enhance wireguard and nginx settings

This commit is contained in:
Rouven Seifert 2023-05-05 23:43:40 +02:00
parent 4a57efccad
commit 8f2c34bc57
Signed by: rouven.seifert
GPG key ID: B95E8FE6B11C4D09
3 changed files with 21 additions and 4 deletions

View file

@ -1,7 +1,14 @@
{ config, ... }: { ... }:
{ {
networking.firewall.allowedTCPPorts = [ 80 443 ]; networking.firewall.allowedTCPPorts = [ 80 443 ];
services.nginx.enable = true; services.nginx = {
enable = true;
recommendedTlsSettings = true;
recommendedProxySettings = true;
recommendedGzipSettings = true;
recommendedZstdSettings = true;
recommendedOptimisation = true;
};
security.acme = { security.acme = {
acceptTerms = true; acceptTerms = true;
defaults = { defaults = {

View file

@ -1,7 +1,14 @@
{ config, ... }: { ... }:
{ {
networking.firewall.allowedTCPPorts = [ 80 443 ]; networking.firewall.allowedTCPPorts = [ 80 443 ];
services.nginx.enable = true; services.nginx = {
enable = true;
recommendedTlsSettings = true;
recommendedProxySettings = true;
recommendedGzipSettings = true;
recommendedZstdSettings = true;
recommendedOptimisation = true;
};
security.acme = { security.acme = {
acceptTerms = true; acceptTerms = true;
defaults = { defaults = {

View file

@ -107,6 +107,9 @@
}; };
networks."30-dorm" = { networks."30-dorm" = {
matchConfig.Name = "dorm"; matchConfig.Name = "dorm";
networkConfig = {
DNS = "192.168.10.1";
};
addresses = [ addresses = [
{ {
addressConfig = { addressConfig = {