Skip to content

web

The web host uses web-service and raw-nix. knixl writes one file for it. The Nix below is the golden test output, so it is exactly what knixl emits.

hosts/web.kdl
host "web" {
system "x86_64-linux"
web-service "example.com" {
upstream "http://127.0.0.1:3000"
acme email="ops@example.com"
hardened #true
}
raw-nix {
#"""
systemd.services.nginx.serviceConfig.MemoryMax = "512M";
"""#
}
}
generated/hosts/web.nix
# Generated by knixl 1.5.2 from hosts/web.kdl
# Do NOT edit. Regenerate from the KDL source.
# Overrides: add a sibling module and use lib.mkForce / lib.mkAfter.
{
config,
lib,
pkgs,
...
}:
{
nixpkgs.hostPlatform = "x86_64-linux";
networking.hostName = "web";
services.nginx.enable = true;
services.nginx.recommendedTlsSettings = true;
services.nginx.recommendedProxySettings = true;
services.nginx.recommendedOptimisation = true;
services.nginx.virtualHosts."example.com".forceSSL = true;
services.nginx.virtualHosts."example.com".enableACME = true;
services.nginx.virtualHosts."example.com".locations."/".proxyPass = "http://127.0.0.1:3000";
services.nginx.virtualHosts."example.com".serverAliases = [
];
security.acme.acceptTerms = true;
security.acme.certs."example.com".email = "ops@example.com";
services.nginx.virtualHosts."example.com".locations."/".extraConfig = ''
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
'';
# raw-nix passthrough
systemd.services.nginx.serviceConfig.MemoryMax = "512M";
}