blob: b3974d5d0d44d4ad369c92030478fec3578468cd (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
|
{ config, pkgs, lib, ... }:
# AdGuard Home - DNS resolver + optional network-wide ad blocker.
#
# DNS listens on port 53 (udp/tcp) directly on the public IP.
# The web UI listens on 127.0.0.1:3000 and is fronted by Caddy.
#
# Admin password is seeded from a sops secret containing a bcrypt hash.
# To generate the hash on your local machine:
# htpasswd -nB admin
# Copy the hash portion (everything after "admin:") into secrets.yaml.
{
services.adguardhome = {
enable = true;
mutableSettings = false; # declarative mode - config comes from Nix only
settings = {
http = {
address = "127.0.0.1:3000";
};
dns = {
bind_hosts = [ "0.0.0.0" ];
port = 53;
# Upstream DNS resolvers (privacy-respecting)
upstream_dns = [
"https://dns.quad9.net/dns-query"
"https://cloudflare-dns.com/dns-query"
];
bootstrap_dns = [
"9.9.9.9"
"1.1.1.1"
];
enable_dnssec = true;
};
# Users block: username "admin", password from sops secret at activation.
# The activation script below writes the hash into the config before
# AdGuard starts, because mutableSettings=false uses a static config file
# but the password hash must be injected at runtime (it contains a secret).
users = [
{
name = "admin";
# Placeholder - replaced at activation time by the script below
password = "REPLACED_AT_ACTIVATION";
}
];
# Basic filtering
filtering = {
enabled = true;
update_interval = 24;
};
# Block lists
filters = [
{
enabled = true;
url = "https://adguardteam.github.io/AdGuardSDNSFilter/Filters/filter.txt";
name = "AdGuard DNS filter";
id = 1;
}
{
enabled = true;
url = "https://adaway.org/hosts.txt";
name = "AdAway Default Blocklist";
id = 2;
}
];
};
};
# At activation: inject the bcrypt password hash from the sops secret into
# the AdGuard config so the declarative config has the real hash.
system.activationScripts.adguard-password = {
deps = [ "setupSecrets" ];
text = ''
HASH_FILE="${config.sops.secrets."adguard/password_hash".path}"
CFG="/var/lib/AdGuardHome/AdGuardHome.yaml"
if [ -f "$HASH_FILE" ] && [ -f "$CFG" ]; then
HASH=$(cat "$HASH_FILE")
${pkgs.gnused}/bin/sed -i "s|REPLACED_AT_ACTIVATION|$HASH|g" "$CFG"
fi
'';
};
}
|