diff --git a/modules/nixos/services/default.nix b/modules/nixos/services/default.nix index 34baa97a..8eb1f646 100644 --- a/modules/nixos/services/default.nix +++ b/modules/nixos/services/default.nix @@ -10,7 +10,6 @@ ./borgbackup.nix ./cloudflared.nix ./forgejo.nix - ./hostling.nix ./immich.nix ./jellyfin.nix ./kanidm.nix diff --git a/modules/nixos/services/hostling.nix b/modules/nixos/services/hostling.nix deleted file mode 100644 index f12267df..00000000 --- a/modules/nixos/services/hostling.nix +++ /dev/null @@ -1,58 +0,0 @@ -{ - lib, - self, - config, - ... -}: -let - inherit (lib) mkIf; - inherit (self.lib) mkServiceOption mkSecret; - - cfg = config.garden.services.hostling; -in -{ - options.garden.services.hostling = mkServiceOption "hostling" { - port = 3025; - host = "127.0.0.1"; - domain = "cdn.${config.networking.domain}"; - }; - - config = mkIf cfg.enable { - sops.secrets.hostling = mkSecret { - file = "hostling"; - key = "env"; - }; - - services = { - hostling = { - enable = true; - createDbLocally = true; - - environmentFile = config.sops.secrets.hostling.path; - - settings = { - inherit (cfg) port; - behind_reverse_proxy = true; - trusted_proxy = cfg.host; - public_url = "https://${cfg.domain}"; - - s3 = { - bucket = "isa-cdn"; - region = "europe-1"; - endpoint = "in64u.upcloudobjects.com"; - proxyfiles = true; - }; - }; - }; - - nginx.virtualHosts.${cfg.domain} = { - locations."/" = { - proxyPass = "http://${cfg.host}:${toString cfg.port}"; - extraConfig = '' - client_max_body_size 1G; - ''; - }; - }; - }; - }; -} diff --git a/modules/nixos/services/kanidm.nix b/modules/nixos/services/kanidm.nix index c4c91f0d..c67d066f 100644 --- a/modules/nixos/services/kanidm.nix +++ b/modules/nixos/services/kanidm.nix @@ -73,13 +73,6 @@ in group = "kanidm"; mode = "440"; }; - kanidm-oauth2-hostling = mkSecret { - file = "kanidm"; - key = "oauth2-hostling"; - owner = "kanidm"; - group = "kanidm"; - mode = "440"; - }; }; services = { @@ -123,7 +116,6 @@ in "linkwarden.access" "wakapi.access" "immich.access" - "hostling.access" ]; }; @@ -136,8 +128,6 @@ in "wakapi.access" = { }; "immich.access" = { }; - - "hostling.access" = { }; }; systems.oauth2 = { @@ -204,21 +194,6 @@ in "profile" ]; }; - - hostling = { - displayName = "hostling"; - originUrl = "https://${cfg'.hostling.domain}/api/auth/login/openid-connect/callback"; - originLanding = "https://${cfg'.hostling.domain}/"; - basicSecretFile = config.sops.secrets.kanidm-oauth2-hostling.path; - allowInsecureClientDisablePkce = true; - preferShortUsername = true; - scopeMaps."hostling.access" = [ - "openid" - "email" - "profile" - ]; - }; - }; }; }; diff --git a/systems/minerva/default.nix b/systems/minerva/default.nix index 711ad215..392246c1 100644 --- a/systems/minerva/default.nix +++ b/systems/minerva/default.nix @@ -28,7 +28,6 @@ blahaj.enable = true; kanidm.enable = true; mailserver.enable = true; - hostling.enable = true; borgbackup.enable = true; # web