From eaacf6a789fe21b70d00a5f4fdcb52d90f2b1f15 Mon Sep 17 00:00:00 2001 From: dawn <90008@klbr.net> Date: Wed, 23 Sep 2026 15:56:23 +0300 Subject: [PATCH] hyd-node: only expose hydrant's public endpoints, behind cloudflare Signed-off-by: dawn --- modules/hyd-node/nginx.nix | 38 ++++++++++++++++++++++++++++++-------- 1 file changed, 30 insertions(+), 8 deletions(-) diff --git a/modules/hyd-node/nginx.nix b/modules/hyd-node/nginx.nix index eb1f7d7..31b8273 100644 --- a/modules/hyd-node/nginx.nix +++ b/modules/hyd-node/nginx.nix @@ -1,18 +1,40 @@ -{...}: { +{lib, cloudflareRanges, ...}: let + ws = { + proxyPass = "http://127.0.0.1:13010"; + proxyWebsockets = true; + extraConfig = '' + proxy_read_timeout 86400; + proxy_send_timeout 86400; + ''; + }; +in { services.nginx = { enable = true; + + commonHttpConfig = '' + ${lib.concatMapStrings (range: "set_real_ip_from ${range}; +") cloudflareRanges} + real_ip_header CF-Connecting-IP; + ''; + virtualHosts.hydrant = { default = true; + + locations."= /health".proxyPass = "http://127.0.0.1:13010"; + locations."= /version".proxyPass = "http://127.0.0.1:13010"; + + locations."= /xrpc/com.atproto.repo.getRecord".proxyPass = "http://127.0.0.1:13010"; + locations."= /xrpc/blue.microcosm.identity.resolveMiniDoc".proxyPass = "http://127.0.0.1:13010"; + locations."= /xrpc/com.bad-example.identity.resolveMiniDoc".proxyPass = "http://127.0.0.1:13010"; + + locations."= /stream" = ws; + locations."= /subscribe" = ws; + locations."/" = { - proxyPass = "http://127.0.0.1:13010"; - proxyWebsockets = true; - extraConfig = '' - proxy_read_timeout 86400; - proxy_send_timeout 86400; - ''; + return = "404"; }; }; }; - networking.firewall.interfaces."tailscale0".allowedTCPPorts = [80]; + networking.firewall.allowedTCPPorts = [80 443]; } -- 2.51.2