From 315434f232c300c52e49c421bf6279be01ac69e8 Mon Sep 17 00:00:00 2001 From: Lemon Lam Date: Wed, 19 Aug 2026 10:58:47 +0800 Subject: [PATCH] nixos/warpgate: proxy protocol support --- nixos/modules/services/security/warpgate.nix | 25 ++++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/nixos/modules/services/security/warpgate.nix b/nixos/modules/services/security/warpgate.nix index 50b4811e66b6..35557c75eae8 100644 --- a/nixos/modules/services/security/warpgate.nix +++ b/nixos/modules/services/security/warpgate.nix @@ -160,6 +160,11 @@ in default = "[::]:2222"; type = str; }; + proxy_protocol = mkOption { + description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy."; + default = false; + type = bool; + }; external_host = mkOption { description = "The SSH listener is reachable via this domain name externally."; default = null; @@ -201,6 +206,11 @@ in default = "[::]:8888"; type = str; }; + proxy_protocol = mkOption { + description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy."; + default = false; + type = bool; + }; external_host = mkOption { description = "The HTTP listener is reachable via this domain name externally."; default = null; @@ -281,6 +291,11 @@ in default = "[::]:33306"; type = str; }; + proxy_protocol = mkOption { + description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy."; + default = false; + type = bool; + }; external_host = mkOption { description = "The MySQL listener is reachable via this domain name externally."; default = null; @@ -321,6 +336,11 @@ in default = "[::]:55432"; type = str; }; + proxy_protocol = mkOption { + description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy."; + default = false; + type = bool; + }; external_host = mkOption { description = "The PostgreSQL listener is reachable via this domain name externally."; default = null; @@ -353,6 +373,11 @@ in default = "[::]:8443"; type = str; }; + proxy_protocol = mkOption { + description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy."; + default = false; + type = bool; + }; external_host = mkOption { description = "The Kubernetes listener is reachable via this domain name externally."; default = null;