From e6ed60548397627bf10f561f9438201dbba0a36e Mon Sep 17 00:00:00 2001 From: Azat Bahawi Date: Sun, 21 Apr 2024 02:15:42 +0300 Subject: 2024-04-21 --- modules/radicale.nix | 58 ++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 58 insertions(+) create mode 100644 modules/radicale.nix (limited to 'modules/radicale.nix') diff --git a/modules/radicale.nix b/modules/radicale.nix new file mode 100644 index 0000000..59fb4a2 --- /dev/null +++ b/modules/radicale.nix @@ -0,0 +1,58 @@ +{ + config, + inputs, + lib, + libNginx, + ... +}: +with lib; +let + cfg = config.nixfiles.modules.radicale; +in +{ + options.nixfiles.modules.radicale = { + enable = mkEnableOption "Radicale"; + + domain = mkOption { + description = "Domain name sans protocol scheme."; + type = with types; str; + default = "radicale.${config.networking.domain}"; + }; + }; + + config = + let + port = 5232; + in + mkIf cfg.enable { + ark.directories = [ "/var/lib/radicale" ]; + + secrets.radicale-htpasswd = { + file = "${inputs.self}/secrets/radicale-htpasswd"; + owner = "radicale"; + group = "radicale"; + }; + + nixfiles.modules.nginx = { + enable = true; + upstreams.radicale.servers."127.0.0.1:${toString port}" = { }; + virtualHosts.${cfg.domain} = { + locations."/".proxyPass = "http://radicale"; + extraConfig = libNginx.config.internalOnly; + }; + }; + + services.radicale = { + enable = true; + settings = { + server.hosts = [ "127.0.0.1:${toString port}" ]; + web.type = "none"; + auth = { + type = "htpasswd"; + htpasswd_filename = config.secrets.radicale-htpasswd.path; + htpasswd_encryption = "bcrypt"; + }; + }; + }; + }; +} -- cgit v1.2.3