summaryrefslogtreecommitdiff
path: root/modules/caddy.nix
diff options
context:
space:
mode:
Diffstat (limited to 'modules/caddy.nix')
-rw-r--r--modules/caddy.nix55
1 files changed, 28 insertions, 27 deletions
diff --git a/modules/caddy.nix b/modules/caddy.nix
index 9c8e70d..d9023f5 100644
--- a/modules/caddy.nix
+++ b/modules/caddy.nix
@@ -1,8 +1,4 @@
-{
- pkgs,
- lib,
- ...
-}:
+{ config, ... }:
let
tailnet = import ../tailnet.nix;
@@ -15,32 +11,37 @@ in
443
];
- services.caddy = {
- enable = true;
-
- package = pkgs.caddy.withPlugins {
- plugins = [
- "github.com/mholt/caddy-l4@v0.1.2"
- ];
+ # TCP forwarding lives here alongside Caddy's HTTP/HTTPS reverse proxies.
+ systemd.sockets.git-ssh-proxy = {
+ wantedBy = [ "sockets.target" ];
+ listenStreams = [ "0.0.0.0:22" ];
+ };
- hash = lib.fakeHash;
+ systemd.services.git-ssh-proxy = {
+ description = "TCP proxy for Git SSH";
+ requires = [ "git-ssh-proxy.socket" ];
+ serviceConfig = {
+ ExecStart = "${config.systemd.package}/lib/systemd/systemd-socket-proxyd ${tailnet.dijkstra-git}:22";
+ DynamicUser = true;
};
+ };
- globalConfig = ''
- layer4 {
- 0.0.0.0:22 {
- route {
- proxy ${tailnet.dijkstra-git}:22
- }
- }
+ systemd.sockets.minecraft-proxy = {
+ wantedBy = [ "sockets.target" ];
+ listenStreams = [ "0.0.0.0:25565" ];
+ };
- 0.0.0.0:25565 {
- route {
- proxy ${tailnet.dijkstra}:25565
- }
- }
- }
- '';
+ systemd.services.minecraft-proxy = {
+ description = "TCP proxy for Minecraft";
+ requires = [ "minecraft-proxy.socket" ];
+ serviceConfig = {
+ ExecStart = "${config.systemd.package}/lib/systemd/systemd-socket-proxyd ${tailnet.dijkstra}:25565";
+ DynamicUser = true;
+ };
+ };
+
+ services.caddy = {
+ enable = true;
extraConfig = ''
# TODO: make it nice