summaryrefslogtreecommitdiff
path: root/hostnix
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix')
-rw-r--r--hostnix/elmo/home-assistant.nix54
-rw-r--r--hostnix/elmo/oidc.nix7
-rw-r--r--hostnix/elmo/syncthing.nix2
-rw-r--r--hostnix/elmo/system.nix2
-rw-r--r--hostnix/elmo/usenet.nix2
5 files changed, 12 insertions, 55 deletions
diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix
index 5299508..4be7c6a 100644
--- a/hostnix/elmo/home-assistant.nix
+++ b/hostnix/elmo/home-assistant.nix
@@ -22,53 +22,9 @@
"vesync"
];
# https://nathan.gs/2023/12/28/home-assistant-add-a-custom-component-in-nixos-revisited/
- customComponents = [
- (
- pkgs.buildHomeAssistantComponent rec {
- owner = "BeryJu";
- domain = "auth_header";
- version = "1.10";
- src = pkgs.fetchFromGitHub {
- inherit owner;
- repo = "hass-auth-header";
- rev = "refs/tags/v${version}";
- hash = "sha256-dSmY3d8Kx0pXl+20dTGAYgjSH6OhNh53jPX7VLCZs7Y=";
- };
- dontBuild = true;
- }
- )
- (
- pkgs.buildHomeAssistantComponent rec {
- owner = "make-all";
- domain = "tuya_local";
- version = "2024.2.0";
- src = pkgs.fetchFromGitHub {
- inherit owner;
- repo = "tuya-local";
- rev = "refs/tags/${version}";
- hash = "sha256-wNdATRXJNHusVO2fMUXqSz0EZRDpodORSuFRXL6ohUs=";
- };
- propagatedBuildInputs = with pkgs.home-assistant.python.pkgs; [
- (
- buildPythonPackage rec {
- pname = "tinytuya";
- version = "1.13.1";
- format = "wheel";
- src = pkgs.fetchPypi {
- inherit pname version format;
- hash = "sha256-j7t4P4U9iuVHyb6HASkf7LmBheHN32IjdKE60HUbjIE=";
- };
- propagatedBuildInputs = [
- colorama
- cryptography
- requests
- ];
- }
- )
- ];
- dontBuild = true;
- }
- )
+ customComponents = with pkgs.home-assistant-custom-components; [
+ auth-header
+ tuya_local
];
config = {
default_config = { };
@@ -595,7 +551,7 @@
# This is frequently used in examples but without clear explanation. It
# might help with WebSockets.
proxy_buffering off;
- # oauth2_proxy NixOS module sets some non-standard headers, but we need
+ # oauth2-proxy NixOS module sets some non-standard headers, but we need
# the preferred_username claim.
auth_request_set $preferred_username $upstream_http_x_auth_request_preferred_username;
proxy_set_header X-Forwarded-Preferred-Username $preferred_username;
@@ -617,5 +573,5 @@
};
};
- services.oauth2_proxy.nginx.virtualHosts = [ "ha.mou.fo" ];
+ services.oauth2-proxy.nginx.virtualHosts = { "ha.mou.fo" = {}; };
}
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix
index 8447aa0..0ed170e 100644
--- a/hostnix/elmo/oidc.nix
+++ b/hostnix/elmo/oidc.nix
@@ -27,14 +27,15 @@
proxy_buffer_size 16k;
'';
- # The oauth2_proxy module has a magic nginx.virtualHosts option that rewrites
+ # The oauth2-proxy module has a magic nginx.virtualHosts option that rewrites
# nginx configs. It's mostly unhelpful, but we use it for brevity. In
# particular, it configures Traefik-like ForwardAuth authentication with
# auth_request. Note if this resource is missing for whatever reason, the
# module magic will fail open (auth_request unset).
- services.oauth2_proxy = {
+ services.oauth2-proxy = {
enable = true;
cookie.domain = "mou.fo";
+ nginx.domain = "kc.mou.fo";
setXauthrequest = true; # include claims
email.domains = [ "*" ]; # allow any authenticated user
# https://oauth2-proxy.github.io/oauth2-proxy/configuration/providers/keycloak_oidc
@@ -55,5 +56,5 @@
# Kludge to bring up after KeyCloak (otherwise OIDC discovery fails). A simple
# ordering dependency isn't enough because keycloak.service is active before
# KeyCloak responds to requests.
- systemd.services.oauth2_proxy.serviceConfig.RestartSec = 5;
+ systemd.services.oauth2-proxy.serviceConfig.RestartSec = 5;
}
diff --git a/hostnix/elmo/syncthing.nix b/hostnix/elmo/syncthing.nix
index 851ac7e..52553f5 100644
--- a/hostnix/elmo/syncthing.nix
+++ b/hostnix/elmo/syncthing.nix
@@ -144,5 +144,5 @@ in
};
};
- services.oauth2_proxy.nginx.virtualHosts = [ "st.mou.fo" ];
+ services.oauth2-proxy.nginx.virtualHosts = { "st.mou.fo" = {}; };
}
diff --git a/hostnix/elmo/system.nix b/hostnix/elmo/system.nix
index d98d1ff..f1464dc 100644
--- a/hostnix/elmo/system.nix
+++ b/hostnix/elmo/system.nix
@@ -19,7 +19,7 @@
services.avahi = {
enable = true;
- nssmdns = true;
+ nssmdns4 = true;
publish = {
enable = true;
addresses = true;
diff --git a/hostnix/elmo/usenet.nix b/hostnix/elmo/usenet.nix
index 26d7a7b..78901a1 100644
--- a/hostnix/elmo/usenet.nix
+++ b/hostnix/elmo/usenet.nix
@@ -48,5 +48,5 @@ in
locations."/".proxyPass = "http://[::1]:6789";
};
- services.oauth2_proxy.nginx.virtualHosts = [ "ng.mou.fo" ];
+ services.oauth2-proxy.nginx.virtualHosts = { "ng.mou.fo" = {}; };
}