diff options
Diffstat (limited to 'hostnix/elmo/acme.nix')
| -rw-r--r-- | hostnix/elmo/acme.nix | 49 |
1 files changed, 49 insertions, 0 deletions
diff --git a/hostnix/elmo/acme.nix b/hostnix/elmo/acme.nix new file mode 100644 index 0000000..fccd5c8 --- /dev/null +++ b/hostnix/elmo/acme.nix @@ -0,0 +1,49 @@ +{ config, lib, pkgs, ... }: + +{ + imports = [ ./dyndns.nix ]; + + # https://github.com/NixOS/nixpkgs/issues/210807#issuecomment-1383263210 + options.services.nginx.virtualHosts = lib.mkOption { + type = lib.types.attrsOf (lib.types.submodule { + config.acmeRoot = lib.mkDefault null; + }); + }; + + config = { + security.acme.acceptTerms = true; + security.acme.defaults.email = "hostmaster@mou.fo"; + + # https://go-acme.github.io/lego/dns/exec/ + security.acme.defaults.dnsProvider = "exec"; + security.acme.defaults.credentialFiles = { + "DDNS_FILE" = "/var/secrets/dyndns/"; + }; + security.acme.defaults.environmentFile = pkgs.writeText "lego.env" '' + # While it can be helpful to follow CNAMEs to find the challenge domain, + # this heuristic may not work with wildcard domains or DNAME. + LEGO_DISABLE_CNAME_SUPPORT=1 + EXEC_PATH=${pkgs.writers.writeBash "lego-exec" '' + set -e + + fqdn=${config.networking.fqdn} + challenge_fqdn=$2''${fqdn%%.*}.dynamic.''${fqdn#*.} + + unset update_rr + if [[ $1 = present ]]; then + update_rr="update add $challenge_fqdn. 300 TXT $3" + fi + + ${pkgs.dnsutils}/bin/nsupdate -v -k ''${DDNS_FILE}_$(< ''${DDNS_FILE}_basename).private <<. + update delete $challenge_fqdn. TXT + $update_rr + send + . + + if [[ $1 = present ]]; then + sleep 5 + fi + ''} + ''; + }; +} |
