diff options
author | Pol Dellaiera <pol.dellaiera@protonmail.com> | 2024-06-04 15:47:03 +0200 |
---|---|---|
committer | GitHub <noreply@github.com> | 2024-06-04 15:47:03 +0200 |
commit | 6b6d4aeb350243f7173d160e0b6a963c496f95e3 (patch) | |
tree | 62c84a438604648e360905731bba180668bb1fbc /nixos/modules | |
parent | cc648ec468521c448da6048fd888e514bae163f0 (diff) | |
parent | f66cb82fef9d3f02cb1f72744e9493116aa41408 (diff) |
Merge pull request #316248 from shivaraj-bh/open-webui
open-webui: init at 0.2.4
Diffstat (limited to 'nixos/modules')
-rw-r--r-- | nixos/modules/module-list.nix | 1 | ||||
-rw-r--r-- | nixos/modules/services/misc/open-webui.nix | 94 |
2 files changed, 95 insertions, 0 deletions
diff --git a/nixos/modules/module-list.nix b/nixos/modules/module-list.nix index b7725051597a3..4c81336fc2310 100644 --- a/nixos/modules/module-list.nix +++ b/nixos/modules/module-list.nix @@ -771,6 +771,7 @@ ./services/misc/octoprint.nix ./services/misc/ollama.nix ./services/misc/ombi.nix + ./services/misc/open-webui.nix ./services/misc/osrm.nix ./services/misc/owncast.nix ./services/misc/packagekit.nix diff --git a/nixos/modules/services/misc/open-webui.nix b/nixos/modules/services/misc/open-webui.nix new file mode 100644 index 0000000000000..de61ff80e9228 --- /dev/null +++ b/nixos/modules/services/misc/open-webui.nix @@ -0,0 +1,94 @@ +{ + config, + lib, + pkgs, + ... +}: +let + inherit (lib) types; + + cfg = config.services.open-webui; +in +{ + options = { + services.open-webui = { + enable = lib.mkEnableOption "Enable open-webui, an interactive chat web app"; + package = lib.mkPackageOption pkgs "open-webui" { }; + + stateDir = lib.mkOption { + type = types.path; + default = "/var/lib/open-webui"; + description = "State directory of open-webui."; + }; + + host = lib.mkOption { + type = types.str; + default = "localhost"; + description = "Host of open-webui"; + }; + + port = lib.mkOption { + type = types.port; + default = 8080; + description = "Port of open-webui"; + }; + + environment = lib.mkOption { + type = types.attrsOf types.str; + default = { }; + example = '' + { + OLLAMA_API_BASE_URL = "http://localhost:11434"; + # Disable authentication + WEBUI_AUTH = "False"; + } + ''; + description = "Extra environment variables for open-webui"; + }; + }; + }; + + config = lib.mkIf cfg.enable { + systemd.services.open-webui = { + description = "User-friendly WebUI for LLMs (Formerly Ollama WebUI)"; + wantedBy = [ "multi-user.target" ]; + after = [ "network.target" ]; + + preStart = '' + mkdir -p ${cfg.stateDir}/static + ''; + + environment = { + STATIC_DIR = "${cfg.stateDir}/static"; + DATA_DIR = "${cfg.stateDir}"; + } // cfg.environment; + + serviceConfig = { + ExecStart = "${lib.getExe cfg.package} serve --host ${cfg.host} --port ${toString cfg.port}"; + WorkingDirectory = cfg.stateDir; + StateDirectory = "open-webui"; + RuntimeDirectory = "open-webui"; + RuntimeDirectoryMode = "0755"; + PrivateTmp = true; + DynamicUser = true; + DevicePolicy = "closed"; + LockPersonality = true; + MemoryDenyWriteExecute = false; # onnxruntime/capi/onnxruntime_pybind11_state.so: cannot enable executable stack as shared object requires: Permission Denied + PrivateUsers = true; + ProtectHome = true; + ProtectHostname = true; + ProtectKernelLogs = true; + ProtectKernelModules = true; + ProtectKernelTunables = true; + ProtectControlGroups = true; + ProcSubset = "all"; # Error in cpuinfo: failed to parse processor information from /proc/cpuinfo + RestrictNamespaces = true; + RestrictRealtime = true; + SystemCallArchitectures = "native"; + UMask = "0077"; + }; + }; + }; + + meta.maintainers = with lib.maintainers; [ shivaraj-bh ]; +} |