nixos-config/modules/media-proxy.nix

61 lines
1.9 KiB
Nix
Raw Normal View History

{ config, lib, pkgs, ... }:
let
port = 8888;
services = {
"media" = config.sops.secrets.media-proxy-auth.path;
2022-09-23 00:14:45 +02:00
"media-sb" = config.sops.secrets.media-proxy-auth.path;
"torrent" = config.sops.secrets.torrent-proxy-auth.path;
2023-10-04 17:02:16 +02:00
"sturzbach" = config.sops.secrets.torrent-proxy-auth.path;
};
in
{
options.sbruder.media-proxy.enable = lib.mkEnableOption "media proxy";
2021-01-06 13:09:29 +01:00
config = lib.mkIf config.sbruder.media-proxy.enable {
sops.secrets = {
torrent-proxy-auth.owner = "nginx";
media-proxy-auth.owner = "nginx";
2021-01-06 13:09:29 +01:00
};
systemd.services.nginx.serviceConfig.SupplementaryGroups = lib.singleton config.users.groups.keys.name;
2021-01-06 13:09:29 +01:00
# otherwise name resolution fails
systemd.services.nginx.after = [ "network-online.target" ];
2021-01-06 13:09:29 +01:00
services.nginx = {
enable = true;
commonHttpConfig = ''
map $http_referer $media_proxy_referer {
~^http://localhost:8888/ "";
default $http_referer;
}
'';
2021-01-06 13:09:29 +01:00
virtualHosts.media-proxy = {
serverName = "localhost";
listen = [
{ inherit port; addr = "127.0.0.1"; }
{ inherit port; addr = "[::1]"; }
];
locations = {
"/".extraConfig = ''
2021-03-05 16:12:25 +01:00
rewrite ^/__nginx-interactive-index-assets__/(.*)$ /media/__nginx-interactive-index-assets__/$1;
2021-01-06 13:09:29 +01:00
'';
} // lib.mapAttrs'
(name: secret: {
name = "/${name}/";
value = {
proxyPass = "https://${name}.sbruder.de/";
proxyWebsockets = true;
extraConfig = ''
proxy_buffering off;
include ${secret};
charset utf-8;
proxy_set_header Referer $media_proxy_referer;
proxy_set_header Origin $media_proxy_referer;
2021-01-06 13:09:29 +01:00
'';
};
})
services;
};
};
};
}