configuring nginx service and acme certs

This commit is contained in:
2025-04-24 22:53:32 -05:00
parent 46d30ca4c0
commit 5296108270
2 changed files with 40 additions and 32 deletions
+36 -29
View File
@@ -1,5 +1,16 @@
{ config, lib, pkgs, meta, ... }:
let
testSiteIndex = pkgs.writeText "index.html" ''
<html>
<head><title>Hello</title></head>
<body>
<h1>Hello from test.roypository.com 🎉</h1>
<p>This content is defined in configuration.nix</p>
</body>
</html>
'';
in
{
imports = [ ];
@@ -15,8 +26,14 @@
"clusterPassword" = {
sopsFile = ./secrets/build.json;
};
"cloudflare-credentials" = {
"cloudflare-api-email" = {
sopsFile = ./secrets/cloudflare.json;
key = "CF_API_EMAIL";
};
"cloudflare-api-key" = {
sopsFile = ./secrets/cloudflare.json;
key = "CF_API_KEY";
};
};
};
@@ -33,42 +50,32 @@
defaults = {
email = "roydumblauskas@gmail.com";
dnsProvider = "cloudflare";
environmentFile = config.sops.secrets."cloudflare-credentials".path;
credentialFiles = {
CF_API_EMAIL = config.sops.secrets."cloudflare-api-email".path;
CF_API_KEY = config.sops.secrets."cloudflare-api-key".path;
};
};
};
services.nginx.enable = true;
services.nginx.virtualHosts."roypository.com" = {
forceSSL = true;
addSSL = true;
enableACME = true;
acmeRoot = null;
};
services.nginx = {
enable = true;
virtualHosts = {
"roypository.com" = {
forceSSL = true;
enableACME = true;
acmeRoot = false;
addSSL = true;
};
"*.roypository.com" = {
forceSSL = true;
enableACME = true;
acmeRoot = false;
addSSL = true;
};
};
};
services.nginx.virtualHosts."test.roypository.com" = {
forceSSL = true;
enableACME = true;
addSSL = true;
acmeRoot = false;
enableACME = true;
acmeRoot = null;
root = "${testSiteIndex}";
locations."/" = {
proxyPass = "http://localhost:3000";
proxyWebsockets = true; # optional: if using websockets
extraConfig = ''
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
index index.html;
'';
};
};
+4 -3
View File
@@ -1,5 +1,6 @@
{
"cloudflare-credentials": "ENC[AES256_GCM,data:GYmJx8Xzb5uMZ8UBpO8bsxH6N9FZQ0GpUM8gsJXp7Mtwioa/taWspwfxUxVqCVB1OuwQpMzMVuTPyAs4bS48nDEZ9YSwuyNU3UJ8zAUG1LzlXC6nSTA=,iv:ob7tqttc7ZcwXApBbuh5ahoDD9AUyEJK4+Bp6SR6Lvo=,tag:ZpFBcuR7MqW9fyFn7tBWNA==,type:str]",
"CF_API_EMAIL": "ENC[AES256_GCM,data:XVxqdkc0tYBSLdxDU1iOxXCwSypUzSY7,iv:jJ7woEszp4g6+qmrDR0o+sgylRRe802ym3LT+ye6iCU=,tag:78NWQ6f9EVDl/ueZUmMgHQ==,type:str]",
"CF_API_KEY": "ENC[AES256_GCM,data:L6AqCuYc10H5ErVkNjmpOj/SO5vExRDNSVqhTSK1iaYF1x78lQ==,iv:7xcuFcz/aOcTE8F7q7KWRuQUl0KO2lVKDc1SNReBPz4=,tag:TXW9C7fxpzEjtky2yJh4XA==,type:str]",
"sops": {
"kms": null,
"gcp_kms": null,
@@ -11,8 +12,8 @@
"enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBiSVlXekdnZW02SlpUN0Zq\nS3hzVGtGdkRQRUMrNExqVEFaQnJrVVRNOXhVClJYT2dNVTFuSE9SYnlnSEJmdkUw\nS21pYmRSaFRIVlp5clVST3VTY0YyS1kKLS0tIE9Hd09QWk0xYzBuSzBnU3gzSmFZ\nWUo3T0EyeXUzVjA2SFNFR1QzeW84OUEKObVZ9D7NZPwRXj7OA7EAJtmarT76TnSb\n/SsZ6vU3hQ9Vcn5EIZ39+MpdFluyxZkoq+0di52BHkgExrUD8VD0Lg==\n-----END AGE ENCRYPTED FILE-----\n"
}
],
"lastmodified": "2025-04-23T20:03:05Z",
"mac": "ENC[AES256_GCM,data:sPoetiHt7L/7GM8DezYal7Vfgz0/pN5Q2zBOABZwFyI7eRPwP9tSdklr4Bflofc7VEabZlH2sF81z3C8TdBZ5VJ2IpjZrTXd4B/U7CmbL+9FPiCoUqSB9xq0OtchsnrVLQCry16+3x8O4CXap2fH8AFgmUiGkTtgRVqkc7UsoeE=,iv:zz/7UGQYhVfHfR/tu6Uu6nUWojc8pCdBC8qHd4N/tTk=,tag:37whEAueDHeiYcvncEZTBw==,type:str]",
"lastmodified": "2025-04-25T02:22:32Z",
"mac": "ENC[AES256_GCM,data:70lznJLy9WJ2CBVyx1YO2dl7Npr853960NzC8s306+eZsykpi1CjgfhQGnR6esd7aSOcSmglQ87zqcwAI87AjmYQero83ynunD7HrsD3IxehOuLB+vsv9sPQypPP+OCb2JoJKL9F8IQwFRDq8G0lwDcasXld5i1UfFZTMSWunrA=,iv:rsHaMJbnNphOkDXDaowYR6IzKrJAkB4X5DLvnD+JWhk=,tag:Kkv0lYgMlM8P4nybKbAnWg==,type:str]",
"pgp": null,
"unencrypted_suffix": "_unencrypted",
"version": "3.9.4"