blob: 8fff82e77a8f27cc7ccd5170e98a9a60863d1d90 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
|
{ pkgs, ... }:
# https://nixos.wiki/wiki/Jellyfin
#
# Manual configuration:
# - Create joe and guest users
# - Administration: Dashboard > Advanced: Networking
# - Bind to local network address: ::1
# - Enable IPv6
# - Add line to /var/lib/jellyfin/config/network.xml (see
# https://github.com/jellyfin/jellyfin/issues/6940):
# <DetectNetworkChange>false</DetectNetworkChange>
{
nixpkgs.config.packageOverrides = pkgs: {
# Apparently adds some hardware acceleration.
intel-vaapi-driver = pkgs.intel-vaapi-driver.override { enableHybridCodec = true; };
};
hardware.graphics = {
enable = true;
# Haswell seems too old to be supported by intel-media-driver (iHD). While
# QSV is apparently implemented for intel-vaapi-driver (i965) by
# intel-media-sdk, Jellyfin seems to only support QSV on iHD.
extraPackages = with pkgs; [ intel-vaapi-driver ];
};
services.jellyfin.enable = true;
services.nginx.virtualHosts."jf.mou.fo" = {
enableACME = true;
forceSSL = true;
locations."/".proxyPass = "http://[::1]:8096";
};
# TODO kavita vs komga?
services.kavita = {
enable = true;
tokenKeyFile = "/var/secrets/kavita.key";
settings = {
Port = 7565;
IpAddresses = "::1";
};
};
services.komga = {
enable = true;
# Cannot override listening on all IPv4 interfaces.
settings.server.port = 7579;
};
# TODO SSO
# systemd.tmpfiles.rules = let
# cfg = pkgs.writeText "application.yml" ''
# spring:
# security:
# oauth2:
# client:
# registration:
# keycloak:
# provider: keycloak # this must match the provider below
# client-id: your-client-id
# client-secret: c830e452-a2a9-40a0-93c1-eb84ea688245
# client-name: Keycloak
# scope: openid,email
# authorization-grant-type: authorization_code
# # the placeholders in {} will be replaced automatically, you don't need to change this line
# redirect-uri: "{baseUrl}/{action}/oauth2/code/{registrationId}"
# provider:
# keycloak: # this must match the provider above
# user-name-attribute: sub
# # either set the issuer-uri, in which case the app will lookup the configuration for you automatically
# issuer-uri: http://localhost:8085/auth/realms/komgatest
# # or set all of the following
# authorization-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/auth
# token-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/token
# jwk-set-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/certs
# user-info-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/userinfo
# '';
# in
# [
# "L+ /var/lib/komga/application.yml - - - - ${cfg}"
# ];
services.nginx.virtualHosts."ka.mou.fo" = {
enableACME = true;
forceSSL = true;
locations."/".proxyPass = "http://127.0.0.1:7579";
};
}
|