{ pkgs, ... }: { services.postgresql = { enable = true; ensureDatabases = [ "hass" ]; ensureUsers = [{ name = "hass"; ensureDBOwnership = true; }]; }; services.home-assistant = { enable = true; extraPackages = ps: with ps; [ psycopg2 ]; extraComponents = [ "androidtv_remote" "apple_tv" "cast" "homekit_controller" "hue" "spotify" "esphome" "met" "radio_browser" ]; customComponents = [ ( pkgs.buildHomeAssistantComponent rec { owner = "BeryJu"; domain = "auth_header"; version = "1.10"; src = pkgs.fetchFromGitHub { inherit owner; repo = "hass-auth-header"; rev = "refs/tags/v${version}"; hash = "sha256-dSmY3d8Kx0pXl+20dTGAYgjSH6OhNh53jPX7VLCZs7Y="; }; dontBuild = true; } ) ( pkgs.buildHomeAssistantComponent rec { owner = "make-all"; domain = "tuya_local"; version = "2023.12.1"; src = pkgs.fetchFromGitHub { inherit owner; repo = "tuya-local"; rev = "refs/tags/${version}"; hash = "sha256-vi5EmtXAyXaUbJl+yAT5EL0yYb3XFRaAj6fybQRCM4A="; }; propagatedBuildInputs = with pkgs.home-assistant.python.pkgs; [ ( buildPythonPackage rec { pname = "tinytuya"; version = "1.13.1"; format = "wheel"; src = pkgs.fetchPypi { inherit pname version format; hash = "sha256-j7t4P4U9iuVHyb6HASkf7LmBheHN32IjdKE60HUbjIE="; }; } ) colorama ]; dontBuild = true; } ) ]; config = { default_config = { }; http = { server_host = "::1"; trusted_proxies = [ "::1" ]; use_x_forwarded_for = true; }; recorder.db_url = "postgresql://@/hass"; auth_header = { }; }; }; services.nginx.virtualHosts."ha.weebnix.mou.fo" = { enableACME = true; forceSSL = true; locations."/" = { proxyPass = "http://[::1]:8123"; proxyWebsockets = true; extraConfig = '' # This is frequently used in examples but without clear explanation. It # might help with WebSockets. proxy_buffering off; # oauth2_proxy NixOS module sets some non-standard headers, but we need # the preferred_username claim. auth_request_set $preferred_username $upstream_http_x_auth_request_preferred_username; proxy_set_header X-Forwarded-Preferred-Username $preferred_username; ''; }; # Duplicate relevant parts of root route to skip oauth2-proxy module magic. locations."/api/" = { proxyPass = "http://[::1]:8123"; proxyWebsockets = true; extraConfig = '' proxy_buffering off; ''; }; # Disable service worker caching that works improperly with reverse proxy. # https://github.com/home-assistant/frontend/issues/14836 # https://community.home-assistant.io/t/disabling-service-worker-reverse-proxy-auth-causes-issues/167082 locations."/service_worker.js" = { return = ''410 "Service worker disabled: https://github.com/home-assistant/frontend/issues/14836"''; }; }; services.oauth2_proxy.nginx.virtualHosts = [ "ha.weebnix.mou.fo" ]; }