blob: 9267d2028985bea088cb2259c6de27ac8456479f (
plain) (
tree)
|
|
{
inputs,
config,
...
}:
{
networking.firewall.allowedTCPPorts = [
80
443
];
security.acme = {
acceptTerms = true;
defaults.email = "franck@fcuny.net";
certs = {
"code.fcuny.net" = {
dnsProvider = "cloudflare";
dnsResolver = "1.1.1.1";
reloadServices = [ "nginx.service" ];
credentialFiles.CF_DNS_API_TOKEN_FILE = config.age.secrets."cloudflare-nginx".path;
};
"go.fcuny.net" = {
dnsProvider = "cloudflare";
dnsResolver = "1.1.1.1";
reloadServices = [ "nginx.service" ];
credentialFiles.CF_DNS_API_TOKEN_FILE = config.age.secrets."cloudflare-nginx".path;
};
"id.fcuny.net" = {
dnsProvider = "cloudflare";
dnsResolver = "1.1.1.1";
reloadServices = [ "nginx.service" ];
credentialFiles.CF_DNS_API_TOKEN_FILE = config.age.secrets."cloudflare-nginx".path;
};
"fcuny.net" = {
dnsProvider = "cloudflare";
dnsResolver = "1.1.1.1";
reloadServices = [ "nginx.service" ];
credentialFiles.CF_DNS_API_TOKEN_FILE = config.age.secrets."cloudflare-nginx".path;
};
};
};
services.nginx = {
enable = true;
recommendedProxySettings = true;
recommendedGzipSettings = true;
recommendedOptimisation = true;
recommendedTlsSettings = true;
virtualHosts = {
"code.fcuny.net" = {
enableACME = true;
acmeRoot = null;
forceSSL = true;
locations."/" = {
proxyPass = "http://10.100.0.60:3000";
};
locations."/metrics" = {
proxyPass = "http://10.100.0.60:3000/metrics";
extraConfig = ''
deny all;
access_log off;
'';
};
};
"go.fcuny.net" = {
enableACME = true;
acmeRoot = null;
forceSSL = true;
locations."/" = {
proxyPass = "http://10.100.0.40:8070";
};
};
"id.fcuny.net" = {
enableACME = true;
acmeRoot = null;
forceSSL = true;
locations."/" = {
proxyPass = "http://10.100.0.60:8080";
};
};
"fcuny.net" = {
enableACME = true;
acmeRoot = null;
forceSSL = true;
root = "${inputs.my-site.packages.x86_64-linux.default}/";
locations = {
"/".tryFiles = "$uri $uri/ $uri/index.html =404";
};
extraConfig = ''
error_page 404 /404;
'';
};
};
};
}
|