mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-07 20:47:14 +03:00
vhost connecting
This commit is contained in:
@@ -123,16 +123,16 @@ in
|
|||||||
forceSSL = true;
|
forceSSL = true;
|
||||||
enableACME = true;
|
enableACME = true;
|
||||||
};
|
};
|
||||||
# vtimeline.zeroq.su — stub behind HTTP basic auth.
|
# vtimeline.zeroq.su — static site behind HTTP basic auth.
|
||||||
# Credentials are pulled from sops (format = yaml, key = "passwords"),
|
# Files live under /home/oqyude/External/Git/VeeamTimelineView/public_html,
|
||||||
# file content is htpasswd-format (one "user:hash" per line).
|
# which is bind-mounted to /var/lib/vtimeline (see systemd.mounts below)
|
||||||
# Empty file = 401 for everyone until somebody populates the secret:
|
# because /home/oqyude is mode 700 and the nginx user (uid 60) cannot
|
||||||
# sops modules/server/secrets/vtimeline-htpasswd.yaml
|
# traverse it. Credentials are pulled from sops; see the sops.secrets
|
||||||
# htpasswd -nbB <login> <password> | sed 's/:$//'
|
# block at the bottom of this file.
|
||||||
"vtimeline.zeroq.su" = {
|
"vtimeline.zeroq.su" = {
|
||||||
forceSSL = true;
|
forceSSL = true;
|
||||||
enableACME = true;
|
enableACME = true;
|
||||||
root = pkgs.writeTextDir "index.html" "<!doctype html><html><body>Nothing here yet.</body></html>";
|
root = "/var/lib/vtimeline";
|
||||||
extraConfig = ''
|
extraConfig = ''
|
||||||
auth_basic "vtimeline";
|
auth_basic "vtimeline";
|
||||||
auth_basic_user_file ${config.sops.secrets.vtimeline-htpasswd.path};
|
auth_basic_user_file ${config.sops.secrets.vtimeline-htpasswd.path};
|
||||||
@@ -267,6 +267,20 @@ in
|
|||||||
443
|
443
|
||||||
];
|
];
|
||||||
|
|
||||||
|
# Bind-mount the vtimeline source tree into /var/lib so the nginx user
|
||||||
|
# (uid 60) doesn't have to traverse /home/oqyude (mode 700). The mount is
|
||||||
|
# lazy (x-systemd.automount) and nofail, so a missing /home/oqyude/External
|
||||||
|
# only shows up as a per-request 500/403, never as a hard boot failure.
|
||||||
|
systemd.mounts = [
|
||||||
|
(xlib.helpers.mkSystemdBind {
|
||||||
|
what = "/home/oqyude/External/Git/VeeamTimelineView/public_html";
|
||||||
|
where = "/var/lib/vtimeline";
|
||||||
|
})
|
||||||
|
];
|
||||||
|
systemd.tmpfiles.rules = [
|
||||||
|
(xlib.helpers.mkTmpfile "d" "/var/lib/vtimeline" "0755" "nginx" "nginx")
|
||||||
|
];
|
||||||
|
|
||||||
# htpasswd file for vtimeline.zeroq.su basic auth.
|
# htpasswd file for vtimeline.zeroq.su basic auth.
|
||||||
# Source layout (per modules/server/secrets/vtimeline-htpasswd.yaml):
|
# Source layout (per modules/server/secrets/vtimeline-htpasswd.yaml):
|
||||||
# passwords: |
|
# passwords: |
|
||||||
|
|||||||
Reference in New Issue
Block a user