summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2024-04-24 02:09:31 -0400
committerJoe Mou <dev@mou.fo>2024-04-26 23:54:54 -0400
commit5c0b6b619b2a7ee4502aa66ad8ee03ffff64cacb (patch)
tree8cb4dc00b6afa879fe321fe6d3c7bb1f19daa33b
parentcce8a71d3192f1ae596e49e86260b8da388e7625 (diff)
ACME with DNS challenge
-rw-r--r--hostnix/elmo/acme.nix56
-rw-r--r--hostnix/elmo/configuration.nix12
-rw-r--r--hostnix/elmo/dyndns.nix3
3 files changed, 60 insertions, 11 deletions
diff --git a/hostnix/elmo/acme.nix b/hostnix/elmo/acme.nix
new file mode 100644
index 0000000..597b781
--- /dev/null
+++ b/hostnix/elmo/acme.nix
@@ -0,0 +1,56 @@
+{ config, lib, pkgs, ... }:
+
+{
+ imports = [ ./dyndns.nix ];
+
+ # https://github.com/NixOS/nixpkgs/issues/210807#issuecomment-1383263210
+ options.services.nginx.virtualHosts = lib.mkOption {
+ type = lib.types.attrsOf (lib.types.submodule {
+ config.acmeRoot = lib.mkDefault null;
+ });
+ };
+
+ config = {
+ security.acme.acceptTerms = true;
+ security.acme.defaults.email = "hostmaster@mou.fo";
+
+ # TODO remove to switch to production certs
+ security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory";
+ services.oauth2_proxy.extraConfig = {
+ "ssl-insecure-skip-verify" = true;
+ "ssl-upstream-insecure-skip-verify" = true;
+ };
+
+ # https://go-acme.github.io/lego/dns/exec/
+ security.acme.defaults.dnsProvider = "exec";
+ security.acme.defaults.credentialFiles = {
+ "DDNS_FILE" = "/var/secrets/dyndns/";
+ };
+ security.acme.defaults.environmentFile = pkgs.writeText "lego.env" ''
+ # While it can be helpful to follow CNAMEs to find the challenge domain,
+ # this heuristic may not work with wildcard domains or DNAME.
+ LEGO_DISABLE_CNAME_SUPPORT=1
+ EXEC_PATH=${pkgs.writers.writeBash "lego-exec" ''
+ set -e
+
+ fqdn=${config.networking.fqdn}
+ challenge_fqdn=$2''${fqdn%%.*}.dynamic.''${fqdn#*.}
+
+ unset update_rr
+ if [[ $1 = present ]]; then
+ update_rr="update add $challenge_fqdn. 300 TXT $3"
+ fi
+
+ ${pkgs.dnsutils}/bin/nsupdate -v -k ''${DDNS_FILE}_$(< ''${DDNS_FILE}_basename).private <<.
+ update delete $challenge_fqdn. TXT
+ $update_rr
+ send
+ .
+
+ if [[ $1 = present ]]; then
+ sleep 5
+ fi
+ ''}
+ '';
+ };
+}
diff --git a/hostnix/elmo/configuration.nix b/hostnix/elmo/configuration.nix
index 31cf90b..250cfab 100644
--- a/hostnix/elmo/configuration.nix
+++ b/hostnix/elmo/configuration.nix
@@ -2,6 +2,7 @@
{
imports = [
+ ./acme.nix
./dns.nix
./dyndns.nix
./hardware-configuration.nix
@@ -15,11 +16,6 @@
nix.settings.experimental-features = [ "nix-command" "flakes" ];
- security.acme.acceptTerms = true;
- security.acme.defaults.email = "hostmaster@mou.fo";
- # TODO switch to production certs
- security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory";
-
security.sudo.wheelNeedsPassword = false;
users.users.joe = {
@@ -60,12 +56,6 @@
recommendedTlsSettings = true;
};
- # TODO remove upon switching to production certs
- services.oauth2_proxy.extraConfig = {
- "ssl-insecure-skip-verify" = true;
- "ssl-upstream-insecure-skip-verify" = true;
- };
-
networking.firewall.allowedTCPPorts = [ 80 443 ];
# This value determines the NixOS release from which the default
diff --git a/hostnix/elmo/dyndns.nix b/hostnix/elmo/dyndns.nix
index 3dc0144..aea6776 100644
--- a/hostnix/elmo/dyndns.nix
+++ b/hostnix/elmo/dyndns.nix
@@ -65,6 +65,9 @@
''${IP6:+update add $RR. 300 AAAA $IP6}
update delete $RR. TXT
update add $RR. 300 TXT "v=spf1 include:_spf.mou.fo ~all"
+ ; Wildcard all subdomains.
+ update delete \\*.$1.$RR. CNAME
+ update add \\*.$1.$RR. 300 CNAME $RR.
send
.
'';