flake/systems/etna/default.nix

153 lines
3.5 KiB
Nix
Raw Normal View History

2024-03-03 16:57:20 +01:00
{
config,
pkgs,
...
}: {
2024-02-02 15:20:48 +01:00
age.secrets = let
path = ../../secrets/etna;
in {
tunnelCreds = {
file = "${path}/tunnelCreds.age";
owner = "cloudflared";
group = "cloudflared";
};
apiRsEnv.file = "${path}/apiRsEnv.age";
2024-02-02 16:20:46 +01:00
ukubotRsEnv.file = "${path}/ukubotRsEnv.age";
2024-02-17 15:15:15 +01:00
ngrokEnv.file = "${path}/ngrokEnv.age";
2024-03-06 22:50:31 +01:00
minecraftEnv.file = "${path}/minecraftEnv.age";
2024-02-02 15:20:48 +01:00
};
2024-01-18 17:28:47 +01:00
boot.loader.systemd-boot.enable = true;
2024-02-02 15:20:48 +01:00
2024-03-06 22:50:31 +01:00
networking.firewall.allowedTCPPorts = [4040];
2024-02-02 15:20:48 +01:00
services = {
api-rs = {
enable = true;
environmentFile = config.age.secrets.apiRsEnv.path;
};
2024-02-02 16:20:46 +01:00
ukubot-rs = {
enable = true;
environmentFile = config.age.secrets.ukubotRsEnv.path;
};
2024-02-03 21:55:58 +01:00
reposilite.enable = true;
2024-02-14 15:59:20 +01:00
tailscale.extraUpFlags = ["--advertise-exit-node"];
2024-02-03 16:19:55 +01:00
vaultwarden = {
enable = true;
config = {
DOMAIN = "https://bw.uku3lig.net";
SIGNUPS_ALLOWED = false;
ROCKET_ADDRESS = "::1";
ROCKET_PORT = 8222;
};
};
2024-03-10 15:02:00 +01:00
cron = {
enable = true;
systemCronJobs = [
"0 3 * * * systemctl restart podman-minecraft.service >> /data/minecraft/cronout 2>&1"
];
};
2024-03-03 16:57:20 +01:00
matrix-conduit = {
enable = true;
settings.global = {
server_name = "m.uku.moe";
allow_registration = true;
port = 6167;
};
};
2024-03-06 22:50:31 +01:00
frp = {
enable = true;
role = "client";
settings = {
2024-03-24 15:58:19 +01:00
serverAddr = "49.13.148.129";
2024-03-06 22:50:31 +01:00
serverPort = 7000;
proxies = [
{
name = "minecraft";
type = "tcp";
localIp = "127.0.0.1";
localPort = 25565;
remotePort = 6000;
}
];
};
};
2024-02-02 15:20:48 +01:00
cloudflared = {
enable = true;
tunnels."57f51ad7-25a0-45f3-b113-0b6ae0b2c3e5" = {
credentialsFile = config.age.secrets.tunnelCreds.path;
ingress = {
"api.uku3lig.net" = "http://localhost:5000";
2024-02-03 16:19:55 +01:00
"bw.uku3lig.net" = "http://localhost:8222";
2024-02-03 21:55:58 +01:00
"maven.uku3lig.net" = "http://localhost:8080";
2024-03-03 16:57:20 +01:00
"m.uku.moe" = "http://localhost:80";
2024-02-02 15:20:48 +01:00
};
default = "http_status:404";
};
};
2024-03-03 16:57:20 +01:00
nginx = {
enable = true;
recommendedProxySettings = true;
virtualHosts."m.uku.moe" = {
locations."=/.well-known/matrix/server" = let
filename = "server-well-known";
content = builtins.toJSON {"m.server" = "m.uku.moe:443";};
in {
alias = builtins.toString (pkgs.writeTextDir filename content) + "/";
tryFiles = "${filename} =200";
extraConfig = ''
default_type application/json;
'';
};
locations."/" = {
proxyPass = "http://localhost:6167/";
proxyWebsockets = true;
extraConfig = ''
proxy_set_header Host $host;
proxy_buffering off;
client_max_body_size 100M;
'';
};
};
};
2024-02-02 15:20:48 +01:00
};
2024-03-06 22:50:31 +01:00
virtualisation.oci-containers.containers = {
"minecraft" = {
image = "itzg/minecraft-server";
ports = ["25565:25565"];
volumes = [
"/data/minecraft:/data"
"/data/downloads:/downloads"
];
environmentFiles = [
config.age.secrets.minecraftEnv.path
];
environment = {
EULA = "true";
2024-03-16 10:25:18 +01:00
MEMORY = "16G";
USE_AIKAR_FLAGS = "true";
2024-03-06 22:50:31 +01:00
TYPE = "AUTO_CURSEFORGE";
CF_SLUG = "all-the-mods-8";
CF_FILE_ID = "4962718";
};
};
};
2024-01-18 15:15:14 +01:00
}