nix-configs

Personal NixOS and home-manager configuration files
Log | Files | Refs

commit ee17ea290a03842fe090f9dd9b822ab3d5421494
parent 9fcce501845aa10c34d19472582c2b231d5bc41f
Author: breadcat <breadcat@users.noreply.github.com>
Date:   Fri, 31 Jul 2026 15:29:11 +0100

Use CF DNS challenges for valid internal SSL

Diffstat:
Mcommon/caddy-ilias.nix | 26+++++++++++++++-----------
1 file changed, 15 insertions(+), 11 deletions(-)

diff --git a/common/caddy-ilias.nix b/common/caddy-ilias.nix @@ -1,8 +1,8 @@ -{ config, lib, pkgs, ... }: +{ config, lib, pkgs, vars, ... }: -# OpenWRT setup for custom LAN domain names: -# uci add_list dhcp.@dnsmasq[0].rebind_domain='lan' -# uci add_list dhcp.@dnsmasq[0].address='/example.lan/192.168.1.3' +# OpenWRT setup for custom *.home. domain names: +# uci add_list dhcp.@dnsmasq[0].rebind_domain='home.minskio.co.uk' +# uci add_list dhcp.@dnsmasq[0].address='/home.minskio.co.uk/192.168.1.3' # uci commit dhcp # service dnsmasq restart @@ -15,9 +15,12 @@ let }; mkVirtualHost = name: svc: { - name = "http://${name}.lan"; + name = "${name}.home.${vars.user.domain}"; value = { extraConfig = '' + tls { + dns cloudflare ${vars.secrets.cloudflare} + } reverse_proxy ${svc.host}:${toString svc.port} ''; }; @@ -26,14 +29,15 @@ in { services.caddy = { enable = true; + package = pkgs.caddy.withPlugins { + plugins = [ "github.com/caddy-dns/cloudflare@v0.2.4" ]; + hash = "sha256-7GoH8YLCoPmPExQxoga2FHB58zQDoZVf1BBwkVi0SsQ="; + }; virtualHosts = (lib.mapAttrs' mkVirtualHost services) // { - "http://192.168.1.3" = { - extraConfig = '' - reverse_proxy 127.0.0.1:8080 - ''; - }; + # Handle http://192.168.1.3:80/ fallback to Stromboli + "http://192.168.1.3" = { extraConfig = "reverse_proxy 127.0.0.1:8080"; }; }; }; - networking.firewall.allowedTCPPorts = [ 80 ]; + networking.firewall.allowedTCPPorts = [ 80 443 ]; } \ No newline at end of file