{ pkgs, ... }: # https://nixos.wiki/wiki/Jellyfin # # Manual configuration: # - Create joe and guest users # - Administration: Dashboard > Advanced: Networking # - Bind to local network address: ::1 # - Enable IPv6 # - Add line to /var/lib/jellyfin/config/network.xml (see # https://github.com/jellyfin/jellyfin/issues/6940): # false { nixpkgs.config.packageOverrides = pkgs: { # Apparently adds some hardware acceleration. intel-vaapi-driver = pkgs.intel-vaapi-driver.override { enableHybridCodec = true; }; }; hardware.graphics = { enable = true; # Haswell seems too old to be supported by intel-media-driver (iHD). While # QSV is apparently implemented for intel-vaapi-driver (i965) by # intel-media-sdk, Jellyfin seems to only support QSV on iHD. extraPackages = with pkgs; [ intel-vaapi-driver ]; }; services.jellyfin.enable = true; services.nginx.virtualHosts."jf.mou.fo" = { enableACME = true; forceSSL = true; locations."/".proxyPass = "http://[::1]:8096"; }; # TODO kavita vs komga? services.kavita = { enable = true; tokenKeyFile = "/var/secrets/kavita.key"; settings = { Port = 7565; IpAddresses = "::1"; }; }; services.komga = { enable = true; # Cannot override listening on all IPv4 interfaces. settings.server.port = 7579; }; # TODO SSO # systemd.tmpfiles.rules = let # cfg = pkgs.writeText "application.yml" '' # spring: # security: # oauth2: # client: # registration: # keycloak: # provider: keycloak # this must match the provider below # client-id: your-client-id # client-secret: c830e452-a2a9-40a0-93c1-eb84ea688245 # client-name: Keycloak # scope: openid,email # authorization-grant-type: authorization_code # # the placeholders in {} will be replaced automatically, you don't need to change this line # redirect-uri: "{baseUrl}/{action}/oauth2/code/{registrationId}" # provider: # keycloak: # this must match the provider above # user-name-attribute: sub # # either set the issuer-uri, in which case the app will lookup the configuration for you automatically # issuer-uri: http://localhost:8085/auth/realms/komgatest # # or set all of the following # authorization-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/auth # token-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/token # jwk-set-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/certs # user-info-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/userinfo # ''; # in # [ # "L+ /var/lib/komga/application.yml - - - - ${cfg}" # ]; services.nginx.virtualHosts."ka.mou.fo" = { enableACME = true; forceSSL = true; locations."/".proxyPass = "http://127.0.0.1:7579"; }; }