- move HAProxy and ACME certificate management to Portal - route application backends to Jeeves over Tailscale - restrict Jeeves backend ports to the Tailscale interface - expose Gems for remote proxy access
18 lines
336 B
Nix
18 lines
336 B
Nix
{ ... }:
|
|
{
|
|
imports = [ ./acme.nix ];
|
|
|
|
networking.firewall.allowedTCPPorts = [
|
|
80
|
|
443
|
|
];
|
|
|
|
# Global robots.txt served by HAProxy for every vhost (see haproxy.cfg).
|
|
environment.etc."haproxy/robots.txt".source = ./robots.txt;
|
|
|
|
services.haproxy = {
|
|
enable = true;
|
|
config = builtins.readFile ./haproxy.cfg;
|
|
};
|
|
}
|