diff --git a/checks/rabbi-gerzi-domains.nix b/checks/rabbi-gerzi-domains.nix new file mode 100644 index 0000000..65ab3fc --- /dev/null +++ b/checks/rabbi-gerzi-domains.nix @@ -0,0 +1,77 @@ +{ + config, + lib, + pkgs, +}: + +let + frontendConfig = config.services.rabbi-gerzi.frontend; + backendConfig = config.services.rabbi-gerzi.backend; + frontendVirtualHost = + config.services.nginx.virtualHosts.${frontendConfig.hostName}; + backendVirtualHost = + config.services.nginx.virtualHosts.${backendConfig.hostName}; + redirectVirtualHost = lib.attrByPath [ "www.rabbigerzi.com" ] { } + config.services.nginx.virtualHosts; + + assertions = [ + { + assertion = frontendConfig.hostName == "rabbigerzi.com"; + message = "Rabbi Gerzi frontend does not use the production domain"; + } + { + assertion = frontendConfig.apiBaseUrl == "https://api.rabbigerzi.com"; + message = "Rabbi Gerzi frontend does not use the production API"; + } + { + assertion = backendConfig.hostName == "api.rabbigerzi.com"; + message = "Rabbi Gerzi backend does not use the production API domain"; + } + { + assertion = backendConfig.corsAllowedOrigins == [ + "https://rabbigerzi.com" + "https://rabbigerzi.yisroelbaum.com" + ]; + message = "Rabbi Gerzi CORS origins do not cover production and staging"; + } + { + assertion = builtins.elem "rabbigerzi.yisroelbaum.com" + frontendVirtualHost.serverAliases; + message = "Rabbi Gerzi frontend staging alias is missing"; + } + { + assertion = builtins.elem "rabbigerziapi.yisroelbaum.com" + backendVirtualHost.serverAliases; + message = "Rabbi Gerzi backend staging alias is missing"; + } + { + assertion = redirectVirtualHost.globalRedirect or null + == "rabbigerzi.com"; + message = "Rabbi Gerzi www host does not redirect to the apex"; + } + { + assertion = redirectVirtualHost.forceSSL or false; + message = "Rabbi Gerzi www redirect does not force HTTPS"; + } + { + assertion = redirectVirtualHost.enableACME or false; + message = "Rabbi Gerzi www redirect does not enable ACME"; + } + ]; + + failedAssertions = lib.filter (assertion: !assertion.assertion) assertions; +in +pkgs.runCommand "rabbi-gerzi-production-domains" + { + failures = lib.concatMapStringsSep "\n" + (assertion: assertion.message) failedAssertions; + preferLocalBuild = true; + } + '' + if [ -n "$failures" ]; then + printf '%s\n' "$failures" >&2 + exit 1 + fi + + touch $out + '' diff --git a/flake.nix b/flake.nix index 1c9a84d..0506c80 100644 --- a/flake.nix +++ b/flake.nix @@ -59,6 +59,12 @@ } ]; }; + checks."${system}".rabbi-gerzi-domains = + import ./checks/rabbi-gerzi-domains.nix { + config = self.nixosConfigurations.nixos.config; + inherit (nixpkgs) lib; + pkgs = nixpkgs.legacyPackages.${system}; + }; devShells."${system}".default = let pkgs = import nixpkgs { inherit system; };