diff --git a/flake.lock b/flake.lock index 8c3cc34..73512f2 100644 --- a/flake.lock +++ b/flake.lock @@ -276,11 +276,11 @@ "xwayland-satellite-unstable": "xwayland-satellite-unstable" }, "locked": { - "lastModified": 1772876957, - "narHash": "sha256-6hQTgZOE3ekAwYIaaE44bqxffsgQKfhjJpUAD/6ECwU=", + "lastModified": 1772884214, + "narHash": "sha256-nl1U1E9Kk9ZmxWdqcwBuFaljxknbrwq8/bY+utQSajk=", "owner": "sodiboo", "repo": "niri-flake", - "rev": "31343a5e27bdbfdb68bf3725473d8308be91889a", + "rev": "3fc5b3670ef77356173ca5f1fa5015e01204bc33", "type": "github" }, "original": { @@ -367,11 +367,11 @@ }, "nixpkgs": { "locked": { - "lastModified": 1772864153, - "narHash": "sha256-YANRi2Sb6uUHFy/zhZjC0DmCpYKPMpXQBKj5iRZv6ks=", + "lastModified": 1772906963, + "narHash": "sha256-jT3m0eiRH9TLqMsMVblze5/DPupInp8Qc8Gop8Zxfho=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "8fbd4361b3a128506685a89bb18ff29ff23f6c59", + "rev": "5a60c0dff24e7109c0e87fd53e5bbc0032fa0cbd", "type": "github" }, "original": { @@ -383,11 +383,11 @@ }, "nixpkgs-stable": { "locked": { - "lastModified": 1772598333, - "narHash": "sha256-YaHht/C35INEX3DeJQNWjNaTcPjYmBwwjFJ2jdtr+5U=", + "lastModified": 1772822230, + "narHash": "sha256-yf3iYLGbGVlIthlQIk5/4/EQDZNNEmuqKZkQssMljuw=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "fabb8c9deee281e50b1065002c9828f2cf7b2239", + "rev": "71caefce12ba78d84fe618cf61644dce01cf3a96", "type": "github" }, "original": { diff --git a/modules/server/network.nix b/modules/server/network.nix index df6c6e5..eed48dc 100644 --- a/modules/server/network.nix +++ b/modules/server/network.nix @@ -31,19 +31,20 @@ in networkConfig.IPv6AcceptRA = "no"; linkConfig.RequiredForOnline = "no"; address = [ "10.65.20.241/32" ]; - routingPolicyRules = lib.forEach config.forest.proxiedUsers (user: { - Table = 1000; - User = user; - Priority = 30001; - Family = "both"; - }) - ++ lib.forEach config.forest.proxiedUsers (user: { - Table = "main"; - User = user; - SuppressPrefixLength = 0; - Priority = 30000; - Family = "both"; - }); + routingPolicyRules = + lib.forEach config.forest.proxiedUsers (user: { + Table = 1000; + User = user; + Priority = 30001; + Family = "both"; + }) + ++ lib.forEach config.forest.proxiedUsers (user: { + Table = "main"; + User = user; + SuppressPrefixLength = 0; + Priority = 30000; + Family = "both"; + }); }; }; netdevs."50-wg0" = { diff --git a/modules/server/nextcloud.nix b/modules/server/nextcloud.nix index 6aa99c5..e5cf17c 100644 --- a/modules/server/nextcloud.nix +++ b/modules/server/nextcloud.nix @@ -92,7 +92,7 @@ "OC\\Preview\\MarkDown" "OC\\Preview\\PDF" ]; - maintenance_window_start = 23; + maintenance_window_start = 23; }; secretFile = config.sops.templates."nc-secrets".path; }; diff --git a/modules/server/nginx.nix b/modules/server/nginx.nix index 58e4ea6..941ce03 100644 --- a/modules/server/nginx.nix +++ b/modules/server/nginx.nix @@ -146,14 +146,12 @@ sslCertificateKey = config.sops.secrets."ssl/key".path; locations."/".proxyPass = "http://127.0.0.1:4533"; }; - /* - "search.monke.moe" = { - onlySSL = true; - useACMEHost = "monke.moe"; - http2 = true; - locations."/".proxyPass = "http://127.0.0.1:8086"; - }; - */ + "${config.services.searx.domain}" = { + onlySSL = true; + useACMEHost = "monke.moe"; + http2 = true; + locations."/".proxyPass = "http://unix:${config.services.searx.uwsgiConfig.socket}"; + }; "ms.monke.moe" = { onlySSL = true; useACMEHost = "monke.moe"; diff --git a/modules/server/searxng.nix b/modules/server/searxng.nix index 0340302..a745834 100644 --- a/modules/server/searxng.nix +++ b/modules/server/searxng.nix @@ -10,11 +10,21 @@ }; services.searx = { - enable = false; - domain = "search.monke.moe"; + enable = true; + domain = "search.auri.ee"; + environmentFile = config.sops.templates.searx-env.path; + uwsgiConfig = { + socket = "/run/searx/searx.sock"; + chmod-socket = "660"; + }; settings = { - server.port = 8086; server.secret_key = "$SEARX_SECRET_KEY"; + enabled_plugins = [ + "Hostname replace" + ]; + hostname_replace = { + "(.*\.)?fandom\.com$" = false; + }; }; }; }