From fdde154c63eeb8e6aac5129f9226f38c4b0b8bf0 Mon Sep 17 00:00:00 2001 From: Grace Yoder Date: Sat, 3 Oct 2026 14:54:12 -0400 Subject: hamano again --- modules/caddy.nix | 55 ++++++++++++++++++++++++++++--------------------------- 1 file changed, 28 insertions(+), 27 deletions(-) (limited to 'modules/caddy.nix') diff --git a/modules/caddy.nix b/modules/caddy.nix index 9c8e70d..d9023f5 100644 --- a/modules/caddy.nix +++ b/modules/caddy.nix @@ -1,8 +1,4 @@ -{ - pkgs, - lib, - ... -}: +{ config, ... }: let tailnet = import ../tailnet.nix; @@ -15,32 +11,37 @@ in 443 ]; - services.caddy = { - enable = true; - - package = pkgs.caddy.withPlugins { - plugins = [ - "github.com/mholt/caddy-l4@v0.1.2" - ]; + # TCP forwarding lives here alongside Caddy's HTTP/HTTPS reverse proxies. + systemd.sockets.git-ssh-proxy = { + wantedBy = [ "sockets.target" ]; + listenStreams = [ "0.0.0.0:22" ]; + }; - hash = lib.fakeHash; + systemd.services.git-ssh-proxy = { + description = "TCP proxy for Git SSH"; + requires = [ "git-ssh-proxy.socket" ]; + serviceConfig = { + ExecStart = "${config.systemd.package}/lib/systemd/systemd-socket-proxyd ${tailnet.dijkstra-git}:22"; + DynamicUser = true; }; + }; - globalConfig = '' - layer4 { - 0.0.0.0:22 { - route { - proxy ${tailnet.dijkstra-git}:22 - } - } + systemd.sockets.minecraft-proxy = { + wantedBy = [ "sockets.target" ]; + listenStreams = [ "0.0.0.0:25565" ]; + }; - 0.0.0.0:25565 { - route { - proxy ${tailnet.dijkstra}:25565 - } - } - } - ''; + systemd.services.minecraft-proxy = { + description = "TCP proxy for Minecraft"; + requires = [ "minecraft-proxy.socket" ]; + serviceConfig = { + ExecStart = "${config.systemd.package}/lib/systemd/systemd-socket-proxyd ${tailnet.dijkstra}:25565"; + DynamicUser = true; + }; + }; + + services.caddy = { + enable = true; extraConfig = '' # TODO: make it nice -- cgit v1.3.1