1
0
Fork 0
dotfiles/container/webserver/default.nix

75 lines
1.9 KiB
Nix
Raw Normal View History

2022-07-30 22:36:06 +00:00
let
2022-07-31 13:10:28 +00:00
secret = import ../../secret/container/webserver;
custom-config = import ./config.nix { inherit secret; };
2022-07-30 22:36:06 +00:00
in
{
virtualisation.arion.projects.webserver.settings = {
services = {
2022-11-27 16:59:57 +00:00
mosquitto = {
2022-11-19 17:02:18 +00:00
service = {
2022-11-27 16:59:57 +00:00
image = "eclipse-mosquitto:2";
container_name = "mosquitto";
2022-11-19 17:02:18 +00:00
restart = "unless-stopped";
2022-11-27 16:59:57 +00:00
ports = [ "1883:1883" ];
user = "nobody";
volumes = [
"/etc/container-webserver/mosquitto:/mosquitto/config:ro"
];
2022-11-19 17:02:18 +00:00
labels = {
"com.centurylinklabs.watchtower.enable" = "true";
};
};
};
2022-07-31 14:40:01 +00:00
weewx = {
service = {
image = "ghcr.io/nifoc/weewx-docker:master";
2022-11-19 18:09:40 +00:00
container_name = "weewx";
2022-08-02 19:05:58 +00:00
restart = "unless-stopped";
2022-11-27 16:51:03 +00:00
depends_on = [ "mosquitto" ];
2022-12-26 16:53:21 +00:00
ports = [ "127.0.0.1:8000:8000" ];
2022-07-31 14:40:01 +00:00
environment = {
"TZ" = "Europe/Berlin";
};
volumes = [
"/etc/container-webserver/weewx:/data"
];
2023-02-19 22:34:09 +00:00
labels = {
"com.centurylinklabs.watchtower.enable" = "true";
};
2023-01-22 12:47:36 +00:00
};
};
2022-07-30 22:36:06 +00:00
};
};
2023-03-06 21:20:26 +00:00
services.nginx.virtualHosts."${secret.container.webserver.hostname}" = {
http3 = true;
root = "/etc/container-webserver/weewx/html/wdc";
forceSSL = true;
useACMEHost = "kempkens.io";
2023-03-06 21:21:22 +00:00
extraConfig = ''
index index.html;
2023-03-06 22:39:49 +00:00
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
2023-03-06 21:21:22 +00:00
'';
2023-03-06 21:22:15 +00:00
locations."~* \.html$".extraConfig = ''
2023-03-06 21:20:26 +00:00
expires modified 120s;
'';
2023-03-06 21:22:15 +00:00
locations."~* \.(js|css)$".extraConfig = ''
2023-03-06 21:20:26 +00:00
expires 1h;
'';
locations."~ ^/dwd/(icons|warn_icons)/" = {
recommendedProxySettings = true;
proxyPass = "http://127.0.0.1:8000";
};
2023-03-06 21:22:15 +00:00
locations."~ ^/dwd/[\w]+\.(gif|png)".extraConfig = ''
2023-03-06 21:20:26 +00:00
expires modified 1h;
'';
};
} // custom-config