X-Git-Url: https://git.immae.eu/?a=blobdiff_plain;f=nixops%2Fmodules%2Fwebsites%2Fdefault.nix;h=228966f77b208a717969aeeb10217d7efa433855;hb=46f30ecca2e18c5abc7b270656e2b24f40e029ea;hp=3db1cfac325dd2479b3075ec1b8c7ae53b704082;hpb=0eaac6ba283159841da70fdfd74cb0ef7c6203ab;p=perso%2FImmae%2FConfig%2FNix.git diff --git a/nixops/modules/websites/default.nix b/nixops/modules/websites/default.nix index 3db1cfa..228966f 100644 --- a/nixops/modules/websites/default.nix +++ b/nixops/modules/websites/default.nix @@ -1,6 +1,8 @@ { lib, pkgs, config, mylibs, myconfig, ... }: let cfg = config.services.myWebsites; + www_root = "/run/current-system/webapps/_www"; + theme_root = "/run/current-system/webapps/_theme"; makeService = name: cfg: let toVhost = vhostConf: { enableSSL = true; @@ -8,22 +10,20 @@ let sslServerKey = "/var/lib/acme/${vhostConf.certName}/key.pem"; sslServerChain = "/var/lib/acme/${vhostConf.certName}/fullchain.pem"; logFormat = "combinedVhost"; - listen = [ - { ip = cfg.ip; port = 443; } - ]; + listen = map (ip: { inherit ip; port = 443; }) cfg.ips; hostName = builtins.head vhostConf.hosts; serverAliases = builtins.tail vhostConf.hosts or []; documentRoot = vhostConf.root; extraConfig = builtins.concatStringsSep "\n" vhostConf.extraConfig; }; nosslVhost = { - listen = [ { ip = cfg.ip; port = 80; } ]; + listen = map (ip: { inherit ip; port = 80; }) cfg.ips; hostName = "nossl.immae.eu"; enableSSL = false; logFormat = "combinedVhost"; - documentRoot = ../../www; + documentRoot = www_root; extraConfig = '' - + DirectoryIndex nossl.html AllowOverride None Require all granted @@ -34,7 +34,7 @@ let ''; }; redirectVhost = { # Should go last, catchall http -> https redirect - listen = [ { ip = cfg.ip; port = 80; } ]; + listen = map (ip: { inherit ip; port = 80; }) cfg.ips; hostName = "redirectSSL"; serverAliases = [ "*" ]; enableSSL = false; @@ -52,14 +52,12 @@ let fallbackVhost = toVhost { # Should go first, default choice certName = "eldiron"; hosts = ["eldiron.immae.eu" ]; - root = ../../www; + root = www_root; extraConfig = [ "DirectoryIndex index.htm" ]; }; in rec { enable = true; - listen = [ - { ip = cfg.ip; port = 443; } - ]; + listen = map (ip: { inherit ip; port = 443; }) cfg.ips; stateDir = "/run/httpd_${name}"; logPerVirtualHost = true; multiProcessingModule = "worker"; @@ -72,12 +70,15 @@ let ++ (pkgs.lib.attrsets.mapAttrsToList (n: v: toVhost v) cfg.vhostConfs) ++ [ redirectVhost ]; }; - makeServiceOptions = name: ip: { + makeServiceOptions = name: { enable = lib.mkEnableOption "enable websites in ${name}"; - ip = lib.mkOption { - type = lib.types.string; - default = ip; - description = "${name} ip to listen to"; + ips = lib.mkOption { + type = lib.types.listOf lib.types.string; + default = let + ips = myconfig.env.servers.eldiron.ips.${name}; + in + [ips.ip4] ++ (ips.ip6 or []); + description = "${name} ips to listen to"; }; modules = lib.mkOption { type = lib.types.listOf (lib.types.str); @@ -141,9 +142,9 @@ in ]; options.services.myWebsites = { - production = makeServiceOptions "production" myconfig.ips.production; - integration = makeServiceOptions "integration" myconfig.ips.integration; - tools = makeServiceOptions "tools" myconfig.ips.main; + production = makeServiceOptions "production"; + integration = makeServiceOptions "integration"; + tools = makeServiceOptions "main"; apacheConfig = lib.mkOption { type = lib.types.attrsOf (lib.types.submodule { @@ -165,22 +166,12 @@ in }; config = { - networking = { - firewall = { - enable = true; - allowedTCPPorts = [ 80 443 ]; - }; - interfaces."eth0".ipv4.addresses = [ - # 176.9.151.89 declared in nixops -> infra / tools - { address = myconfig.ips.production; prefixLength = 32; } - { address = myconfig.ips.integration; prefixLength = 32; } - ]; - }; + networking.firewall.allowedTCPPorts = [ 80 443 ]; - nixpkgs.config.packageOverrides = oldpkgs: rec { + nixpkgs.overlays = [ (self: super: rec { php = php72; - php72 = (oldpkgs.php72.override { - mysql.connector-c = pkgs.mariadb; + php72 = (super.php72.override { + mysql.connector-c = self.mariadb; config.php.mysqlnd = false; config.php.mysqli = false; }).overrideAttrs(old: rec { @@ -194,11 +185,11 @@ in # ext/mysqli/mysqli.c ext/mysqli/mysqli_prop.c # ''; }); - phpPackages = oldpkgs.php72Packages.override { inherit php; }; + phpPackages = super.php72Packages.override { inherit php; }; composerEnv = import ./commons/composer-env.nix { - inherit (pkgs) stdenv writeTextFile fetchurl php unzip; + inherit (self) stdenv writeTextFile fetchurl php unzip; }; - }; + }) ]; services.myWebsites.tools.databases.enable = true; services.myWebsites.tools.tools.enable = true; @@ -290,11 +281,11 @@ in ErrorDocument 502 /maintenance_immae.html ErrorDocument 503 /maintenance_immae.html ErrorDocument 504 /maintenance_immae.html - Alias /maintenance_immae.html ${../../www}/maintenance_immae.html + Alias /maintenance_immae.html ${www_root}/maintenance_immae.html ProxyPass /maintenance_immae.html ! - AliasMatch "(.*)/googleb6d69446ff4ca3e5.html" ${../../www}/googleb6d69446ff4ca3e5.html - + AliasMatch "(.*)/googleb6d69446ff4ca3e5.html" ${www_root}/googleb6d69446ff4ca3e5.html + AllowOverride None Require all granted @@ -303,8 +294,8 @@ in apaxy = { extraConfig = '' - Alias /theme ${./apache/theme} - + Alias /theme ${theme_root} + Options -Indexes AllowOverride None Require all granted @@ -407,6 +398,15 @@ in ''; }; + system.extraSystemBuilderCmds = let + adminer = pkgs.callPackage ./commons/adminer.nix {}; + in '' + mkdir -p $out/webapps + ln -s ${../../www} $out/webapps/_www + ln -s ${./apache/theme} $out/webapps/_theme + ln -s ${adminer.webRoot} $out/webapps/${adminer.apache.webappName} + ''; + services.myPhpfpm = { phpPackage = pkgs.php; phpOptions = ''