Skip to content

homelable

Self-hosted homelab infrastructure visualizer — interactive network diagram with live status monitoring.

Example

nix
{config, ...}: {
  nps.stacks.homelable = {
    enable = true;
    secretKeyFile = config.sops.secrets."homelable/secret_key".path;
    oidc = {
      enable = true;
      clientSecretFile = config.sops.secrets."homelable/authelia/client_secret".path;
      clientSecretHash = "$pbkdf2-sha512$...";
    };
  };
}

Stack Options

nps.stacks.homelable.auth.passwordHashFile

Path to the file containing the bcrypt hash of the local authentication password. Can be generated with: python3 -c "import bcrypt; print(bcrypt.hashpw(b'yourpassword', bcrypt.gensalt()).decode())".

Required unless oidc.enable is set to true.

Type
plaintext
null or absolute path
Default
nix
null
Declaration

nps.stacks.homelable.auth.username

Username for local authentication.

Type
plaintext
string
Default
nix
"admin"
Declaration

nps.stacks.homelable.containers.homelable

Alias of {option}services.podman.containers.homelable.

Type
plaintext
submodule
Declaration

nps.stacks.homelable.containers.homelable-backend

Alias of {option}services.podman.containers.homelable-backend.

Type
plaintext
submodule
Declaration

nps.stacks.homelable.containers.homelable-mcp

Alias of {option}services.podman.containers.homelable-mcp.

Type
plaintext
submodule
Declaration

nps.stacks.homelable.enable

Whether to enable homelable.

Type
plaintext
boolean
Default
nix
false
Example
nix
true
Declaration

nps.stacks.homelable.extraEnv

Extra environment variables for the backend container. Useful for features like deep scans, live view, the gethomepage widget or Proxmox/Zigbee/Z-Wave auto-sync.

See https://github.com/Pouzor/homelable/blob/main/.env.example

Type
plaintext
attribute set of (null or boolean or signed integer or string or absolute path or (submodule))
Default
nix
{ }
Declaration

nps.stacks.homelable.mcp.apiKeyFile

Path to the file containing the API key that authenticates AI clients against the MCP server (MCP_API_KEY). Can be generated with openssl rand -hex 32.

Type
plaintext
absolute path
Declaration

nps.stacks.homelable.mcp.enable

Whether to enable MCP server.

Type
plaintext
boolean
Default
nix
false
Example
nix
true
Declaration

nps.stacks.homelable.mcp.serviceKeyFile

Path to the file containing the service key that authenticates the MCP server against the backend (MCP_SERVICE_KEY). Can be generated with openssl rand -hex 32.

Type
plaintext
absolute path
Declaration

nps.stacks.homelable.oidc.clientSecretFile

The file containing the client secret for the OIDC client that will be registered in Authelia.

For examples on how to generate a client secret, see

https://www.authelia.com/integration/openid-connect/frequently-asked-questions/#client-secret

Type
plaintext
string
Example
nix
config.sops.secrets."immich/authelia/client_secret".path"
Declaration

nps.stacks.homelable.oidc.clientSecretHash

The client secret hash. For examples on how to generate a client secret, see https://www.authelia.com/integration/openid-connect/frequently-asked-questions/#client-secret

The value can be passed in multiple ways:

  1. As a literal string
  2. As an absolute path to a file containing the hash (toFile)
  3. As an absolute oath to a file containing the client_secret, in which case the hash will be automatically computed (toHash)
  4. As null

If left unset (null), the client secret will be read from the file specified in the clientSecretFile option and hashed automatically before being passed to the Authelia container.

Type
plaintext
null or string or (submodule)
Default
nix
null
Example
nix
# Literal String:
"$pbkdf2-sha512$310000$cbOAIWbfz3vCVXIPIp6d2A$J0klwULa6TvPRCU1HAfuKua/dMKTl8gbTYJz2N73ejGUu0LUGz/y3kwmJLuKuAYGg3WQOT0q9ZzVHHUvpKpgvQ"

# Client secret hash stored in a file
{ fromFile = config.sops.secrets."immich/client_secret_hash".path; }

# Client secret stored in a file: Hash will be computed dynamically
{ toHash = config.sops.secrets."immich/client_secret".path; }

# Null (default): Hash will be computed automatically based on the clientSecretFile option
# Equivalent to { toHash = cfg.oidc.clientSecretFile; }
null
Declaration

nps.stacks.homelable.oidc.enable

Whether to enable OIDC login with Authelia. This will register an OIDC client in Authelia and setup the necessary configuration.

For details, see:

Type
plaintext
boolean
Default
nix
false
Declaration

nps.stacks.homelable.oidc.userGroup

Users of this group will be able to log in

Type
plaintext
string
Default
nix
"homelable_user"
Declaration

nps.stacks.homelable.scannerRanges

List of CIDR ranges that will be scanned for devices.

Type
plaintext
list of string
Default
nix
[ ]
Example
nix
[
  "192.168.1.0/24"
  "10.0.0.0/24"
]
Declaration

nps.stacks.homelable.secretKeyFile

Path to the file containing the secret key used to sign session tokens. Can be generated with openssl rand -hex 32.

See https://github.com/Pouzor/homelable/blob/main/.env.example

Type
plaintext
absolute path
Declaration