1 { pkgs, lib, config, hostName, inputs, ... }:
3 inherit (config.services) transmission;
4 inherit (config.users) users;
5 inherit (config.security) gnupg;
7 wg-intra-peers = import (inputs.julm-nix + "/nixos/profiles/wireguard/wg-intra/peers.nix");
10 users.groups.transmission.members = [
14 services.netns.namespaces.${netns}.nftables = ''
15 add rule inet filter input tcp dport ${toString transmission.settings.peer-port} counter accept comment "Transmission"
16 add rule inet filter input udp dport ${toString transmission.settings.peer-port} counter accept comment "Transmission"
17 add rule inet filter output meta skuid ${transmission.user} counter accept comment "Transmission"
19 #users.groups.keys.members = [ transmission.user ];
20 security.gnupg.secrets."transmission/settings.json" = {
21 user = transmission.user;
22 systemdConfig.before = [ "transmission.service" ];
23 systemdConfig.wantedBy = [ "transmission.service" ];
25 fileSystems."/var/lib/transmission" = {
26 device = "${hostName}/var/torrents";
29 systemd.services.transmission = {
31 "netns-${netns}.service"
35 "netns-${netns}.service"
39 unitConfig.JoinsNamespaceOf = ["netns-${netns}.service"];
40 serviceConfig.BindReadOnlyPaths = ["/etc/netns/${netns}/resolv.conf:/etc/resolv.conf"];
41 serviceConfig.PrivateNetwork = true;
42 #serviceConfig.NetworkNamespacePath = "/var/run/netns/${netns}";
44 systemd.sockets.proxy-to-transmission = {
45 wantedBy = ["sockets.target"];
46 listenStreams = ["${wg-intra-peers.${hostName}.ipv4}:9091"];
47 socketConfig.FreeBind = true;
49 systemd.services.proxy-to-transmission = {
50 requires = ["transmission.service"];
51 after = ["transmission.service" "proxy-to-transmission.socket"];
52 unitConfig.JoinsNamespaceOf = ["netns-${netns}.service"];
54 ExecStart = "${pkgs.systemd}/lib/systemd/systemd-socket-proxyd 127.0.0.1:9091";
55 PrivateNetwork = true;
59 systemd.services.stop-transmission = {
60 serviceConfig.Type = "oneshot";
61 unitConfig.Conflicts = ["transmission.service"];
62 startAt = "06..19:0,15,30,45:00";
65 services.transmission = {
67 performanceNetParameters = true;
68 credentialsFile = gnupg.secrets."transmission/settings.json".path;
71 download-dir = "/var/lib/transmission/downloaded";
72 incomplete-dir = "/var/lib/transmission/.incoming";
73 incomplete-dir-enabled = true;
74 watch-dir = "/var/lib/transmission/.torrents";
75 watch-dir-enabled = true;
76 trash-original-torrent-files = false;
78 umask = 7; # 007 octal, in decimal!
79 download-queue-enabled = true;
80 download-queue-size = 5;
81 peer-id-ttl-hours = 6;
82 peer-limit-global = 1000;
83 peer-limit-per-torrent = 100;
86 peer-port-random-on-start = false;
91 port-forwarding-enabled = true;
92 scrape-paused-torrents-enabled = false;
93 peer-socket-tos = "lowcost";
94 queue-stalled-enabled = true;
95 queue-stalled-minutes = 30;
96 speed-limit-down-enabled = false;
98 speed-limit-up-enabled = true;
99 alt-speed-enabled = true;
100 alt-speed-time-enabled = true;
101 alt-speed-down = 1000;
103 alt-speed-time-day = 127; # all days. 65; # weekend only
104 alt-speed-time-begin = 360; # 06h00 local time
105 alt-speed-time-end = 1260; # 21h00 local time
107 ratio-limit-enabled = true;
110 rpc-bind-address = "127.0.0.1";
112 rpc-whitelist = "127.0.0.1,${wg-intra-peers.${hostName}.ipv4}/24";
113 rpc-whitelist-enabled = true;
114 rpc-host-whitelist = "localhost,${hostName}.wg";
115 rpc-host-whitelist-enabled = true;
116 rpc-authentication-required = true;