diff --git a/hosts/server/configuration.nix b/hosts/server/configuration.nix index 188a32ed..e061bd81 100644 --- a/hosts/server/configuration.nix +++ b/hosts/server/configuration.nix @@ -22,6 +22,7 @@ ../../server-modules/fail2ban.nix ../../server-modules/default-creds.nix ../../server-modules/gitea.nix + ../../server-modules/home-assistant.nix # You should let those lines as is ./hardware-configuration.nix diff --git a/server-modules/home-assistant.nix b/server-modules/home-assistant.nix new file mode 100644 index 00000000..cb5f7e46 --- /dev/null +++ b/server-modules/home-assistant.nix @@ -0,0 +1,27 @@ +{config, ...}: { + services.home-assistant = { + enable = true; + openFirewall = true; + extraComponents = [ + "default_config" + "met" + "esphome" + "hue" + "matter" + "thread" + ]; + config = { + default_config = {}; + http = { + trusted_proxies = ["127.0.0.1" "::1"]; + use_x_forwarded_for = true; + }; + }; + }; + + services.matter-server.enable = true; + + networking.firewall.allowedUDPPorts = [5353]; + + services.cloudflared.tunnels."${config.var.tunnelId}".ingress."hass.${config.var.domain}" = "http://localhost:${toString config.services.home-assistant.config.http.server_port}"; +}