diff options
| -rw-r--r-- | hostnix/elmo/acme.nix | 56 | ||||
| -rw-r--r-- | hostnix/elmo/configuration.nix | 12 | ||||
| -rw-r--r-- | hostnix/elmo/dyndns.nix | 3 |
3 files changed, 60 insertions, 11 deletions
diff --git a/hostnix/elmo/acme.nix b/hostnix/elmo/acme.nix new file mode 100644 index 0000000..597b781 --- /dev/null +++ b/hostnix/elmo/acme.nix @@ -0,0 +1,56 @@ +{ config, lib, pkgs, ... }: + +{ + imports = [ ./dyndns.nix ]; + + # https://github.com/NixOS/nixpkgs/issues/210807#issuecomment-1383263210 + options.services.nginx.virtualHosts = lib.mkOption { + type = lib.types.attrsOf (lib.types.submodule { + config.acmeRoot = lib.mkDefault null; + }); + }; + + config = { + security.acme.acceptTerms = true; + security.acme.defaults.email = "hostmaster@mou.fo"; + + # TODO remove to switch to production certs + security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory"; + services.oauth2_proxy.extraConfig = { + "ssl-insecure-skip-verify" = true; + "ssl-upstream-insecure-skip-verify" = true; + }; + + # https://go-acme.github.io/lego/dns/exec/ + security.acme.defaults.dnsProvider = "exec"; + security.acme.defaults.credentialFiles = { + "DDNS_FILE" = "/var/secrets/dyndns/"; + }; + security.acme.defaults.environmentFile = pkgs.writeText "lego.env" '' + # While it can be helpful to follow CNAMEs to find the challenge domain, + # this heuristic may not work with wildcard domains or DNAME. + LEGO_DISABLE_CNAME_SUPPORT=1 + EXEC_PATH=${pkgs.writers.writeBash "lego-exec" '' + set -e + + fqdn=${config.networking.fqdn} + challenge_fqdn=$2''${fqdn%%.*}.dynamic.''${fqdn#*.} + + unset update_rr + if [[ $1 = present ]]; then + update_rr="update add $challenge_fqdn. 300 TXT $3" + fi + + ${pkgs.dnsutils}/bin/nsupdate -v -k ''${DDNS_FILE}_$(< ''${DDNS_FILE}_basename).private <<. + update delete $challenge_fqdn. TXT + $update_rr + send + . + + if [[ $1 = present ]]; then + sleep 5 + fi + ''} + ''; + }; +} diff --git a/hostnix/elmo/configuration.nix b/hostnix/elmo/configuration.nix index 31cf90b..250cfab 100644 --- a/hostnix/elmo/configuration.nix +++ b/hostnix/elmo/configuration.nix @@ -2,6 +2,7 @@ { imports = [ + ./acme.nix ./dns.nix ./dyndns.nix ./hardware-configuration.nix @@ -15,11 +16,6 @@ nix.settings.experimental-features = [ "nix-command" "flakes" ]; - security.acme.acceptTerms = true; - security.acme.defaults.email = "hostmaster@mou.fo"; - # TODO switch to production certs - security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory"; - security.sudo.wheelNeedsPassword = false; users.users.joe = { @@ -60,12 +56,6 @@ recommendedTlsSettings = true; }; - # TODO remove upon switching to production certs - services.oauth2_proxy.extraConfig = { - "ssl-insecure-skip-verify" = true; - "ssl-upstream-insecure-skip-verify" = true; - }; - networking.firewall.allowedTCPPorts = [ 80 443 ]; # This value determines the NixOS release from which the default diff --git a/hostnix/elmo/dyndns.nix b/hostnix/elmo/dyndns.nix index 3dc0144..aea6776 100644 --- a/hostnix/elmo/dyndns.nix +++ b/hostnix/elmo/dyndns.nix @@ -65,6 +65,9 @@ ''${IP6:+update add $RR. 300 AAAA $IP6} update delete $RR. TXT update add $RR. 300 TXT "v=spf1 include:_spf.mou.fo ~all" + ; Wildcard all subdomains. + update delete \\*.$1.$RR. CNAME + update add \\*.$1.$RR. 300 CNAME $RR. send . ''; |
