mirror of
https://github.com/foo-dogsquared/nixos-config.git
synced 2025-01-31 04:58:01 +00:00
chore: reformat the codebase
This commit is contained in:
parent
ae787f8fcc
commit
1c609f5e95
@ -26,17 +26,22 @@ rec {
|
||||
ipv6Gateway = "fe80::1";
|
||||
in
|
||||
{
|
||||
# This is the public-facing interface. Any interface name with a prime
|
||||
# symbol means it's a public-facing interface.
|
||||
main' = {
|
||||
# The gateways for the public addresses are retrieved from the following
|
||||
# pages:
|
||||
#
|
||||
# * https://docs.hetzner.com/cloud/networks/faq/#are-any-ip-addresses-reserved
|
||||
# * https://docs.hetzner.com/robot/dedicated-server/ip/additional-ip-adresses/#gateway
|
||||
IPv4 = {
|
||||
address = "65.109.224.213";
|
||||
gateway = "172.31.1.1";
|
||||
# This is the public-facing interface. Any interface name with a prime
|
||||
# symbol means it's a public-facing interface.
|
||||
main' = {
|
||||
# The gateways for the public addresses are retrieved from the following
|
||||
# pages:
|
||||
#
|
||||
# * https://docs.hetzner.com/cloud/networks/faq/#are-any-ip-addresses-reserved
|
||||
# * https://docs.hetzner.com/robot/dedicated-server/ip/additional-ip-adresses/#gateway
|
||||
IPv4 = {
|
||||
address = "65.109.224.213";
|
||||
gateway = "172.31.1.1";
|
||||
};
|
||||
IPv6 = {
|
||||
address = "2a01:4f9:c012:607a::1";
|
||||
gateway = ipv6Gateway;
|
||||
};
|
||||
};
|
||||
|
||||
internal = {
|
||||
|
@ -47,7 +47,8 @@ let
|
||||
domainZoneFile' = "/etc/coredns/zones/${domain}.zone";
|
||||
in
|
||||
{
|
||||
sops.secrets = let
|
||||
sops.secrets =
|
||||
let
|
||||
getKey = key: {
|
||||
inherit key;
|
||||
sopsFile = ../../secrets/secrets.yaml;
|
||||
@ -58,8 +59,8 @@ in
|
||||
lib.nameValuePair
|
||||
"plover/${secret}"
|
||||
((getKey secret) // config))
|
||||
secrets;
|
||||
in
|
||||
secrets;
|
||||
in
|
||||
getSecrets {
|
||||
"dns/mailbox-security-key" = { };
|
||||
"dns/mailbox-security-key-record" = { };
|
||||
|
@ -78,13 +78,14 @@ in
|
||||
|
||||
# This is based from the reverse proxy guide from the official
|
||||
# documentation at https://www.keycloak.org/server/reverseproxy.
|
||||
locations = let
|
||||
keycloakPath = path: "http://${host}:${toString config.services.keycloak.settings.http-port}";
|
||||
in
|
||||
lib.listToAttrs
|
||||
(lib.lists.map
|
||||
(appPath: lib.nameValuePair appPath { proxyPass = keycloakPath appPath; })
|
||||
[ "/js/" "/realms/" "/resources/" "/robots.txt" ]);
|
||||
locations =
|
||||
let
|
||||
keycloakPath = path: "http://${host}:${toString config.services.keycloak.settings.http-port}";
|
||||
in
|
||||
lib.listToAttrs
|
||||
(lib.lists.map
|
||||
(appPath: lib.nameValuePair appPath { proxyPass = keycloakPath appPath; })
|
||||
[ "/js/" "/realms/" "/resources/" "/robots.txt" ]);
|
||||
};
|
||||
|
||||
"${authInternalDomain}" = {
|
||||
|
@ -71,11 +71,13 @@ in
|
||||
{
|
||||
routeConfig = {
|
||||
Gateway = wireguardPeers.server.IPv4;
|
||||
Destination = let
|
||||
ip = lib.strings.splitString "." wireguardPeers.server.IPv4;
|
||||
properRange = lib.lists.take 3 ip ++ [ "0" ];
|
||||
ip' = lib.concatStringsSep "." properRange;
|
||||
in "${ip'}/16";
|
||||
Destination =
|
||||
let
|
||||
ip = lib.strings.splitString "." wireguardPeers.server.IPv4;
|
||||
properRange = lib.lists.take 3 ip ++ [ "0" ];
|
||||
ip' = lib.concatStringsSep "." properRange;
|
||||
in
|
||||
"${ip'}/16";
|
||||
};
|
||||
}
|
||||
];
|
||||
|
Loading…
Reference in New Issue
Block a user