diff options
author | sefidel <contact@sefidel.net> | 2024-01-24 13:29:27 +0900 |
---|---|---|
committer | sefidel <contact@sefidel.net> | 2024-01-24 18:59:54 +0900 |
commit | 8e9b074467006c76768efe04cf1fb1ef9d652c67 (patch) | |
tree | fad73c7f94a74c77714c260d1fc0a63e2d205b49 /modules/services/rss.nix | |
download | infra-modules-8e9b074467006c76768efe04cf1fb1ef9d652c67.tar.gz infra-modules-8e9b074467006c76768efe04cf1fb1ef9d652c67.zip |
Diffstat (limited to 'modules/services/rss.nix')
-rw-r--r-- | modules/services/rss.nix | 64 |
1 files changed, 64 insertions, 0 deletions
diff --git a/modules/services/rss.nix b/modules/services/rss.nix new file mode 100644 index 0000000..c9663ee --- /dev/null +++ b/modules/services/rss.nix @@ -0,0 +1,64 @@ +{ config, lib, pkgs, ... }: + +with lib; +let + cfg = config.modules.services.rss; +in +{ + options.modules.services.rss = { + enable = mkEnableOption "RSS Aggregator"; + domain = mkOption { type = types.str; }; + realHost = mkOption { type = types.str; default = "rss.${cfg.domain}"; }; + secrets.admin-password = mkOption { type = types.path; description = "path to file containing admin password"; }; + bridge = { + enable = mkEnableOption "RSS Bridge"; + domain = mkOption { type = types.str; default = cfg.domain; }; + realHost = mkOption { type = types.str; default = "rss-bridge.${cfg.bridge.domain}"; }; + whitelist = mkOption { type = types.listOf types.str; default = []; }; + }; + }; + + config = mkIf cfg.enable (mkMerge [ + { + services.freshrss = { + enable = true; + virtualHost = cfg.realHost; + baseUrl = "https://${cfg.realHost}"; + + defaultUser = "admin"; + passwordFile = cfg.secrets.admin-password; + + database = { + type = "pgsql"; + host = "/run/postgresql"; + }; + }; + + modules.persistence.directories = [ + "/var/lib/freshrss" + ]; + + services.nginx.virtualHosts.${cfg.realHost} = { + forceSSL = true; + useACMEHost = cfg.domain; + }; + } + (mkIf cfg.bridge.enable { + services.rss-bridge = { + enable = true; + virtualHost = cfg.bridge.realHost; + } // optionalAttrs (cfg.bridge.whitelist != []) { + whitelist = cfg.bridge.whitelist; + }; + + modules.persistence.directories = [ + "/var/lib/rss-bridge" + ]; + + services.nginx.virtualHosts.${cfg.bridge.realHost} = { + forceSSL = true; + useACMEHost = cfg.bridge.domain; + }; + }) + ]); +} |