diff options
Diffstat (limited to 'hostnix/elmo')
| -rw-r--r-- | hostnix/elmo/media.nix | 55 |
1 files changed, 55 insertions, 0 deletions
diff --git a/hostnix/elmo/media.nix b/hostnix/elmo/media.nix index 783f0f3..4f3d644 100644 --- a/hostnix/elmo/media.nix +++ b/hostnix/elmo/media.nix @@ -32,4 +32,59 @@ forceSSL = true; locations."/".proxyPass = "http://[::1]:8096"; }; + + # TODO kavita vs komga? + services.kavita = { + enable = true; + tokenKeyFile = "/var/secrets/kavita.key"; + settings = { + Port = 7565; + IpAddresses = "::1"; + }; + }; + + services.komga = { + enable = true; + # Cannot override listening on all IPv4 interfaces. + port = 7579; + }; + + # TODO SSO + # systemd.tmpfiles.rules = let + # cfg = pkgs.writeText "application.yml" '' + # spring: + # security: + # oauth2: + # client: + # registration: + # keycloak: + # provider: keycloak # this must match the provider below + # client-id: your-client-id + # client-secret: c830e452-a2a9-40a0-93c1-eb84ea688245 + # client-name: Keycloak + # scope: openid,email + # authorization-grant-type: authorization_code + # # the placeholders in {} will be replaced automatically, you don't need to change this line + # redirect-uri: "{baseUrl}/{action}/oauth2/code/{registrationId}" + # provider: + # keycloak: # this must match the provider above + # user-name-attribute: sub + # # either set the issuer-uri, in which case the app will lookup the configuration for you automatically + # issuer-uri: http://localhost:8085/auth/realms/komgatest + # # or set all of the following + # authorization-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/auth + # token-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/token + # jwk-set-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/certs + # user-info-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/userinfo + # ''; + # in + # [ + # "L+ /var/lib/komga/application.yml - - - - ${cfg}" + # ]; + + services.nginx.virtualHosts."ka.mou.fo" = { + enableACME = true; + forceSSL = true; + locations."/".proxyPass = "http://127.0.0.1:7579"; + }; } |
