fix: change acme handling
This commit is contained in:
@@ -94,6 +94,7 @@ in
|
|||||||
|
|
||||||
services.nginx.enable = true;
|
services.nginx.enable = true;
|
||||||
services.nginx.virtualHosts."${domain}" = {
|
services.nginx.virtualHosts."${domain}" = {
|
||||||
|
enableACME = true;
|
||||||
forceSSL = true;
|
forceSSL = true;
|
||||||
extraConfig = ''
|
extraConfig = ''
|
||||||
proxy_buffering off;
|
proxy_buffering off;
|
||||||
@@ -111,7 +112,6 @@ in
|
|||||||
|
|
||||||
security.acme.certs."${domain}" = {
|
security.acme.certs."${domain}" = {
|
||||||
group = "ssl-users";
|
group = "ssl-users";
|
||||||
allowKeysForGroup = true;
|
|
||||||
};
|
};
|
||||||
|
|
||||||
users.groups.ssl-users = {};
|
users.groups.ssl-users = {};
|
||||||
|
|||||||
Reference in New Issue
Block a user