Skyler Grey | fe1740c | 2023-10-21 01:24:18 +0000 | [diff] [blame] | 1 | { config, pkgs, lib, ... }: { |
| 2 | sops.secrets.clicks_nextcloud_db_password = { |
| 3 | mode = lib.mkForce "0440"; |
| 4 | group = lib.mkForce "nextcloud"; |
| 5 | }; |
Skyler Grey | 09c5cda | 2023-10-09 07:10:10 +0000 | [diff] [blame] | 6 | |
Skyler Grey | fe1740c | 2023-10-21 01:24:18 +0000 | [diff] [blame] | 7 | users.users.nextcloud = { |
| 8 | isSystemUser = true; |
| 9 | createHome = true; |
| 10 | home = "/var/lib/nextcloud"; |
| 11 | group = config.users.groups.nextcloud.name; |
| 12 | shell = pkgs.bashInteractive; |
| 13 | }; |
| 14 | users.groups.nextcloud = { }; |
Skyler Grey | 09c5cda | 2023-10-09 07:10:10 +0000 | [diff] [blame] | 15 | |
Skyler Grey | fe1740c | 2023-10-21 01:24:18 +0000 | [diff] [blame] | 16 | services.nextcloud.enable = true; |
Skyler Grey | 4259e93 | 2023-10-21 21:37:03 +0000 | [diff] [blame] | 17 | services.nextcloud.https = true; |
Skyler Grey | fe1740c | 2023-10-21 01:24:18 +0000 | [diff] [blame] | 18 | services.nextcloud.config.adminpassFile = |
| 19 | config.sops.secrets.nextcloud_admin_password.path; |
| 20 | services.nextcloud.hostName = "nextcloud.clicks.codes"; |
Skyler Grey | 4259e93 | 2023-10-21 21:37:03 +0000 | [diff] [blame] | 21 | services.nginx.virtualHosts.${config.services.nextcloud.hostName} = { |
| 22 | enableACME = true; |
| 23 | forceSSL = true; |
| 24 | }; |
Skyler Grey | fe1740c | 2023-10-21 01:24:18 +0000 | [diff] [blame] | 25 | services.nextcloud.package = pkgs.nextcloud27; |
| 26 | services.nextcloud.poolSettings = { |
| 27 | pm = "dynamic"; |
| 28 | "pm.max_children" = "32"; |
| 29 | "pm.max_requests" = "500"; |
| 30 | "pm.max_spare_servers" = "4"; |
| 31 | "pm.min_spare_servers" = "2"; |
| 32 | "pm.start_servers" = "2"; |
| 33 | "listen.owner" = config.users.users.nextcloud.name; |
| 34 | "listen.group" = config.users.users.nextcloud.group; |
| 35 | }; |
Skyler Grey | 09c5cda | 2023-10-09 07:10:10 +0000 | [diff] [blame] | 36 | |
Skyler Grey | fe1740c | 2023-10-21 01:24:18 +0000 | [diff] [blame] | 37 | services.nextcloud.config = { |
| 38 | dbtype = "pgsql"; |
| 39 | dbport = config.services.postgresql.port; |
| 40 | dbpassFile = config.sops.secrets.clicks_nextcloud_db_password.path; |
| 41 | dbname = "nextcloud"; |
| 42 | dbhost = "localhost"; |
Skyler Grey | 4259e93 | 2023-10-21 21:37:03 +0000 | [diff] [blame] | 43 | extraTrustedDomains = [ "cloud.clicks.codes" "docs.clicks.codes" ]; |
Skyler Grey | fe1740c | 2023-10-21 01:24:18 +0000 | [diff] [blame] | 44 | }; |
Skyler Grey | 09c5cda | 2023-10-09 07:10:10 +0000 | [diff] [blame] | 45 | |
Skyler Grey | fe1740c | 2023-10-21 01:24:18 +0000 | [diff] [blame] | 46 | services.nextcloud.extraOptions = { social_login_auto_redirect = true; }; |
Skyler Grey | 09c5cda | 2023-10-09 07:10:10 +0000 | [diff] [blame] | 47 | |
Skyler Grey | fe1740c | 2023-10-21 01:24:18 +0000 | [diff] [blame] | 48 | services.nextcloud.extraApps = { |
| 49 | sociallogin = pkgs.fetchNextcloudApp { |
| 50 | url = |
| 51 | "https://github.com/zorn-v/nextcloud-social-login/releases/download/v5.5.3/release.tar.gz"; |
| 52 | sha256 = "sha256-96/wtK7t23fXVRcntDONjgb5bYtZuaNZzbvQCa5Gsj4="; |
Skyler Grey | 9ae213d | 2023-10-10 23:43:29 +0000 | [diff] [blame] | 53 | }; |
Skyler Grey | fe1740c | 2023-10-21 01:24:18 +0000 | [diff] [blame] | 54 | richdocumentscode = pkgs.fetchNextcloudApp { |
| 55 | url = "redacted"; |
| 56 | sha256 = "sha256-XYtjBZCIQ6+PL3BNLSZfJTgLLpOyphzR5HOAwI7bWx0="; |
| 57 | }; |
| 58 | richdocuments = pkgs.fetchNextcloudApp { |
| 59 | url = |
| 60 | "https://github.com/nextcloud-releases/richdocuments/releases/download/v8.2.0/richdocuments-v8.2.0.tar.gz"; |
| 61 | sha256 = "sha256-PKw7FXSWvden2+6XjnUDOvbTF71slgeTF/ktS/l2+Dk="; |
| 62 | }; |
Skyler Grey | a0f4452 | 2023-10-24 17:40:40 +0000 | [diff] [blame^] | 63 | calendar = pkgs.fetchNextcloudApp { |
| 64 | url = |
| 65 | "https://github.com/nextcloud-releases/calendar/releases/download/v4.5.2/calendar-v4.5.2.tar.gz"; |
| 66 | sha256 = "sha256-n7GjgAyw2SLoZTEfakmI3IllWUk6o1MF89Zt3WGhR6A="; |
| 67 | }; |
| 68 | contacts = pkgs.fetchNextcloudApp { |
| 69 | url = |
| 70 | "https://github.com/nextcloud-releases/contacts/releases/download/v5.4.2/contacts-v5.4.2.tar.gz"; |
| 71 | sha256 = "sha256-IkKHJ3MY/UPZqa4H86WGOEOypffMIHyJ9WvMqkq/4t8="; |
| 72 | }; |
Skyler Grey | fe1740c | 2023-10-21 01:24:18 +0000 | [diff] [blame] | 73 | }; |
Skyler Grey | 9ae213d | 2023-10-10 23:43:29 +0000 | [diff] [blame] | 74 | |
Skyler Grey | fe1740c | 2023-10-21 01:24:18 +0000 | [diff] [blame] | 75 | sops.secrets.nextcloud_admin_password = { |
| 76 | mode = "0600"; |
| 77 | owner = config.users.users.nextcloud.name; |
| 78 | group = config.users.users.nextcloud.group; |
| 79 | sopsFile = ../secrets/nextcloud.json; |
| 80 | format = "json"; |
| 81 | }; |
Skyler Grey | 13420dc | 2023-10-10 22:23:26 +0000 | [diff] [blame] | 82 | } |