services: hydra: fix reverse proxy and firewall

This commit is contained in:
Kabbone 2024-05-31 19:46:43 +02:00
parent 40fdd49224
commit e8f6f4e96f
Signed by: Kabbone
SSH Key Fingerprint: SHA256:A5zPB5I6u5V78V51c362BBdCwhDhfDUVbt7NfKdjWBY
2 changed files with 3 additions and 5 deletions

View File

@ -97,7 +97,7 @@
firewall = { firewall = {
enable = true; enable = true;
allowedUDPPorts = [ ]; allowedUDPPorts = [ ];
allowedTCPPorts = [ ]; allowedTCPPorts = [ 80 443 ];
}; };
}; };

View File

@ -20,9 +20,7 @@
"${config.services.hydra.hydraURL}" = { "${config.services.hydra.hydraURL}" = {
enableACME = true; enableACME = true;
forceSSL = true; forceSSL = true;
listen = [ { locations."/".proxyPass = "http://localhost:3000";
addr = "127.0.0.1"; port = 3000;
} ];
}; };
}; };
}; };
@ -30,7 +28,7 @@
security.acme = { security.acme = {
defaults.email = "webmaster@kabtop.de"; defaults.email = "webmaster@kabtop.de";
defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory"; #defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory";
acceptTerms = true; acceptTerms = true;
certs.${config.services.hydra.hydraURL} = { certs.${config.services.hydra.hydraURL} = {
dnsProvider = "netcup"; dnsProvider = "netcup";