summaryrefslogtreecommitdiff
path: root/hostnix/elmo/home-assistant.nix
blob: 6d70b861098ee6617c3c7cd9317a4a6cfd7e8d86 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
{ pkgs, ... }:

{
  services.postgresql = {
    enable = true;
    ensureDatabases = [ "hass" ];
    ensureUsers = [{
      name = "hass";
      ensureDBOwnership = true;
    }];
  };

  services.home-assistant = {
    enable = true;
    extraPackages = ps: with ps; [ psycopg2 ];
    extraComponents = [
      "androidtv_remote"
      "apple_tv"
      "cast"
      "homekit_controller"
      "hue"
      "spotify"
      "esphome"
      "met"
      "radio_browser"
    ];
    # https://nathan.gs/2023/12/28/home-assistant-add-a-custom-component-in-nixos-revisited/
    customComponents = [
      (
        pkgs.buildHomeAssistantComponent rec {
          owner = "BeryJu";
          domain = "auth_header";
          version = "1.10";
          src = pkgs.fetchFromGitHub {
            inherit owner;
            repo = "hass-auth-header";
            rev = "refs/tags/v${version}";
            hash = "sha256-dSmY3d8Kx0pXl+20dTGAYgjSH6OhNh53jPX7VLCZs7Y=";
          };
          dontBuild = true;
        }
      )
      (
        pkgs.buildHomeAssistantComponent rec {
          owner = "make-all";
          domain = "tuya_local";
          version = "2024.2.0";
          src = pkgs.fetchFromGitHub {
            inherit owner;
            repo = "tuya-local";
            rev = "refs/tags/${version}";
            hash = "sha256-wNdATRXJNHusVO2fMUXqSz0EZRDpodORSuFRXL6ohUs=";
          };
          propagatedBuildInputs = with pkgs.home-assistant.python.pkgs; [
            (
              buildPythonPackage rec {
                pname = "tinytuya";
                version = "1.13.1";
                format = "wheel";
                src = pkgs.fetchPypi {
                  inherit pname version format;
                  hash = "sha256-j7t4P4U9iuVHyb6HASkf7LmBheHN32IjdKE60HUbjIE=";
                };
                propagatedBuildInputs = [
                  colorama
                  cryptography
                  requests
                ];
              }
            )
          ];
          dontBuild = true;
        }
      )
    ];
    config = {
      default_config = { };
      http = {
        server_host = "::1";
        trusted_proxies = [ "::1" ];
        use_x_forwarded_for = true;
      };
      recorder.db_url = "postgresql://@/hass";
      auth_header = { };
    };
  };

  services.nginx.virtualHosts."ha.elmo.mou.fo" = {
    enableACME = true;
    forceSSL = true;
    locations."/" = {
      proxyPass = "http://[::1]:8123";
      proxyWebsockets = true;
      extraConfig = ''
        # This is frequently used in examples but without clear explanation. It
        # might help with WebSockets.
        proxy_buffering off;
        # oauth2_proxy NixOS module sets some non-standard headers, but we need
        # the preferred_username claim.
        auth_request_set $preferred_username $upstream_http_x_auth_request_preferred_username;
        proxy_set_header X-Forwarded-Preferred-Username $preferred_username;
      '';
    };
    # Duplicate relevant parts of root route to skip oauth2-proxy module magic.
    locations."/api/" = {
      proxyPass = "http://[::1]:8123";
      proxyWebsockets = true;
      extraConfig = ''
        proxy_buffering off;
      '';
    };
    # Disable service worker caching that works improperly with reverse proxy.
    # https://github.com/home-assistant/frontend/issues/14836
    # https://community.home-assistant.io/t/disabling-service-worker-reverse-proxy-auth-causes-issues/167082
    locations."/service_worker.js" = {
      return = ''410 "Service worker disabled: https://github.com/home-assistant/frontend/issues/14836"'';
    };
  };

  services.oauth2_proxy.nginx.virtualHosts = [ "ha.elmo.mou.fo" ];
}