From cedc856a02ac1b2f08765a0f78feb9fd39b5e122 Mon Sep 17 00:00:00 2001 From: oqyude Date: Sat, 8 Aug 2026 17:49:50 +0300 Subject: [PATCH] server preparing migration --- configurations/hardware/server.nix | 1 + configurations/server.nix | 8 +- modules/essentials/settings.nix | 4 +- modules/server/acme.nix | 22 +- modules/server/coredns.nix | 2 +- modules/server/default.nix | 2 +- modules/server/gitea.nix | 2 +- modules/server/nextcloud.nix | 22 +- modules/server/nginx.nix | 406 +++++++++++++++++++++-------- modules/server/onlyoffice.nix | 2 +- modules/server/samba.nix | 2 +- modules/vds/nginx.nix | 220 ---------------- 12 files changed, 328 insertions(+), 365 deletions(-) diff --git a/configurations/hardware/server.nix b/configurations/hardware/server.nix index 4823fcf..b96cb27 100644 --- a/configurations/hardware/server.nix +++ b/configurations/hardware/server.nix @@ -28,6 +28,7 @@ kernel = { sysctl = { "fs.inotify.max_user_watches" = "204800"; + "net.ipv4.ip_forward" = 1; }; }; kernelModules = [ diff --git a/configurations/server.nix b/configurations/server.nix index 9ebb300..96f1fda 100644 --- a/configurations/server.nix +++ b/configurations/server.nix @@ -110,10 +110,10 @@ let hostName = "${xlib.device.hostname}"; networkmanager.enable = true; firewall.enable = false; - nameservers = [ - "127.0.0.1" - "192.168.1.1" - ]; + # nameservers = [ + # "192.168.1.1" + # "127.0.0.1" + # ]; }; system = { diff --git a/modules/essentials/settings.nix b/modules/essentials/settings.nix index 3a1b406..2e63e6d 100644 --- a/modules/essentials/settings.nix +++ b/modules/essentials/settings.nix @@ -15,7 +15,7 @@ settings = { require-sigs = false; substituters = [ - "http://100.64.0.0:5000" + "https://nix-cache.zeroq.su" "https://cache.nixos.org" "https://nix-community.cachix.org" "https://mirror.yandex.ru/nixos" @@ -27,7 +27,7 @@ # "https://nixos.snix.store" # https://nixos.snix.store/ ]; trusted-public-keys = [ - "nix-cache.home.arpa:be5jFLkiwNyOep/McxSafB3jguBmztxx+oJ46ySyc/s=" + "nix-cache.zeroq.su:be5jFLkiwNyOep/McxSafB3jguBmztxx+oJ46ySyc/s=" "nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs=" ]; stalled-download-timeout = 8; diff --git a/modules/server/acme.nix b/modules/server/acme.nix index 8caea58..2b9a982 100644 --- a/modules/server/acme.nix +++ b/modules/server/acme.nix @@ -8,20 +8,20 @@ acme = { acceptTerms = true; defaults = { - email = "oqyude@zeroq.su"; - server = "https://localhost:9000/acme/acme/directory"; - dnsProvider = null; + email = "oqyude@gmail.com"; }; # certs = { - # # "home.arpa" = { - # # domain = "*.home.arpa"; - # # server = "https://localhost:9000/acme/acme/directory"; - # # listenHTTP = ":80"; + # "home.arpa" = { + # email = "oqyude@zeroq.su"; + # domain = "*.home.arpa"; + # server = "https://localhost:9000/acme/acme/directory"; + # listenHTTP = ":80"; + # dnsProvider = null; + # }; + # # "turn.home.arpa" = { + # # listenHTTP = "127.0.0.1:80"; + # # group = "turnserver"; # # }; - # "turn.home.arpa" = { - # listenHTTP = "127.0.0.1:80"; - # group = "turnserver"; - # }; # }; }; }; diff --git a/modules/server/coredns.nix b/modules/server/coredns.nix index d87f783..b1cd65d 100644 --- a/modules/server/coredns.nix +++ b/modules/server/coredns.nix @@ -15,7 +15,7 @@ 192.168.1.20 flux.zeroq.su 192.168.1.20 git.zeroq.su 192.168.1.20 glances.zeroq.su - 192.168.1.20 homebox.home.arpa + 192.168.1.20 homebox.zeroq.su 192.168.1.20 immich.zeroq.su 192.168.1.20 kuma.zeroq.su 192.168.1.20 navidrome.zeroq.su diff --git a/modules/server/default.nix b/modules/server/default.nix index 8fac5ce..b1c9450 100644 --- a/modules/server/default.nix +++ b/modules/server/default.nix @@ -23,7 +23,7 @@ ./postgresql.nix ./power.nix ./samba.nix - ./step-ca.nix + # ./step-ca.nix ./syncthing.nix ./systemd.nix # ../containers/remnawave.nix diff --git a/modules/server/gitea.nix b/modules/server/gitea.nix index 2ea1ce4..6ec7a48 100644 --- a/modules/server/gitea.nix +++ b/modules/server/gitea.nix @@ -14,7 +14,7 @@ appName = "ZeroQ Gitea Service"; settings = { server = { - DOMAIN = "git.home.arpa"; + DOMAIN = "git.zeroq.su"; HTTP_PORT = 3000; }; service.DISABLE_REGISTRATION = true; diff --git a/modules/server/nextcloud.nix b/modules/server/nextcloud.nix index 676b591..3d4a392 100644 --- a/modules/server/nextcloud.nix +++ b/modules/server/nextcloud.nix @@ -11,7 +11,7 @@ nextcloud-whiteboard-server = { enable = true; settings = { - NEXTCLOUD_URL = "https://nextcloud.home.arpa"; + NEXTCLOUD_URL = "https://nextcloud.zeroq.su"; }; secrets = [ config.sops.secrets.nextcloud-whiteboard-jwt.path ]; }; @@ -20,8 +20,8 @@ hostName = "talk.private"; backends.nextcloud = { urls = [ - "https://nextcloud.home.arpa" "https://nextcloud.zeroq.su" + # "https://nextcloud.home.arpa" ]; secretFile = config.sops.secrets.nextcloud-talk-secret.path; }; @@ -40,9 +40,9 @@ secretFile = config.sops.secrets.turn-secret.path; apikeyFile = config.sops.secrets.turn-api-key.path; servers = [ - "turn:turn.home.arpa:3478?transport=udp" - "turn:turn.home.arpa:3478?transport=tcp" - # "turns:turn.home.arpa:5349?transport=tcp" + "turn:turn.zeroq.su:3478?transport=udp" + "turn:turn.zeroq.su:3478?transport=tcp" + # "turns:turn.zeroq.su:5349?transport=tcp" ]; }; }; @@ -72,26 +72,28 @@ trusted_domains = [ "100.64.0.0" "192.168.1.20" + "37.128.246.126" "localhost" + "nextcloud.home.arpa" "nextcloud.private" "nextcloud.zeroq.su" - "office.zeroq.su" "office.home.arpa" - "nextcloud.home.arpa" + "office.zeroq.su" ]; trusted_proxies = [ "100.64.1.0" - "192.168.1.20" "109.248.161.5" + "192.168.1.20" + "37.128.246.126" ]; overwriteprotocol = "https"; # maybe no }; extraAppsEnable = true; appstoreEnable = false; notify_push = { - enable = false; + enable = true; bendDomainToLocalhost = true; - nextcloudUrl = "https://nextcloud.home.arpa"; + nextcloudUrl = "https://nextcloud.zeroq.su"; }; # phpPackage = pkgs.php85; extraApps = { diff --git a/modules/server/nginx.nix b/modules/server/nginx.nix index d2f0777..0e94667 100644 --- a/modules/server/nginx.nix +++ b/modules/server/nginx.nix @@ -35,7 +35,7 @@ in } ]; }; - "office.home.arpa" = { + "office.zeroq.su" = { forceSSL = true; enableACME = true; }; @@ -64,46 +64,46 @@ in client_max_body_size 5G; ''; }; - "pdf.home.arpa" = { - forceSSL = true; - enableACME = true; - locations = { - "/" = { - proxyPass = "http://127.0.0.1:8446"; - proxyWebsockets = true; - }; - }; - extraConfig = '' - client_max_body_size 5G; - ''; - }; - "homebox.home.arpa" = { - forceSSL = true; - enableACME = true; - locations = { - "/" = { - proxyPass = "http://127.0.0.1:7745"; - proxyWebsockets = true; - }; - }; - }; - "nextcloud.home.arpa" = { - forceSSL = true; - enableACME = true; - locations = { - "/" = { - proxyPass = "http://127.0.0.1:10000"; - proxyWebsockets = true; - }; - "/whiteboard" = { - proxyPass = "http://127.0.0.1:3002"; - proxyWebsockets = true; - }; - }; - extraConfig = '' - client_max_body_size 5G; - ''; - }; + # "pdf.home.arpa" = { + # forceSSL = true; + # enableACME = true; + # locations = { + # "/" = { + # proxyPass = "http://127.0.0.1:8446"; + # proxyWebsockets = true; + # }; + # }; + # extraConfig = '' + # client_max_body_size 5G; + # ''; + # }; + # "homebox.home.arpa" = { + # forceSSL = true; + # enableACME = true; + # locations = { + # "/" = { + # proxyPass = "http://127.0.0.1:7745"; + # proxyWebsockets = true; + # }; + # }; + # }; + # "nextcloud.home.arpa" = { + # forceSSL = true; + # enableACME = true; + # locations = { + # "/" = { + # proxyPass = "http://127.0.0.1:10000"; + # proxyWebsockets = true; + # }; + # "/whiteboard" = { + # proxyPass = "http://127.0.0.1:3002"; + # proxyWebsockets = true; + # }; + # }; + # extraConfig = '' + # client_max_body_size 5G; + # ''; + # }; # "talk.home.arpa" = { # forceSSL = true; # enableACME = true; @@ -130,39 +130,28 @@ in # client_max_body_size 5G; # ''; # }; - "ca.home.arpa" = { - forceSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://127.0.0.1:9000"; - proxyWebsockets = true; - }; - extraConfig = '' - client_max_body_size 5G; - ''; - }; - "git.home.arpa" = { - forceSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://127.0.0.1:3000"; - proxyWebsockets = true; - }; - extraConfig = '' - client_max_body_size 5G; - ''; - }; - "git.zeroq.su" = { - forceSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://127.0.0.1:3000"; - proxyWebsockets = true; - }; - extraConfig = '' - client_max_body_size 5G; - ''; - }; + # "ca.zeroq.su" = { + # forceSSL = true; + # enableACME = true; + # locations."/" = { + # proxyPass = "http://127.0.0.1:9000"; + # proxyWebsockets = true; + # }; + # extraConfig = '' + # client_max_body_size 5G; + # ''; + # }; + # "git.home.arpa" = { + # forceSSL = true; + # enableACME = true; + # locations."/" = { + # proxyPass = "http://127.0.0.1:3000"; + # proxyWebsockets = true; + # }; + # extraConfig = '' + # client_max_body_size 5G; + # ''; + # }; # "n8n.home.arpa" = { # forceSSL = true; # enableACME = true; @@ -174,76 +163,263 @@ in # client_max_body_size 5G; # ''; # }; - "kuma.home.arpa" = { - forceSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://127.0.0.1:4001"; - proxyWebsockets = true; - }; - }; - "flux.home.arpa" = { + # "kuma.home.arpa" = { + # forceSSL = true; + # enableACME = true; + # locations."/" = { + # proxyPass = "http://127.0.0.1:4001"; + # proxyWebsockets = true; + # }; + # }; + # "flux.home.arpa" = { + # addSSL = true; + # enableACME = true; + # locations."/" = { + # proxyPass = "http://127.0.0.1:6061"; + # proxyWebsockets = true; + # }; + # }; + # "navidrome.home.arpa" = { + # addSSL = true; + # enableACME = true; + # locations."/" = { + # proxyPass = "http://127.0.0.1:4533"; + # proxyWebsockets = true; + # }; + # }; + # "immich.home.arpa" = { + # addSSL = true; + # enableACME = true; + # locations."/" = { + # proxyPass = "http://127.0.0.1:2283"; + # proxyWebsockets = true; + # }; + # extraConfig = '' + # client_max_body_size 5G; + # ''; + # }; + "immich.zeroq.su" = { addSSL = true; enableACME = true; locations."/" = { - proxyPass = "http://127.0.0.1:6061"; - proxyWebsockets = true; - }; - }; - "navidrome.home.arpa" = { - addSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://127.0.0.1:4533"; - proxyWebsockets = true; - }; - }; - "immich.home.arpa" = { - addSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://127.0.0.1:2283"; + proxyPass = "http://${server}:2283"; proxyWebsockets = true; }; extraConfig = '' client_max_body_size 5G; ''; }; - "calibre.home.arpa" = { + "kuma.zeroq.su" = { forceSSL = true; enableACME = true; locations."/" = { - proxyPass = "http://127.0.0.1:8083"; + proxyPass = "http://${server}:4001"; + proxyWebsockets = true; + }; + }; + "health.zeroq.su" = { + forceSSL = true; + enableACME = true; + locations."/" = { + proxyPass = "http://${server}:19999"; + proxyWebsockets = true; + }; + }; + "git.zeroq.su" = { + forceSSL = true; + enableACME = true; + locations."/" = { + proxyPass = "http://${server}:3000"; + proxyWebsockets = true; + }; + }; + "homebox.zeroq.su" = { + forceSSL = true; + enableACME = true; + locations."/" = { + proxyPass = "http://${server}:7745"; + proxyWebsockets = true; + }; + }; + # "agent.zeroq.su" = { + # forceSSL = true; + # enableACME = true; + # locations."/" = { + # proxyPass = "http://${server}:3000"; + # proxyWebsockets = true; + # }; + # }; + # "node-red.zeroq.su" = { + # forceSSL = true; + # enableACME = true; + # kTLS = true; + # locations."/" = { + # proxyPass = "http://${server}:1880"; + # proxyWebsockets = true; + # }; + # extraConfig = '' + # client_max_body_size 5G; + # ''; + # }; + "zeroq.su" = { + forceSSL = true; + enableACME = true; + root = pkgs.writeTextDir "index.html" '' + + + +
What are you doing here?
+ + + ''; + locations = { + "/guest/" = { + proxyPass = "http://${server}:80"; + proxyWebsockets = true; + }; + # "/.well-known/discord" = { + # extraConfig = '' + # default_type text/plain; + # return 200 "dh=c2d103553a4cfdaa1b7952a87a7d8120a1e167cc"; + # ''; + # }; + }; + }; + "flux.zeroq.su" = { + forceSSL = true; + enableACME = true; + locations."/" = { + proxyPass = "http://${server}:6061"; + proxyWebsockets = true; + }; + }; + "navidrome.zeroq.su" = { + addSSL = true; + enableACME = true; + locations."/" = { + proxyPass = "http://${server}:4533"; + proxyWebsockets = true; + }; + }; + "vetymae.opencodes.zeroq.su" = { + forceSSL = true; + enableACME = true; + locations."/" = { + proxyPass = "http://100.86.62.4:4096"; + proxyWebsockets = true; + }; + }; + "lamet.opencodes.zeroq.su" = { + forceSSL = true; + enableACME = true; + locations."/" = { + proxyPass = "http://100.106.21.39:6061"; + proxyWebsockets = true; + }; + }; + "n8n.zeroq.su" = { + forceSSL = true; + enableACME = true; + locations."/" = { + proxyPass = "http://${server}:5678"; + proxyWebsockets = true; + }; + }; + # "office.zeroq.su" = { + # enableACME = true; + # forceSSL = true; + # locations = { + # "/" = { + # proxyPass = "http://${server}:8090"; + # proxyWebsockets = true; + # }; + # }; + # }; + "nextcloud.zeroq.su" = { + forceSSL = true; + enableACME = true; + locations = { + "/" = { + proxyPass = "http://${server}:10000"; + proxyWebsockets = true; + }; + "/whiteboard" = { + proxyPass = "http://${server}:3002"; + proxyWebsockets = true; + }; + }; + extraConfig = '' + client_max_body_size 5G; + ''; + }; + "calibre.zeroq.su" = { + forceSSL = true; + enableACME = true; + locations."/" = { + proxyPass = "http://${server}:8083"; proxyWebsockets = true; }; extraConfig = '' client_max_body_size 5G; ''; }; - "dns.home.arpa" = { + "nix-cache.zeroq.su" = { forceSSL = true; enableACME = true; locations."/" = { - proxyPass = "http://127.0.0.1:53"; + proxyPass = "http://${server}:5000"; + proxyWebsockets = true; }; extraConfig = '' client_max_body_size 5G; ''; }; - "glances.home.arpa" = { + "pdf.zeroq.su" = { forceSSL = true; enableACME = true; locations."/" = { - proxyPass = "http://127.0.0.1:61208"; - }; - }; - "syncthing.home.arpa" = { - addSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://127.0.0.1:8384"; + proxyPass = "http://${server}:8446"; + proxyWebsockets = true; }; + extraConfig = '' + client_max_body_size 5G; + ''; }; + # "calibre.home.arpa" = { + # forceSSL = true; + # enableACME = true; + # locations."/" = { + # proxyPass = "http://127.0.0.1:8083"; + # proxyWebsockets = true; + # }; + # extraConfig = '' + # client_max_body_size 5G; + # ''; + # }; + # "dns.home.arpa" = { + # forceSSL = true; + # enableACME = true; + # locations."/" = { + # proxyPass = "http://127.0.0.1:53"; + # }; + # extraConfig = '' + # client_max_body_size 5G; + # ''; + # }; + # "glances.home.arpa" = { + # forceSSL = true; + # enableACME = true; + # locations."/" = { + # proxyPass = "http://127.0.0.1:61208"; + # }; + # }; + # "syncthing.home.arpa" = { + # addSSL = true; + # enableACME = true; + # locations."/" = { + # proxyPass = "http://127.0.0.1:8384"; + # }; + # }; # "zeroq.home.arpa" = { # forceSSL = true; # enableACME = true; @@ -269,4 +445,8 @@ in }; }; }; + networking.firewall.allowedTCPPorts = [ + 80 + 443 + ]; } diff --git a/modules/server/onlyoffice.nix b/modules/server/onlyoffice.nix index 7765afd..4e29817 100644 --- a/modules/server/onlyoffice.nix +++ b/modules/server/onlyoffice.nix @@ -17,7 +17,7 @@ in services.onlyoffice = { enable = true; # package = previous.onlyoffice-documentserver; - hostname = "office.home.arpa"; + hostname = "office.zeroq.su"; port = 8090; allowLocalConnections = true; wopi = true; diff --git a/modules/server/samba.nix b/modules/server/samba.nix index 410b1e3..58031fb 100644 --- a/modules/server/samba.nix +++ b/modules/server/samba.nix @@ -10,7 +10,7 @@ samba-wsdd = { enable = true; openFirewall = true; - hostname = "sapphira.home.arpa"; + hostname = "sapphira"; discovery = true; }; samba = { diff --git a/modules/vds/nginx.nix b/modules/vds/nginx.nix index 6a26a26..03b0a1b 100644 --- a/modules/vds/nginx.nix +++ b/modules/vds/nginx.nix @@ -8,7 +8,6 @@ let server = "100.64.0.0"; in { - # environment.etc."nginx/pubray".text = inputs.zeroq-credentials.services.xray.auth; users.users.nginx.extraGroups = [ "acme" ]; services = { nginx = { @@ -17,22 +16,7 @@ in recommendedOptimisation = true; recommendedProxySettings = true; recommendedTlsSettings = true; - # appendHttpConfig = inputs.zeroq-credentials.services.xray.maps; virtualHosts = { - # "pubray.zeroq.su" = { - # enableACME = true; - # forceSSL = true; - # root = "${inputs.zeroq-credentials.services.xray.subs}"; - # locations."/" = { - # extraConfig = '' - # auth_basic "Restricted"; - # auth_basic_user_file /etc/nginx/pubray; - - # if ($subfile = "") { return 403; } - # rewrite ^/$ $subfile break; - # ''; - # }; - # }; "x.zeroq.su" = { forceSSL = true; enableACME = true; @@ -55,210 +39,6 @@ in }; }; }; - "kuma.zeroq.su" = { - forceSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://${server}:4001"; - proxyWebsockets = true; - }; - }; - "health.zeroq.su" = { - forceSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://${server}:19999"; - proxyWebsockets = true; - }; - }; - "git.zeroq.su" = { - forceSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://${server}:3000"; - proxyWebsockets = true; - }; - }; - "homebox.zeroq.su" = { - forceSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://${server}:7745"; - proxyWebsockets = true; - }; - }; - # "agent.zeroq.su" = { - # forceSSL = true; - # enableACME = true; - # locations."/" = { - # proxyPass = "http://${server}:3000"; - # proxyWebsockets = true; - # }; - # }; - # "node-red.zeroq.su" = { - # forceSSL = true; - # enableACME = true; - # kTLS = true; - # locations."/" = { - # proxyPass = "http://${server}:1880"; - # proxyWebsockets = true; - # }; - # extraConfig = '' - # client_max_body_size 5G; - # ''; - # }; - "zeroq.su" = { - forceSSL = true; - enableACME = true; - root = pkgs.writeTextDir "index.html" '' - - - -
What are you doing here?
- - - ''; - locations = { - "/guest/" = { - proxyPass = "http://${server}:80"; - proxyWebsockets = true; - }; - # "/.well-known/discord" = { - # extraConfig = '' - # default_type text/plain; - # return 200 "dh=c2d103553a4cfdaa1b7952a87a7d8120a1e167cc"; - # ''; - # }; - }; - }; - "flux.zeroq.su" = { - forceSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://${server}:6061"; - proxyWebsockets = true; - }; - }; - "navidrome.zeroq.su" = { - addSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://${server}:4533"; - proxyWebsockets = true; - }; - }; - "vetymae.opencodes.zeroq.su" = { - forceSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://100.86.62.4:4096"; - proxyWebsockets = true; - }; - }; - "lamet.opencodes.zeroq.su" = { - forceSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://100.106.21.39:6061"; - proxyWebsockets = true; - }; - }; - "n8n.zeroq.su" = { - forceSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://${server}:5678"; - proxyWebsockets = true; - }; - }; - "office.zeroq.su" = { - enableACME = true; - forceSSL = true; - locations = { - "/" = { - proxyPass = "http://${server}:8090"; - proxyWebsockets = true; - }; - }; - # extraConfig = '' - # client_max_body_size 5G; - - # proxy_http_version 1.1; - # proxy_buffering off; - - # proxy_set_header Host $host; - # proxy_set_header X-Forwarded-Host $host; - # proxy_set_header X-Forwarded-Proto $scheme; - # proxy_set_header X-Real-IP $remote_addr; - # proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - - # proxy_set_header Authorization $http_authorization; - - # proxy_set_header Upgrade $http_upgrade; - # proxy_set_header Connection "upgrade"; - # ''; # absolute_redirect off; - }; - "immich.zeroq.su" = { - forceSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://${server}:2283"; - proxyWebsockets = true; - }; - extraConfig = '' - client_max_body_size 5G; - ''; - }; - "nextcloud.zeroq.su" = { - forceSSL = true; - enableACME = true; - locations = { - "/" = { - proxyPass = "http://${server}:10000"; - proxyWebsockets = true; - }; - "/whiteboard" = { - proxyPass = "http://${server}:3002"; - proxyWebsockets = true; - }; - }; - extraConfig = '' - client_max_body_size 5G; - ''; - }; - "calibre.zeroq.su" = { - forceSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://${server}:8083"; - proxyWebsockets = true; - }; - extraConfig = '' - client_max_body_size 5G; - ''; - }; - "pdf.zeroq.su" = { - forceSSL = true; - enableACME = true; - locations."/" = { - proxyPass = "http://${server}:8446"; - proxyWebsockets = true; - }; - extraConfig = '' - client_max_body_size 5G; - ''; - }; - # "ai.zeroq.su" = { - # forceSSL = true; - # enableACME = true; - # locations."/" = { - # proxyPass = "http://${server}:11112"; - # proxyWebsockets = true; - # }; - # extraConfig = '' - # client_max_body_size 5G; - # ''; - # }; }; }; };