NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

git-site.nix (2298B)


      1 # modules/home/git-site.nix — keep git.daemon-sec.xyz in step with GitLab,
      2 # automatically.
      3 #
      4 #   git-site-sync status     last sync, GitLab's heads, the next timer run
      5 #   git-site-sync now        force a sync (after a theme or build change)
      6 #   git-site-sync log        what the last runs did
      7 #
      8 # A systemd user timer runs `git-site-sync auto` every 15 minutes while you
      9 # are logged in. It asks GitLab for the head of `main` in each mirrored repo
     10 # (NixDaemon, daemon-sec-cheatsheet, daemon-sec-lotl — the list is
     11 # ~/git/daemon-sec/script/git-site/repos.json) and only when one has moved
     12 # runs `npm run git-site:sync`, which rebuilds the pages and uploads what
     13 # changed to the daemon-sec-git bucket. Failures raise a desktop notification.
     14 #
     15 # It uses what an interactive shell has: the ssh config (the private
     16 # cheatsheet repo is fetched over SSH with the sops key, see ssh.nix) and
     17 # wrangler's own login in ~/.config/.wrangler. If wrangler's login ever
     18 # expires, `npx wrangler login` in ~/git/daemon-sec fixes it.
     19 { ... }:
     20 {
     21   flake.homeModules.git-site =
     22     { pkgs, lib, ... }:
     23     let
     24       tool = pkgs.writeShellApplication {
     25         name = "git-site-sync";
     26         runtimeInputs = with pkgs; [
     27           git
     28           openssh
     29           jq
     30           nodejs
     31           python3
     32           util-linux # flock
     33           coreutils
     34           diffutils
     35           gnused
     36           libnotify # notify-send
     37           systemd
     38         ];
     39         text = builtins.readFile ./git-site/git-site-sync.sh;
     40       };
     41     in
     42     {
     43       home.packages = [ tool ];
     44 
     45       systemd.user.services.git-site-sync = {
     46         Unit = {
     47           Description = "Sync git.daemon-sec.xyz from GitLab when a mirrored repo changed";
     48           After = [ "network-online.target" ];
     49         };
     50         Service = {
     51           Type = "oneshot";
     52           ExecStart = "${lib.getExe tool} auto";
     53           Nice = 10;
     54           IOSchedulingClass = "idle";
     55         };
     56       };
     57 
     58       systemd.user.timers.git-site-sync = {
     59         Unit.Description = "Check the mirrored repos every 15 minutes";
     60         Timer = {
     61           OnCalendar = "*:0/15";
     62           Persistent = true; # catch up after the laptop was asleep
     63           RandomizedDelaySec = "90";
     64         };
     65         Install.WantedBy = [ "timers.target" ];
     66       };
     67     };
     68 }