summaryrefslogtreecommitdiff
path: root/hostnix/elmo/media.nix
blob: 7a60030e0c7a96823a90c27b9e44d06240259f2b (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
{ pkgs, ... }:

# https://nixos.wiki/wiki/Jellyfin
{
  hardware.graphics = {
    enable = true;
    # Haswell seems too old to be supported by intel-media-driver (iHD). While
    # QSV is apparently implemented for intel-vaapi-driver (i965) by
    # intel-media-sdk, Jellyfin seems to only support QSV on iHD.
    extraPackages = [
      # Apparently adds some hardware acceleration.
      (pkgs.intel-vaapi-driver.override { enableHybridCodec = true; })
    ];
  };

  # Manual configuration:
  # - Create joe and guest users
  # - Add Media Library
  #   - /srv/media/Movies
  #   - /srv/media/Shows
  #   - /srv/media/incoming/YouTube (Shows)
  # - Administration: Dashboard > Playback: Transcoding
  #     TODO try QSV
  #   - Hardware acceleration: VAAPI
  services.jellyfin.enable = true;

  services.nginx.virtualHosts."jf.mou.fo" = {
    enableACME = true;
    forceSSL = true;
    locations."/".proxyPass = "http://127.0.0.1:8096";
  };

  systemd.tmpfiles.rules = [
    "d /srv/media/incoming/YouTube 2775 ytdl-sub media -"
  ];

  services.ytdl-sub.instances.main = {
    enable = true;
    # TODO schedule = null;
    # The unit runs with ProtectSystem=strict, which leaves the whole
    # filesystem read-only apart from its own state and runtime directories.
    # Without this the output tree is unwritable however it is chowned.
    readWritePaths = [ "/srv/media/incoming/YouTube" ];
    config = {
      presets = {
        "YouTube Channel" = {
          preset = [
            "Jellyfin TV Show by Date"
            "Max 1080p"
          ];
          overrides = {
            tv_show_directory = "/srv/media/incoming/YouTube";
            date_range_after = "20240101"; # arbitrarily early default
          };
          embed_thumbnail = true;
          subtitles = {
            embed_subtitles = true;
            allow_auto_generated_subtitles = true;
          };
          chapters = {
            embed_chapters = true;
            sponsorblock_categories = [ "all" ];
          };
          date_range = {
            after = "{date_range_after}";
            before = "today-2days";
          };
          ytdl_options = {
            break_on_existing = true;
          };
        };
      };
    };
    subscriptions = {
      "YouTube Channel" = {
        "~Moon Channel" = {
          url = "https://www.youtube.com/@moon-channel";
          date_range_after = "20241201";
        };
        "Pinchflat" = "https://www.youtube.com/playlist?list=PLOqoltSk7NvI";
      };
    };
  };

  systemd.services.ytdl-sub-main.serviceConfig.UMask = "0002";

  # TODO kavita vs komga?
  services.kavita = {
    enable = true;
    tokenKeyFile = "/var/secrets/kavita.key";
    settings = {
      Port = 7565;
      IpAddresses = "::1";
    };
  };

  services.komga = {
    enable = true;
    # Cannot override listening on all IPv4 interfaces.
    settings.server.port = 7579;
  };

  # TODO SSO
  # systemd.tmpfiles.rules = let
  #   cfg = pkgs.writeText "application.yml" ''
  #     spring:
  #       security:
  #         oauth2:
  #           client:
  #             registration:
  #               keycloak:
  #                 provider: keycloak # this must match the provider below
  #                 client-id: your-client-id
  #                 client-secret: c830e452-a2a9-40a0-93c1-eb84ea688245
  #                 client-name: Keycloak
  #                 scope: openid,email
  #                 authorization-grant-type: authorization_code
  #                 # the placeholders in {} will be replaced automatically, you don't need to change this line
  #                 redirect-uri: "{baseUrl}/{action}/oauth2/code/{registrationId}"
  #             provider:
  #               keycloak: # this must match the provider above
  #                 user-name-attribute: sub
  #                 # either set the issuer-uri, in which case the app will lookup the configuration for you automatically
  #                 issuer-uri: http://localhost:8085/auth/realms/komgatest
  #                 # or set all of the following
  #                 authorization-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/auth
  #                 token-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/token
  #                 jwk-set-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/certs
  #                 user-info-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/userinfo
  #   '';
  # in
  # [
  #   "L+ /var/lib/komga/application.yml - - - - ${cfg}"
  # ];

  services.nginx.virtualHosts."ka.mou.fo" = {
    enableACME = true;
    forceSSL = true;
    locations."/".proxyPass = "http://127.0.0.1:7579";
  };
}