mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-07 20:47:14 +03:00
tape rotation added
This commit is contained in:
@@ -0,0 +1,17 @@
|
|||||||
|
TAPE_ROTATION_JWT_SECRET=ENC[AES256_GCM,data:xFtVR+6TalkDOlcsUB52QAP1eeZAUzHkCdUTC0eg9oLtXxCtOHNKDynpxWiPdqFCFWmFisOESmNEPgqXkfTThw==,iv:auPyYNpuzBV0YL/RG8DYDTim9N72J6cChWTIQMYgs/0=,tag:yN67SlnBPKzzIqet8IgBXw==,type:str]
|
||||||
|
TAPE_ROTATION_ADMIN_PASSWORD=ENC[AES256_GCM,data:JCOgdAyDP+7m7lOTXGoCSA==,iv:5WSnfpTyjDO+q59YsFWmgdvajzf5CxfPjpeSkYHMjgg=,tag:tvvm4HWUw71/HcDbIpHu5w==,type:str]
|
||||||
|
TAPE_ROTATION_APP_URL=ENC[AES256_GCM,data:GJ5klFIFwJm7/7ts+U6KUy5FYbwkXIipHWTMqT8I,iv:JheRMunpnDcCetLGCa91xYYaMYM92H9UYVtphAOP5IE=,tag:edwFhSXRCV9ZHTQaF2huyw==,type:str]
|
||||||
|
TAPE_ROTATION_CORS_ORIGINS=ENC[AES256_GCM,data:TRWO02hfNBHE4rS5s5qvA1L4gAjTP8yqHDmva2k5,iv:oSNVYZEYwheZQW4KPm8aGq73wr3Ol2E7PS0pU7ra7dM=,tag:J21t12mCWJ6Y2bv0ypCdqA==,type:str]
|
||||||
|
SMTP_HOST=
|
||||||
|
SMTP_PORT=ENC[AES256_GCM,data:LCQ=,iv:WLAbIdlHOj3rewluMXWVzilqvDSV/AJWSCX2r1aKs20=,tag:4Epi95JuDt+hpK5SrgZ/Eg==,type:str]
|
||||||
|
SMTP_USER=
|
||||||
|
SMTP_PASSWORD=
|
||||||
|
SMTP_FROM=ENC[AES256_GCM,data:ojS087+VQNecRLOgkiwDooR53SV3,iv:kGpy74EoXEDGnyo706MEJd2JY5FpJmN9Gy6+f7jOwBM=,tag:FaeLO08Prlk8cC84QFpWLw==,type:str]
|
||||||
|
NOTIFY_EMAIL=
|
||||||
|
TAPE_LABEL_REGEX=
|
||||||
|
sops_age__list_0__map_enc=-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBsSUtSTnJtWHo3WXZWME4r\nNU51dk1rb3NmN3lFT1BMc3E1eVBOTDJUNlZrCkJBT2w2dkpXeEgvMWhWcGVNME8w\nSDZ1ekpUTmxJV0kyb2UrRC9XUTBiUFkKLS0tIGx2MCtxcG9lYjY0dmU4Wld4eEND\neFRRNUd3Rm9iYUg2dWh5elFEaW9wZUUKCvTvSHheiciexXbNXNAI9oioTHUSvreX\nIdOHyjfBfcjgfVIMrp5HQkQCC6labOHRcYgmT4WRkXJ11uTLvgLu1Q==\n-----END AGE ENCRYPTED FILE-----\n
|
||||||
|
sops_age__list_0__map_recipient=age13l2gtk0nzr484zprp7e0pkrt0ne0j4asyn2pjmlaw73nte7t7d8q4sqtxm
|
||||||
|
sops_lastmodified=2026-09-23T18:58:25Z
|
||||||
|
sops_mac=ENC[AES256_GCM,data:iLT3sVq0aV+UEztCdnbTBZraER3kXtksEOHl6AaiINTU6BHM0gTmpn5GdjbJykZDJweYdKVk6vYLB+k8JS33hWS9EoPUtme+FIGkbY6duMGpbVP/DZ5rqol1R+ihChfjmsXpnleVY6kWfnt67CH7LrP2HnsQj5njLF/3Qa4DMe8=,iv:yl8HB2E2Dm5LL1B7eLXXXTxJmEOp6HFvgIb3Ah+zVFg=,tag:iKTWq136tkMDgT4aFqGzmQ==,type:str]
|
||||||
|
sops_unencrypted_suffix=_unencrypted
|
||||||
|
sops_version=3.13.3
|
||||||
@@ -0,0 +1,177 @@
|
|||||||
|
{
|
||||||
|
config,
|
||||||
|
lib,
|
||||||
|
pkgs,
|
||||||
|
xlib,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
# TapeRotation — web app for tracking and rotation of backup tape
|
||||||
|
# cartridges. https://github.com/ElizarovEugene/TapeRotation
|
||||||
|
#
|
||||||
|
# Podman adaptation of the upstream docker-compose deployment. Two
|
||||||
|
# containers on a shared "taperotation_default" network (mirrors the
|
||||||
|
# compose project network):
|
||||||
|
# - taperotation-backend: FastAPI/uvicorn on :8001, SQLite at /data,
|
||||||
|
# file attachments at /app/uploads
|
||||||
|
# - taperotation-frontend: nginx serving the built React app on :80,
|
||||||
|
# proxying /api to http://backend:8001
|
||||||
|
# The backend container gets the network alias "backend" so the
|
||||||
|
# frontend's baked-in nginx upstream (compose service name) resolves.
|
||||||
|
#
|
||||||
|
# Published host port 5174 → container:80 for the web UI. Keep it out
|
||||||
|
# of networking.firewall like the other panel ports and front it with an
|
||||||
|
# nginx vhost, e.g. in server/nginx.nix:
|
||||||
|
# { domain = "tape-rotation.zeroq.su"; port = 5174; }
|
||||||
|
# and set APP_URL / CORS_ORIGINS in the sops-encrypted env file.
|
||||||
|
#
|
||||||
|
# Instance config lives in one sops-encrypted .env file (mirrors the
|
||||||
|
# upstream .env.example, sops-nix format = "dotenv", key = "" → whole
|
||||||
|
# file): sops modules/containers/secrets/tape-rotation.env
|
||||||
|
# On first boot the admin account is created from ADMIN_USERNAME /
|
||||||
|
# ADMIN_PASSWORD from that file.
|
||||||
|
let
|
||||||
|
panel = "${xlib.dirs.services-nodes-folder}/${xlib.device.hostname}/tape-rotation";
|
||||||
|
in
|
||||||
|
{
|
||||||
|
virtualisation = {
|
||||||
|
podman = {
|
||||||
|
enable = true;
|
||||||
|
autoPrune = {
|
||||||
|
enable = true;
|
||||||
|
flags = [ "--all" ];
|
||||||
|
};
|
||||||
|
dockerCompat = true;
|
||||||
|
defaultNetwork.settings.dns_enabled = true;
|
||||||
|
};
|
||||||
|
oci-containers = {
|
||||||
|
backend = "podman";
|
||||||
|
containers = {
|
||||||
|
"taperotation-backend" = {
|
||||||
|
image = "elizaroveugene/taperotation-backend:latest";
|
||||||
|
environment = {
|
||||||
|
"DATABASE_URL" = "sqlite:////data/taperotation.db";
|
||||||
|
"JWT_EXPIRE_MINUTES" = "480";
|
||||||
|
"ADMIN_USERNAME" = "admin";
|
||||||
|
"ADMIN_LANGUAGE" = "en";
|
||||||
|
"NOTIFY_DAYS_BEFORE" = "7";
|
||||||
|
"TZ" = "Europe/Moscow";
|
||||||
|
};
|
||||||
|
environmentFiles = [ "/run/secrets/tape-rotation-env" ];
|
||||||
|
volumes = [
|
||||||
|
"${panel}/db:/data:rw"
|
||||||
|
"${panel}/uploads:/app/uploads:rw"
|
||||||
|
];
|
||||||
|
log-driver = "journald";
|
||||||
|
extraOptions = [
|
||||||
|
"--network=taperotation_default"
|
||||||
|
# frontend nginx proxies /api to http://backend:8001
|
||||||
|
"--network-alias=backend"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
"taperotation-frontend" = {
|
||||||
|
image = "elizaroveugene/taperotation-frontend:latest";
|
||||||
|
ports = [
|
||||||
|
"0.0.0.0:5174:80/tcp"
|
||||||
|
];
|
||||||
|
log-driver = "journald";
|
||||||
|
extraOptions = [
|
||||||
|
"--network=taperotation_default"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
# Enable container name DNS for all Podman networks.
|
||||||
|
networking.firewall.interfaces =
|
||||||
|
let
|
||||||
|
matchAll = if !config.networking.nftables.enable then "podman+" else "podman*";
|
||||||
|
in
|
||||||
|
{
|
||||||
|
"${matchAll}".allowedUDPPorts = [ 53 ];
|
||||||
|
};
|
||||||
|
|
||||||
|
systemd = {
|
||||||
|
services = {
|
||||||
|
"podman-taperotation-backend" = {
|
||||||
|
serviceConfig.Restart = lib.mkOverride 90 "always";
|
||||||
|
after = [ "podman-network-taperotation_default.service" ];
|
||||||
|
requires = [ "podman-network-taperotation_default.service" ];
|
||||||
|
partOf = [ "podman-compose-tape-rotation-root.target" ];
|
||||||
|
wantedBy = [ "podman-compose-tape-rotation-root.target" ];
|
||||||
|
};
|
||||||
|
"podman-taperotation-frontend" = {
|
||||||
|
serviceConfig.Restart = lib.mkOverride 90 "always";
|
||||||
|
after = [
|
||||||
|
"podman-network-taperotation_default.service"
|
||||||
|
"podman-taperotation-backend.service"
|
||||||
|
];
|
||||||
|
requires = [ "podman-network-taperotation_default.service" ];
|
||||||
|
partOf = [ "podman-compose-tape-rotation-root.target" ];
|
||||||
|
wantedBy = [ "podman-compose-tape-rotation-root.target" ];
|
||||||
|
};
|
||||||
|
"podman-network-taperotation_default" = {
|
||||||
|
path = [ pkgs.podman ];
|
||||||
|
serviceConfig = {
|
||||||
|
Type = "oneshot";
|
||||||
|
RemainAfterExit = true;
|
||||||
|
ExecStop = "podman network rm -f taperotation_default";
|
||||||
|
};
|
||||||
|
script = ''
|
||||||
|
podman network inspect taperotation_default || podman network create taperotation_default
|
||||||
|
'';
|
||||||
|
partOf = [ "podman-compose-tape-rotation-root.target" ];
|
||||||
|
wantedBy = [ "podman-compose-tape-rotation-root.target" ];
|
||||||
|
};
|
||||||
|
"podman-update-taperotation" = {
|
||||||
|
path = [ pkgs.podman ];
|
||||||
|
serviceConfig = {
|
||||||
|
Type = "oneshot";
|
||||||
|
TimeoutSec = 300;
|
||||||
|
};
|
||||||
|
script = ''
|
||||||
|
podman pull elizaroveugene/taperotation-backend:latest
|
||||||
|
podman pull elizaroveugene/taperotation-frontend:latest
|
||||||
|
systemctl restart podman-taperotation-backend.service podman-taperotation-frontend.service
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
};
|
||||||
|
# Starts/stops together with all TapeRotation containers.
|
||||||
|
targets."podman-compose-tape-rotation-root" = {
|
||||||
|
unitConfig.Description = "Root target generated by compose2nix.";
|
||||||
|
wantedBy = [ "multi-user.target" ];
|
||||||
|
};
|
||||||
|
# Enable automatic image updates:
|
||||||
|
# systemd.timers."podman-update-taperotation" = {
|
||||||
|
# wantedBy = [ "timers.target" ];
|
||||||
|
# timerConfig = {
|
||||||
|
# OnCalendar = "weekly";
|
||||||
|
# Persistent = true;
|
||||||
|
# };
|
||||||
|
# };
|
||||||
|
tmpfiles.rules = [
|
||||||
|
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-mnt-folder "0755" "root" "root")
|
||||||
|
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-nodes-folder "0755" "root" "root")
|
||||||
|
(xlib.helpers.mkTmpfile "d" "${xlib.dirs.services-nodes-folder}/${xlib.device.hostname}"
|
||||||
|
"0755"
|
||||||
|
"root"
|
||||||
|
"root"
|
||||||
|
)
|
||||||
|
(xlib.helpers.mkTmpfile "d" panel "0755" "root" "root")
|
||||||
|
(xlib.helpers.mkTmpfile "d" "${panel}/db" "0755" "root" "root")
|
||||||
|
(xlib.helpers.mkTmpfile "d" "${panel}/uploads" "0755" "root" "root")
|
||||||
|
# Relabel panel dir for SELinux so containers can access it.
|
||||||
|
(xlib.helpers.mkTmpfile "Z" panel "0755" "root" "root")
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
sops.secrets."tape-rotation-env" = {
|
||||||
|
# key = "" → decrypt the whole file, not a single key.
|
||||||
|
# format = "dotenv" → the file IS one .env ready for environmentFiles:
|
||||||
|
# every non-comment KEY=VALUE line lands in the container environment.
|
||||||
|
key = "";
|
||||||
|
format = "dotenv";
|
||||||
|
sopsFile = ./secrets/tape-rotation.env;
|
||||||
|
mode = "0400";
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -29,6 +29,7 @@
|
|||||||
./syncthing.nix
|
./syncthing.nix
|
||||||
./systemd.nix
|
./systemd.nix
|
||||||
./uptime-kuma.nix
|
./uptime-kuma.nix
|
||||||
|
../containers/tape-rotation.nix
|
||||||
# ../containers/remnawave.nix
|
# ../containers/remnawave.nix
|
||||||
# ./coturn.nix
|
# ./coturn.nix
|
||||||
# ./mealie.nix
|
# ./mealie.nix
|
||||||
|
|||||||
@@ -61,6 +61,10 @@ let
|
|||||||
domain = "flux.zeroq.su";
|
domain = "flux.zeroq.su";
|
||||||
port = 6061;
|
port = 6061;
|
||||||
}
|
}
|
||||||
|
{
|
||||||
|
domain = "tape-rotation.zeroq.su";
|
||||||
|
port = 5174;
|
||||||
|
}
|
||||||
{
|
{
|
||||||
domain = "navidrome.zeroq.su";
|
domain = "navidrome.zeroq.su";
|
||||||
port = 4533;
|
port = 4533;
|
||||||
|
|||||||
Reference in New Issue
Block a user