aboutsummaryrefslogtreecommitdiff
path: root/modules/adguard.nix
blob: b3974d5d0d44d4ad369c92030478fec3578468cd (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
{ config, pkgs, lib, ... }:

# AdGuard Home - DNS resolver + optional network-wide ad blocker.
#
# DNS listens on port 53 (udp/tcp) directly on the public IP.
# The web UI listens on 127.0.0.1:3000 and is fronted by Caddy.
#
# Admin password is seeded from a sops secret containing a bcrypt hash.
# To generate the hash on your local machine:
#   htpasswd -nB admin
# Copy the hash portion (everything after "admin:") into secrets.yaml.
{
  services.adguardhome = {
    enable = true;
    mutableSettings = false; # declarative mode - config comes from Nix only

    settings = {
      http = {
        address = "127.0.0.1:3000";
      };

      dns = {
        bind_hosts = [ "0.0.0.0" ];
        port = 53;
        # Upstream DNS resolvers (privacy-respecting)
        upstream_dns = [
          "https://dns.quad9.net/dns-query"
          "https://cloudflare-dns.com/dns-query"
        ];
        bootstrap_dns = [
          "9.9.9.9"
          "1.1.1.1"
        ];
        enable_dnssec = true;
      };

      # Users block: username "admin", password from sops secret at activation.
      # The activation script below writes the hash into the config before
      # AdGuard starts, because mutableSettings=false uses a static config file
      # but the password hash must be injected at runtime (it contains a secret).
      users = [
        {
          name = "admin";
          # Placeholder - replaced at activation time by the script below
          password = "REPLACED_AT_ACTIVATION";
        }
      ];

      # Basic filtering
      filtering = {
        enabled = true;
        update_interval = 24;
      };

      # Block lists
      filters = [
        {
          enabled = true;
          url = "https://adguardteam.github.io/AdGuardSDNSFilter/Filters/filter.txt";
          name = "AdGuard DNS filter";
          id = 1;
        }
        {
          enabled = true;
          url = "https://adaway.org/hosts.txt";
          name = "AdAway Default Blocklist";
          id = 2;
        }
      ];
    };
  };

  # At activation: inject the bcrypt password hash from the sops secret into
  # the AdGuard config so the declarative config has the real hash.
  system.activationScripts.adguard-password = {
    deps = [ "setupSecrets" ];
    text = ''
      HASH_FILE="${config.sops.secrets."adguard/password_hash".path}"
      CFG="/var/lib/AdGuardHome/AdGuardHome.yaml"
      if [ -f "$HASH_FILE" ] && [ -f "$CFG" ]; then
        HASH=$(cat "$HASH_FILE")
        ${pkgs.gnused}/bin/sed -i "s|REPLACED_AT_ACTIVATION|$HASH|g" "$CFG"
      fi
    '';
  };
}