From c9a1d2da80bca0a85e8c18f6d2db71c4d1127eda Mon Sep 17 00:00:00 2001 From: Collin Williams <96917990+bluedragon1221@users.noreply.github.com> Date: Thu, 29 Jan 2026 20:15:19 -0600 Subject: Spring Cleaning - create new module, `system`, that consumes the `boot` module and takes in the more system-interested services from the `services` module - touch up left over services (which are more self-hosting interested) - touch up yo and yoshi configs --- modules/services/nixos/adguard.nix | 40 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) create mode 100644 modules/services/nixos/adguard.nix (limited to 'modules/services/nixos/adguard.nix') diff --git a/modules/services/nixos/adguard.nix b/modules/services/nixos/adguard.nix new file mode 100644 index 0000000..f59934e --- /dev/null +++ b/modules/services/nixos/adguard.nix @@ -0,0 +1,40 @@ +{ + config, + lib, + ... +}: let + cfg = config.collinux.services.adguard; +in { + imports = [ + (import ./mkCaddyCfg.nix cfg) + ]; + + config = lib.mkIf cfg.enable { + services.adguardhome = { + enable = true; + port = cfg.port; + mutableSettings = true; + settings = { + http = { + pprof.enabled = false; + address = "localhost:${toString cfg.port}"; + }; + users = []; # disable auth (only accessable over tailscale anyway) + dns = { + bind_hosts = ["127.0.0.1" cfg.bind_host]; + upstream_dns = ["https://dns.quad9.net/dns-query"]; + enable_dnssec = true; + }; + tls.enabled = false; + dhcp.enabled = false; + }; + }; + + # disable systemd-resolved (https://github.com/AdguardTeam/AdGuardHome/wiki/FAQ#bindinuse) + services.resolved.extraConfig = lib.mkIf config.services.resolved.enable '' + DNS=127.0.0.1 + DNSStubListener=no + ''; + services.tailscale.extraSetFlags = lib.optional config.collinux.services.networking.tailscale.enable "--accept-dns=false"; # would create an infinite loop of dns lookups + }; +} -- cgit v1.3.1