-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy patharion-compose.nix
More file actions
70 lines (70 loc) · 1.94 KB
/
Copy patharion-compose.nix
File metadata and controls
70 lines (70 loc) · 1.94 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
{pkgs, ...}: let
inherit (pkgs) lib;
flake = builtins.getFlake (toString ./.);
inherit
(flake)
inputs
;
nixosPath = "${<nixpkgs>}/nixos/";
modulesPath = "${nixosPath}/modules";
util = import ./lib/default.nix {inherit lib pkgs;};
inherit
(util)
mapVals
default
moveSecrets
;
# fixes: Using host resolv.conf is not supported with systemd-resolved
arion-common = {
nixos.useSystemd = true;
service = {
useHostStore = true;
secrets = moveSecrets "/run/container-secrets" {
sops_key = {};
};
};
};
container-common = {
networking.useDHCP = false;
networking.firewall.enable = lib.mkForce false;
systemd.network.enable = lib.mkForce false;
};
in {
project.name = "nixos-container";
secrets = {
"sops_key".file = ../tf-config/keys.txt;
};
# ports: host:container, host must be >=1024, same for container to test by vm
# arion exec NAME bash
services = mapVals (default arion-common) {
combined = {
nixos = {
configuration =
{
imports = let
args = {inherit pkgs lib inputs modulesPath util;};
in [
inputs.sops-nix.nixosModules.default
(import ./servers/common args)
./servers/manual
# ./servers/nextcloud
];
}
// container-common;
};
service = {
# solves fuse error when running containers,
# but also enables firewall and causes some warnings/errors
privileged = true;
# needed by (unless privileged=true): sops-nix (unless sops.useTmpfs), lldap opensearch woodpecker-server
# capabilities.CAP_SYS_ADMIN = true;
ports = lib.lists.map (ports: "127.0.0.1:${ports}") [
"8888:8888" # manual
"8000:80" # nextcloud collabora
"9980:9980" # nextcloud collabora
"1465:465" # nextcloud smtp
];
};
};
};
}