summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2024-06-11 16:34:08 -0400
committerJoe Mou <dev@mou.fo>2024-10-09 13:48:40 -0400
commit70a6d533227ea2284bdcc1514b794f99d7eb5361 (patch)
treec30dd37ea2c37667ca5fa286851fc344d03c1500
parentb04eec18b977ab7303bd0ccbd9adaf86f4f3a5a6 (diff)
Upgrade to NixOS 24.05
To resolve database collation version mismatches ("The database was created using collation version 2.38, but the operating system provides version 2.39."): $ sudo -u postgres psql > \c hass > REINDEX DATABASE hass; > ALTER DATABASE hass REFRESH COLLATION VERSION; [ Repeat for all databases (except special database template0) ]
-rw-r--r--hostnix/elmo/home-assistant.nix54
-rw-r--r--hostnix/elmo/oidc.nix7
-rw-r--r--hostnix/elmo/syncthing.nix2
-rw-r--r--hostnix/elmo/system.nix2
-rw-r--r--hostnix/elmo/usenet.nix2
5 files changed, 12 insertions, 55 deletions
diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix
index 5299508..4be7c6a 100644
--- a/hostnix/elmo/home-assistant.nix
+++ b/hostnix/elmo/home-assistant.nix
@@ -22,53 +22,9 @@
"vesync"
];
# https://nathan.gs/2023/12/28/home-assistant-add-a-custom-component-in-nixos-revisited/
- customComponents = [
- (
- pkgs.buildHomeAssistantComponent rec {
- owner = "BeryJu";
- domain = "auth_header";
- version = "1.10";
- src = pkgs.fetchFromGitHub {
- inherit owner;
- repo = "hass-auth-header";
- rev = "refs/tags/v${version}";
- hash = "sha256-dSmY3d8Kx0pXl+20dTGAYgjSH6OhNh53jPX7VLCZs7Y=";
- };
- dontBuild = true;
- }
- )
- (
- pkgs.buildHomeAssistantComponent rec {
- owner = "make-all";
- domain = "tuya_local";
- version = "2024.2.0";
- src = pkgs.fetchFromGitHub {
- inherit owner;
- repo = "tuya-local";
- rev = "refs/tags/${version}";
- hash = "sha256-wNdATRXJNHusVO2fMUXqSz0EZRDpodORSuFRXL6ohUs=";
- };
- propagatedBuildInputs = with pkgs.home-assistant.python.pkgs; [
- (
- buildPythonPackage rec {
- pname = "tinytuya";
- version = "1.13.1";
- format = "wheel";
- src = pkgs.fetchPypi {
- inherit pname version format;
- hash = "sha256-j7t4P4U9iuVHyb6HASkf7LmBheHN32IjdKE60HUbjIE=";
- };
- propagatedBuildInputs = [
- colorama
- cryptography
- requests
- ];
- }
- )
- ];
- dontBuild = true;
- }
- )
+ customComponents = with pkgs.home-assistant-custom-components; [
+ auth-header
+ tuya_local
];
config = {
default_config = { };
@@ -595,7 +551,7 @@
# This is frequently used in examples but without clear explanation. It
# might help with WebSockets.
proxy_buffering off;
- # oauth2_proxy NixOS module sets some non-standard headers, but we need
+ # oauth2-proxy NixOS module sets some non-standard headers, but we need
# the preferred_username claim.
auth_request_set $preferred_username $upstream_http_x_auth_request_preferred_username;
proxy_set_header X-Forwarded-Preferred-Username $preferred_username;
@@ -617,5 +573,5 @@
};
};
- services.oauth2_proxy.nginx.virtualHosts = [ "ha.mou.fo" ];
+ services.oauth2-proxy.nginx.virtualHosts = { "ha.mou.fo" = {}; };
}
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix
index 8447aa0..0ed170e 100644
--- a/hostnix/elmo/oidc.nix
+++ b/hostnix/elmo/oidc.nix
@@ -27,14 +27,15 @@
proxy_buffer_size 16k;
'';
- # The oauth2_proxy module has a magic nginx.virtualHosts option that rewrites
+ # The oauth2-proxy module has a magic nginx.virtualHosts option that rewrites
# nginx configs. It's mostly unhelpful, but we use it for brevity. In
# particular, it configures Traefik-like ForwardAuth authentication with
# auth_request. Note if this resource is missing for whatever reason, the
# module magic will fail open (auth_request unset).
- services.oauth2_proxy = {
+ services.oauth2-proxy = {
enable = true;
cookie.domain = "mou.fo";
+ nginx.domain = "kc.mou.fo";
setXauthrequest = true; # include claims
email.domains = [ "*" ]; # allow any authenticated user
# https://oauth2-proxy.github.io/oauth2-proxy/configuration/providers/keycloak_oidc
@@ -55,5 +56,5 @@
# Kludge to bring up after KeyCloak (otherwise OIDC discovery fails). A simple
# ordering dependency isn't enough because keycloak.service is active before
# KeyCloak responds to requests.
- systemd.services.oauth2_proxy.serviceConfig.RestartSec = 5;
+ systemd.services.oauth2-proxy.serviceConfig.RestartSec = 5;
}
diff --git a/hostnix/elmo/syncthing.nix b/hostnix/elmo/syncthing.nix
index 851ac7e..52553f5 100644
--- a/hostnix/elmo/syncthing.nix
+++ b/hostnix/elmo/syncthing.nix
@@ -144,5 +144,5 @@ in
};
};
- services.oauth2_proxy.nginx.virtualHosts = [ "st.mou.fo" ];
+ services.oauth2-proxy.nginx.virtualHosts = { "st.mou.fo" = {}; };
}
diff --git a/hostnix/elmo/system.nix b/hostnix/elmo/system.nix
index d98d1ff..f1464dc 100644
--- a/hostnix/elmo/system.nix
+++ b/hostnix/elmo/system.nix
@@ -19,7 +19,7 @@
services.avahi = {
enable = true;
- nssmdns = true;
+ nssmdns4 = true;
publish = {
enable = true;
addresses = true;
diff --git a/hostnix/elmo/usenet.nix b/hostnix/elmo/usenet.nix
index 26d7a7b..78901a1 100644
--- a/hostnix/elmo/usenet.nix
+++ b/hostnix/elmo/usenet.nix
@@ -48,5 +48,5 @@ in
locations."/".proxyPass = "http://[::1]:6789";
};
- services.oauth2_proxy.nginx.virtualHosts = [ "ng.mou.fo" ];
+ services.oauth2-proxy.nginx.virtualHosts = { "ng.mou.fo" = {}; };
}