diff --git a/server/mods/mail.nix b/server/mods/mail.nix index 6391cc5..615e888 100644 --- a/server/mods/mail.nix +++ b/server/mods/mail.nix @@ -23,13 +23,18 @@ in { enable = true; enableSubmissions = true; virtualMapType = "regexp"; - virtual = "/.*@bogaledev.ru/ mail@bogaledev.ru"; mapFiles.smtp_passwd = "/secrets/smtp_passwd"; + virtual = "/.*@bogaledev.ru/ mail@bogaledev.ru"; + submissionsOptions = { + smtpd_tls_wrappermode = true; + smtpd_sasl_auth_enable = "yes"; + milter_macro_daemon_name = "ORIGINATING"; + smtpd_client_restrictions = "permit_sasl_authenticated,reject"; + }; settings.main = { smtpd_sasl_type = "dovecot"; smtp_tls_wrappermode = true; smtp_sasl_auth_enable = true; - smtpd_tls_wrappermode = true; smtpd_sasl_auth_enable = true; smtp_tls_security_level = "verify"; relayhost = [ "smtp.resend.com:2465" ]; @@ -38,10 +43,7 @@ in { smtp_sasl_tls_security_options = "noanonymous"; smtp_sasl_password_maps = "hash:/etc/postfix/smtp_passwd"; virtual_transport = "lmtp:unix:${postfixDir}/dovecot-lmtp"; - smtpd_tls_chain_files = [ - "${sslCertDir}/key.pem" - "${sslCertDir}/fullchain.pem" - ]; + smtpd_tls_chain_files = [ "${sslCertDir}/key.pem" "${sslCertDir}/fullchain.pem" ]; }; }; dovecot2 = { @@ -73,10 +75,10 @@ in { inbox = true; "mailbox Sent" = { auto = "subscribe"; - mailbox_special_use = "Sent"; + mailbox_special_use = "\\Sent"; }; "mailbox Archive" = { - auto = "create"; + auto = "subscribe"; mailbox_special_use = "\\Archive"; }; "mailbox Important" = { @@ -84,12 +86,12 @@ in { mailbox_special_use = "\\Flagged"; }; "mailbox Spam" = { - auto = "create"; + auto = "subscribe"; mailbox_autoexpunge = "45d"; mailbox_special_use = "\\Junk"; }; "mailbox Trash" = { - auto = "create"; + auto = "subscribe"; mailbox_autoexpunge = "45d"; mailbox_special_use = "\\Trash"; }; diff --git a/server/mods/web.nix b/server/mods/web.nix index 214fb26..e24b478 100644 --- a/server/mods/web.nix +++ b/server/mods/web.nix @@ -27,19 +27,6 @@ ensureDBOwnership = true; } ]; }; - forgejo = { - enable = true; - database.type = "postgres"; - dump = { - enable = true; - type = "tar.zst"; - }; - settings.server = { - SSH_PORT = 2235; - HTTP_PORT = 8039; - ROOT_URL = "https://bogaledev.ru/git/"; - }; - }; phpfpm.pools.php = { user = "php"; group = "php"; @@ -58,7 +45,7 @@ package = pkgs.vaultwarden-postgresql; environmentFile = "/secrets/vw-token.env"; config = { - ROCKET_PORT = 8032; + ROCKET_PORT = 46151; SIGNUPS_ALLOWED = false; TRASH_AUTO_DELETE_DAYS = 90; PASSWORD_HINTS_ALLOWED = false; @@ -66,6 +53,32 @@ DOMAIN = "https://bogaledev.ru/vw/"; }; }; + forgejo = { + enable = true; + database.type = "postgres"; + dump = { + enable = true; + type = "tar.zst"; + }; + settings = { + service = { + ENABLE_CAPTCHA = true; + REGISTER_EMAIL_CONFIRM = true; + }; + server = { + SSH_PORT = 32831; + PROTOCOL = "http+unix"; + ROOT_URL = "https://bogaledev.ru/git/"; + HTTP_ADDR = "/run/forgejo/forgejo.sock"; + }; + mailer = { + ENABLED = true; + SMTP_PORT = 25; + SMTP_ADDR = "localhost"; + FROM = "Forgejo "; + }; + }; + }; nginx.virtualHosts."bogaledev.ru" = let phpPool = '' index index.php index.html; @@ -92,8 +105,8 @@ ''; locations = { "/".extraConfig = phpPool; - "/git/".proxyPass = "http://127.0.0.1:8039/"; "/local/".extraConfig = "${phpPool} ${localNetworks}"; + "/git/".proxyPass = "http://unix:/run/forgejo/forgejo.sock:/"; "/local/net/".extraConfig = '' allow fc01::/64; allow 10.1.0.0/16; @@ -102,7 +115,7 @@ "/vw/" = { proxyWebsockets = true; extraConfig = localNetworks; - proxyPass = "http://127.0.0.1:8032"; + proxyPass = "http://localhost:46151"; }; }; };