blob: 597b781167d82515cbef3a0e9a1c8c83985eb496 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
|
{ config, lib, pkgs, ... }:
{
imports = [ ./dyndns.nix ];
# https://github.com/NixOS/nixpkgs/issues/210807#issuecomment-1383263210
options.services.nginx.virtualHosts = lib.mkOption {
type = lib.types.attrsOf (lib.types.submodule {
config.acmeRoot = lib.mkDefault null;
});
};
config = {
security.acme.acceptTerms = true;
security.acme.defaults.email = "hostmaster@mou.fo";
# TODO remove to switch to production certs
security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory";
services.oauth2_proxy.extraConfig = {
"ssl-insecure-skip-verify" = true;
"ssl-upstream-insecure-skip-verify" = true;
};
# https://go-acme.github.io/lego/dns/exec/
security.acme.defaults.dnsProvider = "exec";
security.acme.defaults.credentialFiles = {
"DDNS_FILE" = "/var/secrets/dyndns/";
};
security.acme.defaults.environmentFile = pkgs.writeText "lego.env" ''
# While it can be helpful to follow CNAMEs to find the challenge domain,
# this heuristic may not work with wildcard domains or DNAME.
LEGO_DISABLE_CNAME_SUPPORT=1
EXEC_PATH=${pkgs.writers.writeBash "lego-exec" ''
set -e
fqdn=${config.networking.fqdn}
challenge_fqdn=$2''${fqdn%%.*}.dynamic.''${fqdn#*.}
unset update_rr
if [[ $1 = present ]]; then
update_rr="update add $challenge_fqdn. 300 TXT $3"
fi
${pkgs.dnsutils}/bin/nsupdate -v -k ''${DDNS_FILE}_$(< ''${DDNS_FILE}_basename).private <<.
update delete $challenge_fqdn. TXT
$update_rr
send
.
if [[ $1 = present ]]; then
sleep 5
fi
''}
'';
};
}
|