switch to wildcard certs
This commit is contained in:
parent
5c7c56e598
commit
3ed18d33fc
|
@ -5,25 +5,10 @@
|
||||||
acceptTerms = true;
|
acceptTerms = true;
|
||||||
email = "admin+certs@graven.dev";
|
email = "admin+certs@graven.dev";
|
||||||
certs."graven.dev" = {
|
certs."graven.dev" = {
|
||||||
|
extraDomainNames = "*.graven.dev";
|
||||||
dnsProvider = "hurricane";
|
dnsProvider = "hurricane";
|
||||||
credentialsFile = config.secrets.files.acme_graven_dev.file;
|
credentialsFile = config.secrets.files.acme_graven_dev.file;
|
||||||
};
|
};
|
||||||
certs."turn.graven.dev" = {
|
|
||||||
dnsProvider = "hurricane";
|
|
||||||
credentialsFile = config.secrets.files.acme_turn_graven_dev.file;
|
|
||||||
};
|
|
||||||
certs."rss.graven.dev" = {
|
|
||||||
dnsProvider = "hurricane";
|
|
||||||
credentialsFile = config.secrets.files.acme_rss_graven_dev.file;
|
|
||||||
};
|
|
||||||
certs."git.graven.dev" = {
|
|
||||||
dnsProvider = "hurricane";
|
|
||||||
credentialsFile = config.secrets.files.acme_git_graven_dev.file;
|
|
||||||
};
|
|
||||||
certs."vault.graven.dev" = {
|
|
||||||
dnsProvider = "hurricane";
|
|
||||||
credentialsFile = config.secrets.files.acme_vault_graven_dev.file;
|
|
||||||
};
|
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
@ -17,8 +17,8 @@
|
||||||
no-multicast-peers
|
no-multicast-peers
|
||||||
";
|
";
|
||||||
secure-stun = true;
|
secure-stun = true;
|
||||||
cert = "/var/lib/acme/turn.graven.dev/fullchain.pem";
|
cert = "/var/lib/acme/graven.dev/fullchain.pem";
|
||||||
pkey = "/var/lib/acme/turn.graven.dev/key.pem";
|
pkey = "/var/lib/acme/graven.dev/key.pem";
|
||||||
min-port = 49152;
|
min-port = 49152;
|
||||||
max-port = 49999;
|
max-port = 49999;
|
||||||
};
|
};
|
||||||
|
|
|
@ -60,17 +60,17 @@
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
"rss.graven.dev" = {
|
"rss.graven.dev" = {
|
||||||
useACMEHost = "rss.graven.dev";
|
useACMEHost = "graven.dev";
|
||||||
forceSSL = true;
|
forceSSL = true;
|
||||||
};
|
};
|
||||||
"git.graven.dev" = {
|
"git.graven.dev" = {
|
||||||
useACMEHost = "git.graven.dev";
|
useACMEHost = "graven.dev";
|
||||||
forceSSL = true;
|
forceSSL = true;
|
||||||
locations."/".proxyPass = "http://unix:/run/gitea/gitea.sock:";
|
locations."/".proxyPass = "http://unix:/run/gitea/gitea.sock:";
|
||||||
};
|
};
|
||||||
"vault.graven.dev" = {
|
"vault.graven.dev" = {
|
||||||
forceSSL = true;
|
forceSSL = true;
|
||||||
useACMEHost = "vault.graven.dev";
|
useACMEHost = "graven.dev";
|
||||||
locations."/" = {
|
locations."/" = {
|
||||||
proxyPass = "http://localhost:8812";
|
proxyPass = "http://localhost:8812";
|
||||||
proxyWebsockets = true;
|
proxyWebsockets = true;
|
||||||
|
|
Loading…
Reference in a new issue