refactor: split services into reusable services/ modules

- services/{samba,avahi,audiobookshelf,containers,caddy,tailscale}.nix
- common.nix grows firewall base + timezone; hosts import what they need
- jupiter/vm/vps import service modules; drop the jupiter/services.nix monolith
- each module opens its own firewall ports; caddy/tailscale shared by hosts
- verified: jupiter/vps/vbox eval + jupiter builds, config equivalent
This commit is contained in:
erik
2026-07-13 19:13:11 +02:00
parent 2b170af346
commit fb782cb9fe
11 changed files with 187 additions and 222 deletions
+9
View File
@@ -0,0 +1,9 @@
{ ... }:
# Caddy reverse proxy — base enable + open the web ports.
# Each host adds its own `services.caddy.virtualHosts.<name>` (LAN names on
# jupiter, public domains with automatic HTTPS on the vps).
{
services.caddy.enable = true;
networking.firewall.allowedTCPPorts = [ 80 443 ];
}