Skip to content

Commit 0e328a4

Browse files
fix(services): disable opening ports on many services
i think proxy passing using nginx makes more sense i shouldn't be able to just type in the port
1 parent aa8f0eb commit 0e328a4

File tree

16 files changed

+0
-32
lines changed

16 files changed

+0
-32
lines changed

modules/nixos/services/actual.nix

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,6 @@ in
2424
# TODO: need to setup HTTPS to continue using...
2525
services.actual = {
2626
enable = true;
27-
openFirewall = true;
2827
settings = {
2928
inherit (cfg) port;
3029
};

modules/nixos/services/adguardhome/default.nix

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -29,9 +29,6 @@ in
2929
inherit settings;
3030

3131
enable = true;
32-
# https://search.nixos.org/options?channel=24.11&show=services.adguardhome.openFirewall&from=0&size=50&sort=relevance&type=packages&query=adguard
33-
# opens the web port, not the dns port!
34-
openFirewall = true;
3532
};
3633

3734
services.nginx.virtualHosts = {

modules/nixos/services/audiobookshelf.nix

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,6 @@ in
2222

2323
enable = true;
2424
host = "127.0.0.1";
25-
openFirewall = true;
2625
};
2726

2827
services.nginx.virtualHosts = {

modules/nixos/services/calibre.nix

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,6 @@ in
3636
inherit (cfg) libraries;
3737

3838
enable = true;
39-
openFirewall = true;
4039
};
4140

4241
calibre-web = {
@@ -46,7 +45,6 @@ in
4645

4746
ip = "127.0.0.1";
4847
};
49-
openFirewall = true;
5048

5149
options = {
5250
# NOTE: kinda ugly but you can only access one library

modules/nixos/services/code-server.nix

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,5 @@ in
4646
};
4747
};
4848
};
49-
50-
networking.firewall.allowedTCPPorts = [ cfg.port ];
5149
};
5250
}

modules/nixos/services/glances.nix

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,6 @@ in
2121
inherit (cfg) port;
2222

2323
enable = true;
24-
openFirewall = true;
2524
extraArgs = [
2625
"--webserver"
2726
];

modules/nixos/services/immich.nix

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,6 @@ in
2525
inherit (cfg) port mediaLocation;
2626

2727
enable = true;
28-
openFirewall = true;
2928
machine-learning.enable = true;
3029
settings = { };
3130
};

modules/nixos/services/jellyfin.nix

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,6 @@ in
1919
config = lib.mkIf cfg.enable {
2020
services.jellyfin = {
2121
enable = true;
22-
openFirewall = true;
2322
};
2423

2524
services.nginx.virtualHosts = {

modules/nixos/services/jellyseerr.nix

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,6 @@ in
2121
inherit (cfg) port;
2222

2323
enable = true;
24-
openFirewall = true;
2524
};
2625

2726
services.nginx.virtualHosts = {

modules/nixos/services/mealie.nix

Lines changed: 0 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -17,11 +17,6 @@ in
1717
};
1818

1919
config = lib.mkIf cfg.enable {
20-
# no option to open firewall so do it manually!
21-
networking.firewall.allowedTCPPorts = [
22-
cfg.port
23-
];
24-
2520
services.mealie = {
2621
inherit (cfg) port;
2722

0 commit comments

Comments
 (0)