Files
imladris/hw/orion/default.nix
T
kyle 9edaf0f339 orion: pin sift ff87a04 (P2 digest/context/recover)
Dixie chat+embed on :11434, digest thinking off, Honcho
context from rift for hermes-fleet only.
2026-09-23 00:05:30 -07:00

105 lines
3.6 KiB
Nix

{ pkgs, inputs, ... }:
{
imports = [
./hardware-configuration.nix
# orion started as a desktop with an interactive installer;
# the disk is already provisioned.
# ./disk-config.nix
inputs.sift.nixosModules.sift
];
config = {
services.searx = {
enable = true;
redisCreateLocally = true;
environmentFile = "/var/lib/searx/secret.env";
settings = {
general.instance_name = "orion-search";
server = {
bind_address = "127.0.0.1";
port = 8888;
secret_key = "$SEARX_SECRET_KEY";
limiter = false;
public_instance = false;
image_proxy = false;
method = "GET";
base_url = "https://orion.scylla-hammerhead.ts.net/";
};
search.formats = [ "html" "json" ];
# Home IP: brave/ddg/startpage CAPTCHA or 429; google silent 0;
# qwant denied; mojeek 0. bing works. Specialised engines kept.
engines = [
{ name = "bing"; disabled = false; }
{ name = "braveapi"; api_key = "$BRAVE_API_KEY"; disabled = false; inactive = false; }
{ name = "brave"; disabled = true; }
{ name = "duckduckgo"; disabled = true; }
{ name = "startpage"; disabled = true; }
{ name = "google"; disabled = true; }
{ name = "qwant"; disabled = true; }
{ name = "mojeek"; disabled = true; }
{ name = "wikipedia"; disabled = false; }
{ name = "wikidata"; disabled = false; }
{ name = "github"; disabled = false; }
{ name = "arxiv"; disabled = false; }
];
};
};
# searx-init loads EnvironmentFile at spawn. The file must exist before
# systemd starts that unit. activationScripts run after users/groups and
# before units, so the first boot/switch cannot race.
system.activationScripts.searx-secret = {
deps = [ "users" ];
text = ''
install -d -m 0750 -o root -g searx /var/lib/searx
if [ ! -f /var/lib/searx/secret.env ]; then
umask 027
echo "SEARX_SECRET_KEY=$(${pkgs.openssl}/bin/openssl rand -hex 32)" > /var/lib/searx/secret.env
chown root:searx /var/lib/searx/secret.env
chmod 0640 /var/lib/searx/secret.env
fi
'';
};
# Loopback-only SearXNG, TLS via Tailscale Serve. No host firewall hole.
# Restart on NoState: during switch, tailscaled can still be coming up.
systemd.services.tailscale-serve-searx = {
description = "Advertise SearXNG on Tailscale Serve";
after = [ "tailscaled.service" "network-online.target" "searx.service" ];
wants = [ "tailscaled.service" "network-online.target" ];
wantedBy = [ "multi-user.target" ];
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
Restart = "on-failure";
RestartSec = "5s";
ExecStart = "${pkgs.tailscale}/bin/tailscale serve --bg --yes 8888";
};
};
services.sift = {
enable = true;
listen = "127.0.0.1:8890";
denyPrefixes = [ "99.73.161.224/32" ];
settings = {
dixie = {
chat = "http://dixie.scylla-hammerhead.ts.net:11434/v1/chat/completions";
embed = "http://dixie.scylla-hammerhead.ts.net:11434/v1/embeddings";
max_inflight = 2;
queue_depth = 8;
queue_wait = "20s";
};
digest = {
model = "ornith-1.5-9b-uncensored";
thinking = false;
cache = "/var/lib/sift/cache.db";
};
context = {
honcho = "http://rift.scylla-hammerhead.ts.net:8000";
workspaces = [ "hermes-fleet" ];
};
};
};
};
}