Compare commits

...
8 Commits
12 changed files with 156 additions and 107 deletions
Generated
+9 -9
View File
@@ -83,11 +83,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1787146702, "lastModified": 1788642154,
"narHash": "sha256-YbRcLdU/yK4gWsQg7V8WTKZHfXL33g8+wSFUX3wyevs=", "narHash": "sha256-sPpQFVaFTDqO/4vvCAhuAhqTgqN/ygu+9eJcs5eB0js=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "173b7e8d40fdc8c296a9c99854314f17a3a1704c", "rev": "fd0956c99c41ae3c13a73a638f1f7e963aebc4ab",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -487,11 +487,11 @@
}, },
"nixpkgs_2": { "nixpkgs_2": {
"locked": { "locked": {
"lastModified": 1787204541, "lastModified": 1788807765,
"narHash": "sha256-OURZPknrTjQrlNyxPdqzyqmU/81Wes1CUP/Ft1Rv/YI=", "narHash": "sha256-J9oC0bKnkXUrMegqRTXVkyDFJ0gn2U/Qpoo9HgGMQmA=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "5880666fd9eb563038431edb35c2d0aa595884e6", "rev": "93108a538f079596c9a16c72cf03e9322782b6dd",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -540,11 +540,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786629091, "lastModified": 1788337237,
"narHash": "sha256-gkig4nPi1CWc4Z50GBsjE4ygSE7hMpl/TwID2an2Cck=", "narHash": "sha256-gkSH8VUtCo6hnysNmb9DbTuDepH2t5pv+QWjP75xKAk=",
"owner": "Mic92", "owner": "Mic92",
"repo": "sops-nix", "repo": "sops-nix",
"rev": "a8627b21b9107c5711c96b84f32a9a4b3d45295f", "rev": "fbf759290e0cb0a98dfc813a4eb7d53ad1dacb57",
"type": "github" "type": "github"
}, },
"original": { "original": {
+5 -3
View File
@@ -34,6 +34,8 @@ wargame-vods:
password: ENC[AES256_GCM,data:4Vl2Jd80bu3gVKDN7gINo8rbui6x3zxPvYEHf6GBiJDQdmRt8od/5yw4S/8=,iv:ZLdp3j0+8vLluNssXlV52XIJMczhai+6zcHsRwDwGPM=,tag:rjbp9cFbj3EFxnUZQO/QYg==,type:str] password: ENC[AES256_GCM,data:4Vl2Jd80bu3gVKDN7gINo8rbui6x3zxPvYEHf6GBiJDQdmRt8od/5yw4S/8=,iv:ZLdp3j0+8vLluNssXlV52XIJMczhai+6zcHsRwDwGPM=,tag:rjbp9cFbj3EFxnUZQO/QYg==,type:str]
admin-token: ENC[AES256_GCM,data:xxec5YDtWW7VpV+POtfhfhHG45ebCdNuD6PyHExyp0H9Ef/edTCgJtnPYWM=,iv:bLidEo0L1vP8IRtcdZ4Bcw4chHErCUHH31xQS7cFk3g=,tag:AJ9fb6xo8w41FOWu2fHHgQ==,type:str] admin-token: ENC[AES256_GCM,data:xxec5YDtWW7VpV+POtfhfhHG45ebCdNuD6PyHExyp0H9Ef/edTCgJtnPYWM=,iv:bLidEo0L1vP8IRtcdZ4Bcw4chHErCUHH31xQS7cFk3g=,tag:AJ9fb6xo8w41FOWu2fHHgQ==,type:str]
youtube-api-key: ENC[AES256_GCM,data:9W6+QK52mlTPh55ZqHXq020IpPbwbr9+Qzqhi6u96NrnRJEEVr+Z,iv:s3g2kGg2xPWD6/BuQxJ7Eqbm5HpatQbkF6PxuKufxro=,tag:1vvC8STNTX3+e5hLQTJglQ==,type:str] youtube-api-key: ENC[AES256_GCM,data:9W6+QK52mlTPh55ZqHXq020IpPbwbr9+Qzqhi6u96NrnRJEEVr+Z,iv:s3g2kGg2xPWD6/BuQxJ7Eqbm5HpatQbkF6PxuKufxro=,tag:1vvC8STNTX3+e5hLQTJglQ==,type:str]
pocket-id:
encryption_key: ENC[AES256_GCM,data:zwfKjZRDi14/sKDVVpBa0cWSb7S0YnUQOmH0bJF7+jxpiIKzU/mSqIry7eI=,iv:whBV1ZaJ+ygaiwYqjbTyKfKWRwxpx8CdqC/pwM3fGUU=,tag:2VacYAW3l61SgGPjIfQO5A==,type:str]
sops: sops:
age: age:
- enc: | - enc: |
@@ -63,7 +65,7 @@ sops:
dvKJPDYvGb/8JXSkZNkLlWvHEVnsAJ1mJFb1idenYzeQvJlsX07rYA== dvKJPDYvGb/8JXSkZNkLlWvHEVnsAJ1mJFb1idenYzeQvJlsX07rYA==
-----END AGE ENCRYPTED FILE----- -----END AGE ENCRYPTED FILE-----
recipient: age1jrk4h7x4qzhr6z5m4d099mlfyjc4n5n9s52r4gfsdz0slnqlqa9sss735v recipient: age1jrk4h7x4qzhr6z5m4d099mlfyjc4n5n9s52r4gfsdz0slnqlqa9sss735v
lastmodified: "2026-08-17T01:55:47Z" lastmodified: "2026-09-06T18:47:12Z"
mac: ENC[AES256_GCM,data:uR1BHCZi0O0KQUwVauev4CmUwAvj7xABsnQR+3FRfTJK3mcnm2TR+GabQ9F8YyTDo86fK8pYLl4iki766LUy78QJBFMXCKmB7shx5kWIDKWcSU2xlkrPbXSZmQr0Hh5x46YaZbd9UO8xabUdy3p3Vu282V192HWFXsGBQ3T1mvY=,iv:lp2ca+4vd7lIjibaTBBxy/3NmdWenaZrE2dWZzrfrBM=,tag:cJWZT7BgdVJXjwJh/4USuw==,type:str] mac: ENC[AES256_GCM,data:Y/I0EDZsjYYEJisPiEa/gS8d+vc9ksmwH87fAPn1bDzJq+reIiwg+ESkGik8VYcQL8NO6YF3ZU8nyuqIT62ZnWDUU1RZaYwoSkCpEylWmH4xq4ShJTm2Fkqj9f0wtkrCw6uOW5wlio+BlWp6gkYuC9Zp2u29ms73Z0HLU5LPTIg=,iv:h6i4UqFqA3Q3agCP4YWltMe+59VU+tuxG13jw7NO+yI=,tag:BP+7JhgYFoeOuNeUUeLOLg==,type:str]
unencrypted_suffix: _unencrypted unencrypted_suffix: _unencrypted
version: 3.13.2 version: 3.13.3
+11 -4
View File
@@ -12,7 +12,11 @@
let let
strOpt = mkOption { type = str; }; strOpt = mkOption { type = str; };
intOpt = mkOption { type = int; }; intOpt = mkOption { type = int; };
boolOpt = mkOption { boolOptTrue = mkOption {
type = bool;
default = true;
};
boolOptFalse = mkOption {
type = bool; type = bool;
default = false; default = false;
}; };
@@ -35,13 +39,14 @@
volumes = strList; volumes = strList;
environment = attrOpt; environment = attrOpt;
environmentFiles = strList; environmentFiles = strList;
public = boolOpt; public = boolOptFalse;
user = mkOption { user = mkOption {
type = nullOr str; type = nullOr str;
default = null; default = null;
}; };
extraOptions = strList; extraOptions = strList;
oauthProxy = boolOpt; oauthProxy = boolOptFalse;
alwaysPull = boolOptTrue;
extraLabels = attrOpt; extraLabels = attrOpt;
}; };
}); });
@@ -76,6 +81,7 @@
extraOptions, extraOptions,
oauthProxy, oauthProxy,
extraLabels, extraLabels,
alwaysPull,
}: }:
let let
fqn = "${hostname}.${domain}"; fqn = "${hostname}.${domain}";
@@ -97,6 +103,7 @@
{ "traefik.http.routers.${serviceName}.middlewares" = "oidc-auth@file"; } { "traefik.http.routers.${serviceName}.middlewares" = "oidc-auth@file"; }
else else
{ }; { };
options = if alwaysPull then extraOptions ++ [ "--pull=always" ] else options;
in in
{ {
inherit inherit
@@ -106,7 +113,6 @@
environment environment
environmentFiles environmentFiles
user user
extraOptions
; ;
autoStart = true; autoStart = true;
labels = { labels = {
@@ -119,6 +125,7 @@
// oauthLabels // oauthLabels
// homepageLabels // homepageLabels
// extraLabels; // extraLabels;
extraOptions = options;
}; };
in in
builtins.mapAttrs mkContainer config.virtualisation.web-containers.containers builtins.mapAttrs mkContainer config.virtualisation.web-containers.containers
+19 -1
View File
@@ -45,17 +45,32 @@
type = with types; uniq str; type = with types; uniq str;
default = "/var/run/docker.sock"; default = "/var/run/docker.sock";
example = "/var/run/docker.sock"; example = "/var/run/docker.sock";
description = "Path to the container management deamon's socket."; description = "Path to the container management deamon's socket";
};
container-pkg = mkOption {
type = with types; uniq package;
default = pkgs.docker;
example = "pkgs.docker";
description = "The package used to interact with the container system";
};
container-bin = mkOption {
type = with types; uniq str;
default = "${pkgs.docker}/bin/docker";
example = "${pkgs.docker}/bin/docker";
description = "The path to the binary used to interact with the container system";
}; };
}; };
config = { config = {
# local = { # local = {
# container-backend = "docker"; # container-backend = "docker";
# container-bin = pkgs.docker;
# container-socket = "/var/run/docker.sock"; # container-socket = "/var/run/docker.sock";
# }; # };
local = { local = {
container-backend = "podman"; container-backend = "podman";
container-pkg = pkgs.podman;
container-bin = "${pkgs.podman}/bin/podman";
container-socket = "/var/run/podman/podman.sock"; container-socket = "/var/run/podman/podman.sock";
}; };
@@ -125,6 +140,7 @@
image = "ghcr.io/gethomepage/homepage:latest"; image = "ghcr.io/gethomepage/homepage:latest";
autoStart = true; autoStart = true;
extraOptions = [ extraOptions = [
"--pull=always"
"-l=traefik.enable=true" "-l=traefik.enable=true"
"-l=traefik.http.routers.homepage.rule=${localHostRuleHavenisms "start"}" "-l=traefik.http.routers.homepage.rule=${localHostRuleHavenisms "start"}"
"-l=traefik.http.services.homepage.loadbalancer.server.port=3000" "-l=traefik.http.services.homepage.loadbalancer.server.port=3000"
@@ -143,12 +159,14 @@
HOMEPAGE_FILE_SONARR_KEY = "/app/config/secrets/sonarr.key"; HOMEPAGE_FILE_SONARR_KEY = "/app/config/secrets/sonarr.key";
HOMEPAGE_FILE_READARR_KEY = "/app/config/secrets/readarr.key"; HOMEPAGE_FILE_READARR_KEY = "/app/config/secrets/readarr.key";
HOMEPAGE_FILE_DELUGE_PASSWORD = "/app/config/secrets/deluge.pass"; HOMEPAGE_FILE_DELUGE_PASSWORD = "/app/config/secrets/deluge.pass";
HOMEPAGE_ALLOWED_HOSTS = "start.${havenisms}";
}; };
}; };
scrutiny = { scrutiny = {
image = "ghcr.io/analogj/scrutiny:master-omnibus"; image = "ghcr.io/analogj/scrutiny:master-omnibus";
autoStart = true; autoStart = true;
extraOptions = [ extraOptions = [
"--pull=always"
"-l=traefik.enable=true" "-l=traefik.enable=true"
"-l=traefik.http.routers.scrutiny.rule=${localHostRuleHavenisms "scrutiny"}" "-l=traefik.http.routers.scrutiny.rule=${localHostRuleHavenisms "scrutiny"}"
"-l=traefik.http.services.scrutiny.loadbalancer.server.port=8080" "-l=traefik.http.services.scrutiny.loadbalancer.server.port=8080"
@@ -14,36 +14,34 @@ in
}; };
sops.templates."matrix-blazestar-net.env".content = '' sops.templates."matrix-blazestar-net.env".content = ''
TUWUNEL_REGISTRATION_TOKEN=${config.sops.placeholder."matrix/blazestar-registration-token"} CONTINUWUITY_REGISTRATION_TOKEN=${config.sops.placeholder."matrix/blazestar-registration-token"}
''; '';
# This isn't using any of my usual helpers because I wanted to set a custom # This isn't using any of my usual helpers because I wanted to set a custom
# serviceName in Traefik that is different from the hostname to avoid # serviceName in Traefik that is different from the hostname to avoid
# conflicts with the havenisms.com server. # conflicts with the havenisms.com server.
virtualisation.oci-containers.containers."${serviceName}" = { virtualisation.oci-containers.containers."${serviceName}" = {
# The 1.1.0 version has an issue with the compression being incorrectly tagged. image = "forgejo.ellis.link/continuwuation/continuwuity:latest";
# See: https://github.com/matrix-construct/tuwunel/issues/79
image = "ghcr.io/matrix-construct/tuwunel:v1.0.0-release-all-x86_64-linux-gnu";
autoStart = true; autoStart = true;
volumes = [ volumes = [
"matrix-blazestar-net-db:${dbPath}" "matrix-blazestar-net-db:${dbPath}"
]; ];
environment = { environment = {
TUWUNEL_PORT = toString port; CONTINUWUITY_PORT = toString port;
TUWUNEL_ADDRESS = "0.0.0.0"; # It'll bind to localhost by default with Podman CONTINUWUITY_ADDRESS = "0.0.0.0"; # It'll bind to localhost by default with Podman
TUWUNEL_SERVER_NAME = "blazestar.net"; CONTINUWUITY_SERVER_NAME = "blazestar.net";
TUWUNEL_ALLOW_REGISTRATION = "true"; CONTINUWUITY_ALLOW_REGISTRATION = "true";
TUWUNEL_ALLOW_CHECK_FOR_UPDATES = "true"; CONTINUWUITY_ALLOW_CHECK_FOR_UPDATES = "true";
TUWUNEL_ALLOW_FEDERATION = "true"; CONTINUWUITY_ALLOW_FEDERATION = "true";
TUWUNEL_DATABASE_BACKEND = "rocksdb"; CONTINUWUITY_DATABASE_BACKEND = "rocksdb";
TUWUNEL_DATABASE_PATH = dbPath; CONTINUWUITY_DATABASE_PATH = dbPath;
TUWUNEL_WELL_KNOWN = '' CONTINUWUITY_WELL_KNOWN = ''
{ {
client=https://${matrixHost}.blazestar.net, client=https://${matrixHost}.blazestar.net,
server=${matrixHost}.blazestar.net:443 server=${matrixHost}.blazestar.net:443
} }
''; '';
TUWUNEL_TRUSTED_SERVERS = ''["matrix.org", "chat.havenisms.com"]''; CONTINUWUITY_TRUSTED_SERVERS = ''["matrix.org", "chat.havenisms.com"]'';
}; };
environmentFiles = [ environmentFiles = [
config.sops.templates."matrix-blazestar-net.env".path config.sops.templates."matrix-blazestar-net.env".path
@@ -4,7 +4,7 @@ let
in in
{ {
virtualisation.web-containers.containers.uptime = { virtualisation.web-containers.containers.uptime = {
image = "louislam/uptime-kuma:1"; image = "louislam/uptime-kuma:1"; # TODO: Why not version 2?
hostname = "uptime"; hostname = "uptime";
domain = blazestar; domain = blazestar;
port = 3001; port = 3001;
@@ -42,4 +42,22 @@ in
config.sops.templates."wargame-vods.env".path config.sops.templates."wargame-vods.env".path
]; ];
}; };
systemd = {
timers.wargame-vods-import = {
wantedBy = [ "timers.target" ];
timerConfig = {
OnCalendar = "hourly";
Persistent = false; # Do not catch up if timers were missed
RandomizedDelaySec = "5m"; # Jitter so it doesn't get synced up with anything else.
};
};
services.wargame-vods-import = {
description = "Hourly wargame-vods import";
serviceConfig = {
Type = "oneshot";
ExecStart = "${config.local.container-bin} exec wargame-vods /proc/1/exe sync";
};
};
};
} }
+2 -2
View File
@@ -1,5 +1,4 @@
{ config, pkgs, ... }: { ... }:
let inherit (import ./lib.nix config) mkContainer; in
{ {
virtualisation.oci-containers.containers.collabora = { virtualisation.oci-containers.containers.collabora = {
image = "collabora/code"; image = "collabora/code";
@@ -10,5 +9,6 @@ let inherit (import ./lib.nix config) mkContainer; in
DONT_GEN_SSL_CERT = "true"; DONT_GEN_SSL_CERT = "true";
}; };
autoStart = true; autoStart = true;
extraOptions = [ "--pull=always" ];
}; };
} }
+1
View File
@@ -68,5 +68,6 @@ in
# The runner will spawn new containers to run the actions # The runner will spawn new containers to run the actions
"${config.local.container-socket}:/var/run/docker.sock:ro" "${config.local.container-socket}:/var/run/docker.sock:ro"
]; ];
extraOptions = [ "--pull=always" ];
}; };
} }
+1 -1
View File
@@ -67,7 +67,6 @@ in
environmentFiles environmentFiles
ports ports
user user
extraOptions
; ;
autoStart = true; autoStart = true;
labels = { labels = {
@@ -78,6 +77,7 @@ in
// oauthLabels // oauthLabels
// homepageLabels // homepageLabels
// extraLabels; // extraLabels;
extraOptions = extraOptions ++ [ "--pull=always" ];
}; };
# Creates a MariaDB container for a specific app. It should be safe to give # Creates a MariaDB container for a specific app. It should be safe to give
+50 -65
View File
@@ -44,9 +44,10 @@ in
virtualisation.oci-containers.containers = { virtualisation.oci-containers.containers = {
jellyfin = { jellyfin = {
image = "lscr.io/linuxserver/jellyfin:10.11.6"; image = "lscr.io/linuxserver/jellyfin:latest";
autoStart = true; autoStart = true;
extraOptions = [ extraOptions = [
"--pull=always"
"--device=/dev/dri:/dev/dri" "--device=/dev/dri:/dev/dri"
"-l=traefik.enable=true" "-l=traefik.enable=true"
"-l=traefik.http.routers.jellyfin.rule=${hostRuleHavenisms "jellyfin"}" "-l=traefik.http.routers.jellyfin.rule=${hostRuleHavenisms "jellyfin"}"
@@ -72,28 +73,29 @@ in
# GUID = "993"; # GUID = "993";
# }; # };
}; };
deluge = { # deluge = {
image = "lscr.io/linuxserver/deluge:latest"; # image = "lscr.io/linuxserver/deluge:latest";
autoStart = true; # autoStart = true;
dependsOn = [ # dependsOn = [
"gluetun" # "gluetun"
]; # ];
extraOptions = [ # extraOptions = [
"--network=container:gluetun" # "--pull=always"
"-l=homepage.group=Arr" # "--network=container:gluetun"
"-l=homepage.name=Deluge" # "-l=homepage.group=Arr"
"-l=homepage.icon=deluge.svg" # "-l=homepage.name=Deluge"
"-l=homepage.href=https://deluge.${havenisms}" # "-l=homepage.icon=deluge.svg"
"-l=homepage.description=Torrent client" # "-l=homepage.href=https://deluge.${havenisms}"
"-l=homepage.widget.type=deluge" # "-l=homepage.description=Torrent client"
"-l=homepage.widget.password={{HOMEPAGE_FILE_DELUGE_PASSWORD}}" # "-l=homepage.widget.type=deluge"
"-l=homepage.widget.url=http://gluetun:8112" # "-l=homepage.widget.password={{HOMEPAGE_FILE_DELUGE_PASSWORD}}"
]; # "-l=homepage.widget.url=http://gluetun:8112"
volumes = [ # ];
"/tank/media:/data" # volumes = [
"/tank/config/deluge:/config" # "/tank/media:/data"
]; # "/tank/config/deluge:/config"
}; # ];
# };
qbittorrent = { qbittorrent = {
image = "lscr.io/linuxserver/qbittorrent:latest"; image = "lscr.io/linuxserver/qbittorrent:latest";
autoStart = true; autoStart = true;
@@ -101,6 +103,7 @@ in
"gluetun" "gluetun"
]; ];
extraOptions = [ extraOptions = [
"--pull=always"
"--network=container:gluetun" "--network=container:gluetun"
"-l=homepage.group=Arr" "-l=homepage.group=Arr"
"-l=homepage.name=qBitTorrent" "-l=homepage.name=qBitTorrent"
@@ -124,6 +127,7 @@ in
image = "qmcgaw/gluetun:latest"; image = "qmcgaw/gluetun:latest";
autoStart = true; autoStart = true;
extraOptions = [ extraOptions = [
"--pull=always"
# add network admin capability. # add network admin capability.
"--cap-add=NET_ADMIN" "--cap-add=NET_ADMIN"
"--device=/dev/net/tun:/dev/net/tun" "--device=/dev/net/tun:/dev/net/tun"
@@ -150,6 +154,7 @@ in
image = "lscr.io/linuxserver/prowlarr"; image = "lscr.io/linuxserver/prowlarr";
autoStart = true; autoStart = true;
extraOptions = [ extraOptions = [
"--pull=always"
"-l=traefik.enable=true" "-l=traefik.enable=true"
"-l=traefik.http.routers.prowlarr.rule=${localHostRuleHavenisms "prowlarr"}" "-l=traefik.http.routers.prowlarr.rule=${localHostRuleHavenisms "prowlarr"}"
"-l=traefik.http.services.prowlarr.loadbalancer.server.port=9696" "-l=traefik.http.services.prowlarr.loadbalancer.server.port=9696"
@@ -167,27 +172,31 @@ in
}; };
}; };
# Currently broken and doesn't work. :( # Currently broken and doesn't work. :(
# flaresolverr = { flaresolverr = {
# image = "ghcr.io/flaresolverr/flaresolverr:latest"; image = "ghcr.io/flaresolverr/flaresolverr:latest";
# autoStart = true; autoStart = true;
# extraOptions = [ extraOptions = [
# "-l=homepage.group=Infra" "-l=traefik.enable=true"
# "-l=homepage.name=FlareSolverr" "-l=traefik.http.routers.flaresolverr.rule=${localHostRuleHavenisms "flaresolverr"}"
# "-l=homepage.icon=flaresolverr.svg" "-l=traefik.http.services.flaresolverr.loadbalancer.server.port=8191"
# "-l=homepage.href=https://flaresolverr.${domain}" "-l=homepage.group=Infra"
# "-l=homepage.description=Cloudflare bypass" "-l=homepage.name=FlareSolverr"
# ]; "-l=homepage.icon=flaresolverr.svg"
# volumes = [ "-l=homepage.href=https://flaresolverr.${havenisms}"
# "/tank/config/flaresolverr:/config" "-l=homepage.description=Cloudflare bypass"
# ]; ];
# environment = { volumes = [
# UMASK = "002"; "/tank/config/flaresolverr:/config"
# }; ];
# }; environment = {
UMASK = "002";
};
};
radarr = { radarr = {
image = "lscr.io/linuxserver/radarr"; image = "lscr.io/linuxserver/radarr";
autoStart = true; autoStart = true;
extraOptions = [ extraOptions = [
"--pull=always"
"-l=traefik.enable=true" "-l=traefik.enable=true"
"-l=traefik.http.routers.radarr.rule=${localHostRuleHavenisms "radarr"}" "-l=traefik.http.routers.radarr.rule=${localHostRuleHavenisms "radarr"}"
"-l=traefik.http.services.radarr.loadbalancer.server.port=7878" "-l=traefik.http.services.radarr.loadbalancer.server.port=7878"
@@ -212,6 +221,7 @@ in
image = "lscr.io/linuxserver/sonarr"; image = "lscr.io/linuxserver/sonarr";
autoStart = true; autoStart = true;
extraOptions = [ extraOptions = [
"--pull=always"
"-l=traefik.enable=true" "-l=traefik.enable=true"
"-l=traefik.http.routers.sonarr.rule=${localHostRuleHavenisms "sonarr"}" "-l=traefik.http.routers.sonarr.rule=${localHostRuleHavenisms "sonarr"}"
"-l=traefik.http.services.sonarr.loadbalancer.server.port=8989" "-l=traefik.http.services.sonarr.loadbalancer.server.port=8989"
@@ -232,31 +242,6 @@ in
UMASK = "002"; UMASK = "002";
}; };
}; };
readarr = {
# The Linuxserver version of this image doesn't have a latest tag. Odd.
image = "lscr.io/linuxserver/readarr:develop";
autoStart = true;
extraOptions = [
"-l=traefik.enable=true"
"-l=traefik.http.routers.readarr.rule=${localHostRuleHavenisms "readarr"}"
"-l=traefik.http.services.readarr.loadbalancer.server.port=8787"
"-l=homepage.group=Arr"
"-l=homepage.name=Readarr"
"-l=homepage.icon=readarr.svg"
"-l=homepage.href=https://readarr.${havenisms}"
"-l=homepage.description=E-book acquisition"
"-l=homepage.widget.type=readarr"
"-l=homepage.widget.url=http://readarr.havenisms.com:8787"
"-l=homepage.widget.key={{HOMEPAGE_FILE_READARR_KEY}}"
];
volumes = [
"/tank/media:/data"
"/tank/config/readarr:/config"
];
environment = {
UMASK = "002";
};
};
bazarr = mkContainer { bazarr = mkContainer {
# The Linuxserver version of this image doesn't have a latest tag. Odd. # The Linuxserver version of this image doesn't have a latest tag. Odd.
image = "lscr.io/linuxserver/bazarr:latest"; image = "lscr.io/linuxserver/bazarr:latest";
+24 -4
View File
@@ -8,8 +8,25 @@ let
# - 3000: Web UI # - 3000: Web UI
# - 2019: Admin endpoint # - 2019: Admin endpoint
port = 8888; port = 8888;
encryption_key = "pocket-id/encryption_key";
in in
{ {
sops.secrets = {
"${encryption_key}" = {
restartUnits = [ "${config.local.container-backend}-pocket-id.service" ];
mode = "0400";
owner = "pocket-id";
};
};
sops.templates."pocket-id.env" = {
content = ''
ENCRYPTION_KEY=${config.sops.placeholder."${encryption_key}"}
'';
owner = "pocket-id";
};
virtualisation.oci-containers.containers.pocket-id = mkContainer { virtualisation.oci-containers.containers.pocket-id = mkContainer {
image = "ghcr.io/pocket-id/pocket-id"; image = "ghcr.io/pocket-id/pocket-id";
dependsOn = [ ]; dependsOn = [ ];
@@ -24,17 +41,20 @@ in
description = "Pocket ID Auth Server"; description = "Pocket ID Auth Server";
}; };
volumes = [ volumes = [
"/tank/pocket-id/data:/app/backend/data" "/tank/pocket-id/data:/app/data"
]; ];
environment = { environment = {
PUBLIC_APP_URL = "https://auth.${blazestar}"; APP_URL = "https://auth.${blazestar}";
# Whether the app is behind a reverse proxy. # Whether the app is behind a reverse proxy.
TRUST_PROXY = "false"; TRUST_PROXY = "true";
CADDY_PORT = toString port; PORT = toString port;
# PORT = "3000"; # Frontend port # PORT = "3000"; # Frontend port
# BACKEND_PORT = "8080"; # Backend port # BACKEND_PORT = "8080"; # Backend port
PUID = toString config.users.users."pocket-id".uid; PUID = toString config.users.users."pocket-id".uid;
PGID = toString config.users.groups."pocket-id".gid; PGID = toString config.users.groups."pocket-id".gid;
}; };
environmentFiles = [
config.sops.templates."pocket-id.env".path
];
}; };
} }