Reformat.

This commit is contained in:
Dmitry Voronin 2025-01-09 17:08:21 +03:00
parent cc23b6de16
commit 71560ca62f
Signed by: voronind
SSH key fingerprint: SHA256:3kBb4iV2ahufEBNq+vFbUe4QYfHt98DHQjN7QaptY9k
13 changed files with 69 additions and 51 deletions

View file

@ -102,7 +102,7 @@ in
};
"dasha" = {
path = "${cfg.dataDir}/dasha";
devices = ["home"] ++ allDashaDevices;
devices = [ "home" ] ++ allDashaDevices;
};
};
};

View file

@ -1,4 +1,5 @@
{ ... }: {
{ ... }:
{
config.const.host = {
nginx = {
domain = "voronind.com";

View file

@ -7,7 +7,9 @@ in
inherit (cfg) sslCertificate sslCertificateKey extraConfig;
locations."/" = {
proxyPass = "http://127.0.0.1:5001$request_uri";
extraConfig = cfg.allowLocal + ''
extraConfig =
cfg.allowLocal
+ ''
add_header Referrer-Policy 'origin';
'';
};

View file

@ -8,7 +8,9 @@ in
locations."/" = {
proxyPass = "http://[::1]:631$request_uri";
recommendedProxySettings = false;
extraConfig = cfg.allowLocal + ''
extraConfig =
cfg.allowLocal
+ ''
proxy_set_header Host "127.0.0.1";
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forward-For $proxy_add_x_forwarded_for;

View file

@ -8,7 +8,9 @@ in
locations."/" = {
proxyPass = "http://[::1]:8123$request_uri";
recommendedProxySettings = false;
extraConfig = cfg.allowLocal + ''
extraConfig =
cfg.allowLocal
+ ''
proxy_set_header Host $host;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;

View file

@ -7,7 +7,9 @@ in
inherit (cfg) sslCertificate sslCertificateKey extraConfig;
locations."/" = {
tryFiles = "$uri $uri/index.html";
extraConfig = cfg.allowLocal + ''
extraConfig =
cfg.allowLocal
+ ''
proxy_set_header Host "127.0.0.1";
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forward-For $proxy_add_x_forwarded_for;

View file

@ -7,7 +7,9 @@ in
inherit (cfg) sslCertificate sslCertificateKey extraConfig;
locations."/" = {
proxyPass = "http://[::1]:3001$request_uri";
extraConfig = cfg.allowLocal + ''
extraConfig =
cfg.allowLocal
+ ''
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header Host $host;
proxy_http_version 1.1;

View file

@ -5,7 +5,9 @@ in
{
"resume.${cfg.domain}" = {
inherit (cfg) sslCertificate sslCertificateKey extraConfig;
locations."/".extraConfig = cfg.allowLocal + ''
locations."/".extraConfig =
cfg.allowLocal
+ ''
if ($http_accept_language ~ ru) {
return 301 https://git.voronind.com/voronind/resume/releases/download/latest/VoronindRu.pdf;
}

View file

@ -9,7 +9,9 @@ in
locations = {
"~* /$" = {
inherit root;
extraConfig = cfg.allowLocal + ''
extraConfig =
cfg.allowLocal
+ ''
autoindex on;
'';
};

View file

@ -7,7 +7,9 @@ in
inherit (cfg) sslCertificate sslCertificateKey extraConfig;
locations."/" = {
proxyPass = "http://[::1]:8384$request_uri";
extraConfig = cfg.allowLocal + ''
extraConfig =
cfg.allowLocal
+ ''
proxy_set_header Host "localhost";
proxy_set_header X-Forwarded-Host "localhost";
'';

View file

@ -7,7 +7,9 @@ in
inherit (cfg) sslCertificate sslCertificateKey extraConfig;
locations."/" = {
proxyPass = "http://[::1]:33122$request_uri";
extraConfig = cfg.allowLocal + ''
extraConfig =
cfg.allowLocal
+ ''
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Forwarded-Proto https;

View file

@ -23,4 +23,3 @@
};
};
}

View file

@ -1,5 +1,5 @@
{ config, ... }: {
{ config, ... }:
{
# Specify current release version.
system.stateVersion = config.const.stateVersion;
}