set up nginx on bordervm for testing outboard secrets
This commit is contained in:
parent
409c1cfb16
commit
2480fdef5b
@ -89,6 +89,16 @@ in {
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
services.nginx = {
|
||||||
|
enable = true;
|
||||||
|
user = "liminix";
|
||||||
|
virtualHosts.${config.networking.hostName} = {
|
||||||
|
root = "/home/liminix";
|
||||||
|
default = true;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
systemd.services.nginx.serviceConfig.ProtectHome = "read-only";
|
||||||
|
|
||||||
systemd.services.sshd.wantedBy = pkgs.lib.mkForce [ "multi-user.target" ];
|
systemd.services.sshd.wantedBy = pkgs.lib.mkForce [ "multi-user.target" ];
|
||||||
|
|
||||||
virtualisation = {
|
virtualisation = {
|
||||||
|
Loading…
Reference in New Issue
Block a user