mirror of
https://github.com/TheWanderingCrow/CrOS.git
synced 2026-02-26 14:12:35 -05:00
deny all rules
This commit is contained in:
parent
d46e581ddf
commit
8fb8e39de4
5 changed files with 21 additions and 0 deletions
|
|
@ -37,6 +37,11 @@ in
|
||||||
enable = true;
|
enable = true;
|
||||||
recommendedProxySettings = true;
|
recommendedProxySettings = true;
|
||||||
virtualHosts = {
|
virtualHosts = {
|
||||||
|
extraConfig = ''
|
||||||
|
allow 192.168.0.0/16;
|
||||||
|
allow 10.8.0.0/24;
|
||||||
|
deny all;
|
||||||
|
'';
|
||||||
"bar.wanderingcrow.net" = {
|
"bar.wanderingcrow.net" = {
|
||||||
forceSSL = true;
|
forceSSL = true;
|
||||||
useACMEHost = "bar.wanderingcrow.net";
|
useACMEHost = "bar.wanderingcrow.net";
|
||||||
|
|
|
||||||
|
|
@ -35,6 +35,11 @@ in
|
||||||
appKeyFile = config.sops.secrets."bookstack/key".path;
|
appKeyFile = config.sops.secrets."bookstack/key".path;
|
||||||
nginx = {
|
nginx = {
|
||||||
forceSSL = true;
|
forceSSL = true;
|
||||||
|
extraConfig = ''
|
||||||
|
allow 192.168.0.0/16;
|
||||||
|
allow 10.8.0.0/24;
|
||||||
|
deny all;
|
||||||
|
'';
|
||||||
useACMEHost = "bookstack.wanderingcrow.net";
|
useACMEHost = "bookstack.wanderingcrow.net";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
|
||||||
|
|
@ -7,6 +7,11 @@ lib.mkIf config.user.overseer.enable {
|
||||||
services.nginx.virtualHosts."grocy.wanderingcrow.net" = {
|
services.nginx.virtualHosts."grocy.wanderingcrow.net" = {
|
||||||
forceSSL = true;
|
forceSSL = true;
|
||||||
useACMEHost = "grocy.wanderingcrow.net";
|
useACMEHost = "grocy.wanderingcrow.net";
|
||||||
|
extraConfig = ''
|
||||||
|
allow 192.168.0.0/16;
|
||||||
|
allow 10.8.0.0/24;
|
||||||
|
deny all;
|
||||||
|
'';
|
||||||
};
|
};
|
||||||
|
|
||||||
services.grocy = {
|
services.grocy = {
|
||||||
|
|
|
||||||
|
|
@ -26,6 +26,11 @@ lib.mkIf config.user.overseer.enable {
|
||||||
forceSSL = true;
|
forceSSL = true;
|
||||||
useACMEHost = "homebox.wanderingcrow.net";
|
useACMEHost = "homebox.wanderingcrow.net";
|
||||||
locations."/" = {
|
locations."/" = {
|
||||||
|
extraConfig = ''
|
||||||
|
allow 192.168.0.0/16;
|
||||||
|
allow 10.8.0.0/24;
|
||||||
|
deny all;
|
||||||
|
'';
|
||||||
proxyPass = "http://localhost:7745";
|
proxyPass = "http://localhost:7745";
|
||||||
proxyWebsockets = true;
|
proxyWebsockets = true;
|
||||||
};
|
};
|
||||||
|
|
|
||||||
|
|
@ -24,6 +24,7 @@ lib.mkIf config.user.overseer.enable {
|
||||||
locations."/" = {
|
locations."/" = {
|
||||||
extraConfig = ''
|
extraConfig = ''
|
||||||
allow 192.168.0.0/16;
|
allow 192.168.0.0/16;
|
||||||
|
allow 10.8.0.0/24;
|
||||||
deny all;
|
deny all;
|
||||||
'';
|
'';
|
||||||
proxyPass = "http://localhost:8082";
|
proxyPass = "http://localhost:8082";
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue