Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ jobs:
github_access_token: ${{ secrets.GITHUB_TOKEN }}
extra_nix_config: |
extra-substituters = https://cache.zx.dev/main
extra-trusted-public-keys = main:sbkS1Xz6P4g66iyttRGj/o8aPODE6bVG9oKT98/ULKI=
extra-trusted-public-keys = main:mu0jkxdJTGWC3djDSEQb3rvZgqlhA8WVMulcTo5IW6c=
- name: Configure Attic cache
run: |
nix profile install --inputs-from . attic#attic-client
Expand Down
2 changes: 1 addition & 1 deletion flake.nix
Original file line number Diff line number Diff line change
Expand Up @@ -122,7 +122,7 @@
"https://cache.zx.dev/main"
];
extra-trusted-public-keys = [
"main:sbkS1Xz6P4g66iyttRGj/o8aPODE6bVG9oKT98/ULKI="
"main:mu0jkxdJTGWC3djDSEQb3rvZgqlhA8WVMulcTo5IW6c="
];
};
};
Expand Down
9 changes: 2 additions & 7 deletions hosts/glyph/services/attic.nix
Original file line number Diff line number Diff line change
@@ -1,10 +1,5 @@
{config, ...}: {
age.secrets.attic-credentials = {
file = ./../secrets/attic-credentials.age;
mode = "440";
owner = "atticd";
group = "atticd";
};
age.secrets.attic-credentials.file = ./../secrets/attic-credentials.age;

services.atticd = {
enable = true;
Expand All @@ -13,7 +8,7 @@
settings = {
listen = "[::]:8199";

database.url = "sqlite:///var/lib/atticd/server.db?mode=rwc";
database.url = "postgresql:///atticd?host=/run/postgresql";

storage = {
type = "local";
Expand Down
24 changes: 17 additions & 7 deletions hosts/spore/services/db.nix → hosts/glyph/services/db.nix
Original file line number Diff line number Diff line change
@@ -1,15 +1,9 @@
{
config,
pkgs,
...
}: {
{pkgs, ...}: {
services.postgresql = {
enable = true;
package = pkgs.postgresql_16;
enableTCPIP = true;
authentication = pkgs.lib.mkOverride 10 ''
# Any user can connect to any database via Unix socket, local loopback,
# or Tailscale
local all all trust
host all all 127.0.0.1/32 trust
host all all 100.64.0.0/10 trust
Expand All @@ -18,5 +12,21 @@
port = 5432;
max_connections = 150;
};
ensureDatabases = ["atticd" "pocketid"];
ensureUsers = [
{
name = "atticd";
ensureDBOwnership = true;
}
{
name = "pocketid";
ensureDBOwnership = true;
}
];
};

services.postgresqlBackup = {
enable = true;
databases = ["atticd" "pocketid"];
};
}
3 changes: 2 additions & 1 deletion hosts/glyph/services/default.nix
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@
}: {
imports = [
./attic.nix
./db.nix
./avahi.nix
./dns.nix
./filebrowser.nix
Expand Down Expand Up @@ -85,7 +86,7 @@
rc.backup = {
enable = true;
paths = [
"/var/lib/atticd/server.db"
config.services.postgresqlBackup.location
"/var/lib/basic-memory"
"/var/lib/open-webui"
"/var/lib/roon-server/backup"
Expand Down
8 changes: 0 additions & 8 deletions hosts/spore/backup.nix

This file was deleted.

1 change: 0 additions & 1 deletion hosts/spore/default.nix
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,6 @@
(modulesPath + "/installer/scan/not-detected.nix")
(modulesPath + "/profiles/qemu-guest.nix")
./disk-config.nix
./backup.nix
./services
];

Expand Down
1 change: 0 additions & 1 deletion hosts/spore/services/default.nix
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,6 @@
...
}: {
imports = [
./db.nix
./grafana.nix
./homepage-dashboard.nix
./mastodon.nix
Expand Down
16 changes: 2 additions & 14 deletions hosts/spore/services/mastodon.nix
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ in {
configureNginx = true;
database = {
createLocally = false;
host = "127.0.0.1";
host = "glyph.rove-duck.ts.net";
port = 5432;
user = "mastodon";
passwordFile = "/dev/null"; # Not needed
Expand Down Expand Up @@ -84,19 +84,7 @@ in {
];
};

services.postgresql = lib.mkIf enable {
ensureUsers = [
{
name = "mastodon";
ensureDBOwnership = true;
}
];
ensureDatabases = ["mastodon"];
};
services.postgresqlBackup = {
#inherit enable;
databases = ["mastodon"];
};
# Database managed on glyph when re-enabled
services.redis.servers.mastodon = {
inherit enable;
port = 31637;
Expand Down
2 changes: 2 additions & 0 deletions hosts/spore/services/web/auth.nix
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,8 @@
host = "id.zx.dev";
useACMEHost = "zx.dev";
encryptionKeyFile = config.age.secrets.pocket-id-encryption-key.path;
databaseURL = "postgres://pocketid@glyph.rove-duck.ts.net/pocketid";
localDatabase = false;
};
authProxy = {
host = "oauth.zx.dev";
Expand Down
56 changes: 39 additions & 17 deletions modules/nixos/web/auth.nix
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,25 @@ in {
example = "id.example.org";
};

databaseURL = lib.mkOption {
type = lib.types.str;
default = "postgres://pocketid@/pocketid?host=/run/postgresql";
description = ''
PostgreSQL connection string for pocket-id.
'';
example = "postgres://pocketid@glyph.rove-duck.ts.net/pocketid";
};

localDatabase = lib.mkOption {
type = lib.types.bool;
default = true;
description = ''
Whether the database is managed locally. When true, PostgreSQL
is configured with the pocketid database and user, and pocket-id
depends on postgresql.service.
'';
};

encryptionKeyFile = lib.mkOption {
type = lib.types.nullOr lib.types.path;
default = null;
Expand Down Expand Up @@ -122,29 +141,17 @@ in {
settings = {
APP_URL = "https://${cfg.issuer.host}";
TRUST_PROXY = true;
DB_CONNECTION_STRING = "postgres://pocketid@/pocketid?host=/run/postgresql";
DB_CONNECTION_STRING = cfg.issuer.databaseURL;
ENCRYPTION_KEY_FILE = cfg.issuer.encryptionKeyFile;
};
};

services.postgresql = {
ensureDatabases = ["pocketid"];
ensureUsers = [
{
name = "pocketid";
ensureDBOwnership = true;
}
];
};
services.postgresqlBackup = {
enable = lib.mkDefault true;
databases = ["pocketid"];
};

systemd.services.pocket-id = {
wants = ["network-online.target"];
after = ["postgresql.service" "network-online.target"];
requires = ["postgresql.service"];
after =
["network-online.target"]
++ lib.optionals cfg.issuer.localDatabase ["postgresql.service"];
requires = lib.optionals cfg.issuer.localDatabase ["postgresql.service"];
};

services.oauth2-proxy = {
Expand Down Expand Up @@ -205,6 +212,21 @@ in {
};
};
})
(mkIf (cfg.enable && cfg.issuer.localDatabase) {
services.postgresql = {
ensureDatabases = ["pocketid"];
ensureUsers = [
{
name = "pocketid";
ensureDBOwnership = true;
}
];
};
services.postgresqlBackup = {
enable = lib.mkDefault true;
databases = ["pocketid"];
};
})
(let
vhosts = config.services.nginx.virtualHosts;
vhostsRequiringAuth = mapNames (lib.filter (set: set.value.requireAuth) (lib.attrsToList vhosts));
Expand Down