services/nginx: use acme dns challenge

This commit is contained in:
LavaDesu 2022-02-27 02:13:36 +07:00
parent d3f2c9bd28
commit 8c932dd229
Signed by: cilly
GPG key ID: 6500251E087653C9
4 changed files with 24 additions and 4 deletions

View file

@ -1,6 +1,14 @@
{ inputs, ... }: {
security.acme.acceptTerms = true;
security.acme.email = "me@lava.moe";
{ config, inputs, ... }: {
security.acme = {
acceptTerms = true;
email = "me@lava.moe";
certs."lava.moe" = {
domain = "*.lava.moe";
dnsProvider = "cloudflare";
credentialsFile = config.age.secrets."acme_dns".path;
};
};
services.nginx = {
enable = true;
recommendedTlsSettings = true;
@ -10,7 +18,7 @@
virtualHosts = {
"lava.moe" = {
enableACME = true;
useACMEHost = "lava.moe";
forceSSL = true;
root = inputs.website.outPath;
};