Browse Source

nixos-module/container/dnscache: set tls-cert-bundle

legacy
Astro 1 year ago
parent
commit
52cac17f16
  1. 3
      nix/nixos-module/container/dnscache.nix

3
nix/nixos-module/container/dnscache.nix

@ -1,4 +1,4 @@
{ hostName, config, lib, ... }:
{ hostName, config, lib, pkgs, ... }:
lib.mkIf config.site.hosts.${hostName}.services.dnscache.enable {
services.unbound = {
@ -34,6 +34,7 @@ lib.mkIf config.site.hosts.${hostName}.services.dnscache.enable {
forward-addr: 1.0.0.1@853#cloudflare-dns.com
server:
tls-cert-bundle: ${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt
# allow reverse lookup of rfc1918 space, which includes the DN42 address space
unblock-lan-zones: yes
insecure-lan-zones: yes

Loading…
Cancel
Save