feat" diffkit self host" (#72)
Some checks are pending
quality / changes (push) Waiting to run
quality / Flake Check (push) Blocked by required conditions
quality / Nix Format Check (push) Blocked by required conditions
quality / Deploy netty (push) Blocked by required conditions

This commit is contained in:
Hari 2026-04-14 12:44:16 -04:00 committed by GitHub
parent fa2260d8d5
commit d482eb01e4
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
4 changed files with 83 additions and 1 deletions

View file

@ -17,6 +17,7 @@ in
./nginx.nix ./nginx.nix
./vaultwarden.nix ./vaultwarden.nix
./forgejo.nix ./forgejo.nix
./diffkit.nix
./betternas.nix ./betternas.nix
./hermes-gateway.nix ./hermes-gateway.nix
./forgejo-runner.nix ./forgejo-runner.nix

71
hosts/netty/diffkit.nix Normal file
View file

@ -0,0 +1,71 @@
{
pkgs,
username,
...
}:
let
diffkitPort = "3200";
stateDir = "/var/lib/diffkit";
repoDir = "/home/${username}/Documents/GitHub/diffkit";
envFile = "${stateDir}/diffkit.env";
dbPath = "${stateDir}/diffkit.db";
migrationsDir = "${repoDir}/apps/dashboard/drizzle";
migrationScript = pkgs.writeShellScript "diffkit-migrate" ''
set -euo pipefail
DB="${dbPath}"
MIGRATIONS="${migrationsDir}"
${pkgs.sqlite}/bin/sqlite3 "$DB" "SELECT 1;" > /dev/null 2>&1 || true
${pkgs.sqlite}/bin/sqlite3 "$DB" \
"CREATE TABLE IF NOT EXISTS __drizzle_migrations (tag TEXT PRIMARY KEY, applied_at INTEGER NOT NULL);"
for sql_file in "$MIGRATIONS"/[0-9]*.sql; do
[ -f "$sql_file" ] || continue
tag=$(basename "$sql_file" .sql)
applied=$(${pkgs.sqlite}/bin/sqlite3 "$DB" "SELECT COUNT(*) FROM __drizzle_migrations WHERE tag='$tag';")
if [ "$applied" = "0" ]; then
echo "Applying migration: $tag"
${pkgs.gnused}/bin/sed 's/--> statement-breakpoint/;/g' "$sql_file" \
| ${pkgs.sqlite}/bin/sqlite3 "$DB"
${pkgs.sqlite}/bin/sqlite3 "$DB" \
"INSERT INTO __drizzle_migrations (tag, applied_at) VALUES ('$tag', strftime('%s','now'));"
fi
done
echo "Migrations complete."
'';
in
{
systemd.tmpfiles.rules = [
"d ${stateDir} 0750 ${username} users -"
"z ${envFile} 0600 ${username} users -"
];
systemd.services.diffkit = {
description = "diffkit GitHub Diff Viewer";
after = [ "network-online.target" ];
wants = [ "network-online.target" ];
wantedBy = [ "multi-user.target" ];
environment = {
NODE_ENV = "production";
HOST = "127.0.0.1";
PORT = diffkitPort;
DATABASE_PATH = dbPath;
BETTER_AUTH_URL = "https://diffs.harivan.sh";
GITHUB_APP_PRIVATE_KEY_FILE = "${stateDir}/github-app-key.pem";
};
serviceConfig = {
Type = "simple";
User = username;
Group = "users";
WorkingDirectory = "${repoDir}/apps/dashboard";
ExecStartPre = migrationScript;
ExecStart = "${pkgs.nodejs_22}/bin/node node-server.mjs";
EnvironmentFile = "-${envFile}";
Restart = "on-failure";
RestartSec = 5;
};
};
}

View file

@ -6,6 +6,7 @@ let
forgejoDomain = "git.harivan.sh"; forgejoDomain = "git.harivan.sh";
vaultDomain = "vault.harivan.sh"; vaultDomain = "vault.harivan.sh";
betternasDomain = "api.betternas.com"; betternasDomain = "api.betternas.com";
diffkitDomain = "diffs.harivan.sh";
in in
{ {
security.acme = { security.acme = {
@ -43,6 +44,15 @@ in
locations."/".proxyPass = "http://127.0.0.1:8222"; locations."/".proxyPass = "http://127.0.0.1:8222";
}; };
virtualHosts.${diffkitDomain} = {
enableACME = true;
forceSSL = true;
locations."/" = {
proxyPass = "http://127.0.0.1:3200";
proxyWebsockets = true;
};
};
virtualHosts.${betternasDomain} = { virtualHosts.${betternasDomain} = {
enableACME = true; enableACME = true;
forceSSL = true; forceSSL = true;

View file

@ -11,7 +11,7 @@
git git
just just
nixfmt-tree nixfmt-tree
nodePackages.prettier prettier
pre-commit pre-commit
selene selene
shfmt shfmt