diff --git a/homelab-services/minio-service/flake.nix b/homelab-services/minio-service/flake.nix index e69de29..005a46f 100644 --- a/homelab-services/minio-service/flake.nix +++ b/homelab-services/minio-service/flake.nix @@ -0,0 +1,102 @@ +{ + description = "minio service for storing images with api access"; + + inputs = { + nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.05"; + }; + + outputs = { self, nixpkgs, ... }: { + nixosModules.minio-service = { config, lib, pkgs, ... }: + let + opts = config.services.minio-service; + in { + options.services.minio-service = { + enable = lib.mkEnableOption "MinIO object storage server"; + + dataDir = lib.mkOption { + type = lib.types.path; + default = "/var/lib/minio"; + description = "Directory to store MinIO data."; + }; + + dataPort = lib.mkOption { + type = lib.types.port; + default = 9000; + description = "MinIO S3 API port."; + }; + + consolePort = lib.mkOption { + type = lib.types.port; + default = 9001; + description = "MinIO Admin Console port."; + }; + + rootUser = lib.mkOption { + type = lib.types.str; + default = "minioadmin"; + description = "MinIO root username."; + }; + + rootPasswordFile = lib.mkOption { + type = lib.types.path; + description = "File containing MinIO root password."; + }; + + default-nginx = { + enable = lib.mkEnableOption "Enable nginx reverse proxy for MinIO"; + hostname = lib.mkOption { + type = lib.types.str; + default = "localhost"; + description = "Hostname for nginx reverse proxy."; + }; + }; + }; + + config = lib.mkIf opts.enable { + users.groups.minio = {}; + users.users.minio = { + isSystemUser = true; + group = "minio"; + home = opts.dataDir; + }; + + systemd.services.minio = { + description = "MinIO S3-compatible object storage"; + after = [ "network.target" ]; + wantedBy = [ "multi-user.target" ]; + + serviceConfig = { + ExecStart = '' + ${pkgs.minio}/bin/minio server ${opts.dataDir} \ + --address ":${toString opts.dataPort}" \ + --console-address ":${toString opts.consolePort}" + ''; + User = "minio"; + Group = "minio"; + Environment = [ + "MINIO_ROOT_USER=${opts.rootUser}" + "MINIO_ROOT_PASSWORD_FILE=${opts.rootPasswordFile}" + ]; + Restart = "always"; + }; + }; + + services.nginx = lib.mkIf opts.default-nginx.enable { + enable = true; + virtualHosts.${opts.default-nginx.hostname} = { + forceSSL = true; + enableACME = true; + locations."/" = { + proxyPass = "http://localhost:${toString opts.port}"; + }; + }; + }; + + networking.firewall.allowedTCPPorts = lib.mkMerge [ + [ opts.dataPort opts.consolePort ] + (lib.mkIf opts.default-nginx.enable [ 80 443 ]) + ]; + }; + }; + }; +} diff --git a/nixos/flake.nix b/nixos/flake.nix index 1b31e20..c8a5f3b 100644 --- a/nixos/flake.nix +++ b/nixos/flake.nix @@ -20,9 +20,8 @@ # This is a path to the services I've declared. # It just happens to be stored in the same repository (relative), # but could well be a separate repository - tests-service = { - url = "github:RoyDumblauskas/tests-service/main?shallow=1"; - }; + tests-service.url = "github:RoyDumblauskas/tests-service/main?shallow=1"; + minio-service.url = "path:../homelab-services/minio-service"; }; outputs = { self, nixpkgs, home-manager, disko, sops-nix, quasiSecrets, impermanence, tests-service }@inputs: