diff --git a/host-specific/edge/configuration.nix b/host-specific/edge/configuration.nix index 3dc5e0d..948d656 100644 --- a/host-specific/edge/configuration.nix +++ b/host-specific/edge/configuration.nix @@ -140,18 +140,32 @@ frontend public_http bind :::80 v4v6 + mode http + acl spindle_host hdr(host) -i spindle.packetlost.dev + use_backend odin_http if spindle_host default_backend misaki_http backend misaki_http + mode http server misaki 100.72.241.95:80 check + backend odin_http + mode http + server odin 100.127.136.117:80 check + frontend public_https bind :::443 v4v6 + tcp-request inspect-delay 5s + tcp-request content accept if { req.ssl_hello_type 1 } + use_backend odin_https if { req.ssl_sni -i spindle.packetlost.dev } default_backend misaki_https backend misaki_https server misaki 100.72.241.95:443 check + backend odin_https + server odin 100.127.136.117:443 check + frontend public_plex bind :::32400 v4v6 default_backend misaki_plex diff --git a/host-specific/edge/home.nix b/host-specific/edge/home.nix new file mode 100644 index 0000000..c1f5541 --- /dev/null +++ b/host-specific/edge/home.nix @@ -0,0 +1,23 @@ +{ pkgs, ... }: +{ + home = { + username = "noah"; + homeDirectory = "/home/noah"; + packages = with pkgs; [ + fd + htop + ripgrep + tree + ]; + stateVersion = "23.11"; + }; + + programs = { + fish.enable = true; + git.enable = true; + home-manager.enable = true; + }; + + services.ssh-agent.enable = true; + services.gpg-agent.enable = false; +} diff --git a/host-specific/misaki/services.nix b/host-specific/misaki/services.nix index d49b909..9f232da 100644 --- a/host-specific/misaki/services.nix +++ b/host-specific/misaki/services.nix @@ -606,7 +606,6 @@ in "plex.packetlost.dev" "img.ngp.computer" "knot.packetlost.dev" - "spindle.packetlost.dev" "files.ngp.computer" "cache.ngp.computer" "photos.ngp.computer" @@ -937,15 +936,6 @@ in ''; }; }; - virtualHosts."spindle.packetlost.dev" = { - forceSSL = true; - enableACME = true; - acmeRoot = null; - http2 = true; - # Spindle itself runs on Odin; Misaki only terminates TLS publicly. - locations."/".proxyPass = "http://192.168.1.6:6555"; - locations."/".proxyWebsockets = true; - }; virtualHosts."id.ngp.computer" = { forceSSL = true; enableACME = true;