]> Git — Sourcephile - sourcephile-nix.git/blob - machines/losurdo/nginx.nix
gnupg: update nixpkgs#93659
[sourcephile-nix.git] / machines / losurdo / nginx.nix
1 { pkgs, lib, config, ... }:
2 let
3 inherit (config) networking;
4 inherit (config.services) nginx;
5 in
6 {
7 imports = [
8 ../../nixos/profiles/services/nginx.nix
9 nginx/sourcephile.fr.nix
10 ];
11 users.groups."acme".members = [nginx.user];
12 users.groups."transmission".members = [nginx.user];
13 networking.nftables.ruleset = ''
14 add rule inet filter net2fw tcp dport 80 counter accept comment "HTTP"
15 add rule inet filter net2fw tcp dport 443 counter accept comment "HTTPS"
16 '';
17 services.upnpc.redirections = [
18 { description = "HTTP"; externalPort = 80; protocol = "TCP"; duration = 30 * 60;
19 service.wantedBy = ["nginx.service"];
20 service.partOf = ["nginx.service"];
21 }
22 { description = "HTTPS"; externalPort = 443; protocol = "TCP"; duration = 30 * 60;
23 service.wantedBy = ["nginx.service"];
24 service.partOf = ["nginx.service"];
25 }
26 ];
27 services.nginx = {
28 enable = true;
29 package = pkgs.nginx.override {
30 modules = with pkgs.nginxModules; [
31 fancyindex
32 ];
33 };
34 resolver = {
35 addresses = [ "127.0.0.1:53" ];
36 valid = "";
37 };
38 virtualHosts."_" = {
39 default = true;
40 extraConfig = ''
41 # Connection closed without response
42 return 444;
43 '';
44 forceSSL = true;
45 useACMEHost = networking.domain;
46 };
47 };
48 }