tv.ejabberd: use krebs.secret

This commit is contained in:
tv 2016-02-21 05:41:59 +01:00
parent b5fbca3a36
commit d488e5fe72

View File

@ -12,9 +12,17 @@ let
api = { api = {
enable = mkEnableOption "tv.ejabberd"; enable = mkEnableOption "tv.ejabberd";
certFile = mkOption { certfile = mkOption {
type = types.str; type = types.secret-file;
default = toString <secrets/ejabberd.pem>; default = {
path = "/etc/ejabberd/ejabberd.pem";
owner-name = "ejabberd";
source-path = toString <secrets> + "/ejabberd.pem";
};
};
s2s_certfile = mkOption {
type = types.secret-file;
default = cfg.certfile;
}; };
hosts = mkOption { hosts = mkOption {
@ -25,21 +33,22 @@ let
imp = { imp = {
environment.systemPackages = [ my-ejabberdctl ]; environment.systemPackages = [ my-ejabberdctl ];
krebs.secret.files = {
ejabberd-certfile = cfg.certfile;
ejabberd-s2s_certfile = cfg.s2s_certfile;
};
systemd.services.ejabberd = { systemd.services.ejabberd = {
wantedBy = [ "multi-user.target" ]; wantedBy = [ "multi-user.target" ];
after = [ "network.target" ]; requires = [ "secret.service" ];
after = [ "network.target" "secret.service" ];
serviceConfig = { serviceConfig = {
Type = "oneshot"; Type = "oneshot";
RemainAfterExit = "yes"; RemainAfterExit = "yes";
PermissionsStartOnly = "true"; PermissionsStartOnly = "true";
SyslogIdentifier = "ejabberd"; SyslogIdentifier = "ejabberd";
User = user.name; User = user.name;
ExecStartPre = pkgs.writeScript "ejabberd-start" '' ExecStart = pkgs.writeDash "ejabberd" ''
#! /bin/sh
install -o ${user.name} -m 0400 ${cfg.certFile} /etc/ejabberd/ejabberd.pem
'';
ExecStart = pkgs.writeScript "ejabberd-service" ''
#! /bin/sh
${my-ejabberdctl}/bin/ejabberdctl start ${my-ejabberdctl}/bin/ejabberdctl start
''; '';
}; };
@ -75,7 +84,7 @@ let
[ [
{5222, ejabberd_c2s, [ {5222, ejabberd_c2s, [
starttls, starttls,
{certfile, "/etc/ejabberd/ejabberd.pem"}, {certfile, ${toErlang cfg.certfile.path}},
{access, c2s}, {access, c2s},
{shaper, c2s_shaper}, {shaper, c2s_shaper},
{max_stanza_size, 65536} {max_stanza_size, 65536}
@ -92,7 +101,7 @@ let
]} ]}
]}. ]}.
{s2s_use_starttls, required}. {s2s_use_starttls, required}.
{s2s_certfile, "/etc/ejabberd/ejabberd.pem"}. {s2s_certfile, ${toErlang cfg.s2s_certfile.path}}.
{auth_method, internal}. {auth_method, internal}.
{shaper, normal, {maxrate, 1000}}. {shaper, normal, {maxrate, 1000}}.
{shaper, fast, {maxrate, 50000}}. {shaper, fast, {maxrate, 50000}}.
@ -161,5 +170,4 @@ let
# XXX this is a placeholder that happens to work the default strings. # XXX this is a placeholder that happens to work the default strings.
toErlang = builtins.toJSON; toErlang = builtins.toJSON;
in in out
out