diff --git a/machines/gerd/services/murmur.nix b/machines/gerd/services/murmur.nix index f934636..beb653d 100644 --- a/machines/gerd/services/murmur.nix +++ b/machines/gerd/services/murmur.nix @@ -2,7 +2,7 @@ { services.murmur = let - certLocation = config.security.acme.certs."mumble.fricloud.dk".directory; + certLocation = config.security.acme.certs."fricloud.dk".directory; in { enable = true; openFirewall = true; @@ -18,24 +18,8 @@ # set superpassword on start from secrets systemd.services.murmur.preStart = lib.mkAfter ''${config.services.murmur.package}/bin/mumble-server -ini /run/murmur/murmurd.ini -readsupw < ${config.age.secrets.murmur-superpassword.path}''; - services.nginx.virtualHosts."mumble.fricloud.dk" = { - forceSSL = true; - enableACME = true; - root = pkgs.writeTextDir "index.html" '' - -
-This server runs a mumble server, enjoy!
- - - ''; - }; - - # need to change group to murmur for cert + add nginx to murmur group to do HTTP ACME - security.acme.certs."mumble.fricloud.dk".group = config.users.groups.murmur.name; - users.users.nginx.extraGroups = [ config.users.groups.murmur.name ]; + # add murmur user to domain group to access cert + users.groups.fricloud-domain.members = [ config.users.groups.murmur.name ]; age.secrets = { murmur-env.owner = config.users.users.murmur.name;