2024-06-18 19:18:44 +07:00
|
|
|
{ config, lib, ... }:
|
|
|
|
let
|
|
|
|
name = "redmage";
|
|
|
|
podman = config.profile.podman;
|
|
|
|
inherit (lib) mkIf;
|
|
|
|
ip = "10.88.0.2";
|
|
|
|
image = "git.tigor.web.id/tigor/redmage:latest";
|
|
|
|
rootVolume = "/nas/redmage";
|
|
|
|
domain = "${name}.tigor.web.id";
|
|
|
|
user = config.profile.user;
|
|
|
|
uid = toString user.uid;
|
|
|
|
gid = toString user.gid;
|
|
|
|
in
|
|
|
|
{
|
|
|
|
config = mkIf (podman.enable && podman.${name}.enable) {
|
|
|
|
services.caddy.virtualHosts.${domain}.extraConfig = ''
|
2024-09-22 16:26:19 +07:00
|
|
|
@botForbidden header_regexp User-Agent "(?i)AdsBot-Google|Amazonbot|anthropic-ai|Applebot|Applebot-Extended|AwarioRssBot|AwarioSmartBot|Bytespider|CCBot|ChatGPT|ChatGPT-User|Claude-Web|ClaudeBot|cohere-ai|DataForSeoBot|Diffbot|FacebookBot|Google-Extended|GPTBot|ImagesiftBot|magpie-crawler|omgili|Omgilibot|peer39_crawler|PerplexityBot|YouBot"
|
|
|
|
|
|
|
|
handle @botForbidden {
|
|
|
|
respond /* "Access Denied" 403 {
|
|
|
|
close
|
|
|
|
}
|
|
|
|
}
|
2024-06-18 19:18:44 +07:00
|
|
|
reverse_proxy ${ip}:8080
|
|
|
|
'';
|
|
|
|
|
2024-11-24 20:16:30 +07:00
|
|
|
services.nginx.virtualHosts.${domain} = {
|
2024-11-24 21:31:04 +07:00
|
|
|
useACMEHost = "tigor.web.id";
|
2024-11-24 20:16:30 +07:00
|
|
|
forceSSL = true;
|
|
|
|
locations."/" = {
|
|
|
|
proxyPass = "http://${ip}:8080";
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
2024-11-24 21:31:04 +07:00
|
|
|
security.acme.certs."tigor.web.id".extraDomainNames = [ domain ];
|
|
|
|
|
2024-06-18 19:18:44 +07:00
|
|
|
system.activationScripts."podman-${name}" = ''
|
|
|
|
mkdir -p ${rootVolume}/db
|
|
|
|
mkdir -p ${rootVolume}/images
|
|
|
|
chown ${uid}:${gid} ${rootVolume} ${rootVolume}/db ${rootVolume}/images
|
|
|
|
'';
|
|
|
|
|
|
|
|
virtualisation.oci-containers.containers.${name} = {
|
|
|
|
inherit image;
|
2024-06-18 21:00:43 +07:00
|
|
|
hostname = name;
|
2024-06-18 19:18:44 +07:00
|
|
|
autoStart = true;
|
|
|
|
user = "${uid}:${gid}";
|
|
|
|
environment = {
|
|
|
|
TZ = "Asia/Jakarta";
|
|
|
|
};
|
|
|
|
volumes = [
|
|
|
|
"${rootVolume}/db:/app/db"
|
|
|
|
"${rootVolume}/images:/app/downloads"
|
|
|
|
];
|
|
|
|
extraOptions = [
|
|
|
|
"--network=podman"
|
|
|
|
"--ip=${ip}"
|
|
|
|
];
|
2024-06-19 12:49:23 +07:00
|
|
|
labels = {
|
|
|
|
"io.containers.autoupdate" = "registry";
|
|
|
|
};
|
2024-06-18 19:18:44 +07:00
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
}
|