mirror of
https://github.com/foo-dogsquared/nixos-config.git
synced 2025-01-31 04:58:01 +00:00
hosts/plover: update Wezterm mux server config
This should also fix the ACME certificate self-signed permissions error since there is no `wezterm` group (or user). We're just using systemd's dynamic user feature in our service.
This commit is contained in:
parent
9d75a4101f
commit
187b32e7bb
@ -1,7 +1,7 @@
|
|||||||
return {
|
return {
|
||||||
tls_servers = {
|
tls_servers = {
|
||||||
pem_private_key = "@CERT_DIR@/key.pem",
|
pem_private_key = os.getenv("CREDENTIALS_DIRECTORY") .. "/key.pem",
|
||||||
pem_cert = "@CERT_DIR@/cert.pem",
|
pem_cert = os.getenv("CREDENTIALS_DIRECTORY") .. "/cert.pem",
|
||||||
pem_ca = "@CERT_DIR@/fullchain.pem",
|
pem_ca = os.getenv("CREDENTIALS_DIRECTORY") .. "/fullchain.pem",
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
@ -3,21 +3,26 @@
|
|||||||
# We're setting up Wezterm mux server with TLS domains.
|
# We're setting up Wezterm mux server with TLS domains.
|
||||||
let
|
let
|
||||||
weztermDomain = "mux.${config.networking.domain}";
|
weztermDomain = "mux.${config.networking.domain}";
|
||||||
configFile = pkgs.substituteAll {
|
|
||||||
src = ../../config/wezterm/config.lua;
|
|
||||||
CERT_DIR = config.security.acme.certs."${weztermDomain}".directory;
|
|
||||||
};
|
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
services.wezterm-mux-server = {
|
services.wezterm-mux-server = {
|
||||||
inherit configFile;
|
|
||||||
enable = true;
|
enable = true;
|
||||||
|
configFile = ../../config/wezterm/config.lua;
|
||||||
};
|
};
|
||||||
|
|
||||||
security.acme.certs."${weztermDomain}" = {
|
systemd.services.wezterm-mux-server.serviceConfig = {
|
||||||
group = "wezterm";
|
LoadCredential = let
|
||||||
postRun = ''
|
certDir = config.security.acme.certs."${weztermDomain}".directory;
|
||||||
|
credentialCertPath = path: "${path}:${certDir}/${path}";
|
||||||
|
in
|
||||||
|
[
|
||||||
|
(credentialCertPath "key.pem")
|
||||||
|
(credentialCertPath "cert.pem")
|
||||||
|
(credentialCertPath "fullchain.pem")
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
security.acme.certs."${weztermDomain}".postRun = ''
|
||||||
systemctl restart wezterm-mux-server.service
|
systemctl restart wezterm-mux-server.service
|
||||||
'';
|
'';
|
||||||
};
|
|
||||||
}
|
}
|
||||||
|
Loading…
Reference in New Issue
Block a user