More acme setup
This commit is contained in:
@@ -23,7 +23,7 @@
|
|||||||
secrets."mc-arcadia/repo_password" = {};
|
secrets."mc-arcadia/repo_password" = {};
|
||||||
secrets."porkbun.keytab" = {
|
secrets."porkbun.keytab" = {
|
||||||
format = "binary";
|
format = "binary";
|
||||||
sopsFile = ./porkbun.keytab;
|
sopsFile = ../../secrets/diphda/porkbun.keytab;
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -63,11 +63,12 @@
|
|||||||
serviceConfig = {
|
serviceConfig = {
|
||||||
Type = "simple";
|
Type = "simple";
|
||||||
User = "eesim";
|
User = "eesim";
|
||||||
|
Group = "acme";
|
||||||
WorkingDirectory = "/home/eesim/scripts";
|
WorkingDirectory = "/home/eesim/scripts";
|
||||||
ExecStart = ''
|
ExecStart = ''
|
||||||
/home/eesim/scripts/dl_manager_tokio -vv \
|
/home/eesim/scripts/dl_manager_tokio -vv \
|
||||||
-c /home/eesim/scripts/certs/fullchain.cer \
|
-c /var/lib/acme/download.simmer505.com/cert.pem \
|
||||||
-k /home/eesim/scripts/certs/download.simmer505.com.key \
|
-k /var/lib/acme/download.simmer505.com/key.pem \
|
||||||
--script-dir /home/eesim/scripts/ \
|
--script-dir /home/eesim/scripts/ \
|
||||||
0.0.0.0:11112
|
0.0.0.0:11112
|
||||||
'';
|
'';
|
||||||
@@ -79,10 +80,7 @@
|
|||||||
defaults.email = "eesimmons9105@gmail.com";
|
defaults.email = "eesimmons9105@gmail.com";
|
||||||
certs."download.simmer505.com" = {
|
certs."download.simmer505.com" = {
|
||||||
dnsProvider = "porkbun";
|
dnsProvider = "porkbun";
|
||||||
environmentFile = "${pkgs.writeText "porkbun-creds" ''
|
environmentFile = "${config.sops.secrets."porkbun.keytab".path}";
|
||||||
PORKBUN_SECRET_API_KEY="$(cat ${config.sops.secrets."porkbun/api_key".path})"
|
|
||||||
PORKBUN_API_KEY="$(cat ${config.sops.secrets."porkbun/api_key".path})"
|
|
||||||
''}";
|
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user