1
Fork 0
mirror of https://github.com/thegeneralist01/config.git synced 2026-10-09 21:03:30 +02:00

nixos: migrate server services to thegeneralist

Move hosted services and secrets from the retired central hosts, persist USB storage and ownership, harden RTL8822BU Wi-Fi, repair DNS behavior, and order CoreDNS after Tailscale.
This commit is contained in:
TheGeneralist 2026-10-09 14:21:55 +02:00
parent 7f5ecd917b
commit bd887883f7
Signed by: thegeneralist01
SSH key fingerprint: SHA256:pp9qddbCNmVNoSjevdvQvM5z0DHN7LTa8qBMbcMq/R4
41 changed files with 183 additions and 511 deletions

View file

@ -1,52 +0,0 @@
{ config, pkgs, ... }:
{
imports = [
./acme
./dns.nix
./jellyfin
./plex
];
# Nginx
services.nginx = {
enable = true;
enableQuicBPF = true;
experimentalZstdSettings = true;
recommendedUwsgiSettings = true;
recommendedTlsSettings = true;
recommendedProxySettings = true;
recommendedOptimisation = true;
recommendedGzipSettings = true;
recommendedBrotliSettings = true;
statusPage = true;
validateConfigFile = true;
# Domain-specific virtual hosts live in the service modules below.
};
# Cloudflare
environment.systemPackages = [ pkgs.cloudflared ];
age.secrets.cftcert.file = ./cert.pem.age;
age.secrets.cftcredentials.file = ./credentials.age;
services.cloudflared = {
enable = true;
certificateFile = config.age.secrets.cftcert.path;
tunnels = {
"site" = {
ingress = {
"cache.thegeneralist01.com" = "http://localhost:80";
"git.thegeneralist01.com" = "http://localhost:3000";
};
default = "http_status:404";
credentialsFile = config.age.secrets.cftcredentials.path;
certificateFile = config.age.secrets.cftcert.path;
};
};
};
}