62 lines
1.9 KiB
Nix
62 lines
1.9 KiB
Nix
{config, ...}: let
|
|
serviceName = "n8n";
|
|
servicePort = config.m3ta.ports.get serviceName;
|
|
sandboxApiPort = config.m3ta.ports.get "n8n-sandbox-api";
|
|
sambaMounts = [
|
|
"/mnt/AutoAblage"
|
|
"/mnt/SkriptHelper"
|
|
"/mnt/DMS-ALT-INBOX"
|
|
"/mnt/DMS-INBOX"
|
|
];
|
|
in {
|
|
services.n8n = {
|
|
enable = true;
|
|
environment = {
|
|
WEBHOOK_URL = "https://wf.l.az-gruppe.com";
|
|
NODES_EXCLUDE = "[]";
|
|
N8N_RESTRICT_FILE_ACCESS_TO = builtins.concatStringsSep ";" sambaMounts;
|
|
N8N_RUNNERS_ENABLED = true;
|
|
N8N_NATIVE_PYTHON_RUNNER = true;
|
|
N8N_RUNNERS_AUTH_TOKEN_FILE = config.age.secrets.n8n-runner-auth-token.path;
|
|
N8N_LOG_OUTPUT = "json";
|
|
N8N_LOG_LEVEL = "info";
|
|
N8N_ENABLED_MODULES = "instance-ai";
|
|
N8N_INSTANCE_AI_SANDBOX_ENABLED = true;
|
|
N8N_INSTANCE_AI_SANDBOX_PROVIDER = "n8n-sandbox";
|
|
N8N_INSTANCE_AI_SANDBOX_IMAGE = "ghcr.io/n8n-io/n8n-sandbox-service-sandbox:latest";
|
|
N8N_INSTANCE_AI_SANDBOX_API_URL = "http://127.0.0.1:${toString sandboxApiPort}";
|
|
N8N_SANDBOX_SERVICE_URL = "http://127.0.0.1:${toString sandboxApiPort}";
|
|
};
|
|
taskRunners.enable = true;
|
|
};
|
|
|
|
systemd.services.n8n = {
|
|
serviceConfig = {
|
|
EnvironmentFile = ["${config.age.secrets.n8n-env.path}" "${config.age.secrets.n8n-sandbox-env.path}"];
|
|
ReadWritePaths = sambaMounts;
|
|
};
|
|
wants = ["podman-sandbox-api.service"];
|
|
after = ["podman-sandbox-api.service"];
|
|
};
|
|
|
|
systemd.services.n8n-task-runner.serviceConfig.ReadWritePaths = sambaMounts;
|
|
|
|
# Traefik configuration specific to n8n
|
|
services.traefik.dynamicConfigOptions.http = {
|
|
services.${serviceName}.loadBalancer.servers = [
|
|
{
|
|
url = "http://localhost:${toString servicePort}/";
|
|
}
|
|
];
|
|
|
|
routers.${serviceName} = {
|
|
rule = "Host(`wf.l.az-gruppe.com`)";
|
|
tls = {
|
|
certResolver = "ionos";
|
|
};
|
|
service = serviceName;
|
|
entrypoints = "websecure";
|
|
};
|
|
};
|
|
}
|