server preparing migration

This commit is contained in:
2026-08-08 19:24:14 +03:00
parent 5f6288bd15
commit cedc856a02
12 changed files with 328 additions and 365 deletions
+11 -11
View File
@@ -8,20 +8,20 @@
acme = {
acceptTerms = true;
defaults = {
email = "oqyude@zeroq.su";
server = "https://localhost:9000/acme/acme/directory";
dnsProvider = null;
email = "oqyude@gmail.com";
};
# certs = {
# # "home.arpa" = {
# # domain = "*.home.arpa";
# # server = "https://localhost:9000/acme/acme/directory";
# # listenHTTP = ":80";
# "home.arpa" = {
# email = "oqyude@zeroq.su";
# domain = "*.home.arpa";
# server = "https://localhost:9000/acme/acme/directory";
# listenHTTP = ":80";
# dnsProvider = null;
# };
# # "turn.home.arpa" = {
# # listenHTTP = "127.0.0.1:80";
# # group = "turnserver";
# # };
# "turn.home.arpa" = {
# listenHTTP = "127.0.0.1:80";
# group = "turnserver";
# };
# };
};
};
+1 -1
View File
@@ -15,7 +15,7 @@
192.168.1.20 flux.zeroq.su
192.168.1.20 git.zeroq.su
192.168.1.20 glances.zeroq.su
192.168.1.20 homebox.home.arpa
192.168.1.20 homebox.zeroq.su
192.168.1.20 immich.zeroq.su
192.168.1.20 kuma.zeroq.su
192.168.1.20 navidrome.zeroq.su
+1 -1
View File
@@ -23,7 +23,7 @@
./postgresql.nix
./power.nix
./samba.nix
./step-ca.nix
# ./step-ca.nix
./syncthing.nix
./systemd.nix
# ../containers/remnawave.nix
+1 -1
View File
@@ -14,7 +14,7 @@
appName = "ZeroQ Gitea Service";
settings = {
server = {
DOMAIN = "git.home.arpa";
DOMAIN = "git.zeroq.su";
HTTP_PORT = 3000;
};
service.DISABLE_REGISTRATION = true;
+12 -10
View File
@@ -11,7 +11,7 @@
nextcloud-whiteboard-server = {
enable = true;
settings = {
NEXTCLOUD_URL = "https://nextcloud.home.arpa";
NEXTCLOUD_URL = "https://nextcloud.zeroq.su";
};
secrets = [ config.sops.secrets.nextcloud-whiteboard-jwt.path ];
};
@@ -20,8 +20,8 @@
hostName = "talk.private";
backends.nextcloud = {
urls = [
"https://nextcloud.home.arpa"
"https://nextcloud.zeroq.su"
# "https://nextcloud.home.arpa"
];
secretFile = config.sops.secrets.nextcloud-talk-secret.path;
};
@@ -40,9 +40,9 @@
secretFile = config.sops.secrets.turn-secret.path;
apikeyFile = config.sops.secrets.turn-api-key.path;
servers = [
"turn:turn.home.arpa:3478?transport=udp"
"turn:turn.home.arpa:3478?transport=tcp"
# "turns:turn.home.arpa:5349?transport=tcp"
"turn:turn.zeroq.su:3478?transport=udp"
"turn:turn.zeroq.su:3478?transport=tcp"
# "turns:turn.zeroq.su:5349?transport=tcp"
];
};
};
@@ -72,26 +72,28 @@
trusted_domains = [
"100.64.0.0"
"192.168.1.20"
"37.128.246.126"
"localhost"
"nextcloud.home.arpa"
"nextcloud.private"
"nextcloud.zeroq.su"
"office.zeroq.su"
"office.home.arpa"
"nextcloud.home.arpa"
"office.zeroq.su"
];
trusted_proxies = [
"100.64.1.0"
"192.168.1.20"
"109.248.161.5"
"192.168.1.20"
"37.128.246.126"
];
overwriteprotocol = "https"; # maybe no
};
extraAppsEnable = true;
appstoreEnable = false;
notify_push = {
enable = false;
enable = true;
bendDomainToLocalhost = true;
nextcloudUrl = "https://nextcloud.home.arpa";
nextcloudUrl = "https://nextcloud.zeroq.su";
};
# phpPackage = pkgs.php85;
extraApps = {
+293 -113
View File
@@ -35,7 +35,7 @@ in
}
];
};
"office.home.arpa" = {
"office.zeroq.su" = {
forceSSL = true;
enableACME = true;
};
@@ -64,46 +64,46 @@ in
client_max_body_size 5G;
'';
};
"pdf.home.arpa" = {
forceSSL = true;
enableACME = true;
locations = {
"/" = {
proxyPass = "http://127.0.0.1:8446";
proxyWebsockets = true;
};
};
extraConfig = ''
client_max_body_size 5G;
'';
};
"homebox.home.arpa" = {
forceSSL = true;
enableACME = true;
locations = {
"/" = {
proxyPass = "http://127.0.0.1:7745";
proxyWebsockets = true;
};
};
};
"nextcloud.home.arpa" = {
forceSSL = true;
enableACME = true;
locations = {
"/" = {
proxyPass = "http://127.0.0.1:10000";
proxyWebsockets = true;
};
"/whiteboard" = {
proxyPass = "http://127.0.0.1:3002";
proxyWebsockets = true;
};
};
extraConfig = ''
client_max_body_size 5G;
'';
};
# "pdf.home.arpa" = {
# forceSSL = true;
# enableACME = true;
# locations = {
# "/" = {
# proxyPass = "http://127.0.0.1:8446";
# proxyWebsockets = true;
# };
# };
# extraConfig = ''
# client_max_body_size 5G;
# '';
# };
# "homebox.home.arpa" = {
# forceSSL = true;
# enableACME = true;
# locations = {
# "/" = {
# proxyPass = "http://127.0.0.1:7745";
# proxyWebsockets = true;
# };
# };
# };
# "nextcloud.home.arpa" = {
# forceSSL = true;
# enableACME = true;
# locations = {
# "/" = {
# proxyPass = "http://127.0.0.1:10000";
# proxyWebsockets = true;
# };
# "/whiteboard" = {
# proxyPass = "http://127.0.0.1:3002";
# proxyWebsockets = true;
# };
# };
# extraConfig = ''
# client_max_body_size 5G;
# '';
# };
# "talk.home.arpa" = {
# forceSSL = true;
# enableACME = true;
@@ -130,39 +130,28 @@ in
# client_max_body_size 5G;
# '';
# };
"ca.home.arpa" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://127.0.0.1:9000";
proxyWebsockets = true;
};
extraConfig = ''
client_max_body_size 5G;
'';
};
"git.home.arpa" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://127.0.0.1:3000";
proxyWebsockets = true;
};
extraConfig = ''
client_max_body_size 5G;
'';
};
"git.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://127.0.0.1:3000";
proxyWebsockets = true;
};
extraConfig = ''
client_max_body_size 5G;
'';
};
# "ca.zeroq.su" = {
# forceSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:9000";
# proxyWebsockets = true;
# };
# extraConfig = ''
# client_max_body_size 5G;
# '';
# };
# "git.home.arpa" = {
# forceSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:3000";
# proxyWebsockets = true;
# };
# extraConfig = ''
# client_max_body_size 5G;
# '';
# };
# "n8n.home.arpa" = {
# forceSSL = true;
# enableACME = true;
@@ -174,76 +163,263 @@ in
# client_max_body_size 5G;
# '';
# };
"kuma.home.arpa" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://127.0.0.1:4001";
proxyWebsockets = true;
};
};
"flux.home.arpa" = {
# "kuma.home.arpa" = {
# forceSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:4001";
# proxyWebsockets = true;
# };
# };
# "flux.home.arpa" = {
# addSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:6061";
# proxyWebsockets = true;
# };
# };
# "navidrome.home.arpa" = {
# addSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:4533";
# proxyWebsockets = true;
# };
# };
# "immich.home.arpa" = {
# addSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:2283";
# proxyWebsockets = true;
# };
# extraConfig = ''
# client_max_body_size 5G;
# '';
# };
"immich.zeroq.su" = {
addSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://127.0.0.1:6061";
proxyWebsockets = true;
};
};
"navidrome.home.arpa" = {
addSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://127.0.0.1:4533";
proxyWebsockets = true;
};
};
"immich.home.arpa" = {
addSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://127.0.0.1:2283";
proxyPass = "http://${server}:2283";
proxyWebsockets = true;
};
extraConfig = ''
client_max_body_size 5G;
'';
};
"calibre.home.arpa" = {
"kuma.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://127.0.0.1:8083";
proxyPass = "http://${server}:4001";
proxyWebsockets = true;
};
};
"health.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://${server}:19999";
proxyWebsockets = true;
};
};
"git.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://${server}:3000";
proxyWebsockets = true;
};
};
"homebox.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://${server}:7745";
proxyWebsockets = true;
};
};
# "agent.zeroq.su" = {
# forceSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://${server}:3000";
# proxyWebsockets = true;
# };
# };
# "node-red.zeroq.su" = {
# forceSSL = true;
# enableACME = true;
# kTLS = true;
# locations."/" = {
# proxyPass = "http://${server}:1880";
# proxyWebsockets = true;
# };
# extraConfig = ''
# client_max_body_size 5G;
# '';
# };
"zeroq.su" = {
forceSSL = true;
enableACME = true;
root = pkgs.writeTextDir "index.html" ''
<!doctype html>
<html>
<body>
<pre>What are you doing here?</pre>
</body>
</html>
'';
locations = {
"/guest/" = {
proxyPass = "http://${server}:80";
proxyWebsockets = true;
};
# "/.well-known/discord" = {
# extraConfig = ''
# default_type text/plain;
# return 200 "dh=c2d103553a4cfdaa1b7952a87a7d8120a1e167cc";
# '';
# };
};
};
"flux.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://${server}:6061";
proxyWebsockets = true;
};
};
"navidrome.zeroq.su" = {
addSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://${server}:4533";
proxyWebsockets = true;
};
};
"vetymae.opencodes.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://100.86.62.4:4096";
proxyWebsockets = true;
};
};
"lamet.opencodes.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://100.106.21.39:6061";
proxyWebsockets = true;
};
};
"n8n.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://${server}:5678";
proxyWebsockets = true;
};
};
# "office.zeroq.su" = {
# enableACME = true;
# forceSSL = true;
# locations = {
# "/" = {
# proxyPass = "http://${server}:8090";
# proxyWebsockets = true;
# };
# };
# };
"nextcloud.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations = {
"/" = {
proxyPass = "http://${server}:10000";
proxyWebsockets = true;
};
"/whiteboard" = {
proxyPass = "http://${server}:3002";
proxyWebsockets = true;
};
};
extraConfig = ''
client_max_body_size 5G;
'';
};
"calibre.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://${server}:8083";
proxyWebsockets = true;
};
extraConfig = ''
client_max_body_size 5G;
'';
};
"dns.home.arpa" = {
"nix-cache.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://127.0.0.1:53";
proxyPass = "http://${server}:5000";
proxyWebsockets = true;
};
extraConfig = ''
client_max_body_size 5G;
'';
};
"glances.home.arpa" = {
"pdf.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://127.0.0.1:61208";
};
};
"syncthing.home.arpa" = {
addSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://127.0.0.1:8384";
proxyPass = "http://${server}:8446";
proxyWebsockets = true;
};
extraConfig = ''
client_max_body_size 5G;
'';
};
# "calibre.home.arpa" = {
# forceSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:8083";
# proxyWebsockets = true;
# };
# extraConfig = ''
# client_max_body_size 5G;
# '';
# };
# "dns.home.arpa" = {
# forceSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:53";
# };
# extraConfig = ''
# client_max_body_size 5G;
# '';
# };
# "glances.home.arpa" = {
# forceSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:61208";
# };
# };
# "syncthing.home.arpa" = {
# addSSL = true;
# enableACME = true;
# locations."/" = {
# proxyPass = "http://127.0.0.1:8384";
# };
# };
# "zeroq.home.arpa" = {
# forceSSL = true;
# enableACME = true;
@@ -269,4 +445,8 @@ in
};
};
};
networking.firewall.allowedTCPPorts = [
80
443
];
}
+1 -1
View File
@@ -17,7 +17,7 @@ in
services.onlyoffice = {
enable = true;
# package = previous.onlyoffice-documentserver;
hostname = "office.home.arpa";
hostname = "office.zeroq.su";
port = 8090;
allowLocalConnections = true;
wopi = true;
+1 -1
View File
@@ -10,7 +10,7 @@
samba-wsdd = {
enable = true;
openFirewall = true;
hostname = "sapphira.home.arpa";
hostname = "sapphira";
discovery = true;
};
samba = {