hosts: dmz: nix-serve: add reverse proxy

This commit is contained in:
Kabbone 2024-05-31 20:42:16 +02:00
parent cb7412e749
commit 2b30c68a54
Signed by: Kabbone
SSH Key Fingerprint: SHA256:A5zPB5I6u5V78V51c362BBdCwhDhfDUVbt7NfKdjWBY

View File

@ -4,33 +4,40 @@
services = {
hydra = {
enable = true;
hydraURL = "hydra.home.opel-online.de";
hydraURL = "https://hydra.home.opel-online.de";
listenHost = "localhost";
notificationSender = "hydra@localhost";
useSubstitutes = true;
minimumDiskFree = 30;
};
nix-serve = {
enable = true;
port = 5001;
bindAddress = "127.0.0.1";
secretKeyFile = config.age.secrets."keys/nixsign".path;
};
nginx = {
enable = true;
virtualHosts = {
"${config.services.hydra.hydraURL}" = {
"hydra.home.opel-online.de" = {
enableACME = true;
forceSSL = true;
locations."/".proxyPass = "http://localhost:3000";
};
"cache.home.opel-online.de" = {
enableACME = true;
forceSSL = true;
locations."/".proxyPass = "http://localhost:5001";
};
};
};
};
security.acme = {
defaults.email = "webmaster@kabtop.de";
#defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory";
acceptTerms = true;
certs.${config.services.hydra.hydraURL} = {
defaults = {
email = "webmaster@kabtop.de";
#defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory";
dnsProvider = "netcup";
environmentFile = config.age.secrets."services/acme/opel-online".path;
webroot = null;