fix(openwebui): enable ssl for internal sgx

Signed-off-by: Harald Hoyer <harald@hoyer.xyz>
This commit is contained in:
Harald Hoyer 2024-12-06 09:38:15 +01:00
parent c65f89edf8
commit 26dd34a84d
4 changed files with 54 additions and 1 deletions

View file

@ -0,0 +1,23 @@
{
pkgs,
lib,
config,
...
}:
{
sops.secrets.internetbs = {
sopsFile = ../../../.secrets/hetzner/internetbs.yaml; # bring your own password file
};
security.acme = {
acceptTerms = true;
defaults = {
email = "harald@hoyer.xyz";
dnsProvider = "cloudflare";
credentialsFile = config.sops.secrets.internetbs.path;
};
certs = {
"internal.hoyer.world" = { };
};
};
}

View file

@ -11,6 +11,8 @@
./backup.nix ./backup.nix
./network.nix ./network.nix
./openwebui.nix ./openwebui.nix
./acme.nix
./nginx.nix
]; ];
sops.secrets.pccs.sopsFile = ../../../.secrets/sgx/pccs.yaml; sops.secrets.pccs.sopsFile = ../../../.secrets/sgx/pccs.yaml;

View file

@ -0,0 +1,29 @@
{ pkgs, lib, ... }:
{
users.users.nginx.extraGroups = [ "acme" ];
services.nginx = {
enable = true;
clientMaxBodySize = "1000M";
appendHttpConfig = ''
log_format vcombined '$host:$server_port '
'$remote_addr - $remote_user [$time_local] '
'"$request" $status $body_bytes_sent '
'"$http_referer" "$http_user_agent"';
access_log /var/log/nginx/access.log vcombined;
'';
recommendedGzipSettings = true;
recommendedOptimisation = true;
recommendedProxySettings = true;
recommendedTlsSettings = true;
virtualHosts = {
"internal.hoyer.world" = {
enableACME = false;
useACMEHost = "internal.hoyer.world";
forceSSL = true;
locations."/" = {
proxyPass = "http://127.0.0.1:${config.services.open-webui.port}";
};
};
};
};
}

View file

@ -4,7 +4,6 @@
enable = true; enable = true;
port = 8080; port = 8080;
host = "0.0.0.0"; host = "0.0.0.0";
openFirewall= true;
environment = { environment = {
ANONYMIZED_TELEMETRY = "False"; ANONYMIZED_TELEMETRY = "False";
DO_NOT_TRACK = "True"; DO_NOT_TRACK = "True";