diff --git a/nixos/modules/services/security/warpgate.nix b/nixos/modules/services/security/warpgate.nix index 50b4811e66b6..35557c75eae8 100644 --- a/nixos/modules/services/security/warpgate.nix +++ b/nixos/modules/services/security/warpgate.nix @@ -160,6 +160,11 @@ in default = "[::]:2222"; type = str; }; + proxy_protocol = mkOption { + description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy."; + default = false; + type = bool; + }; external_host = mkOption { description = "The SSH listener is reachable via this domain name externally."; default = null; @@ -201,6 +206,11 @@ in default = "[::]:8888"; type = str; }; + proxy_protocol = mkOption { + description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy."; + default = false; + type = bool; + }; external_host = mkOption { description = "The HTTP listener is reachable via this domain name externally."; default = null; @@ -281,6 +291,11 @@ in default = "[::]:33306"; type = str; }; + proxy_protocol = mkOption { + description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy."; + default = false; + type = bool; + }; external_host = mkOption { description = "The MySQL listener is reachable via this domain name externally."; default = null; @@ -321,6 +336,11 @@ in default = "[::]:55432"; type = str; }; + proxy_protocol = mkOption { + description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy."; + default = false; + type = bool; + }; external_host = mkOption { description = "The PostgreSQL listener is reachable via this domain name externally."; default = null; @@ -353,6 +373,11 @@ in default = "[::]:8443"; type = str; }; + proxy_protocol = mkOption { + description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy."; + default = false; + type = bool; + }; external_host = mkOption { description = "The Kubernetes listener is reachable via this domain name externally."; default = null;