1
Fork 0
mirror of https://github.com/thegeneralist01/config.git synced 2026-10-09 21:03:30 +02:00
config/hosts/thegeneralist/dns.nix
TheGeneralist bd887883f7
nixos: migrate server services to thegeneralist
Move hosted services and secrets from the retired central hosts, persist USB storage and ownership, harden RTL8822BU Wi-Fi, repair DNS behavior, and order CoreDNS after Tailscale.
2026-10-09 14:21:55 +02:00

53 lines
1.2 KiB
Nix

{ pkgs, lib, ... }:
let
subdomains = [ "internal" "archive" "plex" ];
mainZoneFile = pkgs.writeText "thegeneralist01.zone" ''
$ORIGIN thegeneralist01.com.
@ IN SOA ns.thegeneralist01.com. thegeneralist01.proton.me. (
2025081501 ; serial (yyyymmddXX)
3600 ; refresh
600 ; retry
86400 ; expire
3600 ; minimum
)
IN NS ns.thegeneralist01.com.
ns IN A 100.108.125.63
${lib.concatStringsSep "\n" (lib.map (sub: "${sub} IN A 100.108.125.63") subdomains)}
'';
forwarderBlock = ''
.:53 {
bind 100.108.125.63
forward . 100.100.100.100 45.90.28.181 45.90.30.181
cache
log
errors
}
'';
in
{
services.coredns = {
enable = true;
config = ''
thegeneralist01.com:53 {
bind 100.108.125.63
file ${mainZoneFile}
log
errors
}
${forwarderBlock}
'';
};
systemd.services.coredns = {
wants = [ "network-online.target" "tailscaled.service" ];
after = [ "network-online.target" "tailscaled.service" ];
serviceConfig = {
Restart = "on-failure";
RestartSec = "2s";
};
};
}