| Age | Commit message (Collapse) | Author |
|
|
|
|
|
|
|
Coexists with ytdl-sub rather than replacing it, downloading into its own
tree under /srv/media/incoming so the two never manage the same files.
Podcast clients cannot authenticate, so the feed, cover art, episode art
and media stream routes bypass oauth2-proxy with auth_request off. Those
are exactly the routes pinchflat serves unauthenticated itself, each
addressed by an unguessable UUID. The OPML endpoint is exposed as well but
stays token-protected by the app.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
|
Fixes socket permission issue. Drop the RuntimeDirectoryMode workaround:
nginx no longer traverses /run/miniflux.
Also drop the now-redundant explicit socket dependencies from bjj-booker
and clippersnip; systemd adds those implicitly.
|
|
|
|
|
|
|
|
|
|
Requires /var/secrets/typetype to be populated by hand:
- env with DATABASE_PASSWORD and POSTGRES_PASSWORD (set the same value)
- youtube_remote_login_internal_token
- youtube_session_encryption_key
Postgres data lives at /var/lib/typetype/postgres as a bind mount rather
than a Docker volume.
Downloads (typetype-downloader + Garage) and SSO are not set up yet.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
|
|
|
|
|
|
|
|
|
See https://community.home-assistant.io/t/all-automations-show-no-traces-found/389304
and https://www.home-assistant.io/faq/unique_id
|
|
|
|
|
|
|
|
Notification dismissal does not seem to work.
|
|
|
|
|
|
git-daemon-export-ok is a very simply access control for
git-http-backend. We explicitly disable it.
See https://github.com/NixOS/nixpkgs/commit/8b6fc43e100d053ed4e7fd28f4f1edf04f0d5374
|
|
n8n has trouble building and just seems to be unnecessary trouble. FWIW
it seems like we could improve our configuration by using the more
standard services.n8n.environment
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Some other minor adjustments to entity naming, fan, and grow light.
|
|
Use a disposable domain until thinking more about authentication.
|
|
|
|
|
|
$ nix flake update --override-input nixpkgs github:NixOS/nixpkgs/ea156c6c3a5b67b0120f92f664853914a58d3b05
Avoid cgit issue until fix lands on stable:
https://github.com/NixOS/nixpkgs/pull/477185
|
|
|
|
- More reliable smart plug on panel light
- SAD lamp timer
|
|
Replaces unmaintained header authentication behind oauth2-proxy.
Add OIDC client for Home Assistant:
- Callback URLs: https://ha.mou.fo/auth/oidc/callback
- Public Client
To link OIDC credentials with the existing joe user, temporarily set:
auth_oidc.features.automatic_user_linking = true;
See https://github.com/christiaangoossens/hass-oidc-auth/blob/main/docs/configuration.md#migrating-from-ha-usernamepassword-users-to-oidc-users
Must login through either:
- https://ha.mou.fo/auth/oidc/welcome
- https://ha.mou.fo/auth/oidc/redirect
Injecting directly into the landing login page is pending
https://github.com/christiaangoossens/hass-oidc-auth/issues/19
|
|
Much simpler to configure and use.
|
|
|
|
|
|
The auth_header Home Assistant custom component has been removed. For
now we use the last package from:
https://github.com/NixOS/nixpkgs/blob/7f88a8b9efaf0e08e63e3806b2b3f42fd83fde91/pkgs/servers/home-assistant/custom-components/auth-header/package.nix
|
|
NixOS 25.11 contains Nix 2.30 which now builds to /nix/var/nix/builds,
which is not space constrained like the previous default of /tmp. To
perform the upgrade to NixOS 25.11, we first must unset our build-dir
from a world writable directory.
See https://github.com/nixos/nix/issues/13701
|
|
|
|
|
|
Getting the right permissions set on the socket is quite awkward.
Perhaps listening on a port would have been preferable. systemd socket
activation would require us to support file descriptor handoff (which
would need to be changed in Nitro).
|
|
|
|
broadcom_sta WiFi driver is considered insecure. We weren't using WiFi
anyway, so remove it. It may be possible to use Broadcom open source
drivers for our BCM4360, but these may only support newer hardware.
Also use allowUnfreePredicate to explicitly whitelist packages.
|
|
|
|
Apparently packageOverrides are deprecated by overlays. Overlays
apparently can "increase eval time". If intel-vaapi-driver is a "leaf"
package then we can use the overridden package instance without
replacing it in nixpkgs. It seems like the only place this package
should be referenced is from hardware.graphics.extraPackages, and not as
a dependency of other packages.
See https://discourse.nixos.org/t/overriding-a-package/59565
|
|
We had been setting TMPDIR for nix-daemon, but nixos-rebuild does not
use that. Use the newer build-dir setting instead.
See https://github.com/NixOS/nixpkgs/issues/293114#issuecomment-2663470083
|