nix-config/hosts/heather
mikl cd018a24c2 heather: install jitsi from scratch per official docs (minimal)
Per https://jitsi.github.io/handbook/docs/devops-guide/devops-guide-docker
and official docker-compose.yml. Minimal config, no copying from old install.

- 4 services: web/prosody/jicofo/jvb (stable-11031, docker hub)
- read_only + tmpfs per official compose
- Named volumes: jitsi-{web,prosody,prosody-data,jicofo,jvb,transcripts}
- Network meet-jitsi, prosody alias xmpp.meet.jitsi
- Reverse proxy: DISABLE_HTTPS=1, Caddy v2 auto-WebSocket (no manual header_up)
- JVB_ADVERTISE_IPS=51.250.45.111, :10000/udp public
- Auth: internal (ENABLE_AUTH=1, AUTH_TYPE=internal). NO GUESTS — template bug
  in prosody: guest domain lacks websocket module → disconnect loop
- Secrets NEW in /var/lib/jitsi-secrets/jitsi.env (root:docker 0640):
  JICOFO_COMPONENT_SECRET, JICOFO_AUTH_PASSWORD, JVB_AUTH_PASSWORD
- Firewall: 10000/udp (NixOS + YC SG)
2026-07-13 00:56:13 +03:00
..
arion-compose.nix heather: install jitsi from scratch per official docs (minimal) 2026-07-13 00:56:13 +03:00
caddy.nix heather: install jitsi from scratch per official docs (minimal) 2026-07-13 00:56:13 +03:00
default.nix heather: install jitsi from scratch per official docs (minimal) 2026-07-13 00:56:13 +03:00
docker.nix heather: replace k3s with docker+arion+caddy+syncthing 2026-07-12 12:23:05 +03:00
image.nix heather/common: passwordless sudo for mikl + fix deprecated options 2026-07-11 22:55:00 +03:00
syncthing.nix heather: make strelaysrv private (pools="") 2026-07-12 17:55:52 +03:00