summaryrefslogtreecommitdiff
path: root/hostnix/elmo/media.nix
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix/elmo/media.nix')
-rw-r--r--hostnix/elmo/media.nix141
1 files changed, 141 insertions, 0 deletions
diff --git a/hostnix/elmo/media.nix b/hostnix/elmo/media.nix
new file mode 100644
index 0000000..7a60030
--- /dev/null
+++ b/hostnix/elmo/media.nix
@@ -0,0 +1,141 @@
+{ pkgs, ... }:
+
+# https://nixos.wiki/wiki/Jellyfin
+{
+ hardware.graphics = {
+ enable = true;
+ # Haswell seems too old to be supported by intel-media-driver (iHD). While
+ # QSV is apparently implemented for intel-vaapi-driver (i965) by
+ # intel-media-sdk, Jellyfin seems to only support QSV on iHD.
+ extraPackages = [
+ # Apparently adds some hardware acceleration.
+ (pkgs.intel-vaapi-driver.override { enableHybridCodec = true; })
+ ];
+ };
+
+ # Manual configuration:
+ # - Create joe and guest users
+ # - Add Media Library
+ # - /srv/media/Movies
+ # - /srv/media/Shows
+ # - /srv/media/incoming/YouTube (Shows)
+ # - Administration: Dashboard > Playback: Transcoding
+ # TODO try QSV
+ # - Hardware acceleration: VAAPI
+ services.jellyfin.enable = true;
+
+ services.nginx.virtualHosts."jf.mou.fo" = {
+ enableACME = true;
+ forceSSL = true;
+ locations."/".proxyPass = "http://127.0.0.1:8096";
+ };
+
+ systemd.tmpfiles.rules = [
+ "d /srv/media/incoming/YouTube 2775 ytdl-sub media -"
+ ];
+
+ services.ytdl-sub.instances.main = {
+ enable = true;
+ # TODO schedule = null;
+ # The unit runs with ProtectSystem=strict, which leaves the whole
+ # filesystem read-only apart from its own state and runtime directories.
+ # Without this the output tree is unwritable however it is chowned.
+ readWritePaths = [ "/srv/media/incoming/YouTube" ];
+ config = {
+ presets = {
+ "YouTube Channel" = {
+ preset = [
+ "Jellyfin TV Show by Date"
+ "Max 1080p"
+ ];
+ overrides = {
+ tv_show_directory = "/srv/media/incoming/YouTube";
+ date_range_after = "20240101"; # arbitrarily early default
+ };
+ embed_thumbnail = true;
+ subtitles = {
+ embed_subtitles = true;
+ allow_auto_generated_subtitles = true;
+ };
+ chapters = {
+ embed_chapters = true;
+ sponsorblock_categories = [ "all" ];
+ };
+ date_range = {
+ after = "{date_range_after}";
+ before = "today-2days";
+ };
+ ytdl_options = {
+ break_on_existing = true;
+ };
+ };
+ };
+ };
+ subscriptions = {
+ "YouTube Channel" = {
+ "~Moon Channel" = {
+ url = "https://www.youtube.com/@moon-channel";
+ date_range_after = "20241201";
+ };
+ "Pinchflat" = "https://www.youtube.com/playlist?list=PLOqoltSk7NvI";
+ };
+ };
+ };
+
+ systemd.services.ytdl-sub-main.serviceConfig.UMask = "0002";
+
+ # TODO kavita vs komga?
+ services.kavita = {
+ enable = true;
+ tokenKeyFile = "/var/secrets/kavita.key";
+ settings = {
+ Port = 7565;
+ IpAddresses = "::1";
+ };
+ };
+
+ services.komga = {
+ enable = true;
+ # Cannot override listening on all IPv4 interfaces.
+ settings.server.port = 7579;
+ };
+
+ # TODO SSO
+ # systemd.tmpfiles.rules = let
+ # cfg = pkgs.writeText "application.yml" ''
+ # spring:
+ # security:
+ # oauth2:
+ # client:
+ # registration:
+ # keycloak:
+ # provider: keycloak # this must match the provider below
+ # client-id: your-client-id
+ # client-secret: c830e452-a2a9-40a0-93c1-eb84ea688245
+ # client-name: Keycloak
+ # scope: openid,email
+ # authorization-grant-type: authorization_code
+ # # the placeholders in {} will be replaced automatically, you don't need to change this line
+ # redirect-uri: "{baseUrl}/{action}/oauth2/code/{registrationId}"
+ # provider:
+ # keycloak: # this must match the provider above
+ # user-name-attribute: sub
+ # # either set the issuer-uri, in which case the app will lookup the configuration for you automatically
+ # issuer-uri: http://localhost:8085/auth/realms/komgatest
+ # # or set all of the following
+ # authorization-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/auth
+ # token-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/token
+ # jwk-set-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/certs
+ # user-info-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/userinfo
+ # '';
+ # in
+ # [
+ # "L+ /var/lib/komga/application.yml - - - - ${cfg}"
+ # ];
+
+ services.nginx.virtualHosts."ka.mou.fo" = {
+ enableACME = true;
+ forceSSL = true;
+ locations."/".proxyPass = "http://127.0.0.1:7579";
+ };
+}