services: hydra: fix reverse proxy and firewall
This commit is contained in:
parent
40fdd49224
commit
e8f6f4e96f
@ -97,7 +97,7 @@
|
|||||||
firewall = {
|
firewall = {
|
||||||
enable = true;
|
enable = true;
|
||||||
allowedUDPPorts = [ ];
|
allowedUDPPorts = [ ];
|
||||||
allowedTCPPorts = [ ];
|
allowedTCPPorts = [ 80 443 ];
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
@ -20,9 +20,7 @@
|
|||||||
"${config.services.hydra.hydraURL}" = {
|
"${config.services.hydra.hydraURL}" = {
|
||||||
enableACME = true;
|
enableACME = true;
|
||||||
forceSSL = true;
|
forceSSL = true;
|
||||||
listen = [ {
|
locations."/".proxyPass = "http://localhost:3000";
|
||||||
addr = "127.0.0.1"; port = 3000;
|
|
||||||
} ];
|
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
@ -30,7 +28,7 @@
|
|||||||
|
|
||||||
security.acme = {
|
security.acme = {
|
||||||
defaults.email = "webmaster@kabtop.de";
|
defaults.email = "webmaster@kabtop.de";
|
||||||
defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory";
|
#defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory";
|
||||||
acceptTerms = true;
|
acceptTerms = true;
|
||||||
certs.${config.services.hydra.hydraURL} = {
|
certs.${config.services.hydra.hydraURL} = {
|
||||||
dnsProvider = "netcup";
|
dnsProvider = "netcup";
|
||||||
|
Loading…
Reference in New Issue
Block a user