diff --git a/homelab-services/nimh-static/flake.nix b/homelab-services/nimh-static/flake.nix new file mode 100644 index 0000000..6780473 --- /dev/null +++ b/homelab-services/nimh-static/flake.nix @@ -0,0 +1,106 @@ +{ + description = "Flake that configures a static site hosted in a k3s pod"; + + inputs = { + nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11"; + }; + + outputs = { + nixosModules.nimh-static = + { + config, + lib, + pkgs, + ... + }: + let + opts = config.services.nimh-static; + in + { + options.services.nimh-static = { + enable = lib.mkEnableOption "serve nimh via k3s pod."; + + credentialsFile = lib.mkOption { + type = lib.types.path; + description = "File containing service (k3s) secrets."; + }; + + rootDir = lib.mkOption { + type = lib.types.path; + description = "Root of the static site"; + }; + + default-nginx = { + enable = lib.mkEnableOption "Enable nginx reverse proxy."; + hostname = lib.mkOption { + type = lib.types.str; + default = "localhost"; + description = "Hostname for reverse proxy"; + }; + + }; + }; + + config = lib.mkIf opts.enable { + users.groups.nimh = { }; + users.users.nimh = { + isSystemUser = true; + createHome = true; + home = "${opts.rootDir}"; + group = "nimh"; + }; + + systemd.services.nimh-static = { + description = "oneshot apply service to k3s"; + after = [ "k3s.servce" ]; + wantedBy = [ "multi-user.target" ]; + + serviceConfig = { + Type = "oneshot"; + ExecStart = '' + kubectl=${pkgs.kubectl}/bin/kubectl + kubectl apply -k ./k3s + + + ''; + + User = "nimh"; + Group = "nimh"; + EnvironmentFile = "${opts.credentialsFile}"; + }; + }; + + service.nginx = lib.mkIf opts.default-nginx.enable { + enable = true; + + virtualHosts.${opts.default-nginx.hostname} = { + forceSSL = true; + + # Parse TLD from hostname to use wildcard cert (just takes last two elements separated by a period) + useACMEHost = + let + b = builtins; + s = lib.strings; + fl = s.splitString "." "${opts.default-nginx.hostname}"; + in + b.concatStringsSep "." [ + (b.elemAt fl (b.length fl - 2)) + (b.elemAt fl (b.length fl - 1)) + ]; + + locations."/" = { + # Default k3s port? + proxyPass = "http://localhost:30080"; + }; + }; + }; + + networking.firewall.allowedTCPPorts = lib.mkif opts.default-nginx.enable [ + 80 + 443 + ]; + }; + + }; + }; +} diff --git a/homelab-services/nimh-static/k3s/service.yaml b/homelab-services/nimh-static/k3s/service.yaml new file mode 100644 index 0000000..3a3ef37 --- /dev/null +++ b/homelab-services/nimh-static/k3s/service.yaml @@ -0,0 +1,7 @@ +apiVersion: v1 +kind: Service +metadata: + name: nimh-static +spec: + selector: + app.hubernetes.io/name: proxy diff --git a/nixos/configuration.nix b/nixos/configuration.nix index 2b2427b..f0e6a23 100755 --- a/nixos/configuration.nix +++ b/nixos/configuration.nix @@ -5,13 +5,6 @@ meta, ... }: - -let - nimhStaticSite = pkgs.runCommand "nimh-static-site" { } '' - mkdir -p $out - cp -r ${../homelab-services/nimh-static}/* $out/ - ''; -in { imports = [ ]; @@ -93,23 +86,6 @@ in }; }; - # Setup vhosts via nginx - # all more complicated should route - # through k3s traefic - services.nginx = { - enable = true; - - virtualHosts."nimh.roypository.com" = { - forceSSL = true; - useACMEHost = "roypository.com"; - - locations."/" = { - root = nimhStaticSite; - index = "index.html"; - }; - }; - }; - # ================================ # # K3S SERVICE # # ================================ #