diff options
| author | Akshay Nair <phenax5@gmail.com> | 2025-06-13 15:02:58 +0530 |
|---|---|---|
| committer | Akshay Nair <phenax5@gmail.com> | 2025-06-13 15:02:58 +0530 |
| commit | fb3c68a676643e60e396daf4076684e12d157677 (patch) | |
| tree | 16a6ee14a9d745079e99a066ad30efda1f947e72 | |
| parent | e6b171f9f1d975ffe34e7a34743b5e92e8593847 (diff) | |
| download | homeserver-nixos-config-fb3c68a676643e60e396daf4076684e12d157677.tar.gz homeserver-nixos-config-fb3c68a676643e60e396daf4076684e12d157677.zip | |
Syncthing + service router refactor
| -rw-r--r-- | configuration.nix | 38 | ||||
| -rw-r--r-- | flake.lock | 6 | ||||
| -rw-r--r-- | modules/hardware.nix | 7 | ||||
| -rw-r--r-- | modules/network/default.nix | 16 | ||||
| -rw-r--r-- | modules/network/service-router.service.nix (renamed from modules/service-router.service.nix) | 7 | ||||
| -rw-r--r-- | modules/storage/default.nix | 6 | ||||
| -rw-r--r-- | modules/storage/syncthing.nix | 44 | ||||
| -rw-r--r-- | settings.nix | 16 |
8 files changed, 103 insertions, 37 deletions
diff --git a/configuration.nix b/configuration.nix index 048164f..ca5aaf8 100644 --- a/configuration.nix +++ b/configuration.nix @@ -1,13 +1,4 @@ -# Edit this configuration file to define what should be installed on -# your system. Help is available in the configuration.nix(5) man page -# and in the NixOS manual (accessible by running ‘nixos-help’). - -{ pkgs, lib, ... }: -let - settings = import ./settings.nix { inherit lib; }; - ports = settings.network.ports; - host = settings.network.host; -in +{ pkgs, ... }: { imports = [ ./modules/hardware.nix @@ -15,20 +6,9 @@ in ./modules/network ./modules/media ./modules/dashboard - ./modules/service-router.service.nix + ./modules/storage ]; - services.service-router = { - enable = true; - routes = { - "home.local" = { inherit host; port = ports.dashboard; }; - "sonarr.local" = { inherit host; port = ports.sonarr; }; - "radarr.local" = { inherit host; port = ports.radarr; }; - "prowlarr.local" = { inherit host; port = ports.prowlarr; }; - "jellyfin.local" = { inherit host; port = ports.jellyfin; }; - }; - }; - nixpkgs.config.allowUnfree = true; environment.systemPackages = with pkgs; [ @@ -38,15 +18,17 @@ in lf util-linux dig - ]; - systemd.extraConfig = ''DefaultLimitNOFILE=65536''; - systemd.user.extraConfig = ''DefaultLimitNOFILE=65536''; - boot.kernel.sysctl."fs.inotify.max_user_instances" = 8192; - security.pam.loginLimits = [ - { domain = "*"; type = "-"; item = "nofile"; value = "65536"; } + # Mom mode + st + ungoogled-chromium ]; + # Mom mode + services.xserver.enable = true; + services.xserver.windowManager.dwm.enable = true; + services.xserver.displayManager.startx.enable = true; + time.timeZone = "Asia/Kolkata"; i18n.defaultLocale = "en_GB.UTF-8"; @@ -53,11 +53,11 @@ }, "nixpkgs": { "locked": { - "lastModified": 1749143949, - "narHash": "sha256-QuUtALJpVrPnPeozlUG/y+oIMSLdptHxb3GK6cpSVhA=", + "lastModified": 1749285348, + "narHash": "sha256-frdhQvPbmDYaScPFiCnfdh3B/Vh81Uuoo0w5TkWmmjU=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "d3d2d80a2191a73d1e86456a751b83aa13085d7d", + "rev": "3e3afe5174c561dee0df6f2c2b2236990146329f", "type": "github" }, "original": { diff --git a/modules/hardware.nix b/modules/hardware.nix index 5a20353..7b11ca6 100644 --- a/modules/hardware.nix +++ b/modules/hardware.nix @@ -63,4 +63,11 @@ swapDevices = [{ device = "/dev/disk/by-label/swap"; }]; networking.useDHCP = lib.mkDefault true; + + systemd.extraConfig = ''DefaultLimitNOFILE=65536''; + systemd.user.extraConfig = ''DefaultLimitNOFILE=65536''; + boot.kernel.sysctl."fs.inotify.max_user_instances" = 8192; + security.pam.loginLimits = [ + { domain = "*"; type = "-"; item = "nofile"; value = "65536"; } + ]; } diff --git a/modules/network/default.nix b/modules/network/default.nix index ee3462c..6a40ef7 100644 --- a/modules/network/default.nix +++ b/modules/network/default.nix @@ -1,12 +1,28 @@ { lib, ... }: let settings = import ../../settings.nix { inherit lib; }; + ports = settings.network.ports; + host = settings.network.host; in { imports = [ ./ssh.nix + ./service-router.service.nix ]; + services.service-router = { + enable = true; + routes = { + "home.local" = { inherit host; port = ports.dashboard; }; + "sonarr.local" = { inherit host; port = ports.sonarr; }; + "radarr.local" = { inherit host; port = ports.radarr; }; + "prowlarr.local" = { inherit host; port = ports.prowlarr; }; + "jellyfin.local" = { inherit host; port = ports.jellyfin; }; + "syncthing.local" = { inherit host; port = ports.syncthing; }; + "lidarr.local" = { inherit host; port = ports.lidarr; }; + }; + }; + networking = { hostName = "bacchus"; diff --git a/modules/service-router.service.nix b/modules/network/service-router.service.nix index 0b9a873..9c4e6e2 100644 --- a/modules/service-router.service.nix +++ b/modules/network/service-router.service.nix @@ -19,6 +19,7 @@ in { port = mkOption { type = types.int; }; host = mkOption { type = types.str; default = "127.0.0.1"; }; protocol = mkOption { type = types.str; default = "http"; }; + nginx = mkOption { type = types.attrs; default = {}; }; }; }); default = {}; }; @@ -27,10 +28,12 @@ in { config = lib.mkIf cfg.enable { services.nginx = { enable = true; + recommendedOptimisation = true; virtualHosts = lib.mapAttrs (_: val: { - locations."/" = { + locations."/" = if val.nginx == {} then { proxyPass = "${val.protocol}://${val.host}:${toString val.port}"; - }; + proxyWebsockets = true; + } else val.nginx; }) cfg.routes; }; diff --git a/modules/storage/default.nix b/modules/storage/default.nix new file mode 100644 index 0000000..22bd2ff --- /dev/null +++ b/modules/storage/default.nix @@ -0,0 +1,6 @@ +{ ... }: +{ + imports = [ + ./syncthing.nix + ]; +} diff --git a/modules/storage/syncthing.nix b/modules/storage/syncthing.nix new file mode 100644 index 0000000..5291182 --- /dev/null +++ b/modules/storage/syncthing.nix @@ -0,0 +1,44 @@ +{ lib, ... }: +let + settings = import ../../settings.nix { inherit lib; }; + group = "syncthing"; +in +{ + systemd.tmpfiles.rules = [ + "d ${settings.syncthing.baseDir} 0770 - ${group} - -" + "d ${settings.syncthing.photosDir} 0770 - ${group} - -" + ]; + users.groups.${group} = { }; + users.users.bacchus.extraGroups = [ group ]; + + networking.firewall.allowedTCPPorts = [ settings.network.ports.syncthing ]; + + services.syncthing = { + enable = true; + user = "bacchus"; + group = group; + dataDir = settings.syncthing.baseDir; + guiAddress = "0.0.0.0:${toString settings.network.ports.syncthing}"; + overrideFolders = true; + + settings = { + folders = { + artemis-photos = { + label = "Photos"; + path = settings.syncthing.photosDir; + }; + }; + + options.urAccepted = -1; + + extraOptions = { + gui = { + enabled = true; + theme = "black"; + user = settings.syncthing.username; + password = settings.syncthing.password; + }; + }; + }; + }; +} diff --git a/settings.nix b/settings.nix index 43a4804..f6c717b 100644 --- a/settings.nix +++ b/settings.nix @@ -8,18 +8,26 @@ in lib.recursiveUpdate privateSettings rec { ssh = 22; radarr = 7878; sonarr = 8989; + lidarr = 8686; prowlarr = 9696; jellyfin = 8096; transmissionRPC = 9091; + syncthing = 3141; }; exposeTransmissionRPC = false; }; - media = { + syncthing = { + baseDir = "/media/syncthing"; + photosDir = "${syncthing.baseDir}/photos"; + }; + + media = rec { baseDir = "/media"; - downloadsDir = "${media.baseDir}/_downloads"; - tvDir = "${media.baseDir}/tv"; - moviesDir = "${media.baseDir}/movies"; + downloadsDir = "${baseDir}/_downloads"; + tvDir = "${baseDir}/tv"; + moviesDir = "${baseDir}/movies"; + musicDir = "${baseDir}/music"; group = "multimedia"; }; } |
