about summary refs log tree commit diff
path: root/machines/srv3
diff options
context:
space:
mode:
authorPatryk Niedźwiedziński <patryk@niedzwiedzinski.cyou>2024-08-18 19:27:07 +0200
committerPatryk Niedźwiedziński <patryk@niedzwiedzinski.cyou>2024-08-18 19:27:07 +0200
commit7453e4bacf3647a74427f8a11e9793a095b551bc (patch)
tree8cafd0e21be51a170855206cb5ca40cb2d914b32 /machines/srv3
parent5e8ed0ca7f5e8788553b656ddbb4aa1dccc2bc03 (diff)
parent5349051441deaf903ae5b933916ef3ec215782af (diff)
downloaddots-7453e4bacf3647a74427f8a11e9793a095b551bc.tar.gz
dots-7453e4bacf3647a74427f8a11e9793a095b551bc.zip
Merge branch 'master' of github.com:pniedzwiedzinski/dots
Diffstat (limited to 'machines/srv3')
-rw-r--r--machines/srv3/configuration.nix37
1 files changed, 2 insertions, 35 deletions
diff --git a/machines/srv3/configuration.nix b/machines/srv3/configuration.nix
index 09ae394..73c20db 100644
--- a/machines/srv3/configuration.nix
+++ b/machines/srv3/configuration.nix
@@ -77,7 +77,7 @@ in
   services.sshguard = {
     enable = true;
     whitelist = [
-      "192.168.0.0/18"
+      "192.168.1.0/24"
     ];
   };
 
@@ -120,16 +120,6 @@ in
       forceSSL = true;
       root = "${www}/pics.niedzwiedzinski.cyou";
     };
-    "rss.srv3.niedzwiedzinski.cyou" = {
-      enableACME = true;
-      forceSSL = true;
-      extraConfig = ''
-        modsecurity_rules '
-          SecRuleEngine On
-          SecRule ARGS:u "@rx life[-_]*hack(s)?" "id:1234,deny,status:403"
-        ';
-      '';
-    };
     "tmp.niedzwiedzinski.cyou" = {
       enableACME = true;
       addSSL = true;
@@ -167,32 +157,9 @@ in
   security.acme.defaults.email = "pniedzwiedzinski19@gmail.com";
   security.acme.acceptTerms = true;
 
-  networking.firewall.allowedTCPPorts = [ 53 80 443 config.services.molly-brown.settings.Port ];
+  networking.firewall.allowedTCPPorts = [ 53 80 443 ];
   networking.firewall.allowedUDPPorts = [ 53 ];
 
-  services.molly-brown = {
-    hostName = "niedzwiedzinski.cyou";
-    enable = true;
-    certPath = "/var/lib/acme/niedzwiedzinski.cyou/cert.pem";
-    keyPath = "/var/lib/acme/niedzwiedzinski.cyou/key.pem";
-    docBase = "${www}/niedzwiedzinski.cyou";
-  };
-
-  systemd = {
-    services.molly-brown.serviceConfig.SupplementaryGroups = [ config.security.acme.certs."niedzwiedzinski.cyou".group ];
-  };
-
-  services.rss-bridge = {
-    enable = true;
-    virtualHost = "rss.srv3.niedzwiedzinski.cyou";
-    whitelist = [
-      "Instagram"
-      "Soundcloud"
-      "Facebook"
-    ];
-  };
-
-
   virtualisation.docker.enable = true;
 
   users = {