summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2025-04-08 23:48:55 -0400
committerJoe Mou <dev@mou.fo>2025-04-16 00:13:55 -0400
commit99ac59f5d550339252b2730245075d1945b264c5 (patch)
tree7964c7ddda96a0316afa5c5d06d3dff6c1b555ff
parentae381a3ddecfcf28284be2afa009adbab4ca934f (diff)
Remove danb/rss and host Miniflux on https://mf.mou.fo
We still want SSO. It seems most promising to register Miniflux as an OIDC client, but this is pending switching to a different identity provider. Alternatively we could use oauth2-proxy and configure AUTH_PROXY_HEADER. We would want to bypass for API endpoints: - /accounts/ClientLogin - /reader/api/
-rw-r--r--hostnix/elmo/rss.nix27
1 files changed, 4 insertions, 23 deletions
diff --git a/hostnix/elmo/rss.nix b/hostnix/elmo/rss.nix
index 421934e..61e3cc5 100644
--- a/hostnix/elmo/rss.nix
+++ b/hostnix/elmo/rss.nix
@@ -4,7 +4,7 @@
services.miniflux = {
enable = true;
config = {
- BASE_URL = "http://mf.elmo.mou.fo";
+ BASE_URL = "https://mf.mou.fo";
CREATE_ADMIN = 0;
LISTEN_ADDR = "/run/miniflux/miniflux.sock";
};
@@ -13,32 +13,13 @@
# https://github.com/NixOS/nixpkgs/issues/177284
systemd.services.miniflux.serviceConfig.RuntimeDirectoryMode = lib.mkForce "0755";
- # TODO allocate a subdomain
- services.nginx.virtualHosts."mf.elmo.mou.fo" = {
- # TODO enableACME = true;
- # TODO forceSSL = true;
+ services.nginx.virtualHosts."mf.mou.fo" = {
+ enableACME = true;
+ forceSSL = true;
locations."/" = {
proxyPass = "http://unix:/run/miniflux/miniflux.sock";
};
};
# TODO services.oauth2-proxy.nginx.virtualHosts = { "mf.mou.fo" = {}; };
-
- virtualisation.podman.enable = true;
- virtualisation.oci-containers = {
- containers = {
- rss = {
- image = "codeberg.org/danb/rss";
- ports = [ "127.0.0.1:8283:80" ];
- volumes = [ "/home/joe/rss:/app/storage" ];
- autoStart = true;
- };
- };
- };
-
- services.nginx.virtualHosts."rss.elmo.mou.fo" = {
- locations."/" = {
- proxyPass = "http://localhost:8283";
- };
- };
}