{ lib, config, proxyReverse, ... }: let port = 42010; url = "maloja.${config.my.domain}"; in { options.my.servers.maloja.enable = lib.mkEnableOption "enable"; config = lib.mkIf config.my.servers.maloja.enable { sops.secrets.maloja.sopsFile = ../../secrets/env.yaml; virtualisation.oci-containers.containers.maloja = { image = "krateng/maloja"; ports = [ "${toString port}:${toString port}" ]; environmentFiles = [ config.sops.secrets.maloja.path ]; environment = { TZ = "America/Mexico_City"; MALOJA_TIMEZONE = "-6"; PUID = "1000"; PGID = "100"; MALOJA_DATA_DIRECTORY = "/mljdata"; MALOJA_SKIP_SETUP = "true"; }; volumes = [ "${config.my.containerData}/maloja:/mljdata" ]; labels = { "flame.type" = "application"; "flame.name" = "Maloja"; "flame.url" = url; "flame.icon" = "bookmark-music"; }; }; services.nginx.virtualHosts."${url}" = proxyReverse port // { }; }; }