blob: 5c30175fe9b0a1603e4b52a5205bdb6e878e7eb8 (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
|
{
inputs,
config,
pkgs,
lib,
...
}:
{
networking.firewall.allowedTCPPorts = [
80
443
];
security.acme = {
acceptTerms = true;
defaults.email = "franck@fcuny.net";
certs = {
"code.fcuny.net" = {
dnsProvider = "cloudflare";
dnsResolver = "1.1.1.1";
reloadServices = [ "nginx.service" ];
credentialFiles.CF_DNS_API_TOKEN_FILE = config.age.secrets."cloudflare-nginx".path;
};
"go.fcuny.net" = {
dnsProvider = "cloudflare";
dnsResolver = "1.1.1.1";
reloadServices = [ "nginx.service" ];
credentialFiles.CF_DNS_API_TOKEN_FILE = config.age.secrets."cloudflare-nginx".path;
};
"id.fcuny.net" = {
dnsProvider = "cloudflare";
dnsResolver = "1.1.1.1";
reloadServices = [ "nginx.service" ];
credentialFiles.CF_DNS_API_TOKEN_FILE = config.age.secrets."cloudflare-nginx".path;
};
"fcuny.net" = {
dnsProvider = "cloudflare";
dnsResolver = "1.1.1.1";
reloadServices = [ "nginx.service" ];
credentialFiles.CF_DNS_API_TOKEN_FILE = config.age.secrets."cloudflare-nginx".path;
};
};
};
services.nginx =
let
accounts = [
{
user = "franck@fcuny.net";
realm = "fcuny.net";
}
];
webfingerConfig = {
"= /.well-known/webfinger" = {
extraConfig = ''
return 307 /__webfinger/$arg_resource;
'';
};
"~ ^/__webfinger/(acct:[^/]+@[^/]+)" = {
root = pkgs.linkFarm "webfinger-entries" (
lib.listToAttrs (
map (acct: {
name = "acct:${acct.user}";
value = pkgs.writeText "webfinger-${acct.user}" ''
{
"subject": "acct:${acct.user}",
"links": [
{
"rel": "http://openid.net/specs/connect/1.0/issuer",
"href": "https://id.fcuny.net/realms/${acct.realm}"
}
]
}
'';
}) accounts
)
);
tryFiles = "/$1 =404";
extraConfig = ''
add_header Content-Type application/json;
'';
};
};
in
{
enable = true;
recommendedProxySettings = true;
recommendedGzipSettings = true;
recommendedOptimisation = true;
recommendedTlsSettings = true;
virtualHosts = {
"code.fcuny.net" = {
enableACME = true;
acmeRoot = null;
forceSSL = true;
locations."/" = {
proxyPass = "http://10.100.0.60:3000";
};
locations."/metrics" = {
proxyPass = "http://10.100.0.60:3000/metrics";
extraConfig = ''
deny all;
access_log off;
'';
};
};
"go.fcuny.net" = {
enableACME = true;
acmeRoot = null;
forceSSL = true;
locations."/" = {
proxyPass = "http://10.100.0.40:8070";
};
};
"id.fcuny.net" = {
enableACME = true;
acmeRoot = null;
forceSSL = true;
locations = (
{
"/" = {
proxyPass = "http://10.100.0.60:8080";
};
}
// webfingerConfig
);
};
"fcuny.net" = {
enableACME = true;
acmeRoot = null;
forceSSL = true;
root = "${inputs.my-site.packages.x86_64-linux.default}/";
locations = {
"/".tryFiles = "$uri $uri/ $uri/index.html =404";
}
// webfingerConfig;
extraConfig = ''
error_page 404 /404;
'';
};
};
};
}
|