diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Reorganize the tree into vendor/ and custom/
Diffstat (limited to 'examples')
-rw-r--r--examples/cgitrc566
-rwxr-xr-xexamples/hooks/post-receive.agefile19
-rwxr-xr-xexamples/hooks/post-update.update-server-info18
-rw-r--r--examples/servers/apache.conf152
-rw-r--r--examples/servers/lighttpd.conf132
-rw-r--r--examples/servers/nginx.conf193
6 files changed, 0 insertions, 1080 deletions
diff --git a/examples/cgitrc b/examples/cgitrc
deleted file mode 100644
index 4a36149..0000000
--- a/examples/cgitrc
+++ /dev/null
This diff is too large to be rendered inline. View it on its own page.
diff --git a/examples/hooks/post-receive.agefile b/examples/hooks/post-receive.agefile
deleted file mode 100755
index 2f72ae9..0000000
--- a/examples/hooks/post-receive.agefile
+++ /dev/null
@@ -1,19 +0,0 @@
-#!/bin/sh
-#
-# An example hook to update the "agefile" for CGit's idle time calculation.
-#
-# This hook assumes that you are using the default agefile location of
-# "info/web/last-modified". If you change the value in your cgitrc then you
-# must also change it here.
-#
-# To install the hook, copy (or link) it to the file "hooks/post-receive" in
-# each of your repositories.
-#
-
-agefile="$(git rev-parse --git-dir)"/info/web/last-modified
-
-mkdir -p "$(dirname "$agefile")" &&
-git for-each-ref \
- --sort=-authordate --count=1 \
- --format='%(authordate:iso8601)' \
- >"$agefile"
diff --git a/examples/hooks/post-update.update-server-info b/examples/hooks/post-update.update-server-info
deleted file mode 100755
index d499ce5..0000000
--- a/examples/hooks/post-update.update-server-info
+++ /dev/null
@@ -1,18 +0,0 @@
-#!/bin/sh
-#
-# Example hook that keeps cgit's dumb HTTP clone data current.
-#
-# cgit can serve "git clone" over HTTP by itself using the dumb protocol,
-# which is on by default through enable-http-clone. The dumb protocol
-# reads a few static files that git refreshes only when you run
-# "git update-server-info", so without this hook a fresh push can leave a
-# clone unable to see the new refs and objects.
-#
-# You do not need this when you clone through git-http-backend (the smart
-# protocol) or over ssh or git://. It matters only when cgit itself is the
-# clone endpoint.
-#
-# To install it, copy or link this file to "hooks/post-update" in each
-# repository and make sure it is executable.
-#
-exec git update-server-info
diff --git a/examples/servers/apache.conf b/examples/servers/apache.conf
deleted file mode 100644
index d042dd9..0000000
--- a/examples/servers/apache.conf
+++ /dev/null
@@ -1,152 +0,0 @@
-# Apache httpd 2.4 configuration for cgit.
-#
-# Apache runs the cgit.cgi binary directly through mod_cgid, so no FastCGI
-# bridge is needed. Drop this file in your vhost directory, for example
-# /etc/apache2/sites-available/cgit.conf on Debian and Ubuntu or
-# /etc/httpd/conf.d/cgit.conf on RHEL and Fedora, then enable it and reload.
-#
-# Paths assumed below, edit them to match your install.
-# cgit CGI binary /usr/lib/cgit/cgit.cgi
-# static assets /usr/share/cgit (cgit.css cgit.js cgit.png favicon.ico robots.txt)
-# cgit config /etc/cgitrc
-# public URL https://git.example.org/ (cgit at the domain root)
-#
-# cgit is one CGI executable. It learns the repository and the page from
-# PATH_INFO and reads page options such as h= and id= from QUERY_STRING.
-# ScriptAlias runs the binary and forwards the trailing path as PATH_INFO, so
-# no extra path tuning is needed. cgit builds its own link base from
-# SCRIPT_NAME. The five static assets are served straight off disk. mod_alias
-# resolves Alias and ScriptAlias in order and the first match wins, so the
-# static Alias lines come before the catch-all ScriptAlias to stop the two
-# routes from shadowing each other.
-
-
-# --- Required modules -------------------------------------------------------
-# mod_cgid suits the threaded MPMs that ship by default. Use mod_cgi instead
-# only on the old prefork MPM. mod_alias provides Alias and ScriptAlias and
-# mod_env provides SetEnv. On Debian and Ubuntu run a2enmod cgid alias env
-# rather than editing these lines. The guards make double-loading harmless.
-<IfModule !mod_cgid.c>
- LoadModule cgid_module modules/mod_cgid.so
-</IfModule>
-<IfModule !mod_alias.c>
- LoadModule alias_module modules/mod_alias.so
-</IfModule>
-<IfModule !mod_env.c>
- LoadModule env_module modules/mod_env.so
-</IfModule>
-<IfModule !mod_headers.c>
- LoadModule headers_module modules/mod_headers.so
-</IfModule>
-
-
-# --- Plain HTTP virtual host ------------------------------------------------
-# This vhost only bounces plain HTTP up to HTTPS. It serves no cgit itself,
-# every cgit directive lives in the HTTPS vhost below. To run without TLS for
-# now, convert the HTTPS vhost to port 80 and delete this whole block rather
-# than editing it, since deleting only the Redirect line would leave a vhost
-# that serves nothing.
-<VirtualHost *:80>
- ServerName git.example.org
-
- ErrorLog /var/log/apache2/cgit_error.log
- CustomLog /var/log/apache2/cgit_access.log combined
-
- Redirect permanent / https://git.example.org/
-</VirtualHost>
-
-
-# --- HTTPS virtual host, this one serves cgit -------------------------------
-# To run without TLS for now, change this opening line to <VirtualHost *:80>,
-# delete the three SSL lines, and delete the port 80 vhost above so there is
-# only one vhost. Everything else stays the same.
-<VirtualHost *:443>
- ServerName git.example.org
-
- ErrorLog /var/log/apache2/cgit_ssl_error.log
- CustomLog /var/log/apache2/cgit_ssl_access.log combined
-
- # TLS needs mod_ssl (a2enmod ssl). Point these at your certificate.
- SSLEngine on
- SSLCertificateFile /etc/ssl/certs/git.example.org.crt
- SSLCertificateKeyFile /etc/ssl/private/git.example.org.key
-
- # Which config cgit reads. It falls back to the compiled-in /etc/cgitrc,
- # the same path used here, but setting it makes the location explicit and
- # lets you point at a per-vhost file later.
- SetEnv CGIT_CONFIG /etc/cgitrc
-
- # --- Security headers (needs mod_headers, a2enmod headers) --------------
- # Set here, not in cgit, so they also cover the static assets Apache
- # serves. script-src stays self because cgit loads only its own cgit.js,
- # and style-src allows inline for the diffstat bars. If you enable the
- # gravatar or libravatar avatar filter, add its host to img-src, for
- # example https://www.gravatar.com.
- Header always set Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'"
- Header always set X-Content-Type-Options "nosniff"
- Header always set Referrer-Policy "no-referrer"
- # Enable only once you serve HTTPS exclusively, since it is hard to undo.
- #Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
-
- # --- Static assets, served directly by Apache ---------------------------
- # These five files are the only things served off disk. Each Alias maps
- # one URL to one file. Because they come before the ScriptAlias below, a
- # request for /cgit.css is answered from disk and never reaches cgit.
- # cgit.css and cgit.js are the paths cgit's HTML points at by default, so
- # if you relocate the assets update both these Alias targets and the css,
- # js, logo and favicon settings in cgitrc to agree.
- Alias /cgit.css /usr/share/cgit/cgit.css
- Alias /cgit.js /usr/share/cgit/cgit.js
- Alias /cgit.png /usr/share/cgit/cgit.png
- Alias /favicon.ico /usr/share/cgit/favicon.ico
- Alias /robots.txt /usr/share/cgit/robots.txt
-
- # Apache 2.4 denies filesystem access by default, so open the asset
- # directory for reading.
- <Directory "/usr/share/cgit">
- Options None
- AllowOverride None
- Require all granted
-
- # Optional. These assets rarely change, so let browsers cache them.
- # Needs mod_expires (a2enmod expires). Safe to delete this block.
- <IfModule mod_expires.c>
- ExpiresActive On
- ExpiresDefault "access plus 30 days"
- </IfModule>
- </Directory>
-
- # --- cgit, the catch-all ------------------------------------------------
- # ScriptAlias maps a URL prefix to a path, marks it executable, and
- # forwards the rest of the URL as PATH_INFO. Mapping / makes cgit the
- # handler for every URL the static Aliases above did not already claim.
- #
- # The trailing slash on cgit.cgi/ is load bearing. It tells Apache that
- # cgit.cgi is the program and the rest of the URL is PATH_INFO. So a
- # request for /torvalds/linux/tree/kernel?h=next runs the binary with
- # PATH_INFO set to /torvalds/linux/tree/kernel and QUERY_STRING set to
- # h=next. cgit derives its link base from SCRIPT_NAME, which at the domain
- # root is / and needs no tuning. For a sub-path install see the note below.
- ScriptAlias / /usr/lib/cgit/cgit.cgi/
-
- <Directory "/usr/lib/cgit">
- # Allow CGI execution here. ScriptAlias implies it, stating it makes
- # the intent clear.
- Options +ExecCGI
- # Run cgit.cgi as a CGI even if it is ever reached through a plain
- # Alias rather than ScriptAlias.
- SetHandler cgi-script
- AllowOverride None
- Require all granted
- </Directory>
-</VirtualHost>
-
-
-# --- Sub-path install, only if cgit is not at the domain root ---------------
-# To serve cgit at https://git.example.org/cgit/ instead of the root, change
-# the ScriptAlias to
-# ScriptAlias /cgit/ /usr/lib/cgit/cgit.cgi/
-# and move the static assets under the same prefix, for example
-# Alias /cgit/cgit.css /usr/share/cgit/cgit.css
-# SCRIPT_NAME then becomes /cgit and cgit auto-detects it. If links come out
-# wrong, pin the base in cgitrc with virtual-root=/cgit.
diff --git a/examples/servers/lighttpd.conf b/examples/servers/lighttpd.conf
deleted file mode 100644
index 3111ed0..0000000
--- a/examples/servers/lighttpd.conf
+++ /dev/null
@@ -1,132 +0,0 @@
-# lighttpd configuration for cgit.
-#
-# lighttpd runs the cgit.cgi binary directly through mod_cgi, so no FastCGI
-# bridge is needed. This is cgit's classic reference deployment, mod_cgi with
-# mod_alias and mod_setenv.
-#
-# Paths assumed below, edit them to match your install.
-# cgit CGI binary /usr/lib/cgit/cgit.cgi
-# static assets /usr/share/cgit (cgit.css cgit.js cgit.png favicon.ico robots.txt)
-# cgit config /etc/cgitrc
-# public URL https://git.example.org/ (cgit at the domain root)
-#
-# cgit is one CGI executable. It learns the repository and the page from
-# PATH_INFO and reads page options such as h= and id= from QUERY_STRING. cgit
-# builds its own link base from SCRIPT_NAME. The five static assets are served
-# straight off disk and must never be routed through cgit.
-
-
-# --- Modules ----------------------------------------------------------------
-# Append the three modules cgit needs so the distro's base config is kept.
-# mod_alias maps URL paths onto files, mod_setenv injects CGIT_CONFIG, and
-# mod_cgi runs cgit.cgi.
-server.modules += ( "mod_alias", "mod_setenv", "mod_cgi" )
-
-
-# --- Server basics ----------------------------------------------------------
-server.port = 80
-server.username = "http" # Debian and Ubuntu use www-data
-server.groupname = "http"
-server.document-root = "/usr/share/cgit" # a valid docroot must exist, the
- # alias rules below do the routing
-server.errorlog = "/var/log/lighttpd/error.log"
-# Access logging needs mod_accesslog. Load it and uncomment to enable.
-#server.modules += ( "mod_accesslog" )
-#accesslog.filename = "/var/log/lighttpd/access.log"
-
-
-# --- MIME types for the static assets ---------------------------------------
-# mod_alias serves the assets off disk, so lighttpd must know their content
-# types. Without this the stylesheet is sent as application/octet-stream and
-# the browser ignores it.
-mimetype.assign = (
- ".css" => "text/css",
- ".js" => "text/javascript",
- ".png" => "image/png",
- ".ico" => "image/vnd.microsoft.icon",
- ".txt" => "text/plain",
-)
-
-
-# --- Virtual host, git.example.org ------------------------------------------
-# A top-level conditional, so it matches on both the port 80 socket and the
-# optional TLS socket at the end of this file.
-$HTTP["host"] == "git.example.org" {
-
- # Which config cgit reads. It falls back to the compiled-in /etc/cgitrc,
- # the same path used here, but setting it makes the location explicit.
- setenv.add-environment = ( "CGIT_CONFIG" => "/etc/cgitrc" )
-
- # --- Security headers ---------------------------------------------------
- # Set here, not in cgit, so they also cover the static assets lighttpd
- # serves. script-src stays self because cgit loads only its own cgit.js,
- # and style-src allows inline for the diffstat bars. If you enable the
- # gravatar or libravatar avatar filter, add its host to img-src.
- setenv.add-response-header = (
- "Content-Security-Policy" => "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'",
- "X-Content-Type-Options" => "nosniff",
- "Referrer-Policy" => "no-referrer"
- )
- # Enable only once you serve HTTPS exclusively, since it is hard to undo.
- #setenv.add-response-header += ( "Strict-Transport-Security" => "max-age=63072000; includeSubDomains" )
-
- # Register the cgit binary as a CGI program. The key cgit.cgi matches the
- # binary's name and the empty value means the file is itself the program,
- # with no interpreter in front of it. This is what makes lighttpd split
- # the trailing path off as PATH_INFO, so never drop it.
- cgi.assign = ( "cgit.cgi" => "" )
-
- # Routing. lighttpd's alias.url is first-match in declaration order, not
- # longest prefix, so the five static entries must come before the / entry.
- # If / came first it would swallow every request and recent lighttpd
- # refuses to start. The static entries are served off disk and the / entry
- # hands everything else to cgit.
- #
- # The trailing slash on cgit.cgi/ is load bearing. lighttpd builds the
- # physical path by stripping the matched key off the front of the URL and
- # appending the rest to the value. For the key / the remainder carries no
- # leading slash, so without the trailing slash a request for
- # /linux/tree/kernel/sched.c glues onto the binary name as
- # /usr/lib/cgit/cgit.cgilinux/tree/... and 404s. The trailing slash
- # restores the separator, giving cgit SCRIPT_FILENAME /usr/lib/cgit/cgit.cgi
- # and PATH_INFO /linux/tree/kernel/sched.c.
- alias.url = (
- "/cgit.css" => "/usr/share/cgit/cgit.css",
- "/cgit.js" => "/usr/share/cgit/cgit.js",
- "/cgit.png" => "/usr/share/cgit/cgit.png",
- "/favicon.ico" => "/usr/share/cgit/favicon.ico",
- "/robots.txt" => "/usr/share/cgit/robots.txt",
- "/" => "/usr/lib/cgit/cgit.cgi/",
- )
-
- # Served at / the SCRIPT_NAME is empty and cgit derives its link base
- # correctly. For a sub-path install use a key without a trailing slash
- # mapped to the binary without a trailing slash, for example
- # "/git" => "/usr/lib/cgit/cgit.cgi"
- # so /git/linux/tree resolves to /usr/lib/cgit/cgit.cgi/linux/tree, giving
- # SCRIPT_NAME /git and PATH_INFO /linux/tree. cgit auto-detects the prefix.
- # If links come out wrong, pin it in cgitrc with virtual-root=/git.
-}
-
-
-# --- Optional HTTPS on 443 --------------------------------------------------
-# Uncomment this whole block to enable TLS. The host block above is socket
-# independent, so it serves cgit over this socket too once the crypto is set.
-#server.modules += ( "mod_openssl" )
-#
-#$SERVER["socket"] == ":443" {
-# ssl.engine = "enable"
-# ssl.pemfile = "/etc/lighttpd/certs/git.example.org.crt"
-# ssl.privkey = "/etc/lighttpd/certs/git.example.org.key"
-# ssl.ca-file = "/etc/lighttpd/certs/git.example.org.chain.pem"
-# ssl.openssl.ssl-conf-cmd = ( "MinProtocol" => "TLSv1.2" )
-#}
-#
-# Redirect plain HTTP to HTTPS, scoped to the port 80 socket. Needs
-# mod_redirect.
-#server.modules += ( "mod_redirect" )
-#$SERVER["socket"] == ":80" {
-# $HTTP["host"] == "git.example.org" {
-# url.redirect = ( "^/(.*)" => "https://git.example.org/$1" )
-# }
-#}
diff --git a/examples/servers/nginx.conf b/examples/servers/nginx.conf
deleted file mode 100644
index 76ac260..0000000
--- a/examples/servers/nginx.conf
+++ /dev/null
@@ -1,193 +0,0 @@
-# nginx configuration for cgit.
-#
-# nginx cannot run CGI programs itself, so a small bridge called fcgiwrap
-# runs the cgit.cgi binary and speaks FastCGI to nginx. Starting fcgiwrap is
-# covered in the notes at the end of this file.
-#
-# Paths assumed below, edit them to match your install.
-# cgit CGI binary /usr/lib/cgit/cgit.cgi
-# static assets /usr/share/cgit (cgit.css cgit.js cgit.png favicon.ico robots.txt)
-# cgit config /etc/cgitrc
-# public URL https://git.example.org/ (cgit at the domain root)
-#
-# cgit is one CGI executable. It learns the repository and the page from
-# PATH_INFO and reads page options such as h= and id= from QUERY_STRING, so
-# nginx must pass PATH_INFO through to the binary. cgit builds its own link
-# base from SCRIPT_NAME. The five static assets are served straight off disk
-# and must never be routed through cgit. Passing PATH_INFO through is the
-# single most important part of the config below.
-
-
-# --- Optional HTTP to HTTPS redirect ----------------------------------------
-# Delete this whole server block if you serve plain HTTP only.
-server {
- listen 80;
- listen [::]:80;
- server_name git.example.org;
-
- # ACME http-01 challenge files, if you use certbot in webroot mode.
- location ^~ /.well-known/acme-challenge/ {
- root /var/www/html;
- }
-
- # Everything else moves to HTTPS.
- location / {
- return 301 https://$host$request_uri;
- }
-}
-
-
-# --- Main site --------------------------------------------------------------
-# Written for TLS on 443. For a quick plain-HTTP test, change the two listen
-# lines to port 80, delete the redirect block above, and delete the four ssl
-# lines below. Everything else stays the same.
-server {
- listen 443 ssl;
- listen [::]:443 ssl;
- http2 on;
- server_name git.example.org;
-
- ssl_certificate /etc/letsencrypt/live/git.example.org/fullchain.pem;
- ssl_certificate_key /etc/letsencrypt/live/git.example.org/privkey.pem;
- ssl_protocols TLSv1.2 TLSv1.3;
- ssl_ciphers HIGH:!aNULL:!MD5;
-
- # --- Security headers ---------------------------------------------------
- # These sit here, not in cgit, because they must also cover the static
- # assets nginx serves directly. cgit loads only its own /cgit.js and uses
- # inline style on the diffstat bars, so script-src stays self while
- # style-src allows inline. always applies them to error responses too. If
- # you enable the gravatar or libravatar avatar filter, add its host to
- # img-src, for example https://www.gravatar.com or https://seccdn.libravatar.org.
- add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'" always;
- add_header X-Content-Type-Options "nosniff" always;
- add_header Referrer-Policy "no-referrer" always;
- # Enable only once you serve HTTPS exclusively, since it is hard to undo.
- #add_header Strict-Transport-Security "max-age=63072000; includeSubDomains" always;
-
- # The document root is the directory that holds the static assets. cgit
- # emits absolute links to /cgit.css and /cgit.png by default, so those
- # files must resolve at the root of the URL space. Pointing root at the
- # asset directory makes /cgit.css map to /usr/share/cgit/cgit.css.
- root /usr/share/cgit;
-
- # Upload cap for large form posts. Snapshots are generated rather than
- # uploaded, so this does not limit them.
- client_max_body_size 64m;
-
- access_log /var/log/nginx/cgit.access.log;
- error_log /var/log/nginx/cgit.error.log;
-
- # --- Static assets, served directly -------------------------------------
- # Match the assets by their exact root-level names, never by bare
- # extension. cgit routes on PATH_INFO and a repository can hold files
- # ending in .css or .png, so /myrepo/tree/style.css and /myrepo/plain/
- # logo.png are real cgit URLs. A broad extension match would capture
- # those, look for them on disk, and return 404 before cgit could render
- # them. Anchoring the regex at the start of the path matches /cgit.css but
- # not /myrepo/tree/cgit.css, so it can never shadow a repository file. An
- # nginx regex location is matched before the prefix location below, so
- # these assets win for their exact URLs and cgit wins for the rest.
- location ~ ^/(cgit\.css|cgit\.js|cgit\.png|favicon\.ico|robots\.txt)$ {
- expires 30d;
- access_log off;
- try_files $uri =404;
- }
-
- # --- cgit, the catch-all ------------------------------------------------
- # Everything that is not a static asset above is a cgit URL, the repo
- # index, a repository, a page within a repository, a snapshot, a feed.
- location / {
- # nginx's standard FastCGI parameters, some of which are overridden
- # below. A later fastcgi_param wins, so include order does not matter.
- include fastcgi_params;
-
- # The program fcgiwrap runs. It must be the cgit binary itself, not
- # $document_root$fastcgi_script_name, which would try to run a repo
- # path and is the usual cause of a failed request.
- fastcgi_param SCRIPT_FILENAME /usr/lib/cgit/cgit.cgi;
-
- # cgit builds its link base, the virtual root, from SCRIPT_NAME. The
- # stock parameters set SCRIPT_NAME to the whole request path, which
- # would make cgit prepend that path to every link. Served at the
- # domain root the script has no prefix, so force SCRIPT_NAME empty and
- # cgit uses / as its base. A sub-path install sets it instead, see the
- # end of this file.
- fastcgi_param SCRIPT_NAME "";
-
- # How cgit learns the repository and page. At the domain root the
- # whole request path is the PATH_INFO.
- fastcgi_param PATH_INFO $uri;
-
- # Page options such as h=branch, id=sha and the snapshot format.
- fastcgi_param QUERY_STRING $query_string;
-
- # Where the static assets live, kept consistent with root above.
- fastcgi_param DOCUMENT_ROOT $document_root;
-
- # The browser's Host header, so cgit builds clone URLs against the
- # name the visitor used rather than server_name.
- fastcgi_param HTTP_HOST $http_host;
-
- # Which config cgit reads. It checks CGIT_CONFIG and falls back to the
- # compiled-in /etc/cgitrc. Setting it makes the location explicit and
- # lets you move cgitrc without recompiling.
- fastcgi_param CGIT_CONFIG /etc/cgitrc;
-
- # The real scheme, so cgit builds correct https clone URLs.
- fastcgi_param HTTPS $https if_not_empty;
-
- # Hand off to the fcgiwrap socket. See the notes for how to create it.
- # A TCP fcgiwrap would use for example 127.0.0.1:9000 here.
- fastcgi_pass unix:/run/fcgiwrap.socket;
-
- # Large outputs such as snapshot tarballs and blame on big files can
- # take a while, so give cgit room and stream rather than buffer.
- fastcgi_read_timeout 300s;
- fastcgi_buffering off;
- }
-}
-
-
-# --- Notes, starting fcgiwrap -----------------------------------------------
-# cgit is a CGI binary and fcgiwrap is the CGI to FastCGI bridge nginx talks
-# to. On Debian and Ubuntu the packaged systemd socket provides
-# /run/fcgiwrap.socket, so enabling it is enough.
-# apt install fcgiwrap
-# systemctl enable --now fcgiwrap.socket
-# The socket must be readable by nginx's user. The packaged unit runs fcgiwrap
-# as www-data, which nginx also uses on those systems. Without systemd you can
-# run
-# spawn-fcgi -s /run/fcgiwrap.socket -M 660 -- /usr/sbin/fcgiwrap
-# or run fcgiwrap over TCP and point fastcgi_pass at 127.0.0.1:9000.
-
-
-# --- Alternative, serving cgit under a sub-path -----------------------------
-# To serve cgit at https://git.example.org/cgit/ instead of the root, split
-# the URL so SCRIPT_NAME is the prefix and PATH_INFO is the rest.
-#
-# location /cgit/ {
-# include fastcgi_params;
-# fastcgi_split_path_info ^(/cgit)(/.*)$;
-# fastcgi_param SCRIPT_FILENAME /usr/lib/cgit/cgit.cgi;
-# fastcgi_param SCRIPT_NAME $fastcgi_script_name;
-# fastcgi_param PATH_INFO $fastcgi_path_info;
-# fastcgi_param QUERY_STRING $query_string;
-# fastcgi_param HTTP_HOST $http_host;
-# fastcgi_param CGIT_CONFIG /etc/cgitrc;
-# fastcgi_param HTTPS $https if_not_empty;
-# fastcgi_pass unix:/run/fcgiwrap.socket;
-# }
-#
-# Serve the assets from the sub-path too, again anchored to the exact names.
-#
-# location ~ ^/cgit/(cgit\.css|cgit\.js|cgit\.png|favicon\.ico|robots\.txt)$ {
-# alias /usr/share/cgit/$1;
-# expires 30d;
-# access_log off;
-# }
-#
-# cgit's default css=/cgit.css and logo=/cgit.png point at the domain root, so
-# under a sub-path also set css=/cgit/cgit.css and logo=/cgit/cgit.png in
-# cgitrc. cgit derives the /cgit prefix from SCRIPT_NAME. If links come out
-# wrong, pin it in cgitrc with virtual-root=/cgit/.