{ config, pkgs, ... }: let domain = "sync.cloonar.com"; networkPrefix = config.networkPrefix; in { sops.secrets.firefox-sync = { mode = "0777"; }; security.acme.certs."${domain}" = { group = "nginx"; }; containers."firefox-sync" = { autoStart = true; ephemeral = false; # because of ssh key privateNetwork = true; hostBridge = "server"; hostAddress = "${config.networkPrefix}.97.1"; localAddress = "${config.networkPrefix}.97.6/24"; bindMounts = { "/run/secrets/firefox-sync" = { hostPath = "/run/secrets/firefox-sync"; isReadOnly = true; }; }; config = { lib, config, pkgs, ... }: { networking = { hostName = "firefox-sync"; useHostResolvConf = false; defaultGateway = { address = "${networkPrefix}.97.1"; interface = "eth0"; }; nameservers = [ "${networkPrefix}.97.1" ]; }; services.mysql.package = pkgs.mariadb; services.firefox-syncserver = { enable = true; settings.host = "0.0.0.0"; singleNode = { enable = true; hostname = "0.0.0.0"; url = "https://${domain}"; }; secrets = "/run/secrets/firefox-sync"; logLevel = "debug"; }; networking.firewall = { enable = true; allowedTCPPorts = [ 5000 ]; }; system.stateVersion = "23.05"; }; }; }