2024-04-16 02:32:16 +02:00
|
|
|
{lib, ...}: {
|
2024-04-24 02:06:04 +02:00
|
|
|
security.acme.certs = {
|
|
|
|
"caspervk.net" = {
|
|
|
|
domain = "*.caspervk.net";
|
|
|
|
reloadServices = [
|
|
|
|
"caddy.service"
|
|
|
|
"murmur.service"
|
|
|
|
];
|
|
|
|
# The NixOS Caddy module is a little too clever and sets the cert's group
|
|
|
|
# to 'caddy', which means other services can't load it. This is not needed
|
|
|
|
# since we handle the group membership manually.
|
|
|
|
group = lib.mkForce "acme";
|
|
|
|
};
|
2024-04-10 01:52:08 +02:00
|
|
|
};
|
|
|
|
users.groups.acme.members = [
|
2024-04-16 01:26:43 +02:00
|
|
|
"caddy"
|
2024-04-10 01:52:08 +02:00
|
|
|
"murmur"
|
|
|
|
];
|
|
|
|
}
|