1 { pkgs, lib, config, ... }:
3 inherit (config) networking;
4 inherit (config.services) nginx;
8 ../../nixos/profiles/services/nginx.nix
9 nginx/autogeree.net.nix
10 nginx/sourcephile.fr.nix
12 users.groups."acme".members = [nginx.user];
13 users.groups."keys".members = [nginx.user];
14 networking.nftables.ruleset = ''
15 add rule inet filter net2fw tcp dport 80 counter accept comment "HTTP"
16 add rule inet filter net2fw tcp dport 443 counter accept comment "HTTPS"
18 fileSystems."/var/lib/nginx" = {
19 device = "rpool/var/www";
24 package = pkgs.nginx.override {
25 modules = with pkgs.nginxModules; [
30 addresses = [ "127.0.0.1:53" ];
35 useACMEHost = networking.domain;