50 lines
1.4 KiB
Nix
50 lines
1.4 KiB
Nix
{config, ...}: let
|
|
serviceName = "homarr";
|
|
servicePort = config.m3ta.ports.get serviceName;
|
|
in {
|
|
virtualisation.oci-containers.containers.${serviceName} = {
|
|
image = "ghcr.io/homarr-labs/homarr:latest";
|
|
environment = {
|
|
TZ = "Europe/Berlin";
|
|
|
|
BASE_URL = "https://dash.az-gruppe.com";
|
|
NEXTAUTH_URL = "https://dash.az-gruppe.com";
|
|
AUTH_PROVIDERS = "oidc";
|
|
AUTH_OIDC_CLIENT_NAME = "Azure";
|
|
AUTH_OIDC_SCOPE_OVERWRITE = "openid email profile";
|
|
AUTH_OIDC_GROUPS_ATTRIBUTE = "roles";
|
|
AUTH_OIDC_GROUPS_LOCAL_MANAGEMENT = "true";
|
|
};
|
|
environmentFiles = [config.age.secrets.homarr-env.path];
|
|
ports = ["127.0.0.1:${toString servicePort}:7575"];
|
|
volumes = ["homarr_data:/appdata"];
|
|
extraOptions = ["--ip=10.89.0.13" "--network=web" "--dns=8.8.8.8" "--dns=8.8.4.4"];
|
|
};
|
|
|
|
# Traefik configuration
|
|
services.traefik.dynamicConfigOptions.http = {
|
|
services.${serviceName}.loadBalancer.servers = [
|
|
{
|
|
url = "http://localhost:${toString servicePort}/";
|
|
}
|
|
];
|
|
|
|
middlewares."${serviceName}-headers".headers = {
|
|
customRequestHeaders = {
|
|
X-Forwarded-Proto = "https";
|
|
X-Forwarded-Port = "443";
|
|
};
|
|
};
|
|
|
|
routers.${serviceName} = {
|
|
rule = "Host(`dash.az-gruppe.com`)";
|
|
tls = {
|
|
certResolver = "ionos";
|
|
};
|
|
service = serviceName;
|
|
entrypoints = "websecure";
|
|
middlewares = ["${serviceName}-headers"];
|
|
};
|
|
};
|
|
}
|