{ config, pkgs, lib, ... }: with lib; let cfg = config.services.naxos.apps.vaultwarden; in { options.services.naxos.apps.vaultwarden = { enable = mkEnableOption "Vaultwarden Password & Secret Vault"; port = mkOption { type = types.port; default = 8222; description = "Web interface port."; }; openFirewall = mkOption { type = types.bool; default = true; description = "Open port in firewall."; }; }; config = mkIf cfg.enable { services.vaultwarden = { enable = true; config = { ROCKET_PORT = cfg.port; ROCKET_ADDRESS = "0.0.0.0"; }; }; networking.firewall.allowedTCPPorts = mkIf cfg.openFirewall [ cfg.port ]; }; }