nixos-configs/devices/cluster/modules/caddy.nix

165 lines
4.3 KiB
Nix
Raw Normal View History

2023-11-29 22:15:31 -05:00
{
caddy-plugins,
pkgs,
config,
...
}: let
inherit (config.vars) mainUser;
inherit (config.sops) secrets;
2023-11-29 22:15:31 -05:00
caddy = caddy-plugins.packages.${pkgs.system}.default;
2024-02-01 11:48:38 -05:00
clusterIP = config.services.pcsd.virtualIps.caddy-vip.ip;
2023-11-29 22:15:31 -05:00
in {
imports = [caddy-plugins.nixosModules.default];
# User stuff
2023-11-29 22:15:31 -05:00
environment.systemPackages = [caddy];
users.users.${mainUser}.extraGroups = ["caddy"];
2023-11-29 22:15:31 -05:00
systemd.services.caddy.serviceConfig = {
EnvironmentFile = secrets.caddy-cloudflare.path;
# For some reason the service
# doesn't shutdown normally
KillSignal = "SIGKILL";
RestartKillSignal = "SIGKILL";
};
2023-11-29 22:15:31 -05:00
services.caddy = {
enable = true;
enableReload = false;
package = caddy;
virtualHosts = let
dockerIP = "10.0.0.122";
jellyIP = "10.0.0.123";
servivi = "10.0.0.249";
in {
"nelim.org" = {
2023-11-29 22:15:31 -05:00
serverAliases = ["*.nelim.org"];
extraConfig = ''
tls {
2024-01-05 16:33:47 -05:00
dns cloudflare {$CLOUDFLARE_API_TOKEN}
2023-11-29 22:15:31 -05:00
resolvers 1.0.0.1
}
'';
subDomains = {
# Misc one-liners
2024-02-28 14:11:41 -05:00
vault.reverseProxy = "${servivi}:8781";
2024-02-28 12:45:17 -05:00
hauk.reverseProxy = "${servivi}:3003";
headscale.reverseProxy = "${clusterIP}:8085";
2023-11-29 22:15:31 -05:00
jelly.reverseProxy = "${jellyIP}:80";
# Resume builder
2024-02-28 13:17:20 -05:00
resume.reverseProxy = "${servivi}:3060";
resauth.reverseProxy = "${servivi}:3100";
2023-11-29 22:15:31 -05:00
# Nextcloud & Co
office.reverseProxy = "http://${servivi}:8055";
2023-11-29 22:15:31 -05:00
nextcloud = {
subDomainName = "cloud";
extraConfig = ''
redir /.well-known/carddav /remote.php/dav 301
redir /.well-known/caldav /remote.php/dav 301
redir /.well-known/webfinger /index.php/.well-known/webfinger 301
redir /.well-known/nodeinfo /index.php/.well-known/nodeinfo 301
'';
reverseProxy = "${servivi}:8042";
2023-11-29 22:15:31 -05:00
};
forgejo = {
subDomainName = "git";
2024-01-07 04:37:11 -05:00
reverseProxy = "${servivi}:3000";
2023-11-29 22:15:31 -05:00
};
nix-binary-cache = {
subDomainName = "cache";
reverseProxy = "${servivi}:5000";
};
2023-11-29 22:15:31 -05:00
calibre = {
subDomainName = "books";
reverseProxy = "${servivi}:8083";
2023-11-29 22:15:31 -05:00
};
immich = {
subDomainName = "photos";
2024-02-19 12:42:02 -05:00
reverseProxy = "${servivi}:2283";
2023-11-29 22:15:31 -05:00
};
# FreshRSS & Co
2024-02-28 12:31:40 -05:00
drss.reverseProxy = "${servivi}:3007";
2023-11-29 22:15:31 -05:00
freshrss = {
subDomainName = "rss";
2024-02-28 12:31:40 -05:00
reverseProxy = "${servivi}:2800";
2023-11-29 22:15:31 -05:00
};
jellyseer = {
subDomainName = "seerr";
reverseProxy = "${servivi}:5055";
2023-11-29 22:15:31 -05:00
};
2024-02-28 16:59:34 -05:00
gameyfin = {
subDomainName = "games";
reverseProxy = "${servivi}:8074";
};
2023-11-29 22:15:31 -05:00
2024-02-28 13:43:07 -05:00
wgui.reverseProxy = "${servivi}:51821";
2023-11-29 22:15:31 -05:00
lan = {
2024-02-18 00:15:37 -05:00
reverseProxy = "${servivi}:3020";
2023-11-29 22:15:31 -05:00
extraConfig = ''
redir /index.html /
'';
subDirectories = {
bazarr.reverseProxy = "${servivi}:6767";
2023-11-29 22:15:31 -05:00
bazarr-french = {
subDirName = "bafrr";
reverseProxy = "${servivi}:6766";
2023-11-29 22:15:31 -05:00
};
prowlarr.reverseProxy = "${servivi}:9696";
radarr.reverseProxy = "${servivi}:7878";
sabnzbd.reverseProxy = "${servivi}:8382";
sonarr.reverseProxy = "${servivi}:8989";
2023-11-29 22:15:31 -05:00
calibre = {
experimental = true;
reverseProxy = "${servivi}:8580";
2023-11-29 22:15:31 -05:00
};
qbittorent = {
subDirName = "qbt";
experimental = true;
2024-02-27 04:33:09 -05:00
reverseProxy = "${servivi}:8080";
2023-11-29 22:15:31 -05:00
};
vaultwarden = {
subDirName = "vault";
experimental = true;
2024-02-28 14:11:41 -05:00
reverseProxy = "${servivi}:8780";
2023-11-29 22:15:31 -05:00
};
};
};
# Top secret Business
joal.extraConfig = ''
route {
rewrite * /joal/ui{uri}
reverse_proxy * ${servivi}:5656
2023-11-29 22:15:31 -05:00
}
'';
joalws.extraConfig = ''
route {
reverse_proxy ${servivi}:5656
2023-11-29 22:15:31 -05:00
}
'';
};
};
};
};
}