nix/nixos/hosts/frankfurt-linode-01/containers/derp.nix

32 lines
1.1 KiB
Nix
Raw Normal View History

2024-06-23 12:07:50 +02:00
{ ... }: {
services.cron = {
enable = true;
systemCronJobs = [
2024-06-24 14:56:28 +02:00
''0 0 * * * root mkdir -p /Storage/Data/Docker/sysctl.io/letsencrypt/; rsync -avr root@framework-server:/Storage/Data/Docker/sysctl.io/letsencrypt/ /Storage/Data/Docker/sysctl.io/letsencrypt/''
2024-06-23 12:07:50 +02:00
];
};
# Containers
virtualisation.oci-containers.containers."derp" = {
image = "docker.io/fredliang/derper";
environment = {
DERP_ADDR = ":1443";
DERP_CERT_DIR = "/app/certs";
DERP_CERT_MODE = "manual";
2024-06-23 12:41:21 +02:00
DERP_DOMAIN = "frankfurt.sysctl.io";
2024-06-23 12:07:50 +02:00
DERP_STUN = "true";
DERP_VERIFY_CLIENTS = "true";
};
volumes = [
"/var/run/tailscale/tailscaled.sock:/var/run/tailscale/tailscaled.sock:ro"
2024-06-24 12:57:28 +02:00
"/Storage/Data/Docker/sysctl.io/letsencrypt/external/certificates/certs/*.sysctl.io.crt:/app/certs/frankfurt.sysctl.io.crt:ro"
"/Storage/Data/Docker/sysctl.io/letsencrypt/external/certificates/private/*.sysctl.io.key:/app/certs/frankfurt.sysctl.io.key:ro"
2024-06-23 12:07:50 +02:00
];
ports = [
"3478:3478/udp"
"1443:1443/tcp"
];
log-driver = "journald";
};
}