{ config, lib, pkgs, inputs, xlib, ... }: { # Runtime virtualisation.podman = { enable = true; autoPrune.enable = true; dockerCompat = true; }; # Enable container name DNS for all Podman networks. networking.firewall.interfaces = let matchAll = if !config.networking.nftables.enable then "podman+" else "podman*"; in { "${matchAll}".allowedUDPPorts = [ 53 ]; }; virtualisation.oci-containers.backend = "podman"; # Containers virtualisation.oci-containers.containers."remnawave-panel-1" = { image = "ghcr.io/remnawave/backend:latest"; environment = { "API_INSTANCES" = "1"; "APP_PORT" = "3000"; "BANDWIDTH_USAGE_NOTIFICATIONS_ENABLED" = "false"; "BANDWIDTH_USAGE_NOTIFICATIONS_THRESHOLD" = "[60, 80]"; "FRONT_END_DOMAIN" = "*"; "IS_DOCS_ENABLED" = "false"; "IS_TELEGRAM_NOTIFICATIONS_ENABLED" = "false"; "METRICS_PASS" = "admin"; "METRICS_PORT" = "3001"; "METRICS_USER" = "admin"; "NOT_CONNECTED_USERS_NOTIFICATIONS_AFTER_HOURS" = "[6, 24, 48]"; "NOT_CONNECTED_USERS_NOTIFICATIONS_ENABLED" = "false"; "PANEL_DOMAIN" = "rw.zeroq.ru"; "POSTGRES_DB" = "remnawave"; "POSTGRES_USER" = "remnawave"; "REDIS_SOCKET" = "/var/run/valkey/valkey.sock"; "SCALAR_PATH" = "/scalar"; "SUB_PUBLIC_DOMAIN" = "rw.zeroq.ru/api/sub"; "SWAGGER_PATH" = "/docs"; # "TELEGRAM_BOT_TOKEN" = "change_me"; # "TELEGRAM_NOTIFY_CRM" = "change_me"; # "TELEGRAM_NOTIFY_NODES" = "change_me"; # "TELEGRAM_NOTIFY_SERVICE" = "change_me"; # "TELEGRAM_NOTIFY_TBLOCKER" = "change_me"; # "TELEGRAM_NOTIFY_USERS" = "change_me"; "WEBHOOK_ENABLED" = "false"; # "WEBHOOK_URL" = "https://your-webhook-url.com/endpoint"; }; environmentFiles = [ "/run/secrets/remnawave-env" ]; ports = [ "3003:3003/tcp" ]; log-driver = "journald"; extraOptions = [ "--network-alias=remnawave-panel-1" "--network=host" # "--network=remnawavebackend_default" ]; }; systemd.services."podman-remnawave-panel-1" = { serviceConfig = { Restart = lib.mkOverride 90 "always"; }; partOf = [ "podman-compose-remnawave-root.target" ]; wantedBy = [ "podman-compose-remnawave-root.target" ]; }; # Builds # systemd.services."podman-build-remnawave-panel-1" = { # path = [ pkgs.podman pkgs.git ]; # serviceConfig = { # Type = "oneshot"; # TimeoutSec = 300; # }; # script = '' # cd /mnt/s/Deploy/remnawave-backend # podman build -t compose2nix/remnawave-panel-1 . # ''; # }; # Root service # When started, this will automatically create all resources and start # the containers. When stopped, this will teardown all resources. systemd.targets."podman-compose-remnawave-root" = { unitConfig = { Description = "Root target generated by compose2nix."; }; wantedBy = [ "multi-user.target" ]; }; services = { postgresql = { ensureDatabases = [ "remnawave" ]; ensureUsers = [ { name = "remnawave"; ensureDBOwnership = true; } ]; }; }; systemd.services = { remnawave-env = { description = "Generate remnawave env file"; requiredBy = [ "podman-remnawave-panel-1.service" ]; before = [ "podman-remnawave-panel-1.service" ]; serviceConfig = { Type = "oneshot"; User = "root"; }; script = '' cat > /run/secrets/remnawave-env <