mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-11 14:27:26 +03:00
Review of dev vs16644fcfound 1 BLOCKING + 3 IMPORTANT + 2 MINOR. All addressed in this commit: B1 (R1.4 stale files in project-rules.md + AGENTS.md): Replaced 'vds/nginx.nix' (removed inef38dc4) with 'home/termux.nix' (added in958247b). R1.4 now correctly lists the 4 files that use 100.64.0.0: home/termux.nix:256, modules/server/nextcloud.nix:73, modules/server/nginx.nix:109,253, modules/vds/systemd.nix:10. I1 (count drift in '15 modules' docs): - AGENTS.md:84 + project-rules.md:97: '15 → 14' (with note that stirling-pdf was deleted in5dd7a58) - manifest.json (T16): rewritten acceptance to '15 archived (13 from server/default.nix:37-50 + 2 from containers/ kokoro-tts and openhands) + 1 deleted (stirling-pdf) + 1 active (open-webui in containers/)' - modules/server/default.nix:37-50: comment now explains the three categories I2 (T1 + T13 status stuck on pending): Both flipped to 'completed' in manifest.json. T1 import fix verified by nix eval (epral stateVersion = '24.05'). T13 done in61b3724(nginx firewall rule removed). I3 (.ci/checks.sh committed) satisfied. M1 (R1.3 stale nginx.nix:225 line number): Removed line number from both project-rules.md and AGENTS.md. Replaced with 'nginx.nix (networking.firewall)'. M2 (R1.2 listed 7 services, 2 in archive): Updated to 12 actual services in both files. n8n and minecraft were archived in T16; they no longer need storage guard. T10 (reality443Forwarding погашен): Removed option from options.nix:66-74, realityPorts from 3x-ui.nix:33-35, and 'reality443Forwarding = true' from vds/default.nix:19. ADR-note comments left in place. T15 (kokoro-tts and openhands archived): git mv modules/containers/kokoro-tts.nix → archive/containers/ git mv modules/containers/openhands.nix → archive/containers/ Also moved modules/containers/kokoro-tts/ (Dockerfile, app.py, etc.) to archive/containers/kokoro-tts/ for completeness. any.nix (nix flake check support): Added stub fileSystems + boot.loader.grub to configurations/any.nix so 'nix flake check' can evaluate the 'default' template config (which is never deployed — real hosts have their own disko/grub). wsl cleanup (dead imports blocking nix flake check): - Removed modules/wsl/containers/default.nix (was only imported nowhere, contained kokoro-tts reference) - Removed './containers' import from modules/wsl/default.nix (resolved to the now-removed default.nix) nix flake check: previously failed with 'Path modules/containers does not exist' (cached evaluation referenced old path). After this commit the error is gone — flake check progressed past the path resolution and started building derivations. Full build output not captured (5-min timeout for download from cache.nixos.org), but path errors are resolved. T5 risk acknowledgment: .agent/decisions/0002-backups-external.md updated with explicit risk table for 'if no backups' scenario + ADR/R1.9 guidance. T1, T2, T6, T7, T8, T9, T10, T12, T13, T15, T16, T17: all → completed in manifest.json. T3, T4, T5, T11, T14: previously completed. Remaining DEFERRED: T3 (otrecа SSH recovery), T5 (5.6 answer).
118 lines
4.0 KiB
Nix
118 lines
4.0 KiB
Nix
{
|
|
config,
|
|
lib,
|
|
pkgs,
|
|
xlib,
|
|
...
|
|
}:
|
|
let
|
|
panel = "${xlib.dirs.services-nodes-folder}/${xlib.device.hostname}/3x-ui";
|
|
# Domain whose Let's Encrypt cert (at /var/lib/acme/<domain>/) gets mounted
|
|
# read-only into the 3x-ui container so the panel can terminate TLS itself.
|
|
# Null when 3x-ui serves plain HTTP and TLS is terminated by an upstream
|
|
# nginx.
|
|
certDomain = config.host."3x-ui".certDomain;
|
|
certMounts =
|
|
if certDomain == null then
|
|
[ ]
|
|
else
|
|
# LE cert mounted read-only so 3x-ui can terminate TLS itself.
|
|
# The 3x-ui settings table must point webCertFile / webKeyFile at
|
|
# /root/cert/fullchain.pem and /root/cert/key.pem.
|
|
map (f: "/var/lib/acme/${certDomain}/${f}:/root/cert/${f}:ro") [
|
|
"fullchain.pem"
|
|
"key.pem"
|
|
];
|
|
basePorts = [
|
|
# Local-only upstreams for the 3x-ui panel and subscription endpoint.
|
|
# The direct Xray inbound remains publicly reachable on 8443.
|
|
"127.0.0.1:2049:2049/tcp"
|
|
"127.0.0.1:2096:2096/tcp"
|
|
"0.0.0.0:8443:8443/tcp"
|
|
];
|
|
in
|
|
{
|
|
# `host."3x-ui"` options are declared in modules/options.nix: they are set
|
|
# by modules/server and modules/vds, so this module cannot be the only place
|
|
# that knows they exist.
|
|
config = {
|
|
virtualisation = {
|
|
podman = {
|
|
enable = true;
|
|
autoPrune = {
|
|
enable = true;
|
|
flags = [ "--all" ];
|
|
};
|
|
dockerCompat = true;
|
|
};
|
|
oci-containers = {
|
|
backend = "podman";
|
|
containers."3xui_app" = {
|
|
image = "ghcr.io/mhsanaei/3x-ui:latest";
|
|
environment = {
|
|
"XRAY_VMESS_AEAD_FORCED" = "false";
|
|
"XUI_ENABLE_FAIL2BAN" = "true";
|
|
"TZ" = "Europe/Moscow";
|
|
};
|
|
volumes = [
|
|
"${panel}/cert/:/root/cert:rw"
|
|
"${panel}/db/:/etc/x-ui:rw"
|
|
]
|
|
++ certMounts;
|
|
log-driver = "journald";
|
|
# Adding a new inbound through the 3x-ui panel on a port outside
|
|
# the 14380-15379 range requires extending basePorts and rebuilding.
|
|
ports = basePorts;
|
|
};
|
|
};
|
|
};
|
|
|
|
systemd = {
|
|
services = {
|
|
"podman-3xui_app" = {
|
|
serviceConfig = xlib.helpers.mkStorageGuard xlib // {
|
|
Restart = lib.mkOverride 90 "always";
|
|
};
|
|
partOf = [ "podman-compose-3x-ui-root.target" ];
|
|
wantedBy = [ "podman-compose-3x-ui-root.target" ];
|
|
};
|
|
# Auto-update was removed intentionally: the `podman pull` path on the
|
|
# auto-update timer caused the declarative Nix state to diverge from the
|
|
# runtime state in 2026-10-04 (see
|
|
# .agent/decisions/notes/3x-ui-xray-26.9.md). The 3x-ui panel image and
|
|
# the Xray core are now updated manually through the panel UI, never
|
|
# via Nix.
|
|
};
|
|
# Starts/stops together with all 3x-ui compose resources.
|
|
targets."podman-compose-3x-ui-root" = {
|
|
unitConfig.Description = "Root target generated by compose2nix.";
|
|
wantedBy = [ "multi-user.target" ];
|
|
};
|
|
tmpfiles.rules = [
|
|
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-mnt-folder "0755" "root" "root")
|
|
(xlib.helpers.mkTmpfile "d" xlib.dirs.services-nodes-folder "0755" "root" "root")
|
|
(xlib.helpers.mkTmpfile "d" "${xlib.dirs.services-nodes-folder}/${xlib.device.hostname}" "0755"
|
|
"root"
|
|
"root"
|
|
)
|
|
(xlib.helpers.mkTmpfile "d" panel "0755" "root" "root")
|
|
(xlib.helpers.mkTmpfile "d" "${panel}/db" "0755" "root" "root")
|
|
(xlib.helpers.mkTmpfile "d" "${panel}/cert" "0755" "root" "root")
|
|
# Relabel panel dir for SELinux so containers can access it.
|
|
(xlib.helpers.mkTmpfile "Z" panel "0755" "root" "root")
|
|
];
|
|
};
|
|
|
|
# Enable container name DNS for all Podman networks.
|
|
networking.firewall = {
|
|
interfaces =
|
|
let
|
|
matchAll = if !config.networking.nftables.enable then "podman+" else "podman*";
|
|
in
|
|
{
|
|
"${matchAll}".allowedUDPPorts = [ 53 ];
|
|
};
|
|
};
|
|
};
|
|
}
|