{ pkgs, ... }: # https://nixos.wiki/wiki/Jellyfin { hardware.graphics = { enable = true; # Haswell seems too old to be supported by intel-media-driver (iHD). While # QSV is apparently implemented for intel-vaapi-driver (i965) by # intel-media-sdk, Jellyfin seems to only support QSV on iHD. extraPackages = [ # Apparently adds some hardware acceleration. (pkgs.intel-vaapi-driver.override { enableHybridCodec = true; }) ]; }; # Manual configuration: # - Create joe and guest users # - Add Media Library # - /srv/media/Movies # - /srv/media/Shows # - /srv/media/incoming/YouTube (Shows) # - Administration: Dashboard > Playback: Transcoding # TODO try QSV # - Hardware acceleration: VAAPI services.jellyfin.enable = true; services.nginx.virtualHosts."jf.mou.fo" = { enableACME = true; forceSSL = true; locations."/".proxyPass = "http://127.0.0.1:8096"; }; systemd.tmpfiles.rules = [ "d /srv/media/incoming/YouTube 2775 ytdl-sub media -" ]; services.ytdl-sub.instances.main = { enable = true; # TODO schedule = null; # The unit runs with ProtectSystem=strict, which leaves the whole # filesystem read-only apart from its own state and runtime directories. # Without this the output tree is unwritable however it is chowned. readWritePaths = [ "/srv/media/incoming/YouTube" ]; config = { presets = { "YouTube Channel" = { preset = [ "Jellyfin TV Show by Date" "Max 1080p" ]; overrides = { tv_show_directory = "/srv/media/incoming/YouTube"; date_range_after = "20240101"; # arbitrarily early default }; embed_thumbnail = true; subtitles = { embed_subtitles = true; allow_auto_generated_subtitles = true; }; chapters = { embed_chapters = true; sponsorblock_categories = [ "all" ]; }; date_range = { after = "{date_range_after}"; before = "today-2days"; }; ytdl_options = { break_on_existing = true; }; }; }; }; subscriptions = { "YouTube Channel" = { "~Moon Channel" = { url = "https://www.youtube.com/@moon-channel"; date_range_after = "20241201"; }; "Pinchflat" = "https://www.youtube.com/playlist?list=PLOqoltSk7NvI"; }; }; }; systemd.services.ytdl-sub-main.serviceConfig.UMask = "0002"; # TODO kavita vs komga? services.kavita = { enable = true; tokenKeyFile = "/var/secrets/kavita.key"; settings = { Port = 7565; IpAddresses = "::1"; }; }; services.komga = { enable = true; # Cannot override listening on all IPv4 interfaces. settings.server.port = 7579; }; # TODO SSO # systemd.tmpfiles.rules = let # cfg = pkgs.writeText "application.yml" '' # spring: # security: # oauth2: # client: # registration: # keycloak: # provider: keycloak # this must match the provider below # client-id: your-client-id # client-secret: c830e452-a2a9-40a0-93c1-eb84ea688245 # client-name: Keycloak # scope: openid,email # authorization-grant-type: authorization_code # # the placeholders in {} will be replaced automatically, you don't need to change this line # redirect-uri: "{baseUrl}/{action}/oauth2/code/{registrationId}" # provider: # keycloak: # this must match the provider above # user-name-attribute: sub # # either set the issuer-uri, in which case the app will lookup the configuration for you automatically # issuer-uri: http://localhost:8085/auth/realms/komgatest # # or set all of the following # authorization-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/auth # token-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/token # jwk-set-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/certs # user-info-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/userinfo # ''; # in # [ # "L+ /var/lib/komga/application.yml - - - - ${cfg}" # ]; services.nginx.virtualHosts."ka.mou.fo" = { enableACME = true; forceSSL = true; locations."/".proxyPass = "http://127.0.0.1:7579"; }; }