{ config, lib, ... }: let cfg = config.os.srv.nginx; in { options.os.srv.nginx = { enable = lib.mkEnableOption "the NGINX reverse proxy service"; openFirewall = lib.mkOption { type = lib.types.bool; default = true; description = "Whether to open ports 80 and 443 in the firewall."; }; }; config = lib.mkIf cfg.enable { services.nginx = { enable = true; recommendedProxySettings = true; recommendedTlsSettings = true; recommendedOptimisation = true; recommendedGzipSettings = true; }; networking.firewall.allowedTCPPorts = lib.mkOptional cfg.openFirewall [ 80 443 ]; systemd.tmpfiles.rules = [ "d /var/log/nginx 0750 nginx adm -" ]; }; }