ma bgt: enable acme with cloudflare
This commit is contained in:
parent
aeb0c2a6ea
commit
2c417ec53d
|
@ -59,6 +59,11 @@ in {
|
||||||
systemd.services.nginx.serviceConfig.ReadWritePaths = [
|
systemd.services.nginx.serviceConfig.ReadWritePaths = [
|
||||||
"/var/spool/nginx/logs/"
|
"/var/spool/nginx/logs/"
|
||||||
];
|
];
|
||||||
|
security.acme.certs."download.binaergewitter.de" = {
|
||||||
|
dnsProvider = "cloudflare";
|
||||||
|
credentialsFile = toString <secrets/lego-binaergewitter>;
|
||||||
|
webroot = lib.mkForce null;
|
||||||
|
};
|
||||||
|
|
||||||
services.nginx = {
|
services.nginx = {
|
||||||
appendHttpConfig = ''
|
appendHttpConfig = ''
|
||||||
|
@ -70,6 +75,8 @@ in {
|
||||||
recommendedGzipSettings = true;
|
recommendedGzipSettings = true;
|
||||||
recommendedOptimisation = true;
|
recommendedOptimisation = true;
|
||||||
virtualHosts."download.binaergewitter.de" = {
|
virtualHosts."download.binaergewitter.de" = {
|
||||||
|
enableSSL = true;
|
||||||
|
enableACME = true;
|
||||||
serverAliases = [ "dl2.binaergewitter.de" ];
|
serverAliases = [ "dl2.binaergewitter.de" ];
|
||||||
root = "/var/www/binaergewitter";
|
root = "/var/www/binaergewitter";
|
||||||
extraConfig = ''
|
extraConfig = ''
|
||||||
|
|
Loading…
Reference in a new issue