diff options
| author | tv <tv@krebsco.de> | 2023-08-01 12:14:30 +0200 |
|---|---|---|
| committer | tv <tv@krebsco.de> | 2023-08-01 12:14:30 +0200 |
| commit | 7be9bfdc55d672de39dce98dae9c6d112404dfc6 (patch) | |
| tree | e89a93ad96e6f35490ffbf6b6a337ca4dcc9a170 /makefu/2configs/dnscrypt/server.nix | |
| parent | 5d1b0675cf179f863a5b34b67661a953197b6057 (diff) | |
| parent | 6e63efa3645353bc0549f5f152ef811fff5d644c (diff) | |
Merge remote-tracking branch 'orange/master'
Diffstat (limited to 'makefu/2configs/dnscrypt/server.nix')
| -rw-r--r-- | makefu/2configs/dnscrypt/server.nix | 26 |
1 files changed, 0 insertions, 26 deletions
diff --git a/makefu/2configs/dnscrypt/server.nix b/makefu/2configs/dnscrypt/server.nix deleted file mode 100644 index 79305e727..000000000 --- a/makefu/2configs/dnscrypt/server.nix +++ /dev/null @@ -1,26 +0,0 @@ -{ config, ... }: -let - # TODO: dataDir is currently not provided by upstream - # data = config.services.dnscrypt-wrapper.dataDir; - data = "/var/lib/dnscrypt-wrapper"; - sec = toString <secrets>; - port = 15251; - user = "dnscrypt-wrapper"; -in { - services.dnscrypt-wrapper = { - enable = true; - address = "0.0.0.0"; - upstream.address = "8.8.8.8"; - providerName = "2.dnscrypt-cert.euer.krebsco.de"; - inherit port; - }; - networking.firewall.allowedUDPPorts = [ port ]; - systemd.services.prepare-dnscrypt-wrapper-keys = { - wantedBy = [ "dnscrypt-wrapper.service" ]; - before = [ "dnscrypt-wrapper.service" ]; - script = '' - install -m700 -o ${user} -v ${sec}/dnscrypt-public.key ${data}/public.key - install -m700 -o ${user} -v ${sec}/dnscrypt-secret.key ${data}/secret.key - ''; - }; -} |
