diff --git a/common/nginx.nix b/common/nginx.nix new file mode 100644 index 0000000..5e06cd0 --- /dev/null +++ b/common/nginx.nix @@ -0,0 +1,41 @@ +{ + config, + lib, + pkgs, + ... +}: let + corsConfig = '' + more_set_headers 'Access-Control-Allow-Origin: *'; + more_set_headers 'Access-Control-Allow-Methods: GET, POST, OPTIONS'; + more_set_headers 'Access-Control-Allow-Headers: Authorization, Content-Type, atproto-proxy'; + + if ($request_method = 'OPTIONS') { + add_header 'Access-Control-Max-Age' 86400; + return 204; + } + ''; +in { + options.services.nginx.virtualHosts = lib.mkOption { + type = lib.types.attrsOf (lib.types.submodule { + options.locations = lib.mkOption { + type = lib.types.attrsOf (lib.types.submodule ({config, ...}: { + options.allowCors = lib.mkEnableOption "CORS headers for this location"; + config.extraConfig = lib.mkIf config.allowCors corsConfig; + })); + }; + }); + }; + + config.services.nginx = { + recommendedProxySettings = true; + recommendedTlsSettings = true; + recommendedOptimisation = true; + recommendedGzipSettings = true; + additionalModules = + lib.mkIf + (lib.any + (vhost: lib.any (location: location.allowCors) (lib.attrValues vhost.locations)) + (lib.attrValues config.services.nginx.virtualHosts)) + [pkgs.nginxModules.moreheaders]; + }; +} diff --git a/flake.nix b/flake.nix index 9950a4b..faad0fb 100644 --- a/flake.nix +++ b/flake.nix @@ -49,6 +49,7 @@ baseModules = [ disko.nixosModules.disko ./common/base.nix + ./common/nginx.nix ./common/tailscale.nix ]; diff --git a/hosts/appview/services/nginx-alpha.nix b/hosts/appview/services/nginx-alpha.nix index 995dc7d..ab6dec3 100644 --- a/hosts/appview/services/nginx-alpha.nix +++ b/hosts/appview/services/nginx-alpha.nix @@ -5,10 +5,6 @@ }: { services.nginx = { enable = true; - recommendedTlsSettings = true; - recommendedOptimisation = true; - recommendedGzipSettings = true; - # Fix proxy headers hash warnings appendHttpConfig = '' proxy_headers_hash_max_size 1024; @@ -24,11 +20,6 @@ locations."/" = { proxyPass = "http://127.0.0.1:3000"; extraConfig = '' - proxy_http_version 1.1; - proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; client_max_body_size 100M; ''; }; diff --git a/hosts/appview/services/nginx.nix b/hosts/appview/services/nginx.nix index 0e33c01..11a67aa 100644 --- a/hosts/appview/services/nginx.nix +++ b/hosts/appview/services/nginx.nix @@ -16,11 +16,6 @@ in { eventsConfig = '' worker_connections 1024; ''; - recommendedProxySettings = true; - recommendedTlsSettings = true; - recommendedOptimisation = true; - recommendedGzipSettings = true; - # bot blocking appendHttpConfig = '' map $http_user_agent $block_bot { diff --git a/hosts/knot1/services/nginx.nix b/hosts/knot1/services/nginx.nix index d188df4..7238f7e 100644 --- a/hosts/knot1/services/nginx.nix +++ b/hosts/knot1/services/nginx.nix @@ -1,30 +1,11 @@ { lib, - pkgs, cloudflareRanges, ... }: let - proxyHeaders = '' - proxy_set_header X-Forwarded-For $remote_addr; - proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-Proto $scheme; - ''; - - corsCfg = '' - more_set_headers 'Access-Control-Allow-Origin: *'; - more_set_headers 'Access-Control-Allow-Methods: GET, POST, OPTIONS'; - more_set_headers 'Access-Control-Allow-Headers: Authorization, Content-Type, atproto-proxy'; - - if ($request_method = 'OPTIONS') { - add_header 'Access-Control-Max-Age' 86400; - return 204; - } - ''; in { services.nginx = { enable = true; - additionalModules = [pkgs.nginxModules.moreheaders]; commonHttpConfig = '' ${lib.concatMapStrings (range: "set_real_ip_from ${range};\n") cloudflareRanges} @@ -36,17 +17,12 @@ in { forceSSL = false; enableACME = false; locations."/" = { + allowCors = true; proxyPass = "http://127.0.0.1:5555"; - - extraConfig = '' - ${proxyHeaders} - ${corsCfg} - ''; }; locations."/events" = { proxyPass = "http://127.0.0.1:5555"; proxyWebsockets = true; - extraConfig = proxyHeaders; }; }; }; diff --git a/hosts/nixery/services/nginx.nix b/hosts/nixery/services/nginx.nix index 9eb8050..06a8c6e 100644 --- a/hosts/nixery/services/nginx.nix +++ b/hosts/nixery/services/nginx.nix @@ -26,10 +26,6 @@ return 405; } - proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; ''; }; }; @@ -41,21 +37,11 @@ }; locations."/events" = { proxyPass = "http://localhost:6555"; - extraConfig = '' - proxy_set_header X-Forwarded-For $remote_addr; - proxy_set_header Host $host; - proxy_set_header Upgrade $http_upgrade; - proxy_set_header Connection "upgrade"; - ''; + proxyWebsockets = true; }; locations."/logs/" = { proxyPass = "http://localhost:6555"; - extraConfig = '' - proxy_set_header X-Forwarded-For $remote_addr; - proxy_set_header Host $host; - proxy_set_header Upgrade $http_upgrade; - proxy_set_header Connection "upgrade"; - ''; + proxyWebsockets = true; }; }; }; diff --git a/hosts/pds/services/nginx.nix b/hosts/pds/services/nginx.nix index 5b1ab80..4ba9646 100644 --- a/hosts/pds/services/nginx.nix +++ b/hosts/pds/services/nginx.nix @@ -15,14 +15,7 @@ # match all other paths locations."/" = { proxyPass = "http://localhost:3000"; - extraConfig = '' - proxy_set_header Host $host; - proxy_set_header X-Real-IP $remote_addr; - proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; - proxy_set_header Upgrade $http_upgrade; - proxy_set_header Connection "upgrade"; - ''; + proxyWebsockets = true; }; }; }; diff --git a/hosts/spindle-hel/services/nginx.nix b/hosts/spindle-hel/services/nginx.nix index bc9a650..61f0ab6 100644 --- a/hosts/spindle-hel/services/nginx.nix +++ b/hosts/spindle-hel/services/nginx.nix @@ -1,7 +1,6 @@ {config, ...}: { services.nginx = { enable = true; - recommendedProxySettings = true; virtualHosts = { "spindle.tangled.sh" = let spindleAddr = "http://${config.services.tangled.spindle.server.listenAddr}"; diff --git a/hosts/spindle/services/nginx.nix b/hosts/spindle/services/nginx.nix index 048fca8..31ab335 100644 --- a/hosts/spindle/services/nginx.nix +++ b/hosts/spindle/services/nginx.nix @@ -10,21 +10,11 @@ }; locations."/events" = { proxyPass = "http://127.0.0.1:6555"; - extraConfig = '' - proxy_set_header X-Forwarded-For $remote_addr; - proxy_set_header Host $host; - proxy_set_header Upgrade $http_upgrade; - proxy_set_header Connection "upgrade"; - ''; + proxyWebsockets = true; }; locations."/logs/" = { proxyPass = "http://127.0.0.1:6555"; - extraConfig = '' - proxy_set_header X-Forwarded-For $remote_addr; - proxy_set_header Host $host; - proxy_set_header Upgrade $http_upgrade; - proxy_set_header Connection "upgrade"; - ''; + proxyWebsockets = true; }; }; };