Archived
Several single-purpose modules sat at modules/ root or in the services/ catch-all despite the repo's established pattern of one directory per concern (tailscale/, beszel/, docker/, nix-cache/): - remote-builder-client.nix -> nix-cache/ (always co-included with nix-cache/client.nix in flake.nix's mkTarget, same buildType guard) - set-locale.nix -> common/ (unconditionally imported by common/configuration.nix already) - enable-ip-forwarding.nix -> networking/ - rotate-traefik-logs.nix -> traefik/rotate-logs.nix - services/docker-health-to-gotify.nix and services/nextcloud-cron-job.nix -> docker/ (both only ever imported by the docker build type, same as the rest of modules/docker/*) Pure path moves plus import-path updates in flake.nix, common/configuration.nix, and build-types/docker.nix — verified eval-equivalent (drvPath-identical) across representative hosts. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01La55Nsss8jZ7ZuzUV9mfot
29 lines
869 B
Nix
29 lines
869 B
Nix
{ pkgs, vars, ... }:
|
|
|
|
{
|
|
systemd.services.docker-health-to-gotify = {
|
|
description = "Alert Gotify when Docker containers become unhealthy";
|
|
after = [ "docker.service" ];
|
|
serviceConfig = {
|
|
Type = "oneshot";
|
|
# Run as root so it can read /etc/secrets and access docker socket
|
|
# User = "root";
|
|
#EnvironmentFile = "-/etc/secrets/docker-health-alert.env";
|
|
ExecStart = "${pkgs.bash}/bin/bash /home/${vars.primaryUser}/docker/monitoring/gotify/docker-health-to-gotify.sh";
|
|
StandardOutput = "journal";
|
|
StandardError = "journal";
|
|
};
|
|
path = with pkgs; [ docker curl coreutils gnused ];
|
|
};
|
|
|
|
systemd.timers.docker-health-to-gotify = {
|
|
wantedBy = [ "timers.target" ];
|
|
timerConfig = {
|
|
OnBootSec = "2min";
|
|
OnUnitActiveSec = "1min";
|
|
AccuracySec = "15s";
|
|
Persistent = true;
|
|
};
|
|
};
|
|
}
|