From 2912581b99bfb855d500631f52bcea86448a519a Mon Sep 17 00:00:00 2001 From: oqyude Date: Wed, 23 Sep 2026 21:46:08 +0300 Subject: [PATCH] tape rotation added --- modules/containers/secrets/tape-rotation.env | 17 ++ modules/containers/tape-rotation.nix | 177 +++++++++++++++++++ modules/server/default.nix | 1 + modules/server/nginx.nix | 4 + 4 files changed, 199 insertions(+) create mode 100644 modules/containers/secrets/tape-rotation.env create mode 100644 modules/containers/tape-rotation.nix diff --git a/modules/containers/secrets/tape-rotation.env b/modules/containers/secrets/tape-rotation.env new file mode 100644 index 0000000..9eb8be1 --- /dev/null +++ b/modules/containers/secrets/tape-rotation.env @@ -0,0 +1,17 @@ +TAPE_ROTATION_JWT_SECRET=ENC[AES256_GCM,data:xFtVR+6TalkDOlcsUB52QAP1eeZAUzHkCdUTC0eg9oLtXxCtOHNKDynpxWiPdqFCFWmFisOESmNEPgqXkfTThw==,iv:auPyYNpuzBV0YL/RG8DYDTim9N72J6cChWTIQMYgs/0=,tag:yN67SlnBPKzzIqet8IgBXw==,type:str] +TAPE_ROTATION_ADMIN_PASSWORD=ENC[AES256_GCM,data:JCOgdAyDP+7m7lOTXGoCSA==,iv:5WSnfpTyjDO+q59YsFWmgdvajzf5CxfPjpeSkYHMjgg=,tag:tvvm4HWUw71/HcDbIpHu5w==,type:str] +TAPE_ROTATION_APP_URL=ENC[AES256_GCM,data:GJ5klFIFwJm7/7ts+U6KUy5FYbwkXIipHWTMqT8I,iv:JheRMunpnDcCetLGCa91xYYaMYM92H9UYVtphAOP5IE=,tag:edwFhSXRCV9ZHTQaF2huyw==,type:str] +TAPE_ROTATION_CORS_ORIGINS=ENC[AES256_GCM,data:TRWO02hfNBHE4rS5s5qvA1L4gAjTP8yqHDmva2k5,iv:oSNVYZEYwheZQW4KPm8aGq73wr3Ol2E7PS0pU7ra7dM=,tag:J21t12mCWJ6Y2bv0ypCdqA==,type:str] +SMTP_HOST= +SMTP_PORT=ENC[AES256_GCM,data:LCQ=,iv:WLAbIdlHOj3rewluMXWVzilqvDSV/AJWSCX2r1aKs20=,tag:4Epi95JuDt+hpK5SrgZ/Eg==,type:str] +SMTP_USER= +SMTP_PASSWORD= +SMTP_FROM=ENC[AES256_GCM,data:ojS087+VQNecRLOgkiwDooR53SV3,iv:kGpy74EoXEDGnyo706MEJd2JY5FpJmN9Gy6+f7jOwBM=,tag:FaeLO08Prlk8cC84QFpWLw==,type:str] +NOTIFY_EMAIL= +TAPE_LABEL_REGEX= +sops_age__list_0__map_enc=-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBsSUtSTnJtWHo3WXZWME4r\nNU51dk1rb3NmN3lFT1BMc3E1eVBOTDJUNlZrCkJBT2w2dkpXeEgvMWhWcGVNME8w\nSDZ1ekpUTmxJV0kyb2UrRC9XUTBiUFkKLS0tIGx2MCtxcG9lYjY0dmU4Wld4eEND\neFRRNUd3Rm9iYUg2dWh5elFEaW9wZUUKCvTvSHheiciexXbNXNAI9oioTHUSvreX\nIdOHyjfBfcjgfVIMrp5HQkQCC6labOHRcYgmT4WRkXJ11uTLvgLu1Q==\n-----END AGE ENCRYPTED FILE-----\n +sops_age__list_0__map_recipient=age13l2gtk0nzr484zprp7e0pkrt0ne0j4asyn2pjmlaw73nte7t7d8q4sqtxm +sops_lastmodified=2026-09-23T18:58:25Z +sops_mac=ENC[AES256_GCM,data:iLT3sVq0aV+UEztCdnbTBZraER3kXtksEOHl6AaiINTU6BHM0gTmpn5GdjbJykZDJweYdKVk6vYLB+k8JS33hWS9EoPUtme+FIGkbY6duMGpbVP/DZ5rqol1R+ihChfjmsXpnleVY6kWfnt67CH7LrP2HnsQj5njLF/3Qa4DMe8=,iv:yl8HB2E2Dm5LL1B7eLXXXTxJmEOp6HFvgIb3Ah+zVFg=,tag:iKTWq136tkMDgT4aFqGzmQ==,type:str] +sops_unencrypted_suffix=_unencrypted +sops_version=3.13.3 diff --git a/modules/containers/tape-rotation.nix b/modules/containers/tape-rotation.nix new file mode 100644 index 0000000..6881405 --- /dev/null +++ b/modules/containers/tape-rotation.nix @@ -0,0 +1,177 @@ +{ + config, + lib, + pkgs, + xlib, + ... +}: +# TapeRotation — web app for tracking and rotation of backup tape +# cartridges. https://github.com/ElizarovEugene/TapeRotation +# +# Podman adaptation of the upstream docker-compose deployment. Two +# containers on a shared "taperotation_default" network (mirrors the +# compose project network): +# - taperotation-backend: FastAPI/uvicorn on :8001, SQLite at /data, +# file attachments at /app/uploads +# - taperotation-frontend: nginx serving the built React app on :80, +# proxying /api to http://backend:8001 +# The backend container gets the network alias "backend" so the +# frontend's baked-in nginx upstream (compose service name) resolves. +# +# Published host port 5174 → container:80 for the web UI. Keep it out +# of networking.firewall like the other panel ports and front it with an +# nginx vhost, e.g. in server/nginx.nix: +# { domain = "tape-rotation.zeroq.su"; port = 5174; } +# and set APP_URL / CORS_ORIGINS in the sops-encrypted env file. +# +# Instance config lives in one sops-encrypted .env file (mirrors the +# upstream .env.example, sops-nix format = "dotenv", key = "" → whole +# file): sops modules/containers/secrets/tape-rotation.env +# On first boot the admin account is created from ADMIN_USERNAME / +# ADMIN_PASSWORD from that file. +let + panel = "${xlib.dirs.services-nodes-folder}/${xlib.device.hostname}/tape-rotation"; +in +{ + virtualisation = { + podman = { + enable = true; + autoPrune = { + enable = true; + flags = [ "--all" ]; + }; + dockerCompat = true; + defaultNetwork.settings.dns_enabled = true; + }; + oci-containers = { + backend = "podman"; + containers = { + "taperotation-backend" = { + image = "elizaroveugene/taperotation-backend:latest"; + environment = { + "DATABASE_URL" = "sqlite:////data/taperotation.db"; + "JWT_EXPIRE_MINUTES" = "480"; + "ADMIN_USERNAME" = "admin"; + "ADMIN_LANGUAGE" = "en"; + "NOTIFY_DAYS_BEFORE" = "7"; + "TZ" = "Europe/Moscow"; + }; + environmentFiles = [ "/run/secrets/tape-rotation-env" ]; + volumes = [ + "${panel}/db:/data:rw" + "${panel}/uploads:/app/uploads:rw" + ]; + log-driver = "journald"; + extraOptions = [ + "--network=taperotation_default" + # frontend nginx proxies /api to http://backend:8001 + "--network-alias=backend" + ]; + }; + "taperotation-frontend" = { + image = "elizaroveugene/taperotation-frontend:latest"; + ports = [ + "0.0.0.0:5174:80/tcp" + ]; + log-driver = "journald"; + extraOptions = [ + "--network=taperotation_default" + ]; + }; + }; + }; + }; + + # Enable container name DNS for all Podman networks. + networking.firewall.interfaces = + let + matchAll = if !config.networking.nftables.enable then "podman+" else "podman*"; + in + { + "${matchAll}".allowedUDPPorts = [ 53 ]; + }; + + systemd = { + services = { + "podman-taperotation-backend" = { + serviceConfig.Restart = lib.mkOverride 90 "always"; + after = [ "podman-network-taperotation_default.service" ]; + requires = [ "podman-network-taperotation_default.service" ]; + partOf = [ "podman-compose-tape-rotation-root.target" ]; + wantedBy = [ "podman-compose-tape-rotation-root.target" ]; + }; + "podman-taperotation-frontend" = { + serviceConfig.Restart = lib.mkOverride 90 "always"; + after = [ + "podman-network-taperotation_default.service" + "podman-taperotation-backend.service" + ]; + requires = [ "podman-network-taperotation_default.service" ]; + partOf = [ "podman-compose-tape-rotation-root.target" ]; + wantedBy = [ "podman-compose-tape-rotation-root.target" ]; + }; + "podman-network-taperotation_default" = { + path = [ pkgs.podman ]; + serviceConfig = { + Type = "oneshot"; + RemainAfterExit = true; + ExecStop = "podman network rm -f taperotation_default"; + }; + script = '' + podman network inspect taperotation_default || podman network create taperotation_default + ''; + partOf = [ "podman-compose-tape-rotation-root.target" ]; + wantedBy = [ "podman-compose-tape-rotation-root.target" ]; + }; + "podman-update-taperotation" = { + path = [ pkgs.podman ]; + serviceConfig = { + Type = "oneshot"; + TimeoutSec = 300; + }; + script = '' + podman pull elizaroveugene/taperotation-backend:latest + podman pull elizaroveugene/taperotation-frontend:latest + systemctl restart podman-taperotation-backend.service podman-taperotation-frontend.service + ''; + }; + }; + # Starts/stops together with all TapeRotation containers. + targets."podman-compose-tape-rotation-root" = { + unitConfig.Description = "Root target generated by compose2nix."; + wantedBy = [ "multi-user.target" ]; + }; + # Enable automatic image updates: + # systemd.timers."podman-update-taperotation" = { + # wantedBy = [ "timers.target" ]; + # timerConfig = { + # OnCalendar = "weekly"; + # Persistent = true; + # }; + # }; + tmpfiles.rules = [ + (xlib.helpers.mkTmpfile "d" xlib.dirs.services-mnt-folder "0755" "root" "root") + (xlib.helpers.mkTmpfile "d" xlib.dirs.services-nodes-folder "0755" "root" "root") + (xlib.helpers.mkTmpfile "d" "${xlib.dirs.services-nodes-folder}/${xlib.device.hostname}" + "0755" + "root" + "root" + ) + (xlib.helpers.mkTmpfile "d" panel "0755" "root" "root") + (xlib.helpers.mkTmpfile "d" "${panel}/db" "0755" "root" "root") + (xlib.helpers.mkTmpfile "d" "${panel}/uploads" "0755" "root" "root") + # Relabel panel dir for SELinux so containers can access it. + (xlib.helpers.mkTmpfile "Z" panel "0755" "root" "root") + ]; + }; + + sops.secrets."tape-rotation-env" = { + # key = "" → decrypt the whole file, not a single key. + # format = "dotenv" → the file IS one .env ready for environmentFiles: + # every non-comment KEY=VALUE line lands in the container environment. + key = ""; + format = "dotenv"; + sopsFile = ./secrets/tape-rotation.env; + mode = "0400"; + }; +} \ No newline at end of file diff --git a/modules/server/default.nix b/modules/server/default.nix index 7fbe7e9..6bdf30f 100644 --- a/modules/server/default.nix +++ b/modules/server/default.nix @@ -29,6 +29,7 @@ ./syncthing.nix ./systemd.nix ./uptime-kuma.nix + ../containers/tape-rotation.nix # ../containers/remnawave.nix # ./coturn.nix # ./mealie.nix diff --git a/modules/server/nginx.nix b/modules/server/nginx.nix index a4e8a2b..87f2944 100644 --- a/modules/server/nginx.nix +++ b/modules/server/nginx.nix @@ -61,6 +61,10 @@ let domain = "flux.zeroq.su"; port = 6061; } + { + domain = "tape-rotation.zeroq.su"; + port = 5174; + } { domain = "navidrome.zeroq.su"; port = 4533;