web.nix clean up
This commit is contained in:
parent
6f09291dbd
commit
9ba0580b04
@ -4,7 +4,7 @@
|
|||||||
grafana = {
|
grafana = {
|
||||||
image = "grafana/grafana-enterprise";
|
image = "grafana/grafana-enterprise";
|
||||||
volumes = [ "/zfs/media/docker/configs/grafana:/var/lib/grafana" ];
|
volumes = [ "/zfs/media/docker/configs/grafana:/var/lib/grafana" ];
|
||||||
user = "998:998";
|
user = "600:600";
|
||||||
extraOptions = [ "--network=web" ];
|
extraOptions = [ "--network=web" ];
|
||||||
autoStart = true;
|
autoStart = true;
|
||||||
};
|
};
|
||||||
@ -29,12 +29,12 @@
|
|||||||
};
|
};
|
||||||
haproxy = {
|
haproxy = {
|
||||||
image = "haproxy:latest";
|
image = "haproxy:latest";
|
||||||
user = "998:998";
|
user = "600:600";
|
||||||
environment = {
|
environment = {
|
||||||
TZ = "Etc/EST";
|
TZ = "Etc/EST";
|
||||||
};
|
};
|
||||||
volumes = [
|
volumes = [
|
||||||
"/zfs/media/docker/cloudflare.pem:/etc/ssl/certs/cloudflare.pem"
|
"${config.sops.secrets."docker/haproxy_cert".path}:/etc/ssl/certs/cloudflare.pem"
|
||||||
"/root/nix-dotfiles/systems/jeeves/docker/haproxy.cfg:/usr/local/etc/haproxy/haproxy.cfg"
|
"/root/nix-dotfiles/systems/jeeves/docker/haproxy.cfg:/usr/local/etc/haproxy/haproxy.cfg"
|
||||||
];
|
];
|
||||||
dependsOn = [
|
dependsOn = [
|
||||||
@ -61,10 +61,9 @@
|
|||||||
|
|
||||||
sops = {
|
sops = {
|
||||||
defaultSopsFile = ../secrets.yaml;
|
defaultSopsFile = ../secrets.yaml;
|
||||||
secrets."docker/cloud_flare_tunnel".owner = "docker-service";
|
secrets = {
|
||||||
secrets."docker/haproxy_cert" = {
|
"docker/cloud_flare_tunnel".owner = "docker-service";
|
||||||
owner = "docker-service";
|
"docker/haproxy_cert".owner = "docker-service";
|
||||||
path = "/zfs/media/docker/test_cloudflare.pem";
|
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
Loading…
x
Reference in New Issue
Block a user