{ pkgs, config, ... }: { services.caddy = { enable = true; package = pkgs.caddy.withPlugins { plugins = [ "github.com/caddy-dns/cloudflare@89f16b99c18ef49c8bb470a82f895bce01cbaece" ]; hash = "sha256-JoujVXRXjKUam1Ej3/zKVvF0nX97dUizmISjy3M3Kr8="; }; email = "erwin@datarift.nl"; virtualHosts = { "git.datarift.nl" = { extraConfig = '' @local { remote_ip 10.0.0.0/24 } handle @local { reverse_proxy 127.0.0.1:3000 } handle { error "Nope." 403 } tls { dns cloudflare {env.CF_API_TOKEN} } ''; }; }; }; networking.firewall.allowedTCPPorts = [ 80 443 ]; systemd.services.caddy.serviceConfig.EnvironmentFile = [ config.sops.secrets.caddy-env.path ]; }