{ config, lib, masterDomain, securityTemplates, ... }: let cfg = config.os.srv.ntopng; in { options.os.srv.ntopng = { enable = lib.mkEnableOption "enables ntopng monitoring"; proxyConfig = lib.mkOption { type = lib.types.attrs; default = { }; }; }; config = lib.mkIf cfg.enable { services.ntopng = { enable = true; extraConfig = "--packet-fanout 'cluster' -g 2 -m '192.168.0.0/16,10.0.0.0/8' -X 50000 --community"; # TODO fill interfaces interfaces = [ "" # WAN Interface "" # LAN Interface "" # Virtual Bridge ]; }; os.srv.ntopng.proxyConfig = { "ntopng.${masterDomain}" = { enableACME = true; forceSSL = true; locations."/" = { proxyPass = "http://${config.os.core.network.ips.vm2-gateway}:3000"; extraConfig = securityTemplates.restrictToInternal; }; }; }; }; }