feat: everything perfect now trust me bro

This commit is contained in:
s-prechtl 2025-07-14 18:54:16 +02:00
parent 6d8ce8772b
commit 45d9c2bf7d

View file

@ -42,10 +42,12 @@ in {
};
networking.firewall.allowedTCPPorts = [ 80 443 ];
# Make certificate readable
users.users.nginx.extraGroups = [ "turnserver" ];
services.nginx.virtualHosts.${turn.realm} = {
addSSL = true;
enableACME = false; # well do ACME ourselves
forceSSL = false;
forceSSL = true;
sslCertificate = "${config.security.acme.certs.${turn.realm}.directory}/full.pem";
sslCertificateKey = "${config.security.acme.certs.${turn.realm}.directory}/key.pem";
locations."/.well-known/acme-challenge/" = {