open-webui via podman added

This commit is contained in:
2026-10-07 13:49:40 +03:00
parent 5e9641602a
commit 58333d0257
6 changed files with 220 additions and 29 deletions
+1
View File
@@ -20,6 +20,7 @@
192.168.1.20 kuma.zeroq.su
192.168.1.20 navidrome.zeroq.su
192.168.1.20 nextcloud.zeroq.su
192.168.1.20 open.zeroq.su
192.168.1.20 office.zeroq.su
192.168.1.20 pdf.zeroq.su
192.168.1.20 syncthing.zeroq.su
+1 -1
View File
@@ -6,6 +6,7 @@
{
imports = [
../containers/3x-ui.nix
../containers/open-webui.nix
../containers/tape-rotation.nix
../pkgs/beets.nix
./acme.nix
@@ -38,7 +39,6 @@
# ./n8n.nix
# ./netdata.nix
# ./nfs.nix
# ./open-webui.nix
# ./rsync.nix
# ./step-ca.nix
# ./stirling-pdf.nix
+25
View File
@@ -65,6 +65,12 @@ let
domain = "tape-rotation.zeroq.su";
port = 5174;
}
# NOTE: open.zeroq.su is intentionally NOT in this `sites` list —
# mkProxy hard-codes ${server} = 192.168.1.20, but the Open WebUI
# container binds to 127.0.0.1:8080 only (loopback, see
# modules/containers/open-webui.nix). The vhost is added directly
# to `virtualHosts` below, alongside x.zeroq.su (3x-ui panel,
# same loopback-only pattern).
{
domain = "navidrome.zeroq.su";
port = 4533;
@@ -162,6 +168,25 @@ in
};
};
};
# Open WebUI — same loopback-only pattern as x.zeroq.su above.
# The container listens on 127.0.0.1:8080 (modules/containers/open-webui.nix),
# so we proxy_pass to 127.0.0.1, not the LAN IP. The two extra
# directives are required by the upstream HTTPS docs:
# proxy_buffering off for SSE streaming (markdown in chat breaks
# under the default `proxy_buffering on` from recommendedProxySettings),
# and a 300 s read timeout for long LLM completions.
"open.zeroq.su" = {
forceSSL = true;
enableACME = true;
locations."/" = {
proxyPass = "http://127.0.0.1:8080";
proxyWebsockets = true;
};
extraConfig = ''
proxy_buffering off;
proxy_read_timeout 300s;
'';
};
"zeroq.su" = {
forceSSL = true;
enableACME = true;
-28
View File
@@ -1,28 +0,0 @@
{
config,
inputs,
lib,
pkgs,
...
}:
{
services = {
open-webui = {
enable = false;
host = "0.0.0.0";
port = 11112;
openFirewall = true;
environment = {
ANONYMIZED_TELEMETRY = "False";
DO_NOT_TRACK = "True";
SCARF_NO_ANALYTICS = "True";
OPENAI_API_BASE_URL = "http://192.168.1.100:1234/v1";
#OLLAMA_API_BASE_URL = "http://127.0.0.1:1234";
WEBUI_AUTH = "True";
ENABLE_SIGNUP = "False";
ENABLE_SIGNUP_PASSWORD_CONFIRMATION = "True";
ENABLE_VERSION_UPDATE_CHECK = "False";
};
};
};
}