mirror of
https://github.com/thegeneralist01/config.git
synced 2026-10-09 21:03:30 +02:00
nixos: migrate server services to thegeneralist
Move hosted services and secrets from the retired central hosts, persist USB storage and ownership, harden RTL8822BU Wi-Fi, repair DNS behavior, and order CoreDNS after Tailscale.
This commit is contained in:
parent
7f5ecd917b
commit
bd887883f7
41 changed files with 183 additions and 511 deletions
|
|
@ -1,52 +0,0 @@
|
|||
{ config, pkgs, ... }:
|
||||
{
|
||||
imports = [
|
||||
./acme
|
||||
./dns.nix
|
||||
./jellyfin
|
||||
./plex
|
||||
];
|
||||
|
||||
# Nginx
|
||||
services.nginx = {
|
||||
enable = true;
|
||||
enableQuicBPF = true;
|
||||
|
||||
experimentalZstdSettings = true;
|
||||
recommendedUwsgiSettings = true;
|
||||
recommendedTlsSettings = true;
|
||||
recommendedProxySettings = true;
|
||||
recommendedOptimisation = true;
|
||||
recommendedGzipSettings = true;
|
||||
recommendedBrotliSettings = true;
|
||||
|
||||
statusPage = true;
|
||||
validateConfigFile = true;
|
||||
|
||||
# Domain-specific virtual hosts live in the service modules below.
|
||||
};
|
||||
|
||||
# Cloudflare
|
||||
environment.systemPackages = [ pkgs.cloudflared ];
|
||||
|
||||
age.secrets.cftcert.file = ./cert.pem.age;
|
||||
age.secrets.cftcredentials.file = ./credentials.age;
|
||||
|
||||
services.cloudflared = {
|
||||
enable = true;
|
||||
certificateFile = config.age.secrets.cftcert.path;
|
||||
|
||||
tunnels = {
|
||||
"site" = {
|
||||
ingress = {
|
||||
"cache.thegeneralist01.com" = "http://localhost:80";
|
||||
"git.thegeneralist01.com" = "http://localhost:3000";
|
||||
};
|
||||
default = "http_status:404";
|
||||
|
||||
credentialsFile = config.age.secrets.cftcredentials.path;
|
||||
certificateFile = config.age.secrets.cftcert.path;
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue