{ pkgs, ... }: let misskeyDomain = "social.owo.monster"; misskeyPort = 3020; redisPort = 3019; in { users.users."misskey" = { isNormalUser = true; createHome = true; extraGroups = [ "docker" ]; }; home-manager.users."misskey".home.packages = with pkgs; [ git docker-compose ]; virtualisation.docker.enable = true; # make .config/default.yml a symlink to /etc/misskey.yml environment.etc."misskey.yml".text = pkgs.lib.generators.toYAML { } { url = "https://${misskeyDomain}/"; port = misskeyPort; db = { host = "localhost"; port = "5432"; db = "misskey"; user = "misskey"; pass = "a"; }; redis = { host = "127.0.0.1"; port = redisPort; }; }; services.nginx.virtualHosts."${misskeyDomain}" = { forceSSL = true; enableACME = true; locations = { "/" = { proxyPass = "http://127.0.0.1:${toString misskeyPort}"; proxyWebsockets = true; }; }; }; services.postgresql = { enable = true; ensureUsers = [{ name = "misskey"; ensurePermissions."DATABASE misskey" = "ALL PRIVILEGES"; }]; ensureDatabases = [ "misskey" ]; }; services.redis.servers."misskey" = { enable = true; port = redisPort; }; }