Reorganize services/ into category subfolders
Group service modules by category (media, network, vpn, identity, dev, desktop) to make the growing services/ dir easier to navigate. containers.nix stays at the top level since it's a shared backend, not a single-category service. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,36 @@
|
||||
{ ... }:
|
||||
|
||||
# Local recursive DNS resolver (privacy + DNSSEC). Your adblock DNS
|
||||
# (pihole/AdGuard) forwards to this instead of a public upstream.
|
||||
# Listens on 127.0.0.1:5335 — point the adblock engine's upstream there:
|
||||
# AdGuard: dns.upstream_dns = [ "127.0.0.1:5335" ];
|
||||
# pihole: upstream = "127.0.0.1#5335";
|
||||
{
|
||||
services.unbound = {
|
||||
enable = true;
|
||||
# Do NOT point resolv.conf at unbound: it listens on :5335, not :53, so
|
||||
# that leaves the host with no resolver until pihole binds :53 — a
|
||||
# boot-time deadlock. Host resolves via networking.nameservers instead.
|
||||
resolveLocalQueries = false;
|
||||
# NixOS manages the DNSSEC root trust anchor (unbound-anchor).
|
||||
settings.server = {
|
||||
interface = [ "127.0.0.1" ];
|
||||
port = 5335;
|
||||
access-control = [ "127.0.0.0/8 allow" ];
|
||||
|
||||
do-ip6 = "no"; # flip to yes if you resolve over IPv6
|
||||
prefer-ip6 = "no";
|
||||
|
||||
# Privacy / hardening (standard pi-hole+unbound guide).
|
||||
hide-identity = true;
|
||||
hide-version = true;
|
||||
harden-glue = true;
|
||||
harden-dnssec-stripped = true;
|
||||
use-caps-for-id = false;
|
||||
qname-minimisation = true;
|
||||
|
||||
edns-buffer-size = 1232;
|
||||
prefetch = true;
|
||||
};
|
||||
};
|
||||
}
|
||||
Reference in New Issue
Block a user