web.nix clean up

This commit is contained in:
Richie Cahill 2024-06-21 22:02:56 -04:00
parent 6f09291dbd
commit 9ba0580b04

View File

@ -4,7 +4,7 @@
grafana = { grafana = {
image = "grafana/grafana-enterprise"; image = "grafana/grafana-enterprise";
volumes = [ "/zfs/media/docker/configs/grafana:/var/lib/grafana" ]; volumes = [ "/zfs/media/docker/configs/grafana:/var/lib/grafana" ];
user = "998:998"; user = "600:600";
extraOptions = [ "--network=web" ]; extraOptions = [ "--network=web" ];
autoStart = true; autoStart = true;
}; };
@ -29,12 +29,12 @@
}; };
haproxy = { haproxy = {
image = "haproxy:latest"; image = "haproxy:latest";
user = "998:998"; user = "600:600";
environment = { environment = {
TZ = "Etc/EST"; TZ = "Etc/EST";
}; };
volumes = [ volumes = [
"/zfs/media/docker/cloudflare.pem:/etc/ssl/certs/cloudflare.pem" "${config.sops.secrets."docker/haproxy_cert".path}:/etc/ssl/certs/cloudflare.pem"
"/root/nix-dotfiles/systems/jeeves/docker/haproxy.cfg:/usr/local/etc/haproxy/haproxy.cfg" "/root/nix-dotfiles/systems/jeeves/docker/haproxy.cfg:/usr/local/etc/haproxy/haproxy.cfg"
]; ];
dependsOn = [ dependsOn = [
@ -61,10 +61,9 @@
sops = { sops = {
defaultSopsFile = ../secrets.yaml; defaultSopsFile = ../secrets.yaml;
secrets."docker/cloud_flare_tunnel".owner = "docker-service"; secrets = {
secrets."docker/haproxy_cert" = { "docker/cloud_flare_tunnel".owner = "docker-service";
owner = "docker-service"; "docker/haproxy_cert".owner = "docker-service";
path = "/zfs/media/docker/test_cloudflare.pem";
}; };
}; };
} }