diff --git a/server/configuration.nix b/server/configuration.nix index 8e462ee..64952e2 100644 --- a/server/configuration.nix +++ b/server/configuration.nix @@ -31,7 +31,7 @@ networking = { hostName = "nixos-server"; firewall = { - allowedTCPPorts = [ 25 443 587 993 ]; + allowedTCPPorts = [ 25 443 465 993 ]; allowedUDPPorts = [ 443 ]; }; wg-quick.interfaces.awg0 = { diff --git a/server/mods/mail.nix b/server/mods/mail.nix index 02bdfc8..6391cc5 100644 --- a/server/mods/mail.nix +++ b/server/mods/mail.nix @@ -1,12 +1,11 @@ { config, lib, pkgs, ... }: -{ +let + postfixDir = "/var/spool/postfix"; +in { systemd.tmpfiles.rules = [ - "d /var/spool/postfix 0775 postfix postfix -" - "d /var/spool/postfix/private 0770 postfix postfix -" + "d ${postfixDir} 0700 postfix postfix -" ]; services = let - mailBase = "/var/spool/mail/vmail"; - saslSocket = "/var/spool/postfix/private/auth"; sslCertDir = config.security.acme.certs."bogaledev.ru".directory; in { redis.servers.rspamd = { @@ -20,57 +19,82 @@ servers = "${config.services.redis.servers.rspamd.unixSocket}"; ''; }; - dovecot2 = { - enable = true; - settings = { - ssl = "required"; - mail_gid = "vmail"; - mail_uid = "vmail"; - mail_path = mailBase; - protocols.imap = true; - mail_driver = "maildir"; - auth_mechanisms = [ "plain" ]; - dovecot_config_version = "2.4.5"; - dovecot_storage_version = "2.4.5"; - ssl_server_key_file = "${sslCertDir}/key.pem"; - ssl_server_cert_file = "${sslCertDir}/fullchain.pem"; - "passdb passwd-file".passwd_file_path = "/secrets/dovecot-pw"; - "service auth"."unix_listener ${saslSocket}" = { - mode = "0660"; - user = "postfix"; - group = "postfix"; - }; - }; - }; postfix = { enable = true; - enableSubmission = true; + enableSubmissions = true; virtualMapType = "regexp"; virtual = "/.*@bogaledev.ru/ mail@bogaledev.ru"; - mapFiles = { - smtp_passwd = "/secrets/smtp_passwd"; - mailbox = pkgs.writeText "mailbox" "mail@bogaledev.ru /"; - }; + mapFiles.smtp_passwd = "/secrets/smtp_passwd"; settings.main = { smtpd_sasl_type = "dovecot"; - smtpd_sasl_path = saslSocket; - smtp_sasl_auth_enable = "yes"; - smtpd_sasl_auth_enable = "yes"; - virtual_mailbox_base = mailBase; - virtual_uid_maps = "static:1819"; - virtual_gid_maps = "static:1819"; - smtp_tls_security_level = "encrypt"; - smtpd_tls_security_level = "encrypt"; - relayhost = [ "smtp.resend.com:2587" ]; + smtp_tls_wrappermode = true; + smtp_sasl_auth_enable = true; + smtpd_tls_wrappermode = true; + smtpd_sasl_auth_enable = true; + smtp_tls_security_level = "verify"; + relayhost = [ "smtp.resend.com:2465" ]; + smtpd_sasl_path = "${postfixDir}/auth"; virtual_mailbox_domains = "bogaledev.ru"; smtp_sasl_tls_security_options = "noanonymous"; - virtual_mailbox_maps = "hash:/etc/postfix/mailbox"; smtp_sasl_password_maps = "hash:/etc/postfix/smtp_passwd"; + virtual_transport = "lmtp:unix:${postfixDir}/dovecot-lmtp"; smtpd_tls_chain_files = [ "${sslCertDir}/key.pem" "${sslCertDir}/fullchain.pem" ]; }; }; + dovecot2 = { + enable = true; + settings = { + ssl = "required"; + mail_gid = "vmail"; + mail_uid = "vmail"; + mail_driver = "maildir"; + protocols = [ "imap" "lmtp" ]; + auth_mechanisms = [ "plain" ]; + dovecot_config_version = "2.4.5"; + dovecot_storage_version = "2.4.5"; + mail_path = "/var/spool/mail/vmail"; + ssl_server_key_file = "${sslCertDir}/key.pem"; + ssl_server_cert_file = "${sslCertDir}/fullchain.pem"; + "passdb passwd-file".passwd_file_path = "/secrets/dovecot-pw"; + "service auth"."unix_listener ${postfixDir}/auth" = { + mode = "0600"; + user = "postfix"; + group = "postfix"; + }; + "service lmtp"."unix_listener ${postfixDir}/dovecot-lmtp" = { + mode = "0600"; + user = "postfix"; + group = "postfix"; + }; + "namespace inbox" = { + inbox = true; + "mailbox Sent" = { + auto = "subscribe"; + mailbox_special_use = "Sent"; + }; + "mailbox Archive" = { + auto = "create"; + mailbox_special_use = "\\Archive"; + }; + "mailbox Important" = { + auto = "subscribe"; + mailbox_special_use = "\\Flagged"; + }; + "mailbox Spam" = { + auto = "create"; + mailbox_autoexpunge = "45d"; + mailbox_special_use = "\\Junk"; + }; + "mailbox Trash" = { + auto = "create"; + mailbox_autoexpunge = "45d"; + mailbox_special_use = "\\Trash"; + }; + }; + }; + }; }; } diff --git a/server/mods/web.nix b/server/mods/web.nix index 3d4d24d..214fb26 100644 --- a/server/mods/web.nix +++ b/server/mods/web.nix @@ -16,8 +16,8 @@ in { postgresqlBackup = { enable = true; - compression = "none"; - databases = [ "php" "forgejo" "vaultwarden" ]; + compression = "zstd"; + databases = [ "php" "vaultwarden" ]; }; postgresql = { enable = true; @@ -30,7 +30,12 @@ forgejo = { enable = true; database.type = "postgres"; + dump = { + enable = true; + type = "tar.zst"; + }; settings.server = { + SSH_PORT = 2235; HTTP_PORT = 8039; ROOT_URL = "https://bogaledev.ru/git/"; }; @@ -63,6 +68,7 @@ }; nginx.virtualHosts."bogaledev.ru" = let phpPool = '' + index index.php index.html; location ~ \.php$ { fastcgi_pass unix:${config.services.phpfpm.pools.php.socket}; } @@ -85,15 +91,9 @@ add_header X-Content-Type-Options "nosniff" always; ''; locations = { + "/".extraConfig = phpPool; "/git/".proxyPass = "http://127.0.0.1:8039/"; - "/" = { - extraConfig = phpPool; - index = "index.php index.html"; - }; - "/local/" = { - extraConfig = "${phpPool} ${localNetworks}"; - index = "index.php index.html"; - }; + "/local/".extraConfig = "${phpPool} ${localNetworks}"; "/local/net/".extraConfig = '' allow fc01::/64; allow 10.1.0.0/16;