diff --git a/aspects/hosts/_alexandria/freshrss.nix b/aspects/hosts/_alexandria/freshrss.nix deleted file mode 100644 index b5880d5..0000000 --- a/aspects/hosts/_alexandria/freshrss.nix +++ /dev/null @@ -1,34 +0,0 @@ -{ - config, - lib, - inputs, - ... -}: - -let - mkNginxVHosts = inputs.self.lib.mkNginxVHosts; -in - -{ - services = { - freshrss = { - enable = true; - defaultUser = "admin"; - passwordFile = config.age.secrets.freshrss-adminpass.path; - baseUrl = "https://rss.baduhai.dev"; - dataDir = "/data/freshrss"; - webserver = "nginx"; - virtualHost = "rss.baduhai.dev"; - }; - - nginx.virtualHosts = mkNginxVHosts { - domains."rss.baduhai.dev" = { }; - }; - }; - - age.secrets.freshrss-adminpass = { - file = "${inputs.self}/secrets/freshrss-adminpass.age"; - owner = "freshrss"; - group = "freshrss"; - }; -} diff --git a/aspects/hosts/_alexandria/miniflux.nix b/aspects/hosts/_alexandria/miniflux.nix new file mode 100644 index 0000000..ca68492 --- /dev/null +++ b/aspects/hosts/_alexandria/miniflux.nix @@ -0,0 +1,38 @@ +{ + config, + lib, + inputs, + ... +}: + +let + mkNginxVHosts = inputs.self.lib.mkNginxVHosts; +in + +{ + services = { + miniflux = { + enable = true; + config = { + LISTEN_ADDR = "/run/miniflux/miniflux.sock"; + CREATE_ADMIN = 1; + }; + adminCredentialsFile = config.age.secrets.miniflux-admincreds.path; + createDatabaseLocally = true; + }; + + nginx.virtualHosts = mkNginxVHosts { + domains."rss.baduhai.dev" = { + locations."/".proxyPass = "http://unix:/run/miniflux/miniflux.sock:/"; + }; + }; + }; + + users.users.nginx.extraGroups = [ "miniflux" ]; + + age.secrets.miniflux-admincreds = { + file = "${inputs.self}/secrets/miniflux-admincreds.age"; + owner = "miniflux"; + group = "miniflux"; + }; +} diff --git a/data/services.nix b/data/services.nix index b3eddf5..9f04d89 100644 --- a/data/services.nix +++ b/data/services.nix @@ -34,7 +34,7 @@ host = "alexandria"; } { - name = "freshrss"; + name = "miniflux"; domain = "rss.baduhai.dev"; host = "alexandria"; } diff --git a/secrets/freshrss-adminpass.age b/secrets/freshrss-adminpass.age deleted file mode 100644 index b7d7c90..0000000 Binary files a/secrets/freshrss-adminpass.age and /dev/null differ diff --git a/secrets/miniflux-admincreds.age b/secrets/miniflux-admincreds.age new file mode 100644 index 0000000..f5269f0 --- /dev/null +++ b/secrets/miniflux-admincreds.age @@ -0,0 +1,9 @@ +age-encryption.org/v1 +-> ssh-ed25519 Kfdnog QEq4A011oVny6vo1+wOcQNnpkf77216PZXJqK4rGTGY +FPeASmXRirxeF2T2jXhA/tEaO0p1CZJ6D3lv3p2KTX0 +-> ssh-ed25519 8YSAiw gxuXAt2nG6qXhWwAAiFwNCNYJV2VGKnDNkjU61NOJ2o +xncp+M4lVixiTmXQU5QrtdQ860t/1JpvOcO4YXAy3to +-> ssh-ed25519 J6tVTA Mr0XrEFP/o7nFWBKal+ehzMiejWpVDIBiiMqWzdOzEM +0DTqm2LyMMlVZlTk67Y3hTiVjcJG9gprnXj6QjYxrJw +--- FXUNp6O7vuibJj0RI3SZN3IBK1Hx5ouUij2ah05lCYA +X*0B3jb͏SVbBciD.5\`&`越-Ui"gХȊ`O Gc'=@qn[ \ No newline at end of file diff --git a/secrets/secrets.nix b/secrets/secrets.nix index 277d880..d052896 100644 --- a/secrets/secrets.nix +++ b/secrets/secrets.nix @@ -32,7 +32,7 @@ in rotterdam-user trantor ]; - "freshrss-adminpass.age".publicKeys = [ + "miniflux-admincreds.age".publicKeys = [ io-user rotterdam-user alexandria