Tom Hubrecht
88d9b8c3e3
Some checks failed
Check meta / check_dns (pull_request) Successful in 19s
Check meta / check_meta (pull_request) Successful in 20s
Check workflows / check_workflows (pull_request) Successful in 24s
Build all the nodes / ap01 (pull_request) Successful in 1m15s
Build all the nodes / bridge01 (pull_request) Successful in 1m53s
Build all the nodes / geo01 (pull_request) Successful in 1m55s
Build all the nodes / geo02 (pull_request) Successful in 1m53s
Build all the nodes / compute01 (pull_request) Successful in 2m33s
Build all the nodes / rescue01 (pull_request) Successful in 2m13s
Build all the nodes / storage01 (pull_request) Successful in 1m57s
Run pre-commit on all files / check (pull_request) Successful in 30s
Build all the nodes / web02 (pull_request) Successful in 1m47s
Build all the nodes / vault01 (pull_request) Successful in 2m21s
Build all the nodes / web03 (pull_request) Successful in 1m40s
Build all the nodes / web01 (pull_request) Successful in 2m54s
Check meta / check_dns (push) Successful in 20s
Check meta / check_meta (push) Successful in 19s
Check workflows / check_workflows (push) Successful in 25s
Build all the nodes / ap01 (push) Successful in 1m16s
Build all the nodes / bridge01 (push) Successful in 1m41s
Build all the nodes / geo02 (push) Successful in 1m44s
Build all the nodes / geo01 (push) Successful in 1m53s
Build all the nodes / compute01 (push) Successful in 2m20s
Build all the nodes / rescue01 (push) Successful in 1m49s
Build all the nodes / storage01 (push) Successful in 1m46s
Build all the nodes / vault01 (push) Successful in 1m45s
Run pre-commit on all files / check (push) Successful in 30s
Build all the nodes / web02 (push) Has been cancelled
Build all the nodes / web01 (push) Has been cancelled
Build all the nodes / web03 (push) Has been cancelled
Signed-off-by: Tom Hubrecht <tom.hubrecht@dgnum.eu> Acked-by: Ryan Lahfa <ryan.lahfa@dgnum.eu> Acked-by: Maurice Debray <maurice.debray@dgnum.eu> Acked-by: Lubin Bailly <lubin.bailly@dgnum.eu> Acked-by: Jean-Marc Gailis <jean-marc.gailis@dgnum.eu> as the legal authority, at the time of writing, in DGNum. Acked-by: Elias Coppens <elias.coppens@dgnum.eu> as a member, at the time of writing, of the DGNum executive counsel.
141 lines
3.3 KiB
Nix
141 lines
3.3 KiB
Nix
# SPDX-FileCopyrightText: 2024 Maurice Debray <maurice.debray@dgnum.eu>
|
|
# SPDX-FileCopyrightText: 2024 Tom Hubrecht <tom.hubrecht@dgnum.eu>
|
|
#
|
|
# SPDX-License-Identifier: EUPL-1.2
|
|
|
|
{ config, lib, ... }:
|
|
|
|
let
|
|
inherit (lib) mkOption;
|
|
|
|
inherit (lib.types)
|
|
attrsOf
|
|
ints
|
|
listOf
|
|
str
|
|
submodule
|
|
;
|
|
|
|
mkRetired =
|
|
hosts:
|
|
builtins.listToAttrs (
|
|
builtins.map (name: {
|
|
inherit name;
|
|
value = {
|
|
enableACME = true;
|
|
forceSSL = true;
|
|
locations."/".return = "301 https://${cfg.retiredHost}/${name}";
|
|
};
|
|
}) hosts
|
|
);
|
|
|
|
mkPermanent = _: globalRedirect: {
|
|
inherit globalRedirect;
|
|
|
|
enableACME = true;
|
|
forceSSL = true;
|
|
};
|
|
|
|
mkTemporary =
|
|
_:
|
|
{
|
|
to,
|
|
code,
|
|
location,
|
|
}:
|
|
{
|
|
enableACME = true;
|
|
forceSSL = true;
|
|
|
|
locations.${location}.return = "${toString code} ${to}";
|
|
};
|
|
|
|
cfg = config.dgn-redirections;
|
|
in
|
|
|
|
{
|
|
options.dgn-redirections = {
|
|
permanent = mkOption {
|
|
type = attrsOf str;
|
|
default = { };
|
|
description = ''
|
|
Attribute set of redirections, for:
|
|
{ a = b; },
|
|
a redirection from a to b will be made.
|
|
'';
|
|
};
|
|
|
|
temporary = mkOption {
|
|
type = attrsOf (submodule {
|
|
options = {
|
|
to = mkOption {
|
|
type = str;
|
|
description = "Target of the redirection";
|
|
};
|
|
code = mkOption {
|
|
type = ints.between 300 399;
|
|
default = 302;
|
|
example = 308;
|
|
description = ''
|
|
HTTP status used by the redirection. Possible usecases
|
|
include temporary (302, 307) redirects, keeping the request method and
|
|
body (307, 308), or explicitly resetting the method to GET (303).
|
|
See <https://developer.mozilla.org/en-US/docs/Web/HTTP/Redirections>.
|
|
'';
|
|
};
|
|
location = mkOption {
|
|
type = str;
|
|
default = "/";
|
|
description = "nginx-style location for the source of the redirection";
|
|
};
|
|
};
|
|
});
|
|
default = { };
|
|
example = {
|
|
"source.dgnum.eu" = {
|
|
to = "https://target.dgnum.eu/path_to_page";
|
|
code = 307;
|
|
location = "/subpath/";
|
|
};
|
|
};
|
|
description = ''
|
|
Attribute set of temporary redirections. The attribute is the source
|
|
domain.
|
|
|
|
For:
|
|
```
|
|
{
|
|
"source.dgnum.eu" = {
|
|
to = "https://target.dgnum.eu/path_to_page";
|
|
code = 307;
|
|
};
|
|
}
|
|
```
|
|
a 307 redirect from all the urls within the domain `source.dgnum.eu` to
|
|
`https://target.dgnum.eu/path_to_page` will be made.
|
|
'';
|
|
};
|
|
|
|
retired = mkOption {
|
|
type = listOf str;
|
|
default = [ ];
|
|
description = ''
|
|
List of retired domains, they will we redirected to `retired.dgnum.eu/$host`.
|
|
'';
|
|
};
|
|
|
|
retiredHost = mkOption {
|
|
type = str;
|
|
default = "retired.dgnum.eu";
|
|
description = ''
|
|
Host used for the redirections of retired services.
|
|
'';
|
|
};
|
|
};
|
|
|
|
config = {
|
|
services.nginx.virtualHosts =
|
|
(builtins.mapAttrs mkPermanent cfg.permanent // builtins.mapAttrs mkTemporary cfg.temporary)
|
|
// (mkRetired cfg.retired);
|
|
};
|
|
}
|