This pattern is error prone, especially with __structuredAttrs, where
nested lists can leave important attributes such as `patches` null.
The treewide rewrite was produced with ast-grep, followed by `nix fmt`
and manual fixes for two `sema-undefined-variable` violations.
Future occurrences will be rejected by nixpkgs-vet once this change is
merged:
https://github.com/NixOS/nixpkgs-vet/pull/301
A module opts in with `dynamic = true` The build writes a `load_module`
line for every .so it installed to $out/etc/nginx/dynamic-modules.conf,
and the NixOS module includes that file.
Closes: #258260
Assisted-by: Claude:claude-fable-5-1
compressMimeTypes documents itself as being taken from the ngx_brotli sample
configuration and h5bp/server-configs-nginx, but had drifted from both.
Most notably "application/rss+xml" was missing while "application/x-rss+xml"
(the older, non-standard spelling) was present, so RSS feeds served from a
".rss" file went out uncompressed. Both referenced configs list it, and it is
what the default mailcap mime.types database maps ".rss" to.
Also add the remaining types those references recommend and we did not carry:
application/vnd.api+json (ngx_brotli)
application/x-javascript (both)
text/x-cross-domain-policy (h5bp)
plus "image/x-icon" and "image/x-ms-bmp", which nginx's own conf/mime.types
maps ".ico" and ".bmp" to. Those matter when services.nginx.defaultMimeTypes
points at nginx's database instead of mailcap, as its own example suggests.
Superseded aliases the references still list (font/eot, font/opentype,
font/truetype, application/x-font-*, image/x-win-bitmap) are deliberately left
out: no mime.types database we ship maps to them, and the registered
equivalents are already covered.
The new nginx-compression test serves one file per extension that the default
mime.types database maps to a type recommendedGzipSettings is expected to
compress, and asserts every response comes back gzipped. The type mapping
itself is deliberately not pinned, so the test only fails when a type nginx
actually serves is missing from compressMimeTypes -- which is how ".rss"
slipped through. It also asserts already-compressed formats are served
verbatim.
Assisted-by: Claude Code (Claude Opus 5)
If enabled, it sets up error pages that are valid gRPC messages.
This is useful if you proxy gRPC and want to emit errors from nginx, for
example when adding authentication on top.
Otherwise nginx prints warnings such as the following when using lua code:
nginx: lua atpanic: Lua VM crashed, reason: runtime code generation failed, restricted kernel?
Add `services.nginx.lua.{enable,extraPackages}` to enable OpenResty's
lua-nginx-module on a stock nginx. When enabled it adds the module,
includes lua-resty-core, and wires up lua_package_path /
lua_package_cpath (and lua_ssl_trusted_certificate) from a
luajit_openresty package set built from extraPackages.
When the configured package already bundles Lua (openresty), the module
and bundled libraries are not re-added; only the search path is set up so
its own lualib stays in use.
Migrate the openresty-lua test to the new option and add an nginx-lua
test covering the stock-nginx path.
Assisted-by: Claude:claude-opus-4-8
Give hints about how to configure TLSv1.3 ciphersuites, because they get
configured somewhere else and the "incomplete" list might throw people
off.
Remove TLSv1 and TLSv1.1 from examples, they should not be used any more.
When a request has no body but Content-Length does have a value, the
request can hang waiting for the body.
We should clear out the Content-Length header when forwarding the
request without the body.
The Mozilla Server-Side TLS guide is lagging quite a bit, because since
OpenSSL 3.5.0 we can provide hybrid key exchanges, that hopefully protect
against "store now, decrypt later" attacks, that could be applied once
capable quantum computers eventually come into existance.
> The ngx_http_v3_module module (1.25.0) provides experimental support
> for HTTP/3.
Yes, still experimental, at least in nginx. No mention in angie.
> 0-RTT support requires the OpenSSL library version 3.5.1 or higher.
> Alternatively, BoringSSL, LibreSSL, or QuicTLS libraries can be used to
> build and run this module.
But OpenSSL gets the first mention and our OpenSSL version right now is
3.6.0.
That means we don't need two more packages to ship nginx built with
QuicTLS which does not yet support PQ crypto right.
The option services.nginx.virtualHost.<...>.enableSSL is deprecated for
8 years [^1]. It causes confusion for people who guess the option and
think it's the right one.
I think it's time to remove it for good.
^1: a912a6a291
Currently, nginx gets restarted when adding a new ACME certificate, even
when `services.nginx.enableReload = true` because of changes in the
Wants/After/Before sections of `nginx.service`.
This change moves these dependencies to `nginx-config-reload.service` and
the respective ACME systemd units.
The previous setup caused all renewal units to be triggered upon
ever so slight changes in config. In larger setups (100+ certificates)
adding a new certificate caused high system load and/or large memory
consumption issues. The memory issues are already a alleviated with
the locking mechanism. However, this then causes long delays upwards
of multiple minutes depending on individual runs and also caused
superfluous activations.
In this change we streamline the overall setup of units:
1. The unit that other services can depend upon is 'acme-{cert}.service'.
We call this the 'base unit'. As this one as `RemainAfterExit` set
the `acme-finished-{cert}` targets are not required any longer.
2. We now always generate initial self-signed certificates to simplify
the dependency structure. This deprecates the `preliminarySelfsigned`
option.
3. The `acme-order-renew-{cert}` service gets activated after the base
unit and services using certificates have started and performs all acme
interactions. When it finishes others services (like web servers) will
be notified through the `reloadServices` option or they can use
`wantedBy` and `after` dependencies if they implement their own reload
units.
The renewal timer also triggers this unit.
4. The timer unit is explicitly blocked from being started by s-t-c.
5. Permission management has been cleaned up a bit: there was an
inconsistency between having the .lego files set to 600 vs 640
on the exposed side. This is unified to 640 now.
6. Exempt the account target from being restarted by s-t-c. This will
happen automatically if something relevant to the account changes.