Compare commits
13
Commits
beb426efcb
...
5c779be346
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
5c779be346 | ||
|
|
dc89305f34 | ||
|
|
78bc3cebbd | ||
|
|
3e13124196 | ||
|
|
aac8ea00fb | ||
|
|
a4ba6a49b6 | ||
|
|
2e34b07ad9 | ||
|
|
d0c6c7c01b | ||
|
|
d20c374427 | ||
|
|
03a0a0a229 | ||
|
|
80ebbb7078 | ||
|
|
6795a52fa5 | ||
|
|
15c5dc6db0 |
Generated
+33
-33
@@ -48,11 +48,11 @@
|
||||
},
|
||||
"locked": {
|
||||
"dir": "pkgs/firefox-addons",
|
||||
"lastModified": 1783828963,
|
||||
"narHash": "sha256-eTytzcUJCaDUZ3/9EF0+V3fvlikQMQBwiX1Sx4Gy+No=",
|
||||
"lastModified": 1786420971,
|
||||
"narHash": "sha256-irKN0AY5fDS96h7z3Cjp3EB7OwTJU1SeWFb1GxnFu3E=",
|
||||
"owner": "rycee",
|
||||
"repo": "nur-expressions",
|
||||
"rev": "8d61e9afde605cd6c22dab68b83d7a71f0a6c5b2",
|
||||
"rev": "a56dfe072a448e664d208e9ed5f7f9dc9a720686",
|
||||
"type": "gitlab"
|
||||
},
|
||||
"original": {
|
||||
@@ -83,11 +83,11 @@
|
||||
"nixpkgs-lib": "nixpkgs-lib"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1782949081,
|
||||
"narHash": "sha256-vp6Y/Grm98ESt6ceOkWiHWyZRDV3J1RID4w+6NWK9yA=",
|
||||
"lastModified": 1785627969,
|
||||
"narHash": "sha256-4dtXQk/NMePegK/nWp5NSeuZKLATItOq61lpEvmXqGw=",
|
||||
"owner": "hercules-ci",
|
||||
"repo": "flake-parts",
|
||||
"rev": "17c9d6cdfc60c64f4ee8d306f9bc0b4ccb51481e",
|
||||
"rev": "427bf4bd9435fdf21321c8cc628c24efc14c0f7a",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -103,11 +103,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1783740085,
|
||||
"narHash": "sha256-qajyHfZY29G2oEQk+uHxmsJcRoBUBXP9maTpFlwP/dI=",
|
||||
"lastModified": 1785119570,
|
||||
"narHash": "sha256-Rgs2xKnGLFWQscxUaXX07oyZeuMDOHEbqDOsgliLFGM=",
|
||||
"owner": "nix-community",
|
||||
"repo": "home-manager",
|
||||
"rev": "3cd22efe6471dc7365c822bd9ad73a21e55f38fb",
|
||||
"rev": "d4fd24667c8cbef124bb70a20380cab75ec8474d",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -119,11 +119,11 @@
|
||||
},
|
||||
"import-tree": {
|
||||
"locked": {
|
||||
"lastModified": 1778781969,
|
||||
"narHash": "sha256-Jjuz5CmSkur8KvLDoGa+vylEp+RkQtv4mt/qcMznpH0=",
|
||||
"lastModified": 1784254960,
|
||||
"narHash": "sha256-iI88R3wHz8wTKQb5orvpc51L/Xr64AJyxid/0MKa/b8=",
|
||||
"owner": "vic",
|
||||
"repo": "import-tree",
|
||||
"rev": "d321337efd0f23a9eb14a42adb7b2c29313ab274",
|
||||
"rev": "4ebb10ae17d5f1ad366e7aef5b92cb8eecf24f69",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -141,11 +141,11 @@
|
||||
"systems": "systems"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1783827446,
|
||||
"narHash": "sha256-F4ezAeh0W20dHTrXekOvJ/S2gRXGVZrFwKjAp3vwQu8=",
|
||||
"lastModified": 1786414302,
|
||||
"narHash": "sha256-FNGnUYud1D3BqE1JU2Uef+puLB2Rml7gKSdIGQOb550=",
|
||||
"owner": "Infinidoge",
|
||||
"repo": "nix-minecraft",
|
||||
"rev": "68f0b46d34625e4a745dc400e9ea30aaeec910c3",
|
||||
"rev": "cacc8cd89550f0cbec7103f3db5e96d1a66c58e7",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -159,11 +159,11 @@
|
||||
"nixpkgs": "nixpkgs"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1783792734,
|
||||
"narHash": "sha256-50rvY9GdFvpYDcMLcD/4cWSi0hVxArT5wsGlVsHy8eY=",
|
||||
"lastModified": 1786437054,
|
||||
"narHash": "sha256-I++HzBBAgQ17UaLVU6aSm1/7LDo6c9xr8rAbpByWywE=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixos-hardware",
|
||||
"rev": "8efb4337e857949f4cfac86d12ef1066f417f31f",
|
||||
"rev": "6ed13b1d888d5cb07dbb0723eb1df86bbacd0b9c",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -188,11 +188,11 @@
|
||||
},
|
||||
"nixpkgs-lib": {
|
||||
"locked": {
|
||||
"lastModified": 1782614948,
|
||||
"narHash": "sha256-ePjCwr1sNm9NYUqywL7QfK3JnlS015msC+eBu2zKlp8=",
|
||||
"lastModified": 1785031560,
|
||||
"narHash": "sha256-OmshNvn2vupOFpYinLUu+1Dnpu4n7Q5N3ggGVNHpkUI=",
|
||||
"owner": "nix-community",
|
||||
"repo": "nixpkgs.lib",
|
||||
"rev": "db3f255737b94216eb71cce308e2912cf6bc2d7c",
|
||||
"rev": "0e79af5e3d4dcfcd676ab5ba3f95d2e3352e078c",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -203,11 +203,11 @@
|
||||
},
|
||||
"nixpkgs-unstable": {
|
||||
"locked": {
|
||||
"lastModified": 1783776592,
|
||||
"narHash": "sha256-UgCQzxeWI75XM8G+hPrPh+MKzEPjG3SpAj7dtqSbksA=",
|
||||
"lastModified": 1786247143,
|
||||
"narHash": "sha256-8S3Kcxs7D4UtxJxSJZz0m14CGhuW0MxfrIwJxeGWGnQ=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "e7a3ca8092b61ff85b6a45bf863ea2b2d6a661b3",
|
||||
"rev": "279b4a8275f032c566576b3f181fa0f27197f588",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -219,11 +219,11 @@
|
||||
},
|
||||
"nixpkgs_2": {
|
||||
"locked": {
|
||||
"lastModified": 1783703440,
|
||||
"narHash": "sha256-O3/YajjWo001VUIgD8BwaRdSNLUFe7nZ1qV5TwhRBcw=",
|
||||
"lastModified": 1786313170,
|
||||
"narHash": "sha256-9BG7OgUWdu0ONDO5X2q6+K4bsuBITkX/3W4nNJu1Ito=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "8f0500b9660505dc3cb647775fe9a978a74b5283",
|
||||
"rev": "fcb8fcd6bf2d0adecae5bd491afaaaf8311b758d",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -256,11 +256,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1783174389,
|
||||
"narHash": "sha256-aCWC8ngycU7OdJrU2+Je3qf+1a2ykuBvpPhZT/9tXMc=",
|
||||
"lastModified": 1786375908,
|
||||
"narHash": "sha256-G7qDAT98nywA4EFmJCwIRO5wKvDlBBN3BWpsOnjAto8=",
|
||||
"owner": "Mic92",
|
||||
"repo": "sops-nix",
|
||||
"rev": "f1406619a3884cd5c47992a70b8b35c9c0fcb4c9",
|
||||
"rev": "d1337e05ba0a8e88a75d2c0e1595d82f3b3e2ac4",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -277,11 +277,11 @@
|
||||
"systems": "systems_2"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1783838433,
|
||||
"narHash": "sha256-Zb8+v76qSPYDlUea1y30YzgdEoDjA97vRmeqfPAqwZs=",
|
||||
"lastModified": 1786252193,
|
||||
"narHash": "sha256-a9SbkJWloPso00G4zIUkerd9n2qRyDYoDPeUc4O3ME8=",
|
||||
"owner": "Gerg-L",
|
||||
"repo": "spicetify-nix",
|
||||
"rev": "c6ab7371e40abd405313af9bddafd5f37cc94f83",
|
||||
"rev": "a87616995724d27079b495ca07318512af799449",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
|
||||
@@ -98,6 +98,12 @@
|
||||
hive.matrix.hiddenServiceSecret = config.sops.secrets.matrix-hs-secret.path;
|
||||
hive.matrix.hiddenServiceHostnameSopsKey = config.sops.secrets.hidden-matrix-hostname.name;
|
||||
hive.matrix.registrationSecretSopsKey = config.sops.secrets.hidden-matrix-registration-secret.name;
|
||||
hive.calibre.enable = true;
|
||||
hive.calibre.instanceFQDN = "calibre.jroeger.de";
|
||||
hive.calibre.libraries = ["Rote Bücher" "Technik" "Wissenschaft oder so" "Dokumente"];
|
||||
hive.korrosync.enable = true;
|
||||
hive.korrosync.localPort = 7416;
|
||||
hive.korrosync.instanceFQDN = "korrosync.jroeger.de";
|
||||
|
||||
# This value determines the NixOS release from which the default
|
||||
# settings for stateful data, like file locations and database versions
|
||||
|
||||
@@ -21,6 +21,8 @@
|
||||
self.nixosModules.borg-server
|
||||
self.nixosModules.wireguard-server
|
||||
self.nixosModules.matrix
|
||||
self.nixosModules.calibre
|
||||
self.nixosModules.korrosync-hive
|
||||
];
|
||||
};
|
||||
}
|
||||
|
||||
@@ -0,0 +1,122 @@
|
||||
{
|
||||
flake.nixosModules.calibre = {
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}: let
|
||||
cfg = config.hive.calibre;
|
||||
calibre = config.services.calibre-server.package;
|
||||
calibre-user = config.services.calibre-server.user;
|
||||
calibre-group = config.services.calibre-server.group;
|
||||
calibre-users = "${cfg.basePath}/users.sqlite";
|
||||
libraries = map (n: "${cfg.basePath}/${n}") cfg.libraries;
|
||||
ensure-libs = lib.concatStrings (
|
||||
map (l: ''
|
||||
if [ ! -d "${l}" ]; then
|
||||
echo "Creating Calibre libraray directory \"${l}\""
|
||||
mkdir "${l}"
|
||||
chown ${calibre-user}:${calibre-group} "${l}"
|
||||
fi
|
||||
|
||||
if [ ! -f "${l}/metadata.db" ]; then
|
||||
echo "Creating Calibre libraray metadata \"${l}\""
|
||||
${calibre}/bin/calibredb --with-library="${l}" list
|
||||
chown -R ${calibre-user}:${calibre-group} "${l}"
|
||||
fi
|
||||
'')
|
||||
libraries
|
||||
);
|
||||
in {
|
||||
options.hive.calibre = {
|
||||
enable = lib.mkEnableOption "Enable calibre server";
|
||||
localPort = lib.mkOption {
|
||||
type = lib.types.int;
|
||||
example = 8080;
|
||||
default = 45988;
|
||||
description = "Specify the local port calibre server uses.";
|
||||
};
|
||||
basePath = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
example = "/var/calibre-server";
|
||||
default = "/srv/calibre-server";
|
||||
description = "The base-path for calibre data";
|
||||
};
|
||||
instanceFQDN = lib.mkOption {
|
||||
type = lib.types.singleLineStr;
|
||||
example = "calibre.example.com";
|
||||
description = "Fully qualified domain name of the calibre instance";
|
||||
};
|
||||
libraries = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.singleLineStr;
|
||||
example = ["library1" "private" "foo"];
|
||||
default = ["library"];
|
||||
description = "A list of libraries to serve. (Must be present in the base-path, will be initialized if not existing)";
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
services.calibre-server = {
|
||||
enable = true;
|
||||
|
||||
auth.enable = true;
|
||||
auth.mode = "basic";
|
||||
auth.userDb = "${calibre-users}";
|
||||
|
||||
host = "::1";
|
||||
port = cfg.localPort;
|
||||
|
||||
inherit libraries;
|
||||
};
|
||||
|
||||
# Fallback server with only 403
|
||||
services.nginx.virtualHosts.${config.networking.domain} = lib.mkDefault {
|
||||
default = true;
|
||||
locations."/".return = 403;
|
||||
forceSSL = true;
|
||||
enableACME = true;
|
||||
};
|
||||
|
||||
# Virtual host for calibre
|
||||
services.nginx.virtualHosts."${cfg.instanceFQDN}" = {
|
||||
forceSSL = true;
|
||||
enableACME = true;
|
||||
locations."/" = {
|
||||
proxyPass = "http://[::1]:${toString cfg.localPort}";
|
||||
extraConfig = ''
|
||||
client_max_body_size 150M;
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
environment.systemPackages = [
|
||||
(pkgs.writeShellScriptBin "calibre-manager-users" ''
|
||||
sudo -u ${calibre-user} ${calibre}/bin/calibre-server --userdb=${calibre-users} --manage-users
|
||||
'')
|
||||
];
|
||||
|
||||
systemd.services.calibre-init = {
|
||||
description = "Initialize Calibre databases";
|
||||
|
||||
wantedBy = ["calibre-server.service"];
|
||||
before = ["calibre-server.service"];
|
||||
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
|
||||
ExecStart = pkgs.writeShellScript "calibre-init" ''
|
||||
if [ ! -d ${cfg.basePath} ]; then
|
||||
echo "Creating Calibre base directory \"${cfg.basePath}\""
|
||||
mkdir ${cfg.basePath}
|
||||
chown ${calibre-user}:${calibre-group} ${cfg.basePath}
|
||||
fi
|
||||
|
||||
${ensure-libs}
|
||||
'';
|
||||
|
||||
RemainAfterExit = true;
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,42 @@
|
||||
{
|
||||
lib,
|
||||
fetchFromGitHub,
|
||||
rustPlatform,
|
||||
openssl,
|
||||
pkg-config,
|
||||
cacert,
|
||||
...
|
||||
}:
|
||||
rustPlatform.buildRustPackage (finalAttrs: {
|
||||
pname = "korrosync";
|
||||
version = "0.4.0";
|
||||
|
||||
# Use patched version until https://github.com/szaffarano/korrosync/pull/131 is merged
|
||||
src = fetchFromGitHub {
|
||||
owner = "inaltoasinistra";
|
||||
repo = "korrosync";
|
||||
rev = "df735653b100071ce9303f3b7b71cb235189ba5d";
|
||||
hash = "sha256-8Gp5i7pN7gXjGESHNO5h4P1mWXEtR8jAh2Y39Mcur6g=";
|
||||
};
|
||||
|
||||
buildInputs = [
|
||||
openssl
|
||||
pkg-config
|
||||
];
|
||||
|
||||
nativeBuildInputs = [
|
||||
pkg-config
|
||||
];
|
||||
|
||||
#cargoHash = "sha256-3oMPREUWwKNEeaf8FdWHdjPMLU5xMSMzxKrmrhU+iko=";
|
||||
cargoLock.lockFile = "${finalAttrs.src}/Cargo.lock";
|
||||
|
||||
SSL_CERT_FILE = "${cacert}/etc/ssl/certs/ca-bundle.crt";
|
||||
NIX_SSL_CERT_FILE = "${cacert}/etc/ssl/certs/ca-bundle.crt";
|
||||
|
||||
meta = {
|
||||
description = "KOReader Sync Server";
|
||||
license = lib.licenses.mit;
|
||||
homepage = "https://github.com/szaffarano/korrosync";
|
||||
};
|
||||
})
|
||||
@@ -0,0 +1,162 @@
|
||||
{self, ...}: {
|
||||
flake.overlays.korrosync = final: prev: {
|
||||
korrosync = final.callPackage ./_derivation.nix {};
|
||||
};
|
||||
flake.nixosModules.korrosync-overlay = {
|
||||
nixpkgs.overlays = [self.overlays.korrosync];
|
||||
};
|
||||
perSystem = {pkgs, ...}: {
|
||||
packages.korrosync = pkgs.callPackage ./_derivation.nix {};
|
||||
};
|
||||
|
||||
flake.nixosModules.korrosync = {
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}: let
|
||||
cfg = config.services.korrosync;
|
||||
in {
|
||||
options.services.korrosync = {
|
||||
enable = lib.mkEnableOption "Enable KOrrosync service";
|
||||
enable-service = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
description = "Enable korrosync service";
|
||||
example = true;
|
||||
default = true;
|
||||
};
|
||||
enable-configured-binary = lib.mkEnableOption "Put a korrosync binary into system-packges using the set configuration options.";
|
||||
data-path = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
description = "The path where korrosync saves it's data.";
|
||||
example = "/var/lib/korrosync";
|
||||
default = "/var/lib/korrosync";
|
||||
};
|
||||
user = lib.mkOption {
|
||||
type = lib.types.singleLineStr;
|
||||
description = "The user under with korrosync runs.";
|
||||
example = "korrosync";
|
||||
default = "korrosync";
|
||||
};
|
||||
group = lib.mkOption {
|
||||
type = lib.types.singleLineStr;
|
||||
description = "The group under with korrosync runs.";
|
||||
example = "korrosync";
|
||||
default = "korrosync";
|
||||
};
|
||||
listen-address = lib.mkOption {
|
||||
description = "The listen address of the korrosync server";
|
||||
type = lib.types.singleLineStr;
|
||||
example = "0.0.0.0";
|
||||
default = "127.0.0.1";
|
||||
};
|
||||
listen-port = lib.mkOption {
|
||||
description = "The listen port of the korrosync server";
|
||||
type = lib.types.int;
|
||||
example = 3000;
|
||||
default = 3000;
|
||||
};
|
||||
rate-limit-per-second = lib.mkOption {
|
||||
type = lib.types.int;
|
||||
description = "Rate limit replenishment rate per second";
|
||||
example = 2;
|
||||
default = 2;
|
||||
};
|
||||
rate-limit-burst-size = lib.mkOption {
|
||||
type = lib.types.int;
|
||||
description = "Maximum burst size before rate limiting";
|
||||
example = 5;
|
||||
default = 5;
|
||||
};
|
||||
};
|
||||
|
||||
imports = [
|
||||
self.nixosModules.korrosync-overlay
|
||||
];
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
# User setup
|
||||
users.users = lib.mkIf (cfg.user == "korrosync") {
|
||||
korrosync = {
|
||||
description = "Korrosync service";
|
||||
useDefaultShell = true;
|
||||
group = cfg.group;
|
||||
isSystemUser = true;
|
||||
};
|
||||
};
|
||||
users.groups = lib.mkIf (cfg.group == "korrosync") {
|
||||
korrosync = {};
|
||||
};
|
||||
|
||||
# Pre-configured binary
|
||||
environment.systemPackages = lib.mkIf cfg.enable-configured-binary [
|
||||
(let
|
||||
envVars = config.systemd.services.korrosync.environment;
|
||||
in
|
||||
pkgs.writeShellScriptBin "korrosync"
|
||||
''
|
||||
export KORROSYNC_DB_PATH="${envVars.KORROSYNC_DB_PATH}"
|
||||
export KORROSYNC_SERVER_ADDRESS="${envVars.KORROSYNC_SERVER_ADDRESS}"
|
||||
export KORROSYNC_USE_TLS="${envVars.KORROSYNC_USE_TLS}"
|
||||
export KORROSYNC_RATE_LIMIT_PER_SECOND="${envVars.KORROSYNC_RATE_LIMIT_PER_SECOND}"
|
||||
export KORROSYNC_RATE_LIMIT_BURST_SIZE="${envVars.KORROSYNC_RATE_LIMIT_BURST_SIZE}"
|
||||
exec ${pkgs.korrosync}/bin/korrosync "$@"
|
||||
'')
|
||||
];
|
||||
|
||||
# base service
|
||||
systemd.services.korrosync = {
|
||||
enable = cfg.enable-service;
|
||||
description = "Korrosync - KOReader Sync Server";
|
||||
|
||||
after = ["network.target"];
|
||||
wantedBy = ["multi-user.target"];
|
||||
|
||||
environment = {
|
||||
KORROSYNC_DB_PATH = "${cfg.data-path}/db.redb";
|
||||
KORROSYNC_SERVER_ADDRESS = "${cfg.listen-address}:${toString cfg.listen-port}";
|
||||
KORROSYNC_USE_TLS = "false";
|
||||
KORROSYNC_RATE_LIMIT_PER_SECOND = "${toString cfg.rate-limit-per-second}";
|
||||
KORROSYNC_RATE_LIMIT_BURST_SIZE = "${toString cfg.rate-limit-burst-size}";
|
||||
};
|
||||
|
||||
serviceConfig = {
|
||||
Type = "simple";
|
||||
User = cfg.user;
|
||||
Group = cfg.group;
|
||||
ExecStart = "${pkgs.korrosync}/bin/korrosync serve";
|
||||
Restart = "on-failure";
|
||||
RestartSec = "5s";
|
||||
NoNewPrivileges = true;
|
||||
PrivateTmp = true;
|
||||
ProtectSystem = "strict";
|
||||
ProtectHome = true;
|
||||
ReadWritePaths = cfg.data-path;
|
||||
};
|
||||
};
|
||||
|
||||
# Initialize data directory
|
||||
systemd.services.korrosync-init = {
|
||||
description = "Initialize Korrosync databases";
|
||||
|
||||
wantedBy = ["korrosync.service"];
|
||||
before = ["korrosync.service"];
|
||||
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
|
||||
ExecStart = pkgs.writeShellScript "korrosync-init" ''
|
||||
if [ ! -d ${cfg.data-path} ]; then
|
||||
echo "Creating Korrosync base directory \"${cfg.data-path}\""
|
||||
mkdir ${cfg.data-path}
|
||||
chmod 770 ${cfg.data-path}
|
||||
chown ${cfg.user}:${cfg.group} ${cfg.data-path}
|
||||
fi
|
||||
'';
|
||||
|
||||
RemainAfterExit = true;
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,65 @@
|
||||
{self, ...}: {
|
||||
flake.nixosModules.korrosync-hive = {
|
||||
config,
|
||||
lib,
|
||||
...
|
||||
}: let
|
||||
cfg = config.hive.korrosync;
|
||||
in {
|
||||
options.hive.korrosync = {
|
||||
enable = lib.mkEnableOption "Enable korrosync server";
|
||||
localPort = lib.mkOption {
|
||||
type = lib.types.int;
|
||||
example = 8080;
|
||||
default = 45988;
|
||||
description = "Specify the local port korrosync server uses.";
|
||||
};
|
||||
instanceFQDN = lib.mkOption {
|
||||
type = lib.types.singleLineStr;
|
||||
example = "calibre.example.com";
|
||||
description = "Fully qualified domain name of the korrosync instance";
|
||||
};
|
||||
blockUserCreation = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
description = "Disallow /user/create endpoint via nginx";
|
||||
example = true;
|
||||
default = true;
|
||||
};
|
||||
};
|
||||
|
||||
imports = [
|
||||
self.nixosModules.korrosync
|
||||
];
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
services.korrosync = {
|
||||
enable = true;
|
||||
listen-port = cfg.localPort;
|
||||
listen-address = "127.0.0.1";
|
||||
data-path = "/srv/korrosync";
|
||||
enable-configured-binary = true;
|
||||
};
|
||||
|
||||
# Fallback server with only 403
|
||||
services.nginx.virtualHosts.${config.networking.domain} = lib.mkDefault {
|
||||
default = true;
|
||||
locations."/".return = 403;
|
||||
forceSSL = true;
|
||||
enableACME = true;
|
||||
};
|
||||
|
||||
# Virtual host for korrosync
|
||||
services.nginx.virtualHosts."${cfg.instanceFQDN}" = {
|
||||
forceSSL = true;
|
||||
enableACME = true;
|
||||
locations =
|
||||
{
|
||||
"/".proxyPass = "http://127.0.0.1:${toString cfg.localPort}";
|
||||
}
|
||||
// (lib.optionalAttrs cfg.blockUserCreation {
|
||||
"/users/create".return = 403;
|
||||
});
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -40,13 +40,6 @@
|
||||
# Database setup
|
||||
services.postgresql = {
|
||||
enable = true;
|
||||
initialScript = pkgs.writeText "matrix-synapse-initScript" ''
|
||||
CREATE ROLE "matrix-synapse";
|
||||
CREATE DATABASE "matrix-synapse" WITH OWNER "matrix-synapse"
|
||||
TEMPLATE template0
|
||||
LC_COLLATE = "C"
|
||||
LC_CTYPE = "C";
|
||||
'';
|
||||
};
|
||||
|
||||
# Hidden service
|
||||
|
||||
@@ -4,10 +4,11 @@ declare -rA presets=(
|
||||
[davinci-resolve]="-c:v dnxhd -profile:v dnxhr_hq -pix_fmt yuv422p -c:a pcm_s16le"
|
||||
[instagram]="-vf scale='if(gte(iw/ih,1),1920,-1)':'if(gte(iw/ih,1),-1,1920)':flags=lanczos -r 30 -c:v libx264 -profile:v high -level 4.1 -pix_fmt yuv420p -preset slow -crf 18 -bf 2 -g 15 -keyint_min 15 -x264-params \"open-gop=0:cabac=1:b-pyramid=none\" -movflags +faststart -c:a aac -b:a 96k"
|
||||
[insta-4k]="-r 30 -c:v libx264 -profile:v high -level 4.1 -pix_fmt yuv420p -preset slow -crf 18 -bf 2 -g 15 -keyint_min 15 -x264-params \"open-gop=0:cabac=1:b-pyramid=none\" -movflags +faststart -c:a aac -b:a 96k"
|
||||
[storage-hevc]="-c:v libx265 -preset slower -crf 18 -pix_fmt yuv420p10le -x265-params aq-mode=3:aq-strength=1.0:psy-rd=1.8:psy-rdoq=1.0 -c:a copy"
|
||||
[storage-av1]="-c:v libsvtav1 -preset 6 -crf 28 -pix_fmt yuv420p -g 240 -svtav1-params tune=0:aq-mode=2 -c:a copy"
|
||||
[storage-av1-1080p]="-vf scale='if(gte(iw/ih,1),1920,-1)':'if(gte(iw/ih,1),-1,1920)' -c:v libsvtav1 -preset 6 -crf 28 -pix_fmt yuv420p -g 240 -svtav1-params tune=0:aq-mode=2 -c:a copy"
|
||||
[storage-av1-nvenc]="-c:v av1_nvenc -cq 28 -preset slow -pix_fmt yuv420p10le -c:a copy"
|
||||
[storage-hevc-faster]="-c:v libx265 -preset slow -crf 26 -x265-params aq-mode=3:aq-strength=1.0:psy-rd=1.8:psy-rdoq=1.0 -c:a copy"
|
||||
[storage-hevc]="-c:v libx265 -preset slower -crf 22 -x265-params aq-mode=3:aq-strength=1.0:psy-rd=1.8:psy-rdoq=1.0 -c:a copy"
|
||||
[storage-av1]="-c:v libsvtav1 -preset 6 -crf 28 -g 240 -svtav1-params tune=0:aq-mode=2 -c:a copy"
|
||||
[storage-av1-1080p]="-vf scale='if(gte(iw/ih,1),1920,-1)':'if(gte(iw/ih,1),-1,1920)' -c:v libsvtav1 -preset 6 -crf 28 -g 240 -svtav1-params tune=0:aq-mode=2 -c:a copy"
|
||||
[storage-av1-nvenc]="-c:v av1_nvenc -cq 28 -preset slow -c:a copy"
|
||||
[network]="-c:v libx264 -preset slow -crf 22 -pix_fmt yuv420p -c:a aac -b:a 128k"
|
||||
[network-1080p]="-vf scale='if(gte(iw/ih,1),1920,-1)':'if(gte(iw/ih,1),-1,1920)' -c:v libx264 -preset slow -crf 22 -pix_fmt yuv420p -c:a aac -b:a 128k"
|
||||
[whatsapp]="-vf scale='if(gte(iw/ih,1),1920,-1)':'if(gte(iw/ih,1),-1,1920)' -c:v libx264 -preset slow -crf 30 -profile:v baseline -level 3.0 -pix_fmt yuv420p -r 25 -g 50 -c:a aac -b:a 160k -r:a 44100"
|
||||
@@ -17,6 +18,7 @@ declare -rA containers=(
|
||||
[davinci-resolve]="mov"
|
||||
[instagram]="mp4"
|
||||
[insta-4k]="mp4"
|
||||
[storage-hevc-faster]="mkv"
|
||||
[storage-hevc]="mkv"
|
||||
[storage-av1]="mkv"
|
||||
[storage-av1-1080p]="mkv"
|
||||
|
||||
Reference in New Issue
Block a user