From ae2348fdccac306615798d1ad9522dfe3e59c9b7 Mon Sep 17 00:00:00 2001 From: servius Date: Mon, 13 Apr 2026 01:51:25 +0530 Subject: [PATCH] chore: Move esphome to its own module --- nixos/tsuba/services/default.nix | 1 + nixos/tsuba/services/esphome.nix | 34 +++++++++++++++++++ .../{esphome.yaml => reTerminal-e1002.yaml} | 3 +- nixos/tsuba/services/homeassistant.nix | 27 --------------- secrets/esphome.yaml | 5 +-- 5 files changed, 40 insertions(+), 30 deletions(-) create mode 100644 nixos/tsuba/services/esphome.nix rename nixos/tsuba/services/esphome/{esphome.yaml => reTerminal-e1002.yaml} (99%) diff --git a/nixos/tsuba/services/default.nix b/nixos/tsuba/services/default.nix index b38a371..15482b7 100644 --- a/nixos/tsuba/services/default.nix +++ b/nixos/tsuba/services/default.nix @@ -8,6 +8,7 @@ ./deluge.nix ./aria2.nix ./homeassistant.nix + ./esphome.nix ./flaresolverr.nix ./caddy.nix ./monitoring.nix diff --git a/nixos/tsuba/services/esphome.nix b/nixos/tsuba/services/esphome.nix new file mode 100644 index 0000000..57ed874 --- /dev/null +++ b/nixos/tsuba/services/esphome.nix @@ -0,0 +1,34 @@ +# https://wiki.seeedstudio.com/getting_started_with_reterminal_e1002 +{config, ...}: { + sops.secrets.esphome = { + sopsFile = ../../../secrets/esphome.yaml; + format = "yaml"; + key = ""; + }; + + virtualisation.oci-containers.containers.esphome = { + image = "ghcr.io/esphome/esphome:latest"; + ports = ["6052:6052"]; + extraOptions = [ + "--device=/dev/ttyUSB0:/dev/ttyUSB0" + ]; + volumes = [ + "/var/lib/esphome:/config" + "/etc/localtime:/etc/localtime:ro" + ]; + environment = { + TZ = config.time.timeZone; + }; + }; + + systemd.tmpfiles.rules = [ + "d /var/lib/esphome 0755 root root -" + "C+ /var/lib/esphome/secrets.yaml 0644 root root - ${config.sops.secrets.esphome.path}" + "C+ /var/lib/esphome/reTerminal-e1002.yaml 0644 root root - ${./esphome/reTerminal-e1002.yaml}" + ]; + + services.caddy.virtualHosts."esphome.darksailor.dev".extraConfig = '' + import cloudflare + reverse_proxy localhost:6052 + ''; +} diff --git a/nixos/tsuba/services/esphome/esphome.yaml b/nixos/tsuba/services/esphome/reTerminal-e1002.yaml similarity index 99% rename from nixos/tsuba/services/esphome/esphome.yaml rename to nixos/tsuba/services/esphome/reTerminal-e1002.yaml index 1f28e39..0245eaa 100644 --- a/nixos/tsuba/services/esphome/esphome.yaml +++ b/nixos/tsuba/services/esphome/reTerminal-e1002.yaml @@ -34,7 +34,7 @@ logger: api: encryption: - key: "T4iKqws+XpTZ99iY9EXANjnFD16BlukBL0vHP3Al3sQ=" + key: !secret reterminal_e1002_enc_key ota: - platform: esphome @@ -383,6 +383,7 @@ display: id: epaper_display model: Seeed-reTerminal-E1002 update_interval: never + full_update_every: 10 lambda: |- if (id(page_index) == 0) { it.image(0, 0, id(dashboard_image_home)); diff --git a/nixos/tsuba/services/homeassistant.nix b/nixos/tsuba/services/homeassistant.nix index 8dd05a9..ef25a15 100644 --- a/nixos/tsuba/services/homeassistant.nix +++ b/nixos/tsuba/services/homeassistant.nix @@ -5,12 +5,6 @@ ... }: { sops.secrets."homeassistant/puppet-token" = {}; - sops.secrets.esphome = { - sopsFile = ../../../secrets/esphome.yaml; - format = "yaml"; - key = ""; - }; - virtualisation.oci-containers = { containers = { homeassistant = { @@ -40,21 +34,6 @@ "/var/lib/puppet/options.json:/data/options.json:ro" ]; }; - - esphome = { - image = "ghcr.io/esphome/esphome:latest"; - extraOptions = [ - "--network=host" - "--device=/dev/ttyUSB0:/dev/ttyUSB0" - ]; - volumes = [ - "/var/lib/esphome:/config" - "/etc/localtime:/etc/localtime:ro" - ]; - environment = { - TZ = config.time.timeZone; - }; - }; }; }; @@ -79,12 +58,6 @@ EOF ''; }; - systemd.tmpfiles.rules = [ - "d /var/lib/esphome 0755 root root -" - "L+ /var/lib/esphome/secrets.yaml - - - - ${config.sops.secrets.esphome.path}" - "L+ /var/lib/esphome/esphome.yaml - - - - ${./esphome/esphome.yaml}" - ]; - users.users.homeassistant = { isSystemUser = true; home = "/var/lib/homeassistant"; diff --git a/secrets/esphome.yaml b/secrets/esphome.yaml index f6578ac..2db6b7a 100644 --- a/secrets/esphome.yaml +++ b/secrets/esphome.yaml @@ -1,6 +1,7 @@ wifi_ssid: ENC[AES256_GCM,data:NnVQYmNcUYJaFjI=,iv:BnLy0ps0NXEQPI1mo89Ts904EdjYl/Aoam37Lg6S4i4=,tag:1vgHdIJaUf1NnkMEIDoJBg==,type:str] wifi_password: ENC[AES256_GCM,data:cKTVPyePQEQ=,iv:kAnTlamPYQeLmuIkLh5bR35GVwtHfelBYuOv3lb8lkM=,tag:rpv/8TIZTlhxqG9Rtm7phw==,type:str] ota_password: ENC[AES256_GCM,data:1RPEM6+pmnvI6BjIEzouwfnLGLfetA==,iv:tY5Vp756nRVIyGhFlE+xc953HNzIlmn1XH57XYGIW1o=,tag:RC7pCj3Z0513DzvVIzsepg==,type:str] +reterminal_e1002_enc_key: ENC[AES256_GCM,data:w/8ioxMZgx28x2DPEUBNXzQETYWAIuxKJYNJreJ88V0RYzOQvZ7GVPhDSLY=,iv:dxFcd7ds5KFiIPi4l+8SS+O1tqOG7BxSD/ekzmiUI94=,tag:GCVF4IAEuFtSQghA2Zyx8g==,type:str] sops: age: - recipient: age1pw7kluxp7872c63ne4jecq75glj060jkmqwzkk6esatuyck9egfswufdpk @@ -12,7 +13,7 @@ sops: UGV0VDhwOTJwNXRUYnBzS2F6MUhDdHMKo89gNR1JQfHM9zsH/bcf/fZts8jWu7FC rqVMqcdCaieT/mzrFZ8V5DUzjthnErhVS7nN3tZAxPhLgHPLwNcYkQ== -----END AGE ENCRYPTED FILE----- - lastmodified: "2026-04-12T19:27:19Z" - mac: ENC[AES256_GCM,data:RGk0pOI9pcem0WOhfacFaFUyjl6OaqCiKt4epVUcql/Ml0Uve2Wgm1bVPkOQD6EWwDNjAhxj4CZRtPGaZrg1TEQnLkMjGmbZ6JSo/TpvJD9v/JRH881hBwx4umR7JOynp3KcIJgYW8h+he8cQ2MCOtJIEh4Z6CbJ88rKwothFSo=,iv:ZiKNUzJ7s52/9rVC5MFeB4QvObIQf7BLzVsD3KxNkrM=,tag:f8ul4gstfYL7HgvhW7OlKg==,type:str] + lastmodified: "2026-04-12T20:03:57Z" + mac: ENC[AES256_GCM,data:OVuclHg0wNAsE8IOKPScOXmoWIq1bfV8l36mm+SI3swue5doV+JRjlKUEC3CaxZYq/de61xfP05y1bI1Oc3z6ZQLBfVfrRwtWMsi+PjPGFFGRc/O/oM+pX13XitqnvIHigRbH6sdu32VqvpGH8ywoOh00yPw0uFhnoTbuDzZcSM=,iv:Wwv2EKmb4ejcJ8C45w9H1rhmO79tcOh1WDIpdjEFRVo=,tag:JaQuDrOAR9qsP+oS/ot97w==,type:str] unencrypted_suffix: _unencrypted version: 3.12.2 -- 2.51.2