chore: move ssl creds to agenix
Some checks failed
/ test (push) Failing after 3m51s

This commit is contained in:
nydragon 2025-03-10 18:39:10 +01:00
parent 5e4969dc7b
commit 6cd5beda6a
Signed by: nydragon
SSH key fingerprint: SHA256:WcjW5NJPQ8Dx4uQDmoIlVPLWE27Od3fxoe0IUvuoPHE
2 changed files with 14 additions and 7 deletions

View file

@ -26,7 +26,10 @@ in
group = "rustypaste"; group = "rustypaste";
}; };
forgejo-runner-token.file = ../../secrets/forgejo-runner-token.age; forgejo-runner-token.file = ../../secrets/forgejo-runner-token.age;
acme.file = ../../secrets/acme.age; acme = {
owner = if config.security.acme.useRoot then "root" else "acme";
file = ../../secrets/acme.age;
};
}; };
boot.loader.grub = { boot.loader.grub = {
@ -96,11 +99,12 @@ in
polkit.enable = true; polkit.enable = true;
acme = { acme = {
defaults.email = "admin@ccnlc.eu";
acceptTerms = true; acceptTerms = true;
dnsProvider = "ovh"; defaults = {
environmentFile = config.age.secrets.acme.path; email = "contact@ccnlc.eu";
dnsProvider = "ovh";
environmentFile = config.age.secrets.acme.path;
};
}; };
}; };

View file

@ -27,7 +27,10 @@
file = ../../secrets/freshrss-default-password.age; file = ../../secrets/freshrss-default-password.age;
owner = config.services.freshrss.user; owner = config.services.freshrss.user;
}; };
acme.file = ../../secrets/acme.age; acme = {
owner = if config.security.acme.useRoot then "root" else "acme";
file = ../../secrets/acme.age;
};
}; };
boot.loader.grub = { boot.loader.grub = {
@ -162,7 +165,7 @@
enable = true; enable = true;
recommendedProxySettings = true; recommendedProxySettings = true;
recommendedTlsSettings = true; recommendedTlsSettings = true;
clientMaxBodySize = "2000M"; clientMaxBodySize = "0";
virtualHosts = virtualHosts =
let let
mkVHLocal = mkVH "http://localhost"; mkVHLocal = mkVH "http://localhost";