ing.
41 location ~ ^/.+\.git/git-receive-pack$ {
42 return 403;
43 }
44
45 # These paths belong to git, not cgit. None of them collide with cgit's
46 # own repo pages (cgit uses /refs/, /tree/, /plain/, ... not /info/refs
47 # or /objects/).
48 location ~ ^/.+\.git/(HEAD|info/refs|objects/.*|git-upload-pack)$ {
49 include fastcgi_params;
50
51 fastcgi_pass unix:/run/fcgiwrap.socket;
52 fastcgi_param SCRIPT_FILENAME /usr/lib/git-core/git-http-backend;
53 fastcgi_param GIT_PROJECT_ROOT /git;
54 fastcgi_param GIT_HTTP_EXPORT_ALL 1;
55 fastcgi_param PATH_INFO $uri;
56 fastcgi_param QUERY_STRING $args;
57
58 # /git is owned by uid 1001, which maps to no account on this host,
59 # so git rejects every repo as "dubious ownership". Scope the
60 # exception to this backend via env instead of relaxing the check
61 # globally in /etc/gitconfig. Note: git 2.43 does not support path
62 # globs here, so "*" is the only working value.
63 fastcgi_param GIT_CONFIG_COUNT 1;
64 fastcgi_param GIT_CONFIG_KEY_0 safe.directory;
65 fastcgi_param GIT_CONFIG_VALUE_0 "*";
66
67 # Clones stream large packfiles -- don't spool them to disk first.
68 fastcgi_buffering off;
69 fastcgi_read_timeout 900;
70 client_max_body_size 64m;
71 }
72
73 location / {
74 try_files $uri @cgit;
75 }
76
77 location @cgit {
78 include fastcgi_params;
79
80 fastcgi_pass unix:/run/fcgiwrap.socket;
81 fastcgi_param SCRIPT_FILENAME /usr/lib/cgit/cgit.cgi;
82 fastcgi_param PATH_INFO $uri;
83 fastcgi_param QUERY_STRING $args;
84 fastcgi_param HTTP_HOST $host;
85
86 # Snapshot tarballs of large repos can take a while to stream.
87 fastcgi_read_timeout 300;
88 fastcgi_buffer_size 128k;
89 fastcgi_buffers 16 64k;
90 }
91}