2024-02-22 10:56:31 +01:00
|
|
|
{ config, lib, pkgs, ... }: {
|
|
|
|
|
|
|
|
# open up access to the mastodon web interface
|
|
|
|
networking.firewall.allowedTCPPorts = [ 443 ];
|
|
|
|
|
|
|
|
services.mastodon = {
|
|
|
|
enable = true;
|
|
|
|
|
|
|
|
# TODO: set up a domain name, and a DNS service so that this can run not in a vm
|
|
|
|
# localDomain = "domain.social";
|
|
|
|
configureNginx = true;
|
|
|
|
|
|
|
|
# TODO: configure a mailserver so this works
|
2024-02-28 22:49:16 +01:00
|
|
|
# smtp.fromAddress = "mastodon@social.local.gd";
|
2024-02-22 10:56:31 +01:00
|
|
|
|
|
|
|
# TODO: this is hardware-dependent. let's figure it out when we have hardware
|
|
|
|
# streamingProcesses = 1;
|
|
|
|
};
|
|
|
|
|
|
|
|
security.acme = {
|
|
|
|
acceptTerms = true;
|
|
|
|
preliminarySelfsigned = true;
|
|
|
|
# TODO: configure a mailserver so we can set up acme
|
|
|
|
# defaults.email = "test@example.com";
|
|
|
|
};
|
|
|
|
|
|
|
|
# let us log in
|
|
|
|
users.mutableUsers = false;
|
|
|
|
users.users.root.password = " ";
|
|
|
|
|
|
|
|
# access to convenient things
|
|
|
|
environment.systemPackages = with pkgs; [ w3m python3 ];
|
|
|
|
nix.extraOptions = ''
|
|
|
|
extra-experimental-features = nix-command flakes
|
|
|
|
'';
|
|
|
|
|
|
|
|
# these configurations only apply when producing a VM (e.g. nixos-rebuild build-vm)
|
|
|
|
virtualisation.vmVariant = { config, ... }: {
|
|
|
|
services.mastodon = {
|
|
|
|
# redirects to localhost, but allows it to have a proper domain name
|
|
|
|
# SEE: local.gd
|
|
|
|
localDomain = "social.local.gd";
|
|
|
|
|
2024-02-28 22:49:16 +01:00
|
|
|
smtp = {
|
|
|
|
fromAddress = "mastodon@social.local.gd";
|
|
|
|
createLocally = false;
|
|
|
|
};
|
2024-02-22 10:56:31 +01:00
|
|
|
# from the documentation: recommended is the amount of your CPU cores minus one.
|
|
|
|
# but it also must be a positive integer
|
|
|
|
streamingProcesses = let
|
2024-02-28 22:49:16 +01:00
|
|
|
ncores = config.virtualisation.cores;
|
2024-02-22 10:56:31 +01:00
|
|
|
max = x: y: if x > y then x else y;
|
|
|
|
in
|
|
|
|
max 1 (ncores - 1);
|
|
|
|
};
|
|
|
|
|
|
|
|
security.acme = {
|
|
|
|
defaults = {
|
|
|
|
# invalid server; the systemd service will fail, and we won't get properly signed certificates
|
|
|
|
# but let's not spam the letsencrypt servers (and we don't own this domain anyways)
|
|
|
|
server = "https://127.0.0.1";
|
|
|
|
email = "none";
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
2024-02-28 22:49:16 +01:00
|
|
|
virtualisation.memorySize = 2048;
|
2024-02-22 10:56:31 +01:00
|
|
|
virtualisation.forwardPorts = [
|
|
|
|
{
|
|
|
|
from = "host";
|
|
|
|
host.port = 44443;
|
|
|
|
guest.port = 443;
|
|
|
|
}
|
|
|
|
];
|
|
|
|
};
|
|
|
|
}
|
|
|
|
|