depot/cluster/services/nginx/nginx.nix

33 lines
1.1 KiB
Nix
Raw Normal View History

{ config, depot, ... }:
2021-10-16 21:16:46 +03:00
let
2023-08-31 01:55:45 +03:00
inherit (depot.lib.meta) adminEmail;
2022-09-02 00:05:39 +03:00
in {
2022-05-30 23:19:26 +03:00
security.acme.defaults.email = adminEmail;
2021-10-16 21:16:46 +03:00
security.acme.acceptTerms = true;
services.nginx = {
enable = true;
recommendedProxySettings = true;
recommendedTlsSettings = true;
recommendedOptimisation = true;
recommendedGzipSettings = true;
proxyResolveWhileRunning = true;
2021-10-16 21:16:46 +03:00
resolver = {
addresses = config.networking.nameservers;
2021-10-16 21:16:46 +03:00
valid = "30s";
};
appendHttpConfig = ''
server_names_hash_bucket_size 128;
proxy_headers_hash_max_size 4096;
proxy_headers_hash_bucket_size 128;
log_format fmt_loki 'host=$host remote_addr=$remote_addr remote_user=$remote_user request="$request" status=$status body_bytes_sent=$body_bytes_sent http_referer="$http_referer" http_user_agent="$http_user_agent"';
access_log syslog:server=unix:/dev/log,tag=nginx_access,nohostname fmt_loki;
2021-10-16 21:16:46 +03:00
'';
};
networking.firewall.allowedTCPPorts = [ 80 443 ];
systemd.services.nginx = {
after = [ "network-online.target" ];
wants = [ "network-online.target" ];
};
2021-10-16 21:16:46 +03:00
}