Added radicale

This commit is contained in:
fwastring 2025-09-09 21:30:23 +02:00
parent 7f89ce17ab
commit fbd8f1fc96
2 changed files with 38 additions and 10 deletions

View file

@ -15,6 +15,7 @@
../../moduler/base.nix
../../moduler/users.nix
../../moduler/kitchenowl.nix
../../moduler/radicale.nix
#../../moduler/nginx.nix
#../../moduler/k3s.nix
../../moduler/vaultwarden.nix
@ -28,6 +29,7 @@
git
];
security.acme = {
acceptTerms = true;
defaults.email = "fredrik@wastring.com";
@ -42,15 +44,13 @@
enable = true;
recommendedProxySettings = true;
recommendedTlsSettings = true;
# other Nginx options
virtualHosts."shop.wastring.com" = {
enableACME = true;
forceSSL = true;
locations."/" = {
proxyPass = "http://127.0.0.1:8080";
proxyWebsockets = true; # needed if you need to use WebSocket
proxyWebsockets = true;
extraConfig =
# required when the target is also TLS server with multiple hosts
"proxy_ssl_server_name on;"
+
# required when the server wants to use HTTP Authentication
@ -59,7 +59,6 @@
};
};
# services.tailscale.enable = true;
# services.tailscale.package = pkgs.unstable.tailscale;

29
moduler/radicale.nix Normal file
View file

@ -0,0 +1,29 @@
{
...
}:
{
security.acme = {
certs."cal.wastring.com" = {
dnsProvider = "gandiv5";
webroot = null;
credentialsFile = /run/secrets/gandi_key;
dnsPropagationCheck = true;
};
};
services.nginx = {
virtualHosts."cal.wastring.com" = {
enableACME = true;
forceSSL = true;
locations."/" = {
proxyPass = "http://127.0.0.1:5232";
proxyWebsockets = true; # needed if you need to use WebSocket
extraConfig = "proxy_ssl_server_name on;" + "proxy_pass_header Authorization;";
};
};
};
services.radicale = {
enable = true;
settings.server.hosts = [ "0.0.0.0:5232" ];
};
}