{config, ...}: let domain = "push.${config.customOps.domain.fqdn}"; ntfyPort = "8080"; mollyPort = "8020"; nginxConf = '' proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_buffering off; proxy_request_buffering off; proxy_redirect off; proxy_connect_timeout 3m; proxy_send_timeout 3m; proxy_read_timeout 3m; client_max_body_size 0; ''; in { sops.secrets = { "push/mollysocket" = {}; }; services.ntfy-sh = { enable = true; settings = { listen-http = ":${ntfyPort}"; base-url = "https://${domain}"; behind-proxy = true; auth-file = "/var/lib/ntfy-sh/user.db"; auth-access = ["*:up*:write-only"]; }; }; services.mollysocket = { enable = true; settings = { allowed_endpoints = [ "https://${domain}" ]; webserver = true; }; environmentFile = config.sops.secrets."push/mollysocket".path; }; services.nginx.virtualHosts.${domain} = { forceSSL = true; enableACME = true; locations."/" = { proxyPass = "http://127.0.0.1:${ntfyPort}"; extraConfig = '' set $redirect_https ""; if ($request_method = GET) { set $redirect_https "yes"; } if ($request_uri ~* "^/([-_a-z0-9]{0,64}$|docs/|static/)") { set $redirect_https "''${redirect_https}yes"; } if ($redirect_https = "yesyes") { return 302 https://$http_host$request_uri$is_args$query_string; } ${nginxConf} ''; }; }; services.nginx.virtualHosts."mollysocket.${domain}" = { forceSSL = true; enableACME = true; locations."/" = { proxyPass = "http://127.0.0.1:${mollyPort}"; extraConfig = nginxConf; }; }; }