vhost connecting

This commit is contained in:
2026-10-07 17:53:06 +03:00
parent 7fd1736f1d
commit 75433e2af7
+21 -7
View File
@@ -123,16 +123,16 @@ in
forceSSL = true; forceSSL = true;
enableACME = true; enableACME = true;
}; };
# vtimeline.zeroq.su — stub behind HTTP basic auth. # vtimeline.zeroq.su — static site behind HTTP basic auth.
# Credentials are pulled from sops (format = yaml, key = "passwords"), # Files live under /home/oqyude/External/Git/VeeamTimelineView/public_html,
# file content is htpasswd-format (one "user:hash" per line). # which is bind-mounted to /var/lib/vtimeline (see systemd.mounts below)
# Empty file = 401 for everyone until somebody populates the secret: # because /home/oqyude is mode 700 and the nginx user (uid 60) cannot
# sops modules/server/secrets/vtimeline-htpasswd.yaml # traverse it. Credentials are pulled from sops; see the sops.secrets
# htpasswd -nbB <login> <password> | sed 's/:$//' # block at the bottom of this file.
"vtimeline.zeroq.su" = { "vtimeline.zeroq.su" = {
forceSSL = true; forceSSL = true;
enableACME = true; enableACME = true;
root = pkgs.writeTextDir "index.html" "<!doctype html><html><body>Nothing here yet.</body></html>"; root = "/var/lib/vtimeline";
extraConfig = '' extraConfig = ''
auth_basic "vtimeline"; auth_basic "vtimeline";
auth_basic_user_file ${config.sops.secrets.vtimeline-htpasswd.path}; auth_basic_user_file ${config.sops.secrets.vtimeline-htpasswd.path};
@@ -267,6 +267,20 @@ in
443 443
]; ];
# Bind-mount the vtimeline source tree into /var/lib so the nginx user
# (uid 60) doesn't have to traverse /home/oqyude (mode 700). The mount is
# lazy (x-systemd.automount) and nofail, so a missing /home/oqyude/External
# only shows up as a per-request 500/403, never as a hard boot failure.
systemd.mounts = [
(xlib.helpers.mkSystemdBind {
what = "/home/oqyude/External/Git/VeeamTimelineView/public_html";
where = "/var/lib/vtimeline";
})
];
systemd.tmpfiles.rules = [
(xlib.helpers.mkTmpfile "d" "/var/lib/vtimeline" "0755" "nginx" "nginx")
];
# htpasswd file for vtimeline.zeroq.su basic auth. # htpasswd file for vtimeline.zeroq.su basic auth.
# Source layout (per modules/server/secrets/vtimeline-htpasswd.yaml): # Source layout (per modules/server/secrets/vtimeline-htpasswd.yaml):
# passwords: | # passwords: |