summaryrefslogtreecommitdiff
path: root/hostnix/weebnix/configuration.nix
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix/weebnix/configuration.nix')
-rw-r--r--hostnix/weebnix/configuration.nix51
1 files changed, 51 insertions, 0 deletions
diff --git a/hostnix/weebnix/configuration.nix b/hostnix/weebnix/configuration.nix
index 72b0523..f38148a 100644
--- a/hostnix/weebnix/configuration.nix
+++ b/hostnix/weebnix/configuration.nix
@@ -13,6 +13,11 @@
security.sudo.wheelNeedsPassword = false;
+ security.acme.acceptTerms = true;
+ security.acme.defaults.email = "hostmaster@mou.fo";
+ # TODO switch to production certs
+ security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory";
+
users.users.joe = {
isNormalUser = true;
extraGroups = [ "wheel" ];
@@ -30,7 +35,53 @@
services.openssh.enable = true;
+ services.keycloak = {
+ enable = true;
+ database.passwordFile = "/var/lib/secrets/keycloak.dbpass";
+ settings = {
+ hostname = "kc.weebnix.mou.fo";
+ http-host = "127.0.0.1";
+ http-port = 7567;
+ proxy = "edge";
+ };
+ };
+
+ services.nginx = {
+ enable = true;
+ recommendedGzipSettings = true;
+ recommendedOptimisation = true;
+ recommendedProxySettings = true;
+ recommendedTlsSettings = true;
+ virtualHosts."kc.weebnix.mou.fo" = {
+ enableACME = true;
+ forceSSL = true;
+ locations."/".proxyPass = "http://127.0.0.1:7567";
+ };
+ # Slightly crazy setup to SNI reverse proxy HTTPS to multiple upstreams.
+ # We displace ourselves onto port 8443, and send requests that are not
+ # intended for us to weeber. This is done because Apache running on weeber
+ # cannot SNI reverse proxy, so we put weebnix in front of weeber on IPv4.
+ # TODO get rid of all this when replacing weeber or maybe consider HAProxy
+ defaultSSLListenPort = 8443;
+ streamConfig = ''
+ map $ssl_preread_server_name $selected_upstream {
+ hostnames;
+ weebnix.mou.fo self;
+ *.weebnix.mou.fo self;
+ default weeber;
+ }
+ upstream self { server 127.0.0.1:8443; }
+ upstream weeber { server 192.168.0.168:443; }
+ server {
+ listen 0.0.0.0:443;
+ listen [::0]:443;
+ proxy_pass $selected_upstream;
+ ssl_preread on;
+ }
+ '';
+ };
+ networking.firewall.allowedTCPPorts = [ 80 443 ];
# This value determines the NixOS release from which the default
# settings for stateful data, like file locations and database versions