{ pkgs, ... }: { services.redlib = { enable = true; address = "[::1]"; port = 7682; }; systemd.services.redlib = { environment = { REDLIB_DEFAULT_SHOW_NSFW = "on"; REDLIB_DEFAULT_USE_HLS = "on"; REDLIB_DEFAULT_WIDE = "on"; REDLIB_ROBOTS_DISABLE_INDEXING = "on"; }; }; services.nginx.virtualHosts."lr.mou.fo" = { enableACME = true; forceSSL = true; locations."/".proxyPass = "http://[::1]:7682"; }; systemd.tmpfiles.rules = [ "d /var/secrets/nitter 0750 root wheel" ]; services.nitter = { enable = true; # This must be populated manually as per # https://github.com/zedeus/nitter/wiki/Guest-Account-Branch-Deployment # Alternatively it can use logged in account tokens with # https://github.com/PrivacyDevel/nitter/blob/master/twitter_oauth.sh guestAccounts = "/var/secrets/nitter/guest-accounts.jsonl"; server = { port = 7873; https = true; hostname = "ni.mou.fo"; address = "127.0.0.1"; }; preferences = { hlsPlayback = true; }; }; systemd.services.nitter = { unitConfig = { AssertPathExists = "/var/secrets/nitter/guest-accounts.jsonl"; }; }; services.nginx.virtualHosts."ni.mou.fo" = { enableACME = true; forceSSL = true; locations."/".proxyPass = "http://127.0.0.1:7873"; }; }