summaryrefslogtreecommitdiff
path: root/adonis/push/default.nix
diff options
context:
space:
mode:
Diffstat (limited to 'adonis/push/default.nix')
-rw-r--r--adonis/push/default.nix55
1 files changed, 55 insertions, 0 deletions
diff --git a/adonis/push/default.nix b/adonis/push/default.nix
new file mode 100644
index 0000000..1dc8f1a
--- /dev/null
+++ b/adonis/push/default.nix
@@ -0,0 +1,55 @@
+{config, ...}: let
+ domain = "push.${config.customOps.domain.fqdn}";
+ ntfyPort = "8080";
+ mollyPort = "8020";
+ nginxConf = ''
+ proxy_set_header Host $host;
+ proxy_set_header Upgrade $http_upgrade;
+ proxy_set_header Connection "upgrade";
+ proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
+ '';
+in {
+ sops.secrets = {
+ "push/mollysocket" = {};
+ };
+
+ services.ntfy-sh = {
+ enable = true;
+ settings = {
+ listen-http = ":${ntfyPort}";
+ base-url = "https://${domain}";
+ behind-proxy = true;
+ auth-file = "/var/lib/ntfy/auth.db";
+ auth-access = ["*:up*:write-only"];
+ };
+ };
+
+ services.mollysocket = {
+ enable = true;
+ settings = {
+ allowed_endpoints = [
+ "https://${domain}"
+ ];
+ webserver = true;
+ };
+ environmentFile = config.sops.secrets."push/mollysocket".path;
+ };
+
+ services.nginx.virtualHosts.${domain} = {
+ forceSSL = true;
+ enableACME = true;
+ locations."/" = {
+ proxyPass = "http://127.0.0.1:${ntfyPort}";
+ extraConfig = nginxConf;
+ };
+ };
+
+ services.nginx.virtualHosts."mollysocket.${domain}" = {
+ forceSSL = true;
+ enableACME = true;
+ locations."/" = {
+ proxyPass = "http://127.0.0.1:${mollyPort}";
+ extraConfig = nginxConf;
+ };
+ };
+}