From 9242347eafe49d23bc442e11bc573f1ecc64ebd5 Mon Sep 17 00:00:00 2001 From: tux Date: Sun, 9 Aug 2026 18:18:26 +0530 Subject: [PATCH] refactor(services): standardize host and proxy options --- modules/nixos/services/aiostreams.nix | 28 ++++++++++++++++++---- modules/nixos/services/mediaflow-proxy.nix | 27 +++++++++++++++++---- modules/nixos/services/uptime-kuma.nix | 28 ++++++++++++++++++---- modules/nixos/services/vaultwarden.nix | 27 +++++++++++++++++---- 4 files changed, 94 insertions(+), 16 deletions(-) diff --git a/modules/nixos/services/aiostreams.nix b/modules/nixos/services/aiostreams.nix index 90a77c0..9c60f87 100644 --- a/modules/nixos/services/aiostreams.nix +++ b/modules/nixos/services/aiostreams.nix @@ -15,6 +15,12 @@ options.tnix.services.aiostreams = { enable = mkEnableOption "AIOStreams"; + host = mkOption { + type = types.str; + default = "127.0.0.1"; + description = "Host on which AIOStreams listens"; + }; + port = mkOption { type = types.port; default = 3000; @@ -24,7 +30,13 @@ domain = mkOption { type = types.str; default = ""; - description = "Domain on which nginx serves AIOStreams (disabled when empty)"; + description = "Domain on which AIOStreams is available"; + }; + + configureNginx = mkOption { + type = types.bool; + default = false; + description = "Whether to configure Nginx as a reverse proxy for AIOStreams"; }; image = mkOption { @@ -47,10 +59,17 @@ }; config = mkIf cfg.enable { + assertions = [ + { + assertion = cfg.domain != ""; + message = "tnix.services.aiostreams.domain must be set when tnix.services.aiostreams.enable is true."; + } + ]; + virtualisation.oci-containers.containers.aiostreams = { image = cfg.image; ports = [ - "127.0.0.1:${port}:3000" + "${cfg.host}:${port}:3000" ]; environment = { ADDON_ID = cfg.domain; @@ -62,11 +81,12 @@ ]; }; - services.nginx.virtualHosts.${cfg.domain} = mkIf (cfg.domain != "") { + services.nginx.virtualHosts.${cfg.domain} = mkIf cfg.configureNginx { forceSSL = acmeHost != ""; useACMEHost = mkIf (acmeHost != "") acmeHost; locations."/" = { - proxyPass = "http://127.0.0.1:${port}"; + proxyPass = "http://${cfg.host}:${port}"; + proxyWebsockets = true; }; }; }; diff --git a/modules/nixos/services/mediaflow-proxy.nix b/modules/nixos/services/mediaflow-proxy.nix index d5f4a03..4bc833a 100644 --- a/modules/nixos/services/mediaflow-proxy.nix +++ b/modules/nixos/services/mediaflow-proxy.nix @@ -15,6 +15,12 @@ options.tnix.services.mediaflow-proxy = { enable = mkEnableOption "MediaFlow Proxy"; + host = mkOption { + type = types.str; + default = "0.0.0.0"; + description = "Host on which MediaFlow Proxy listens"; + }; + port = mkOption { type = types.port; default = 8888; @@ -24,7 +30,13 @@ domain = mkOption { type = types.str; default = ""; - description = "Domain on which nginx serves MediaFlow Proxy (disabled when empty)"; + description = "Domain on which MediaFlow Proxy is available"; + }; + + configureNginx = mkOption { + type = types.bool; + default = false; + description = "Whether to configure Nginx as a reverse proxy for MediaFlow Proxy"; }; image = mkOption { @@ -41,10 +53,17 @@ }; config = mkIf cfg.enable { + assertions = [ + { + assertion = !cfg.configureNginx || cfg.domain != ""; + message = "tnix.services.mediaflow-proxy.domain must be set when configureNginx is enabled."; + } + ]; + virtualisation.oci-containers.containers.mediaflow-proxy = { image = cfg.image; ports = [ - "${port}:${port}" + "${cfg.host}:${port}:${port}" ]; environment = { APP__SERVER__HOST = "0.0.0.0"; @@ -53,11 +72,11 @@ environmentFiles = optional (cfg.environmentFile != null) cfg.environmentFile; }; - services.nginx.virtualHosts.${cfg.domain} = mkIf (cfg.domain != "") { + services.nginx.virtualHosts.${cfg.domain} = mkIf cfg.configureNginx { forceSSL = acmeHost != ""; useACMEHost = mkIf (acmeHost != "") acmeHost; locations."/" = { - proxyPass = "http://127.0.0.1:${port}"; + proxyPass = "http://${cfg.host}:${port}"; proxyWebsockets = true; }; }; diff --git a/modules/nixos/services/uptime-kuma.nix b/modules/nixos/services/uptime-kuma.nix index b3a88f4..218a5f5 100644 --- a/modules/nixos/services/uptime-kuma.nix +++ b/modules/nixos/services/uptime-kuma.nix @@ -15,6 +15,12 @@ options.tnix.services.uptime-kuma = { enable = mkEnableOption "Uptime Kuma"; + host = mkOption { + type = types.str; + default = "127.0.0.1"; + description = "Host on which Uptime Kuma listens"; + }; + port = mkOption { type = types.port; default = 1111; @@ -24,25 +30,39 @@ domain = mkOption { type = types.str; default = ""; - description = "Domain on which nginx serves Uptime Kuma (disabled when empty)"; + description = "Domain on which Uptime Kuma is available"; + }; + + configureNginx = mkOption { + type = types.bool; + default = false; + description = "Whether to configure Nginx as a reverse proxy for Uptime Kuma"; }; }; config = mkIf cfg.enable { + assertions = [ + { + assertion = cfg.domain != ""; + message = "tnix.services.uptime-kuma.domain must be set when tnix.services.uptime-kuma.enable is true."; + } + ]; + services = { uptime-kuma = { enable = true; settings = { - HOST = "127.0.0.1"; + HOST = cfg.host; PORT = port; }; }; - nginx.virtualHosts.${cfg.domain} = mkIf (cfg.domain != "") { + nginx.virtualHosts.${cfg.domain} = mkIf cfg.configureNginx { forceSSL = acmeHost != ""; useACMEHost = mkIf (acmeHost != "") acmeHost; locations."/" = { - proxyPass = "http://127.0.0.1:${port}"; + proxyPass = "http://${cfg.host}:${port}"; + proxyWebsockets = true; }; }; }; diff --git a/modules/nixos/services/vaultwarden.nix b/modules/nixos/services/vaultwarden.nix index d9f5681..8d6df40 100644 --- a/modules/nixos/services/vaultwarden.nix +++ b/modules/nixos/services/vaultwarden.nix @@ -15,6 +15,12 @@ options.tnix.services.vaultwarden = { enable = mkEnableOption "Vaultwarden"; + host = mkOption { + type = types.str; + default = "127.0.0.1"; + description = "Host on which Vaultwarden listens"; + }; + port = mkOption { type = types.port; default = 8000; @@ -24,17 +30,30 @@ domain = mkOption { type = types.str; default = ""; - description = "Domain on which nginx serves Vaultwarden (disabled when empty)"; + description = "Domain on which Vaultwarden is available"; + }; + + configureNginx = mkOption { + type = types.bool; + default = false; + description = "Whether to configure Nginx as a reverse proxy for Vaultwarden"; }; }; config = mkIf cfg.enable { + assertions = [ + { + assertion = cfg.domain != ""; + message = "tnix.services.vaultwarden.domain must be set when tnix.services.vaultwarden.enable is true."; + } + ]; + services = { vaultwarden = { enable = true; dbBackend = "postgresql"; config = { - ROCKET_ADDRESS = "127.0.0.1"; + ROCKET_ADDRESS = cfg.host; ROCKET_PORT = cfg.port; DOMAIN = "https://${cfg.domain}"; @@ -45,11 +64,11 @@ }; }; - nginx.virtualHosts.${cfg.domain} = mkIf (cfg.domain != "") { + nginx.virtualHosts.${cfg.domain} = mkIf cfg.configureNginx { forceSSL = acmeHost != ""; useACMEHost = mkIf (acmeHost != "") acmeHost; locations."/" = { - proxyPass = "http://127.0.0.1:${port}"; + proxyPass = "http://${cfg.host}:${port}"; proxyWebsockets = true; }; };