add basic nginx, php-fpm and database
This commit is contained in:
parent
0cd207bd22
commit
c9ae8e70b3
2 changed files with 51 additions and 0 deletions
|
|
@ -2,6 +2,7 @@
|
||||||
imports = [
|
imports = [
|
||||||
(modulesPath + "/profiles/qemu-guest.nix")
|
(modulesPath + "/profiles/qemu-guest.nix")
|
||||||
./forgejo.nix
|
./forgejo.nix
|
||||||
|
./web.nix
|
||||||
];
|
];
|
||||||
|
|
||||||
boot.loader.grub = {
|
boot.loader.grub = {
|
||||||
|
|
|
||||||
50
web.nix
Normal file
50
web.nix
Normal file
|
|
@ -0,0 +1,50 @@
|
||||||
|
{ pkgs, ...}: {
|
||||||
|
users.users.web = { isSystemUser = true; group = "web"; };
|
||||||
|
users.groups.web = {};
|
||||||
|
|
||||||
|
systemd.tmpfiles.rules = [
|
||||||
|
"d /var/www/html 0755 web web -"
|
||||||
|
];
|
||||||
|
|
||||||
|
services.phpfpm.pools.www = {
|
||||||
|
user = "web";
|
||||||
|
group = "web";
|
||||||
|
phpPackage = pkgs.php84.buildEnv {
|
||||||
|
extensions = ({ enabled, all }: enabled ++ (with all; [ intl pdo_mysql opcache apcu ]));
|
||||||
|
};
|
||||||
|
settings = {
|
||||||
|
"listen.owner" = "nginx";
|
||||||
|
"listen.group" = "nginx";
|
||||||
|
"pm" = "dynamic";
|
||||||
|
"pm.max_children" = 10;
|
||||||
|
"pm.start_servers" = 2;
|
||||||
|
"pm.min_spare_servers" = 1;
|
||||||
|
"pm.max_spare_servers" = 3;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
services.nginx = {
|
||||||
|
enable = true;
|
||||||
|
virtualHosts."default" = {
|
||||||
|
default = true;
|
||||||
|
root = "/var/www/html";
|
||||||
|
locations."/".index = "index.php index.html";
|
||||||
|
locations."~ \\.php$".extraConfig = ''
|
||||||
|
fastcgi_pass unix:/run/phpfpm/www.sock;
|
||||||
|
include ${pkgs.nginx}/conf/fastcgi_params;
|
||||||
|
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
# database "app" and a MySQL user "web" that logs in via the local socket (no password)
|
||||||
|
services.mysql = {
|
||||||
|
ensureDatabases = [ "app" ];
|
||||||
|
ensureUsers = [{
|
||||||
|
name = "web";
|
||||||
|
ensurePermissions = { "app.*" = "ALL PRIVILEGES"; };
|
||||||
|
}];
|
||||||
|
};
|
||||||
|
|
||||||
|
networking.firewall.allowedTCPPorts = [ 80 ];
|
||||||
|
}
|
||||||
Loading…
Add table
Add a link
Reference in a new issue