Compare commits

...

6 Commits

9 changed files with 295 additions and 211 deletions

175
flake.lock generated
View File

@@ -42,11 +42,11 @@
]
},
"locked": {
"lastModified": 1784368054,
"narHash": "sha256-zF1iJkBQSDWmRO4/LEeHR1SpKY0lqZaxkoQJpPS9K9U=",
"lastModified": 1785877886,
"narHash": "sha256-H2CrAlJD9FsUbSEIhPVK3IyVjnK0vSxPruBef17GcBs=",
"owner": "hyprwm",
"repo": "aquamarine",
"rev": "9b5f14d9483445e766294eb8fbe0b8f370269ed0",
"rev": "1a10fe26a9f7d989c359e6a9ea61aa2e44d06c36",
"type": "github"
},
"original": {
@@ -139,11 +139,11 @@
"utils": "utils"
},
"locked": {
"lastModified": 1781627888,
"narHash": "sha256-5yHuAh9k7rT7rtf3uRaXkiUyYvQE9oaCgzhprLm2mr8=",
"lastModified": 1785892481,
"narHash": "sha256-1JTy9/LyITSBP1a4WZ9tmOv2yDh9OTbA3YUJbQHiMYc=",
"owner": "serokell",
"repo": "deploy-rs",
"rev": "6d3087eedff75a715b40c0e124ba15d2dd7bec28",
"rev": "f6f2359a6cb7e3c51ea673bcb39933ac2622350d",
"type": "github"
},
"original": {
@@ -237,20 +237,6 @@
}
},
"flake-compat_5": {
"locked": {
"lastModified": 1733328505,
"narHash": "sha256-NeCCThCEP3eCl2l/+27kNNK7QrwZB1IJCrXfrbv5oqU=",
"rev": "ff81ac966bb2cae68946d5ed5fc4994f96d0ffec",
"revCount": 69,
"type": "tarball",
"url": "https://api.flakehub.com/f/pinned/edolstra/flake-compat/1.1.0/01948eb7-9cba-704f-bbf3-3fa956735b52/source.tar.gz"
},
"original": {
"type": "tarball",
"url": "https://flakehub.com/f/edolstra/flake-compat/1.tar.gz"
}
},
"flake-compat_6": {
"flake": false,
"locked": {
"lastModified": 1767039857,
@@ -273,11 +259,11 @@
]
},
"locked": {
"lastModified": 1782949081,
"narHash": "sha256-vp6Y/Grm98ESt6ceOkWiHWyZRDV3J1RID4w+6NWK9yA=",
"lastModified": 1785627969,
"narHash": "sha256-4dtXQk/NMePegK/nWp5NSeuZKLATItOq61lpEvmXqGw=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "17c9d6cdfc60c64f4ee8d306f9bc0b4ccb51481e",
"rev": "427bf4bd9435fdf21321c8cc628c24efc14c0f7a",
"type": "github"
},
"original": {
@@ -446,11 +432,11 @@
]
},
"locked": {
"lastModified": 1784789275,
"narHash": "sha256-cgRTWuG+u1tBPhm01JrId2k0Bni09phVJ1Q0BZlRd7M=",
"lastModified": 1786031233,
"narHash": "sha256-TIDlLTLI1/pB7IqgjzcKQjpODQsZE2oII4XGG9B6KjI=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "3b0e6bbd65869af1beadf5963a99befc179d209f",
"rev": "7834e82588860aaf780cec1366524456a70898d7",
"type": "github"
},
"original": {
@@ -525,11 +511,11 @@
]
},
"locked": {
"lastModified": 1782566056,
"narHash": "sha256-haEZcHzYrePnjFOYSWTbxm/Nrla0aPslJfmvdCvqtVc=",
"lastModified": 1785855875,
"narHash": "sha256-dpW3UKG2NTboxxYGzOX4nZiH8YI++CpgosHmVaquOEI=",
"owner": "hyprwm",
"repo": "hyprgraphics",
"rev": "c6e7b9f673f4360bc813d3dc75028f75ee88d3f8",
"rev": "8699c38f0e4a1ca3bfc84f84ba020509ced1f133",
"type": "github"
},
"original": {
@@ -555,11 +541,11 @@
"xdph": "xdph"
},
"locked": {
"lastModified": 1784738137,
"narHash": "sha256-+6Ei2gg7/ZdjieINcdNx/+BHgF+J59dOG8m65ZR0rnc=",
"lastModified": 1786022009,
"narHash": "sha256-ugTeq1o6wUVlIgIgTqLhGy4/85R7jFerbb2qMij4ZQA=",
"owner": "hyprwm",
"repo": "Hyprland",
"rev": "7d2ea270704c265dd100a7898e6186e49c6741a7",
"rev": "7d4a3c5768d5a04c7b62e63265c82a3659529fd7",
"type": "github"
},
"original": {
@@ -601,11 +587,11 @@
]
},
"locked": {
"lastModified": 1784196523,
"narHash": "sha256-ahtKMGXFJdlQNhatQm1+BBU/pGfGYnAqQt3vWvq4p8s=",
"lastModified": 1784533903,
"narHash": "sha256-Ee78BRFi+MrmgHmmW+2dZUEI1R3cssEzza0ar3fsNX8=",
"owner": "hyprwm",
"repo": "hyprland-guiutils",
"rev": "a6ccb6cb112ed5a244c0191fb972347ecfa893e0",
"rev": "a16ad89ed5fb4192c966018a80c652de8d96f748",
"type": "github"
},
"original": {
@@ -732,11 +718,11 @@
]
},
"locked": {
"lastModified": 1784323413,
"narHash": "sha256-XnAVV+H4f8Xdv0yZcSwJ5kCjLyE8fHxPeLX6a3HSrAU=",
"lastModified": 1785843795,
"narHash": "sha256-DFc543bQN94Kt+RsD3Hiu7qCA1uKdqaFJKPMjzANKGU=",
"owner": "hyprwm",
"repo": "hyprutils",
"rev": "5f03477ab3a005ff27c527486f551883535aea2f",
"rev": "5a7b8cf221914ce4714407950e4ffbdddcd8b66f",
"type": "github"
},
"original": {
@@ -786,11 +772,11 @@
]
},
"locked": {
"lastModified": 1778410714,
"narHash": "sha256-o6RzFj4nJXaPRY7EM01siuCQeT41RfwwmcmFQqwFJJg=",
"lastModified": 1784465130,
"narHash": "sha256-ak5fWEmWZyax8trkV4aphdvjrbUiSyl6qS+y5GwBS7Y=",
"owner": "hyprwm",
"repo": "hyprwire",
"rev": "85148a8e612808cf5ddb25d0b3c5840f3498a7dc",
"rev": "7d935bb54674aa0fbd327d2a6888bd0630079ed0",
"type": "github"
},
"original": {
@@ -900,11 +886,11 @@
"scenefx": "scenefx"
},
"locked": {
"lastModified": 1784771949,
"narHash": "sha256-ZsdV6ObmQtTupYJFKoyF/P0IL80mpLWwGHktWpi83iw=",
"lastModified": 1786023192,
"narHash": "sha256-DNDGxZdMcBPgAva8hPMIElMXeuzAji/U52zhrcDpK24=",
"owner": "DreamMaoMao",
"repo": "mango",
"rev": "3a159f4bf8b479fa5626f37a30eba5335e699f53",
"rev": "c33047edbe2abeb80667332651d73990188a54ac",
"type": "github"
},
"original": {
@@ -915,17 +901,17 @@
},
"nixcord": {
"inputs": {
"flake-compat": "flake-compat_5",
"flake-parts": "flake-parts_3",
"nixpkgs": "nixpkgs_7",
"nixpkgs-nixcord": "nixpkgs-nixcord"
"nixpkgs-nixcord": "nixpkgs-nixcord",
"treefmt-nix": "treefmt-nix"
},
"locked": {
"lastModified": 1784802409,
"narHash": "sha256-IkbeXL5pTJHW0pQbp0bjaa+DeRPsKMofB2cFf7G1qw0=",
"lastModified": 1786029571,
"narHash": "sha256-UJG9waq3IdLqPrmhzQ72Upo8JpnW8dtFDdtgDPC6vMo=",
"owner": "kaylorben",
"repo": "nixcord",
"rev": "8f18918faa85bf53656a3e9d5ef068e8ec6dc9e5",
"rev": "557f4da81118590c0e3723ab6fc2ced88b3e9273",
"type": "github"
},
"original": {
@@ -939,11 +925,11 @@
"nixpkgs": "nixpkgs_8"
},
"locked": {
"lastModified": 1784723954,
"narHash": "sha256-1CfD8ZUjCkTgjsneLZ/lxCHhgDfqxxE7/GX0MmsgiqA=",
"lastModified": 1785232496,
"narHash": "sha256-65EQYIRRpTdpH8lUiB6Mvo5uBkG60aBIzAJuALfx+O0=",
"owner": "NixOS",
"repo": "nixos-hardware",
"rev": "a017f5b72210026af5b3ac5949f08d94380a6fbd",
"rev": "2e790b0a6be8ec2b76174ac0931b8ff11919ec98",
"type": "github"
},
"original": {
@@ -1001,11 +987,11 @@
},
"nixpkgs-nixcord": {
"locked": {
"lastModified": 1784432872,
"narHash": "sha256-n3gKTBIV4ZA5VQpUakffBe3KGu4+mhPoA34rrqS0GkA=",
"lastModified": 1785386831,
"narHash": "sha256-sPS3CaXH8RAT3FZRuy4VcV47iuYIWMMfa0GbyJKC3o4=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "fd1462031fdee08f65fd0b4c6b64e22239a77870",
"rev": "21ea275a7c46aef9d4d6ddc962e6d562e9d94183",
"type": "github"
},
"original": {
@@ -1033,11 +1019,11 @@
},
"nixpkgs_10": {
"locked": {
"lastModified": 1784497964,
"narHash": "sha256-vlHUuqAcbcH2RKmHbPiuQzbv1pnzzavXnI62RD0bqCU=",
"lastModified": 1785967620,
"narHash": "sha256-IItrdb7Puk05RqOBWZYFC5X6Wl1sJmCfh5MWVHw5iMM=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "241313f4e8e508cb9b13278c2b0fa25b9ca27163",
"rev": "b7c2ada94fe99c15b0dbcf4d11fd7850b957a436",
"type": "github"
},
"original": {
@@ -1097,11 +1083,11 @@
},
"nixpkgs_3": {
"locked": {
"lastModified": 1784356753,
"narHash": "sha256-12KrbMiWLcf8m7pCvAtZh1ZrgF85ZXDXvfR/fWTKy84=",
"lastModified": 1785828668,
"narHash": "sha256-8fsyqeO+mJqvIzeO4xIpgJe/f7MTbbVTEC6RT6WSXNs=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "61b7c44c4073f0b827768aff0049561b5110ea5a",
"rev": "e72e4f299401a3689d4b3d5fc6496b11db7064eb",
"type": "github"
},
"original": {
@@ -1161,11 +1147,11 @@
},
"nixpkgs_7": {
"locked": {
"lastModified": 1784432872,
"narHash": "sha256-n3gKTBIV4ZA5VQpUakffBe3KGu4+mhPoA34rrqS0GkA=",
"lastModified": 1785386831,
"narHash": "sha256-sPS3CaXH8RAT3FZRuy4VcV47iuYIWMMfa0GbyJKC3o4=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "fd1462031fdee08f65fd0b4c6b64e22239a77870",
"rev": "21ea275a7c46aef9d4d6ddc962e6d562e9d94183",
"type": "github"
},
"original": {
@@ -1190,11 +1176,11 @@
},
"nixpkgs_9": {
"locked": {
"lastModified": 1784497964,
"narHash": "sha256-vlHUuqAcbcH2RKmHbPiuQzbv1pnzzavXnI62RD0bqCU=",
"lastModified": 1785967620,
"narHash": "sha256-IItrdb7Puk05RqOBWZYFC5X6Wl1sJmCfh5MWVHw5iMM=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "241313f4e8e508cb9b13278c2b0fa25b9ca27163",
"rev": "b7c2ada94fe99c15b0dbcf4d11fd7850b957a436",
"type": "github"
},
"original": {
@@ -1210,11 +1196,11 @@
"nixpkgs": "nixpkgs_10"
},
"locked": {
"lastModified": 1784812182,
"narHash": "sha256-EoQD/QSJspwQtOxPFbPccUCghTWAA3pof8elGaxOvOo=",
"lastModified": 1786032888,
"narHash": "sha256-6hYYaIo4ODwadrtYLvDKX1ehezDAUJwLuH2g5OkkWt4=",
"owner": "nix-community",
"repo": "nur",
"rev": "acde88ba322d6ba922e5f6bae1dfecce703f31eb",
"rev": "366ac747ddcbc2f9243cf0f39ebf33c37c355cba",
"type": "github"
},
"original": {
@@ -1290,7 +1276,7 @@
"sops-nix": "sops-nix",
"tnvim": "tnvim",
"tpanel": "tpanel",
"treefmt-nix": "treefmt-nix",
"treefmt-nix": "treefmt-nix_2",
"vicinae-extensions": "vicinae-extensions",
"wezterm-flake": "wezterm-flake"
}
@@ -1537,15 +1523,36 @@
}
},
"treefmt-nix": {
"inputs": {
"nixpkgs": [
"nixcord",
"nixpkgs"
]
},
"locked": {
"lastModified": 1785360170,
"narHash": "sha256-XE1lKgQ3eIO3E7zWryqcRsax+mYXod/5RHBn4YaR9YE=",
"owner": "numtide",
"repo": "treefmt-nix",
"rev": "d1187f8bc71fb8aab02395869ec3f5c1920f75c0",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "treefmt-nix",
"type": "github"
}
},
"treefmt-nix_2": {
"inputs": {
"nixpkgs": "nixpkgs_12"
},
"locked": {
"lastModified": 1784369104,
"narHash": "sha256-47cxbcZODibHv3rELFQ9vZly0vUNkND/atn/U7HLeb0=",
"lastModified": 1785945821,
"narHash": "sha256-NLSyTCW4K4ofhNBllt3omPasm6QpralXH1DBZOc91Dw=",
"owner": "numtide",
"repo": "treefmt-nix",
"rev": "df3c0640565d04a0261253cdd89fce78ec50168a",
"rev": "ae7910970dddc408fe6ab1c8e4b277bb21d72dc0",
"type": "github"
},
"original": {
@@ -1599,7 +1606,7 @@
},
"vicinae-extensions": {
"inputs": {
"flake-compat": "flake-compat_6",
"flake-compat": "flake-compat_5",
"nixpkgs": [
"nixpkgs"
],
@@ -1607,11 +1614,11 @@
"vicinae": "vicinae"
},
"locked": {
"lastModified": 1784504910,
"narHash": "sha256-fzPBEJZiRvc/FNMdpbdcfaZzF01U4IQenHW9IQFzhos=",
"lastModified": 1785867893,
"narHash": "sha256-uspI0fHn4BsbJcZ2Fv0wmoq+MErfT5xIFSrn+iuBKe0=",
"owner": "vicinaehq",
"repo": "extensions",
"rev": "ca74eede9a778a9373c8f5fd221b0a5026dcd1ef",
"rev": "22bc47b8ad1907a8aaeec502696a8202fac64a00",
"type": "github"
},
"original": {
@@ -1634,11 +1641,11 @@
},
"locked": {
"dir": "nix",
"lastModified": 1784224552,
"narHash": "sha256-+u0IHNwYJPb26F8WzMgNvLfZBDsR/sc13H5tOaXiEjA=",
"lastModified": 1785919232,
"narHash": "sha256-Mqg8BmN7GDL8tK+sRQqvpOAXsbLL6Jbr895zznBp5RU=",
"owner": "wez",
"repo": "wezterm",
"rev": "76b606ec597a3c0263fa60321548637451c0a547",
"rev": "4b1c3c151eb530e569f867e1461693c56fe89695",
"type": "github"
},
"original": {
@@ -1677,11 +1684,11 @@
]
},
"locked": {
"lastModified": 1784371182,
"narHash": "sha256-S8A1lezEalltWcCp3gAic5lssS0xTSISK6fKODefhOk=",
"lastModified": 1785846792,
"narHash": "sha256-sNIGmqZJiOM/lCWUuslV53zuk/p5sGCRcS3kHKfxQvA=",
"owner": "hyprwm",
"repo": "xdg-desktop-portal-hyprland",
"rev": "08d99f727944dd15e4740090305e31c5fb92a50a",
"rev": "b653ab53a435e92cc00f34771e6823bc59f2f740",
"type": "github"
},
"original": {

View File

@@ -11,22 +11,22 @@
qt = {
enable = true;
style = {
name = "Breeze";
package = pkgs.kdePackages.breeze;
};
style.name = "adwaita-dark";
};
gtk = {
enable = true;
theme = {
name = "Materia-dark";
package = pkgs.materia-theme;
name = "adw-gtk3-dark";
package = pkgs.adw-gtk3;
};
iconTheme = {
package = pkgs.tela-icon-theme;
name = "Tela-black";
};
};
# Make GTK4/libadwaita apps prefer dark too (they ignore gtk.theme).
dconf.settings."org/gnome/desktop/interface".color-scheme = "prefer-dark";
};
}

View File

@@ -87,81 +87,68 @@
title = "AI Generated Commit Messages";
key = "CommitMsg";
command = ''
bash -c "
# Check for staged changes
diff=\$(git diff --cached | head -n 10)
if [ -z \"\$diff\" ]; then
echo \"No changes in staging. Add changes first.\"
bash -lc '
diff=$(git diff --cached)
if [ -z "$diff" ]; then
echo "No changes in staging. Add changes first."
exit 1
fi
SELECTED_TYPE=\"{{.Form.Type}}\"
COMMITS_TO_SUGGEST=8
SELECTED_TYPE="{{.Form.Type}}"
COMMITS_TO_SUGGEST=4
opencode run -m \"google/gemini-2.5-flash-lite\" \"
You are an expert at writing Git commits. Your job is to write commit messages that follow the Conventional Commits format.
opencode run --format json --model=google/gemini-3.5-flash-lite --variant=none "
You are an expert at writing Git commits. Your job is to write commit messages that follow the Conventional Commits format.
The user has selected: \$SELECTED_TYPE
The user has selected: $SELECTED_TYPE
Your task is to:
1. Analyze the code changes
2. Determine the most appropriate commit type (if user selected 'ai-defined')
3. Determine an appropriate scope (component/area affected)
4. Decide if this is a breaking change
5. Write clear, concise commit messages
Your task is to:
1. Analyze the code changes
2. Determine the most appropriate commit type if user selected ai-defined
3. Determine an appropriate scope, component, or area affected
4. Decide if this is a breaking change
5. Write clear, concise commit messages
Available commit types:
- feat: A new feature
- fix: A bug fix
- docs: Documentation only changes
- style: Changes that do not affect the meaning of the code
- refactor: A code change that neither fixes a bug nor adds a feature
- perf: A code change that improves performance
- test: Adding missing tests or correcting existing tests
- build: Changes that affect the build system or external dependencies
- ci: Changes to CI configuration files and scripts
- chore: Other changes that don't modify src or test files
- revert: Reverts a previous commit
Available commit types:
- feat: A new feature
- fix: A bug fix
- docs: Documentation only changes
- style: Changes that do not affect the meaning of the code
- refactor: A code change that neither fixes a bug nor adds a feature
- perf: A code change that improves performance
- test: Adding missing tests or correcting existing tests
- build: Changes that affect the build system or external dependencies
- ci: Changes to CI configuration files and scripts
- chore: Other changes that do not modify src or test files
- revert: Reverts a previous commit
Follow these guidelines:
- Structure: <type>(<scope>): <description>
- If user selected 'ai-defined', analyze the changes and pick the most suitable type
- If user selected a specific type, use that type: \$SELECTED_TYPE
- Add scope in parentheses if applicable (e.g., auth, api, ui, config)
- Use exclamation mark (!) after type/scope for breaking changes: type(scope)!: description
- Use lowercase for description (except proper nouns)
- Use imperative mood (\\\"add\\\", not \\\"added\\\")
- Keep description under 50 characters when possible
- No period at the end of subject line
Follow these guidelines:
- Structure: <type>(<scope>): <description>
- If user selected ai-defined, analyze the changes and pick the most suitable type
- If user selected a specific type, use that type: $SELECTED_TYPE
- Add scope in parentheses if applicable, for example auth, api, ui, config
- Use exclamation mark after type or scope for breaking changes: type(scope)!: description
- Use lowercase for description except proper nouns
- Use imperative mood: add, not added
- Keep description under 50 characters when possible
- No period at the end of subject line
Examples:
- feat(auth): add OAuth login support
- fix(api): handle null response in user endpoint
- docs(readme): update installation instructions
- style(ui): improve button spacing consistency
- refactor(database): simplify query builder logic
- test(auth): add unit tests for login flow
- build(deps): upgrade React to version 18
- ci(github): fix deployment workflow
- chore(config): update ESLint rules
- perf(api)!: optimize database queries
IMPORTANT:
- Generate exactly $COMMITS_TO_SUGGEST different commit message options
- If user selected ai-defined, you can use different types for different options
- If user selected a specific type, all messages must use that type
- Only return commit messages, no explanations
- Do not use markdown code blocks
- One message per line
IMPORTANT:
- Generate exactly \$COMMITS_TO_SUGGEST different commit message options
- If user selected 'ai-defined', you can use different types for different options
- If user selected a specific type, all messages must use that type
- Only return commit messages, no explanations
- Do not use markdown code blocks
- One message per line
Previous commits for context:
$(git log --oneline -10)
Previous commits for context:
\$(git log --oneline -10)
Changes to analyze:
\$(git diff --cached --stat)
\$(git diff --cached)
\"
"
Changes to analyze:
$(git diff --cached --stat)
$diff
" | JQ_TEXT=text jq -r "select(.type == env.JQ_TEXT) | .part.text? // empty"
'
'';
}
];

View File

@@ -47,14 +47,15 @@
mediaflow-proxy = {
enable = true;
port = 8888;
environment = {
APP__SERVER__HOST = "0.0.0.0";
APP__SERVER__PORT = "8888";
};
domain = "mf-proxy.lab.tux.rs";
environmentFile = innerArgs.config.sops.secrets."mediaflow-proxy".path;
};
vaultwarden = {
enable = true;
port = 9999;
domain = "bw.lab.tux.rs";
};
};
virtualisation = {

View File

@@ -8,14 +8,29 @@
with lib;
let
cfg = config.tnix.services.aiostreams;
port = toString cfg.port;
acmeHost = config.tnix.services.nginx.domain;
in
{
options.tnix.services.aiostreams = {
enable = mkEnableOption "Enable AIOStreams";
enable = mkEnableOption "AIOStreams";
port = mkOption {
type = types.int;
type = types.port;
default = 3000;
description = "Port on which AIOStreams listens";
};
domain = mkOption {
type = types.str;
default = "";
description = "Domain on which nginx serves AIOStreams (disabled when empty)";
};
image = mkOption {
type = types.str;
default = "ghcr.io/viren070/aiostreams:latest";
description = "Container image to use";
};
dataDir = mkOption {
@@ -24,41 +39,34 @@
description = "Directory to store persistent AIOStreams data";
};
environment = mkOption {
type = with types; attrsOf str;
default = { };
};
environmentFile = mkOption {
type = with types; path;
default = "";
type = types.nullOr types.path;
default = null;
description = "Environment file with secrets passed to the container";
};
};
config = mkIf cfg.enable {
virtualisation.oci-containers.containers.aiostreams = {
autoStart = true;
image = "ghcr.io/viren070/aiostreams:latest";
image = cfg.image;
ports = [
"${toString cfg.port}:3000"
"127.0.0.1:${port}:3000"
];
environment = cfg.environment;
environmentFiles = [ cfg.environmentFile ];
environment = {
ADDON_ID = cfg.domain;
BASE_URL = "https://${cfg.domain}";
};
environmentFiles = optional (cfg.environmentFile != null) cfg.environmentFile;
volumes = [
"${cfg.dataDir}:/app/data"
];
};
services.nginx.virtualHosts = {
"${cfg.environment.ADDON_ID}" = {
forceSSL = true;
useACMEHost = "lab.tux.rs";
locations = {
"/" = {
proxyPass = "http://localhost:${toString cfg.port}";
};
};
services.nginx.virtualHosts.${cfg.domain} = mkIf (cfg.domain != "") {
forceSSL = acmeHost != "";
useACMEHost = mkIf (acmeHost != "") acmeHost;
locations."/" = {
proxyPass = "http://127.0.0.1:${port}";
};
};
};

View File

@@ -29,7 +29,7 @@
dataDir = mkOption {
type = types.path;
default = "/var/lib/cyber-tux";
description = "Directory where CyberTux stores its data.";
description = "Directory where CyberTux stores its data (must be under /var/lib).";
};
environmentFile = mkOption {
@@ -41,7 +41,8 @@
config = mkIf cfg.enable {
systemd.services.cyber-tux = {
description = "CyberTux Discord bot";
after = [ "network.target" ];
after = [ "network-online.target" ];
wants = [ "network-online.target" ];
wantedBy = [ "multi-user.target" ];
serviceConfig = {

View File

@@ -8,48 +8,57 @@
with lib;
let
cfg = config.tnix.services.mediaflow-proxy;
port = toString cfg.port;
acmeHost = config.tnix.services.nginx.domain;
in
{
options.tnix.services.mediaflow-proxy = {
enable = mkEnableOption "Enable MediaFlow Proxy";
enable = mkEnableOption "MediaFlow Proxy";
port = mkOption {
type = types.int;
type = types.port;
default = 8888;
description = "Port on which MediaFlow Proxy listens";
};
environment = mkOption {
type = with types; attrsOf str;
default = { };
domain = mkOption {
type = types.str;
default = "";
description = "Domain on which nginx serves MediaFlow Proxy (disabled when empty)";
};
image = mkOption {
type = types.str;
default = "ghcr.io/mhdzumair/mediaflow-proxy-light:latest";
description = "Container image to use";
};
environmentFile = mkOption {
type = with types; path;
default = "";
type = types.nullOr types.path;
default = null;
description = "Environment file with secrets passed to the container";
};
};
config = mkIf cfg.enable {
virtualisation.oci-containers.containers.mediaflow-proxy = {
autoStart = true;
image = "ghcr.io/mhdzumair/mediaflow-proxy-light:latest";
image = cfg.image;
ports = [
"${toString cfg.port}:8888"
"${port}:${port}"
];
environment = cfg.environment;
environmentFiles = [ cfg.environmentFile ];
environment = {
APP__SERVER__HOST = "0.0.0.0";
APP__SERVER__PORT = port;
};
environmentFiles = optional (cfg.environmentFile != null) cfg.environmentFile;
};
services.nginx.virtualHosts = {
"mf-proxy.lab.tux.rs" = {
forceSSL = true;
useACMEHost = "lab.tux.rs";
locations = {
"/" = {
proxyPass = "http://localhost:${toString cfg.port}";
};
};
services.nginx.virtualHosts.${cfg.domain} = mkIf (cfg.domain != "") {
forceSSL = acmeHost != "";
useACMEHost = mkIf (acmeHost != "") acmeHost;
locations."/" = {
proxyPass = "http://127.0.0.1:${port}";
proxyWebsockets = true;
};
};
};

View File

@@ -12,11 +12,12 @@
in
{
options.tnix.services.nginx = {
enable = mkEnableOption "Enable Nginx";
enable = mkEnableOption "Nginx";
domain = mkOption {
type = types.str;
default = "";
description = "Base domain for the wildcard ACME certificate (disabled when empty)";
};
};
@@ -24,8 +25,8 @@
security = {
acme = {
acceptTerms = true;
defaults.email = "${userEmail}";
certs = {
defaults.email = userEmail;
certs = mkIf (cfg.domain != "") {
"${cfg.domain}" = {
group = "nginx";
domain = "*.${cfg.domain}";

View File

@@ -0,0 +1,70 @@
{
flake.modules.nixos.services =
{
config,
lib,
...
}:
with lib;
let
cfg = config.tnix.services.vaultwarden;
port = toString cfg.port;
acmeHost = config.tnix.services.nginx.domain;
in
{
options.tnix.services.vaultwarden = {
enable = mkEnableOption "Vaultwarden";
port = mkOption {
type = types.port;
default = 8000;
description = "Port on which Vaultwarden listens";
};
domain = mkOption {
type = types.str;
default = "";
description = "Domain on which nginx serves Vaultwarden (disabled when empty)";
};
};
config = mkIf cfg.enable {
services = {
vaultwarden = {
enable = true;
dbBackend = "postgresql";
config = {
ROCKET_ADDRESS = "127.0.0.1";
ROCKET_PORT = cfg.port;
DOMAIN = "https://${cfg.domain}";
DATABASE_URL = "postgresql:///vaultwarden?host=/run/postgresql";
ENABLE_WEBSOCKET = true;
SIGNUPS_ALLOWED = true;
DISABLE_ICON_DOWNLOAD = true;
};
};
nginx.virtualHosts.${cfg.domain} = mkIf (cfg.domain != "") {
forceSSL = acmeHost != "";
useACMEHost = mkIf (acmeHost != "") acmeHost;
locations."/" = {
proxyPass = "http://127.0.0.1:${port}";
proxyWebsockets = true;
};
};
postgresql = {
enable = true;
ensureDatabases = [ "vaultwarden" ];
ensureUsers = [
{
name = "vaultwarden";
ensureDBOwnership = true;
}
];
};
};
};
};
}