fix(nginx): fallback listen to 80

This commit is contained in:
Henri Bourcereau 2026-07-28 15:39:06 +02:00
parent 80585d2712
commit c9550af4ad

View file

@ -137,9 +137,18 @@ in
forceSSL = withSSL; forceSSL = withSSL;
# Explicit listen so this vhost isn't shadowed by a default_server # Explicit listen so this vhost isn't shadowed by a default_server
# created by other virtual hosts with forceSSL = true. # created by other virtual hosts with forceSSL = true.
# When withSSL is true, also list plain-HTTP addresses (ssl =
# false): NixOS's forceSSL redirect vhost is generated by
# filtering this list down to the non-SSL entries, so without
# them the redirect server ends up with no `listen` at all and
# nginx silently falls back to its compiled-in default port
# (8000), clashing with any other service using that port.
listen = [ listen = [
{ addr = "0.0.0.0"; port = listenPort; ssl = withSSL; } { addr = "0.0.0.0"; port = listenPort; ssl = withSSL; }
{ addr = "[::]"; port = listenPort; ssl = withSSL; } { addr = "[::]"; port = listenPort; ssl = withSSL; }
] ++ optionals withSSL [
{ addr = "0.0.0.0"; port = 80; ssl = false; }
{ addr = "[::]"; port = 80; ssl = false; }
]; ];
locations."/" = { locations."/" = {
extraConfig = proxyConfig; extraConfig = proxyConfig;