From 95ddd2d8e95ff1da6740c6daae400cfc1c0c3255 Mon Sep 17 00:00:00 2001 From: Sin Ser'hao Date: Fri, 11 Sep 2026 14:43:20 +0200 Subject: [PATCH] stable somewhat --- flake.lock | 129 ++++++++++----------- hosts/sin/actual.nix | 24 +++- hosts/sin/configuration.nix | 22 +++- hosts/sin/jellyfin.nix | 19 +-- hosts/sin/luks-btrfs-raid.nix | 4 +- hosts/sin/secrets.nix | 7 +- hosts/sin/secrets/actual-client_secret.age | 12 ++ hosts/sin/secrets/airvpn-params.age | 15 +++ hosts/sin/transmission.nix | 42 ++++--- hosts/sin/trilium.nix | 7 +- hosts/thea/authelia.nix | 21 ++++ hosts/thea/configuration.nix | 45 +++++++ hosts/thea/jellyfin.nix | 81 +++++++++++++ hosts/thea/nginx.nix | 67 ++++++++--- 14 files changed, 380 insertions(+), 115 deletions(-) create mode 100644 hosts/sin/secrets/actual-client_secret.age create mode 100644 hosts/sin/secrets/airvpn-params.age create mode 100644 hosts/thea/jellyfin.nix diff --git a/flake.lock b/flake.lock index 03b20b1..71eece9 100644 --- a/flake.lock +++ b/flake.lock @@ -46,11 +46,11 @@ "stable": "stable" }, "locked": { - "lastModified": 1762034856, - "narHash": "sha256-QVey3iP3UEoiFVXgypyjTvCrsIlA4ecx6Acaz5C8/PQ=", + "lastModified": 1786742289, + "narHash": "sha256-r61K9svFDQkI5jONYksneDtDT5c4SkWrZVD3ni5O6Ak=", "owner": "zhaofengli", "repo": "colmena", - "rev": "349b035a5027f23d88eeb3bc41085d7ee29f18ed", + "rev": "dc22786a43315b212eeafe13409a7203328e5a30", "type": "github" }, "original": { @@ -65,11 +65,11 @@ "nixpkgs": "nixpkgs_3" }, "locked": { - "lastModified": 1779822991, - "narHash": "sha256-r6e4eHEyQJEDhT6gkW3B9+OgB0pZebw2+du4bvN3vww=", + "lastModified": 1788296568, + "narHash": "sha256-k0oAChIZU2ycgJQX6fup9ncSvvOU1K93ZcDZYGiBhuA=", "owner": "9001", "repo": "copyparty", - "rev": "6e75faa62349a59f4df328a4939ba8626d89ee1a", + "rev": "4e318d516531e6a9c683b21e58b9cb48131eb175", "type": "github" }, "original": { @@ -107,11 +107,11 @@ ] }, "locked": { - "lastModified": 1780290312, - "narHash": "sha256-eTAlX0CwgB84Ts3GaBd944A3DRXVMzgA0EqroZBISUo=", + "lastModified": 1781152676, + "narHash": "sha256-RxWs5ND31KzTG7wvMM+PMfUjyNpmIEr999lqNARaM5o=", "owner": "nix-community", "repo": "disko", - "rev": "115e5211780054d8a890b41f0b7734cafad54dfe", + "rev": "ff8702b4de27f72b4c78573dfb89ec74e36abdf1", "type": "github" }, "original": { @@ -123,11 +123,11 @@ "flake-compat": { "flake": false, "locked": { - "lastModified": 1650374568, - "narHash": "sha256-Z+s0J8/r907g149rllvwhb4pKi8Wam5ij0st8PwAh+E=", + "lastModified": 1767039857, + "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=", "owner": "edolstra", "repo": "flake-compat", - "rev": "b4a34015c698c7793d592d66adbab377907a2be8", + "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab", "type": "github" }, "original": { @@ -169,12 +169,15 @@ } }, "flake-utils": { + "inputs": { + "systems": "systems_2" + }, "locked": { - "lastModified": 1659877975, - "narHash": "sha256-zllb8aq3YO3h8B/U0/J1WBgAL8EX5yWf5pMj3G0NAmc=", + "lastModified": 1731533236, + "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=", "owner": "numtide", "repo": "flake-utils", - "rev": "c0e246b9b83f637f4681389ecabcb2681b4f3af0", + "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", "type": "github" }, "original": { @@ -204,18 +207,17 @@ "simple-mailserver", "flake-compat" ], - "gitignore": "gitignore", "nixpkgs": [ "simple-mailserver", "nixpkgs" ] }, "locked": { - "lastModified": 1778507602, - "narHash": "sha256-kTwur1wV+01SdqskVMSo6JMEpg71ps3HpbFY2GsflKs=", + "lastModified": 1787424939, + "narHash": "sha256-O2tBn84NNuHrnqNVxx/XqsXwfYvS1YwBh+7CBnbCYsk=", "owner": "cachix", "repo": "git-hooks.nix", - "rev": "61ab0e80d9c7ab14c256b5b453d8b3fb0189ba0a", + "rev": "809414f0cdadf82cf11b06c2b29ba9b3168b3297", "type": "github" }, "original": { @@ -224,28 +226,6 @@ "type": "github" } }, - "gitignore": { - "inputs": { - "nixpkgs": [ - "simple-mailserver", - "git-hooks", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1709087332, - "narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=", - "owner": "hercules-ci", - "repo": "gitignore.nix", - "rev": "637db329424fd7e46cf4185293b9cc8c88c95394", - "type": "github" - }, - "original": { - "owner": "hercules-ci", - "repo": "gitignore.nix", - "type": "github" - } - }, "home-manager": { "inputs": { "nixpkgs": [ @@ -275,11 +255,11 @@ ] }, "locked": { - "lastModified": 1729742964, - "narHash": "sha256-B4mzTcQ0FZHdpeWcpDYPERtyjJd/NIuaQ9+BV1h+MpA=", + "lastModified": 1737420293, + "narHash": "sha256-F1G5ifvqTpJq7fdkT34e/Jy9VCyzd5XfJ9TO8fHhJWE=", "owner": "nix-community", "repo": "nix-github-actions", - "rev": "e04df33f62cdcf93d73e9a04142464753a16db67", + "rev": "f4158fa080ef4503c8f4c820967d946c2af31ec9", "type": "github" }, "original": { @@ -292,14 +272,14 @@ "inputs": { "flake-compat": "flake-compat_2", "nixpkgs": "nixpkgs_4", - "systems": "systems_2" + "systems": "systems_3" }, "locked": { - "lastModified": 1780375694, - "narHash": "sha256-TznzgYVONg28KiSFB2rVdf/eLVIMtEQOxKt13Kzyrp8=", + "lastModified": 1788494954, + "narHash": "sha256-SRWINWPWk2ezK387AxdliOQ+h3T93EGUIV6Fm4WVFd0=", "owner": "Infinidoge", "repo": "nix-minecraft", - "rev": "e6f8bec35104ca5955efe73742da58d2823684f7", + "rev": "62e95390de025f9bd99220b9e2059d429bb94125", "type": "github" }, "original": { @@ -342,11 +322,11 @@ }, "nixpkgs_2": { "locked": { - "lastModified": 1750134718, - "narHash": "sha256-v263g4GbxXv87hMXMCpjkIxd/viIF7p3JpJrwgKdNiI=", + "lastModified": 1783224372, + "narHash": "sha256-8i/87eeoqiGE4yOTjwSA3Eh/ziJRQEmd/unYU+K27sk=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "9e83b64f727c88a7711a2c463a7b16eedb69a84c", + "rev": "d407951447dcd00442e97087bf374aad70c04cea", "type": "github" }, "original": { @@ -389,11 +369,11 @@ }, "nixpkgs_5": { "locked": { - "lastModified": 1780203844, - "narHash": "sha256-K5sT4jTpGs15ADhviMKNBH38REpPf5Q6mM1+N6cArVE=", + "lastModified": 1788405554, + "narHash": "sha256-r2f1oUwixlgq9zOdYLqJLfS/lWBT60/IITjhTKI59JU=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "b51242d7d43689db2f3be91bd05d5b24fbb469c4", + "rev": "a5cc6f2c37bf518436dc8d1c288ccd0c43c2f4c4", "type": "github" }, "original": { @@ -419,11 +399,11 @@ }, "nixpkgs_7": { "locked": { - "lastModified": 1779630130, - "narHash": "sha256-RWn/gMXEy+p6yL5lKh51Z/w6RHC+5Px18Tarkuva99Y=", + "lastModified": 1787948808, + "narHash": "sha256-eGTDlxFCHGX/SI9ygF48RWTg5u88ikF0O3KRLA7i3+w=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "68ac0b94b449482d8a90f3e3791d61a8ee186f07", + "rev": "66b643c7d4e3f50124081b60845fd07a8455d263", "type": "github" }, "original": { @@ -490,11 +470,11 @@ "nixpkgs": "nixpkgs_7" }, "locked": { - "lastModified": 1780340963, - "narHash": "sha256-rQCWOQXN0/sQxwP7T2Y3hsC1KYxLQgul6l9LPbQdqi4=", + "lastModified": 1787963050, + "narHash": "sha256-yt4H/X9CU2iaLl2NJ/MBycQs7Jl0tbJP5uuDdGWiPGg=", "owner": "simple-nixos-mailserver", "repo": "nixos-mailserver", - "rev": "a61228e6918a9d673c3faf48ab23e92a55822012", + "rev": "27b3c74d96351b770ec8216430d5d947290917e9", "type": "gitlab" }, "original": { @@ -505,16 +485,16 @@ }, "stable": { "locked": { - "lastModified": 1750133334, - "narHash": "sha256-urV51uWH7fVnhIvsZIELIYalMYsyr2FCalvlRTzqWRw=", + "lastModified": 1783625654, + "narHash": "sha256-pI1244/PJfTyKhlAr2QYQC55vR6UQdnGA0rJUgtO2IQ=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "36ab78dab7da2e4e27911007033713bab534187b", + "rev": "a0230bd8d5cbd13893b2263918d396a2c7dd0407", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixos-25.05", + "ref": "release-26.05", "repo": "nixpkgs", "type": "github" } @@ -549,6 +529,21 @@ "type": "github" } }, + "systems_3": { + "locked": { + "lastModified": 1681028828, + "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", + "owner": "nix-systems", + "repo": "default", + "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default", + "type": "github" + } + }, "testing-grounds": { "inputs": { "nixpkgs": "nixpkgs_8" @@ -569,11 +564,11 @@ }, "unstable": { "locked": { - "lastModified": 1780651739, - "narHash": "sha256-3VfA5BcsITQmorkCW/6ZF9usmLTkFTAfTj4QT7DG338=", + "lastModified": 1788515940, + "narHash": "sha256-LEIpgfNpod6hxwUpaHPRl+Bo9z2RPgNEcunUCzGIad0=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "e91830af5eb4b2394ddd405998dec32f0ef18a51", + "rev": "1b8415cbb4924944b7db753a2377b6a6561d8aa2", "type": "github" }, "original": { diff --git a/hosts/sin/actual.nix b/hosts/sin/actual.nix index 4ef6e69..3b6b9fb 100644 --- a/hosts/sin/actual.nix +++ b/hosts/sin/actual.nix @@ -1,12 +1,32 @@ -{ inputs, pkgs, ... }: +{ + inputs, + pkgs, + config, + ... +}: let unstable = import inputs.unstable { system = pkgs.stdenv.system; }; in { + users.users.actual = { + isSystemUser = true; + group = config.users.groups.actual.name; + }; + users.groups.actual = { }; services.actual = { package = unstable.actual-server; enable = true; openFirewall = true; - settings.port = 3001; + user = config.users.users.actual.name; + settings = { + port = 3001; + openId = { + discoveryURL = "https://auth.shobu.fr"; + client_id = "actual-budget"; + client_secret._secret = config.age.secrets.actual-client_secret.path; + server_hostname = "https://actual.shobu.fr"; + authMethod = "oauth2"; + }; + }; }; } diff --git a/hosts/sin/configuration.nix b/hosts/sin/configuration.nix index e1a4568..ec2457a 100644 --- a/hosts/sin/configuration.nix +++ b/hosts/sin/configuration.nix @@ -32,9 +32,25 @@ networking = { hostName = "sin"; - networkmanager.enable = true; + networkmanager = { + enable = true; + settings = { + main = { + dns = "default"; + }; - # nameservers = [ "10.0.0.4" ]; + connection = { + "ipv4.ignore-auto-dns" = true; + "ipv6.ignore-auto-dns" = true; + }; + }; + }; + + nameservers = [ + "9.9.9.9" + "149.112.112.112" + "8.8.8.8" + ]; # dhcpcd.extraConfig = "nohook resolv.conf"; @@ -48,6 +64,8 @@ config.services.trilium-server.port 53 + + 5690 # testing for wizarr ]; allowedUDPPorts = [ 53 ]; diff --git a/hosts/sin/jellyfin.nix b/hosts/sin/jellyfin.nix index 58ca94f..4dd1827 100644 --- a/hosts/sin/jellyfin.nix +++ b/hosts/sin/jellyfin.nix @@ -44,51 +44,44 @@ in users.users."starr" = { isSystemUser = true; group = "starr"; - extraGroups = [ "jellyfin" ]; }; users.users.sonarr.extraGroups = [ - "jellyfin" "radarr" "transmission" "starr" ]; users.users.radarr.extraGroups = [ - "jellyfin" "sonarr" "transmission" "starr" ]; users.users.bazarr.extraGroups = [ - "jellyfin" "sonarr" "transmission" "starr" "radarr" ]; users.users.lidarr.extraGroups = [ - "jellyfin" "starr" "transmission" ]; users.users.whisparr.extraGroups = [ - "jellyfin" "starr" "transmission" ]; users.users.shobu.extraGroups = [ - "jellyfin" "starr" "transmission" "radarr" "sonarr" ]; - users.users.jellyfin.extraGroups = [ - "render" - "video" - ]; + # users.users.jellyfin.extraGroups = [ + # "render" + # "video" + # ]; users.groups = { starr = { @@ -107,7 +100,7 @@ in in { jellyfin = { - enable = true; + enable = false; openFirewall = true; }; @@ -154,7 +147,7 @@ in ]; }; - jellyseerr = { + seerr = { enable = true; openFirewall = true; }; diff --git a/hosts/sin/luks-btrfs-raid.nix b/hosts/sin/luks-btrfs-raid.nix index 2334ba5..e329c53 100644 --- a/hosts/sin/luks-btrfs-raid.nix +++ b/hosts/sin/luks-btrfs-raid.nix @@ -7,7 +7,7 @@ # and the actual btrfs raid on the second disk, and the name of these entries matters! system = { type = "disk"; - device = "/dev/sdb"; + device = "/dev/sda"; content = { type = "gpt"; partitions = { @@ -56,7 +56,7 @@ data = { type = "disk"; - device = "/dev/sda"; + device = "/dev/sdb"; content = { type = "gpt"; partitions = { diff --git a/hosts/sin/secrets.nix b/hosts/sin/secrets.nix index d0c114f..2d0c7f4 100644 --- a/hosts/sin/secrets.nix +++ b/hosts/sin/secrets.nix @@ -7,7 +7,7 @@ # mode = "770"; # }; airvpn-params = { - file = ./secrets/airvpn_wireguard_key_env.age; + file = ./secrets/airvpn-params.age; mode = "700"; }; copyparty-serhao = { @@ -27,5 +27,10 @@ file = ./secrets/authelia-session.age; mode = "700"; }; + actual-client_secret = { + file = ./secrets/actual-client_secret.age; + mode = "700"; + owner = "actual"; + }; }; } diff --git a/hosts/sin/secrets/actual-client_secret.age b/hosts/sin/secrets/actual-client_secret.age new file mode 100644 index 0000000..8a2fc50 --- /dev/null +++ b/hosts/sin/secrets/actual-client_secret.age @@ -0,0 +1,12 @@ +-----BEGIN AGE ENCRYPTED FILE----- +YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNzaC1lZDI1NTE5IC91cWo0QSBuNXRB +ZnhnOFFhdUJZaHhHZVFHSVVRNThMdndDalV0Y3U5czBNSGh3b0U4ClRFWFYxQXpl +VnBhRVo0SHZjVE9weDhlcEdnbElwZnErTUVkTmFiZE1jQWMKLT4gc3NoLWVkMjU1 +MTkgTm9TbDZRIFdDU01HdjlXc1VUL3FuM0FTZS81ZGgveXovVFB2bi85aGpLNWFI +YmhjekUKNjFWSGl1OVJTZDFmOEtCK0l2a25KYWdSRm9hdkxGV1JZYUY5NStoRDhw +bwotPiAmLHJbLWdyZWFzZSBiKiBJIDxpIVNVCkZLQ3Fwc2N0dU9UUFo2QTVEODg2 +RkNBRWdFSmUKLS0tIHU1SUl1amt5Z1NSbVpvcGx5eHZOcmxpb2lnWlg5NENGZXJ1 +MDFveGJONlEK4tVPaUccMrkiQZriMRvYcegvemtcOBIVGAa/hUX7BoLXUas2FVct +gSCJKPBzt0Jyg2Qcj4kBgjqdNBGG0AP4QjTaxg2Vy5B/Ao5jV3v9heSRzucTkxUG +bxB6Bt7tgF6XDDsBcXsFNiS7 +-----END AGE ENCRYPTED FILE----- diff --git a/hosts/sin/secrets/airvpn-params.age b/hosts/sin/secrets/airvpn-params.age new file mode 100644 index 0000000..76e13fb --- /dev/null +++ b/hosts/sin/secrets/airvpn-params.age @@ -0,0 +1,15 @@ +-----BEGIN AGE ENCRYPTED FILE----- +YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNzaC1lZDI1NTE5IC91cWo0QSA3S2dM +RVE2R3liVzdReiszZXZtVUJGbzVRRTY5YUhCY2h6WWNTVUxGRGhVCmYyWGsrMGZG +cEZmeFZyN0dtblI4NHRmUTNhWjlzRThuMEpaR01zUFVGejAKLT4gc3NoLWVkMjU1 +MTkgTm9TbDZRIEVxR1hMWXJxdFNTa1c1WlZrWEs3YkFCZmxRclhxNEd6RnBkU1A0 +U0g2MWMKVUkrV1JVWm5xblRwalY1cWtFODRJcnlRZHJaSkY1R1RyLzZtTWNacDVa +WQotPiA3aUQnMCd9LWdyZWFzZSBtQiBkVW9cIHssXDwuMjo1CngyajZobkxXUnpL +VXozVytpay9GL0JrNUliUVNVckZZbHQ3dnJkY0FJOHJqVHBQMU1lVzV3emhsVWhh +VXZ6VG8Kdmtyak1nCi0tLSA4NnYxNnQ0VDZFZlR0MC9lUmdXYld1QWtMRCtDR05C +TTU0L2pDa2trdmFJCn0WLrNMRqn2jUSTwunUtj82aXfcdsdEGl8EIkqPEpig//gH +urGRbk9vR1UzTcykWAXbqtXMs8tl9pMVSYWD/qLG2qUWNSkLFbGxRphAhgofVZBZ +Fd8lqAa5bXQQXh4kKSBRQEtVXci18E/kxPFKofVxnf3STx0oldbde5pf1dWjBd2H +VkyFjm8vAxJJyEcVRGtb7muQt+PezfSXpdzCsO/Uuiwvd5WXO9EM7xuJjJRWSRUT +VjkfehDjkmy5501zmeFLq8dkB4stSrjkIg8= +-----END AGE ENCRYPTED FILE----- diff --git a/hosts/sin/transmission.nix b/hosts/sin/transmission.nix index 0062133..f904df3 100644 --- a/hosts/sin/transmission.nix +++ b/hosts/sin/transmission.nix @@ -39,21 +39,21 @@ virtualisation.oci-containers = let - peerport = "63369"; + peerport = "44161"; + webport = "44160"; in { backend = "docker"; containers = { gluetun = { - image = "qmcgaw/gluetun"; + image = "qmcgaw/gluetun:latest"; environment = { VPN_SERVICE_PROVIDER = "airvpn"; VPN_TYPE = "wireguard"; - # WIREGUARD_PRIVATE_KEY = "from agenix"; - # WIREGUARD_PRESHARED_KEY = "from agenix"; - # WIREGUARD_ADDRESSES = "from agenix"; - # SERVER_COUNTRIES = "from agenix"; - FIREWALL_VPN_INPUT_PORTS = "13277,${peerport}"; + SERVER_NAMES = "Taiyangshou"; + FIREWALL_VPN_INPUT_PORTS = "${peerport},${webport}"; + + TZ = "Europe/Paris"; }; environmentFiles = [ config.age.secrets.airvpn-params.path @@ -65,31 +65,47 @@ ]; ports = [ "13277:13277" - "9091:13277" + "${webport}:${webport}" "${peerport}:${peerport}" "${peerport}:${peerport}/udp" ]; - }; - transmission = { - image = "docker.io/linuxserver/transmission:latest"; volumes = [ - "/etc/transmission:/config" + "/etc/gluetun:/gluetun" + ]; + }; + qbittorrent = { + image = "lscr.io/linuxserver/qbittorrent:latest"; + volumes = [ "/etc/localtime:/etc/localtime:ro" + "/mnt/mediacenter/torrents:/mnt/mediacenter/torrents" "/mnt/data/transmission_downloads:/mnt/data/transmission_downloads" + + "/mnt/data/downloads:/downloads" + + "/etc/qbittorrent:/config" ]; dependsOn = [ "gluetun" ]; extraOptions = [ "--network=container:gluetun" + # "-u=992:989" + # "-u=${toString config.users.users.transmission.uid}:${toString config.users.groups.starr.gid}" ]; environment = { PUID = toString config.users.users.transmission.uid; PGID = toString config.users.groups.starr.gid; - PEERPORT = peerport; + TZ = "Europe/Paris"; + + WEBUI_PORT = "${webport}"; + TORRENTING_PORT = "${peerport}"; }; }; }; }; + networking.firewall.allowedTCPPorts = [ + 44160 + 13277 + ]; } diff --git a/hosts/sin/trilium.nix b/hosts/sin/trilium.nix index 0af5a0c..24c6ba9 100644 --- a/hosts/sin/trilium.nix +++ b/hosts/sin/trilium.nix @@ -1,7 +1,12 @@ -{ ... }: +{ inputs, pkgs, ... }: +let + unstable = import inputs.unstable { system = pkgs.stdenv.system; }; +in + { services.trilium-server = { enable = true; + package = unstable.trilium-server; port = 12783; host = "0.0.0.0"; # noAuthentication = true; diff --git a/hosts/thea/authelia.nix b/hosts/thea/authelia.nix index 32af57e..8adeac0 100644 --- a/hosts/thea/authelia.nix +++ b/hosts/thea/authelia.nix @@ -134,6 +134,27 @@ in userinfo_signed_response_alg = "none"; token_endpoint_auth_method = "client_secret_basic"; } + { + client_id = "actual-budget"; + client_name = "Actual Budget"; + client_secret = "$pbkdf2-sha512$310000$0mdiwSrzfswVhLmJi0b/YQ$RjAuXY226qSrbpViJ2pitIA1B0a2rvL.5VfxnRwvvXzXlQAezczy5xK7.3X2uBvLgpnTjpxf3zdcvoDJ2ieIHw"; + public = false; + authorization_policy = "two_factor"; + require_pkce = false; + pkce_challenge_method = ""; + redirect_uris = [ "https://actual.shobu.fr/openid/callback" ]; + scopes = [ + "openid" + "profile" + "groups" + "email" + ]; + response_types = [ "code" ]; + grant_types = [ "authorization_code" ]; + access_token_signed_response_alg = "none"; + userinfo_signed_response_alg = "none"; + token_endpoint_auth_method = "client_secret_basic"; + } ]; }; }; diff --git a/hosts/thea/configuration.nix b/hosts/thea/configuration.nix index a01cbd2..e300584 100644 --- a/hosts/thea/configuration.nix +++ b/hosts/thea/configuration.nix @@ -22,6 +22,7 @@ in ./secrets ./authelia.nix ./glances.nix + ./jellyfin.nix ]; # Use the systemd-boot EFI boot loader. @@ -46,6 +47,17 @@ in # minecraft ad hoc server ports 25665 25675 + ] + ++ [ + # rqbit + 63369 + 37751 + ]; + + allowedUDPPorts = [ + # rqbit + 63369 + 37751 ]; }; nat = { @@ -53,6 +65,16 @@ in internalInterfaces = [ "enp1s0" ]; externalInterface = "enp1s0"; forwardPorts = [ + { + sourcePort = 25665; + proto = "tcp"; + destination = "127.0.0.1:25665"; + } + { + sourcePort = 25665; + proto = "udp"; + destination = "127.0.0.1:25665"; + } { # TODO refactor this in the gitea/n100 module sourcePort = nodes.sin.config.services.gitea.settings.server.SSH_PORT; @@ -69,6 +91,16 @@ in proto = "tcp"; destination = "${sin-address}:8086"; } + # { + # sourcePort = 54721; + # proto = "tcp"; + # destination = "${sin-address}:54721"; + # } + # { + # sourcePort = 54721; + # proto = "udp"; + # destination = "${sin-address}:54721"; + # } ]; }; }; @@ -112,6 +144,19 @@ in ports = [ 22 ]; }; + services.openarena = { + enable = true; + openPorts = true; + extraFlags = [ + "+set dedicated 2" + "+set sv_hostname 'Ser\'Hao\'s server'" + "+map oa_dm1" + "+set" + "rconPassword" + "test" + ]; + }; + # Open ports in the firewall. # networking.firewall.allowedTCPPorts = [ ... ]; # networking.firewall.allowedUDPPorts = [ ... ]; diff --git a/hosts/thea/jellyfin.nix b/hosts/thea/jellyfin.nix new file mode 100644 index 0000000..98e2b82 --- /dev/null +++ b/hosts/thea/jellyfin.nix @@ -0,0 +1,81 @@ +{ pkgs, ... }: +let + sin-address = "192.168.1.14"; +in +{ + fileSystems."/mnt/mediacenter" = { + device = "shobu@${sin-address}:/mnt/mediacenter"; + fsType = "sshfs"; + options = [ + "nodev" + "noatime" + "allow_other" + "user=n100" + "IdentityFile=/root/.ssh/id_ed25519" + ]; + }; + + fileSystems."/mnt/jellyfin" = { + device = "/dev/disk/by-uuid/09c733e4-b0df-4416-977b-50d9feb225fc"; + fsType = "btrfs"; + options = [ + "subvol=jellyfin" + "user=jellyfin" + ]; + }; + + systemd.services.jellyfin.environment.LIBVA_DRIVER_NAME = "iHD"; # or i965 for older GPUs + environment.sessionVariables = { + LIBVA_DRIVER_NAME = "iHD"; + }; + + hardware.graphics = { + enable = true; + + extraPackages = with pkgs; [ + intel-ocl + intel-compute-runtime + intel-media-driver + vpl-gpu-rt + ]; + }; + hardware.enableAllFirmware = true; + hardware.enableRedistributableFirmware = true; + boot.kernelParams = [ + "i915.enable_guc=3" + "i915.force_probe=46d1" + ]; + + services = { + jellyfin = rec { + enable = true; + dataDir = "/mnt/jellyfin"; + configDir = "${dataDir}/config"; + openFirewall = true; + hardwareAcceleration = { + enable = true; + type = "qsv"; + device = "/dev/dri/by-path/pci-0000:00:02.0-render"; + }; + }; + }; + + users.users."starr" = { + uid = 993; + isSystemUser = true; + group = "starr"; + }; + + users.groups = { + starr = { + gid = 990; + }; + }; + + users.users.jellyfin.extraGroups = [ + "render" + "video" + "starr" + ]; + +} diff --git a/hosts/thea/nginx.nix b/hosts/thea/nginx.nix index 36b20ad..3710d16 100644 --- a/hosts/thea/nginx.nix +++ b/hosts/thea/nginx.nix @@ -29,16 +29,27 @@ in virtualHosts = let - mkVHost = host: port: { - "${host}" = { - enableACME = true; - forceSSL = true; + mkVHost = + { + host, + port, + target ? sin-address, + }: + { + "${host}" = { + enableACME = true; + forceSSL = true; - locations."/" = { - proxyPass = "http://${sin-address}:${toString port}"; + locations."/" = { + proxyPass = "http://${target}:${toString port}"; + extraConfig = '' + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + ''; + }; }; }; - }; mkStarr = host: port: { "${host}" = { enableACME = true; @@ -53,6 +64,8 @@ in proxyWebsockets = true; extraConfig = '' proxy_ssl_server_name on; + + proxy_read_timeout 4800s; ''; }; locations."/" = { @@ -63,7 +76,6 @@ in include ${authelia-snippets.authelia-authrequest}; proxy_ssl_server_name on; - proxy_read_timeout 4800s; ''; }; }; @@ -99,18 +111,45 @@ in ) vhost); in ( - (withWebsockets (mkVHost "jellyfin.shobu.fr" "8096") "/") + (withWebsockets (mkVHost { + host = "jellyfin.shobu.fr"; + port = "8096"; + target = "127.0.0.1"; + }) "/") // mkStarr "radarr.shobu.fr" "7878" // mkStarr "sonarr.shobu.fr" "8989" // mkStarr "prowlarr.shobu.fr" "9696" // mkStarr "bazarr.shobu.fr" "6767" // mkStarr "lidarr.shobu.fr" "8686" // mkStarr "whisparr.shobu.fr" "6969" - // mkVHost "jellyseerr.shobu.fr" "5055" - // withAuthelia (mkVHost "transmission.shobu.fr" "9091") "/" - // withAuthelia (mkVHost "zimablade-admin.shobu.fr" "61208") "/" - // withAuthelia (mkVHost "actual.shobu.fr" nodes.sin.config.services.actual.settings.port) "/" - // (withWebsockets (mkVHost "trilium.shobu.fr" "12783") "/") + // mkVHost { + host = "jellyseerr.shobu.fr"; + port = "5055"; + } + // withAuthelia (mkVHost { + host = "transmission.shobu.fr"; + port = "13277"; + }) "/" + // mkVHost { + host = "qbittorrent.shobu.fr"; + port = "44160"; + } + // withAuthelia (mkVHost { + host = "zimablade-admin.shobu.fr"; + port = "61208"; + }) "/" + // (mkVHost { + host = "actual.shobu.fr"; + port = nodes.sin.config.services.actual.settings.port; + }) + // (withWebsockets (mkVHost { + host = "trilium.shobu.fr"; + port = "12783"; + }) "/") + // mkVHost { + host = "invit.shobu.fr"; + port = "5690"; + } // { "shobu.fr" = { enableACME = true;