grimm-nix-server/modules/letsencrypt.nix

16 lines
332 B
Nix
Raw Normal View History

{ lib, config, inputs, pkgs, ... }:
let
2024-05-08 20:45:41 +02:00
inherit (config.networking) domain;
root_email = "contact@${domain}";
in {
security.acme = {
acceptTerms = true;
defaults.email = root_email;
2024-05-08 20:45:41 +02:00
certs."${domain}" = {
webroot = "/var/lib/acme/acme-challenge/";
};
};
users.users.nginx.extraGroups = [ "acme" ];
}