1
0
Fork 0
forked from emily/nixfiles
nixfiles-emily/config/hosts/web-dus/configuration.nix

112 lines
3.2 KiB
Nix
Raw Normal View History

{ config, inputs, lib, pkgs, ... }: {
2024-01-10 13:50:25 +01:00
imports = [
inputs.fernglas.nixosModules.default
2024-01-16 20:03:30 +01:00
inputs.kyouma-www.nixosModules.default
2024-01-17 14:34:33 +01:00
../../common
2024-02-05 22:22:40 +01:00
../../profiles/headless.nix
../../profiles/kartoffel.nix
../../profiles/lxc.nix
../../services/nginx.nix
2024-01-10 13:50:25 +01:00
];
2023-12-06 10:21:07 +01:00
networking = {
2024-01-12 15:11:33 +01:00
hostName = "web-dus";
nftables.enable = lib.mkForce false;
2024-04-04 14:42:48 +02:00
firewall.allowedTCPPorts = [ 80 443 11019 ];
2024-01-09 16:23:24 +01:00
firewall.allowedUDPPorts = [ 443 ];
2023-12-06 10:21:07 +01:00
};
systemd.network.networks."98-eth-default" = {
address = [
"2a0f:be01:0:100::1312/128"
];
};
2024-01-16 20:03:30 +01:00
services.vyosBld = {
enable = true;
2024-01-17 15:49:17 +01:00
output = "/var/www/kyouma.net/vyos";
2024-01-16 20:03:30 +01:00
buildFlags = {
architecture = "amd64";
build-by = "noc@kyouma.net";
build-type = "release";
version = "1.5-$(date %Y%m%d)";
};
};
2024-01-09 17:02:32 +01:00
services.fernglas = {
enable = true;
2023-12-06 10:21:07 +01:00
settings = {
2024-01-09 17:02:32 +01:00
api.bind = "[::1]:3000";
collectors = {
bmp_collector = {
collector_type = "Bmp";
2024-04-04 14:42:48 +02:00
bind = "[::]:11019";
2024-01-09 17:02:32 +01:00
peers = {
"45.150.123.0" = {};
};
};
};
2023-12-06 10:21:07 +01:00
};
};
2024-04-04 14:42:48 +02:00
kyouma.nginx.virtualHosts = let
kyouma-www = inputs.kyouma-www.packages.${config.nixpkgs.hostPlatform.system};
autoIndex = ''
autoindex on;
autoindex_exact_size off;
autoindex_format html;
autoindex_localtime on;
'';
in {
"miau.zip" = { root = kyouma-www.default; };
"www.miau.zip" = { redirectTo = "miau.zip"; };
"www.kyouma.net" = { redirectTo = "kyouma.net"; };
"emily.cat" = { root = "/var/www/emily.cat/_site"; };
"www.emily.cat" = { redirectTo = "kyouma.net"; };
"www.cocaine.trade" = { redirectTo = "cocaine.trade"; };
2023-12-06 10:21:07 +01:00
2024-04-04 14:42:48 +02:00
"redirect" = {
default = true;
reuseport = true;
useACMEHost = "kyouma.net";
extraConfig = ''
return 403;
'';
};
"cocaine.trade" = {
root = "/var/www/basti/cocaine.trade";
extraConfig = ''error_page 404 /404.html;'';
locations."/" = {
index = "index.html";
tryFiles = "$uri $uri.html =404";
2023-12-06 10:21:07 +01:00
};
2024-04-04 14:42:48 +02:00
locations."= /".extraConfig = ''rewrite ^ /index.html last;'';
};
"files.cocaine.trade" = {
useACMEHost = "cocaine.trade";
root = "/var/www/basti/files.cocaine.trade";
locations."/".extraConfig = autoIndex;
};
"kyouma.net" = {
root = kyouma-www.default;
locations = {
"/assets/media/".root = kyouma-www.vid;
"/vyos/" = {
root = config.services.vyosBld.output;
extraConfig = autoIndex;
2023-12-06 10:21:07 +01:00
};
2024-04-04 14:42:48 +02:00
"/ihk/" = {
root = "/var/www/kyouma.net/ihk";
extraConfig = autoIndex;
2024-01-09 15:46:18 +01:00
};
2023-12-06 10:21:07 +01:00
};
2024-04-04 14:42:48 +02:00
};
"lg.kyouma.net" = {
useACMEHost = "kyouma.net";
locations."/".root = inputs.fernglas.packages.${config.nixpkgs.hostPlatform.system}.fernglas-frontend;
locations."/api/".proxyPass = "http://${config.services.fernglas.settings.api.bind}";
2023-12-06 10:21:07 +01:00
};
};
2024-01-10 13:30:05 +01:00
security.acme.certs = {
"miau.zip" = { extraDomainNames = [ "www.miau.zip" "lg.miau.zip" ]; };
"kyouma.net" = { extraDomainNames = [ "www.kyouma.net" "lg.kyouma.net" ]; };
"emily.cat" = { extraDomainNames = [ "www.emily.cat" ]; };
"cocaine.trade" = { extraDomainNames = [ "www.cocaine.trade" "files.cocaine.trade" ]; };
2023-12-06 10:21:07 +01:00
};
}