From 70a6d533227ea2284bdcc1514b794f99d7eb5361 Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Tue, 11 Jun 2024 16:34:08 -0400 Subject: Upgrade to NixOS 24.05 To resolve database collation version mismatches ("The database was created using collation version 2.38, but the operating system provides version 2.39."): $ sudo -u postgres psql > \c hass > REINDEX DATABASE hass; > ALTER DATABASE hass REFRESH COLLATION VERSION; [ Repeat for all databases (except special database template0) ] --- hostnix/elmo/home-assistant.nix | 54 ++++------------------------------------- hostnix/elmo/oidc.nix | 7 +++--- hostnix/elmo/syncthing.nix | 2 +- hostnix/elmo/system.nix | 2 +- hostnix/elmo/usenet.nix | 2 +- 5 files changed, 12 insertions(+), 55 deletions(-) (limited to 'hostnix/elmo') diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix index 5299508..4be7c6a 100644 --- a/hostnix/elmo/home-assistant.nix +++ b/hostnix/elmo/home-assistant.nix @@ -22,53 +22,9 @@ "vesync" ]; # https://nathan.gs/2023/12/28/home-assistant-add-a-custom-component-in-nixos-revisited/ - customComponents = [ - ( - pkgs.buildHomeAssistantComponent rec { - owner = "BeryJu"; - domain = "auth_header"; - version = "1.10"; - src = pkgs.fetchFromGitHub { - inherit owner; - repo = "hass-auth-header"; - rev = "refs/tags/v${version}"; - hash = "sha256-dSmY3d8Kx0pXl+20dTGAYgjSH6OhNh53jPX7VLCZs7Y="; - }; - dontBuild = true; - } - ) - ( - pkgs.buildHomeAssistantComponent rec { - owner = "make-all"; - domain = "tuya_local"; - version = "2024.2.0"; - src = pkgs.fetchFromGitHub { - inherit owner; - repo = "tuya-local"; - rev = "refs/tags/${version}"; - hash = "sha256-wNdATRXJNHusVO2fMUXqSz0EZRDpodORSuFRXL6ohUs="; - }; - propagatedBuildInputs = with pkgs.home-assistant.python.pkgs; [ - ( - buildPythonPackage rec { - pname = "tinytuya"; - version = "1.13.1"; - format = "wheel"; - src = pkgs.fetchPypi { - inherit pname version format; - hash = "sha256-j7t4P4U9iuVHyb6HASkf7LmBheHN32IjdKE60HUbjIE="; - }; - propagatedBuildInputs = [ - colorama - cryptography - requests - ]; - } - ) - ]; - dontBuild = true; - } - ) + customComponents = with pkgs.home-assistant-custom-components; [ + auth-header + tuya_local ]; config = { default_config = { }; @@ -595,7 +551,7 @@ # This is frequently used in examples but without clear explanation. It # might help with WebSockets. proxy_buffering off; - # oauth2_proxy NixOS module sets some non-standard headers, but we need + # oauth2-proxy NixOS module sets some non-standard headers, but we need # the preferred_username claim. auth_request_set $preferred_username $upstream_http_x_auth_request_preferred_username; proxy_set_header X-Forwarded-Preferred-Username $preferred_username; @@ -617,5 +573,5 @@ }; }; - services.oauth2_proxy.nginx.virtualHosts = [ "ha.mou.fo" ]; + services.oauth2-proxy.nginx.virtualHosts = { "ha.mou.fo" = {}; }; } diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix index 8447aa0..0ed170e 100644 --- a/hostnix/elmo/oidc.nix +++ b/hostnix/elmo/oidc.nix @@ -27,14 +27,15 @@ proxy_buffer_size 16k; ''; - # The oauth2_proxy module has a magic nginx.virtualHosts option that rewrites + # The oauth2-proxy module has a magic nginx.virtualHosts option that rewrites # nginx configs. It's mostly unhelpful, but we use it for brevity. In # particular, it configures Traefik-like ForwardAuth authentication with # auth_request. Note if this resource is missing for whatever reason, the # module magic will fail open (auth_request unset). - services.oauth2_proxy = { + services.oauth2-proxy = { enable = true; cookie.domain = "mou.fo"; + nginx.domain = "kc.mou.fo"; setXauthrequest = true; # include claims email.domains = [ "*" ]; # allow any authenticated user # https://oauth2-proxy.github.io/oauth2-proxy/configuration/providers/keycloak_oidc @@ -55,5 +56,5 @@ # Kludge to bring up after KeyCloak (otherwise OIDC discovery fails). A simple # ordering dependency isn't enough because keycloak.service is active before # KeyCloak responds to requests. - systemd.services.oauth2_proxy.serviceConfig.RestartSec = 5; + systemd.services.oauth2-proxy.serviceConfig.RestartSec = 5; } diff --git a/hostnix/elmo/syncthing.nix b/hostnix/elmo/syncthing.nix index 851ac7e..52553f5 100644 --- a/hostnix/elmo/syncthing.nix +++ b/hostnix/elmo/syncthing.nix @@ -144,5 +144,5 @@ in }; }; - services.oauth2_proxy.nginx.virtualHosts = [ "st.mou.fo" ]; + services.oauth2-proxy.nginx.virtualHosts = { "st.mou.fo" = {}; }; } diff --git a/hostnix/elmo/system.nix b/hostnix/elmo/system.nix index d98d1ff..f1464dc 100644 --- a/hostnix/elmo/system.nix +++ b/hostnix/elmo/system.nix @@ -19,7 +19,7 @@ services.avahi = { enable = true; - nssmdns = true; + nssmdns4 = true; publish = { enable = true; addresses = true; diff --git a/hostnix/elmo/usenet.nix b/hostnix/elmo/usenet.nix index 26d7a7b..78901a1 100644 --- a/hostnix/elmo/usenet.nix +++ b/hostnix/elmo/usenet.nix @@ -48,5 +48,5 @@ in locations."/".proxyPass = "http://[::1]:6789"; }; - services.oauth2_proxy.nginx.virtualHosts = [ "ng.mou.fo" ]; + services.oauth2-proxy.nginx.virtualHosts = { "ng.mou.fo" = {}; }; } -- cgit v1.3.1