feat: ente: added

This commit is contained in:
2026-06-06 13:26:36 +00:00
parent 59dc5ecd1e
commit e04b7e11da
5 changed files with 291 additions and 4 deletions
+224
View File
@@ -0,0 +1,224 @@
{ ... }: {
lib,
config,
...
}: let
cfg = config.hectic.services.ente;
webHostNames = [
cfg.domains.accounts
cfg.domains.cast
cfg.domains.photos
];
in {
options.hectic.services.ente = {
enable = lib.mkEnableOption "Ente Photos self-hosted service";
apiDomain = lib.mkOption {
type = lib.types.str;
description = "Public hostname for the Ente Museum API.";
};
domains = {
accounts = lib.mkOption {
type = lib.types.str;
description = "Public hostname for the Ente accounts web app.";
};
cast = lib.mkOption {
type = lib.types.str;
description = "Public hostname for the Ente cast web app.";
};
albums = lib.mkOption {
type = lib.types.str;
description = "Public hostname for public Ente album links.";
};
photos = lib.mkOption {
type = lib.types.str;
description = "Public hostname for the Ente Photos web app.";
};
};
maxUploadSize = lib.mkOption {
type = lib.types.str;
default = "10G";
description = "Maximum request body accepted by nginx in front of Museum.";
};
disableRegistration = lib.mkOption {
type = lib.types.bool;
default = false;
description = "Whether Museum should reject new account registration.";
};
smtp = {
enable = lib.mkEnableOption "SMTP delivery for Ente verification emails";
host = lib.mkOption {
type = lib.types.str;
default = "127.0.0.1";
description = "SMTP host Museum uses to send verification emails.";
};
port = lib.mkOption {
type = lib.types.port;
default = 25;
description = "SMTP port Museum uses to send verification emails.";
};
email = lib.mkOption {
type = lib.types.str;
description = "From email address used by Museum.";
};
senderName = lib.mkOption {
type = lib.types.str;
default = "Ente Photos";
description = "Display name used for Ente verification emails.";
};
encryption = lib.mkOption {
type = lib.types.nullOr (lib.types.enum [ "tls" "ssl" ]);
default = null;
description = "Optional SMTP encryption mode. Leave null for local plaintext SMTP.";
};
};
storage = {
bucket = lib.mkOption {
type = lib.types.str;
description = "S3-compatible bucket used by Ente for photo object storage.";
};
endpoint = lib.mkOption {
type = lib.types.str;
description = "S3-compatible endpoint URL.";
};
region = lib.mkOption {
type = lib.types.str;
description = "S3-compatible region name.";
};
hotStorage = lib.mkOption {
type = lib.types.enum [
"b2-eu-cen"
"wasabi-eu-central-2-v3"
"scw-eu-fr-v3"
];
default = "b2-eu-cen";
description = ''
Museum's primary hot-storage key. Upstream requires one of its
historical S3 storage identifiers even when the backing provider is a
generic S3-compatible service.
'';
};
usePathStyleUrls = lib.mkOption {
type = lib.types.bool;
default = false;
description = "Whether Museum should use path-style S3 URLs.";
};
};
secrets = {
encryptionKeyFile = lib.mkOption {
type = lib.types.path;
description = "File containing Museum key.encryption.";
};
hashKeyFile = lib.mkOption {
type = lib.types.path;
description = "File containing Museum key.hash.";
};
jwtSecretFile = lib.mkOption {
type = lib.types.path;
description = "File containing Museum jwt.secret.";
};
s3AccessKeyFile = lib.mkOption {
type = lib.types.path;
description = "File containing the S3 access key.";
};
s3SecretKeyFile = lib.mkOption {
type = lib.types.path;
description = "File containing the S3 secret key.";
};
};
};
config = lib.mkIf cfg.enable {
services.ente = {
api = {
enable = true;
enableLocalDB = true;
domain = cfg.apiDomain;
nginx.enable = true;
settings = {
key = {
encryption._secret = cfg.secrets.encryptionKeyFile;
hash._secret = cfg.secrets.hashKeyFile;
};
jwt.secret._secret = cfg.secrets.jwtSecretFile;
s3 = {
hot_storage.primary = cfg.storage.hotStorage;
derived-storage = cfg.storage.hotStorage;
are_local_buckets = false;
use_path_style_urls = cfg.storage.usePathStyleUrls;
${cfg.storage.hotStorage} = {
key._secret = cfg.secrets.s3AccessKeyFile;
secret._secret = cfg.secrets.s3SecretKeyFile;
endpoint = cfg.storage.endpoint;
region = cfg.storage.region;
bucket = cfg.storage.bucket;
};
};
internal.disable-registration = cfg.disableRegistration;
smtp = lib.mkIf cfg.smtp.enable ({
inherit (cfg.smtp) host port email;
sender-name = cfg.smtp.senderName;
} // lib.optionalAttrs (cfg.smtp.encryption != null) {
encryption = cfg.smtp.encryption;
});
};
};
web = {
enable = true;
domains = {
api = cfg.apiDomain;
inherit (cfg.domains) accounts cast albums photos;
};
};
};
services.nginx.virtualHosts =
(lib.genAttrs webHostNames (_: {
enableACME = true;
forceSSL = true;
})) // {
${cfg.apiDomain} = {
enableACME = true;
forceSSL = true;
extraConfig = lib.mkForce ''
client_max_body_size ${cfg.maxUploadSize};
'';
locations."/".extraConfig = ''
proxy_read_timeout 600s;
proxy_send_timeout 600s;
'';
};
};
};
}
+2 -1
View File
@@ -8,6 +8,7 @@
hectic.services.attic = { hectic.services.attic = {
enable = true; enable = true;
hostName = "cache.${domain}"; hostName = "cache.${domain}";
port = 8081;
environmentFile = config.sops.secrets."atticd/environment".path; environmentFile = config.sops.secrets."atticd/environment".path;
storage = { storage = {
bucket = "cache-hectic-lab"; bucket = "cache-hectic-lab";
@@ -23,7 +24,7 @@
client_max_body_size 0; client_max_body_size 0;
''; '';
locations."/" = { locations."/" = {
proxyPass = "http://127.0.0.1:8080"; proxyPass = "http://127.0.0.1:8081";
}; };
}; };
} }
+42
View File
@@ -0,0 +1,42 @@
{
domain,
...
}: {
config,
...
}: let
enteDomain = "ente.${domain}";
in {
hectic.services.ente = {
enable = true;
apiDomain = "api.${enteDomain}";
disableRegistration = false;
domains = {
accounts = "accounts.${enteDomain}";
cast = "cast.${enteDomain}";
albums = "albums.${enteDomain}";
photos = "photos.${enteDomain}";
};
smtp = {
enable = true;
host = "mail.${domain}";
email = "security@${domain}";
};
storage = {
bucket = "ente-hectic-lab";
endpoint = "https://hel1.your-objectstorage.com";
region = "hel1";
};
secrets = {
encryptionKeyFile = config.sops.secrets."ente/key-encryption".path;
hashKeyFile = config.sops.secrets."ente/key-hash".path;
jwtSecretFile = config.sops.secrets."ente/jwt-secret".path;
s3AccessKeyFile = config.sops.secrets."ente/s3-access-key".path;
s3SecretKeyFile = config.sops.secrets."ente/s3-secret-key".path;
};
};
}
+15 -1
View File
@@ -37,6 +37,13 @@ let
hashedPasswordFile = config.sops.secrets."mailserver/${name}/hashedPassword".path; hashedPasswordFile = config.sops.secrets."mailserver/${name}/hashedPassword".path;
}; };
}; };
mkEnteSecret = name: {
name = "ente/${name}";
value = {
owner = "ente";
group = "ente";
};
};
in { in {
imports = [ imports = [
self.nixosModules.hectic self.nixosModules.hectic
@@ -50,6 +57,7 @@ in {
(import ./attic.nix { inherit flake self inputs domain; }) (import ./attic.nix { inherit flake self inputs domain; })
(import ./containers.nix { inherit flake self inputs; }) (import ./containers.nix { inherit flake self inputs; })
(import ./ente.nix { inherit domain; })
(import ./mechabellum.nix { inherit flake self inputs domain; }) (import ./mechabellum.nix { inherit flake self inputs domain; })
(import (./. + "/sentinèlla.nix") { inherit flake self inputs domain; }) (import (./. + "/sentinèlla.nix") { inherit flake self inputs domain; })
]; ];
@@ -115,7 +123,13 @@ in {
}; };
"atticd/environment" = {}; "atticd/environment" = {};
"wg-bfs/private-key" = {}; "wg-bfs/private-key" = {};
}; } // builtins.listToAttrs (map mkEnteSecret [
"key-encryption"
"key-hash"
"jwt-secret"
"s3-access-key"
"s3-secret-key"
]);
}; };
users.users.root.openssh.authorizedKeys.keys = [ users.users.root.openssh.authorizedKeys.keys = [
+8 -2
View File
File diff suppressed because one or more lines are too long