diff options
| author | Collin Williams <96917990+bluedragon1221@users.noreply.github.com> | 2026-01-29 20:15:19 -0600 |
|---|---|---|
| committer | Collin Williams <96917990+bluedragon1221@users.noreply.github.com> | 2026-01-30 08:38:21 -0600 |
| commit | c9a1d2da80bca0a85e8c18f6d2db71c4d1127eda (patch) | |
| tree | 9da79e318ff0533a3708aee85a0b6a6d7f1d1036 /modules/services/nixos/adguard.nix | |
| parent | c81952cbcb6c6f1b41c2b6e2a366891991cceaee (diff) | |
Spring Cleaning
- create new module, `system`, that consumes the `boot` module and takes
in the more system-interested services from the `services` module
- touch up left over services (which are more self-hosting interested)
- touch up yo and yoshi configs
Diffstat (limited to 'modules/services/nixos/adguard.nix')
| -rw-r--r-- | modules/services/nixos/adguard.nix | 40 |
1 files changed, 40 insertions, 0 deletions
diff --git a/modules/services/nixos/adguard.nix b/modules/services/nixos/adguard.nix new file mode 100644 index 0000000..f59934e --- /dev/null +++ b/modules/services/nixos/adguard.nix @@ -0,0 +1,40 @@ +{ + config, + lib, + ... +}: let + cfg = config.collinux.services.adguard; +in { + imports = [ + (import ./mkCaddyCfg.nix cfg) + ]; + + config = lib.mkIf cfg.enable { + services.adguardhome = { + enable = true; + port = cfg.port; + mutableSettings = true; + settings = { + http = { + pprof.enabled = false; + address = "localhost:${toString cfg.port}"; + }; + users = []; # disable auth (only accessable over tailscale anyway) + dns = { + bind_hosts = ["127.0.0.1" cfg.bind_host]; + upstream_dns = ["https://dns.quad9.net/dns-query"]; + enable_dnssec = true; + }; + tls.enabled = false; + dhcp.enabled = false; + }; + }; + + # disable systemd-resolved (https://github.com/AdguardTeam/AdGuardHome/wiki/FAQ#bindinuse) + services.resolved.extraConfig = lib.mkIf config.services.resolved.enable '' + DNS=127.0.0.1 + DNSStubListener=no + ''; + services.tailscale.extraSetFlags = lib.optional config.collinux.services.networking.tailscale.enable "--accept-dns=false"; # would create an infinite loop of dns lookups + }; +} |
