{ pkgs, ... }: { services.libreddit = { enable = true; address = "[::1]"; port = 7682; }; systemd.services.libreddit = { environment = { LIBREDDIT_DEFAULT_SHOW_NSFW = "on"; LIBREDDIT_DEFAULT_USE_HLS = "on"; LIBREDDIT_DEFAULT_WIDE = "on"; # v0.30.0 is too old for these settings # LIBREDDIT_PUSHSHIFT_FRONTEND = "www.reveddit.com"; # LIBREDDIT_ROBOTS_DISABLE_INDEXING = "on"; }; }; services.nginx.virtualHosts."lr.mou.fo" = { enableACME = true; forceSSL = true; locations."/".proxyPass = "http://[::1]:7682"; }; systemd.tmpfiles.rules = [ "d /var/secrets/nitter 0750 root wheel" ]; services.nitter = { enable = true; # This must be populated manually as per # https://github.com/zedeus/nitter/wiki/Guest-Account-Branch-Deployment # Alternatively it can use logged in account tokens with # https://github.com/PrivacyDevel/nitter/blob/master/twitter_oauth.sh guestAccounts = "/var/secrets/nitter/guest-accounts.jsonl"; server = { port = 7873; https = true; hostname = "ni.mou.fo"; address = "127.0.0.1"; }; preferences = { hlsPlayback = true; }; }; systemd.services.nitter = { unitConfig = { AssertPathExists = "/var/secrets/nitter/guest-accounts.jsonl"; }; }; services.nginx.virtualHosts."ni.mou.fo" = { enableACME = true; forceSSL = true; locations."/".proxyPass = "http://127.0.0.1:7873"; }; }