From 3b4607ede54b7607ce3a61a8cbec0062d6404692 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E2=9C=BF=20corey=20=28they/them=29?= Date: Mon, 16 Mar 2026 22:08:44 -0700 Subject: [PATCH 1/3] feat(glyph): add Open Terminal container Adds OpenTerminal (open-webui/open-terminal) as a Podman OCI container on glyph. Enables multi-user mode for per-user isolation with Open WebUI. Co-Authored-By: Claude Opus 4.6 (1M context) --- hosts/glyph/services/default.nix | 1 + hosts/glyph/services/open-terminal.nix | 19 +++++++++++++++++++ lib/secrets/glyph.nix | 1 + 3 files changed, 21 insertions(+) create mode 100644 hosts/glyph/services/open-terminal.nix diff --git a/hosts/glyph/services/default.nix b/hosts/glyph/services/default.nix index a77a6da9..59bc0e8b 100644 --- a/hosts/glyph/services/default.nix +++ b/hosts/glyph/services/default.nix @@ -11,6 +11,7 @@ ./filebrowser.nix ./jellyfin.nix ./nfs.nix + ./open-terminal.nix ./open-webui.nix ./prometheus.nix ./samba.nix diff --git a/hosts/glyph/services/open-terminal.nix b/hosts/glyph/services/open-terminal.nix new file mode 100644 index 00000000..411efbaa --- /dev/null +++ b/hosts/glyph/services/open-terminal.nix @@ -0,0 +1,19 @@ +{config, ...}: { + age.secrets.open-terminal-env = { + file = ./../secrets/open-terminal-env.age; + mode = "440"; + }; + + virtualisation.podman.enable = true; + virtualisation.oci-containers.backend = "podman"; + virtualisation.oci-containers.containers.open-terminal = { + image = "ghcr.io/open-webui/open-terminal:latest"; + ports = ["8000:8000"]; + volumes = ["open-terminal:/home/user"]; + environmentFiles = [config.age.secrets.open-terminal-env.path]; + environment = { + OPEN_TERMINAL_MULTI_USER = "true"; + }; + extraOptions = ["--pull=newer"]; + }; +} diff --git a/lib/secrets/glyph.nix b/lib/secrets/glyph.nix index f45bd768..135a9eec 100644 --- a/lib/secrets/glyph.nix +++ b/lib/secrets/glyph.nix @@ -6,6 +6,7 @@ in { "hosts/glyph/secrets/pushover-user-token.age".publicKeys = keys; "hosts/glyph/secrets/kagi-api-key.age".publicKeys = keys; "hosts/glyph/secrets/context7-api-key.age".publicKeys = keys; + "hosts/glyph/secrets/open-terminal-env.age".publicKeys = keys; "hosts/glyph/secrets/open-webui-env.age".publicKeys = keys; "hosts/glyph/secrets/graphite-auth-token.age".publicKeys = keys; "hosts/glyph/secrets/attic-credentials.age".publicKeys = keys; From 94e3a4871bc7edf607d0403b8ccb4071438e7690 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E2=9C=BF=20corey=20=28they/them=29?= Date: Mon, 16 Mar 2026 22:25:11 -0700 Subject: [PATCH 2/3] define secret --- hosts/glyph/secrets/open-terminal-env.age | 8 ++++++++ 1 file changed, 8 insertions(+) create mode 100644 hosts/glyph/secrets/open-terminal-env.age diff --git a/hosts/glyph/secrets/open-terminal-env.age b/hosts/glyph/secrets/open-terminal-env.age new file mode 100644 index 00000000..745c306e --- /dev/null +++ b/hosts/glyph/secrets/open-terminal-env.age @@ -0,0 +1,8 @@ +age-encryption.org/v1 +-> ssh-ed25519 rSr+rA JKiIcU0UOS9LRURInhjXW3/zifYQc6h0ylG+nG/qs10 +sigqGhEtQKYErUUDcRuov1OalYJuzx76O0FJiUHCKOM +-> ssh-ed25519 3EWhnQ tnANAMEcv2VRxNjTXID5LpX7LdzV/aQQNgTe6mVVnhU +wA/jDKTlpQE8XTEOWuzJ7dQidDw9mITn9dnrNk1tnso +--- vmJelA+19FTGMQlaTrUamU1a6lFoehrLXok10IgGdzU +ïͤÈï‰ Ž*9`c+»7äÂ͹+1ÉQ®s<íê>®–ß«Ùè<½WaóÇW!7ZÀy nžà +­–#ÝdÆc ´©â±äŸV‰1bzDZ#ߪañ‹è†g×kXÑLE0¤;øúyÓý"]I”#ùºåz6Ò \ No newline at end of file From e34eb8ced0c5e2bbdc1a1b38f61cb86c1eb89e96 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E2=9C=BF=20corey=20=28they/them=29?= Date: Tue, 17 Mar 2026 07:21:45 -0700 Subject: [PATCH 3/3] update open-webui env --- hosts/glyph/secrets/open-webui-env.age | Bin 659 -> 889 bytes 1 file changed, 0 insertions(+), 0 deletions(-) diff --git a/hosts/glyph/secrets/open-webui-env.age b/hosts/glyph/secrets/open-webui-env.age index 6b4154489d02b4c50435b41d944f2adac0d21565..598e41371b7e839f19ffc2393faa65175f109e80 100644 GIT binary patch delta 858 zcmV-g1Eu_v1^EV$EPqf}XJke*Q8sojF;rSuI5=!gW>R%GY(p=3Vo7U5cQImWdSX>| zL{(T*YYKNxQZi$5IcY<2d3bR~PIGT-cw}o@S~E6!HEK>TOK>qcNi$e%OJXlrYYHts zAaiqQEoEdfH8n9gATvc*Xl_v;S#okOMn_jcPf1EsNpEj3Pk%{FbZs+DLv(jVaWQo< zQfzc)Fe_<6Qc-SA3OGhqd0JIvP%>(7GFdNrX=_F{Fg0yuHCc9JaCd2Wax`soQF(Jt zaZYnZ3N0-yAZ0LcS5$O*O=Cz{GGs7IQdmV!Fj8$dY)4`+RBLoNM^|P+RYOfhN@g%H z3aIW?7(-L+9)DRoOXhvSM(Z(ue~Y#X)g-c{u%AUG)-kv|L_!Vlm9Dg~xEsO%9@Au$ zjh+xFdw;`rXNxiAKQz|2qCgqn~j+(z`SBe#}P4R(n;s+42D|Xss_=uZn^#aWw33Mm=rk(U?X8UlZM;w8`D~WEVzQ; z&4LG2Q-4{o>>=$M+7|z1>8-OQoLt0svL&kF_%g8$mk!en%f8@I@Jxw z0JU!1eeTFzE&%nmDSGELdITfFu+@{m3;|y)+YFlQ>x|vm+$k5$v8mSX0%hKe^>QYu z*G=O@6V(kY1f7VpKVd!mm$*GU*6LdG;zst}{5~*tio-ijn=E z=|PVcg8G9Rh>6MO65;%%2aNDWd=RiL$u3l+q@0-H!Gz2$_BJ`q^&v>yVhUP6l!DyL z+lb{WowG1-Ycbcw-=ep)`LP9#xg|R{tWv)YhdOp};f*@^^~t-v8!y>8Qj_ kmGpC&sRen88>WhOsMI>1>1MiKLyfv{3e`oB^%0sta8GK0g#Z8m delta 626 zcmV-&0*(Fo29pJlEPrJybY^gEL~&O{baGlkO?o+0R8?9{QY&&*JPGd(x zN>o*DYYIeSNm(y5VN^qUSvYWWNl{vGHflIjN=$8VM|LzeQAcV?cs4gyH(^dxFbXX` zAaiqQEoEdfH8n9gATvc*Xl_v;H%@IsYBEe^Hf3-yGGR(NaDOW}R6{XmNv(#Nrzk|pqg!zcfhnOTTa(@FDxK1lzwu_@E= zHc@h!gKOIRgfo;eFR~A5e)dqQuwJ>kt;R^4EJ$-ar-d8A`_?%fmlHEb-#vJ(CvAwRC>Nnu3Iki M=JIiE@|=ePfw|2JZU6uP