summaryrefslogtreecommitdiff
path: root/hostnix/elmo/acme.nix
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix/elmo/acme.nix')
-rw-r--r--hostnix/elmo/acme.nix56
1 files changed, 56 insertions, 0 deletions
diff --git a/hostnix/elmo/acme.nix b/hostnix/elmo/acme.nix
new file mode 100644
index 0000000..597b781
--- /dev/null
+++ b/hostnix/elmo/acme.nix
@@ -0,0 +1,56 @@
+{ config, lib, pkgs, ... }:
+
+{
+ imports = [ ./dyndns.nix ];
+
+ # https://github.com/NixOS/nixpkgs/issues/210807#issuecomment-1383263210
+ options.services.nginx.virtualHosts = lib.mkOption {
+ type = lib.types.attrsOf (lib.types.submodule {
+ config.acmeRoot = lib.mkDefault null;
+ });
+ };
+
+ config = {
+ security.acme.acceptTerms = true;
+ security.acme.defaults.email = "hostmaster@mou.fo";
+
+ # TODO remove to switch to production certs
+ security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory";
+ services.oauth2_proxy.extraConfig = {
+ "ssl-insecure-skip-verify" = true;
+ "ssl-upstream-insecure-skip-verify" = true;
+ };
+
+ # https://go-acme.github.io/lego/dns/exec/
+ security.acme.defaults.dnsProvider = "exec";
+ security.acme.defaults.credentialFiles = {
+ "DDNS_FILE" = "/var/secrets/dyndns/";
+ };
+ security.acme.defaults.environmentFile = pkgs.writeText "lego.env" ''
+ # While it can be helpful to follow CNAMEs to find the challenge domain,
+ # this heuristic may not work with wildcard domains or DNAME.
+ LEGO_DISABLE_CNAME_SUPPORT=1
+ EXEC_PATH=${pkgs.writers.writeBash "lego-exec" ''
+ set -e
+
+ fqdn=${config.networking.fqdn}
+ challenge_fqdn=$2''${fqdn%%.*}.dynamic.''${fqdn#*.}
+
+ unset update_rr
+ if [[ $1 = present ]]; then
+ update_rr="update add $challenge_fqdn. 300 TXT $3"
+ fi
+
+ ${pkgs.dnsutils}/bin/nsupdate -v -k ''${DDNS_FILE}_$(< ''${DDNS_FILE}_basename).private <<.
+ update delete $challenge_fqdn. TXT
+ $update_rr
+ send
+ .
+
+ if [[ $1 = present ]]; then
+ sleep 5
+ fi
+ ''}
+ '';
+ };
+}