add web-01 host
This commit is contained in:
89
hosts/web-01.cloonar.com/sites/autoconfig.nix
Normal file
89
hosts/web-01.cloonar.com/sites/autoconfig.nix
Normal file
@@ -0,0 +1,89 @@
|
||||
{ pkgs, lib, config, ... }:
|
||||
let
|
||||
domains = [
|
||||
"cloonar.com"
|
||||
"ghetto.at"
|
||||
"optiprot.eu"
|
||||
];
|
||||
|
||||
vhostConfig = {
|
||||
forceSSL = true;
|
||||
enableACME = true;
|
||||
acmeRoot = null;
|
||||
root = "/var/www/autoconfig";
|
||||
|
||||
# MS Outlook
|
||||
locations."~* ^/autodiscover/autodiscover.xml".extraConfig = ''
|
||||
root /var/www/autoconfig;
|
||||
try_files /autodiscover.php =404;
|
||||
include ${pkgs.nginx}/conf/fastcgi_params;
|
||||
include ${pkgs.nginx}/conf/fastcgi.conf;
|
||||
fastcgi_pass unix:${config.services.phpfpm.pools.autoconfig.socket};
|
||||
'';
|
||||
|
||||
# Thunderbird
|
||||
locations."/.well-known/autoconfig/mail/config-v1.1.xml".extraConfig = ''
|
||||
root /var/www/autoconfig;
|
||||
try_files /config-v1.1.php =404;
|
||||
include ${pkgs.nginx}/conf/fastcgi_params;
|
||||
include ${pkgs.nginx}/conf/fastcgi.conf;
|
||||
fastcgi_pass unix:${config.services.phpfpm.pools.autoconfig.socket};
|
||||
'';
|
||||
|
||||
# Apple devices
|
||||
locations."/apple/get-mobileconfig".extraConfig = ''
|
||||
root /var/www/autoconfig;
|
||||
try_files /apple.php =404;
|
||||
include ${pkgs.nginx}/conf/fastcgi_params;
|
||||
include ${pkgs.nginx}/conf/fastcgi.conf;
|
||||
fastcgi_pass unix:${config.services.phpfpm.pools.autoconfig.socket};
|
||||
'';
|
||||
|
||||
# disable logging for Apple Touch Icons
|
||||
locations."~ /apple-touch-icon(|-\d+x\d+)(|-precomposed).png".extraConfig = ''
|
||||
log_not_found off;
|
||||
access_log off;
|
||||
'';
|
||||
};
|
||||
in
|
||||
{
|
||||
services.nginx.virtualHosts."autoconfig.cloonar.com" = vhostConfig;
|
||||
services.nginx.virtualHosts."autoconfig.ghetto.at" = vhostConfig;
|
||||
services.nginx.virtualHosts."autoconfig.optiprot.eu" = vhostConfig;
|
||||
services.nginx.virtualHosts."autoconfig.superbros.tv" = vhostConfig;
|
||||
|
||||
systemd.services."phpfpm-autoconfig".serviceConfig.ProtectHome = lib.mkForce false;
|
||||
|
||||
services.phpfpm.pools."autoconfig" = {
|
||||
user = "autoconfig";
|
||||
settings = {
|
||||
"listen.owner" = config.services.nginx.user;
|
||||
"pm" = "dynamic";
|
||||
"pm.max_children" = 32;
|
||||
"pm.max_requests" = 500;
|
||||
"pm.start_servers" = 2;
|
||||
"pm.min_spare_servers" = 2;
|
||||
"pm.max_spare_servers" = 5;
|
||||
"php_admin_value[error_log]" = "stderr";
|
||||
"php_admin_flag[log_errors]" = true;
|
||||
"catch_workers_output" = true;
|
||||
"access.log" = "/var/log/$pool.access.log";
|
||||
};
|
||||
phpPackage = pkgs.php;
|
||||
phpEnv."PATH" = lib.makeBinPath [ pkgs.php ];
|
||||
};
|
||||
|
||||
users.users."autoconfig" = {
|
||||
#isSystemUser = true;
|
||||
isNormalUser = true;
|
||||
createHome = true;
|
||||
home = "/var/www/autoconfig";
|
||||
homeMode= "770";
|
||||
#home = "/home/${domain}";
|
||||
group = "nginx";
|
||||
openssh.authorizedKeys.keys = [
|
||||
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDZg6mxd6kuB7zxxTMw/kgP2Cfddjnz8hCtSbzKckNBtM9TbnJ76ZbAjgh/TDcm/qBADlICi+Ib0tMlzK1BJWLxe1SjHOR78BPzPGASmjtj6vuNAFyM20Ise5rhbbo2sC6o82F6HP4iak+hFzhwTf0Ld1LT5dJ78CltKgHFmyKIaRYBILn5MvTnmORG2UfFY1Tef2DiujrQD24bM2f4BYR2Ni0zoyim8UUkjciQkXceB8yDJQX/e1WcNxGU7Bsh2WGZMu6Ykeinbf7LIu8pPGH2sf81N8tbsYc4PxZv9lovgRWdNNmSfB+Ocsn4jWBN9nVtb8XMXycTaenI4W57F+ZWrx0LddPhwfXbLAdFgxyvqtWW/WF48DH2vETQcCATowIhtU7QDZ3pDKaTIIYhDYnMvPJuM2rQP0SCMaNzQlziXWFvKTRw8nnqkpzTz488OJVkYvULXhiRgr0Uxe6eh7XCOO9SF5wdj1cGeewefOiOjpxmg/GnaQvQW6KjFRMj1ZE="
|
||||
];
|
||||
};
|
||||
users.groups.autoconfig = {};
|
||||
}
|
||||
Reference in New Issue
Block a user