diff options
-rw-r--r-- | hosts/vidhar/default.nix | 5 | ||||
-rw-r--r-- | hosts/vidhar/prometheus/default.nix | 2 |
2 files changed, 7 insertions, 0 deletions
diff --git a/hosts/vidhar/default.nix b/hosts/vidhar/default.nix index 69ca1403..d8f9cdb4 100644 --- a/hosts/vidhar/default.nix +++ b/hosts/vidhar/default.nix | |||
@@ -131,6 +131,8 @@ | |||
131 | 131 | ||
132 | access_log syslog:server=unix:/dev/log main; | 132 | access_log syslog:server=unix:/dev/log main; |
133 | error_log syslog:server=unix:/dev/log info; | 133 | error_log syslog:server=unix:/dev/log info; |
134 | |||
135 | client_body_temp_path /run/nginx-client-bodies; | ||
134 | ''; | 136 | ''; |
135 | upstreams.grafana = { | 137 | upstreams.grafana = { |
136 | servers = { "unix:${config.services.grafana.socket}" = {}; }; | 138 | servers = { "unix:${config.services.grafana.socket}" = {}; }; |
@@ -175,6 +177,9 @@ | |||
175 | serviceConfig = { | 177 | serviceConfig = { |
176 | ExecReload = lib.mkForce "${pkgs.coreutils}/bin/kill -HUP $MAINPID"; | 178 | ExecReload = lib.mkForce "${pkgs.coreutils}/bin/kill -HUP $MAINPID"; |
177 | LoadCredential = [ "selfsigned.key:${config.sops.secrets."selfsigned.key".path}" ]; | 179 | LoadCredential = [ "selfsigned.key:${config.sops.secrets."selfsigned.key".path}" ]; |
180 | |||
181 | RuntimeDirectory = lib.mkForce [ "nginx" "nginx-client-bodies" ]; | ||
182 | RuntimeDirectoryMode = "0750"; | ||
178 | }; | 183 | }; |
179 | }; | 184 | }; |
180 | 185 | ||
diff --git a/hosts/vidhar/prometheus/default.nix b/hosts/vidhar/prometheus/default.nix index 4a666e95..8d7b0fe8 100644 --- a/hosts/vidhar/prometheus/default.nix +++ b/hosts/vidhar/prometheus/default.nix | |||
@@ -400,6 +400,8 @@ in { | |||
400 | ssl_client_certificate ${./ca/ca.crt}; | 400 | ssl_client_certificate ${./ca/ca.crt}; |
401 | ssl_trusted_certificate ${./ca/ca.crt}; | 401 | ssl_trusted_certificate ${./ca/ca.crt}; |
402 | ssl_verify_client on; | 402 | ssl_verify_client on; |
403 | |||
404 | client_max_body_size 0; | ||
403 | ''; | 405 | ''; |
404 | locations."/" = { | 406 | locations."/" = { |
405 | proxyPass = "http://prometheus/"; | 407 | proxyPass = "http://prometheus/"; |