diff --git a/modules/atproto/tranquil.nix b/modules/atproto/tranquil.nix index 712d2c6..b48a6c9 100644 --- a/modules/atproto/tranquil.nix +++ b/modules/atproto/tranquil.nix @@ -9,7 +9,7 @@ in }; den.aspects.tranquil = { user, ... }: { - nixos = { config, ... }: { + nixos = { config, pkgs, ... }: { imports = [ inputs.tranquil-pds.nixosModules.default ]; services.tranquil-pds = { @@ -48,6 +48,10 @@ in services.caddy = { enable = true; + package = pkgs.caddy.withPlugins { + plugins = [ "github.com/caddy-dns/route53@v1.6.2" ]; + hash = "sha256-F/jqR4iEsklJFycTjSaW8B/V3iTGqqGOzwYBUXxRKrc="; + }; virtualHosts = { ${hostname} = { -- 2.51.2 From 298985d844630eb2b35e46318ec7b83d4bac79a8 Mon Sep 17 00:00:00 2001 From: Alex van de Sandt Date: Wed, 1 Jul 2026 22:57:21 -0500 Subject: [PATCH 2/5] Simplify with let/in binding --- modules/atproto/tranquil.nix | 105 ++++++++++++++++++----------------- 1 file changed, 55 insertions(+), 50 deletions(-) diff --git a/modules/atproto/tranquil.nix b/modules/atproto/tranquil.nix index b48a6c9..5264833 100644 --- a/modules/atproto/tranquil.nix +++ b/modules/atproto/tranquil.nix @@ -9,73 +9,78 @@ in }; den.aspects.tranquil = { user, ... }: { - nixos = { config, pkgs, ... }: { - imports = [ inputs.tranquil-pds.nixosModules.default ]; + nixos = + { config, pkgs, ... }: + let + secrets = config.sops.secrets; + in + { + imports = [ inputs.tranquil-pds.nixosModules.default ]; - services.tranquil-pds = { - enable = true; + services.tranquil-pds = { + enable = true; - database.createLocally = true; + database.createLocally = true; - settings = { - server = { - inherit hostname; - age_assurance_override = true; - contact_email = email; - max_blob_size = 1024 * 1014 * 1; # 1 GiB - }; + settings = { + server = { + inherit hostname; + age_assurance_override = true; + contact_email = email; + max_blob_size = 1024 * 1014 * 1; # 1 GiB + }; - email = { - from_address = email; + email = { + from_address = email; - smarthost = { - host = "smtp.fastmail.com"; - port = 587; + smarthost = { + host = "smtp.fastmail.com"; + port = 587; + }; }; }; - }; - environmentFiles = [ config.sops.secrets.tranquil-pds.path ]; - }; - - networking.firewall = { - enable = true; - allowedTCPPorts = [ - 80 - 443 - ]; - }; + environmentFiles = [ secrets.tranquil-pds.path ]; + }; - services.caddy = { - enable = true; - package = pkgs.caddy.withPlugins { - plugins = [ "github.com/caddy-dns/route53@v1.6.2" ]; - hash = "sha256-F/jqR4iEsklJFycTjSaW8B/V3iTGqqGOzwYBUXxRKrc="; + networking.firewall = { + enable = true; + allowedTCPPorts = [ + 80 + 443 + ]; }; - virtualHosts = { - ${hostname} = { - # by default, tranquil runs on port 3000. - # You can change this with the tranquil-pds.settings.server.port option in the service config. - extraConfig = '' - reverse_proxy localhost:3000 - ''; + services.caddy = { + enable = true; + package = pkgs.caddy.withPlugins { + plugins = [ "github.com/caddy-dns/route53@v1.6.2" ]; + hash = "sha256-F/jqR4iEsklJFycTjSaW8B/V3iTGqqGOzwYBUXxRKrc="; + }; + + virtualHosts = { + ${hostname} = { + # by default, tranquil runs on port 3000. + # You can change this with the tranquil-pds.settings.server.port option in the service config. + extraConfig = '' + reverse_proxy localhost:3000 + ''; + }; }; }; - }; - sops = { - defaultSopsFile = ../../secrets/pds.env; - secrets = { - tranquil-pds = { - format = "dotenv"; - key = ""; + sops = { + defaultSopsFile = ../../secrets/pds.env; + secrets = { + tranquil-pds = { + format = "dotenv"; + key = ""; - owner = user.name; - group = "wheel"; + owner = user.name; + group = "wheel"; + }; }; }; }; - }; }; } -- 2.51.2 From 25be32dd3d89b65a572a8d6df6935df6c44f1b6a Mon Sep 17 00:00:00 2001 From: Alex van de Sandt Date: Wed, 1 Jul 2026 23:21:41 -0500 Subject: [PATCH 3/5] Add AWS credentials for caddy --- modules/atproto/tranquil.nix | 12 +++++++++--- secrets/caddy.env | 10 ++++++++++ 2 files changed, 19 insertions(+), 3 deletions(-) create mode 100644 secrets/caddy.env diff --git a/modules/atproto/tranquil.nix b/modules/atproto/tranquil.nix index 5264833..0b61aa0 100644 --- a/modules/atproto/tranquil.nix +++ b/modules/atproto/tranquil.nix @@ -40,6 +40,7 @@ in }; }; + # Bring in secrets and smarthost credentials environmentFiles = [ secrets.tranquil-pds.path ]; }; @@ -60,25 +61,30 @@ in virtualHosts = { ${hostname} = { - # by default, tranquil runs on port 3000. - # You can change this with the tranquil-pds.settings.server.port option in the service config. extraConfig = '' reverse_proxy localhost:3000 ''; }; }; }; + systemd.services.caddy.serviceConfig.EnvironmentFile = [ secrets.caddy.path ]; sops = { - defaultSopsFile = ../../secrets/pds.env; secrets = { tranquil-pds = { + sopsFile = ../../secrets/pds.env; format = "dotenv"; key = ""; owner = user.name; group = "wheel"; }; + + caddy = { + sopsFile = ../../secrets/caddy.env; + format = "dotenv"; + key = ""; + }; }; }; }; diff --git a/secrets/caddy.env b/secrets/caddy.env new file mode 100644 index 0000000..cdb37b4 --- /dev/null +++ b/secrets/caddy.env @@ -0,0 +1,10 @@ +AWS_ACCESS_KEY_ID=ENC[AES256_GCM,data:vC+9u2FJQYjG7Y7cakl9v3YjSgk=,iv:/HauLg03FpMOmJWRtyP5gAFbgPHWegu+FqnfyOcRjgU=,tag:bJTTg5Hcr+RtuhgkKuq5wQ==,type:str] +AWS_SECRET_ACCESS_KEY=ENC[AES256_GCM,data:oonLTo6xOrogBeJxdQvzVKeOZJCecfg+X7LkPEUbbVBkESdv4qOxaw==,iv:eAjnsndCmpdLNVK3oYRG8e1uc/O1qUjXhnCBwhS0c3k=,tag:EsSrN0XWzC7ZviABdeLNVQ==,type:str] +sops_age__list_0__map_enc=-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBMaTNiQmVVckIvYzJBcm5k\nSFFmYTBTUHNpUFVzRm5hZytTcTNCZ3lqT2xnCkdWWnlVeE12V3N0NjF6SVpESE1R\nNElqaW5KSDlKVXMyVzRHS2lBNUZUZXMKLS0tIDVwR1pTY0g3LzVlcGR1a3hoQjE2\nSHJRM2ltblNHYVBsWk1KQkJIc1RLbFEKcNh7qYYq0/6DHEJ70pXpJLi7u8E99DVy\n5kmx3M63U3MuDV7Bfz2bFkguwY0xnGq0ekY3jSsFnBWzMVIoPdDQEA==\n-----END AGE ENCRYPTED FILE-----\n +sops_age__list_0__map_recipient=age1j0jft6cd5h7g0lq8hxkuq3ysrj6wzkq0gw5yxlh5aklsqdth644qapy6tg +sops_age__list_1__map_enc=-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBOYVM5NUZUalR2c3Q5NzZP\nbWl5Z0tuNkduN2lKaGZ0bkhMVWg5NEM2MENrCmZQNU9oaVU0S1hZWHViWk8zOGhL\nd0xmWHVxaHR6MEQvWlZYRHRBSCtyalkKLS0tIFZkWmYxejE0R2QyS09wRFZvVndH\nQ25ETlc1ZjMremlsUlFQSzMxamlkL1kKrZ4zPBukie9lNbJg35dOt4Ic9M/Z3FZR\nWcITyYcycaci0ywXlCVZNwdz/V17dsPbUZTbx25hSncE9URFD9BCwQ==\n-----END AGE ENCRYPTED FILE-----\n +sops_age__list_1__map_recipient=age1t94dyp6exjjex0tx5rhznfg7ua6jfgte597ke4wtl2hm2a472dqqpdf9z8 +sops_lastmodified=2026-07-02T04:21:01Z +sops_mac=ENC[AES256_GCM,data:4ElcD/ADYOs8x3An6mSIPbJ2A4KM8ztCG+ea39dyM38HJnaCD2dyad2lwjkHWrEz+tn0q5+eDrWrJwmta8jrGHNY5Bf8FLVAvOcJkjbTYZ9s6v/UL7BeqbImkGy1/AfS/hUeEP+3cq4Lona8fO5FWQE97KAqxUE4Dtx/Y2Yz27E=,iv:7q6FlOZXF7HaKOrWP++UuqDNitoQtJCy94TrVHXaV1o=,tag:VDwImku499vhdRKhdzSJQw==,type:str] +sops_unencrypted_suffix=_unencrypted +sops_version=3.13.1 -- 2.51.2 From d6d33fc188b05ffd11144806cd9a3162c20e8fe0 Mon Sep 17 00:00:00 2001 From: Alex van de Sandt Date: Wed, 1 Jul 2026 23:28:48 -0500 Subject: [PATCH 4/5] Fix route 53 plugin hash --- modules/atproto/tranquil.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/atproto/tranquil.nix b/modules/atproto/tranquil.nix index 0b61aa0..2d0faf0 100644 --- a/modules/atproto/tranquil.nix +++ b/modules/atproto/tranquil.nix @@ -56,7 +56,7 @@ in enable = true; package = pkgs.caddy.withPlugins { plugins = [ "github.com/caddy-dns/route53@v1.6.2" ]; - hash = "sha256-F/jqR4iEsklJFycTjSaW8B/V3iTGqqGOzwYBUXxRKrc="; + hash = "sha256-dxrfc6o6PBxRqMRUDpenHDctHUNQx4ZmAy9577RTTKg="; }; virtualHosts = { -- 2.51.2 From ccf622b0bd96408342f1387227d5efc7669ca09e Mon Sep 17 00:00:00 2001 From: Alex van de Sandt Date: Wed, 1 Jul 2026 23:51:22 -0500 Subject: [PATCH 5/5] Enable wildcard TLS certs on pds domain --- modules/atproto/tranquil.nix | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/modules/atproto/tranquil.nix b/modules/atproto/tranquil.nix index 2d0faf0..ce94a9d 100644 --- a/modules/atproto/tranquil.nix +++ b/modules/atproto/tranquil.nix @@ -63,6 +63,21 @@ in ${hostname} = { extraConfig = '' reverse_proxy localhost:3000 + tls { + dns route53 { + region "us-east-1" + } + } + ''; + }; + "*.${hostname}" = { + extraConfig = '' + reverse_proxy localhost:3000 + tls { + dns route53 { + region "us-east-1" + } + } ''; }; };