{ pkgs, ... }: { imports = [ ./hardware-configuration.nix # orion started as a desktop with an interactive installer; # the disk is already provisioned. # ./disk-config.nix ]; config = { services.searx = { enable = true; redisCreateLocally = true; environmentFile = "/var/lib/searx/secret.env"; settings = { general.instance_name = "orion-search"; server = { bind_address = "127.0.0.1"; port = 8888; secret_key = "$SEARX_SECRET_KEY"; limiter = false; public_instance = false; image_proxy = false; method = "GET"; base_url = "https://orion.scylla-hammerhead.ts.net/"; }; search.formats = [ "html" "json" ]; }; }; # Secret stays on the box, never in the nix store. Mode 0640 root:searx. systemd.services.searx-secret = { description = "Generate SearXNG secret if missing"; wantedBy = [ "searx.service" ]; before = [ "searx.service" ]; after = [ "systemd-sysusers.service" ]; serviceConfig = { Type = "oneshot"; RemainAfterExit = true; }; script = '' install -d -m 0750 -o root -g searx /var/lib/searx if [ ! -f /var/lib/searx/secret.env ]; then umask 027 echo "SEARX_SECRET_KEY=$(${pkgs.openssl}/bin/openssl rand -hex 32)" > /var/lib/searx/secret.env chown root:searx /var/lib/searx/secret.env chmod 0640 /var/lib/searx/secret.env fi ''; }; # Loopback-only SearXNG, TLS via Tailscale Serve. No host firewall hole. systemd.services.tailscale-serve-searx = { description = "Advertise SearXNG on Tailscale Serve"; after = [ "tailscaled.service" "searx.service" ]; wants = [ "tailscaled.service" ]; wantedBy = [ "multi-user.target" ]; serviceConfig = { Type = "oneshot"; RemainAfterExit = true; ExecStart = "${pkgs.tailscale}/bin/tailscale serve --bg --yes 8888"; }; }; }; }