nixos-config/modules/nixos/services/homeserver/vaultwarden.nix
2025-10-04 22:58:27 -04:00

29 lines
687 B
Nix
Executable file

{ config, ... }:
{
sops.secrets."vaultwarden/secrets.env".restartUnits = [ "vaultwarden.service" ];
services.caddy.virtualHosts."vaultwarden.taild5f7e6.ts.net".extraConfig =
assert config.services.caddy.enable;
''
import default-settings
bind tailscale/vaultwarden
# block connections to admin login
respond /admin/* 403
reverse_proxy localhost:8000
'';
services.vaultwarden = {
enable = true;
backupDir = "/var/backups/vaultwarden";
config = {
DOMAIN = "https://vaultwarden.taild5f7e6.ts.net";
SIGNUPS_ALLOWED = false;
};
environmentFile = config.sops.secrets."vaultwarden/secrets.env".path;
};
}