Compare commits
10 Commits
a1030b3417
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
| df0e38125e | |||
| 702749a275 | |||
| bc3a31f845 | |||
| 7c11147a3b | |||
| c49ea2eb68 | |||
| 8dc4e683a8 | |||
| 6277642492 | |||
| baf1f38c5f | |||
| 9f621b130e | |||
| 4dd4733179 |
3
.gitignore
vendored
3
.gitignore
vendored
@@ -1,3 +1,4 @@
|
||||
/mobile02.qcow2
|
||||
/.session
|
||||
.session
|
||||
/result
|
||||
/modules/containers/container.nix
|
||||
|
||||
150
flake.lock
generated
150
flake.lock
generated
@@ -91,7 +91,7 @@
|
||||
},
|
||||
"davinci": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_2",
|
||||
"nixpkgs": "nixpkgs",
|
||||
"nixpkgs-pinned": "nixpkgs-pinned"
|
||||
},
|
||||
"locked": {
|
||||
@@ -108,24 +108,6 @@
|
||||
"url": "https://git.voidarc.co.uk/voidarc/nixos.davinci"
|
||||
}
|
||||
},
|
||||
"disko": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1781152676,
|
||||
"narHash": "sha256-RxWs5ND31KzTG7wvMM+PMfUjyNpmIEr999lqNARaM5o=",
|
||||
"owner": "nix-community",
|
||||
"repo": "disko",
|
||||
"rev": "ff8702b4de27f72b4c78573dfb89ec74e36abdf1",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "nix-community",
|
||||
"repo": "disko",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"flake-compat": {
|
||||
"flake": false,
|
||||
"locked": {
|
||||
@@ -408,7 +390,7 @@
|
||||
"hyprland": {
|
||||
"inputs": {
|
||||
"hyprland": "hyprland_2",
|
||||
"nixpkgs": "nixpkgs_4",
|
||||
"nixpkgs": "nixpkgs_3",
|
||||
"otter-launcher": "otter-launcher",
|
||||
"woomer": "woomer",
|
||||
"wrappers": "wrappers",
|
||||
@@ -528,7 +510,7 @@
|
||||
"hyprutils": "hyprutils",
|
||||
"hyprwayland-scanner": "hyprwayland-scanner",
|
||||
"hyprwire": "hyprwire",
|
||||
"nixpkgs": "nixpkgs_3",
|
||||
"nixpkgs": "nixpkgs_2",
|
||||
"pre-commit-hooks": "pre-commit-hooks",
|
||||
"systems": "systems_2",
|
||||
"xdph": "xdph"
|
||||
@@ -778,7 +760,7 @@
|
||||
"gotify-desktop": "gotify-desktop",
|
||||
"hyprland": "hyprland",
|
||||
"import-tree": "import-tree_2",
|
||||
"nixpkgs": "nixpkgs_7",
|
||||
"nixpkgs": "nixpkgs_6",
|
||||
"nvim": "nvim",
|
||||
"omnisearch": "omnisearch",
|
||||
"otter-launcher": "otter-launcher_2",
|
||||
@@ -790,11 +772,11 @@
|
||||
"wshowkeys": "wshowkeys_2"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1785343603,
|
||||
"narHash": "sha256-JjK0d5DlcBaf3+v+SozdG+OvFA6bopuvMaecV+mveOw=",
|
||||
"lastModified": 1785436692,
|
||||
"narHash": "sha256-vB5j+Vf91MCv6joAqb95uCvcNCPuzAU07+uvFAb8atE=",
|
||||
"ref": "dendritic",
|
||||
"rev": "88266b040f4a3d22b0911c7f8cb373c3589ed5d3",
|
||||
"revCount": 219,
|
||||
"rev": "00f680029034e908c09f7ba9af5bb9d83fb090f5",
|
||||
"revCount": 221,
|
||||
"type": "git",
|
||||
"url": "https://git.voidarc.co.uk/voidarc/nixos.git"
|
||||
},
|
||||
@@ -806,16 +788,16 @@
|
||||
},
|
||||
"nixpkgs": {
|
||||
"locked": {
|
||||
"lastModified": 1780930886,
|
||||
"narHash": "sha256-rppURzHviaQN131F+nLiLdGfcb0uCd9gGP0E5+iw9MI=",
|
||||
"lastModified": 1782233679,
|
||||
"narHash": "sha256-QyuGP5+QOtmXpy4i2X4DhBVBaySBdDKQEhqKcphcp34=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "8c3cede7ddc26bd659d2d383b5610efbd2c7a16e",
|
||||
"rev": "667d5cf1c59585031d743c78b394b0a647537c35",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"ref": "nixpkgs-unstable",
|
||||
"ref": "nixos-26.05",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
@@ -897,22 +879,6 @@
|
||||
}
|
||||
},
|
||||
"nixpkgs_10": {
|
||||
"locked": {
|
||||
"lastModified": 1783224372,
|
||||
"narHash": "sha256-8i/87eeoqiGE4yOTjwSA3Eh/ziJRQEmd/unYU+K27sk=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "d407951447dcd00442e97087bf374aad70c04cea",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "nixos",
|
||||
"ref": "nixos-unstable",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_11": {
|
||||
"locked": {
|
||||
"lastModified": 1744536153,
|
||||
"narHash": "sha256-awS2zRgF4uTwrOKwwiJcByDzDOdo3Q1rPZbiHQg/N38=",
|
||||
@@ -928,7 +894,7 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_12": {
|
||||
"nixpkgs_11": {
|
||||
"locked": {
|
||||
"lastModified": 1780336545,
|
||||
"narHash": "sha256-vhVhuXzFrIOfcssC/9hDHx7MHzDKjF3keHuREOQqQiQ=",
|
||||
@@ -944,13 +910,13 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_13": {
|
||||
"nixpkgs_12": {
|
||||
"locked": {
|
||||
"lastModified": 1785133411,
|
||||
"narHash": "sha256-Yjv0WEg39KRYS0rBdTbu6Fc/or/ihAKk13W9sQ6VWd0=",
|
||||
"lastModified": 1785386831,
|
||||
"narHash": "sha256-sPS3CaXH8RAT3FZRuy4VcV47iuYIWMMfa0GbyJKC3o4=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "2f5a153c270b70cb0f8c11f46d96d6d3bc39f4e3",
|
||||
"rev": "21ea275a7c46aef9d4d6ddc962e6d562e9d94183",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -961,22 +927,6 @@
|
||||
}
|
||||
},
|
||||
"nixpkgs_2": {
|
||||
"locked": {
|
||||
"lastModified": 1782233679,
|
||||
"narHash": "sha256-QyuGP5+QOtmXpy4i2X4DhBVBaySBdDKQEhqKcphcp34=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "667d5cf1c59585031d743c78b394b0a647537c35",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"ref": "nixos-26.05",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_3": {
|
||||
"locked": {
|
||||
"lastModified": 1784356753,
|
||||
"narHash": "sha256-12KrbMiWLcf8m7pCvAtZh1ZrgF85ZXDXvfR/fWTKy84=",
|
||||
@@ -992,7 +942,7 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_4": {
|
||||
"nixpkgs_3": {
|
||||
"locked": {
|
||||
"lastModified": 1785090369,
|
||||
"narHash": "sha256-m0pDuRJG7EDo9ri+4Ksu83VsI+PlxNC9lNBfydejce4=",
|
||||
@@ -1008,7 +958,7 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_5": {
|
||||
"nixpkgs_4": {
|
||||
"locked": {
|
||||
"lastModified": 1782175435,
|
||||
"narHash": "sha256-EMzXKmnOtBQ2MnvpiNOm7E+kOMvdPrIKaeg52Tip2Uk=",
|
||||
@@ -1024,7 +974,7 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_6": {
|
||||
"nixpkgs_5": {
|
||||
"locked": {
|
||||
"lastModified": 1773734432,
|
||||
"narHash": "sha256-IF5ppUWh6gHGHYDbtVUyhwy/i7D261P7fWD1bPefOsw=",
|
||||
@@ -1040,7 +990,7 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_7": {
|
||||
"nixpkgs_6": {
|
||||
"locked": {
|
||||
"lastModified": 1785104993,
|
||||
"narHash": "sha256-eKbrvPoAOFutbYMdbB3r5EQVmFxKv24iKqHPPUXA0gM=",
|
||||
@@ -1056,7 +1006,7 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_8": {
|
||||
"nixpkgs_7": {
|
||||
"locked": {
|
||||
"lastModified": 1782467914,
|
||||
"narHash": "sha256-pGvFkM8N0xEkIIXDe5YYfbEAvHrk4IxBrjB/x8OomhE=",
|
||||
@@ -1072,7 +1022,7 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_9": {
|
||||
"nixpkgs_8": {
|
||||
"locked": {
|
||||
"lastModified": 1780336545,
|
||||
"narHash": "sha256-vhVhuXzFrIOfcssC/9hDHx7MHzDKjF3keHuREOQqQiQ=",
|
||||
@@ -1088,9 +1038,25 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_9": {
|
||||
"locked": {
|
||||
"lastModified": 1783224372,
|
||||
"narHash": "sha256-8i/87eeoqiGE4yOTjwSA3Eh/ziJRQEmd/unYU+K27sk=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "d407951447dcd00442e97087bf374aad70c04cea",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "nixos",
|
||||
"ref": "nixos-unstable",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nvim": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_8",
|
||||
"nixpkgs": "nixpkgs_7",
|
||||
"wrappers": "wrappers_2"
|
||||
},
|
||||
"locked": {
|
||||
@@ -1220,16 +1186,16 @@
|
||||
},
|
||||
"root": {
|
||||
"inputs": {
|
||||
"disko": "disko",
|
||||
"flake-parts": "flake-parts",
|
||||
"import-tree": "import-tree",
|
||||
"nix-config": "nix-config",
|
||||
"nixpkgs": "nixpkgs_13"
|
||||
"nixpkgs": "nixpkgs_12",
|
||||
"sops-nix": "sops-nix"
|
||||
}
|
||||
},
|
||||
"rust-overlay": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_11"
|
||||
"nixpkgs": "nixpkgs_10"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1784438913,
|
||||
@@ -1247,7 +1213,7 @@
|
||||
},
|
||||
"sls-steam": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_10"
|
||||
"nixpkgs": "nixpkgs_9"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1785224226,
|
||||
@@ -1263,6 +1229,26 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"sops-nix": {
|
||||
"inputs": {
|
||||
"nixpkgs": [
|
||||
"nixpkgs"
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1783174389,
|
||||
"narHash": "sha256-aCWC8ngycU7OdJrU2+Je3qf+1a2ykuBvpPhZT/9tXMc=",
|
||||
"owner": "Mic92",
|
||||
"repo": "sops-nix",
|
||||
"rev": "f1406619a3884cd5c47992a70b8b35c9c0fcb4c9",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "Mic92",
|
||||
"repo": "sops-nix",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"systems": {
|
||||
"locked": {
|
||||
"lastModified": 1681028828,
|
||||
@@ -1442,7 +1428,7 @@
|
||||
"woomer": {
|
||||
"inputs": {
|
||||
"crane": "crane",
|
||||
"nixpkgs": "nixpkgs_5",
|
||||
"nixpkgs": "nixpkgs_4",
|
||||
"systems": "systems_4"
|
||||
},
|
||||
"locked": {
|
||||
@@ -1484,7 +1470,7 @@
|
||||
},
|
||||
"wrappers": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_6"
|
||||
"nixpkgs": "nixpkgs_5"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1785177581,
|
||||
@@ -1502,7 +1488,7 @@
|
||||
},
|
||||
"wrappers_2": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_9"
|
||||
"nixpkgs": "nixpkgs_8"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1782135443,
|
||||
@@ -1520,7 +1506,7 @@
|
||||
},
|
||||
"wrappers_3": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_12"
|
||||
"nixpkgs": "nixpkgs_11"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1782135443,
|
||||
|
||||
@@ -8,6 +8,12 @@
|
||||
# flake parts
|
||||
flake-parts.url = "github:hercules-ci/flake-parts";
|
||||
import-tree.url = "github:vic/import-tree";
|
||||
|
||||
# secret management
|
||||
sops-nix = {
|
||||
url = "github:Mic92/sops-nix";
|
||||
inputs.nixpkgs.follows = "nixpkgs";
|
||||
};
|
||||
};
|
||||
|
||||
outputs = inputs: inputs.flake-parts.lib.mkFlake {inherit inputs;} (inputs.import-tree ./modules);
|
||||
|
||||
364
modules/containers/arr/container.nix
Normal file
364
modules/containers/arr/container.nix
Normal file
@@ -0,0 +1,364 @@
|
||||
{moduleWithSystem, ...}: {
|
||||
flake.nixosModules.containerArrStack = moduleWithSystem ({pkgs, ...}: {config, ...}: {
|
||||
virtualisation.oci-containers.containers."bazarr" = {
|
||||
image = "lscr.io/linuxserver/bazarr:latest";
|
||||
environment = {
|
||||
"PGID" = "0";
|
||||
"PUID" = "0";
|
||||
"TZ" = "Etc/UTC";
|
||||
};
|
||||
volumes = [
|
||||
"/containers/arr/bazarr-config:/config:rw"
|
||||
"/mnt/storage/streaming:/data:rw"
|
||||
];
|
||||
ports = [
|
||||
"8994:6767/tcp"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=bazarr"
|
||||
"--network=arr-stack_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-bazarr" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
};
|
||||
virtualisation.oci-containers.containers."flaresolverr" = {
|
||||
image = "ghcr.io/flaresolverr/flaresolverr:latest";
|
||||
environment = {
|
||||
"CAPTCHA_SOLVER" = "none";
|
||||
"LOG_HTML" = "false";
|
||||
"LOG_LEVEL" = "info";
|
||||
"TZ" = "Europe/London";
|
||||
};
|
||||
ports = [
|
||||
"8191:8191/tcp"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=flaresolverr"
|
||||
"--network=arr-stack_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-flaresolverr" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
};
|
||||
virtualisation.oci-containers.containers."lidarr" = {
|
||||
image = "lscr.io/linuxserver/lidarr:nightly";
|
||||
environment = {
|
||||
"PGID" = "0";
|
||||
"PUID" = "0";
|
||||
"TZ" = "Europe/London";
|
||||
};
|
||||
volumes = [
|
||||
"/containers/arr/lidarr-config:/config:rw"
|
||||
"/mnt/storage/streaming:/data:rw"
|
||||
];
|
||||
ports = [
|
||||
"8992:8686/tcp"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=lidarr"
|
||||
"--network=arr-stack_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-lidarr" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
};
|
||||
virtualisation.oci-containers.containers."lidatube" = {
|
||||
image = "thewicklowwolf/lidatube:latest";
|
||||
environment = {
|
||||
"PGID" = "0";
|
||||
"PUID" = "0";
|
||||
"lidarr_address" = "http://192.168.1.180:8992";
|
||||
};
|
||||
environmentFiles = [config.sops.secrets.lidarr-api-key.path];
|
||||
volumes = [
|
||||
"/containers/arr/lidatube-config:/lidatube/config:rw"
|
||||
"/etc/localtime:/etc/localtime:ro"
|
||||
"/mnt/storage/streaming/lidarr:/lidatube/downloads:rw"
|
||||
];
|
||||
ports = [
|
||||
"8997:5000/tcp"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=lidatube"
|
||||
"--network=arr-stack_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-lidatube" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
};
|
||||
virtualisation.oci-containers.containers."nginx" = {
|
||||
image = "lscr.io/linuxserver/nginx:latest";
|
||||
environment = {
|
||||
"NGINX_AUTORELOAD" = "true";
|
||||
"PGID" = "1000";
|
||||
"PUID" = "1000";
|
||||
"TZ" = "Europe/London";
|
||||
};
|
||||
volumes = [
|
||||
"/containers/arr/nginx-config:/config:rw"
|
||||
];
|
||||
ports = [
|
||||
"8989:80/tcp"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=nginx"
|
||||
"--network=arr-stack_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-nginx" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
};
|
||||
virtualisation.oci-containers.containers."prowlarr" = {
|
||||
image = "lscr.io/linuxserver/prowlarr:latest";
|
||||
environment = {
|
||||
"PGID" = "1000";
|
||||
"PUID" = "1000";
|
||||
"TZ" = "Etc/UTC";
|
||||
};
|
||||
volumes = [
|
||||
"/containers/arr/prowlarr-config:/config:rw"
|
||||
];
|
||||
ports = [
|
||||
"8996:9696/tcp"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=prowlarr"
|
||||
"--network=arr-stack_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-prowlarr" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
};
|
||||
virtualisation.oci-containers.containers."qbittorrent" = {
|
||||
image = "lscr.io/linuxserver/qbittorrent:latest";
|
||||
environment = {
|
||||
"PGID" = "0";
|
||||
"PUID" = "0";
|
||||
"TORRENTING_PORT" = "6881";
|
||||
"TZ" = "Etc/UTC";
|
||||
"WEBUI_PORT" = "8995";
|
||||
};
|
||||
volumes = [
|
||||
"/containers/arr/qbittorrnt-config:/config:rw"
|
||||
"/mnt/storage/streaming/downloadclient:/data/downloadclient:rw"
|
||||
];
|
||||
ports = [
|
||||
"8995:8995/tcp"
|
||||
"6881:6881/tcp"
|
||||
"6881:6881/udp"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=qbittorrent"
|
||||
"--network=arr-stack_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-qbittorrent" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
};
|
||||
virtualisation.oci-containers.containers."radarr" = {
|
||||
image = "lscr.io/linuxserver/radarr:latest";
|
||||
environment = {
|
||||
"PGID" = "0";
|
||||
"PUID" = "0";
|
||||
"TZ" = "Europe/London";
|
||||
};
|
||||
volumes = [
|
||||
"/containers/arr/radarr-config:/config:rw"
|
||||
"/mnt/storage/streaming:/data:rw"
|
||||
];
|
||||
ports = [
|
||||
"8991:7878/tcp"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=radarr"
|
||||
"--network=arr-stack_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-radarr" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
};
|
||||
virtualisation.oci-containers.containers."sonarr" = {
|
||||
image = "lscr.io/linuxserver/sonarr:latest";
|
||||
environment = {
|
||||
"PGID" = "0";
|
||||
"PUID" = "0";
|
||||
"TZ" = "Europe/London";
|
||||
};
|
||||
volumes = [
|
||||
"/containers/arr/sonarr-config:/config:rw"
|
||||
"/mnt/storage/streaming:/data:rw"
|
||||
];
|
||||
ports = [
|
||||
"8990:8989/tcp"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=sonarr"
|
||||
"--network=arr-stack_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-sonarr" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-arr-stack_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-arr-stack-root.target"
|
||||
];
|
||||
};
|
||||
|
||||
# Networks
|
||||
systemd.services."podman-network-arr-stack_default" = {
|
||||
path = [pkgs.podman];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
RemainAfterExit = true;
|
||||
ExecStop = "podman network rm -f arr-stack_default";
|
||||
};
|
||||
script = ''
|
||||
podman network inspect arr-stack_default || podman network create arr-stack_default
|
||||
'';
|
||||
partOf = ["podman-compose-arr-stack-root.target"];
|
||||
wantedBy = ["podman-compose-arr-stack-root.target"];
|
||||
};
|
||||
|
||||
# Root service
|
||||
# When started, this will automatically create all resources and start
|
||||
# the containers. When stopped, this will teardown all resources.
|
||||
systemd.targets."podman-compose-arr-stack-root" = {
|
||||
unitConfig = {
|
||||
Description = "Root target generated by compose2nix.";
|
||||
};
|
||||
wantedBy = ["multi-user.target"];
|
||||
};
|
||||
});
|
||||
}
|
||||
67
modules/containers/blog/container.nix
Normal file
67
modules/containers/blog/container.nix
Normal file
@@ -0,0 +1,67 @@
|
||||
{moduleWithSystem, ...}: {
|
||||
flake.nixosModules.containerBlog = moduleWithSystem ({pkgs, ...}: {
|
||||
virtualisation.oci-containers.containers."nginx-blog" = {
|
||||
image = "lscr.io/linuxserver/nginx:latest";
|
||||
environment = {
|
||||
"NGINX_AUTORELOAD" = "true";
|
||||
"NGINX_AUTORELOAD_WATCHLIST" = "";
|
||||
"PGID" = "1000";
|
||||
"PUID" = "1000";
|
||||
"TZ" = "Etc/UTC";
|
||||
};
|
||||
volumes = [
|
||||
"/containers/blog/nginx:/config:rw"
|
||||
];
|
||||
ports = [
|
||||
"3030:80/tcp"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=nginx"
|
||||
"--network=blog_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-nginx-blog" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-blog_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-blog_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-blog-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-blog-root.target"
|
||||
];
|
||||
};
|
||||
|
||||
# Networks
|
||||
systemd.services."podman-network-blog_default" = {
|
||||
path = [pkgs.podman];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
RemainAfterExit = true;
|
||||
ExecStop = "podman network rm -f blog_default";
|
||||
};
|
||||
script = ''
|
||||
podman network inspect blog_default || podman network create blog_default
|
||||
'';
|
||||
partOf = ["podman-compose-blog-root.target"];
|
||||
wantedBy = ["podman-compose-blog-root.target"];
|
||||
};
|
||||
|
||||
# Root service
|
||||
# When started, this will automatically create all resources and start
|
||||
# the containers. When stopped, this will teardown all resources.
|
||||
systemd.targets."podman-compose-blog-root" = {
|
||||
unitConfig = {
|
||||
Description = "Root target generated by compose2nix.";
|
||||
};
|
||||
wantedBy = ["multi-user.target"];
|
||||
};
|
||||
});
|
||||
}
|
||||
70
modules/containers/copyparty/container.nix
Normal file
70
modules/containers/copyparty/container.nix
Normal file
@@ -0,0 +1,70 @@
|
||||
{moduleWithSystem, ...}: {
|
||||
flake.nixosModules.containerCopyparty = moduleWithSystem ({pkgs, ...}: {
|
||||
virtualisation.oci-containers.containers."copyparty" = {
|
||||
image = "copyparty/ac:latest";
|
||||
environment = {
|
||||
"LD_PRELOAD" = "/usr/lib/libmimalloc-secure.so.NOPE";
|
||||
};
|
||||
volumes = [
|
||||
"/containers/copyparty:/cfg:rw,z"
|
||||
"/mnt/storage:/w:rw,z"
|
||||
];
|
||||
ports = [
|
||||
"8001:3923/tcp"
|
||||
];
|
||||
user = "0:0";
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--health-cmd=wget --spider -q 127.0.0.1:3923/?reset=/._"
|
||||
"--health-interval=1m0s"
|
||||
"--health-retries=5"
|
||||
"--health-start-period=15s"
|
||||
"--health-timeout=2s"
|
||||
"--network-alias=copyparty"
|
||||
"--network=copyparty_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-copyparty" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-copyparty_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-copyparty_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-copyparty-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-copyparty-root.target"
|
||||
];
|
||||
};
|
||||
|
||||
# Networks
|
||||
systemd.services."podman-network-copyparty_default" = {
|
||||
path = [pkgs.podman];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
RemainAfterExit = true;
|
||||
ExecStop = "podman network rm -f copyparty_default";
|
||||
};
|
||||
script = ''
|
||||
podman network inspect copyparty_default || podman network create copyparty_default
|
||||
'';
|
||||
partOf = ["podman-compose-copyparty-root.target"];
|
||||
wantedBy = ["podman-compose-copyparty-root.target"];
|
||||
};
|
||||
|
||||
# Root service
|
||||
# When started, this will automatically create all resources and start
|
||||
# the containers. When stopped, this will teardown all resources.
|
||||
systemd.targets."podman-compose-copyparty-root" = {
|
||||
unitConfig = {
|
||||
Description = "Root target generated by compose2nix.";
|
||||
};
|
||||
wantedBy = ["multi-user.target"];
|
||||
};
|
||||
});
|
||||
}
|
||||
75
modules/containers/cryptpad/container.nix
Normal file
75
modules/containers/cryptpad/container.nix
Normal file
@@ -0,0 +1,75 @@
|
||||
{moduleWithSystem, ...}: {
|
||||
flake.nixosModules.containerCryptpad = moduleWithSystem ({pkgs, ...}: {
|
||||
virtualisation.oci-containers.containers."cryptpad-cryptpad" = {
|
||||
image = "cryptpad/cryptpad:latest";
|
||||
environment = {
|
||||
"CPAD_CONF" = "/cryptpad/config/config.js";
|
||||
"CPAD_INSTALL_ONLYOFFICE" = "yes";
|
||||
"CPAD_MAIN_DOMAIN" = "https://office.voidarc.co.uk";
|
||||
"CPAD_SANDBOX_DOMAIN" = "https://word.voidarc.co.uk";
|
||||
};
|
||||
volumes = [
|
||||
"/containers/cryptpad/config/config.example.js:/cryptpad/config/config.js:rw"
|
||||
"/containers/cryptpad/customize:/cryptpad/customize:rw"
|
||||
"/containers/cryptpad/data/blob:/cryptpad/blob:rw"
|
||||
"/containers/cryptpad/data/block:/cryptpad/block:rw"
|
||||
"/containers/cryptpad/data/data:/cryptpad/data:rw"
|
||||
"/containers/cryptpad/data/files:/cryptpad/datastore:rw"
|
||||
"/containers/cryptpad/onlyoffice-conf:/cryptpad/onlyoffice-conf:rw"
|
||||
"/containers/cryptpad/onlyoffice-dist:/cryptpad/www/common/onlyoffice/dist:rw"
|
||||
];
|
||||
ports = [
|
||||
"3000:3000/tcp"
|
||||
"3003:3003/tcp"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--hostname=cryptpad"
|
||||
"--network-alias=cryptpad"
|
||||
"--network=cryptpad_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-cryptpad-cryptpad" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-cryptpad_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-cryptpad_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-cryptpad-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-cryptpad-root.target"
|
||||
];
|
||||
};
|
||||
|
||||
# Networks
|
||||
systemd.services."podman-network-cryptpad_default" = {
|
||||
path = [pkgs.podman];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
RemainAfterExit = true;
|
||||
ExecStop = "podman network rm -f cryptpad_default";
|
||||
};
|
||||
script = ''
|
||||
podman network inspect cryptpad_default || podman network create cryptpad_default
|
||||
'';
|
||||
partOf = ["podman-compose-cryptpad-root.target"];
|
||||
wantedBy = ["podman-compose-cryptpad-root.target"];
|
||||
};
|
||||
|
||||
# Root service
|
||||
# When started, this will automatically create all resources and start
|
||||
# the containers. When stopped, this will teardown all resources.
|
||||
systemd.targets."podman-compose-cryptpad-root" = {
|
||||
unitConfig = {
|
||||
Description = "Root target generated by compose2nix.";
|
||||
};
|
||||
wantedBy = ["multi-user.target"];
|
||||
};
|
||||
});
|
||||
}
|
||||
50
modules/containers/default.nix
Normal file
50
modules/containers/default.nix
Normal file
@@ -0,0 +1,50 @@
|
||||
{self, ...}: {
|
||||
flake.nixosModules.containers = {
|
||||
pkgs,
|
||||
config,
|
||||
...
|
||||
}: let
|
||||
modules = with self.nixosModules; [
|
||||
containerArrStack
|
||||
containerBlog
|
||||
containerCopyparty
|
||||
containerCryptpad
|
||||
containerGitea
|
||||
containerGotify
|
||||
containerImmich
|
||||
containerJellyfin
|
||||
containerMail
|
||||
containerN8N
|
||||
containerKomga
|
||||
containerNginxHomeAssistant
|
||||
containerSilverbullet
|
||||
];
|
||||
in {
|
||||
imports = modules;
|
||||
# Runtime
|
||||
virtualisation.podman = {
|
||||
enable = true;
|
||||
autoPrune.enable = true;
|
||||
dockerCompat = true;
|
||||
};
|
||||
|
||||
environment.systemPackages = with pkgs; [
|
||||
podman-compose
|
||||
];
|
||||
|
||||
hardware.nvidia-container-toolkit = {
|
||||
enable = true;
|
||||
};
|
||||
# Enable container name DNS for all Podman networks.
|
||||
networking.firewall.interfaces = let
|
||||
matchAll =
|
||||
if !config.networking.nftables.enable
|
||||
then "podman+"
|
||||
else "podman*";
|
||||
in {
|
||||
"${matchAll}".allowedUDPPorts = [53];
|
||||
};
|
||||
|
||||
virtualisation.oci-containers.backend = "podman";
|
||||
};
|
||||
}
|
||||
108
modules/containers/gitea/container.nix
Normal file
108
modules/containers/gitea/container.nix
Normal file
@@ -0,0 +1,108 @@
|
||||
{moduleWithSystem, ...}: {
|
||||
flake.nixosModules.containerGitea = moduleWithSystem ({pkgs, ...}: {config, ...}: {
|
||||
virtualisation.oci-containers.containers."gitea" = {
|
||||
image = "docker.gitea.com/gitea:1.25.4";
|
||||
environment = {
|
||||
"GITEA__database__DB_TYPE" = "mysql";
|
||||
"GITEA__database__HOST" = "gitea-db:3306";
|
||||
"GITEA__database__NAME" = "gitea";
|
||||
"GITEA__database__USER" = "gitea";
|
||||
};
|
||||
environmentFiles = [config.sops.templates."gitea.env".path];
|
||||
volumes = [
|
||||
"/containers/gitea/gitea:/data:rw"
|
||||
"/etc/localtime:/etc/localtime:ro"
|
||||
"/etc/timezone:/etc/timezone:ro"
|
||||
];
|
||||
ports = [
|
||||
"3009:3000/tcp"
|
||||
"222:22/tcp"
|
||||
];
|
||||
dependsOn = [
|
||||
"gitea-db"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=server"
|
||||
"--network=gitea_gitea"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-gitea" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-gitea_gitea.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-gitea_gitea.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-gitea-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-gitea-root.target"
|
||||
];
|
||||
};
|
||||
|
||||
virtualisation.oci-containers.containers."gitea-db" = {
|
||||
image = "docker.io/library/mysql:8";
|
||||
environment = {
|
||||
"MYSQL_DATABASE" = "gitea";
|
||||
# "MYSQL_PASSWORD" = config.sops.secrets."gitea-db-passwd";
|
||||
# "MYSQL_ROOT_PASSWORD" = config.sops.secrets."gitea-db-passwd";
|
||||
"MYSQL_USER" = "gitea";
|
||||
};
|
||||
environmentFiles = [config.sops.templates."gitea.env".path];
|
||||
extraOptions = [
|
||||
"--network-alias=db"
|
||||
"--network=gitea_gitea"
|
||||
];
|
||||
volumes = [
|
||||
"/containers/gitea/mysql:/var/lib/mysql:rw"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-gitea-db" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-gitea_gitea.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-gitea_gitea.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-gitea-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-gitea-root.target"
|
||||
];
|
||||
};
|
||||
|
||||
# Networks
|
||||
systemd.services."podman-network-gitea_gitea" = {
|
||||
path = [pkgs.podman];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
RemainAfterExit = true;
|
||||
ExecStop = "podman network rm -f gitea_gitea";
|
||||
};
|
||||
script = ''
|
||||
podman network inspect gitea_gitea || podman network create gitea_gitea
|
||||
'';
|
||||
partOf = ["podman-compose-gitea-root.target"];
|
||||
wantedBy = ["podman-compose-gitea-root.target"];
|
||||
};
|
||||
|
||||
# Root service
|
||||
# When started, this will automatically create all resources and start
|
||||
# the containers. When stopped, this will teardown all resources.
|
||||
systemd.targets."podman-compose-gitea-root" = {
|
||||
unitConfig = {
|
||||
Description = "Root target generated by compose2nix.";
|
||||
};
|
||||
wantedBy = ["multi-user.target"];
|
||||
};
|
||||
});
|
||||
}
|
||||
62
modules/containers/gotify/container.nix
Normal file
62
modules/containers/gotify/container.nix
Normal file
@@ -0,0 +1,62 @@
|
||||
{moduleWithSystem, ...}: {
|
||||
flake.nixosModules.containerGotify = moduleWithSystem ({pkgs, ...}: {
|
||||
virtualisation.oci-containers.containers."gotify-gotify" = {
|
||||
image = "gotify/server";
|
||||
environment = {
|
||||
};
|
||||
volumes = [
|
||||
"/containers/gotify/gotify_data:/app/data:rw"
|
||||
];
|
||||
ports = [
|
||||
"8088:80/tcp"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=gotify"
|
||||
"--network=gotify_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-gotify-gotify" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-gotify_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-gotify_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-gotify-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-gotify-root.target"
|
||||
];
|
||||
};
|
||||
|
||||
# Networks
|
||||
systemd.services."podman-network-gotify_default" = {
|
||||
path = [pkgs.podman];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
RemainAfterExit = true;
|
||||
ExecStop = "podman network rm -f gotify_default";
|
||||
};
|
||||
script = ''
|
||||
podman network inspect gotify_default || podman network create gotify_default
|
||||
'';
|
||||
partOf = ["podman-compose-gotify-root.target"];
|
||||
wantedBy = ["podman-compose-gotify-root.target"];
|
||||
};
|
||||
|
||||
# Root service
|
||||
# When started, this will automatically create all resources and start
|
||||
# the containers. When stopped, this will teardown all resources.
|
||||
systemd.targets."podman-compose-gotify-root" = {
|
||||
unitConfig = {
|
||||
Description = "Root target generated by compose2nix.";
|
||||
};
|
||||
wantedBy = ["multi-user.target"];
|
||||
};
|
||||
});
|
||||
}
|
||||
194
modules/containers/immich/container.nix
Normal file
194
modules/containers/immich/container.nix
Normal file
@@ -0,0 +1,194 @@
|
||||
{moduleWithSystem, ...}: {
|
||||
flake.nixosModules.containerImmich = moduleWithSystem ({pkgs, ...}: {config, ...}: {
|
||||
virtualisation.oci-containers.containers."immich_machine_learning" = {
|
||||
image = "ghcr.io/immich-app/immich-machine-learning:release";
|
||||
environment = {
|
||||
"DB_DATABASE_NAME" = "immich";
|
||||
"DB_DATA_LOCATION" = "./postgres";
|
||||
"DB_HOST" = "immich_postgres";
|
||||
"DB_PORT" = "5432";
|
||||
"DB_USERNAME" = "postgres";
|
||||
"EXTERNAL_IMMICH_URL" = "https://immich.voidarc.co.uk";
|
||||
"IMMICH_URL" = "http://192.168.1.180:2283";
|
||||
"IMMICH_VERSION" = "release";
|
||||
"UPLOAD_LOCATION" = "/mnt/storage/streaming/images";
|
||||
};
|
||||
environmentFiles = [config.sops.templates."immich.env".path];
|
||||
volumes = [
|
||||
"immich_model-cache:/cache:rw"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=immich-machine-learning"
|
||||
"--network=immich_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-immich_machine_learning" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-immich_default.service"
|
||||
"podman-volume-immich_model-cache.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-immich_default.service"
|
||||
"podman-volume-immich_model-cache.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-immich-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-immich-root.target"
|
||||
];
|
||||
};
|
||||
virtualisation.oci-containers.containers."immich_postgres" = {
|
||||
image = "ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0@sha256:32324a2f41df5de9efe1af166b7008c3f55646f8d0e00d9550c16c9822366b4a";
|
||||
environment = {
|
||||
"POSTGRES_DB" = "immich";
|
||||
"POSTGRES_INITDB_ARGS" = "--data-checksums";
|
||||
"POSTGRES_USER" = "postgres";
|
||||
};
|
||||
environmentFiles = [config.sops.templates."immich.env".path];
|
||||
volumes = [
|
||||
"/containers/immich/postgres:/var/lib/postgresql/data:rw"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=database"
|
||||
"--network=immich_default"
|
||||
"--shm-size=134217728"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-immich_postgres" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-immich_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-immich_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-immich-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-immich-root.target"
|
||||
];
|
||||
};
|
||||
virtualisation.oci-containers.containers."immich_redis" = {
|
||||
image = "docker.io/valkey/valkey:8-bookworm@sha256:a137a2b60aca1a75130022d6bb96af423fefae4eb55faf395732db3544803280";
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--health-cmd=redis-cli ping || exit 1"
|
||||
"--network-alias=redis"
|
||||
"--network=immich_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-immich_redis" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-immich_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-immich_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-immich-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-immich-root.target"
|
||||
];
|
||||
};
|
||||
virtualisation.oci-containers.containers."immich_server" = {
|
||||
image = "ghcr.io/immich-app/immich-server:release";
|
||||
environment = {
|
||||
"DB_DATABASE_NAME" = "immich";
|
||||
"DB_DATA_LOCATION" = "./postgres";
|
||||
"DB_HOST" = "immich_postgres";
|
||||
"DB_PORT" = "5432";
|
||||
"DB_USERNAME" = "postgres";
|
||||
"EXTERNAL_IMMICH_URL" = "https://immich.voidarc.co.uk";
|
||||
"IMMICH_URL" = "http://192.168.1.180:2283";
|
||||
"IMMICH_VERSION" = "release";
|
||||
"UPLOAD_LOCATION" = "/mnt/storage/streaming/images";
|
||||
};
|
||||
environmentFiles = [config.sops.templates."immich.env".path];
|
||||
volumes = [
|
||||
"/etc/localtime:/etc/localtime:ro"
|
||||
"/mnt/storage/streaming/images/:/data:rw"
|
||||
];
|
||||
ports = [
|
||||
"2283:2283/tcp"
|
||||
];
|
||||
dependsOn = [
|
||||
"immich_postgres"
|
||||
"immich_redis"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=immich-server"
|
||||
"--network=immich_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-immich_server" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-immich_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-immich_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-immich-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-immich-root.target"
|
||||
];
|
||||
};
|
||||
|
||||
# Networks
|
||||
systemd.services."podman-network-immich_default" = {
|
||||
path = [pkgs.podman];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
RemainAfterExit = true;
|
||||
ExecStop = "podman network rm -f immich_default";
|
||||
};
|
||||
script = ''
|
||||
podman network inspect immich_default || podman network create immich_default
|
||||
'';
|
||||
partOf = ["podman-compose-immich-root.target"];
|
||||
wantedBy = ["podman-compose-immich-root.target"];
|
||||
};
|
||||
|
||||
# Volumes
|
||||
systemd.services."podman-volume-immich_model-cache" = {
|
||||
path = [pkgs.podman];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
RemainAfterExit = true;
|
||||
};
|
||||
script = ''
|
||||
podman volume inspect immich_model-cache || podman volume create immich_model-cache
|
||||
'';
|
||||
partOf = ["podman-compose-immich-root.target"];
|
||||
wantedBy = ["podman-compose-immich-root.target"];
|
||||
};
|
||||
|
||||
# Root service
|
||||
# When started, this will automatically create all resources and start
|
||||
# the containers. When stopped, this will teardown all resources.
|
||||
systemd.targets."podman-compose-immich-root" = {
|
||||
unitConfig = {
|
||||
Description = "Root target generated by compose2nix.";
|
||||
};
|
||||
wantedBy = ["multi-user.target"];
|
||||
};
|
||||
});
|
||||
}
|
||||
69
modules/containers/jellyfin/container.nix
Normal file
69
modules/containers/jellyfin/container.nix
Normal file
@@ -0,0 +1,69 @@
|
||||
{moduleWithSystem, ...}: {
|
||||
flake.nixosModules.containerJellyfin = moduleWithSystem ({pkgs, ...}: {
|
||||
virtualisation.oci-containers.containers."jellyfin" = {
|
||||
image = "jellyfin/jellyfin";
|
||||
environment = {
|
||||
"JELLYFIN_PublishedServerUrl" = "https://watch.voidarc.co.uk";
|
||||
};
|
||||
volumes = [
|
||||
"/containers/jellyfin/cache:/cache:rw"
|
||||
"/containers/jellyfin/config:/config:rw"
|
||||
"/mnt/storage/streaming:/media:rw"
|
||||
];
|
||||
ports = [
|
||||
"8096:8096/tcp"
|
||||
"7359:7359/udp"
|
||||
];
|
||||
user = "0:0";
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--add-host=host.docker.internal:host-gateway"
|
||||
"--device=nvidia.com/gpu=all"
|
||||
"--network-alias=jellyfin"
|
||||
"--network=jellyfin_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-jellyfin" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-jellyfin_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-jellyfin_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-jellyfin-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-jellyfin-root.target"
|
||||
];
|
||||
};
|
||||
|
||||
# Networks
|
||||
systemd.services."podman-network-jellyfin_default" = {
|
||||
path = [pkgs.podman];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
RemainAfterExit = true;
|
||||
ExecStop = "podman network rm -f jellyfin_default";
|
||||
};
|
||||
script = ''
|
||||
podman network inspect jellyfin_default || podman network create jellyfin_default
|
||||
'';
|
||||
partOf = ["podman-compose-jellyfin-root.target"];
|
||||
wantedBy = ["podman-compose-jellyfin-root.target"];
|
||||
};
|
||||
|
||||
# Root service
|
||||
# When started, this will automatically create all resources and start
|
||||
# the containers. When stopped, this will teardown all resources.
|
||||
systemd.targets."podman-compose-jellyfin-root" = {
|
||||
unitConfig = {
|
||||
Description = "Root target generated by compose2nix.";
|
||||
};
|
||||
wantedBy = ["multi-user.target"];
|
||||
};
|
||||
});
|
||||
}
|
||||
63
modules/containers/komga/container.nix
Normal file
63
modules/containers/komga/container.nix
Normal file
@@ -0,0 +1,63 @@
|
||||
{moduleWithSystem, ...}: {
|
||||
flake.nixosModules.containerKomga = moduleWithSystem ({pkgs, ...}: {
|
||||
|
||||
virtualisation.oci-containers.containers."komga" = {
|
||||
image = "gotson/komga";
|
||||
volumes = [
|
||||
"/containers/komga/config:/config:rw"
|
||||
"/etc/timezone:/etc/timezone:ro"
|
||||
"/mnt/storage/streaming/manga:/data:rw"
|
||||
];
|
||||
ports = [
|
||||
"25600:25600/tcp"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=komga"
|
||||
"--network=komga_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-komga" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-komga_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-komga_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-komga-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-komga-root.target"
|
||||
];
|
||||
};
|
||||
|
||||
# Networks
|
||||
systemd.services."podman-network-komga_default" = {
|
||||
path = [ pkgs.podman ];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
RemainAfterExit = true;
|
||||
ExecStop = "podman network rm -f komga_default";
|
||||
};
|
||||
script = ''
|
||||
podman network inspect komga_default || podman network create komga_default
|
||||
'';
|
||||
partOf = [ "podman-compose-komga-root.target" ];
|
||||
wantedBy = [ "podman-compose-komga-root.target" ];
|
||||
};
|
||||
|
||||
# Root service
|
||||
# When started, this will automatically create all resources and start
|
||||
# the containers. When stopped, this will teardown all resources.
|
||||
systemd.targets."podman-compose-komga-root" = {
|
||||
unitConfig = {
|
||||
Description = "Root target generated by compose2nix.";
|
||||
};
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
};
|
||||
});
|
||||
}
|
||||
88
modules/containers/mail/container.nix
Normal file
88
modules/containers/mail/container.nix
Normal file
@@ -0,0 +1,88 @@
|
||||
{moduleWithSystem, ...}: {
|
||||
flake.nixosModules.containerMail = moduleWithSystem ({pkgs, ...}: {config, ...}: {
|
||||
# Containers
|
||||
virtualisation.oci-containers.containers."mailserver" = {
|
||||
image = "ghcr.io/docker-mailserver/docker-mailserver:latest";
|
||||
environment = {
|
||||
"DEFAULT_RELAY_HOST" = "[smtp-relay.brevo.com]:587";
|
||||
"DOMAINNAME" = "voidarc.co.uk";
|
||||
"ENABLE_CLAMAV" = "1";
|
||||
"ENABLE_FAIL2BAN" = "1";
|
||||
"ENABLE_POSTFIX_VIRTUAL_TRANSPORT" = "1";
|
||||
"ENABLE_POSTGREY" = "1";
|
||||
"ENABLE_SPAMASSASSIN" = "1";
|
||||
"HOSTNAME" = "mail.voidarc.co.uk";
|
||||
"ONE_DIR" = "1";
|
||||
"PERMIT_DOCKER" = "network";
|
||||
"POSTMASTER_ADDRESS" = "postmaster@voidarc.co.uk";
|
||||
"SPOOF_PROTECTION" = "1";
|
||||
"SSL_DOMAIN" = "mail.voidarc.co.uk";
|
||||
"SSL_TYPE" = "letsencrypt";
|
||||
};
|
||||
environmentFiles = [config.sops.templates."mail.env".path];
|
||||
volumes = [
|
||||
"/containers/mail/config:/tmp/docker-mailserver:rw"
|
||||
"/containers/mail/maildata:/var/mail:rw"
|
||||
"/containers/mail/mailstate:/var/mail-state:rw"
|
||||
"/etc/letsencrypt:/etc/letsencrypt:rw"
|
||||
"/etc/localtime:/etc/localtime:ro"
|
||||
];
|
||||
ports = [
|
||||
"25:25/tcp"
|
||||
"143:143/tcp"
|
||||
"465:465/tcp"
|
||||
"587:587/tcp"
|
||||
"993:993/tcp"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--cap-add=NET_ADMIN"
|
||||
"--hostname=mail.voidarc.co.uk"
|
||||
"--network-alias=mail"
|
||||
"--network=mail_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-mailserver" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-mail_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-mail_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-mail-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-mail-root.target"
|
||||
];
|
||||
};
|
||||
|
||||
# Networks
|
||||
systemd.services."podman-network-mail_default" = {
|
||||
path = [pkgs.podman];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
RemainAfterExit = true;
|
||||
ExecStop = "podman network rm -f mail_default";
|
||||
};
|
||||
script = ''
|
||||
podman network inspect mail_default || podman network create mail_default
|
||||
'';
|
||||
partOf = ["podman-compose-mail-root.target"];
|
||||
wantedBy = ["podman-compose-mail-root.target"];
|
||||
};
|
||||
|
||||
# Root service
|
||||
# When started, this will automatically create all resources and start
|
||||
# the containers. When stopped, this will teardown all resources.
|
||||
systemd.targets."podman-compose-mail-root" = {
|
||||
unitConfig = {
|
||||
Description = "Root target generated by compose2nix.";
|
||||
};
|
||||
wantedBy = ["multi-user.target"];
|
||||
};
|
||||
});
|
||||
}
|
||||
86
modules/containers/n8n/container.nix
Normal file
86
modules/containers/n8n/container.nix
Normal file
@@ -0,0 +1,86 @@
|
||||
{moduleWithSystem, ...}: {
|
||||
flake.nixosModules.containerN8N = moduleWithSystem ({pkgs, ...}: {
|
||||
virtualisation.oci-containers.containers."n8n-n8n" = {
|
||||
image = "docker.n8n.io/n8nio/n8n";
|
||||
environment = {
|
||||
"GENERIC_TIMEZONE" = "";
|
||||
"N8N_HOST" = ".";
|
||||
"N8N_PORT" = "5678";
|
||||
"N8N_PROTOCOL" = "https";
|
||||
"N8N_SECURE_COOKIE" = "false";
|
||||
"NODE_ENV" = "production";
|
||||
"WEBHOOK_URL" = "https://./";
|
||||
};
|
||||
volumes = [
|
||||
"/containers/n8n/local-files:/files:rw"
|
||||
"/containers/n8n/n8n-data:/home/node/.n8n:rw"
|
||||
];
|
||||
ports = [
|
||||
"0.0.0.0:5678:5678/tcp"
|
||||
];
|
||||
labels = {
|
||||
"traefik.enable" = "false";
|
||||
"traefik.http.middlewares.n8n.headers.SSLHost" = "";
|
||||
"traefik.http.middlewares.n8n.headers.SSLRedirect" = "true";
|
||||
"traefik.http.middlewares.n8n.headers.STSIncludeSubdomains" = "true";
|
||||
"traefik.http.middlewares.n8n.headers.STSPreload" = "true";
|
||||
"traefik.http.middlewares.n8n.headers.STSSeconds" = "315360000";
|
||||
"traefik.http.middlewares.n8n.headers.browserXSSFilter" = "true";
|
||||
"traefik.http.middlewares.n8n.headers.contentTypeNosniff" = "true";
|
||||
"traefik.http.middlewares.n8n.headers.forceSTSHeader" = "true";
|
||||
"traefik.http.routers.n8n.entrypoints" = "web,websecure";
|
||||
"traefik.http.routers.n8n.middlewares" = "n8n@docker";
|
||||
"traefik.http.routers.n8n.rule" = "Host(`.`)";
|
||||
"traefik.http.routers.n8n.tls" = "true";
|
||||
"traefik.http.routers.n8n.tls.certresolver" = "mytlschallenge";
|
||||
};
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=n8n"
|
||||
"--network=n8n_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-n8n-n8n" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-n8n_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-n8n_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-n8n-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-n8n-root.target"
|
||||
];
|
||||
};
|
||||
|
||||
# Networks
|
||||
systemd.services."podman-network-n8n_default" = {
|
||||
path = [pkgs.podman];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
RemainAfterExit = true;
|
||||
ExecStop = "podman network rm -f n8n_default";
|
||||
};
|
||||
script = ''
|
||||
podman network inspect n8n_default || podman network create n8n_default
|
||||
'';
|
||||
partOf = ["podman-compose-n8n-root.target"];
|
||||
wantedBy = ["podman-compose-n8n-root.target"];
|
||||
};
|
||||
|
||||
# Root service
|
||||
# When started, this will automatically create all resources and start
|
||||
# the containers. When stopped, this will teardown all resources.
|
||||
systemd.targets."podman-compose-n8n-root" = {
|
||||
unitConfig = {
|
||||
Description = "Root target generated by compose2nix.";
|
||||
};
|
||||
wantedBy = ["multi-user.target"];
|
||||
};
|
||||
});
|
||||
}
|
||||
70
modules/containers/nginx-ha/container.nix
Normal file
70
modules/containers/nginx-ha/container.nix
Normal file
@@ -0,0 +1,70 @@
|
||||
{moduleWithSystem, ...}: {
|
||||
flake.nixosModules.containerNginxHomeAssistant = moduleWithSystem ({
|
||||
pkgs,
|
||||
...
|
||||
}: {
|
||||
virtualisation.oci-containers.containers."nginx-home-assistant" = {
|
||||
image = "lscr.io/linuxserver/nginx:latest";
|
||||
environment = {
|
||||
"NGINX_AUTORELOAD" = "true";
|
||||
"PGID" = "0";
|
||||
"PUID" = "0";
|
||||
"TZ" = "Etc/UTC";
|
||||
};
|
||||
volumes = [
|
||||
"/containers/nginx-ha/config:/config:rw"
|
||||
];
|
||||
ports = [
|
||||
"8123:80/tcp"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=nginx"
|
||||
"--network=nginx-ha_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-nginx-home-assistant" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-nginx-ha_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-nginx-ha_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-nginx-ha-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-nginx-ha-root.target"
|
||||
];
|
||||
};
|
||||
|
||||
# Networks
|
||||
systemd.services."podman-network-nginx-ha_default" = {
|
||||
path = [ pkgs.podman ];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
RemainAfterExit = true;
|
||||
ExecStop = "podman network rm -f nginx-ha_default";
|
||||
};
|
||||
script = ''
|
||||
podman network inspect nginx-ha_default || podman network create nginx-ha_default
|
||||
'';
|
||||
partOf = [ "podman-compose-nginx-ha-root.target" ];
|
||||
wantedBy = [ "podman-compose-nginx-ha-root.target" ];
|
||||
};
|
||||
|
||||
# Root service
|
||||
# When started, this will automatically create all resources and start
|
||||
# the containers. When stopped, this will teardown all resources.
|
||||
systemd.targets."podman-compose-nginx-ha-root" = {
|
||||
unitConfig = {
|
||||
Description = "Root target generated by compose2nix.";
|
||||
};
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
};
|
||||
|
||||
});
|
||||
}
|
||||
61
modules/containers/silverbullet/container.nix
Normal file
61
modules/containers/silverbullet/container.nix
Normal file
@@ -0,0 +1,61 @@
|
||||
{moduleWithSystem, ...}: {
|
||||
flake.nixosModules.containerSilverbullet = moduleWithSystem ({pkgs, ...}: {config, ...}: {
|
||||
virtualisation.oci-containers.containers."silverbullet-silverbullet" = {
|
||||
image = "ghcr.io/silverbulletmd/silverbullet:v2";
|
||||
environmentFiles = [config.sops.templates."silverbullet.env".path];
|
||||
volumes = [
|
||||
"/mnt/storage/Notes:/space:rw"
|
||||
];
|
||||
ports = [
|
||||
"9003:3000/tcp"
|
||||
];
|
||||
log-driver = "journald";
|
||||
extraOptions = [
|
||||
"--network-alias=silverbullet"
|
||||
"--network=silverbullet_default"
|
||||
];
|
||||
};
|
||||
systemd.services."podman-silverbullet-silverbullet" = {
|
||||
serviceConfig = {
|
||||
Restart = pkgs.lib.mkOverride 90 "always";
|
||||
};
|
||||
after = [
|
||||
"podman-network-silverbullet_default.service"
|
||||
];
|
||||
requires = [
|
||||
"podman-network-silverbullet_default.service"
|
||||
];
|
||||
partOf = [
|
||||
"podman-compose-silverbullet-root.target"
|
||||
];
|
||||
wantedBy = [
|
||||
"podman-compose-silverbullet-root.target"
|
||||
];
|
||||
};
|
||||
|
||||
# Networks
|
||||
systemd.services."podman-network-silverbullet_default" = {
|
||||
path = [pkgs.podman];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
RemainAfterExit = true;
|
||||
ExecStop = "podman network rm -f silverbullet_default";
|
||||
};
|
||||
script = ''
|
||||
podman network inspect silverbullet_default || podman network create silverbullet_default
|
||||
'';
|
||||
partOf = ["podman-compose-silverbullet-root.target"];
|
||||
wantedBy = ["podman-compose-silverbullet-root.target"];
|
||||
};
|
||||
|
||||
# Root service
|
||||
# When started, this will automatically create all resources and start
|
||||
# the containers. When stopped, this will teardown all resources.
|
||||
systemd.targets."podman-compose-silverbullet-root" = {
|
||||
unitConfig = {
|
||||
Description = "Root target generated by compose2nix.";
|
||||
};
|
||||
wantedBy = ["multi-user.target"];
|
||||
};
|
||||
});
|
||||
}
|
||||
15
modules/features/certbot/default.nix
Normal file
15
modules/features/certbot/default.nix
Normal file
@@ -0,0 +1,15 @@
|
||||
{moduleWithSystem, ...}: {
|
||||
flake.nixosModules.certbot = moduleWithSystem ({pkgs, ...}: {
|
||||
security.acme.acceptTerms = true;
|
||||
security.acme.defaults.email = "admin@voidarc.co.uk";
|
||||
|
||||
security.acme.certs."mail.voidarc.co.uk" = {
|
||||
domain = "mail.voidarc.co.uk";
|
||||
dnsProvider = "cloudflare";
|
||||
credentialFiles = {
|
||||
"RFC2136_TSIG_SECRET_FILE" = "/run/secrets/tsig-secret-example.org";
|
||||
}
|
||||
;
|
||||
};
|
||||
});
|
||||
}
|
||||
49
modules/features/sops/default.nix
Normal file
49
modules/features/sops/default.nix
Normal file
@@ -0,0 +1,49 @@
|
||||
{
|
||||
self,
|
||||
inputs,
|
||||
...
|
||||
}: {
|
||||
flake.nixosModules.secrets = {
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}: {
|
||||
imports = [inputs.sops-nix.nixosModules.sops];
|
||||
|
||||
sops = {
|
||||
age.keyFile = "/etc/sops/age/keys.txt";
|
||||
defaultSopsFile = ../../../secrets/secrets.yaml;
|
||||
|
||||
secrets = {
|
||||
lidarr-api-key = {};
|
||||
gitea-db-passwd = {};
|
||||
immich-api-key = {};
|
||||
immich-db-passwd = {};
|
||||
immich-postgres-passwd = {};
|
||||
mail-relay-user = {};
|
||||
mail-relay-passwd = {};
|
||||
silverbullet-user = {};
|
||||
};
|
||||
templates = {
|
||||
"gitea.env".content = ''
|
||||
GITEA__database__PASSWD=${config.sops.placeholder.gitea-db-passwd}
|
||||
MYSQL_PASSWORD=${config.sops.placeholder.gitea-db-passwd}
|
||||
MYSQL_ROOT_PASSWORD=${config.sops.placeholder.gitea-db-passwd}
|
||||
'';
|
||||
"immich.env".content = ''
|
||||
DB_PASSWORD=${config.sops.placeholder.immich-db-passwd}
|
||||
IMMICH_API_KEY=${config.sops.placeholder.immich-api-key}
|
||||
POSTGRES_PASSWORD=${config.sops.placeholder.immich-postgres-passwd}
|
||||
'';
|
||||
"mail.env".content = ''
|
||||
RELAY_USER=${config.sops.placeholder.mail-relay-user}
|
||||
RELAY_PASSWORD=${config.sops.placeholder.mail-relay-passwd}
|
||||
'';
|
||||
"silverbullet.env".content = ''
|
||||
SB_USER=${config.sops.placeholder.silverbullet-user}
|
||||
'';
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -10,6 +10,10 @@
|
||||
server02Configuration
|
||||
core
|
||||
server02DiskConfiguration
|
||||
nvidiaDrivers
|
||||
containers
|
||||
secrets
|
||||
certbot
|
||||
]
|
||||
++ (with inputs.nix-config.nixosModules; [
|
||||
nvim
|
||||
|
||||
18
modules/system/drivers/nvidia.nix
Normal file
18
modules/system/drivers/nvidia.nix
Normal file
@@ -0,0 +1,18 @@
|
||||
{moduleWithSystem, ...}: {
|
||||
flake.nixosModules.nvidiaDrivers = moduleWithSystem ({unfreePkgs, ...}: {
|
||||
hardware.graphics = {
|
||||
enable = true;
|
||||
enable32Bit = true;
|
||||
};
|
||||
|
||||
nixpkgs.config.allowUnfree = true;
|
||||
|
||||
services.xserver.videoDrivers = ["nvidia"];
|
||||
|
||||
hardware.nvidia = {
|
||||
modesetting.enable = true;
|
||||
open = false;
|
||||
package = unfreePkgs.linuxPackages_latest.nvidiaPackages.legacy_580;
|
||||
};
|
||||
});
|
||||
}
|
||||
26
secrets/secrets.yaml
Normal file
26
secrets/secrets.yaml
Normal file
@@ -0,0 +1,26 @@
|
||||
#ENC[AES256_GCM,data:khWAeqeHxdTknlnvYe9IQEDwly17IWSQVVLfJEt9wyQDQlJD,iv:7XMH+6P4pYt91TBNB/g+cQGrofoBtWUoAJSV144tWtk=,tag:XKZUFtH8p5RW3ZRQ3RdRAg==,type:comment]
|
||||
#ENC[AES256_GCM,data:XWHmXDKdr0zhomE49Fecb6GMC8oYQUJiqj7xOqVebGO6Jx3r,iv:OPNw21pezQ0hunlLwpmHimKAfn16Tj8tlEnZKXV7Obs=,tag:0UfKKWs9VqiU/lVNZg4CkQ==,type:comment]
|
||||
_placeholder: ""
|
||||
gitea-db-passwd: ENC[AES256_GCM,data:LAR6PEE=,iv:4B6XwOgVpT1SvLrAbwHD4R25Gvq/hCt1AXPPK+N6zSY=,tag:+MopOvN4NGqLjxZvE9gflQ==,type:str]
|
||||
lidarr-api-key: ENC[AES256_GCM,data:65L7TFz/JK0faqdcHdZg2x+sr0Ke0o7eJOvtoE+ewgQ=,iv:8LStRO5Ktj51gl6ZxMrrCGIjmbGmc6BHgMX00L9tqCg=,tag:1FvCxPG/90u0tL8JNmhw+w==,type:str]
|
||||
immich-db-passwd: ENC[AES256_GCM,data:7DGBgqA6jfc=,iv:D0LGRE/B2HF848dVcZUBJUiZI98s51HPUGdsK2e6rU4=,tag:4q65tp9ylMGnk/867H8/lg==,type:str]
|
||||
immich-api-key: ENC[AES256_GCM,data:gMBIqOKVEBuHjusnznp9o4vNwLhBSJovdfLDrwGKX9QDTyWiKfqqnFiA,iv:13VRP2OtjNLuwbhtCJI9y5ds4CKFN3SYfQM0zsFOoMQ=,tag:nI8WpKRiELZ9/6GrxvK8QQ==,type:str]
|
||||
immich-postgres-passwd: ENC[AES256_GCM,data:Kv0l+xMwcBA=,iv:SLzp6Qo1YrwAmrhtg11MtIPGqyZ78AYJUlh0/Be2sDA=,tag:lLzndD6/jK/lUy9ijzjkyQ==,type:str]
|
||||
mail-relay-user: ENC[AES256_GCM,data:yaqB1uJ9N+9LwSsS4VsCsQxK/IPA8A0m,iv:k8c9GVeU4bdH8G+4SVKYOw4X5ytiPn33rnqx7CVn4hs=,tag:P9l6G87kI2CH301PPUmXzw==,type:str]
|
||||
mail-relay-passwd: ENC[AES256_GCM,data:9+2KuS27qukbedmG4fLwyw==,iv:+x5EgbJw/fha98CO58lwTxeF1lfZ5dL8W0zkyOvfF8w=,tag:GnMpinf68b2HdISia0wkrg==,type:str]
|
||||
silverbullet-user: ENC[AES256_GCM,data:8eoTT+T1+/khV7A96h3KoA==,iv:5wRlIU8hdRnseI5b3WUUZ0KOYtLdyrcON/P+yxg0LCs=,tag:Xxiae5Yrhv2gzIpUPX3PAw==,type:str]
|
||||
sops:
|
||||
age:
|
||||
- enc: |
|
||||
-----BEGIN AGE ENCRYPTED FILE-----
|
||||
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBqNks4dEM5Vi9RVEhCWUdT
|
||||
VkZ1ODhyR3kvT1JkekZnMnRzQzc4Y0N0ZzBjCld3U0Q4SDA4M0lmeXFway9BaGtP
|
||||
dHBDMFB2YVZteUttc0JFYXZGY0hvRXMKLS0tIEw4Y1RGVmUyazdObXlZTmEwQllP
|
||||
bkpZeHNzbnovYys4VStaUG9oVjRkbnMKjUF6toOclXUYR8lWuzC6X+qMraQNXhTo
|
||||
XS8/g9qFT4nSgM/8nLhx7I4j5/NQU+CuB/iiG5Zs4iY6+vvAe0jIUg==
|
||||
-----END AGE ENCRYPTED FILE-----
|
||||
recipient: age1rg4rsns375z2zj4tv8cyqtjl504fw8tprlmj2w057dz6ztttjstsgjvkvy
|
||||
lastmodified: "2026-07-31T17:10:29Z"
|
||||
mac: ENC[AES256_GCM,data:RzmgeFEKYRzqEnHMtSxpg7GKleAr64F7bI7EM/FHq/aYyHgtYkn22oGz8uz9/RVijLIyHcL1rJSOyO7RhUSInqfJeSOKLyxI/X1B862ZuqYOkAFSMOeNMl719cINmgw9uHUQD62Tk6VReii1L0Yf2t/l29wObIRTKg96aZPEkjA=,iv:jAWIpSq7jx71RQ6agMu7ULG2IV6oG5U7ri9rbTyQ8JU=,tag:ybo7an+/9pN0sBA73WzGjg==,type:str]
|
||||
unencrypted_suffix: _unencrypted
|
||||
version: 3.13.3
|
||||
Reference in New Issue
Block a user