No description
  • Nix 91.1%
  • Python 8.8%
Find a file
2026-08-16 17:26:13 -06:00
.forgejo/workflows fix: set git remote URL with token for push auth in workflow 2026-07-26 14:31:57 -06:00
config fix(searxng): define doi_resolvers explicitly (file replaces defaults, choices were empty) 2026-08-12 19:55:33 -06:00
docs docs: add Caddy to Traefik migration plan for NetBird self-hosting 2026-06-01 20:38:37 -06:00
dotfiles refactor: move service configs to config/ directory 2026-06-23 16:31:19 -06:00
scripts feat: enable Forgejo Actions, runner, and automated image update workflow 2026-07-25 00:36:21 -06:00
.editorconfig feat(nix-formatting): add nixfmt pre-commit hook and .editorconfig 2026-05-06 11:00:59 -06:00
.env feat: add GetHealthy fitness tracker stack 2026-08-09 17:46:10 -06:00
.gitignore feat: add borg backup job for minerva services 2026-08-04 20:49:40 -06:00
actualbudget.nix style: formatting 2026-03-14 14:38:26 -06:00
AGENTS.md docs: add comment-out rule to agent instructions and checklist 2026-07-26 20:55:24 -06:00
aiostreams.nix feat: add AIOStreams (Stremio Super-Addon) 2026-08-03 00:10:19 -06:00
airtrail.nix fix(airtrail): chown postgres data dir to alpine uid 70 (999 broke postgres:17-alpine) 2026-08-12 19:42:16 -06:00
archivebox.nix fix: add trailing newline to archivebox.nix 2026-08-08 21:10:25 -06:00
autosuspend.nix chore: disable autosuspend in favor of scheduled sleep 2026-04-23 20:58:33 -06:00
bentopdf.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
beszel.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
borg.nix chore: move borg backup to 22:00 2026-08-08 23:04:47 -06:00
caddy.nix feat: add GetHealthy fitness tracker stack 2026-08-09 17:46:10 -06:00
changedetection.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
cobalt.nix fix: use latest tag for all containers with broken image tags 2026-07-26 19:30:47 -06:00
collabora.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
commitlint.config.js fix: enable subject-empty and type-empty commitlint rules 2026-05-23 19:48:52 -06:00
configuration.nix feat: enable netbird sso for copyparty 2026-08-16 17:26:13 -06:00
copyparty.nix style: formatting 2026-03-14 14:38:26 -06:00
dawarich.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
disable-sleep.nix style: formatting 2026-03-14 14:38:26 -06:00
dnsmasq.nix chore: finish immich migration to proxmox, remove local migration proxy 2026-08-08 18:52:58 -06:00
dozzle.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
dynacat.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
flake.lock chore: update flake.lock file 2026-07-22 17:10:09 -06:00
flake.nix feat: add Grayjay headless server (port 11338) 2026-06-04 20:40:31 -06:00
forgejo.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
futo-notes.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
gatus.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
gethealthy.nix style: format gethealthy.nix 2026-08-09 17:51:32 -06:00
glance.nix chore: comment out Actual Budget service 2026-05-17 17:10:02 -06:00
grafana.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
grayjay.nix fix: use handle_path instead of handle for Caddy file_server 2026-07-26 02:27:04 -06:00
grocy.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
hacs.nix feat: add proxmox integration to home assistant 2026-03-01 20:09:40 -06:00
hardware-configuration.nix feat: add tmp unlock 2026-04-15 18:21:23 -06:00
homarr.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
home-assistant.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
home.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
homepage-config.nix fix: rename speedtest entries to distinguish minerva vs proxmox 2026-08-03 00:14:44 -06:00
homepage-public.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
homepage-services.nix refactor: move Caddy entries + homepage services into individual .nix files 2026-07-31 19:27:39 -06:00
homepage.nix refactor: move Caddy entries + homepage services into individual .nix files 2026-07-31 19:27:39 -06:00
immich.nix feat: migrate immich to proxmox, keep local proxy for migration 2026-08-03 00:11:27 -06:00
INFRA_ANALYSIS.md docs: remove 6 resolved items from INFRA_ANALYSIS.md, renumber remaining 2026-07-26 20:48:33 -06:00
joplin-server.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
karakeep.nix feat: enable full-page archive for karakeep 2026-08-09 23:03:38 -06:00
kosync.nix chore: pin all unpinned Docker images to specific versions 2026-07-24 23:43:44 -06:00
kurrier.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
languagetool.nix chore: pin all unpinned Docker images to specific versions 2026-07-24 23:43:44 -06:00
lefthook.yml fix(nix-formatting): filter staged files to *.nix only 2026-05-06 11:01:25 -06:00
librespeed.nix chore: switch LinuxServer Docker images to latest tag 2026-07-26 17:58:24 -06:00
libretranslate.nix style: formatting 2026-03-14 14:38:26 -06:00
local-content-share.nix feat: add local-content-share (file sharing tool) 2026-07-02 01:11:45 -06:00
localsend.nix first commit 2026-03-01 17:25:24 -06:00
mafl.nix chore: pin all unpinned Docker images to specific versions 2026-07-24 23:43:44 -06:00
marreta.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
metube.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
mise.toml feat: add mise task to clear metube downloads 2026-08-05 17:59:07 -06:00
n8n.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
netbird-caddy-sync-readme.md feat: add netbird-caddy-sync service to sync Caddy vhosts to NetBird reverse proxy 2026-06-18 20:44:32 -06:00
netbird-caddy-sync.nix feat: add remote Home dashboard, service exclude list, and NetBird SSO support 2026-06-19 00:38:09 -06:00
netbird.nix fix(netbird): disable default daemon, fix login ReadWritePaths 2026-07-27 13:23:09 -06:00
nextcloud.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
nixos-config@minerva.code-workspace docs: add workspace file 2026-05-04 10:04:20 -06:00
onlyoffice.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
opencloud.nix feat: enable calendar/contacts in OpenCloud via radicale service 2026-08-01 12:13:58 -06:00
pairdrop.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
papra.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
pinchflat.nix fix: use latest tag for all containers with broken image tags 2026-07-26 19:30:47 -06:00
plausible.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
podsync.nix style: add trailing newline to podsync.nix 2026-08-08 19:22:36 -06:00
priceghost.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
projectsend.nix chore: switch LinuxServer Docker images to latest tag 2026-07-26 17:58:24 -06:00
prometheus-blackbox.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
proxmox-control-server.py feat: complete minerva.lan to home.arpa migration for all services 2026-05-09 23:51:49 -06:00
proxmox-control.nix feat(nix-formatting): add nixfmt pre-commit hook and .editorconfig 2026-05-06 11:00:59 -06:00
pulse.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
reactive-resume.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
README.md style: format README 2026-06-09 08:25:11 -06:00
redlib.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
runner-config.yaml fix: revert to native:host (daemon doesn't support -self-hosted) 2026-07-26 17:44:18 -06:00
rustdesk.nix chore: pin all unpinned Docker images to specific versions 2026-07-24 23:43:44 -06:00
scheduled-power.nix fix(sleep-scheduler): correct wake alarm to 'today' instead of 'tomorrow', add time-sync guard and midnight window check 2026-05-21 07:09:48 -06:00
seafile.nix chore: pin all unpinned Docker images to specific versions 2026-07-24 23:43:44 -06:00
searxng.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
SERVICES_CHECKLIST.md docs: add docker port conflict check and Immich ML port 3003 2026-07-26 21:11:38 -06:00
smokeping.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
snappymail.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
sparkyfitness.nix fix: revert sparkyfitness postgres volume to /var/lib/postgresql for PG18 layout 2026-08-08 22:32:59 -06:00
speedtest-tracker.nix fix: rename speedtest entries to distinguish minerva vs proxmox 2026-08-03 00:14:44 -06:00
sync.py fix(netbird-sync): route all NetBird RP targets through Caddy proxy 2026-07-27 13:23:15 -06:00
syncthing.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
tasktrove.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
transmute.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
uptime-kuma.nix chore: pin all unpinned Docker images to specific versions 2026-07-24 23:43:44 -06:00
vaultwarden.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
vert.nix fix: remove Caddy entries from service .nix files, restore caddy.nix 2026-07-31 19:39:36 -06:00
wger.nix fix: add PS_DATABASE_URI for wger containers 2026-08-09 13:48:18 -06:00

NixOS

Rebuild

sudo nixos-rebuild switch --flake .#$(hostname)

Forgejo

Adding SSH key for git push

1. Generate an SSH key on the new PC: ssh-keygen -t ed25519 -C "s4mxdhid@zurimail.org"
2. Add the public key to Forgejo at <https://forgejo.home.arpa/user/settings/keys>
3. Then clone with: git clone ssh://forgejo@minerva.lan/s4mxdhid/nixos-config.git

1. Add your SSH key to Forgejo: <https://forgejo.home.arpa/user/settings/keys>
2. Switch remote to SSH:

   ```bash
   git remote set-url origin ssh://forgejo@minerva.lan/s4mxdhid/nixos-config.git
nix-shell -p openssl --run 'echo "NEXTAUTH_SECRET=$(openssl rand -base64 36)" | sudo tee /var/lib/karakeep/secrets.env'

Nextcloud Docker Setup

Initial Installation

Nextcloud is run as a Docker container managed by NixOS virtualisation.oci-containers. PostgreSQL runs as a separate container on the same Docker network (nextcloud-net).

Docker Network

The nextcloud-net network must exist before containers start. It is created by init-nextcloud-network.service on boot. To create it manually:

sudo docker network create nextcloud-net

First Boot / Fresh Install

The Docker entrypoint only runs auto-install if config/config.php does not exist. If installation did not complete cleanly, remove the partial config and reinstall manually:

sudo docker stop nextcloud
sudo rm -f /var/lib/nextcloud/config/config.php
sudo systemctl start docker-nextcloud.service

sudo docker exec -u 33 nextcloud php /var/www/html/occ maintenance:install \
  --database pgsql \
  --database-name nextcloud \
  --database-host postgres-nextcloud \
  --database-user nextcloud \
  --database-pass <POSTGRES_PASSWORD> \
  --admin-user admin \
  --admin-pass <ADMIN_PASSWORD> \
  --data-dir /var/www/html/data

Post-Install Configuration

After install, set trusted domains, proxy settings and overwrite protocol:

sudo docker exec -u 33 nextcloud php occ config:system:set trusted_domains 0 --value localhost
sudo docker exec -u 33 nextcloud php occ config:system:set trusted_domains 1 --value nextcloud.home.arpa
sudo docker exec -u 33 nextcloud php occ config:system:set trusted_domains 2 --value minerva.lan
sudo docker exec -u 33 nextcloud php occ config:system:set trusted_domains 3 --value 100.118.90.26
sudo docker exec -u 33 nextcloud php occ config:system:set trusted_domains 4 --value cloud.minerva.netbird.selfhosted
sudo docker exec -u 33 nextcloud php occ config:system:set trusted_domains 5 --value nextcloud
sudo docker exec -u 33 nextcloud php occ config:system:set overwriteprotocol --value https
sudo docker exec -u 33 nextcloud php occ config:system:set overwrite.cli.url --value https://nextcloud.home.arpa
sudo docker exec -u 33 nextcloud php occ config:system:set trusted_proxies 0 --value 127.0.0.1
sudo docker exec -u 33 nextcloud php occ config:system:set trusted_proxies 1 --value 172.19.0.0/16

Changing Admin Password

The NEXTCLOUD_ADMIN_PASSWORD env var is only read on first install. To change the password on a running instance:

sudo docker exec -u 33 nextcloud php occ user:resetpassword admin

Known Issues & Fixes

Ownership of mounted directories

The Nextcloud container runs as www-data (UID 33). If Docker creates host directories as root, the container can't write to them. systemd.tmpfiles.rules in nextcloud.nix ensures correct ownership on every boot. To fix manually:

sudo chown -R 33:33 /var/lib/nextcloud/
sudo systemd-tmpfiles --create

PostgreSQL permissions

If the database was partially initialized, tables may be owned by the wrong user. To reset cleanly:

sudo docker stop nextcloud
sudo docker exec postgres-nextcloud psql -U nextcloud -d postgres -c "DROP DATABASE nextcloud WITH (FORCE);"
sudo docker exec postgres-nextcloud psql -U nextcloud -d postgres -c "CREATE DATABASE nextcloud OWNER nextcloud;"
sudo docker exec postgres-nextcloud psql -U nextcloud -d nextcloud -c "GRANT ALL ON SCHEMA public TO nextcloud; ALTER SCHEMA public OWNER TO nextcloud;"

NixOS native module conflict

If services.nextcloud was previously enabled, it leaves behind config files in /var/lib/nextcloud/config/ including an override.config.php symlink pointing to the nix store. These must be removed before the Docker container can initialize:

sudo rm /var/lib/nextcloud/config/override.config.php
sudo find /var/lib/nextcloud/config/ -name "*.php" -delete

Firewall / PostgreSQL connectivity

PostgreSQL is not exposed to the host — both containers communicate via nextcloud-net. Use container names (postgres-nextcloud) not host IPs (172.17.0.1) in config.


OnlyOffice Docker Setup

OnlyOffice runs as a Docker container connected to nextcloud-net so it can communicate with Nextcloud by container name.

Nextcloud Integration

sudo docker exec -u 33 nextcloud php occ app:enable onlyoffice
sudo docker exec -u 33 nextcloud php occ config:app:set onlyoffice DocumentServerUrl --value="https://onlyoffice.home.arpa/"
sudo docker exec -u 33 nextcloud php occ config:app:set onlyoffice DocumentServerInternalUrl --value="http://onlyoffice:80/"
sudo docker exec -u 33 nextcloud php occ config:app:set onlyoffice StorageUrl --value="http://nextcloud:80/"
sudo docker exec -u 33 nextcloud php occ config:app:set onlyoffice jwt_secret --value="<JWT_SECRET>"
sudo docker exec -u 33 nextcloud php occ config:app:set onlyoffice jwt_header --value="Authorization"

Add nextcloud and onlyoffice as trusted domains so containers can reach each other:

sudo docker exec -u 33 nextcloud php occ config:system:set trusted_domains 5 --value="nextcloud"
sudo docker exec -u 33 nextcloud php occ config:system:set trusted_domains 6 --value="onlyoffice"

Troubleshooting

Files downloading instead of opening

If Nextcloud shows "no plugin available" or downloads files instead of opening them, check for a cached connection error:

sudo docker exec -u 33 nextcloud php occ config:list onlyoffice | grep settings_error

If present, clear it:

sudo docker exec -u 33 nextcloud php occ config:app:delete onlyoffice settings_error
sudo docker exec -u 33 nextcloud php occ config:app:delete onlyoffice demo

Then verify the internal connection works:

sudo docker exec nextcloud curl -sk http://onlyoffice:80/healthcheck  # should return: true
sudo docker exec onlyoffice curl -sk http://nextcloud:80/status.php   # should return JSON

OnlyOffice not on nextcloud-net

If the above curl commands fail, connect OnlyOffice to the network:

sudo docker network connect nextcloud-net onlyoffice

This is handled automatically via extraOptions = [ "--network=nextcloud-net" ] in onlyoffice.nix on rebuild.


OpenCloud Native Module

OpenCloud uses the NixOS services.opencloud module (available from NixOS 25.11+).

Known Issues & Fixes

500 error on login / IDM not initialized

If IDM fails to initialize on first boot (often caused by the search service crashing and interrupting startup), wipe IDM and IDP state and restart:

sudo systemctl stop opencloud
sudo rm -rf /var/lib/opencloud/idm
sudo rm -rf /var/lib/opencloud/idp
sudo systemctl start opencloud
sudo journalctl -u opencloud -f

TLS certificate errors in internal services

Add OC_INSECURE = "true" to the environment in opencloud.nix to allow internal services to skip TLS verification when communicating over loopback.

search service crashes on startup

The search service has a known bleve index corruption issue. Exclude it:

OC_EXCLUDE_RUN_SERVICES = "search";

Trust Caddy Internal CA (macOS)

The Caddy internal root CA is stored on the NixOS host at /var/lib/caddy/.local/share/caddy/pki/authorities/ (restricted to the caddy user). The openssl approach only extracts the intermediate CA, not the self-signed root — the root CA is never sent in the TLS handshake.

# On the NixOS host: find and export the root CA
sudo ls -la /var/lib/caddy/.local/share/caddy/pki/authorities/
sudo cat /var/lib/caddy/.local/share/caddy/pki/authorities/local/root.crt > /tmp/caddy_root.crt

# On macOS: download the root CA from the NixOS host
scp minerva@192.168.1.20:/tmp/caddy_root.crt ~/Downloads/caddy_root.crt

# Import into system keychain
sudo security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain ~/Downloads/caddy_root.crt