{ config, lib, pkgs, ... }: { imports = [ ../common.nix ./hardware-configuration.nix ]; boot.kernelParams = [ "memmap=0x4000%0xbfb76000-4" "memmap=0x4000%0xbfb7a000-4" ]; users.users.nginx.extraGroups = [ "acme" ]; users.users.bogale.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKH8f3tKQQFFCkLS76TcY7oPzmbVrTkMZN7KSDHPX4o1" ]; networking = { hostName = "nixos-server"; networkmanager.ensureProfiles.profiles.home-wifi = { wifi.ssid = "bogale_2.4"; wifi-security.psk = "$BOGALE_2_4_PSK"; }; firewall = { allowedTCPPorts = [ 80 443 ]; allowedUDPPorts = [ 443 ]; }; }; security.acme = { acceptTerms = true; certs."bogaledev.ru" = { validMinDays = 3; dnsProvider = "cloudflare"; email = "acme-tls@bogaledev.ru"; reloadServices = [ "nginx.service" ]; extraDomainNames = [ "*.bogaledev.ru" ]; credentialFiles = { "CF_DNS_API_TOKEN_FILE" = "/root/secrets/cf-token"; }; }; }; services = { postgresql.enable = true; openssh = { enable = true; settings = { PermitRootLogin = "no"; PasswordAuthentication = false; }; }; phpfpm.pools.main = { user = "nginx"; group = "nginx"; settings = { "pm" = "ondemand"; "pm.max_children" = 8; "listen.owner" = "nginx"; "listen.group" = "nginx"; }; }; vaultwarden = { enable = true; configureNginx = true; dbBackend = "postgresql"; configurePostgres = true; domain = "vw.bogaledev.ru"; package = pkgs.vaultwarden-postgresql; environmentFile = "/root/secrets/vaultwarden.env"; config = { #EMAIL_TOKEN_SIZE = 8; #SMTP_SECURITY = "off"; #SMTP_HOST = "localhost"; SIGNUPS_ALLOWED = false; #REQUIRE_DEVICE_EMAIL = true; TRASH_AUTO_DELETE_DAYS = 90; PASSWORD_HINTS_ALLOWED = false; EMERGENCY_ACCESS_ALLOWED = false; #SMTP_FROM = "vaultwarden@bogaledev.ru"; }; }; nginx = { enable = true; recommendedTlsSettings = true; recommendedGzipSettings = true; recommendedOptimisation = true; recommendedProxySettings = true; recommendedBrotliSettings = true; virtualHosts."bogaledev.ru" = { quic = true; default = true; forceSSL = true; root = "/srv/http"; useACMEHost = "bogaledev.ru"; extraConfig = '' add_header Alt-Svc 'h3=":443"; ma=86400' always; ''; locations = { "/".index = "index.php index.html"; "~ \\.php$".extraConfig = '' fastcgi_pass unix:${config.services.phpfpm.pools.main.socket}; ''; }; }; virtualHosts."vw.bogaledev.ru" = { quic = true; forceSSL = true; useACMEHost = "bogaledev.ru"; extraConfig = '' allow fc00::/64; allow 10.0.0.0/24; allow 192.168.1.0/24; deny all; add_header Alt-Svc 'h3=":443"; ma=86400' always; ''; }; }; }; }