- Create modules/ directory with reusable NixOS modules - Add system module for main user configuration - Add podman module for rootless container support - Add nginx module with automatic Let's Encrypt SSL - Add searxng module with Anubis AI firewall protection - Configure SearXNG at search.ashisgreat.xyz - Enable nginx reverse proxy with HTTPS Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
32 lines
673 B
Nix
32 lines
673 B
Nix
# Podman Module
|
|
# Provides: Rootless container runtime configuration
|
|
{
|
|
config,
|
|
lib,
|
|
pkgs,
|
|
...
|
|
}:
|
|
|
|
let
|
|
cfg = config.myModules.podman;
|
|
mainUser = config.myModules.system.mainUser;
|
|
in
|
|
{
|
|
options.myModules.podman = {
|
|
enable = lib.mkEnableOption "Podman container runtime";
|
|
};
|
|
|
|
config = lib.mkIf cfg.enable {
|
|
virtualisation.podman = {
|
|
enable = true;
|
|
dockerCompat = true;
|
|
defaultNetwork.settings.dns_enabled = true;
|
|
};
|
|
|
|
# Enable OCI containers (quadlet/podman containers)
|
|
virtualisation.oci-containers.backend = "podman";
|
|
|
|
# Give main user access to podman
|
|
users.users.${mainUser}.extraGroups = [ "podman" ];
|
|
};
|
|
}
|