FIX : modules/rest-server.nix
Add caddy for reverse proxy, change firewall rules and change rest-server address for localhost
This commit is contained in:
parent
bb6e4d268a
commit
925a08ffee
|
@ -1,5 +1,8 @@
|
||||||
|
|
||||||
{ lib, config, ... }:
|
{ lib, config, pkgs, ... }:
|
||||||
|
let
|
||||||
|
caddyDir = "/var/lib/caddy";
|
||||||
|
in
|
||||||
{
|
{
|
||||||
services.restic.server = {
|
services.restic.server = {
|
||||||
enable = true;
|
enable = true;
|
||||||
|
@ -7,9 +10,33 @@
|
||||||
extraFlags = [ "--no-auth" ];
|
extraFlags = [ "--no-auth" ];
|
||||||
dataDir = "/var/lib/backup";
|
dataDir = "/var/lib/backup";
|
||||||
prometheus = true;
|
prometheus = true;
|
||||||
|
listenAddress = "127.0.0.1:8080";
|
||||||
};
|
};
|
||||||
networking = {
|
networking = {
|
||||||
firewall.enable = true;
|
firewall.enable = true;
|
||||||
firewall.allowedTCPPorts = [ 8000 ];
|
firewall.allowedTCPPorts = [ 80 443 ];
|
||||||
};
|
};
|
||||||
|
services.caddy = {
|
||||||
|
enable = true;
|
||||||
|
email = "lucazeau.alexandre@gmail.com";
|
||||||
|
config = ''
|
||||||
|
{
|
||||||
|
storage file_system {
|
||||||
|
root ${caddyDir}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
https://back.atlanticaweb.fr {
|
||||||
|
reverse_proxy http://127.0.0.1:8080
|
||||||
|
}
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
users.users.caddy = {
|
||||||
|
group = "caddy";
|
||||||
|
uid = config.ids.uids.caddy;
|
||||||
|
home = caddyDir;
|
||||||
|
createHome = true;
|
||||||
|
extraGroups = [ "users" ];
|
||||||
|
};
|
||||||
|
|
||||||
|
users.groups.caddy.gid = config.ids.uids.caddy;
|
||||||
}
|
}
|
||||||
|
|
Loading…
Reference in New Issue