{ config, ... }: let host = "s3.dgnum.eu"; webHost = "cdn.dgnum.eu"; data_dir = "/data/slow/garage/data"; metadata_dir = "/data/fast/garage/meta"; in { services.garage = { enable = true; settings = { inherit data_dir metadata_dir; replication_mode = "none"; compression_level = 7; rpc_bind_addr = "[::]:3901"; rpc_public_addr = "127.0.0.1:3901"; s3_api = { s3_region = "garage"; api_bind_addr = "127.0.0.1:3900"; root_domain = ".${host}"; }; s3_web = { bind_addr = "127.0.0.1:3902"; root_domain = ".${webHost}"; index = "index.html"; }; k2v_api.api_bind_addr = "[::]:3904"; admin.api_bind_addr = "0.0.0.0:3903"; }; environmentFile = config.age.secrets."garage-environment_file".path; }; systemd.services.garage.serviceConfig = { User = "garage"; ReadWriteDirectories = [ data_dir metadata_dir ]; }; users.users.garage = { isSystemUser = true; group = "garage"; }; users.groups.garage = { }; services.nginx.virtualHosts = { ${host} = { enableACME = true; forceSSL = true; locations."/".extraConfig = '' proxy_pass http://127.0.0.1:3900; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header Host $host; # Disable buffering to a temporary file. proxy_max_temp_file_size 0; ''; }; ${webHost} = { enableACME = true; forceSSL = true; locations."/".extraConfig = '' proxy_pass http://127.0.0.1:3902; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header Host $host;''; }; }; }