summaryrefslogtreecommitdiff
path: root/hosts
diff options
context:
space:
mode:
authorTim Keller <tjk@tjkeller.xyz>2026-09-15 15:39:19 -0500
committerTim Keller <tjk@tjkeller.xyz>2026-09-15 15:39:19 -0500
commit0e6ce57a67f7158e27be3332b715466960ba0b99 (patch)
tree5b24cb3ec199350c5eaac6d47e9f8018fa54215e /hosts
parent871ff4e7fb4c22b2aea5cec147b091128fd50c72 (diff)
downloadnixos-0e6ce57a67f7158e27be3332b715466960ba0b99.tar.xz
nixos-0e6ce57a67f7158e27be3332b715466960ba0b99.zip
move searxng service to poweredge-pro
Diffstat (limited to 'hosts')
-rw-r--r--hosts/poweredge-pro/searxng.nix132
1 files changed, 132 insertions, 0 deletions
diff --git a/hosts/poweredge-pro/searxng.nix b/hosts/poweredge-pro/searxng.nix
new file mode 100644
index 0000000..cc5dfaf
--- /dev/null
+++ b/hosts/poweredge-pro/searxng.nix
@@ -0,0 +1,132 @@
+{
+ containers.searxng = {
+ autoStart = true;
+ privateNetwork = true;
+ hostBridge = "br-lan0";
+ localMacAddress = "02:00:00:00:00:05";
+
+ config = { pkgs, lib, config, ... }: let
+ environmentFile = "/run/searx/searxng.env";
+ generateEnvironmentFile = ''
+ umask 077
+ echo "SEARXNG_SECRET=$(head -c 56 /dev/urandom | base64)" > ${environmentFile}
+ ls /run/searx
+ '';
+ in {
+ # Network
+ networking.interfaces.eth0.useDHCP = true;
+
+ # Generate secret key
+ systemd.services.searx-environment-file = {
+ description = "Generate environment file with secret key for searx";
+ wantedBy = [ "searx-init.service" ];
+ partOf = [ "searx-init.service" ];
+ before = [ "searx-init.service" ];
+ serviceConfig = {
+ Type = "oneshot";
+ RemainAfterExit = true;
+ User = "searx";
+ RuntimeDirectory = "searx";
+ RuntimeDirectoryMode = "750";
+ ConditionPathExists = "!${environmentFile}";
+ };
+ script = generateEnvironmentFile;
+ };
+
+ # Configure searxng
+ services.searx = {
+ enable = true;
+ redisCreateLocally = true;
+ package = pkgs.searxng;
+ inherit environmentFile; # Provides secret key
+ openFirewall = true;
+
+ # UWSGI configuration
+ runInUwsgi = true;
+
+ uwsgiConfig = {
+ socket = "/run/searx/searx.sock";
+ http = ":8888";
+ chmod-socket = "660";
+ };
+
+ settings = {
+ general = {
+ instance_name = "TJK Search";
+ donation_url = "https://tjkeller.xyz";
+ enable_metrics = false;
+ };
+
+ server = {
+ port = 8080;
+ bind_address = "0.0.0.0";
+ };
+
+ # Search engine settings
+ search = {
+ safe_search = 2; # Strict
+ autocomplete = "";
+ default_lang = "en-US";
+ };
+
+ preferences.lock = [ "safesearch" ]; # Lock safe_search at strict
+
+ # https://docs.searxng.org/admin/plugins.html
+ enabled_plugins = [
+ "Tor check plugin"
+ "Tracker URL remover"
+ "Basic Calculator"
+ "Unit converter plugin"
+ "Hash plugin"
+ "Self Information"
+ "Open Access DOI rewrite"
+ "Hostnames plugin"
+ ];
+
+ hostnames.replace = {
+ "(.*\.)?youtube\.com$" = "yt.tjkeller.xyz";
+ "(.*\.)?youtu\.be$" = "yt.tjkeller.xyz";
+ #"(.*\.)?reddit\.com$" = "old.reddit.com";
+ };
+
+ # Enable / disabled search engines from default list
+ engines = lib.mapAttrsToList (name: value: { inherit name; disabled = !value; }) {
+ # Images
+ "artic" = false;
+ "deviantart" = false;
+ "flickr" = false;
+ "library of congress" = false;
+ "openverse" = false;
+ "pinterest" = false;
+ "public domain image archive" = false;
+ "unsplash" = false;
+ "wallhaven" = false;
+ "wikicommons.images" = false;
+
+ # Videos
+ "bitchute" = true;
+ "dailymotion" = false;
+ "piped" = false;
+ "rumble" = true;
+ "sepiasearch" = false;
+ "vimeo" = false;
+ "wikicommons.videos" = false;
+
+ # Music
+ "piped.music" = false;
+
+ # Files
+ "1337x" = true;
+ "annas archive" = true;
+ "library genesis" = true;
+
+ # Apps
+ "fdroid" = true;
+ };
+ };
+ };
+
+ system.stateVersion = "26.05";
+ };
+ };
+}