2023-11-04 22:20:49 +01:00
|
|
|
{ config, ... }:
|
2024-07-27 22:24:54 +02:00
|
|
|
|
2023-11-04 22:20:49 +01:00
|
|
|
{
|
|
|
|
services.nginx = {
|
|
|
|
enable = true;
|
|
|
|
|
|
|
|
virtualHosts = {
|
2024-07-27 22:24:54 +02:00
|
|
|
"esphome.ccchh.net" = {
|
|
|
|
forceSSL = true;
|
2023-11-04 22:20:49 +01:00
|
|
|
enableACME = true;
|
|
|
|
serverName = "esphome.ccchh.net";
|
|
|
|
|
|
|
|
listen = [
|
|
|
|
{
|
|
|
|
addr = "0.0.0.0";
|
2024-07-27 22:24:54 +02:00
|
|
|
port = 80;
|
|
|
|
}
|
|
|
|
{
|
|
|
|
addr = "[::]";
|
|
|
|
port = 80;
|
|
|
|
}
|
|
|
|
{
|
|
|
|
addr = "0.0.0.0";
|
|
|
|
port = 443;
|
|
|
|
ssl = true;
|
|
|
|
}
|
|
|
|
{
|
|
|
|
addr = "[::]";
|
|
|
|
port = 443;
|
|
|
|
ssl = true;
|
2023-11-04 22:20:49 +01:00
|
|
|
}
|
|
|
|
];
|
|
|
|
|
2024-07-27 22:24:54 +02:00
|
|
|
locations."/" = {
|
|
|
|
proxyPass = "http://${config.services.esphome.address}:${builtins.toString config.services.esphome.port}";
|
|
|
|
proxyWebsockets = true;
|
|
|
|
};
|
|
|
|
};
|
|
|
|
"esphome.z9.ccchh.net" = {
|
2023-11-04 22:20:49 +01:00
|
|
|
forceSSL = true;
|
|
|
|
useACMEHost = "esphome.ccchh.net";
|
2024-07-27 22:24:54 +02:00
|
|
|
serverName = "esphome.z9.ccchh.net";
|
2023-11-04 22:20:49 +01:00
|
|
|
|
|
|
|
listen = [
|
|
|
|
{
|
|
|
|
addr = "0.0.0.0";
|
|
|
|
port = 80;
|
|
|
|
}
|
2024-07-27 22:24:54 +02:00
|
|
|
{
|
|
|
|
addr = "[::]";
|
|
|
|
port = 80;
|
|
|
|
}
|
2023-11-04 22:20:49 +01:00
|
|
|
{
|
|
|
|
addr = "0.0.0.0";
|
|
|
|
port = 443;
|
|
|
|
ssl = true;
|
|
|
|
}
|
2024-07-27 22:24:54 +02:00
|
|
|
{
|
|
|
|
addr = "[::]";
|
|
|
|
port = 443;
|
|
|
|
ssl = true;
|
|
|
|
}
|
2023-11-04 22:20:49 +01:00
|
|
|
];
|
|
|
|
|
2024-07-27 22:24:54 +02:00
|
|
|
globalRedirect = "esphome.ccchh.net";
|
|
|
|
redirectCode = 307;
|
2023-11-04 22:20:49 +01:00
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
2024-07-27 22:24:54 +02:00
|
|
|
security.acme.certs."esphome.ccchh.net".extraDomainNames = [ "esphome.z9.ccchh.net" ];
|
2024-03-06 22:50:32 +01:00
|
|
|
|
2024-07-27 22:24:54 +02:00
|
|
|
networking.firewall.allowedTCPPorts = [ 80 443 ];
|
2023-11-04 22:20:49 +01:00
|
|
|
}
|