diff --git a/config/hosts/public-web-static/virtualHosts/didays.de.nix b/config/hosts/public-web-static/virtualHosts/didays.de.nix index 6874e4f..ab3cc7b 100644 --- a/config/hosts/public-web-static/virtualHosts/didays.de.nix +++ b/config/hosts/public-web-static/virtualHosts/didays.de.nix @@ -5,10 +5,15 @@ let dataDir = "/var/www/${domain}"; deployUser = "didays-deploy"; in { + security.acme.certs."${domain}".extraDomainNames = [ "www.${domain}" ]; + services.nginx.virtualHosts = { "acme-${domain}" = { enableACME = true; serverName = "${domain}"; + serverAliases = [ + "www.${domain}" + ]; listen = [ { @@ -22,6 +27,41 @@ in { ]; }; + "www.${domain}" = { + forceSSL = true; + useACMEHost = "${domain}"; + + listen = [ + { + addr = "[::]"; + port = 8443; + ssl = true; + proxyProtocol = true; + } + { + addr = "0.0.0.0"; + port = 8443; + ssl = true; + proxyProtocol = true; + } + ]; + + locations."/" = { + return = "302 https://didays.de$request_uri"; + }; + + extraConfig = '' + # Make use of the ngx_http_realip_module to set the $remote_addr and + # $remote_port to the client address and client port, when using proxy + # protocol. + # First set our proxy protocol proxy as trusted. + set_real_ip_from 172.31.17.140; + # Then tell the realip_module to get the addreses from the proxy protocol + # header. + real_ip_header proxy_protocol; + ''; + }; + "${domain}" = { forceSSL = true; useACMEHost = "${domain}";