{ pkgs, lib, config, ... }: let domain = "self-service.cloonar.com"; php = pkgs.php82; version = "1.5.2"; dataDir = "/var/www/${domain}"; in { environment.systemPackages = with pkgs; [ smarty3 ]; systemd.services."phpfpm-${domain}".serviceConfig.ProtectHome = lib.mkForce false; systemd.services.selfservicepassword_setup = let overrideConfig = pkgs.writeText "nextcloud-config.php" '' ${dataDir}/package.tar.gz /run/current-system/sw/bin/tar xf ${dataDir}/package.tar.gz -C ${dataDir} mv ${dataDir}/self-service-password-${version}/* ${dataDir}/public/ rm -rf ${dataDir}/self-service-password-${version} cp ${overrideConfig} ${dataDir}/public/conf/config.inc.local.php ''; path = [ pkgs.gzip pkgs.curl ]; serviceConfig.Type = "oneshot"; serviceConfig.User = domain; }; services.phpfpm.pools."${domain}" = { user = domain; settings = { "listen.owner" = config.services.nginx.user; "pm" = "dynamic"; "pm.max_children" = 32; "pm.max_requests" = 500; "pm.start_servers" = 2; "pm.min_spare_servers" = 2; "pm.max_spare_servers" = 5; "php_flag[display_errors]" = "on"; "php_admin_value[error_log]" = "/var/log/${domain}.error.log"; "php_admin_flag[log_errors]" = "on"; "php_value[include_path]" = ".:/usr/share/php:${pkgs.smarty3}"; "catch_workers_output" = "yes"; "access.log" = "/var/log/$pool.access.log"; }; phpPackage = php; phpEnv."PATH" = lib.makeBinPath [ php ]; }; services.nginx.virtualHosts."${domain}" = { forceSSL = true; enableACME = true; acmeRoot = null; root = "${dataDir}/public/htdocs"; locations."/favicon.ico".extraConfig = '' log_not_found off; access_log off; ''; # extraConfig = '' # if (!-e $request_filename) { # rewrite ^/(.+)\.(\d+)\.(php|js|css|png|jpg|gif|gzip)$ /$1.$3 last; # } # ''; locations."/".extraConfig = '' index index.php index.html; try_files $uri $uri/ /index.php$is_args$args; ''; locations."~ [^/]\.php(/|$)".extraConfig = '' fastcgi_split_path_info ^(.+?\.php)(/.*)$; if (!-f $document_root$fastcgi_script_name) { return 404; } include ${pkgs.nginx}/conf/fastcgi_params; include ${pkgs.nginx}/conf/fastcgi.conf; fastcgi_buffer_size 32k; fastcgi_buffers 8 16k; fastcgi_connect_timeout 240s; fastcgi_read_timeout 240s; fastcgi_send_timeout 240s; fastcgi_pass unix:${config.services.phpfpm.pools."${domain}".socket}; fastcgi_index index.php; ''; # locations."~ /\.".extraConfig = '' # log_not_found off; # deny all; # ''; # # locations."~ /scripts".extraConfig = '' # log_not_found off; # deny all; # ''; }; users.users."${domain}" = { #isSystemUser = true; isNormalUser = true; createHome = true; home = dataDir; homeMode= "770"; group = "nginx"; }; users.groups.${domain} = {}; }