diff options
| author | Collin Williams <96917990+bluedragon1221@users.noreply.github.com> | 2026-02-23 15:09:58 -0600 |
|---|---|---|
| committer | Collin Williams <96917990+bluedragon1221@users.noreply.github.com> | 2026-02-23 15:09:58 -0600 |
| commit | d2747292dff98c64b974bdfe6b46bc62252298de (patch) | |
| tree | eec31506ba7e7b66888b4b05cb7d9fe720a2e42d /modules/services/options.nix | |
| parent | 66232d31d1f115a796dc76a9f6df88a6b13c424e (diff) | |
clean up services
Diffstat (limited to 'modules/services/options.nix')
| -rw-r--r-- | modules/services/options.nix | 219 |
1 files changed, 112 insertions, 107 deletions
diff --git a/modules/services/options.nix b/modules/services/options.nix index 0e250ed..eb88e21 100644 --- a/modules/services/options.nix +++ b/modules/services/options.nix @@ -3,132 +3,137 @@ my-lib, ... }: let - inherit (lib) mkOption mkEnableOption; + inherit (lib) mkOption mkEnableOption types; inherit (my-lib.netTypes {inherit lib;}) ipAddr; - selfhostOptions = { + # A helper function to generate the submodule + webserviceOptions = { service_name, default_port ? null, - }: { - enable = mkEnableOption "${service_name} selfhosted service"; - serviceName = mkOption { - internal = true; - type = lib.types.str; - default = service_name; - }; - port = mkOption { - description = "The port on which ${service_name} will listen for incomming connections"; - type = lib.types.port; - default = default_port; - }; - listenAddr = mkOption { - description = "The IP address on which ${service_name} will listen for incoming connections"; - type = ipAddr; - default = "127.0.0.1"; - }; - privateUrl = mkOption { - description = "Internal .local name for the service. Don't put the protocol (https://) in the string"; - type = lib.types.nullOr lib.types.str; - default = null; - }; - publicUrl = mkOption { - description = "Public website on which the service will be hosted. Don't put the protocol (https://) in the string"; - type = lib.types.nullOr lib.types.str; - default = null; - }; - }; + reverse_proxy ? true, + }: + { + enable = mkEnableOption "${service_name} selfhosted service"; + listenAddr = mkOption { + description = "The IP address on which ${service_name} will listen for incoming connections"; + type = ipAddr; + default = "127.0.0.1"; + }; + privateUrl = mkOption { + description = "Internal .local name for the service. Don't put the protocol (https://) in the string"; + type = lib.types.nullOr lib.types.str; + default = null; + }; + publicUrl = mkOption { + description = "Public website on which the service will be hosted. Don't put the protocol (https://) in the string"; + type = lib.types.nullOr lib.types.str; + default = null; + }; + } + // ( + if reverse_proxy + then { + reverseProxy = mkOption { + internal = true; + type = lib.types.bool; + default = true; + }; + port = mkOption { + description = "The port on which ${service_name} will listen for incomming connections"; + type = lib.types.port; + default = default_port; + }; + } + else { + manualCaddyConfig = mkOption { + description = "Configuration to describe this service in caddy, since reverse_proxy = false."; + type = lib.types.str; + }; + } + ); in { - options = { - collinux.services = { - sshd = { - enable = mkEnableOption "OpenSSH server"; + options.collinux.services = { + sshd = { + enable = mkEnableOption "OpenSSH server"; - portConfig = mkOption { - description = "List of ssh bind hosts. see submodule options for details"; - type = lib.types.listOf (lib.types.submodule { - options = { - port = mkOption { - description = "Port to run on"; - type = lib.types.port; - }; - - listenAddr = mkOption { - description = "Address to listen on"; - type = lib.types.str; - default = "127.0.0.1"; - }; + portConfig = mkOption { + description = "List of ssh bind hosts. see submodule options for details"; + type = lib.types.listOf (lib.types.submodule { + options = { + port = mkOption { + description = "Port to run on"; + type = lib.types.port; + }; - otp = mkEnableOption "Whether to require TOTP (Google Authenticator) 2fa codes for this port"; - rootLogin = mkEnableOption "Whether to allow root login for this port"; + listenAddr = mkOption { + description = "Address to listen on"; + type = lib.types.str; + default = "127.0.0.1"; }; - }); - }; - }; - forgejo = selfhostOptions { - service_name = "forgejo"; - default_port = 8010; + otp = mkEnableOption "Whether to require TOTP (Google Authenticator) 2fa codes for this port"; + rootLogin = mkEnableOption "Whether to allow root login for this port"; + }; + }); }; + }; - goaccess.enable = mkEnableOption "GoAccess Real-Time Analytics"; + forgejo = webserviceOptions { + service_name = "forgejo"; + default_port = 8010; + }; - cgit.enable = mkEnableOption "cgit web git frontend"; + goaccess = webserviceOptions { + service_name = "goaccess"; + reverse_proxy = false; + }; - # mopidy = { - # enable = mkEnableOption "Mopidy MPD server"; - # port = mkOption { - # description = "port to run the service on"; - # type = lib.types.port; - # default = 6600; - # }; - # }; + cgit = webserviceOptions { + service_name = "cgit"; + reverse_proxy = false; + }; - polaris = selfhostOptions { - service_name = "polaris"; - default_port = 8079; - }; + polaris = webserviceOptions { + service_name = "polaris"; + default_port = 8079; + }; - copyparty = - (selfhostOptions { - service_name = "copyparty"; - default_port = 8099; - }) - // { - users = mkOption { - type = lib.types.attrsOf (lib.types.submodule ({config, ...}: { - options = { - name = mkOption { - type = lib.types.str; - default = config._module.args.name; - internal = true; - }; - isAdmin = mkEnableOption "whether this user is an admin"; - passwordFile = mkOption { - description = "Absolute path to a file containing the password for this user"; - type = lib.types.str; - example = "/run/secrets.d/copyparty-passwd"; - }; - hasPublicDir = mkEnableOption "give this user a world-readable directory at /public/<username>"; - }; - })); - }; - }; + qbittorrent = webserviceOptions { + service_name = "qbittorrent"; + default_port = 8076; + }; - ngircd = { - enable = mkEnableOption "IRC Server"; - port = mkOption { - type = lib.types.port; - default = 6667; + copyparty = + (webserviceOptions { + service_name = "copyparty"; + default_port = 8099; + }) + // { + users = mkOption { + type = lib.types.attrsOf (lib.types.submodule ({config, ...}: { + options = { + name = mkOption { + type = lib.types.str; + default = config._module.args.name; + internal = true; + }; + isAdmin = mkEnableOption "whether this user is an admin"; + passwordFile = mkOption { + description = "Absolute path to a file containing the password for this user"; + type = lib.types.str; + example = "/run/secrets.d/copyparty-passwd"; + }; + hasPublicDir = mkEnableOption "give this user a world-readable directory at /public/<username>"; + }; + })); }; }; - caddy = { - enable = mkEnableOption "caddy https server"; - envFile = mkOption { - description = "Absolute path to file that contains environment variables for caddy operations"; - type = lib.types.str; - example = "/run/secrets.d/caddy-env"; - }; + caddy = { + enable = mkEnableOption "caddy https server"; + envFile = mkOption { + type = types.str; + example = "/run/secrets.d/caddy-env"; }; }; }; |
