diff --git a/hosts/servers/hosting-02.nix b/hosts/servers/hosting-02.nix index 83af31b..b6eb4d8 100644 --- a/hosts/servers/hosting-02.nix +++ b/hosts/servers/hosting-02.nix @@ -23,6 +23,7 @@ publicKey = "KkShcqgwbkX2A9n1hhST6qu+m3ldxdJ2Lx8Eiw6mdXw="; endpoint = "146.70.117.226:51820"; privateKeyFile = config.sops.secrets.wireguardKey.path; + dns = "10.64.0.1"; }; services.storagebox = { @@ -67,6 +68,24 @@ }; }; + services.gonic = { + enable = true; + settings = { + music-path = [ "/data/music" ]; + podcast-path = [ "/data/podcast" ]; + playlists-path = [ "/data/playlists" ]; + }; + }; + + services.nginx.virtualHosts."music.escapeangle.com" = { + forceSSL = true; + enableACME = true; + locations."/" = { + proxyPass = "http://localhost:4747"; + proxyWebsockets = true; + }; + }; + sops = { defaultSopsFile = ./hosting-02.yaml; secrets = { diff --git a/modules/nixos/namespaced-vpn.nix b/modules/nixos/namespaced-vpn.nix index b6f7a2a..e95e2c0 100644 --- a/modules/nixos/namespaced-vpn.nix +++ b/modules/nixos/namespaced-vpn.nix @@ -47,6 +47,11 @@ in type = types.str; default = "10.10.10.2/30"; }; + + dns = mkOption { + type = types.str; + default = "9.9.9.9"; + }; }; config = mkIf cfg.enable { @@ -138,5 +143,10 @@ in }; }; + environment.etc."netns/${cfg.namespace}/resolv.conf" = { + text = '' + nameserver ${cfg.dns} + ''; + }; }; }