X-Git-Url: https://git.immae.eu/?a=blobdiff_plain;f=modules%2Fprivate%2Fmonitoring%2Fstatus.nix;h=e0bc0e1c29611954c3fe00949575dbb481a7b693;hb=3ffa15baf832f5b94cfd8d1b978eaa42f4102e07;hp=ed4d6812857eca914ef7d6213fe8185cd164525d;hpb=6e9f30f4c63fddc5ce886b26b7e4e9ca23a93111;p=perso%2FImmae%2FConfig%2FNix.git diff --git a/modules/private/monitoring/status.nix b/modules/private/monitoring/status.nix index ed4d681..e0bc0e1 100644 --- a/modules/private/monitoring/status.nix +++ b/modules/private/monitoring/status.nix @@ -29,15 +29,20 @@ recommendedGzipSettings = true; recommendedProxySettings = true; virtualHosts."status.immae.eu" = { + acmeRoot = config.security.acme.certs."${name}".webroot; useACMEHost = name; forceSSL = true; locations."/".proxyPass = "http://unix:/run/naemon-status/socket.sock:/"; }; }; - security.acme.certs."${name}".extraDomains."status.immae.eu" = null; + security.acme.certs."${name}" = { + extraDomains."status.immae.eu" = null; + user = config.services.nginx.user; + group = config.services.nginx.group; + }; myServices.certificates.enable = true; - networking.firewall.allowedTCPPorts = [ 80 443 18000 ]; + networking.firewall.allowedTCPPorts = [ 80 443 ]; systemd.services.naemon-status = { description = "Naemon status"; after = [ "network.target" ];