{lib, cloudflareRanges, ...}: let ws = { proxyPass = "http://127.0.0.1:13010"; proxyWebsockets = true; extraConfig = '' proxy_read_timeout 86400; proxy_send_timeout 86400; ''; }; in { services.nginx = { enable = true; commonHttpConfig = '' ${lib.concatMapStrings (range: "set_real_ip_from ${range}; ") cloudflareRanges} real_ip_header CF-Connecting-IP; ''; virtualHosts.hydrant = { default = true; locations."= /health".proxyPass = "http://127.0.0.1:13010"; locations."= /version".proxyPass = "http://127.0.0.1:13010"; locations."= /xrpc/com.atproto.repo.getRecord".proxyPass = "http://127.0.0.1:13010"; locations."= /xrpc/blue.microcosm.identity.resolveMiniDoc".proxyPass = "http://127.0.0.1:13010"; locations."= /xrpc/com.bad-example.identity.resolveMiniDoc".proxyPass = "http://127.0.0.1:13010"; locations."= /stream" = ws; locations."= /subscribe" = ws; locations."/" = { return = "404"; }; }; }; networking.firewall.allowedTCPPorts = [80 443]; }