Skip to content

shared

The shared host uses security-headers. knixl writes one file for it. The Nix below is the golden test output, so it is exactly what knixl emits.

hosts/shared.kdl
// Demonstrates let-hoisting: the same security-headers block is applied to two
// virtual hosts, so the generated file binds it once as _knixl0 and references it
// at both vhosts.
host "shared" {
system "x86_64-linux"
nixpkgs release="25.05"
security-headers {
vhost "a.example.com"
vhost "b.example.com"
}
}
generated/hosts/shared.nix
# Generated by knixl 1.5.2 from hosts/shared.kdl
# Do NOT edit. Regenerate from the KDL source.
# Overrides: add a sibling module and use lib.mkForce / lib.mkAfter.
{
config,
lib,
pkgs,
...
}:
let
_knixl0 = ''
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
'';
in
{
nixpkgs.hostPlatform = "x86_64-linux";
networking.hostName = "shared";
services.nginx.virtualHosts."a.example.com".extraConfig = _knixl0;
services.nginx.virtualHosts."b.example.com".extraConfig = _knixl0;
}