Add forge server, clean up common nginx configuration, and update for

latest nixos configuration expectations
This commit is contained in:
Haak Saxberg 2025-01-04 09:50:53 -08:00
parent c5de48b167
commit 8b74198e4d
8 changed files with 99 additions and 33 deletions

View file

@ -22,16 +22,7 @@
# 2. override default hardening measure from NixOS - this is default since 22.05
systemd.services.jellyfin.serviceConfig.PrivateDevices = lib.mkForce false;
security.acme.acceptTerms = true;
security.acme.defaults.email = lib.strings.fileContents ../../../../secrets/letsencrypt/mediaserver/email;
services.nginx = {
enable = true;
recommendedGzipSettings = true;
recommendedOptimisation = true;
recommendedProxySettings = true;
recommendedTlsSettings = true;
virtualHosts."${lib.strings.fileContents ../../../../secrets/letsencrypt/mediaserver/domain}" = {
forceSSL = true;
enableACME = true;