moved firewall and acme
This commit is contained in:
parent
b639a6cd85
commit
c76fcf6f92
|
@ -128,8 +128,19 @@
|
||||||
services.openssh.enable = true;
|
services.openssh.enable = true;
|
||||||
services.openssh.settings.PasswordAuthentication = false;
|
services.openssh.settings.PasswordAuthentication = false;
|
||||||
# services.openssh.settings.PermitRootLogin = "proh";
|
# services.openssh.settings.PermitRootLogin = "proh";
|
||||||
|
security.acme = {
|
||||||
|
acceptTerms = true;
|
||||||
|
defaults = {
|
||||||
|
email = "glennpub@proton.me";
|
||||||
|
dnsProvider = "cloudflare";
|
||||||
|
# # location of your CLOUDFLARE_DNS_API_TOKEN=[value]
|
||||||
|
# # https://www.freedesktop.org/software/systemd/man/latest/systemd.exec.html#EnvironmentFile=
|
||||||
|
environmentFile = "/etc/nixos/.secrets/cloudflare_dns_tokend";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
# Open ports in the firewall.
|
# Open ports in the firewall.
|
||||||
|
networking.firewall.allowedTCPPorts = [ 80 443 ];
|
||||||
# networking.firewall.allowedTCPPorts = [ ... ];
|
# networking.firewall.allowedTCPPorts = [ ... ];
|
||||||
# networking.firewall.allowedUDPPorts = [ ... ];
|
# networking.firewall.allowedUDPPorts = [ ... ];
|
||||||
# Or disable the firewall altogether.
|
# Or disable the firewall altogether.
|
||||||
|
|
11
forgejo.nix
11
forgejo.nix
|
@ -5,17 +5,6 @@ let
|
||||||
# derp = "hi";
|
# derp = "hi";
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
security.acme = {
|
|
||||||
acceptTerms = true;
|
|
||||||
defaults = {
|
|
||||||
email = "glennpub@proton.me";
|
|
||||||
dnsProvider = "cloudflare";
|
|
||||||
# # location of your CLOUDFLARE_DNS_API_TOKEN=[value]
|
|
||||||
# # https://www.freedesktop.org/software/systemd/man/latest/systemd.exec.html#EnvironmentFile=
|
|
||||||
environmentFile = "/etc/nixos/.secrets/cloudflare_dns_tokend";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
networking.firewall.allowedTCPPorts = [ 80 443 3000 ];
|
|
||||||
services.forgejo = {
|
services.forgejo = {
|
||||||
enable = true;
|
enable = true;
|
||||||
settings = {
|
settings = {
|
||||||
|
|
Loading…
Reference in a new issue