FIX : modules/rest-server.nix

Add caddy for reverse proxy, change firewall rules and change
rest-server address for localhost
This commit is contained in:
Alexandre LUCAZEAU 2022-05-26 19:08:00 +00:00
parent bb6e4d268a
commit 925a08ffee
1 changed files with 29 additions and 2 deletions

View File

@ -1,5 +1,8 @@
{ lib, config, ... }:
{ lib, config, pkgs, ... }:
let
caddyDir = "/var/lib/caddy";
in
{
services.restic.server = {
enable = true;
@ -7,9 +10,33 @@
extraFlags = [ "--no-auth" ];
dataDir = "/var/lib/backup";
prometheus = true;
listenAddress = "127.0.0.1:8080";
};
networking = {
firewall.enable = true;
firewall.allowedTCPPorts = [ 8000 ];
firewall.allowedTCPPorts = [ 80 443 ];
};
services.caddy = {
enable = true;
email = "lucazeau.alexandre@gmail.com";
config = ''
{
storage file_system {
root ${caddyDir}
}
}
https://back.atlanticaweb.fr {
reverse_proxy http://127.0.0.1:8080
}
'';
};
users.users.caddy = {
group = "caddy";
uid = config.ids.uids.caddy;
home = caddyDir;
createHome = true;
extraGroups = [ "users" ];
};
users.groups.caddy.gid = config.ids.uids.caddy;
}