Separate user identity (data) from the reusable modules, and let a host declare any number of users instead of exactly one. - users/registry.nix: per-user identity (name, email, groups, authorized and signing keys) as the single source of identity; no user data is hardcoded in the modules. - mkHost takes a `users` set keyed by username; per-user identity is injected into each home config via the `identity` module arg (extraSpecialArgs is per-host, so it cannot carry per-user data). - modules/users.nix builds accounts from the registry; modules/ssh.nix no longer defines authorized keys (the registry owns them); home/git.nix and home/desktop.nix read `identity`; users/emmathorpe/work.nix drops its now-redundant git identity override. - Restructure the tree: users/, home/, modules/, hosts/, lib/ replace the former lyrathorpe/ and system/ layout. - Add standalone homeConfigurations (the portable subset: shell, git, editor, claude) and an exported homeModules output for use on machines not managed by this flake, or as an input to other flakes. Behaviour-preserving for existing hosts: lyrathorpe-mbp and emmathorpe-edaas evaluate to identical derivations; lyrathorpe-t400, lyrathorpe-macpro31 and lyrathorpe-rpi5 differ only by de-duplicating a repeated authorized_keys entry. Fixes the SSH authorized-key leak (one user's key was applied to every account), the hardcoded default git identity, and the hardcoded EDaaS linger setting.
40 lines
1.5 KiB
Nix
40 lines
1.5 KiB
Nix
# Native nginx reverse proxy. The proxy configuration is declarative Nix:
|
|
# every proxied service is an entry under services.nginx.virtualHosts, so the
|
|
# whole routing table lives in this file and is built/version-controlled with
|
|
# the rest of the system.
|
|
#
|
|
# To add a proxied service, add another virtualHosts."<host>" entry following
|
|
# the example below. To serve it over HTTPS, uncomment enableACME + forceSSL on
|
|
# that vhost once it has a real DNS name and the ACME HTTP-01/DNS-01 challenge
|
|
# can be satisfied (see security.acme for the account/email and DNS settings).
|
|
{ ... }:
|
|
{
|
|
services.nginx = {
|
|
enable = true;
|
|
recommendedProxySettings = true; # sane proxy_set_header defaults (Host, X-Forwarded-*)
|
|
recommendedTlsSettings = true;
|
|
recommendedOptimisation = true;
|
|
recommendedGzipSettings = true;
|
|
|
|
virtualHosts = {
|
|
# Example reverse-proxy vhost. Replace the name and upstream with a real
|
|
# service (e.g. a container published by the Docker host on this machine).
|
|
"example.lan" = {
|
|
# enableACME = true; # request a Let's Encrypt cert for this host
|
|
# forceSSL = true; # redirect HTTP -> HTTPS once the cert exists
|
|
locations."/" = {
|
|
proxyPass = "http://127.0.0.1:8080";
|
|
proxyWebsockets = true; # forward Upgrade/Connection for WebSocket apps
|
|
};
|
|
};
|
|
};
|
|
};
|
|
|
|
# Public reverse-proxy ports. 443 is opened now so flipping a vhost to TLS
|
|
# needs no firewall change.
|
|
networking.firewall.allowedTCPPorts = [
|
|
80
|
|
443
|
|
];
|
|
}
|