aboutsummaryrefslogtreecommitdiffstats
path: root/flake.nix
blob: 6092965f7be3f4ea777d7f794fc0c69ea9898ab8 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
{
	description = "EmbedTube - A YouTube micro-client for embeded videos";

	inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";

	outputs = { self, nixpkgs }: let
		systems = [ "x86_64-linux" "aarch64-linux" "x86_64-darwin" "aarch64-darwin" ];
		forAllSystems = f: nixpkgs.lib.genAttrs systems (system: f nixpkgs.legacyPackages.${system});
	in {
		packages = forAllSystems (pkgs: {
			default = pkgs.buildGoModule {
				pname = "embedtube";
				version = "1.0.0";
				src = ./.;
				vendorHash = "sha256-bVuk+0Ukt8AOueQHRMK1sphjfk9eG5SG9gRLxe3eHJg=";
				meta.mainProgram = "embedtube";
			};
		});

		devShells = forAllSystems (pkgs: {
			default = pkgs.mkShell {
				packages = with pkgs; [ go gopls gotools ];
			};
		});

		nixosModules.default = { config, lib, pkgs, ... }: let
			cfg = config.services.embedtube;
			haveAPIKey = cfg.apiKeyFile != null;
		in {
			options.services.embedtube = {
				enable = lib.mkEnableOption "enable embedtube service";
				package = lib.mkOption {
					type = lib.types.package;
					default = self.packages.${pkgs.stdenv.hostPlatform.system}.default;
					defaultText = lib.literalExpression "embedtube.packages.\${system}.default";
					description = "The embedtube package to use";
				};
				port = lib.mkOption {
					type = lib.types.port;
					default = 8080;
					description = "port to listen on";
				};
				listenAddress = lib.mkOption {
					type = lib.types.str;
					default = "127.0.0.1";
					description = "address to bind to";
				};
				openFirewall = lib.mkEnableOption "open the listen port in the firewall";
				apiKeyFile = lib.mkOption {
					type = lib.types.nullOr lib.types.path;
					default = null;
					description = "file containing api key, not to be included in nix store";
				};
			};

			config = lib.mkIf cfg.enable {
				networking.firewall.allowedTCPPorts = lib.mkIf cfg.openFirewall [ cfg.port ];
				systemd.services.embedtube = {
					description = "embedtube";
					wantedBy = [ "multi-user.target" ];
					after = [ "network-online.target" ];
					wants = [ "network-online.target" ];
					serviceConfig = {
						ExecStart = lib.getExe cfg.package;
						LoadCredential = lib.mkIf haveAPIKey [ "api_key:${cfg.apiKeyFile}" ];
						Restart = "on-failure";
						DynamicUser = true;
					};
					environment = {
						PORT = toString cfg.port;
						HOST = cfg.listenAddress;
						API_KEY_FILE = lib.mkIf haveAPIKey "%d/api_key";
					};
				};
			};
		};
	};
}