mirror of
https://github.com/gensokyo-zone/infrastructure.git
synced 2026-02-09 12:29:19 -08:00
fix: service firewall settings
This commit is contained in:
parent
3d188ab76e
commit
d87b210c46
4 changed files with 6 additions and 4 deletions
|
|
@ -3,14 +3,15 @@
|
|||
lib,
|
||||
...
|
||||
}:
|
||||
with lib; let
|
||||
let
|
||||
inherit (lib.modules) mkDefault;
|
||||
cfg = config.services.zigbee2mqtt;
|
||||
in {
|
||||
services.nginx.virtualHosts.${cfg.domain} = {
|
||||
vouch.enable = true;
|
||||
locations = {
|
||||
"/" = {
|
||||
proxyPass = "http://127.0.0.1:${toString cfg.settings.frontend.port}";
|
||||
proxyPass = mkDefault "http://127.0.0.1:${toString cfg.settings.frontend.port}";
|
||||
extraConfig = ''
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
|
|
|
|||
|
|
@ -10,6 +10,7 @@ in {
|
|||
enable = mkDefault true;
|
||||
domain = mkDefault "login.${config.networking.domain}";
|
||||
settings = {
|
||||
vouch.listen = mkDefault "0.0.0.0";
|
||||
vouch.cookie.secure = mkDefault false;
|
||||
};
|
||||
enableSettingsSecrets = mkDefault true;
|
||||
|
|
|
|||
|
|
@ -15,7 +15,6 @@ in {
|
|||
|
||||
services.zigbee2mqtt = {
|
||||
enable = mkDefault true;
|
||||
openFirewall = mkDefault true;
|
||||
domain = mkDefault "z2m.${config.networking.domain}";
|
||||
settings = {
|
||||
advanced = {
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue