nixos/hosts/vm/nextcloud/nextcloud.nix

71 lines
1.9 KiB
Nix
Raw Blame History

This file contains invisible Unicode characters!

This file contains invisible Unicode characters that may be processed differently from what appears below. If your use case is intentional and legitimate, you can safely ignore this warning. Use the Escape button to reveal hidden characters.

This file contains ambiguous Unicode characters that may be confused with others in your current locale. If your use case is intentional and legitimate, you can safely ignore this warning. Use the Escape button to highlight these characters.

{ pkgs, config, ... }:
{
age.secrets = {
nextcloud_db_pass = {
file = ../../../secrets/nextcloud/nextcloud_db_pass.age;
owner = "nextcloud";
group = "nextcloud";
};
nextcloud_admin_pass = {
file = ../../../secrets/nextcloud/nextcloud_admin_pass.age;
owner = "nextcloud";
group = "nextcloud";
};
# Attention : sensible au retour à la ligne final (il n’en faut pas) !
nextcloud_ldap_pass = {
file = ../../../secrets/nextcloud/nextcloud_ldap_pass.age;
};
};
services.nextcloud = {
enable = true;
package = pkgs.nextcloud34;
configureRedis = true;
hostName = "nextcloud.crans.org";
https = true;
maxUploadSize = "4G";
config = {
dbtype = "pgsql";
dbhost = "tealc.adm.crans.org";
dbuser = "nextcloud";
dbpassFile = config.age.secrets.nextcloud_db_pass.path;
adminpassFile = config.age.secrets.nextcloud_admin_pass.path;
};
phpOptions = {
"opcache.interned_strings_buffer" = "32";
"opcache.memory_consumption" = "512";
};
settings = {
trusted_proxies = [
# hodaur
"172.16.10.145"
# reverseproxy
"172.16.10.151"
];
mail_domain = "crans.org";
mail_from_address = "root";
mail_smtphost = "smtp.crans.org";
mail_smtpport = 25;
};
appstoreEnable = true;
extraAppsEnable = true;
};
# Activation CORS pour récuppérer les agendas depuis le wiki
# TODO: à mettre que sur /remote.php/dav/public-calendars/ pour éviter des requêtes malveillantes depuis le wiki.
services.nginx.virtualHosts.${config.services.nextcloud.hostName}.extraConfig = ''
add_header 'Access-Control-Allow-Origin' 'https://mediawiki.crans.org' always;
add_header 'Access-Control-Allow-Methods' 'GET' always;
add_header 'Access-Control-Allow-Credentials' 'false' always;
add_header 'Vary' 'Origin' always;
'';
}