summaryrefslogtreecommitdiff
path: root/hostnix/weebnix
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2023-12-21 20:09:41 -0800
committerJoe Mou <dev@mou.fo>2023-12-22 16:37:20 -0800
commitd5f787a40b8406c6f20350b2945a741901cefb44 (patch)
treea71c6fb0c68a2f7222f6df21cea0eaf47792665a /hostnix/weebnix
parent6e953726913bee6449f8599be1448a33bcb3d177 (diff)
Revert "Switch to production ACME certs"
This reverts commit 18148c3dec9154f43c5be6f2ed9e427e990c6a06.
Diffstat (limited to 'hostnix/weebnix')
-rw-r--r--hostnix/weebnix/configuration.nix8
1 files changed, 8 insertions, 0 deletions
diff --git a/hostnix/weebnix/configuration.nix b/hostnix/weebnix/configuration.nix
index a1c1420..14427f0 100644
--- a/hostnix/weebnix/configuration.nix
+++ b/hostnix/weebnix/configuration.nix
@@ -18,6 +18,8 @@
security.acme.acceptTerms = true;
security.acme.defaults.email = "hostmaster@mou.fo";
+ # TODO switch to production certs
+ security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory";
users.users.joe = {
isNormalUser = true;
@@ -66,6 +68,12 @@
'';
};
+ # TODO remove upon switching to production certs
+ services.oauth2_proxy.extraConfig = {
+ "ssl-insecure-skip-verify" = true;
+ "ssl-upstream-insecure-skip-verify" = true;
+ };
+
networking.firewall.allowedTCPPorts = [ 80 443 ];
# This value determines the NixOS release from which the default