2020-07-12 15:30:42 +02:00
|
|
|
{ config, pkgs, ... }:
|
2020-07-07 00:18:43 +02:00
|
|
|
|
|
|
|
{
|
|
|
|
config = {
|
|
|
|
services.nginx = {
|
|
|
|
enable = true;
|
|
|
|
enableReload = true;
|
|
|
|
|
|
|
|
recommendedTlsSettings = true;
|
|
|
|
recommendedGzipSettings = true;
|
|
|
|
recommendedProxySettings = true;
|
2021-04-16 12:48:56 +02:00
|
|
|
|
2022-01-29 23:17:48 +01:00
|
|
|
commonHttpConfig = ''
|
|
|
|
log_format json_combined escape=json
|
|
|
|
'{'
|
|
|
|
'"remote_addr":"$remote_addr",'
|
|
|
|
'"method":"$request_method",'
|
|
|
|
'"host":"$host",'
|
|
|
|
'"uri":"$request_uri",'
|
|
|
|
'"status":$status,'
|
|
|
|
'"request_size":$request_length,'
|
|
|
|
'"response_size":$body_bytes_sent,'
|
|
|
|
'"response_time":$request_time,'
|
|
|
|
'"referrer":"$http_referer",'
|
|
|
|
'"user_agent":"$http_user_agent"'
|
|
|
|
'}';
|
|
|
|
|
|
|
|
access_log syslog:server=unix:/dev/log,nohostname json_combined;
|
|
|
|
'';
|
|
|
|
|
2021-04-16 12:48:56 +02:00
|
|
|
appendHttpConfig = ''
|
|
|
|
add_header Permissions-Policy "interest-cohort=()";
|
|
|
|
'';
|
2020-07-07 00:18:43 +02:00
|
|
|
};
|
2020-07-12 15:30:42 +02:00
|
|
|
|
|
|
|
# NixOS 20.03 broke nginx and I can't be bothered to debug it
|
|
|
|
# anymore, all solution attempts have failed, so here's a
|
|
|
|
# brute-force fix.
|
|
|
|
#
|
|
|
|
# TODO(tazjin): Find a link to the upstream issue and see if
|
|
|
|
# they've sorted it after ~20.09
|
|
|
|
systemd.services.fix-nginx = {
|
|
|
|
script = "${pkgs.coreutils}/bin/chown -f -R nginx: /var/spool/nginx /var/cache/nginx";
|
|
|
|
|
|
|
|
serviceConfig = {
|
|
|
|
User = "root";
|
|
|
|
Type = "oneshot";
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
systemd.timers.fix-nginx = {
|
|
|
|
wantedBy = [ "multi-user.target" ];
|
|
|
|
timerConfig = {
|
|
|
|
OnCalendar = "minutely";
|
|
|
|
};
|
|
|
|
};
|
2020-07-07 00:18:43 +02:00
|
|
|
};
|
|
|
|
}
|