gitea: leave webhook registration operator-managed

This commit is contained in:
2026-08-23 03:59:31 +00:00
parent 959ad30fdc
commit d117d26fde
3 changed files with 5 additions and 80 deletions
+5 -5
View File
@@ -43,7 +43,7 @@ Mars includes a small HMAC-validating relay for Gitea webhooks. It forwards the
authenticated request body unchanged, along with Gitea event and delivery authenticated request body unchanged, along with Gitea event and delivery
headers, to Hermes over localhost. The relay has no event, repository, action, headers, to Hermes over localhost. The relay has no event, repository, action,
payload, or prompt policy; Hermes owns interpretation and response behavior. payload, or prompt policy; Hermes owns interpretation and response behavior.
Jupiter's Gitea provisioning service registers the webhook idempotently at Add the Gitea repository webhook manually with target URL
`http://mars.orbit.sol:8645/gitea`. `http://mars.orbit.sol:8645/gitea`.
Hermes separately subscribes to `pull_request_comment` and Hermes separately subscribes to `pull_request_comment` and
@@ -52,10 +52,10 @@ pull requests not authored by `luna`, then handles external comments in the
pull request using Tea/Gitea. This route policy is intentionally outside the pull request using Tea/Gitea. This route policy is intentionally outside the
relay. relay.
Before deploying either host, add the same random Before deploying Mars, add a random `gitea_hermes_webhook_secret` value to
`gitea_hermes_webhook_secret` value to both `secrets/mars.yaml` and `secrets/mars.yaml` with `sops --set`. Use that same value when manually
`secrets/jupiter.yaml` with `sops --set`. The value is intentionally not creating the Gitea webhook. The value is intentionally not included in the
included in the repository. repository.
## Test in VirtualBox (no hardware needed) ## Test in VirtualBox (no hardware needed)
-5
View File
@@ -48,11 +48,6 @@
# ci-bot access token to allow the ci-bot user to push to repos # ci-bot access token to allow the ci-bot user to push to repos
sops.secrets.gitea_ci_bot_token.owner = "gitea"; sops.secrets.gitea_ci_bot_token.owner = "gitea";
# Add the same value to secrets/jupiter.yaml before deploying Jupiter.
sops.secrets.gitea_hermes_webhook_secret = {
owner = "gitea";
};
# SABnzbd credentials (web UI login, API keys, eweka.nl usenet server) — # SABnzbd credentials (web UI login, API keys, eweka.nl usenet server) —
# migrated off the reused ini in services/media/sabnzbd.nix into # migrated off the reused ini in services/media/sabnzbd.nix into
# services.sabnzbd.settings + secretValues. sabnzbd_api_key predates this # services.sabnzbd.settings + secretValues. sabnzbd_api_key predates this
-70
View File
@@ -21,36 +21,6 @@ let
# nothing she does lands without darman clicking merge. # nothing she does lands without darman clicking merge.
lunaRepos = [ "darman/homelab" ]; lunaRepos = [ "darman/homelab" ];
# Forward every Gitea event to the generic Mars relay. Hermes owns the
# decision about which events matter and what to do with them.
giteaWebhookEvents = [
"create"
"delete"
"fork"
"push"
"issues"
"issue_assign"
"issue_label"
"issue_milestone"
"issue_comment"
"pull_request"
"pull_request_assign"
"pull_request_label"
"pull_request_milestone"
"pull_request_comment"
"pull_request_review_approved"
"pull_request_review_rejected"
"pull_request_review_comment"
"pull_request_sync"
"pull_request_review_request"
"wiki"
"repository"
"release"
"package"
"status"
"workflow_run"
"workflow_job"
];
in in
{ {
services.gitea = { services.gitea = {
@@ -296,44 +266,4 @@ in
''; '';
}; };
# Register the generic Gitea webhook. This is idempotent: it updates the
# existing hook for the relay target or creates it when absent. Event policy
# belongs to Hermes, so the source sends the complete Gitea event set.
systemd.services.gitea-hermes-webhook-provision = {
description = "Provision Gitea webhook for Hermes events";
after = [ "gitea.service" ];
requires = [ "gitea.service" ];
wantedBy = [ "multi-user.target" ];
path = [ pkgs.curl pkgs.jq ];
environment = {
TOKEN_FILE = config.sops.secrets.gitea_provisioning_token.path;
SECRET_FILE = config.sops.secrets.gitea_hermes_webhook_secret.path;
};
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
User = config.services.gitea.user;
};
script = ''
set -euo pipefail
api=http://127.0.0.1:${toString config.services.gitea.settings.server.HTTP_PORT}/api/v1
admin_token="$(cat "$TOKEN_FILE")"
secret="$(cat "$SECRET_FILE")"
auth=(-H "Authorization: token $admin_token")
target="http://mars.orbit.sol:8645/gitea"
body="$(jq -n --arg url "$target" --arg secret "$secret" \
--argjson events '${builtins.toJSON giteaWebhookEvents}' \
'{type: "gitea", config: {content_type: "json", url: $url, secret: $secret}, events: $events, active: true}')"
hook_id="$(curl -fsS "''${auth[@]}" "$api/repos/darman/homelab/hooks" \
| jq -r --arg url "$target" 'first(.[] | select(.type == "gitea" and .config.url == $url)) | .id // empty')"
if [ -n "$hook_id" ]; then
curl -fsS "''${auth[@]}" -H 'Content-Type: application/json' \
-X PATCH "$api/repos/darman/homelab/hooks/$hook_id" -d "$body" >/dev/null
else
curl -fsS "''${auth[@]}" -H 'Content-Type: application/json' \
-X POST "$api/repos/darman/homelab/hooks" -d "$body" >/dev/null
fi
'';
};
} }