1 { config, lib, name, ... }:
7 base = mkOption { description = "Base of the LDAP tree"; type = str; };
8 host = mkOption { description = "Host to access LDAP"; type = str; };
9 root_dn = mkOption { description = "DN of the root user"; type = str; };
10 root_pw = mkOption { description = "Hashed password of the root user"; type = str; };
11 replication_dn = mkOption { description = "DN of the user allowed to replicate the LDAP directory"; type = str; };
12 replication_pw = mkOption { description = "Password of the user allowed to replicate the LDAP directory"; type = str; };
14 mkLdapOptions = name: more: mkOption {
15 description = "${name} LDAP configuration";
17 options = ldapOptions // {
18 dn = mkOption { description = "DN of the ${name} user"; type = str; };
19 password = mkOption { description = "password of the ${name} user"; type = str; };
20 filter = mkOption { description = "Filter for ${name} users"; type = str; default = ""; };
25 host = mkOption { description = "Host to access Mysql"; type = str; };
26 remoteHost = mkOption { description = "Host to access Mysql from outside"; type = str; };
27 port = mkOption { description = "Port to access Mysql"; type = str; };
28 socket = mkOption { description = "Socket to access Mysql"; type = path; };
29 systemUsers = mkOption {
30 description = "Attrs of user-passwords allowed to access mysql";
34 description = "PAM configuration for mysql";
37 dn = mkOption { description = "DN to connect as to check users"; type = str; };
38 password = mkOption { description = "DN password to connect as to check users"; type = str; };
39 filter = mkOption { description = "filter to match users"; type = str; };
44 mkMysqlOptions = name: more: mkOption {
45 description = "${name} mysql configuration";
47 options = mysqlOptions // {
48 database = mkOption { description = "${name} database"; type = str; };
49 user = mkOption { description = "${name} user"; type = str; };
50 password = mkOption { description = "mysql password of the ${name} user"; type = str; };
55 host = mkOption { description = "Host to access Postgresql"; type = str; };
56 port = mkOption { description = "Port to access Postgresql"; type = str; };
57 socket = mkOption { description = "Socket to access Postgresql"; type = path; };
59 description = "PAM configuration for psql";
62 dn = mkOption { description = "DN to connect as to check users"; type = str; };
63 password = mkOption { description = "DN password to connect as to check users"; type = str; };
64 filter = mkOption { description = "filter to match users"; type = str; };
69 mkPsqlOptions = name: mkOption {
70 description = "${name} psql configuration";
72 options = psqlOptions // {
73 database = mkOption { description = "${name} database"; type = str; };
74 schema = mkOption { description = "${name} schema"; type = nullOr str; default = null; };
75 user = mkOption { description = "${name} user"; type = str; };
76 password = mkOption { description = "psql password of the ${name} user"; type = str; };
81 host = mkOption { description = "Host to access Redis"; type = str; };
82 port = mkOption { description = "Port to access Redis"; type = str; };
83 socket = mkOption { description = "Socket to access Redis"; type = path; };
85 description = "Attrs of db number. Each number should be unique to avoid collision!";
88 spiped_key = mkOption {
91 Key to use with spiped to make a secure channel to replication
95 description = "Predixy configuration. Unused yet";
98 read = mkOption { type = str; description = "Read password"; };
103 mkRedisOptions = name: mkOption {
104 description = "${name} redis configuration";
106 options = redisOptions // {
107 db = mkOption { description = "${name} database"; type = str; };
112 host = mkOption { description = "Host to access SMTP"; type = str; };
113 port = mkOption { description = "Port to access SMTP"; type = str; };
115 mkSmtpOptions = name: mkOption {
116 description = "${name} smtp configuration";
118 options = smtpOptions // {
119 email = mkOption { description = "${name} email"; type = str; };
120 password = mkOption { description = "SMTP password of the ${name} user"; type = str; };
124 hostEnv = submodule {
127 description = "Host FQDN";
134 Sublist of users from realUsers. Function that takes pkgs as
135 argument and gives an array as a result
140 description = "List of e-mails that the server can be a sender of";
145 LDAP credentials for the host
149 password = mkOption { type = str; description = "Password for the LDAP connection"; };
150 dn = mkOption { type = str; description = "DN for the LDAP connection"; };
155 description = "subdomain and priority for MX server";
156 default = { enable = false; };
159 enable = mkEnableOption "Enable MX";
160 subdomain = mkOption { type = nullOr str; description = "Subdomain name (mx-*)"; };
161 priority = mkOption { type = nullOr str; description = "Priority"; };
167 attrs of ip4/ip6 grouped by section
169 type = attrsOf (submodule {
175 ip4 addresses of the host
182 ip6 addresses of the host
195 Attrs of servers information in the cluster (not necessarily handled by nixops)
198 type = attrsOf hostEnv;
200 hetznerCloud = mkOption {
202 Hetzner Cloud credential information
206 authToken = mkOption {
217 Hetzner credential information
221 user = mkOption { type = str; description = "User"; };
222 pass = mkOption { type = str; description = "Password"; };
228 sshd service credential information
232 rootKeys = mkOption { type = attrsOf str; description = "Keys of root users"; };
235 LDAP credentials for cn=ssh,ou=services,dc=immae,dc=eu dn
239 password = mkOption { description = "Password"; type = str; };
248 non-standard reserved ports. Must be unique!
253 noDupl = x: builtins.length (builtins.attrValues x) == builtins.length (unique (builtins.attrValues x));
255 x: if isAttrs x && noDupl x then x else throw "Non unique values for ports";
259 httpd service credential information
265 LDAP credentials for cn=httpd,ou=services,dc=immae,dc=eu dn
269 password = mkOption { description = "Password"; type = str; };
277 type = submodule { options = smtpOptions; };
278 description = "SMTP configuration";
282 LDAP server configuration
285 options = ldapOptions;
288 databases = mkOption {
289 description = "Databases configuration";
293 type = submodule { options = mysqlOptions; };
294 description = "Mysql configuration";
297 type = submodule { options = redisOptions; };
298 description = "Redis configuration";
300 postgresql = mkOption {
301 type = submodule { options = psqlOptions; };
302 description = "Postgresql configuration";
308 description = "Jabber configuration";
311 postfix_user_filter = mkOption { type = str; description = "Postfix filter to get xmpp users"; };
312 ldap = mkLdapOptions "Jabber" {};
313 postgresql = mkPsqlOptions "Jabber";
317 realUsers = mkOption {
319 Attrset of function taking pkgs as argument.
320 Real users settings, should provide a subattr of users.users.<name>
321 with at least: name, (hashed)Password, shell
323 type = attrsOf unspecified;
326 description = "System and regular users uid/gid";
327 type = attrsOf (submodule {
330 description = "user uid";
334 description = "user gid";
341 description = "DNS configuration";
345 description = "SOA information";
349 description = "Serial number. Should be incremented at each change and unique";
353 description = "Refresh time";
357 description = "Retry time";
361 description = "Expire time";
365 description = "Default TTL time";
369 description = "hostmaster e-mail";
373 description = "Primary NS";
380 description = "Attrs of NS servers group";
383 "ns1.foo.com" = [ "198.51.100.10" "2001:db8:abcd::1" ];
384 "ns2.foo.com" = [ "198.51.100.15" "2001:db8:1234::1" ];
387 type = attrsOf (attrsOf (listOf str));
391 description = "DNS keys";
392 type = attrsOf (submodule {
394 algorithm = mkOption { type = str; description = "Algorithm"; };
395 secret = mkOption { type = str; description = "Secret"; };
399 slaveZones = mkOption {
400 description = "List of slave zones";
401 type = listOf (submodule {
403 name = mkOption { type = str; description = "zone name"; };
405 description = "NS master groups of this zone";
410 description = "Keys associated to the server";
416 masterZones = mkOption {
417 description = "List of master zones";
418 type = listOf (submodule {
420 name = mkOption { type = str; description = "zone name"; };
421 withCAA = mkOption { type = nullOr str; description = "CAA entry"; default = null; };
423 description = "NS slave groups of this zone";
427 description = "groups names that should have their NS entries listed here";
431 description = "Extra zone configuration for bind";
437 entries = mkOption { type = lines; description = "Regular entries of the NS zone"; };
438 withEmail = mkOption {
439 description = "List of domains that should have mail entries (MX, dkim, SPF, ...)";
441 type = listOf (submodule {
443 domain = mkOption { type = str; description = "Which subdomain is concerned"; };
444 send = mkOption { type = bool; description = "Whether there can be e-mails originating from the subdomain"; };
445 receive = mkOption { type = bool; description = "Whether there can be e-mails arriving to the subdomain"; };
457 Remote backup with duplicity
461 password = mkOption { type = str; description = "Password for encrypting files"; };
463 type = attrsOf (submodule {
467 example = literalExample ''
468 bucket: "s3://some_host/${bucket}";
472 Takes a bucket name as argument and returns a url
475 accessKeyId = mkOption { type = str; description = "Remote access-key"; };
476 secretAccessKey = mkOption { type = str; description = "Remote access secret"; };
483 zrepl_backup = mkOption {
487 description = "SSH key information";
490 public = mkOption { type = str; description = "Public part of the key"; };
491 private = mkOption { type = lines; description = "Private part of the key"; };
495 mysql = mkMysqlOptions "Zrepl" {};
499 rsync_backup = mkOption {
501 Rsync backup configuration from controlled host
506 description = "SSH key information";
509 public = mkOption { type = str; description = "Public part of the key"; };
510 private = mkOption { type = lines; description = "Private part of the key"; };
514 profiles = mkOption {
515 description = "Attrs of profiles to backup";
516 type = attrsOf (submodule {
518 keep = mkOption { type = int; description = "Number of backups to keep"; };
519 check_command = mkOption { type = str; description = "command to check if backup needs to be done"; default = "backup"; };
520 login = mkOption { type = str; description = "Login to connect to host"; };
521 port = mkOption { type = str; default = "22"; description = "Port to connect to host"; };
522 host = mkOption { type = str; description = "Host to connect to"; };
523 host_key = mkOption { type = str; description = "Host key"; };
524 host_key_type = mkOption { type = str; description = "Host key type"; };
526 description = "Parts to backup for this host";
527 type = attrsOf (submodule {
529 remote_folder = mkOption { type = path; description = "Remote folder to backup";};
530 exclude_from = mkOption {
533 description = "List of folders/files to exclude from the backup";
535 files_from = mkOption {
538 description = "List of folders/files to backup in the base folder";
543 description = "Extra arguments to pass to rsync";
554 monitoring = mkOption {
555 description = "Monitoring configuration";
558 status_url = mkOption { type = str; description = "URL to push status to"; };
559 status_token = mkOption { type = str; description = "Token for the status url"; };
560 http_user_password = mkOption { type = str; description = "HTTP credentials to check services behind wall"; };
561 email = mkOption { type = str; description = "Admin E-mail"; };
562 ssh_public_key = mkOption { type = str; description = "SSH public key"; };
563 ssh_secret_key = mkOption { type = str; description = "SSH secret key"; };
564 imap_login = mkOption { type = str; description = "IMAP login"; };
565 imap_password = mkOption { type = str; description = "IMAP password"; };
566 eriomem_keys = mkOption { type = listOf (listOf str); description = "Eriomem keys"; default = []; };
568 description = "OVH credentials for sms script";
571 endpoint = mkOption { type = str; default = "ovh-eu"; description = "OVH endpoint"; };
572 application_key = mkOption { type = str; description = "Application key"; };
573 application_secret = mkOption { type = str; description = "Application secret"; };
574 consumer_key = mkOption { type = str; description = "Consumer key"; };
575 account = mkOption { type = str; description = "Account"; };
579 nrdp_tokens = mkOption { type = listOf str; description = "Tokens allowed to push status update"; };
580 slack_url = mkOption { type = str; description = "Slack webhook url to push status update"; };
581 slack_channel = mkOption { type = str; description = "Slack channel to push status update"; };
582 netdata_aggregator = mkOption { type = str; description = "Url where netdata information should be sent"; };
583 netdata_keys = mkOption { type = attrsOf str; description = "netdata host keys"; };
584 contacts = mkOption { type = attrsOf unspecified; description = "Contact dicts to fill naemon objects"; };
585 email_check = mkOption {
586 description = "Emails services to check";
587 type = attrsOf (submodule {
589 local = mkOption { type = bool; default = false; description = "Use local configuration"; };
590 port = mkOption { type = nullOr str; default = null; description = "Port to connect to ssh"; };
591 login = mkOption { type = nullOr str; default = null; description = "Login to connect to ssh"; };
592 targets = mkOption { type = listOf str; description = "Hosts to send E-mails to"; };
593 mail_address = mkOption { type = nullOr str; default = null; description = "E-mail recipient part to send e-mail to"; };
594 mail_domain = mkOption { type = nullOr str; default = null; description = "E-mail domain part to send e-mail to"; };
602 description = "MPD configuration";
605 folder = mkOption { type = str; description = "Folder to serve from the MPD instance"; };
606 password = mkOption { type = str; description = "Password to connect to the MPD instance"; };
607 host = mkOption { type = str; description = "Host to connect to the MPD instance"; };
608 port = mkOption { type = str; description = "Port to connect to the MPD instance"; };
613 description = "FTP configuration";
616 ldap = mkLdapOptions "FTP" {
617 proftpd_filter = mkOption { type = str; description = "Filter for proftpd listing in LDAP"; };
618 pure-ftpd_filter = mkOption { type = str; description = "Filter for pure-ftpd listing in LDAP"; };
624 description = "VPN configuration";
625 type = attrsOf (submodule {
627 prefix = mkOption { type = str; description = "ipv6 prefix for the vpn subnet"; };
628 privateKey = mkOption { type = str; description = "Private key for the host"; };
629 publicKey = mkOption { type = str; description = "Public key for the host"; };
634 description = "Mail configuration";
638 description = "DMARC configuration";
641 ignore_hosts = mkOption {
644 Hosts to ignore when checking for dmarc
651 description = "DKIM configuration";
652 type = attrsOf (submodule {
658 "p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC3w1a2aMxWw9+hdcmbqX4UevcVqr204y0K73Wdc7MPZiOOlUJQYsMNSYR1Y/SC7jmPKeitpcJCpQgn/cveJZbuikjjPLsDReHyFEYmC278ZLRTELHx6f1IXM8WE08JIRT69CfZiMi1rVcOh9qRT4F93PyjCauU8Y5hJjtg9ThsWwIDAQAB" )
660 description = "Public entry to put in DNS TXT field";
662 private = mkOption { type = str; description = "Private key"; };
667 description = "Postfix configuration";
670 additional_mailbox_domains = mkOption {
672 List of domains that are used as mailbox final destination, in addition to those defined in the DNS records
676 mysql = mkMysqlOptions "Postfix" {
677 password_encrypt = mkOption { type = str; description = "Key to encrypt relay password in database"; };
679 backup_domains = mkOption {
681 Domains that are accepted for relay as backup domain
683 type = attrsOf (submodule {
685 domains = mkOption { type = listOf str; description = "Domains list"; };
686 relay_restrictions = mkOption {
689 Restrictions for relaying the e-mails from the domains
692 recipient_maps = mkOption {
694 Recipient map to accept relay for.
695 Must be specified for domain, the rules apply to everyone!
697 type = listOf (submodule {
700 type = enum [ "hash" ];
701 description = "Map type";
705 description = "Map content";
717 description = "Dovecot configuration";
720 ldap = mkLdapOptions "Dovecot" {
721 pass_attrs = mkOption { type = str; description = "Password attribute in LDAP"; };
722 user_attrs = mkOption { type = str; description = "User attribute mapping in LDAP"; };
723 iterate_attrs = mkOption { type = str; description = "User attribute mapping for listing in LDAP"; };
724 iterate_filter = mkOption { type = str; description = "User attribute filter for listing in LDAP"; };
725 postfix_mailbox_filter = mkOption { type = str; description = "Postfix filter to get mailboxes"; };
731 description = "rspamd configuration";
734 redis = mkRedisOptions "Redis";
735 read_password_hashed = mkOption { type = str; description = "Hashed read password for rspamd"; };
736 write_password_hashed = mkOption { type = str; description = "Hashed write password for rspamd"; };
737 read_password = mkOption {
739 description = "Read password for rspamd. Unused";
742 write_password = mkOption {
744 description = "Write password for rspamd. Unused";
751 description = "Mail script recipients";
752 type = attrsOf (submodule {
754 external = mkEnableOption "Create a script_<name>@mail.immae.eu external address";
757 git source to fetch the script from.
758 It must have a default.nix file as its root accepting a scriptEnv parameter
762 url = mkOption { type = str; description = "git url to fetch"; };
763 rev = mkOption { type = str; description = "git reference to fetch"; };
768 description = "Variables to pass to the script";
775 description = "Sympa configuration";
778 listmasters = mkOption {
780 description = "Listmasters";
782 postgresql = mkPsqlOptions "Sympa";
783 data_sources = mkOption {
786 description = "Data sources to make available to sympa";
791 description = "Scenari to make available to sympa";
800 description = "Coturn configuration";
803 auth_access_key = mkOption { type = str; description = "key to access coturn"; };
807 buildbot = mkOption {
808 description = "Buildbot configuration";
812 description = "SSH key information";
815 public = mkOption { type = str; description = "Public part of the key"; };
816 private = mkOption { type = lines; description = "Private part of the key"; };
820 workerPassword = mkOption { description = "Buildbot worker password"; type = str; };
822 description = "Buildbot user";
826 description = "user uid";
830 description = "user gid";
837 description = "Ldap configuration for buildbot";
840 password = mkOption { type = str; description = "Buildbot password"; };
844 projects = mkOption {
845 description = "Projects to make a buildbot for";
846 type = attrsOf (submodule {
848 name = mkOption { type = str; description = "Project name"; };
849 packages = mkOption {
851 example = literalExample ''
852 pkgs: [ pkgs.bash pkgs.git pkgs.gzip pkgs.openssh ];
856 Builds packages list to make available to buildbot project.
857 Takes pkgs as argument.
860 pythonPackages = mkOption {
862 example = literalExample ''
863 p: pkgs: [ pkgs.python3Packages.pip ];
867 Builds python packages list to make available to buildbot project.
868 Takes buildbot python module as first argument and pkgs as second argument in order to augment the python modules list.
871 pythonPathHome = mkOption { type = bool; description = "Whether to add project’s python home to python path"; };
872 workerPort = mkOption { type = port; description = "Port for the worker"; };
874 #type = attrsOf (either str (functionTo str));
875 type = attrsOf unspecified;
876 description = "Secrets for the project to dump as files. Might be a function that takes pkgs as argument";
878 environment = mkOption {
879 #type = attrsOf (either str (functionTo str));
880 type = attrsOf unspecified;
882 Environment variables for the project. Might be a function that takes pkgs as argument.
883 BUILDBOT_ is prefixed to the variable names
886 activationScript = mkOption {
889 Activation script to run during deployment
892 builderPaths = mkOption {
893 type = attrsOf unspecified;
896 Attrs of functions to make accessible specifically per builder.
897 Takes pkgs as argument and should return a single path containing binaries.
898 This path will be accessible as BUILDBOT_PATH_<attrskey>
901 webhookTokens = mkOption {
902 type = nullOr (listOf str);
905 List of tokens allowed to push to project’s change_hook/base endpoint
915 description = "Tools configurations";
918 contact = mkOption { type = str; description = "Contact e-mail address"; };
921 type = attrsOf (submodule {
923 url = mkOption { type = str; description = "URL to fetch"; };
924 sha256 = mkOption { type = str; description = "Hash of the url"; };
927 description = "Assets to provide on assets.immae.eu";
930 description = "Davical configuration";
933 postgresql = mkPsqlOptions "Davical";
934 ldap = mkLdapOptions "Davical" {};
938 diaspora = mkOption {
939 description = "Diaspora configuration";
942 postgresql = mkPsqlOptions "Diaspora";
943 redis = mkRedisOptions "Diaspora";
944 ldap = mkLdapOptions "Diaspora" {};
945 secret_token = mkOption { type = str; description = "Secret token"; };
949 dmarc_reports = mkOption {
950 description = "DMARC reports configuration";
953 mysql = mkMysqlOptions "DMARC" {};
954 anonymous_key = mkOption { type = str; description = "Anonymous hashing key"; };
958 etherpad-lite = mkOption {
959 description = "Etherpad configuration";
962 postgresql = mkPsqlOptions "Etherpad";
963 ldap = mkLdapOptions "Etherpad" {
964 group_filter = mkOption { type = str; description = "Filter for groups"; };
966 adminPassword = mkOption { type = str; description = "Admin password for mypads / admin"; };
967 session_key = mkOption { type = str; description = "Session key"; };
968 api_key = mkOption { type = str; description = "API key"; };
969 redirects = mkOption { type = str; description = "Redirects for apache"; };
973 gitolite = mkOption {
974 description = "Gitolite configuration";
977 ldap = mkLdapOptions "Gitolite" {};
979 description = "SSH key information";
982 public = mkOption { type = str; description = "Public part of the key"; };
983 private = mkOption { type = lines; description = "Private part of the key"; };
990 kanboard = mkOption {
991 description = "Kanboard configuration";
994 postgresql = mkPsqlOptions "Kanboard";
995 ldap = mkLdapOptions "Kanboard" {
996 admin_dn = mkOption { type = str; description = "Admin DN"; };
1001 mantisbt = mkOption {
1002 description = "Mantisbt configuration";
1005 postgresql = mkPsqlOptions "Mantisbt";
1006 ldap = mkLdapOptions "Mantisbt" {};
1007 master_salt = mkOption { type = str; description = "Master salt for password hash"; };
1011 mastodon = mkOption {
1012 description = "Mastodon configuration";
1015 postgresql = mkPsqlOptions "Mastodon";
1016 redis = mkRedisOptions "Mastodon";
1017 ldap = mkLdapOptions "Mastodon" {};
1018 paperclip_secret = mkOption { type = str; description = "Paperclip secret"; };
1019 otp_secret = mkOption { type = str; description = "OTP secret"; };
1020 secret_key_base = mkOption { type = str; description = "Secret key base"; };
1022 description = "vapid key";
1025 private = mkOption { type = str; description = "Private key"; };
1026 public = mkOption { type = str; description = "Public key"; };
1033 mediagoblin = mkOption {
1034 description = "Mediagoblin configuration";
1037 postgresql = mkPsqlOptions "Mediagoblin";
1038 redis = mkRedisOptions "Mediagoblin";
1039 ldap = mkLdapOptions "Mediagoblin" {};
1043 nextcloud = mkOption {
1044 description = "Nextcloud configuration";
1047 postgresql = mkPsqlOptions "Peertube";
1048 redis = mkRedisOptions "Peertube";
1049 password_salt = mkOption { type = str; description = "Password salt"; };
1050 instance_id = mkOption { type = str; description = "Instance ID"; };
1051 secret = mkOption { type = str; description = "App secret"; };
1055 peertube = mkOption {
1056 description = "Peertube configuration";
1059 listenPort = mkOption { type = port; description = "Port to listen to"; };
1060 postgresql = mkPsqlOptions "Peertube";
1061 redis = mkRedisOptions "Peertube";
1062 ldap = mkLdapOptions "Peertube" {};
1066 syden_peertube = mkOption {
1067 description = "Peertube Syden configuration";
1070 listenPort = mkOption { type = port; description = "Port to listen to"; };
1071 postgresql = mkPsqlOptions "Peertube";
1072 redis = mkRedisOptions "Peertube";
1076 phpldapadmin = mkOption {
1077 description = "phpLdapAdmin configuration";
1080 ldap = mkLdapOptions "phpldapadmin" {};
1085 description = "Rompr configuration";
1089 description = "MPD configuration";
1092 host = mkOption { type = str; description = "Host for MPD"; };
1093 port = mkOption { type = port; description = "Port to access MPD host"; };
1100 roundcubemail = mkOption {
1101 description = "Roundcubemail configuration";
1104 postgresql = mkPsqlOptions "TT-RSS";
1105 secret = mkOption { type = str; description = "Secret"; };
1109 shaarli = mkOption {
1110 description = "Shaarli configuration";
1113 ldap = mkLdapOptions "Shaarli" {};
1117 status_engine = mkOption {
1118 description = "Status Engine configuration";
1121 mysql = mkMysqlOptions "StatusEngine" {};
1122 ldap = mkLdapOptions "StatusEngine" {};
1127 description = "Taskwarrior configuration";
1130 ldap = mkLdapOptions "Taskwarrior" {};
1131 taskwarrior-web = mkOption {
1132 description = "taskwarrior-web profiles";
1133 type = attrsOf (submodule {
1137 description = "List of ldap uids having access to this profile";
1139 org = mkOption { type = str; description = "Taskd organisation"; };
1140 key = mkOption { type = str; description = "Taskd key"; };
1141 date = mkOption { type = str; description = "Preferred date format"; };
1149 description = "TT-RSS configuration";
1152 postgresql = mkPsqlOptions "TT-RSS";
1153 ldap = mkLdapOptions "TT-RSS" {};
1157 wallabag = mkOption {
1158 description = "Wallabag configuration";
1161 postgresql = mkPsqlOptions "Wallabag";
1162 ldap = mkLdapOptions "Wallabag" {
1163 admin_filter = mkOption { type = str; description = "Admin users filter"; };
1165 redis = mkRedisOptions "Wallabag";
1166 secret = mkOption { type = str; description = "App secret"; };
1170 webhooks = mkOption {
1172 description = "Mapping 'name'.php => script for webhooks";
1174 csp_reports = mkOption {
1175 description = "CSP report configuration";
1178 report_uri = mkOption { type = str; description = "URI to report CSP violations to"; };
1179 policies = mkOption { type = attrsOf str; description = "CSP policies to apply"; };
1180 postgresql = mkPsqlOptions "CSP reports";
1184 commento = mkOption {
1185 description = "Commento configuration";
1188 listenPort = mkOption { type = port; description = "Port to listen to"; };
1189 postgresql = mkPsqlOptions "Commento";
1190 smtp = mkSmtpOptions "Commento";
1194 cryptpad = mkOption {
1195 description = "Cryptpad configuration";
1196 type = attrsOf (submodule {
1198 email = mkOption { type = str; description = "Admin e-mail"; };
1199 admins = mkOption { type = listOf str; description = "Instance admin public keys"; };
1200 port = mkOption { type = port; description = "Port to listen to"; };
1205 description = "Ympd configuration";
1208 listenPort = mkOption { type = port; description = "Port to listen to"; };
1210 description = "MPD configuration";
1213 password = mkOption { type = str; description = "Password to access MPD host"; };
1214 host = mkOption { type = str; description = "Host for MPD"; };
1215 port = mkOption { type = port; description = "Port to access MPD host"; };
1223 description = "Umami configuration";
1226 listenPort = mkOption { type = port; description = "Port to listen to"; };
1227 postgresql = mkPsqlOptions "Umami";
1228 hashSalt = mkOption { type = str; description = "Hash salt"; };
1233 description = "Yourls configuration";
1236 mysql = mkMysqlOptions "Yourls" {};
1237 ldap = mkLdapOptions "Yourls" {};
1238 cookieKey = mkOption { type = str; description = "Cookie key"; };
1245 serverSpecific = mkOption { type = attrsOf unspecified; description = "Server specific configuration"; };
1246 websites = mkOption {
1247 description = "Websites configurations";
1250 christophe_carpentier = mkOption {
1251 description = "Christophe Carpentier configuration by environment";
1254 agorakit = mkOption {
1255 description = "Agorakit configuration";
1258 mysql = mkMysqlOptions "Agorakit" {};
1259 smtp = mkSmtpOptions "Agorakit";
1260 appkey = mkOption { type = str; description = "App key"; };
1268 description = "Immae configuration by environment";
1272 description = "Temp configuration";
1275 ldap = mkLdapOptions "Immae temp" {
1276 filter = mkOption { type = str; description = "Filter for user access"; };
1284 isabelle = mkOption {
1285 description = "Isabelle configurations by environment";
1288 atenSubmodule = mkOption {
1289 description = "environment configuration";
1292 environment = mkOption { type = str; description = "Symfony environment"; };
1293 secret = mkOption { type = str; description = "Symfony App secret"; };
1294 postgresql = mkPsqlOptions "Aten";
1301 aten_production = atenSubmodule;
1302 aten_integration = atenSubmodule;
1303 iridologie = mkOption {
1304 description = "environment configuration";
1307 environment = mkOption { type = str; description = "SPIP environment"; };
1308 mysql = mkMysqlOptions "Iridologie" {};
1309 ldap = mkLdapOptions "Iridologie" {};
1317 description = "Chloe configurations by environment";
1320 chloeSubmodule = mkOption {
1321 description = "environment configuration";
1324 environment = mkOption { type = str; description = "SPIP environment"; };
1325 mysql = mkMysqlOptions "Chloe" {};
1326 ldap = mkLdapOptions "Chloe" {};
1333 production = chloeSubmodule;
1334 integration = chloeSubmodule;
1336 description = "environment configuration";
1339 mysql = mkMysqlOptions "ChloeNew" {};
1340 ldap = mkLdapOptions "ChloeNew" {};
1341 secret = mkOption { type = str; description = "Symfony App secret"; };
1348 connexionswing = mkOption {
1349 description = "Connexionswing configurations by environment";
1352 csSubmodule = mkOption {
1353 description = "environment configuration";
1356 environment = mkOption { type = str; description = "Symfony environment"; };
1357 mysql = mkMysqlOptions "Connexionswing" {};
1358 secret = mkOption { type = str; description = "Symfony App secret"; };
1359 email = mkOption { type = str; description = "Symfony email notification"; };
1366 production = csSubmodule;
1367 integration = csSubmodule;
1372 description = "Naturaloutil configuration";
1375 mysql = mkMysqlOptions "Naturaloutil" {};
1376 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1380 telio_tortay = mkOption {
1381 description = "Telio Tortay configuration";
1384 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1388 ludivine = mkOption {
1389 description = "Ludivinecassal configurations by environment";
1392 lcSubmodule = mkOption {
1393 description = "environment configuration";
1396 environment = mkOption { type = str; description = "Symfony environment"; };
1397 mysql = mkMysqlOptions "LudivineCassal" {};
1398 ldap = mkLdapOptions "LudivineCassal" {};
1399 secret = mkOption { type = str; description = "Symfony App secret"; };
1406 production = lcSubmodule;
1407 integration = lcSubmodule;
1411 nicecoop = mkOption {
1412 description = "Nicecoop configuration";
1416 port = mkOption { description = "Port to listen to"; type = port; };
1417 longpoll_port = mkOption { description = "Port to listen to"; type = port; };
1418 postgresql = mkPsqlOptions "Odoo";
1419 admin_password = mkOption { type = str; description = "Admin password"; };
1422 smtp = mkSmtpOptions "GestionCompte";
1423 mysql = mkMysqlOptions "gestion-compte" {};
1424 secret = mkOption { type = str; description = "Application secret"; };
1425 adminpassword = mkOption { type = str; description = "Admin password"; };
1427 gestion-compte-integration = {
1428 smtp = mkSmtpOptions "GestionCompte";
1429 mysql = mkMysqlOptions "gestion-compte" {};
1430 secret = mkOption { type = str; description = "Application secret"; };
1431 adminpassword = mkOption { type = str; description = "Admin password"; };
1434 smtp = mkSmtpOptions "Copanier";
1435 staff = mkOption { type = listOf str; description = "List of staff members"; };
1441 description = "Emilia configuration";
1444 postgresql = mkPsqlOptions "Emilia";
1448 florian = mkOption {
1449 description = "Florian configuration";
1452 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1456 nassime = mkOption {
1457 description = "Nassime configuration";
1460 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1464 piedsjaloux = mkOption {
1465 description = "Piedsjaloux configurations by environment";
1468 pjSubmodule = mkOption {
1469 description = "environment configuration";
1472 environment = mkOption { type = str; description = "Symfony environment"; };
1473 mysql = mkMysqlOptions "Piedsjaloux" {};
1474 secret = mkOption { type = str; description = "Symfony App secret"; };
1481 production = pjSubmodule;
1482 integration = pjSubmodule;
1487 description = "Europe Richie configurations by environment";
1490 mysql = mkMysqlOptions "Richie" {};
1491 smtp_mailer = mkOption {
1492 description = "SMTP mailer configuration";
1495 user = mkOption { type = str; description = "Username"; };
1496 password = mkOption { type = str; description = "Password"; };
1503 caldance = mkOption {
1504 description = "Caldance configurations by environment";
1507 integration = mkOption {
1508 description = "environment configuration";
1511 password = mkOption { type = str; description = "Password file content for basic auth"; };
1518 tellesflorian = mkOption {
1519 description = "Tellesflorian configurations by environment";
1522 tfSubmodule = mkOption {
1523 description = "environment configuration";
1526 environment = mkOption { type = str; description = "Symfony environment"; };
1527 mysql = mkMysqlOptions "Tellesflorian" {};
1528 secret = mkOption { type = str; description = "Symfony App secret"; };
1529 invite_passwords = mkOption { type = str; description = "Password basic auth"; };
1536 integration = tfSubmodule;
1544 options.hostEnv = mkOption {
1547 default = config.myEnv.servers."${name}";
1548 description = "Host environment";