2024-09-09 03:47:53 +00:00
|
|
|
{
|
|
|
|
config,
|
|
|
|
lib,
|
|
|
|
pkgs,
|
|
|
|
...
|
|
|
|
}:
|
2024-09-06 16:57:11 +00:00
|
|
|
|
|
|
|
let
|
|
|
|
cfg = config.aux.system.services.home-assistant;
|
|
|
|
in
|
|
|
|
{
|
|
|
|
options = {
|
|
|
|
aux.system.services.home-assistant = {
|
2024-09-08 15:58:56 +00:00
|
|
|
enable = lib.mkEnableOption "Enables Home Assistant.";
|
2024-09-06 16:57:11 +00:00
|
|
|
home = lib.mkOption {
|
|
|
|
default = "/etc/home-assistant";
|
|
|
|
type = lib.types.str;
|
|
|
|
description = "Where to store Home Assistant's files";
|
|
|
|
example = "/home/home-assistant";
|
|
|
|
};
|
|
|
|
url = lib.mkOption {
|
|
|
|
default = "";
|
|
|
|
type = lib.types.str;
|
|
|
|
description = "The complete URL where Home Assistant is hosted.";
|
|
|
|
example = "https://home-assistant.example.com";
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
};
|
|
|
|
|
|
|
|
config = lib.mkIf cfg.enable {
|
|
|
|
services = {
|
|
|
|
home-assistant = {
|
2024-09-07 23:07:50 +00:00
|
|
|
enable = true;
|
2024-09-07 17:44:14 +00:00
|
|
|
# opt-out from declarative configuration management
|
|
|
|
lovelaceConfig = null;
|
|
|
|
# configure the path to your config directory
|
|
|
|
configDir = cfg.home;
|
|
|
|
# specify list of components required by your configuration
|
|
|
|
extraComponents = [
|
2024-09-07 23:07:50 +00:00
|
|
|
"default_config"
|
2024-09-07 17:44:14 +00:00
|
|
|
"esphome"
|
|
|
|
"eufy"
|
|
|
|
"govee_light_local"
|
|
|
|
"met"
|
|
|
|
"radio_browser"
|
|
|
|
"tplink"
|
|
|
|
];
|
2024-09-07 23:07:50 +00:00
|
|
|
extraPackages = python3Packages: with python3Packages; [ numpy ];
|
|
|
|
config.http = {
|
|
|
|
server_host = "::1";
|
|
|
|
trusted_proxies = [ "::1" ];
|
|
|
|
use_x_forwarded_for = true;
|
|
|
|
};
|
2024-09-07 17:44:14 +00:00
|
|
|
};
|
|
|
|
nginx.virtualHosts."${cfg.url}" = {
|
2024-09-09 03:47:53 +00:00
|
|
|
useACMEHost = pkgs.util.getDomainFromURL cfg.url;
|
2024-09-07 17:44:14 +00:00
|
|
|
forceSSL = true;
|
|
|
|
locations."/" = {
|
2024-09-07 23:07:50 +00:00
|
|
|
proxyPass = "http://[::1]:8123";
|
2024-09-07 17:44:14 +00:00
|
|
|
proxyWebsockets = true;
|
|
|
|
extraConfig = ''
|
|
|
|
# Security / XSS Mitigation Headers
|
|
|
|
add_header X-Frame-Options "SAMEORIGIN";
|
|
|
|
add_header X-Content-Type-Options "nosniff";
|
2024-09-06 16:57:11 +00:00
|
|
|
|
2024-09-07 17:44:14 +00:00
|
|
|
proxy_ssl_server_name on;
|
|
|
|
proxy_set_header Host $host;
|
|
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
|
|
proxy_set_header X-Real-IP $remote_addr;
|
2024-09-06 16:57:11 +00:00
|
|
|
|
2024-09-07 17:44:14 +00:00
|
|
|
proxy_buffering off;
|
|
|
|
'';
|
|
|
|
};
|
2024-09-06 16:57:11 +00:00
|
|
|
};
|
|
|
|
};
|
2024-09-07 17:44:14 +00:00
|
|
|
|
|
|
|
systemd.services = {
|
|
|
|
home-assistant.unitConfig.RequiresMountsFor = cfg.home;
|
|
|
|
nginx.wants = [ config.systemd.services.home-assistant.name ];
|
2024-09-06 16:57:11 +00:00
|
|
|
};
|
|
|
|
};
|
|
|
|
}
|