Files
imladris/hw/orion/default.nix
T
kyle e6938ef782 orion: drop MCP, add SearXNG on loopback + Tailscale Serve
SearXNG binds 127.0.0.1:8888 (json+html, limiter off). Secret is
/var/lib/searx/secret.env, generated on-box. TLS via `tailscale serve`.
MCP agent, packages, extra firewall ports, and MCP DNS removed from this
host only.
2026-09-22 18:01:23 -07:00

66 lines
2.0 KiB
Nix

{ pkgs, ... }:
{
imports = [
./hardware-configuration.nix
# orion started as a desktop with an interactive installer;
# the disk is already provisioned.
# ./disk-config.nix
];
config = {
services.searx = {
enable = true;
redisCreateLocally = true;
environmentFile = "/var/lib/searx/secret.env";
settings = {
general.instance_name = "orion-search";
server = {
bind_address = "127.0.0.1";
port = 8888;
secret_key = "$SEARX_SECRET_KEY";
limiter = false;
public_instance = false;
image_proxy = false;
method = "GET";
base_url = "https://orion.scylla-hammerhead.ts.net/";
};
search.formats = [ "html" "json" ];
};
};
# Secret stays on the box, never in the nix store. Mode 0640 root:searx.
systemd.services.searx-secret = {
description = "Generate SearXNG secret if missing";
wantedBy = [ "searx.service" ];
before = [ "searx.service" ];
after = [ "systemd-sysusers.service" ];
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
};
script = ''
install -d -m 0750 -o root -g searx /var/lib/searx
if [ ! -f /var/lib/searx/secret.env ]; then
umask 027
echo "SEARX_SECRET_KEY=$(${pkgs.openssl}/bin/openssl rand -hex 32)" > /var/lib/searx/secret.env
chown root:searx /var/lib/searx/secret.env
chmod 0640 /var/lib/searx/secret.env
fi
'';
};
# Loopback-only SearXNG, TLS via Tailscale Serve. No host firewall hole.
systemd.services.tailscale-serve-searx = {
description = "Advertise SearXNG on Tailscale Serve";
after = [ "tailscaled.service" "searx.service" ];
wants = [ "tailscaled.service" ];
wantedBy = [ "multi-user.target" ];
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
ExecStart = "${pkgs.tailscale}/bin/tailscale serve --bg --yes 8888";
};
};
};
}