| Age | Commit message (Collapse) | Author |
|
|
|
|
|
|
|
Coexists with ytdl-sub rather than replacing it, downloading into its own
tree under /srv/media/incoming so the two never manage the same files.
Podcast clients cannot authenticate, so the feed, cover art, episode art
and media stream routes bypass oauth2-proxy with auth_request off. Those
are exactly the routes pinchflat serves unauthenticated itself, each
addressed by an unguessable UUID. The OPML endpoint is exposed as well but
stays token-protected by the app.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
|
Fixes socket permission issue. Drop the RuntimeDirectoryMode workaround:
nginx no longer traverses /run/miniflux.
Also drop the now-redundant explicit socket dependencies from bjj-booker
and clippersnip; systemd adds those implicitly.
|
|
|
|
|
|
|
|
|
|
Requires /var/secrets/typetype to be populated by hand:
- env with DATABASE_PASSWORD and POSTGRES_PASSWORD (set the same value)
- youtube_remote_login_internal_token
- youtube_session_encryption_key
Postgres data lives at /var/lib/typetype/postgres as a bind mount rather
than a Docker volume.
Downloads (typetype-downloader + Garage) and SSO are not set up yet.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
|
|
|
|
|
|
|
|
|
See https://community.home-assistant.io/t/all-automations-show-no-traces-found/389304
and https://www.home-assistant.io/faq/unique_id
|
|
|
|
|
|
|
|
Notification dismissal does not seem to work.
|
|
|
|
/usr/bin/git is an xcode-select shim that needs to stat
/Library/Developer/CommandLineTools to find the real git binary; the
sandbox denied that path by default, breaking git entirely.
Separately, when TARGET_DIR is a subdirectory of a larger repo, the
real .git/.jj directories live above TARGET_DIR and were unwritable,
breaking commits from within the subdirectory. default.nix now
resolves the real git/jj dirs at launch and passes them through as
GIT_DIR/JJ_DIR sandbox params.
|
|
|
|
|
|
|
|
|
|
Sometimes seems to work with uninstall, but generally doesn't.
|
|
|
|
git-daemon-export-ok is a very simply access control for
git-http-backend. We explicitly disable it.
See https://github.com/NixOS/nixpkgs/commit/8b6fc43e100d053ed4e7fd28f4f1edf04f0d5374
|
|
n8n has trouble building and just seems to be unnecessary trouble. FWIW
it seems like we could improve our configuration by using the more
standard services.n8n.environment
|
|
There appear to be some issues:
- Remap Super/Alt on client
- Mouse pointer disappears
- Scroll not working
- Letterboxing
|
|
Also install fd and rg so those vim fzf commands work
|
|
Perhaps less secure but we're running this command a whole lot.
|
|
Every activation fails with trying to uninstall sunshine's dependencies,
for some reason.
|
|
|
|
Give access to .dotfiles, fix ~/src subdirectories, and check that we
don't allow access to everything.
|
|
|
|
|
|
Cannot use nix-darwin because of https://github.com/nix-darwin/nix-darwin/issues/1041
Anyway since it uses kernel extensions, etc, this might be better via
the cask.
Since Karabiner-Elements creates a virtual device, it should be
configured before LinearMouse. Unlike LinearMouse, reverse scrolling
works with iPad continuity too
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Rollback nixpkgs for https://github.com/NixOS/nixpkgs/issues/507531
|
|
From https://github.com/neko-kai/claude-code-sandbox
|
|
|
|
|
|
|