2024-03-25 19:46:18 +01:00
|
|
|
{ materusArg, config, lib, pkgs, ... }:
|
|
|
|
{
|
|
|
|
options.waffentragerService.nextcloud.enable = materusArg.pkgs.lib.mkBoolOpt false "Enable nextcloud";
|
|
|
|
|
|
|
|
config =
|
|
|
|
let
|
|
|
|
cfg = config.waffentragerService.nextcloud;
|
|
|
|
in
|
|
|
|
lib.mkIf cfg.enable {
|
|
|
|
waffentragerService.elements.enable = true;
|
|
|
|
waffentragerService.postgresql.enable = true;
|
|
|
|
waffentragerService.nginx.enable = true;
|
2024-03-26 00:52:23 +01:00
|
|
|
environment.systemPackages = [ pkgs.samba pkgs.exiftool pkgs.ffmpeg-headless ];
|
2024-03-25 19:46:18 +01:00
|
|
|
sops.secrets.nextcloud-adminpass.owner = config.users.users.nextcloud.name;
|
|
|
|
sops.secrets.nextcloud-adminpass.group = config.users.users.nextcloud.group;
|
|
|
|
|
|
|
|
services.postgresql.ensureDatabases = [ "nextcloud" ];
|
|
|
|
services.postgresql.ensureUsers = [{
|
|
|
|
name = "nextcloud";
|
|
|
|
ensureDBOwnership = true;
|
|
|
|
}];
|
|
|
|
services.nextcloud = {
|
|
|
|
enable = true;
|
|
|
|
notify_push.enable = true;
|
2024-06-17 13:41:18 +02:00
|
|
|
package = pkgs.nextcloud29;
|
2024-03-25 19:46:18 +01:00
|
|
|
hostName = "waffentrager.materus.pl";
|
|
|
|
home = config.waffentragerService.elements.nextcloudDir;
|
|
|
|
config.adminuser = "master";
|
|
|
|
config.adminpassFile = config.sops.secrets.nextcloud-adminpass.path;
|
|
|
|
config.dbtype = "pgsql";
|
|
|
|
extraAppsEnable = true;
|
|
|
|
maxUploadSize = "4G";
|
|
|
|
https = true;
|
|
|
|
enableImagemagick = true;
|
|
|
|
configureRedis = true;
|
|
|
|
webfinger = true;
|
|
|
|
appstoreEnable = true;
|
|
|
|
database.createLocally = true;
|
|
|
|
nginx.recommendedHttpHeaders = true;
|
2024-06-17 13:41:18 +02:00
|
|
|
extraApps = with pkgs.nextcloud29Packages.apps; {
|
2024-03-26 09:22:50 +01:00
|
|
|
inherit notify_push previewgenerator;
|
|
|
|
};
|
2024-06-17 13:41:18 +02:00
|
|
|
settings = {
|
|
|
|
"profile.enabled" = true;
|
|
|
|
default_phone_region = "PL";
|
|
|
|
trusted_proxies = [ materusArg.ips.valkyrie materusArg.ips.wireguard.valkyrie materusArg.ips.wireguard.waffentrager ];
|
2024-03-25 19:46:18 +01:00
|
|
|
mail_smtpmode = "sendmail";
|
|
|
|
mail_sendmailmode = "pipe";
|
2024-03-26 15:29:45 +01:00
|
|
|
enable_previews = true;
|
2024-03-28 17:13:49 +01:00
|
|
|
preview_format = "webp";
|
2024-03-26 15:29:45 +01:00
|
|
|
enabledPreviewProviders = [
|
|
|
|
''OC\Preview\Movie''
|
|
|
|
''OC\Preview\PNG''
|
|
|
|
''OC\Preview\JPEG''
|
|
|
|
''OC\Preview\GIF''
|
|
|
|
''OC\Preview\BMP''
|
|
|
|
''OC\Preview\XBitmap''
|
|
|
|
''OC\Preview\MP3''
|
2024-07-12 01:28:33 +02:00
|
|
|
''OC\Preview\OGG''
|
|
|
|
''OC\Preview\OPUS''
|
2024-03-26 15:29:45 +01:00
|
|
|
''OC\Preview\MP4''
|
|
|
|
''OC\Preview\TXT''
|
|
|
|
''OC\Preview\MarkDown''
|
|
|
|
''OC\Preview\PDF''
|
2024-03-26 20:14:37 +01:00
|
|
|
''OC\Preview\WebP''
|
|
|
|
''OC\Preview\OpenDocument''
|
|
|
|
''OC\Preview\Krita''
|
|
|
|
''OC\Preview\AVIF''
|
2024-03-26 15:29:45 +01:00
|
|
|
];
|
|
|
|
"overwrite.cli.url" = "https://${config.services.nextcloud.hostName}";
|
2024-03-25 19:46:18 +01:00
|
|
|
};
|
2024-03-25 21:56:01 +01:00
|
|
|
|
2024-03-26 09:22:50 +01:00
|
|
|
phpOptions = {
|
2024-03-28 17:13:49 +01:00
|
|
|
"opcache.memory_consumption" = "512";
|
|
|
|
"opcache.interned_strings_buffer" = "64";
|
|
|
|
"opcache.max_accelerated_files"="50000";
|
2024-03-26 10:21:34 +01:00
|
|
|
"opcache.jit" = "1255";
|
|
|
|
"opcache.jit_buffer_size" = "128M";
|
2024-03-28 17:13:49 +01:00
|
|
|
"opcache.validate_timestamps" = "0";
|
|
|
|
"opcache.revalidate_freq" = "0";
|
|
|
|
"opcache.fast_shutdown" = "1";
|
2024-03-26 10:21:34 +01:00
|
|
|
"opcache.save_comments" = "1";
|
2024-03-25 21:56:01 +01:00
|
|
|
};
|
2024-03-28 17:13:49 +01:00
|
|
|
phpExtraExtensions = ex: [ ex.zip ex.zlib ex.tidy ex.smbclient ];
|
2024-03-25 19:46:18 +01:00
|
|
|
};
|
|
|
|
services.nginx.virtualHosts.${config.services.nextcloud.hostName} = {
|
2024-03-26 01:42:38 +01:00
|
|
|
forceSSL = true;
|
|
|
|
http3 = true;
|
2024-03-25 19:46:18 +01:00
|
|
|
sslTrustedCertificate = "/var/lib/mnt_acme/materus.pl/chain.pem";
|
|
|
|
sslCertificateKey = "/var/lib/mnt_acme/materus.pl/key.pem";
|
|
|
|
sslCertificate = "/var/lib/mnt_acme/materus.pl/fullchain.pem";
|
|
|
|
extraConfig = ''
|
|
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
};
|
|
|
|
}
|