Run it your way
Without Cloud Connect
Section titled “Without Cloud Connect”The host can operate independently. You provide a bare HTTPS public origin, a reverse proxy, connectivity and optionally TURN. Keep the gateway’s cleartext listener on loopback. Allow only the local users you intend to admit.
Follow the configuration reference shipped with your host package. Do not publish the gateway’s HTTP port directly to the Internet.
With an authorized checkout of the Darpan source flake, import darpan.nixosModules.default. Public binary-flake distribution is not available yet; the regular Linux release tarball is not a Nix flake.
services.darpan = { enable = true; allowedUsers = [ "alice" ]; cloud = { enable = true; url = "https://app.YOUR-SITE"; hostsDomain = "YOUR-HOSTS-DOMAIN"; slug = "studio"; ssoOnly = true; };};Use your actual lowercase domains and the name selected during pairing. Rebuild, pair as darpan-connect, and start the connector. Its state directory is created before pairing and the gateway can read credentials without granting the connector access to gateway sockets.
For a self-managed reverse proxy, omit cloud and set services.darpan.url to your HTTPS origin.
State and backups
Section titled “State and backups”Keep your configuration and user files backed up. Connector state contains credentials: do not share it or place it in an unencrypted public backup. Re-pair if a host credential is exposed.