ca4a0b23ab
- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/ X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail upstream copies via header_down on mail.severijnse.eu - tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync _25/_465/_993, fail-safe placeholders; coredns zone updated - pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint, ...); CI pre-commit job over x86_64 + aarch64 matrix - gitea: enable Gitea Actions + self-hosted runner (native:host, aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook - fix statix warnings (merge repeated systemd/database/configFile keys, inherit, bool-compare guards); add missing trailing newlines
13 lines
347 B
Nix
13 lines
347 B
Nix
{...}: {
|
|
# NOTE: Caddy handles all TLS natively via its ACME integration.
|
|
# This module is kept as a fallback for non-Caddy services.
|
|
# Currently NOT imported in default.nix — uncomment there to activate.
|
|
security.acme = {
|
|
acceptTerms = true;
|
|
defaults = {
|
|
email = "jory@severijnse.eu";
|
|
group = "caddy";
|
|
};
|
|
};
|
|
}
|