diff --git a/modules/hyd-node/nginx.nix b/modules/hyd-node/nginx.nix index eb1f7d7..31b8273 100644 --- a/modules/hyd-node/nginx.nix +++ b/modules/hyd-node/nginx.nix @@ -1,18 +1,40 @@ -{...}: { +{lib, cloudflareRanges, ...}: let + ws = { + proxyPass = "http://127.0.0.1:13010"; + proxyWebsockets = true; + extraConfig = '' + proxy_read_timeout 86400; + proxy_send_timeout 86400; + ''; + }; +in { services.nginx = { enable = true; + + commonHttpConfig = '' + ${lib.concatMapStrings (range: "set_real_ip_from ${range}; +") cloudflareRanges} + real_ip_header CF-Connecting-IP; + ''; + virtualHosts.hydrant = { default = true; + + locations."= /health".proxyPass = "http://127.0.0.1:13010"; + locations."= /version".proxyPass = "http://127.0.0.1:13010"; + + locations."= /xrpc/com.atproto.repo.getRecord".proxyPass = "http://127.0.0.1:13010"; + locations."= /xrpc/blue.microcosm.identity.resolveMiniDoc".proxyPass = "http://127.0.0.1:13010"; + locations."= /xrpc/com.bad-example.identity.resolveMiniDoc".proxyPass = "http://127.0.0.1:13010"; + + locations."= /stream" = ws; + locations."= /subscribe" = ws; + locations."/" = { - proxyPass = "http://127.0.0.1:13010"; - proxyWebsockets = true; - extraConfig = '' - proxy_read_timeout 86400; - proxy_send_timeout 86400; - ''; + return = "404"; }; }; }; - networking.firewall.interfaces."tailscale0".allowedTCPPorts = [80]; + networking.firewall.allowedTCPPorts = [80 443]; }