grimm-nix-server/modules/mjolnir.nix

70 lines
1.8 KiB
Nix
Raw Normal View History

2023-12-31 19:06:33 +01:00
{ config, ... } :
let
in {
2024-01-01 09:58:03 +01:00
age.secrets = {
2023-12-31 19:06:33 +01:00
matrix_mjolnir_pass = {
file = ../secrets/matrix_mjolnir_pass.age;
owner = "mjolnir";
group = "mjolnir";
mode = "0600";
};
2024-01-01 09:58:03 +01:00
matrix_mjolnir_tle_pass = {
file = ../secrets/matrix_mjolnir_tle_pass.age;
2023-12-31 19:06:33 +01:00
owner = "mjolnir";
group = "mjolnir";
2024-01-01 09:58:03 +01:00
mode = "0777"; # not ideal, but containers are weird
2023-12-31 19:06:33 +01:00
};
};
2024-01-01 09:58:03 +01:00
# global mjolnir
2023-12-31 19:06:33 +01:00
services.mjolnir = {
enable = true;
homeserverUrl = config.services.matrix-synapse-next.settings.public_baseurl;
protectedRooms = [
"https://matrix.to/#/!zDkrFrfuMIKbqYFbFv:grimmauld.de"
];
managementRoom = "!kgfXXqEYHGgToIwhMP:grimmauld.de";
pantalaimon = {
enable = true;
username = "mjolnir";
options = {
homeserver = config.services.matrix-synapse-next.settings.public_baseurl;
};
passwordFile = config.age.secrets.matrix_mjolnir_pass.path;
};
};
2024-01-01 09:58:03 +01:00
2024-01-26 10:14:45 +01:00
services.logrotate.checkConfig = false; # needed or this explodes
2024-01-01 09:58:03 +01:00
containers.mjolnirtle = let
baseurl = config.services.matrix-synapse-next.settings.public_baseurl;
pass_file = config.age.secrets.matrix_mjolnir_tle_pass.path;
in {
privateNetwork = false; # don't want nat
autoStart = true;
bindMounts."${pass_file}".isReadOnly = true;
config = { config, ... }: {
system.stateVersion = "unstable";
# tle mjolnir
2024-01-26 10:14:45 +01:00
services.logrotate.checkConfig = false;
2024-01-01 09:58:03 +01:00
services.mjolnir = {
enable = true;
homeserverUrl = baseurl;
protectedRooms = [
"https://matrix.to/#/!BgDBnHgMgilMMnPMyp:grimmauld.de"
];
managementRoom = "!NQedmlMeoQErGgAwxm:grimmauld.de";
pantalaimon = {
enable = true;
username = "mjolnir_tle";
options = {
homeserver = baseurl;
};
passwordFile = pass_file;
};
};
};
};
2023-12-31 19:06:33 +01:00
}