Evie Litherland-Smith
a853475779
Move (hopefully) all reverse proxies to caddy Left off adguard for now, tbd if it needs outside access Moved service expressions up a level since it was a bit unneccesary before
41 lines
1,002 B
Nix
41 lines
1,002 B
Nix
{ config, lib, pkgs, ... }:
|
|
|
|
{
|
|
services.adguardhome = {
|
|
enable = true;
|
|
mutableSettings = false;
|
|
settings = rec {
|
|
http.address = "0.0.0.0:3200";
|
|
dns = {
|
|
bind_hosts = [ "127.0.0.1" "192.168.1.230" ];
|
|
bootstrap_dns = [ "9.9.9.9" "149.112.112.10" ];
|
|
ratelimit = 0;
|
|
safe_search.enabled = true;
|
|
rewrites = [
|
|
{
|
|
domain = "xenia.me.uk";
|
|
answer = "192.168.1.230";
|
|
}
|
|
{
|
|
domain = "*.xenia.me.uk";
|
|
answer = "A";
|
|
}
|
|
];
|
|
blocked_services.ids = [ ];
|
|
};
|
|
filtering = { inherit (dns) safe_search rewrites blocked_services; };
|
|
querylog.ignored = [
|
|
"discovery.syncthing.net"
|
|
"discovery-v6.syncthing.net"
|
|
"matrix.tchncs.de"
|
|
];
|
|
statistics = { inherit (querylog) ignored; };
|
|
};
|
|
openFirewall = true;
|
|
};
|
|
networking.firewall = {
|
|
allowedTCPPorts = [ 53 ];
|
|
allowedUDPPorts = [ 53 ];
|
|
};
|
|
}
|