nixos-config/2configs/nginx/euer.wiki.nix

111 lines
2.9 KiB
Nix
Raw Normal View History

2015-10-28 21:31:07 +01:00
{ config, lib, pkgs, ... }:
2016-10-20 20:54:38 +02:00
with import <stockholm/lib>;
2015-10-28 21:31:07 +01:00
let
2015-10-29 10:55:54 +01:00
sec = toString <secrets>;
2016-07-28 13:02:06 +02:00
ext-dom = "wiki.euer.krebsco.de";
2015-10-28 21:31:07 +01:00
user = config.services.nginx.user;
group = config.services.nginx.group;
fpm-socket = "/var/run/php5-fpm.sock";
hostname = config.krebs.build.host.name;
tw-upload = pkgs.tw-upload-plugin;
base-dir = "/var/www/wiki.euer";
base-cfg = "${base-dir}/twconf.ini";
wiki-dir = "${base-dir}/store/";
backup-dir = "${base-dir}/backup/";
# contains:
# user1 = pass1
# userN = passN
2018-03-23 10:28:33 +01:00
# afterwards put /var/www/<ext-dom>/user1.html as tiddlywiki
2015-10-29 10:55:54 +01:00
tw-pass-file = "${sec}/tw-pass.ini";
2016-12-24 23:38:01 +01:00
2015-10-28 21:31:07 +01:00
in {
state = [ base-dir ];
# hotfix for broken wiki after reboot
systemd.services."phpfpm-euer-wiki".serviceConfig.RequiresMountFor = [ "/media/cloud" ];
2015-10-28 21:31:07 +01:00
services.phpfpm = {
pools.euer-wiki = {
inherit user group;
listen = fpm-socket;
settings = {
2019-10-28 11:53:39 +01:00
"listen.owner" = user;
"pm" = "dynamic";
"pm.max_children" = 5;
"pm.start_servers" = 2;
"pm.min_spare_servers" = 1;
"pm.max_spare_servers" = 3;
"chdir" = "/";
"php_admin_value[error_log]" = "stderr";
"php_admin_flag[log_errors]" = "on";
"catch_workers_output" = "yes";
};
phpEnv.twconf = base-cfg;
2015-10-28 21:31:07 +01:00
};
};
systemd.services.prepare-tw = {
wantedBy = [ "local-fs.target" ];
2018-03-23 10:28:33 +01:00
before = [ "phpfpm.service" "nginx.service" ];
2015-10-28 21:31:07 +01:00
serviceConfig = {
ExecStart = pkgs.writeScript "prepare-tw-service" ''
#!/bin/sh
if ! test -d "${base-dir}" ;then
mkdir -p "${wiki-dir}" "${backup-dir}"
2015-10-28 21:31:07 +01:00
# write the base configuration
cat > "${base-cfg}" <<EOF
2015-10-28 21:31:07 +01:00
[users]
$(cat "${tw-pass-file}")
[directories]
backupdir = ${backup-dir}
savedir = ${wiki-dir}
EOF
chown -R ${user}:${group} "${base-dir}"
chmod 700 -R "${base-dir}"
fi
2015-10-28 21:31:07 +01:00
'';
Type = "oneshot";
RemainAfterExit = "yes";
TimeoutSec = "0";
};
};
2016-12-24 23:38:01 +01:00
services.nginx = {
2015-10-28 21:31:07 +01:00
enable = mkDefault true;
recommendedGzipSettings = true;
2016-12-24 23:38:01 +01:00
virtualHosts = {
"${ext-dom}" = {
#serverAliases = [
2018-01-09 19:10:07 +01:00
# "wiki.makefu.r"
2016-12-24 23:38:01 +01:00
# "wiki.makefu"
#];
forceSSL = true;
enableACME = true;
locations = {
"/" = {
root = wiki-dir;
2018-03-23 10:28:33 +01:00
index = "makefu.html";
2016-12-24 23:38:01 +01:00
extraConfig = ''
expires -1;
autoindex on;
'';
};
"/store.php" = {
root = tw-upload;
extraConfig = ''
client_max_body_size 200M;
fastcgi_split_path_info ^(.+\.php)(/.+)$;
fastcgi_pass unix:${fpm-socket};
include ${pkgs.nginx}/conf/fastcgi_params;
include ${pkgs.nginx}/conf/fastcgi.conf;
'';
};
};
2015-10-28 21:31:07 +01:00
};
};
};
}