{config, ...}: let domain = "push.${config.customOps.domain.fqdn}"; ntfyPort = "8080"; mollyPort = "8020"; nginxConf = '' proxy_set_header Host $host; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; ''; in { sops.secrets = { "push/mollysocket" = {}; }; services.ntfy-sh = { enable = true; settings = { listen-http = ":${ntfyPort}"; base-url = "https://${domain}"; behind-proxy = true; auth-file = "/var/lib/ntfy/auth.db"; auth-access = ["*:up*:write-only"]; }; }; services.mollysocket = { enable = true; settings = { allowed_endpoints = [ "https://${domain}" ]; webserver = true; }; environmentFile = config.sops.secrets."push/mollysocket".path; }; services.nginx.virtualHosts.${domain} = { forceSSL = true; enableACME = true; locations."/" = { proxyPass = "http://127.0.0.1:${ntfyPort}"; extraConfig = nginxConf; }; }; services.nginx.virtualHosts."mollysocket.${domain}" = { forceSSL = true; enableACME = true; locations."/" = { proxyPass = "http://127.0.0.1:${mollyPort}"; extraConfig = nginxConf; }; }; }