From 4a71d7b81260dca99ce3bd2f4697b15e67f80b24 Mon Sep 17 00:00:00 2001 From: sefidel Date: Sat, 9 Dec 2023 21:35:15 +0900 Subject: feat(modules/rss): add rss-bridge --- modules/services/rss.nix | 63 +++++++++++++++++++++++++++++++++--------------- 1 file changed, 44 insertions(+), 19 deletions(-) (limited to 'modules') diff --git a/modules/services/rss.nix b/modules/services/rss.nix index 7c44580..c7fadd3 100644 --- a/modules/services/rss.nix +++ b/modules/services/rss.nix @@ -10,30 +10,55 @@ in domain = mkOption { type = types.str; }; realHost = mkOption { type = types.str; default = "rss.${cfg.domain}"; }; secrets.admin-password = mkOption { type = types.str; description = "path to file containing admin password"; }; + bridge = { + enable = mkEnableOption "RSS Bridge"; + domain = mkOption { type = types.str; default = cfg.domain; }; + realHost = mkOption { type = types.str; default = "rss-bridge.${cfg.bridge.domain}"; }; + whitelist = mkOption { type = types.listOf types.str; default = []; }; + }; }; - config = mkIf cfg.enable { - services.freshrss = { - enable = true; - virtualHost = cfg.realHost; - baseUrl = "https://${cfg.realHost}"; + config = mkIf cfg.enable (mkMerge [ + { + services.freshrss = { + enable = true; + virtualHost = cfg.realHost; + baseUrl = "https://${cfg.realHost}"; - defaultUser = "admin"; - passwordFile = cfg.secrets.admin-password; + defaultUser = "admin"; + passwordFile = cfg.secrets.admin-password; - database = { - type = "pgsql"; - host = "/run/postgresql"; + database = { + type = "pgsql"; + host = "/run/postgresql"; + }; }; - }; - environment.persistence."/persist".directories = [ - "/var/lib/freshrss" - ]; + environment.persistence."/persist".directories = [ + "/var/lib/freshrss" + ]; - services.nginx.virtualHosts.${cfg.realHost} = { - forceSSL = true; - useACMEHost = cfg.domain; - }; - }; + services.nginx.virtualHosts.${cfg.realHost} = { + forceSSL = true; + useACMEHost = cfg.domain; + }; + } + (mkIf cfg.bridge.enable { + services.rss-bridge = { + enable = true; + virtualHost = cfg.bridge.realHost; + } // optionalAttrs (cfg.bridge.whitelist != []) { + whitelist = cfg.bridge.whitelist; + }; + + environment.persistence."/persist".directories = [ + "/var/lib/rss-bridge" + ]; + + services.nginx.virtualHosts.${cfg.bridge.realHost} = { + forceSSL = true; + useACMEHost = cfg.bridge.domain; + }; + }) + ]); } -- cgit 1.4.1