chore: expose open-webui to sentinel

This commit is contained in:
oddlama 2024-06-09 21:09:04 +02:00
parent 55fe825a74
commit 03fdaa739f
No known key found for this signature in database
GPG key ID: 14EFE510775FE39A
8 changed files with 29 additions and 8 deletions

View file

@ -4,11 +4,9 @@ in {
microvm.mem = 1024 * 16;
microvm.vcpu = 20;
wireguard.proxy-home = {
client.via = "ward";
firewallRuleForNode.ward-web-proxy.allowedTCPPorts = [
config.services.open-webui.port
];
wireguard.proxy-sentinel = {
client.via = "sentinel";
firewallRuleForNode.sentinel.allowedTCPPorts = [config.services.open-webui.port];
};
networking.firewall.allowedTCPPorts = [config.services.ollama.port];
@ -42,7 +40,7 @@ in {
WEBUI_AUTH = "False";
ENABLE_SIGNUP = "False";
OLLAMA_BASE_URL = "http://localhgost:11434";
OLLAMA_BASE_URL = "http://localhost:11434";
TRANSFORMERS_CACHE = "/var/lib/open-webui/.cache/huggingface";
WEBUI_AUTH_TRUSTED_EMAIL_HEADER = "X-Email";
@ -65,7 +63,7 @@ in {
oauth2 = {
enable = true;
allowedGroups = ["access_openwebui"];
X-Email = "\${upstream_http_x_auth_request_email}@local";
X-Email = "\${upstream_http_x_auth_request_email}@${config.repo.secrets.global.domains.personal}";
};
# FIXME: refer to lan 192.168... and fd10:: via globals
extraConfig = ''