diff options
Diffstat (limited to 'hosts/kay/modules/acme.nix')
-rw-r--r-- | hosts/kay/modules/acme.nix | 23 |
1 files changed, 23 insertions, 0 deletions
diff --git a/hosts/kay/modules/acme.nix b/hosts/kay/modules/acme.nix new file mode 100644 index 0000000..f4ded0a --- /dev/null +++ b/hosts/kay/modules/acme.nix @@ -0,0 +1,23 @@ +{ config, pkgs, ... }: let + email = config.userdata.email; + domain = config.userdata.domain; + + environmentFile = + pkgs.writeText "acme-dns" "RFC2136_NAMESERVER='[2001:470:ee65::1]:53'"; +in { + security.acme = { + acceptTerms = true; + defaults.email = email; + + certs.${domain} = { + inherit domain; + extraDomainNames = [ "*.${domain}" ]; + + dnsProvider = "rfc2136"; + dnsPropagationCheck = false; # local DNS server + + inherit environmentFile; + group = config.services.nginx.group; + }; + }; +} |