summaryrefslogtreecommitdiff
path: root/hostnix/elmo/media.nix
blob: 53fa0d22f036fd8320219d6797f6e741253a331f (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
{ pkgs, ... }:

# https://nixos.wiki/wiki/Jellyfin
#
# Manual configuration:
# - Create joe and guest users
# - Administration: Dashboard > Advanced: Networking
#   - Bind to local network address: ::1
#   - Enable IPv6
# - Add line to /var/lib/jellyfin/config/network.xml (see
#   https://github.com/jellyfin/jellyfin/issues/6940):
#     <DetectNetworkChange>false</DetectNetworkChange>

{
  nixpkgs.config.packageOverrides = pkgs: {
    # Apparently adds some hardware acceleration.
    intel-vaapi-driver = pkgs.intel-vaapi-driver.override { enableHybridCodec = true; };
  };

  hardware.graphics = {
    enable = true;
    # Haswell seems too old to be supported by intel-media-driver (iHD). While
    # QSV is apparently implemented for intel-vaapi-driver (i965) by
    # intel-media-sdk, Jellyfin seems to only support QSV on iHD.
    extraPackages = with pkgs; [ intel-vaapi-driver ];
  };

  services.jellyfin.enable = true;

  services.nginx.virtualHosts."jf.mou.fo" = {
    enableACME = true;
    forceSSL = true;
    locations."/".proxyPass = "http://[::1]:8096";
  };

  services.ytdl-sub.instances.main = {
    enable = true;
    # TODO schedule = null;
    config = {
      presets = {
        "YouTube Channel" = {
          preset = [
            "Jellyfin TV Show by Date"
            "Max 1080p"
          ];
          overrides = {
            tv_show_directory = "/srv/media/incoming/YouTube";
            date_range_after = "20240101";  # arbitrarily early default
          };
          embed_thumbnail = true;
          subtitles = {
            embed_subtitles = true;
            allow_auto_generated_subtitles = true;
          };
          chapters = {
            embed_chapters = true;
            sponsorblock_categories = [ "all" ];
          };
          date_range = {
            after = "{date_range_after}";
            before = "today-2days";
          };
          ytdl_options = {
            break_on_existing = true;
          };
        };
      };
    };
    subscriptions = {
      "YouTube Channel" = {
        "~Moon Channel" = {
          url = "https://www.youtube.com/@moon-channel";
          date_range_after = "20241201";
        };
      };
    };
  };

  # TODO kavita vs komga?
  services.kavita = {
    enable = true;
    tokenKeyFile = "/var/secrets/kavita.key";
    settings = {
      Port = 7565;
      IpAddresses = "::1";
    };
  };

  services.komga = {
    enable = true;
    # Cannot override listening on all IPv4 interfaces.
    settings.server.port = 7579;
  };

  # TODO SSO
  # systemd.tmpfiles.rules = let
  #   cfg = pkgs.writeText "application.yml" ''
  #     spring:
  #       security:
  #         oauth2:
  #           client:
  #             registration:
  #               keycloak:
  #                 provider: keycloak # this must match the provider below
  #                 client-id: your-client-id
  #                 client-secret: c830e452-a2a9-40a0-93c1-eb84ea688245
  #                 client-name: Keycloak
  #                 scope: openid,email
  #                 authorization-grant-type: authorization_code
  #                 # the placeholders in {} will be replaced automatically, you don't need to change this line
  #                 redirect-uri: "{baseUrl}/{action}/oauth2/code/{registrationId}"
  #             provider:
  #               keycloak: # this must match the provider above
  #                 user-name-attribute: sub
  #                 # either set the issuer-uri, in which case the app will lookup the configuration for you automatically
  #                 issuer-uri: http://localhost:8085/auth/realms/komgatest
  #                 # or set all of the following
  #                 authorization-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/auth
  #                 token-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/token
  #                 jwk-set-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/certs
  #                 user-info-uri: http://localhost:8085/auth/realms/komgatest/protocol/openid-connect/userinfo
  #   '';
  # in
  # [
  #   "L+ /var/lib/komga/application.yml - - - - ${cfg}"
  # ];

  services.nginx.virtualHosts."ka.mou.fo" = {
    enableACME = true;
    forceSSL = true;
    locations."/".proxyPass = "http://127.0.0.1:7579";
  };
}