File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1+ { pkgs , ...} : {
2+ users . users . basic-memory = {
3+ isSystemUser = true ;
4+ group = "basic-memory" ;
5+ home = "/var/lib/basic-memory" ;
6+ } ;
7+ users . groups . basic-memory = { } ;
8+
9+ systemd . services . basic-memory = {
10+ description = "basic-memory MCP Server" ;
11+ after = [ "network-online.target" ] ;
12+ wants = [ "network-online.target" ] ;
13+ wantedBy = [ "multi-user.target" ] ;
14+
15+ environment = {
16+ HOME = "/var/lib/basic-memory" ;
17+ BASIC_MEMORY_CONFIG_DIR = "/var/lib/basic-memory" ;
18+ UV_CACHE_DIR = "/var/lib/basic-memory/.cache/uv" ;
19+ } ;
20+
21+ serviceConfig = {
22+ ExecStart = "${ pkgs . uv } /bin/uvx basic-memory mcp --transport streamable-http --port 8091 --host 127.0.0.1" ;
23+ User = "basic-memory" ;
24+ Group = "basic-memory" ;
25+ WorkingDirectory = "/var/lib/basic-memory" ;
26+ StateDirectory = "basic-memory" ;
27+ Restart = "on-failure" ;
28+ RestartSec = 5 ;
29+
30+ # Hardening
31+ NoNewPrivileges = true ;
32+ PrivateDevices = true ;
33+ PrivateTmp = true ;
34+ ProtectHome = true ;
35+ ProtectSystem = "strict" ;
36+ ReadWritePaths = [ "/var/lib/basic-memory" ] ;
37+ ProtectKernelTunables = true ;
38+ ProtectKernelModules = true ;
39+ ProtectControlGroups = true ;
40+ RestrictSUIDSGID = true ;
41+ } ;
42+ } ;
43+ }
Original file line number Diff line number Diff line change 55} : {
66 imports = [
77 ./avahi.nix
8+ ./basic-memory.nix
89 ./dns.nix
910 ./filebrowser.nix
1011 ./jellyfin.nix
You can’t perform that action at this time.
0 commit comments