summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorGregor Kleen <gkleen@yggdrasil.li>2022-01-31 17:58:52 +0100
committerGregor Kleen <gkleen@yggdrasil.li>2022-01-31 17:58:52 +0100
commitefad24c66648dbfdd703c39bf2d36307476b6ef4 (patch)
treea001872f7e18d177490df339454bd11fd9ab5b2a
parent2472b98524f5bbfe40f456077f635eb24ab382da (diff)
downloadnixos-efad24c66648dbfdd703c39bf2d36307476b6ef4.tar
nixos-efad24c66648dbfdd703c39bf2d36307476b6ef4.tar.gz
nixos-efad24c66648dbfdd703c39bf2d36307476b6ef4.tar.bz2
nixos-efad24c66648dbfdd703c39bf2d36307476b6ef4.tar.xz
nixos-efad24c66648dbfdd703c39bf2d36307476b6ef4.zip
...
-rw-r--r--hosts/surtr/http.nix7
1 files changed, 5 insertions, 2 deletions
diff --git a/hosts/surtr/http.nix b/hosts/surtr/http.nix
index 032b1fa5..6edc1466 100644
--- a/hosts/surtr/http.nix
+++ b/hosts/surtr/http.nix
@@ -50,7 +50,7 @@
50 virtualHosts = { 50 virtualHosts = {
51 "webdav.141.li" = { 51 "webdav.141.li" = {
52 forceSSL = true; 52 forceSSL = true;
53 sslCertificate = "${config.security.acme.certs."webdav.141.li".directory}/fullchain.pem"; 53 sslCertificate = "/run/credentials/nginx.service/webdav.141.li.pem";
54 sslCertificateKey = "/run/credentials/nginx.service/webdav.141.li.key.pem"; 54 sslCertificateKey = "/run/credentials/nginx.service/webdav.141.li.key.pem";
55 locations."/" = { 55 locations."/" = {
56 proxyPass = "http://webdav/"; 56 proxyPass = "http://webdav/";
@@ -69,7 +69,10 @@
69 systemd.services.nginx = { 69 systemd.services.nginx = {
70 preStart = lib.mkForce config.services.nginx.preStart; 70 preStart = lib.mkForce config.services.nginx.preStart;
71 serviceConfig = { 71 serviceConfig = {
72 LoadCredential = [ "webdav.141.li.key.pem:${config.security.acme.certs."webdav.141.li".directory}/key.pem" ]; 72 LoadCredential = [
73 "webdav.141.li.key.pem:${config.security.acme.certs."webdav.141.li".directory}/key.pem"
74 "webdav.141.li.pem:${config.security.acme.certs."webdav.141.li".directory}/fullchain.pem"
75 ];
73 }; 76 };
74 }; 77 };
75 }; 78 };