Rename modules directory system to nixos

This commit is contained in:
SebastianStork 2026-02-26 21:11:45 +01:00
parent 653a6f310b
commit 1c1b9221fc
Signed by: SebastianStork
SSH key fingerprint: SHA256:tRrGdjYOwgHxpSc/wTOZQZEjxcb15P0tyXRsbAfd+2Q
48 changed files with 1 additions and 1 deletions

View file

@ -0,0 +1,62 @@
{ config, lib, ... }:
let
cfg = config.custom.web-services.karakeep;
in
{
options.custom.web-services.karakeep = {
enable = lib.mkEnableOption "";
domain = lib.mkOption {
type = lib.types.nonEmptyStr;
default = "";
};
port = lib.mkOption {
type = lib.types.port;
default = 18195;
};
};
config = lib.mkIf cfg.enable {
sops = {
secrets."karakeep/openai-api-key" = { };
templates."karakeep.env" = {
content = "OPENAI_API_KEY=${config.sops.placeholder."karakeep/openai-api-key"}";
owner = config.users.users.karakeep.name;
restartUnits = [ "karakeep-web.service" ];
};
};
services.karakeep = {
enable = true;
environmentFile = config.sops.templates."karakeep.env".path;
extraEnvironment = {
PORT = toString cfg.port;
DISABLE_NEW_RELEASE_CHECK = "true";
OCR_LANGS = "eng,deu";
};
};
users = {
users.meilisearch = {
isSystemUser = true;
group = config.users.groups.meilisearch.name;
};
groups.meilisearch = { };
};
systemd.services.meilisearch.serviceConfig = {
DynamicUser = lib.mkForce false;
User = config.users.users.meilisearch.name;
Group = config.users.groups.meilisearch.name;
ReadWritePaths = lib.mkForce [ ];
};
custom = {
services.caddy.virtualHosts.${cfg.domain}.port = cfg.port;
persistence.directories = [
"/var/lib/karakeep"
"/var/lib/meilisearch"
];
};
};
}