mirror of
https://git.selfprivacy.org/SelfPrivacy/selfprivacy-nixos-config.git
synced 2025-01-06 16:14:17 +00:00
fix ACME for DigitalOcean: add DNS propagation check exceptions
This commit is contained in:
parent
19f30daf80
commit
05fe40ac21
|
@ -14,6 +14,7 @@ let
|
||||||
dnsCredentialsTemplate = dnsCredentialsTemplates.${cfg.dns.provider};
|
dnsCredentialsTemplate = dnsCredentialsTemplates.${cfg.dns.provider};
|
||||||
acme-env-filepath = "/var/lib/selfprivacy/acme-env";
|
acme-env-filepath = "/var/lib/selfprivacy/acme-env";
|
||||||
secrets-filepath = "/etc/selfprivacy/secrets.json";
|
secrets-filepath = "/etc/selfprivacy/secrets.json";
|
||||||
|
dnsPropagationCheckExceptions = [ "DIGITALOCEAN" ];
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
users.groups.acmereceivers.members = [ "nginx" ];
|
users.groups.acmereceivers.members = [ "nginx" ];
|
||||||
|
@ -31,7 +32,8 @@ in
|
||||||
group = "acmereceivers";
|
group = "acmereceivers";
|
||||||
dnsProvider = lib.strings.toLower cfg.dns.provider;
|
dnsProvider = lib.strings.toLower cfg.dns.provider;
|
||||||
credentialsFile = acme-env-filepath;
|
credentialsFile = acme-env-filepath;
|
||||||
dnsPropagationCheck = true;
|
dnsPropagationCheck =
|
||||||
|
! (lib.elem cfg.dns.provider dnsPropagationCheckExceptions);
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
Loading…
Reference in a new issue