acme settings

This commit is contained in:
Lgmrszd 2024-01-15 00:22:14 +03:00
parent 895d85c1db
commit dd8bae8d47
No known key found for this signature in database
GPG key ID: 9396B8BA6FBB14DE

View file

@ -1,4 +1,11 @@
{ pkgs, ... }: { { pkgs, ... }:
let
rootDomain = "lgm.6dcdb488.nip.io";
gtnhDomain = "gtnh.${rootDomain}";
akkoDomain = "akko.testdrive.${rootDomain}";
iceDomain = "ice.testdrive.${rootDomain}";
in
{
imports = [ imports = [
./hardware-configuration.nix ./hardware-configuration.nix
@ -27,31 +34,55 @@
port = 22; port = 22;
}; };
users.users.nginx.extraGroups = [ "acme" ];
services.nginx = { services.nginx = {
enable = true; enable = true;
virtualHosts."gtnh.lgm.6dcdb488.nip.io" = { virtualHosts.${gtnhDomain} = {
# addSSL = true; # addSSL = true;
forceSSL = true; forceSSL = true;
enableACME = true; # enableACME = true;
useACMEHost = "lgm.6dcdb488.nip.io";
root = "/var/www/gtnh"; root = "/var/www/gtnh";
}; };
virtualHosts."akko.testdrive.lgm.6dcdb488.nip.io" = { virtualHosts.${akkoDomain} = {
# addSSL = true; # addSSL = true;
forceSSL = true; forceSSL = true;
enableACME = true; # enableACME = true;
useACMEHost = "lgm.6dcdb488.nip.io";
root = "/var/www/todo"; root = "/var/www/todo";
}; };
virtualHosts."ice.testdrive.lgm.6dcdb488.nip.io" = { virtualHosts.${iceDomain} = {
# addSSL = true; # addSSL = true;
forceSSL = true; forceSSL = true;
enableACME = true; # enableACME = true;
useACMEHost = "lgm.6dcdb488.nip.io";
root = "/var/www/todo"; root = "/var/www/todo";
}; };
virtualHosts."acmechallenge.${rootDomain}" = {
# Catchall vhost, will redirect users to HTTPS for all vhosts
serverAliases = [ "*.${rootDomain}" ];
locations."/.well-known/acme-challenge" = {
root = "/var/lib/acme/.challenges";
};
locations."/" = {
return = "301 https://$host$request_uri";
};
};
}; };
security.acme = { security.acme = {
acceptTerms = true; acceptTerms = true;
defaults.email = "lgmrszd@disroot.org"; defaults.email = "lgmrszd@disroot.org";
certs.${rootDomain} = {
group = "nginx";
webroot = "/var/lib/acme/.challenges";
extraDomainNames = [
gtnhDomain
akkoDomain
iceDomain
];
};
}; };