aboutsummaryrefslogtreecommitdiff
path: root/modules/caddy.nix
diff options
context:
space:
mode:
Diffstat (limited to 'modules/caddy.nix')
-rw-r--r--modules/caddy.nix25
1 files changed, 14 insertions, 11 deletions
diff --git a/modules/caddy.nix b/modules/caddy.nix
index c2c41e4..f82c7f0 100644
--- a/modules/caddy.nix
+++ b/modules/caddy.nix
@@ -9,10 +9,17 @@
virtualHosts = {
- # AdGuard Home web UI
+ # AdGuard Home web UI, plus the HTTP-01 webroot for the independent
+ # ACME cert AdGuard uses for its own DoH/DoT TLS (modules/acme.nix).
"dns.karanj.com" = {
extraConfig = ''
- reverse_proxy 127.0.0.1:3000
+ handle /.well-known/acme-challenge/* {
+ root * /var/lib/acme/acme-challenge
+ file_server
+ }
+ handle {
+ reverse_proxy 127.0.0.1:3000
+ }
'';
};
@@ -30,17 +37,13 @@
'';
};
- # cgit - public read-only git viewer + smart HTTP for git clone/pull
+ # cgit - public read-only git viewer + smart HTTP for git clone/pull.
+ # Both cgit browsing and git-http-backend (clone/pull) are served by
+ # the same nginx vhost on 8086 - nginx itself routes between them by
+ # matching the request path, so a single proxy here covers both.
"git.karanj.com" = {
extraConfig = ''
- # Smart HTTP git (clone/pull only - no push exposed)
- handle /git/* {
- reverse_proxy 127.0.0.1:8085
- }
- # cgit web UI
- handle {
- reverse_proxy 127.0.0.1:8086
- }
+ reverse_proxy 127.0.0.1:8086
'';
};