From 9561853d2c5c18749dd7d8d3eca25a360e2d8dfe Mon Sep 17 00:00:00 2001 From: Collin Williams <96917990+bluedragon1221@users.noreply.github.com> Date: Fri, 6 Mar 2026 09:34:57 -0600 Subject: Add copilot-api package and service - Package copilot-api (GitHub Copilot API proxy) using bun - Create systemd service module for copilot-api - Enable service on ganymede listening on localhost:4141 - Add SSH port forwarding from mercury to ganymede for copilot-api - Update gitignore to exclude Claude Code artifacts Co-Authored-By: Claude (claude-sonnet-4.5) --- modules/services/nixos/copilot-api.nix | 62 ++++++++++++++++++++++++++++++++++ modules/services/nixos/default.nix | 1 + 2 files changed, 63 insertions(+) create mode 100644 modules/services/nixos/copilot-api.nix (limited to 'modules/services/nixos') diff --git a/modules/services/nixos/copilot-api.nix b/modules/services/nixos/copilot-api.nix new file mode 100644 index 0000000..d9d4da3 --- /dev/null +++ b/modules/services/nixos/copilot-api.nix @@ -0,0 +1,62 @@ +{ + config, + lib, + pkgs, + ... +}: let + cfg = config.collinux.services.copilot-api; +in { + config = lib.mkIf cfg.enable { + users.groups."copilot-api" = {}; + users.users."copilot-api" = { + isSystemUser = true; + group = "copilot-api"; + home = "/var/lib/copilot-api"; + createHome = true; + }; + + systemd.services."copilot-api" = { + description = "GitHub Copilot API Proxy"; + restartIfChanged = true; + wants = ["network-online.target"]; + after = ["network-online.target"]; + wantedBy = ["multi-user.target"]; + + serviceConfig = { + User = "copilot-api"; + Group = "copilot-api"; + Type = "simple"; + Restart = "on-failure"; + RestartSec = "5s"; + + # Load environment variables from file (e.g., GH_TOKEN) + EnvironmentFile = lib.mkIf (cfg.githubToken != null) cfg.githubToken; + + # Security hardening + PrivateTmp = true; + ProtectSystem = "strict"; + ProtectHome = true; + NoNewPrivileges = true; + PrivateDevices = true; + ProtectKernelTunables = true; + ProtectControlGroups = true; + RestrictSUIDSGID = true; + + # Allow writing to state directory + StateDirectory = "copilot-api"; + WorkingDirectory = "/var/lib/copilot-api"; + + ExecStart = let + copilot-api = pkgs.callPackage ../../../pkgs/copilot-api {}; + # Use bash to read token from environment and pass to command + startScript = pkgs.writeShellScript "copilot-api-start" '' + exec ${copilot-api}/bin/copilot-api start \ + --port ${toString cfg.port} \ + --host ${cfg.listenAddr} \ + ${lib.optionalString (cfg.githubToken != null) "--github-token \"$GH_TOKEN\""} + ''; + in "${startScript}"; + }; + }; + }; +} diff --git a/modules/services/nixos/default.nix b/modules/services/nixos/default.nix index d0e170c..3533908 100644 --- a/modules/services/nixos/default.nix +++ b/modules/services/nixos/default.nix @@ -15,5 +15,6 @@ ./minecraft.nix ./copyparty.nix ./qbittorrent.nix + ./copilot-api.nix ]; } -- cgit v1.3.1