diff options
author | tv <tv@krebsco.de> | 2023-09-11 18:24:28 +0200 |
---|---|---|
committer | tv <tv@krebsco.de> | 2023-09-13 18:07:11 +0200 |
commit | 0c4f3acb281be6290c55a6e96bc29fab5b5c7a11 (patch) | |
tree | dadaec00477a095273475ac345b2066b4748c399 /configs/nginx | |
parent | ab1d0479e90f11806d4703ec6fffed3d5f782914 (diff) |
stockholm -> hrm
Diffstat (limited to 'configs/nginx')
-rw-r--r-- | configs/nginx/default.nix | 21 | ||||
-rw-r--r-- | configs/nginx/public_html.nix | 17 |
2 files changed, 38 insertions, 0 deletions
diff --git a/configs/nginx/default.nix b/configs/nginx/default.nix new file mode 100644 index 0000000..e288c52 --- /dev/null +++ b/configs/nginx/default.nix @@ -0,0 +1,21 @@ +{ config, ... }: { + services.nginx = { + enableReload = true; + + recommendedGzipSettings = true; + recommendedOptimisation = true; + recommendedTlsSettings = true; + + virtualHosts.${builtins.toJSON ""} = { + default = true; + extraConfig = '' + error_page 400 =444 /; + return 444; + ''; + rejectSSL = true; + }; + }; + tv.iptables = { + input-retiolum-accept-tcp = [ "http" ]; + }; +} diff --git a/configs/nginx/public_html.nix b/configs/nginx/public_html.nix new file mode 100644 index 0000000..cd8e3c4 --- /dev/null +++ b/configs/nginx/public_html.nix @@ -0,0 +1,17 @@ +{ config, ... }: { + services.nginx = { + enable = true; + virtualHosts.default = { + serverAliases = [ + "localhost" + "${config.krebs.build.host.name}" + "${config.krebs.build.host.name}.hkw" + "${config.krebs.build.host.name}.r" + ]; + locations."~ ^/~([a-z]+)(?:/(.*))?\$" = { + alias = "/srv/$1/public_html/$2"; + }; + }; + }; + tv.iptables.input-internet-accept-tcp = [ "http" ]; +} |