Commit Graph

327 Commits

Author SHA1 Message Date
Michael Daniels
3b6689cb66 treewide: remove optional cond [...] (#560097) 2026-09-08 23:49:27 +00:00
Ihar Hrachyshka
a6479a6e32 treewide: remove optional cond [ ... ]
This pattern is error prone, especially with __structuredAttrs, where
nested lists can leave important attributes such as `patches` null.

The treewide rewrite was produced with ast-grep, followed by `nix fmt`
and manual fixes for two `sema-undefined-variable` violations.

Future occurrences will be rejected by nixpkgs-vet once this change is
merged:

https://github.com/NixOS/nixpkgs-vet/pull/301
2026-09-07 20:41:05 -04:00
Ilan Joselevich
27719f2425 nginx: support dynamic modules
A module opts in with `dynamic = true` The build writes a `load_module`
line for every .so it installed to $out/etc/nginx/dynamic-modules.conf,
and the NixOS module includes that file.

Closes: #258260

Assisted-by: Claude:claude-fable-5-1
2026-09-05 15:36:26 +02:00
Nelson Vides
e03c04e689 nixos/nginx: add missing types from the referenced compression configs
compressMimeTypes documents itself as being taken from the ngx_brotli sample
configuration and h5bp/server-configs-nginx, but had drifted from both.

Most notably "application/rss+xml" was missing while "application/x-rss+xml"
(the older, non-standard spelling) was present, so RSS feeds served from a
".rss" file went out uncompressed. Both referenced configs list it, and it is
what the default mailcap mime.types database maps ".rss" to.

Also add the remaining types those references recommend and we did not carry:

  application/vnd.api+json      (ngx_brotli)
  application/x-javascript      (both)
  text/x-cross-domain-policy    (h5bp)

plus "image/x-icon" and "image/x-ms-bmp", which nginx's own conf/mime.types
maps ".ico" and ".bmp" to. Those matter when services.nginx.defaultMimeTypes
points at nginx's database instead of mailcap, as its own example suggests.

Superseded aliases the references still list (font/eot, font/opentype,
font/truetype, application/x-font-*, image/x-win-bitmap) are deliberately left
out: no mime.types database we ship maps to them, and the registered
equivalents are already covered.

The new nginx-compression test serves one file per extension that the default
mime.types database maps to a type recommendedGzipSettings is expected to
compress, and asserts every response comes back gzipped. The type mapping
itself is deliberately not pinned, so the test only fails when a type nginx
actually serves is missing from compressMimeTypes -- which is how ".rss"
slipped through. It also asserts already-compressed formats are served
verbatim.

Assisted-by: Claude Code (Claude Opus 5)
2026-08-26 10:47:18 +02:00
Michael Daniels
c8575682d1 Merge branch 'master' into staging-next 2026-08-21 20:22:07 -04:00
Florian Klink
833cd50ea6 nixos/nginx: add locations.<name>.useGrpcErrorPages option
If enabled, it sets up error pages that are valid gRPC messages.
This is useful if you proxy gRPC and want to emit errors from nginx, for
example when adding authentication on top.
2026-08-21 21:22:26 +03:00
Maximilian Bosch
ea6542782d nixos/nginx: generally turn off MemoryDenyWriteExecute
See #384302 for the issues associated with it.
2026-08-07 21:01:30 +02:00
Tom Herbers
238c598440 tengine: drop
Drop due to seriously delayed responses to security vulnerabilities.
2026-08-03 16:58:38 +02:00
Leona Maroni
34ce4d9ac2 nixos/nginx: setup logrotate to send kill USR1 signal only once (#362733) 2026-07-26 15:48:40 +00:00
Sandro Jäckel
4080106f0b nixos/nginx: do not match pkgs.openresty as some modules like brotli add buildInputs
--- /dev/fd/63	2026-07-12 01:29:24.447317728 +0200
+++ /dev/fd/62	2026-07-12 01:29:24.448317734 +0200
@@ -4,7 +4,7 @@
         [ ( "doc"
           , DerivationOutput
               { path =
-                  "/nix/store/r2jdcgwxp2a4pa1cxa6yvf9p0f7wi1ih-openresty-1.31.1.1-doc"
+                  "/nix/store/syrb1ccks4vqgg25ygrylahxglknrc5j-openresty-1.31.1.1-doc"
               , hashAlgo = ""
               , hash = ""
               }
@@ -12,7 +12,7 @@
         , ( "out"
           , DerivationOutput
               { path =
-                  "/nix/store/2saawkswxnxs4ffb98r7bidy4vj6259c-openresty-1.31.1.1"
+                  "/nix/store/n48gwmah2pxfc8vg7dc3ki0c4xmszr1d-openresty-1.31.1.1"
               , hashAlgo = ""
               , hash = ""
               }
@@ -62,12 +62,18 @@
         , ( "/nix/store/v2k6k32vbrfsl2cciclgl1k8v8c3jxv8-nginx-doc-unstable-0-unstable-2026-05-15.drv"
           , fromList [ "out" ]
           )
+        , ( "/nix/store/wkgfkcxnpk1dy9qdd7m22ifkhyxn1hd5-brotli-1.2.0.drv"
+          , fromList [ "dev" ]
+          )
         , ( "/nix/store/wx2j9jzk90dlsz9wvbrjdxlm4q1vf8aq-openresty-nix-etag-1.15.4.patch.drv"
           , fromList [ "out" ]
           )
         , ( "/nix/store/xk8m6ai5q00gr0h3vm8afc5dk1plpw9i-install-shell-files.drv"
           , fromList [ "out" ]
           )
+        , ( "/nix/store/xy1vwc4173xz5hz2yjv7z83gz3ss6h72-brotli.drv"
+          , fromList [ "out" ]
+          )
         , ( "/nix/store/zhhm8h70q64qgwg3bccc7ygwy48jn5c3-libxml2-2.15.3.drv"
           , fromList [ "dev" ]
           )
@@ -95,14 +101,14 @@
           )
         , ( "__structuredAttrs" , "" )
         , ( "buildInputs"
-          , "/nix/store/i0jqva96qfgc76g8w7jbyiv6h3si07b9-openssl-3.6.2-dev /nix/store/a9psmsc93llkravrd50rrv8k3dwdw60x-zlib-1.3.2-dev /nix/store/y5yv1kzvmppzdp0jkq3yf3apx563canv-pcre2-10.46-dev /nix/store/35wfzwiy77ab9dhzjblb4kmdnckss40i-libxml2-2.15.3-dev /nix/store/9vgz8w91lcw9f43glyqmfj50v1hvgkmp-libxslt-1.1.45-dev /nix/store/k7kxg101ikkm0cyf8jcqhg948vy542af-perl-5.42.0 /nix/store/hzdwjd2s60585lygfj81qdhm2825frsm-libpq-18.4-dev"
+          , "/nix/store/i0jqva96qfgc76g8w7jbyiv6h3si07b9-openssl-3.6.2-dev /nix/store/a9psmsc93llkravrd50rrv8k3dwdw60x-zlib-1.3.2-dev /nix/store/y5yv1kzvmppzdp0jkq3yf3apx563canv-pcre2-10.46-dev /nix/store/35wfzwiy77ab9dhzjblb4kmdnckss40i-libxml2-2.15.3-dev /nix/store/9vgz8w91lcw9f43glyqmfj50v1hvgkmp-libxslt-1.1.45-dev /nix/store/k7kxg101ikkm0cyf8jcqhg948vy542af-perl-5.42.0 /nix/store/hzdwjd2s60585lygfj81qdhm2825frsm-libpq-18.4-dev /nix/store/pcq77h5mhc5nfvf1rs92a5l5g0kaapdg-brotli-1.2.0-dev"
           )
         , ( "builder"
           , "/nix/store/zh1ijdhb6gng1509b1zrilb6xlzx60j6-bash-5.3p9/bin/bash"
           )
         , ( "cmakeFlags" , "" )
         , ( "configureFlags"
-          , "--sbin-path=bin/nginx --with-http_ssl_module --with-http_v2_module --with-http_v3_module --with-http_realip_module --with-http_addition_module --with-http_xslt_module --with-http_sub_module --with-http_dav_module --with-http_flv_module --with-http_mp4_module --with-http_gunzip_module --with-http_gzip_static_module --with-http_auth_request_module --with-http_random_index_module --with-http_secure_link_module --with-http_degradation_module --with-http_stub_status_module --with-threads --with-pcre-jit --http-log-path=/var/log/nginx/access.log --error-log-path=/var/log/nginx/error.log --pid-path=/var/log/nginx/nginx.pid --http-client-body-temp-path=/tmp/nginx_client_body --http-proxy-temp-path=/tmp/nginx_proxy --http-fastcgi-temp-path=/tmp/nginx_fastcgi --http-uwsgi-temp-path=/tmp/nginx_uwsgi --http-scgi-temp-path=/tmp/nginx_scgi --with-openssl-opt=enable-ktls --with-stream --with-stream_realip_module --with-stream_ssl_module --with-stream_ssl_preread_module --with-file-aio --with-http_postgres_module"
+          , "--sbin-path=bin/nginx --with-http_ssl_module --with-http_v2_module --with-http_v3_module --with-http_realip_module --with-http_addition_module --with-http_xslt_module --with-http_sub_module --with-http_dav_module --with-http_flv_module --with-http_mp4_module --with-http_gunzip_module --with-http_gzip_static_module --with-http_auth_request_module --with-http_random_index_module --with-http_secure_link_module --with-http_degradation_module --with-http_stub_status_module --with-threads --with-pcre-jit --http-log-path=/var/log/nginx/access.log --error-log-path=/var/log/nginx/error.log --pid-path=/var/log/nginx/nginx.pid --http-client-body-temp-path=/tmp/nginx_client_body --http-proxy-temp-path=/tmp/nginx_proxy --http-fastcgi-temp-path=/tmp/nginx_fastcgi --http-uwsgi-temp-path=/tmp/nginx_uwsgi --http-scgi-temp-path=/tmp/nginx_scgi --with-openssl-opt=enable-ktls --with-stream --with-stream_realip_module --with-stream_ssl_module --with-stream_ssl_preread_module --with-file-aio --with-http_postgres_module --add-module=/nix/store/sw63grm2cbi76pcq44izm8f8fdvzjafn-brotli"
           )
         , ( "configurePlatforms" , "" )
         , ( "depsBuildBuild" , "" )
@@ -113,11 +119,13 @@
         , ( "depsHostHostPropagated" , "" )
         , ( "depsTargetTarget" , "" )
         , ( "depsTargetTargetPropagated" , "" )
-        , ( "disallowedReferences" , "" )
+        , ( "disallowedReferences"
+          , "/nix/store/sw63grm2cbi76pcq44izm8f8fdvzjafn-brotli"
+          )
         , ( "doCheck" , "" )
         , ( "doInstallCheck" , "" )
         , ( "doc"
-          , "/nix/store/r2jdcgwxp2a4pa1cxa6yvf9p0f7wi1ih-openresty-1.31.1.1-doc"
+          , "/nix/store/syrb1ccks4vqgg25ygrylahxglknrc5j-openresty-1.31.1.1-doc"
           )
         , ( "enableParallelBuilding" , "1" )
         , ( "enableParallelChecking" , "1" )
@@ -129,7 +137,7 @@
           )
         , ( "nginxVersion" , "1.31.1" )
         , ( "out"
-          , "/nix/store/2saawkswxnxs4ffb98r7bidy4vj6259c-openresty-1.31.1.1"
+          , "/nix/store/n48gwmah2pxfc8vg7dc3ki0c4xmszr1d-openresty-1.31.1.1"
           )
         , ( "outputs" , "out doc" )
         , ( "patches"
@@ -137,7 +145,7 @@
           )
         , ( "pname" , "openresty" )
         , ( "postInstall"
-          , "ln -s $out/luajit/bin/luajit-2.1.ROLLING $out/bin/luajit-openresty\nln -sf $out/nginx/bin/nginx $out/bin/openresty\nln -s $out/nginx/bin/nginx $out/bin/nginx\nln -s $out/nginx/conf $out/conf\nln -s $out/nginx/html $out/html\n\nwrapProgram $out/bin/restydoc \\\n  --prefix PATH : /nix/store/i6jrv1f3mygdh2gv5r2yn1lm77d3qals-groff-1.24.1/bin\n\nsubstituteInPlace $out/bin/resty \\\n  --replace-fail \"'bin/nginx'\" \"'$out/bin/nginx'\"\n"
+          , "ln -s $out/luajit/bin/luajit-2.1.ROLLING $out/bin/luajit-openresty\nln -sf $out/nginx/bin/nginx $out/bin/openresty\nln -s $out/nginx/bin/nginx $out/bin/nginx\nln -s $out/nginx/conf $out/conf\nln -s $out/nginx/html $out/html\n\nwrapProgram $out/bin/restydoc \\\n  --prefix PATH : /nix/store/i6jrv1f3mygdh2gv5r2yn1lm77d3qals-groff-1.24.1/bin\n\nsubstituteInPlace $out/bin/resty \\\n  --replace-fail \"'bin/nginx'\" \"'$out/bin/nginx'\"\nremove-references-to -t /nix/store/sw63grm2cbi76pcq44izm8f8fdvzjafn-brotli $(readlink -fn $out/bin/nginx)\n"
           )
         , ( "postPatch"
           , "substituteInPlace bundle/nginx-1.31.1/src/http/ngx_http_core_module.c \\\n  --replace-fail '@nixStoreDir@' \"$NIX_STORE\" \\\n  --replace-fail '@nixStoreDirLen@' \"${#NIX_STORE}\"\n\npatchShebangs configure bundle/\n"
2026-07-14 13:15:19 +02:00
Sandro Jäckel
323b76b823 Revert "nixos/nginx: disable MemoryDenyWriteExecute when lua with luajit is enabled"
This reverts commit 04b527753e.
2026-07-12 01:33:42 +02:00
Sandro Jäckel
04b527753e nixos/nginx: disable MemoryDenyWriteExecute when lua with luajit is enabled
Otherwise nginx prints warnings such as the following when using lua code:

nginx: lua atpanic: Lua VM crashed, reason: runtime code generation failed, restricted kernel?
2026-07-11 02:44:04 +02:00
Jean-Baptiste Giraudeau
e32b3af849 nixos/nginx: setup logrotate to send kill USR1 signal only once
by setting `sharedscripts = true` so that nginx receive
the kill USR1 signal only once at the end, instead of once per log file.
2026-07-05 15:46:07 +02:00
Maximilian Bosch
309b10bfca nixos/nginx: Always symlink nginx configuration to /etc/nginx/nginx.conf (#164100) 2026-07-04 10:25:07 +00:00
Maximilian Bosch
27fbd73b93 nixos/nginx: not using reuseport for unix domain listens (#473182) 2026-07-03 15:07:37 +00:00
Victor Nawothnig
dc68e7fd15 nixos/nginx: Always symlink nginx configuration to /etc/nginx/nginx.conf 2026-07-03 16:51:56 +02:00
Maximilian Bosch
5fd9527f61 nginx: add ma27 and leona to maintainers, remove inactive maintainers (#536585) 2026-06-29 10:33:26 +00:00
Leona Maroni
54bf69f9d7 nixos/nginx: add leona and ma27 as maintainers 2026-06-29 10:52:49 +02:00
Ilan Joselevich
eaffe290dd nixos/nginx: add lua option for Lua scripting support
Add `services.nginx.lua.{enable,extraPackages}` to enable OpenResty's
lua-nginx-module on a stock nginx. When enabled it adds the module,
includes lua-resty-core, and wires up lua_package_path /
lua_package_cpath (and lua_ssl_trusted_certificate) from a
luajit_openresty package set built from extraPackages.

When the configured package already bundles Lua (openresty), the module
and bundled libraries are not re-added; only the search path is set up so
its own lualib stays in use.

Migrate the openresty-lua test to the new option and add an nginx-lua
test covering the stock-nginx path.

Assisted-by: Claude:claude-opus-4-8
2026-06-25 00:56:45 +03:00
Michael Hoang
6d1bbc317c nixos/nginx: drop option for configuring DHE
This option is no longer necessary as DHE is deprecated in NixOS as of #513396
and ECDHE does not require any configuration changes.
2026-05-25 09:18:10 +02:00
Michael Hoang
6db66126ec nixos/nginx: sync Mozilla recommended cipher list
https://ssl-config.mozilla.org/#server=nginx&config=intermediate&guideline=6.0
https://wiki.mozilla.org/Security/Server_Side_TLS#Version_History
2026-05-25 09:15:25 +02:00
Martin Weinelt
dd3f260355 nixos/nginx: make cipher configuration structured
Give hints about how to configure TLSv1.3 ciphersuites, because they get
configured somewhere else and the "incomplete" list might throw people
off.

Remove TLSv1 and TLSv1.1 from examples, they should not be used any more.
2026-05-05 01:11:07 +02:00
Sandro
1d74c186d4 nixos/nginx: allow using security.dhparams via sslDhparam = true (#452972) 2026-03-09 23:27:39 +00:00
n0099
22f3caf747 nixos/nginx: allow using security.dhparams via sslDhparam = true
Currently `security.dhparams` is only used by `services.dovecot2` : 98ff3f9af2/nixos/modules/services/mail/dovecot.nix (L627-L630)
Co-authored-by: Sandro <sandro.jaeckel@gmail.com>
2026-01-06 14:53:27 +00:00
Glen Huang
4f10f5d413 nixos/nginx: not using reuseport for unix domain listens 2025-12-22 14:10:30 +08:00
Martin Weinelt
788e084c85 nixos/nginx: add support for PQ key exchanges in TLS1.3
The Mozilla Server-Side TLS guide is lagging quite a bit, because since
OpenSSL 3.5.0 we can provide hybrid key exchanges, that hopefully protect
against "store now, decrypt later" attacks, that could be applied once
capable quantum computers eventually come into existance.
2025-11-25 03:44:45 +01:00
Martin Weinelt
6d95c0c8b6 nginxQuic, angieQuic: retire
> The ngx_http_v3_module module (1.25.0) provides experimental support
> for HTTP/3.

Yes, still experimental, at least in nginx. No mention in angie.

> 0-RTT support requires the OpenSSL library version 3.5.1 or higher.
> Alternatively, BoringSSL, LibreSSL, or QuicTLS libraries can be used to
>  build and run this module.

But OpenSSL gets the first mention and our OpenSSL version right now is
3.6.0.

That means we don't need two more packages to ship nginx built with
QuicTLS which does not yet support PQ crypto right.
2025-11-25 00:13:58 +01:00
osbm
66f490f4b9 treewide: replace Cyrillic characters with Latin 2025-11-14 16:32:16 +03:00
h7x4
1b42cb3018 nixos/nginx: lib.mapAttrsToList -> lib.attrValues 2025-10-26 15:33:34 +09:00
Leona Maroni
05026b194c nixos/nginx: remove deprecated vhost option enableSSL (#446053) 2025-10-23 13:36:01 +00:00
Leona Maroni
a2d81c0a43 nixos/nginx: allow adding new ACME certificates without nginx restart (#445544) 2025-10-14 07:52:56 +00:00
Leona Maroni
6b7e5a5aca nixos/nginx: remove deprecated vhost option enableSSL
The option services.nginx.virtualHost.<...>.enableSSL is deprecated for
8 years [^1]. It causes confusion for people who guess the option and
think it's the right one.
I think it's time to remove it for good.

^1: a912a6a291
2025-09-25 16:34:38 +02:00
Leona Maroni
b3a76d495e nixos/nginx: allow adding new ACME certificates without nginx restart
Currently, nginx gets restarted when adding a new ACME certificate, even
when `services.nginx.enableReload = true` because of changes in the
Wants/After/Before sections of `nginx.service`.
This change moves these dependencies to `nginx-config-reload.service` and
the respective ACME systemd units.
2025-09-25 10:36:42 +02:00
Leona Maroni
33dc105554 nixos/nginx: set X-Forwarded-Server proxy header to hostname
X-Forwarded-Server represents the last server in a row of reverse proxies
in the common use, see:
- https://www.fastly.com/documentation/reference/http/http-headers/X-Forwarded-Server/
- https://httpd.apache.org/docs/2.4/mod/mod_proxy.html#x-headers
- https://docs.valsight.com/on-premise/latest/reverse-proxy

X-Forwarded-Host instead is the original request host.

This change adapts our NGINX module to the common use of this header.
2025-09-23 22:22:35 +02:00
isabel
4ff7ee96bf nixos/nginx: add prependConfig options (#416411) 2025-08-16 18:55:51 +01:00
Christian Theune
2d0a489125 nixos/acme: improve scalability - reduce superfluous unit activations
The previous setup caused all renewal units to be triggered upon
ever so slight changes in config. In larger setups (100+ certificates)
adding a new certificate caused high system load and/or large memory
consumption issues. The memory issues are already a alleviated with
the locking mechanism. However, this then causes long delays upwards
of multiple minutes depending on individual runs and also caused
superfluous activations.

In this change we streamline the overall setup of units:

1. The unit that other services can depend upon is 'acme-{cert}.service'.
We call this the 'base unit'. As this one as `RemainAfterExit` set
the `acme-finished-{cert}` targets are not required any longer.

2. We now always generate initial self-signed certificates to simplify
the dependency structure. This deprecates the `preliminarySelfsigned`
option.

3. The `acme-order-renew-{cert}` service gets activated after the base
unit and services using certificates have started and performs all acme
interactions. When it finishes others services (like web servers) will
be notified through the `reloadServices` option or they can use
`wantedBy` and `after` dependencies if they implement their own reload
units.

The renewal timer also triggers this unit.

4. The timer unit is explicitly blocked from being started by s-t-c.

5. Permission management has been cleaned up a bit: there was an
   inconsistency between having the .lego files set to 600 vs 640
   on the exposed side. This is unified to 640 now.

6. Exempt the account target from being restarted by s-t-c. This will
   happen automatically if something relevant to the account changes.
2025-08-08 16:28:42 +02:00
teutat3s
e62971b005 nixos/nginx: sync with Mozilla Intermediate TLS configuration
- adds ssl_ecdh_curve, per https://github.com/mozilla/ssl-config-generator/issues/76
- removes ssl_stapling, after Let's Encrypt ended support for OCSP
  stapling https://letsencrypt.org/2024/12/05/ending-ocsp/, enabling ssl_stapling
  leads to warning log spam:
```
  ssl_stapling" ignored, no OCSP responder URL in the certificate "<cert-directory>
```
2025-07-26 14:26:28 +02:00
Wolfgang Walther
5a0711127c treewide: run nixfmt 1.0.0 2025-07-24 13:55:40 +02:00
Sandro Jäckel
0f964599a5 nixos/nginx: remove usage of recommendedZstdSettings and zstd settings duplication 2025-07-16 14:14:03 +02:00
Franz Pletz
db75f90103 nixos/nginx: remove recommendedZstdSettings, add experimental option
The zstd nginx module has known bugs and upstream is currently not
maintained. We should not recommend a buggy module and configuration
to our users since we are not maintaining the module either.
2025-07-03 17:41:22 +02:00
vdbe
b8d052a70d nixos/nginx: add prependConfig options
This is needed for example to load dynamic nginx modules.
Which need to be loaded before any `http` or `stream` blocks.
See: https://docs.nginx.com/nginx/admin-guide/dynamic-modules/dynamic-modules/#installing-and-loading-the-module
2025-06-13 12:21:18 +02:00
Maximilian Bosch
4a2a4193f9 nixos/nginx: fix type of mapHashBucketSize
While the default is indeed 32/64/128, the option accepts any `size`[1]
including values >128, as observed in a customer project.

[1] https://nginx.org/en/docs/http/ngx_http_map_module.html
2025-06-05 14:58:17 +02:00
Bert Proesmans
4c02c43a42 nixos/nginx: fix mkDefaultListenVhost mapping for unix sockets 2025-04-03 19:57:26 +00:00
Silvan Mosberger
374e6bcc40 treewide: Format all Nix files
Format all Nix files using the officially approved formatter,
making the CI check introduced in the previous commit succeed:

  nix-build ci -A fmt.check

This is the next step of the of the [implementation](https://github.com/NixOS/nixfmt/issues/153)
of the accepted [RFC 166](https://github.com/NixOS/rfcs/pull/166).

This commit will lead to merge conflicts for a number of PRs,
up to an estimated ~1100 (~33%) among the PRs with activity in the past 2
months, but that should be lower than what it would be without the previous
[partial treewide format](https://github.com/NixOS/nixpkgs/pull/322537).

Merge conflicts caused by this commit can now automatically be resolved while rebasing using the
[auto-rebase script](8616af08d9/maintainers/scripts/auto-rebase).

If you run into any problems regarding any of this, please reach out to the
[formatting team](https://nixos.org/community/teams/formatting/) by
pinging @NixOS/nix-formatting.
2025-04-01 20:10:43 +02:00
Maximilian Bosch
303bd80713 Merge: nixos/nginx: add locations."name".uwsgiPass option and use it (#346776) 2025-03-01 12:34:20 +01:00
Maximilian Bosch
2ad694fff9 nixos/nginx: remove custom HTTP_ header from recommendedUwsgiSettings
`uwsgi_pass` uses the uwsgi protocol instead of the HTTP protocol
(that's what `proxy_pass` is for). Also, the source IP is already
derived from the REMOTE_ADDR param that's specified by the uwsgi
defaults from nginx, similarily to how it's done for fcgi.

Hence, removing that since it seems not necessary (and perhaps even
wrong).
2025-02-21 13:48:07 +01:00
K900
17f38bc01d nixos/acme: disable rate limiting to fix the test
Sometimes the nginx reload service fires too fast so systemd kills it.
2025-01-19 12:19:00 +03:00
Sandro Jäckel
a810945475 nixos/nginx: default resolver.ipv6 to networking.enableIPv6 2024-12-25 03:58:32 +01:00
Sandro Jäckel
d1a28bbdb4 nixos/nginx: add locations."name".uwsgiPass and related options and use it 2024-12-11 01:07:02 +01:00
Sandro Jäckel
996f9e4f28 nixos/nginx: don't disable IPC
This also disables the memfd_create syscall which is required for
certain regex's when using pcre2.

see https://github.com/NixOS/nixpkgs/pull/355989#issuecomment-2506841275
2024-11-29 00:41:46 +01:00