{ pkgs, tree, ... }: let misskeyDomain = "social.owo.monster"; misskeyPort = 3020; redisPort = 3019; misskeyPackages = with pkgs; [ nodejs yarn nodePackages.node-gyp python3 pkg-config glib vips stdenv ]; misskeyPackage = pkgs.callPackage ./misskey-pkg.nix { }; misskeyConfig = { url = "https://${misskeyDomain}/"; port = misskeyPort; id = "aid"; db = { host = "localhost"; port = "5432"; db = "misskey"; user = "misskey"; pass = "password"; }; redis = { host = "127.0.0.1"; port = redisPort; }; }; misskeyConfigFile = builtins.toFile "default.yml" (pkgs.lib.generators.toYAML { } misskeyConfig); in { users.users."misskey" = { isNormalUser = true; createHome = true; }; home-manager.users."misskey" = { home.packages = misskeyPackages; home.stateVersion = "22.05"; imports = with tree; [ home.base home.dev.small ]; }; systemd.tmpfiles.rules = [ "d /home/misskey/misskey-files - misskey users" ]; systemd.services.misskey-files = { serviceConfig.Type = "oneshot"; after = [ "home-manager-misskey.service" "network.target" ]; path = with pkgs; [ bash git ] ++ misskeyPackages; script = '' rm -rf /home/misskey/misskey || true cp -rv ${misskeyPackage} /home/misskey/misskey rm -rf /home/misskey/misskey/.config mkdir /home/misskey/misskey/.config cat ${misskeyConfigFile} > /home/misskey/misskey/.config/default.yml ln -s /home/misskey/misskey-files /home/misskey/misskey/files cd /home/misskey/misskey yarn install NODE_ENV=production yarn build chown -R misskey:users /home/misskey/misskey ''; }; systemd.services.misskey-password = { serviceConfig.Type = "oneshot"; wants = [ "postgresql.service" ]; script = '' ${pkgs.postgresql}/bin/psql -c "ALTER USER misskey WITH PASSWORD 'password';" ''; serviceConfig.User = "misskey"; }; systemd.services.misskey = { after = [ "misskey-files.service" "misskey-password.service" ]; wants = [ "postgresql.service" "redis-misskey.service" "misskey-password.service" ]; wantedBy = [ "multi-user.target" ]; path = with pkgs; [ bash git ] ++ misskeyPackages; environment.NODE_ENV = "production"; serviceConfig = { User = "misskey"; WorkingDirectory = "/home/misskey/misskey"; ExecStartPre = "${pkgs.yarn}/bin/yarn migrate"; ExecStart = "${pkgs.nodejs}/bin/node --experimental-json-modules packages/backend/built/index.js"; #TimeoutSec = 60; #StandardOutput = "syslog"; #StandardError = "syslog"; #SyslogIdentifier = "misskey"; #Restart = "always"; }; }; services.nginx.virtualHosts."${misskeyDomain}" = { forceSSL = true; enableACME = true; locations = { "/" = { proxyPass = "http://127.0.0.1:${toString misskeyPort}"; proxyWebsockets = true; }; }; }; services.postgresql = { enable = true; ensureUsers = [{ name = "misskey"; ensurePermissions."DATABASE misskey" = "ALL PRIVILEGES"; }]; ensureDatabases = [ "misskey" ]; initialScript = pkgs.writeText "init" '' create user misskey with password 'password'; grant all privileges on database misskey to misskey; ''; }; services.redis.servers."misskey" = { enable = true; port = redisPort; }; }