diff --git a/module.nix b/module.nix index 2f38d5b..2d2cac2 100644 --- a/module.nix +++ b/module.nix @@ -137,9 +137,18 @@ in forceSSL = withSSL; # Explicit listen so this vhost isn't shadowed by a default_server # created by other virtual hosts with forceSSL = true. + # When withSSL is true, also list plain-HTTP addresses (ssl = + # false): NixOS's forceSSL redirect vhost is generated by + # filtering this list down to the non-SSL entries, so without + # them the redirect server ends up with no `listen` at all and + # nginx silently falls back to its compiled-in default port + # (8000), clashing with any other service using that port. listen = [ { addr = "0.0.0.0"; port = listenPort; ssl = withSSL; } { addr = "[::]"; port = listenPort; ssl = withSSL; } + ] ++ optionals withSSL [ + { addr = "0.0.0.0"; port = 80; ssl = false; } + { addr = "[::]"; port = 80; ssl = false; } ]; locations."/" = { extraConfig = proxyConfig;