]> git.immae.eu Git - perso/Immae/Config/Nix.git/blob - modules/private/environment.nix
Add coturn server
[perso/Immae/Config/Nix.git] / modules / private / environment.nix
1 { config, lib, name, ... }:
2 with lib;
3 with types;
4 with lists;
5 let
6 ldapOptions = {
7 base = mkOption { description = "Base of the LDAP tree"; type = str; };
8 host = mkOption { description = "Host to access LDAP"; type = str; };
9 root_dn = mkOption { description = "DN of the root user"; type = str; };
10 root_pw = mkOption { description = "Hashed password of the root user"; type = str; };
11 replication_dn = mkOption { description = "DN of the user allowed to replicate the LDAP directory"; type = str; };
12 replication_pw = mkOption { description = "Password of the user allowed to replicate the LDAP directory"; type = str; };
13 };
14 mkLdapOptions = name: more: mkOption {
15 description = "${name} LDAP configuration";
16 type = submodule {
17 options = ldapOptions // {
18 dn = mkOption { description = "DN of the ${name} user"; type = str; };
19 password = mkOption { description = "password of the ${name} user"; type = str; };
20 filter = mkOption { description = "Filter for ${name} users"; type = str; default = ""; };
21 } // more;
22 };
23 };
24 mysqlOptions = {
25 host = mkOption { description = "Host to access Mysql"; type = str; };
26 remoteHost = mkOption { description = "Host to access Mysql from outside"; type = str; };
27 port = mkOption { description = "Port to access Mysql"; type = str; };
28 socket = mkOption { description = "Socket to access Mysql"; type = path; };
29 systemUsers = mkOption {
30 description = "Attrs of user-passwords allowed to access mysql";
31 type = attrsOf str;
32 };
33 pam = mkOption {
34 description = "PAM configuration for mysql";
35 type = submodule {
36 options = {
37 dn = mkOption { description = "DN to connect as to check users"; type = str; };
38 password = mkOption { description = "DN password to connect as to check users"; type = str; };
39 filter = mkOption { description = "filter to match users"; type = str; };
40 };
41 };
42 };
43 };
44 mkMysqlOptions = name: more: mkOption {
45 description = "${name} mysql configuration";
46 type = submodule {
47 options = mysqlOptions // {
48 database = mkOption { description = "${name} database"; type = str; };
49 user = mkOption { description = "${name} user"; type = str; };
50 password = mkOption { description = "mysql password of the ${name} user"; type = str; };
51 } // more;
52 };
53 };
54 psqlOptions = {
55 host = mkOption { description = "Host to access Postgresql"; type = str; };
56 port = mkOption { description = "Port to access Postgresql"; type = str; };
57 socket = mkOption { description = "Socket to access Postgresql"; type = path; };
58 pam = mkOption {
59 description = "PAM configuration for psql";
60 type = submodule {
61 options = {
62 dn = mkOption { description = "DN to connect as to check users"; type = str; };
63 password = mkOption { description = "DN password to connect as to check users"; type = str; };
64 filter = mkOption { description = "filter to match users"; type = str; };
65 };
66 };
67 };
68 };
69 mkPsqlOptions = name: mkOption {
70 description = "${name} psql configuration";
71 type = submodule {
72 options = psqlOptions // {
73 database = mkOption { description = "${name} database"; type = str; };
74 schema = mkOption { description = "${name} schema"; type = nullOr str; default = null; };
75 user = mkOption { description = "${name} user"; type = str; };
76 password = mkOption { description = "psql password of the ${name} user"; type = str; };
77 };
78 };
79 };
80 redisOptions = {
81 host = mkOption { description = "Host to access Redis"; type = str; };
82 port = mkOption { description = "Port to access Redis"; type = str; };
83 socket = mkOption { description = "Socket to access Redis"; type = path; };
84 dbs = mkOption {
85 description = "Attrs of db number. Each number should be unique to avoid collision!";
86 type = attrsOf str;
87 };
88 spiped_key = mkOption {
89 type = str;
90 description = ''
91 Key to use with spiped to make a secure channel to replication
92 '';
93 };
94 predixy = mkOption {
95 description = "Predixy configuration. Unused yet";
96 type = submodule {
97 options = {
98 read = mkOption { type = str; description = "Read password"; };
99 };
100 };
101 };
102 };
103 mkRedisOptions = name: mkOption {
104 description = "${name} redis configuration";
105 type = submodule {
106 options = redisOptions // {
107 db = mkOption { description = "${name} database"; type = str; };
108 };
109 };
110 };
111 smtpOptions = {
112 host = mkOption { description = "Host to access SMTP"; type = str; };
113 port = mkOption { description = "Port to access SMTP"; type = str; };
114 };
115 mkSmtpOptions = name: mkOption {
116 description = "${name} smtp configuration";
117 type = submodule {
118 options = smtpOptions // {
119 email = mkOption { description = "${name} email"; type = str; };
120 password = mkOption { description = "SMTP password of the ${name} user"; type = str; };
121 };
122 };
123 };
124 hostEnv = submodule {
125 options = {
126 fqdn = mkOption {
127 description = "Host FQDN";
128 type = str;
129 };
130 users = mkOption {
131 type = unspecified;
132 default = pkgs: [];
133 description = ''
134 Sublist of users from realUsers. Function that takes pkgs as
135 argument and gives an array as a result
136 '';
137 };
138 emails = mkOption {
139 default = [];
140 description = "List of e-mails that the server can be a sender of";
141 type = listOf str;
142 };
143 ldap = mkOption {
144 description = ''
145 LDAP credentials for the host
146 '';
147 type = submodule {
148 options = {
149 password = mkOption { type = str; description = "Password for the LDAP connection"; };
150 dn = mkOption { type = str; description = "DN for the LDAP connection"; };
151 };
152 };
153 };
154 mx = mkOption {
155 description = "subdomain and priority for MX server";
156 default = { enable = false; };
157 type = submodule {
158 options = {
159 enable = mkEnableOption "Enable MX";
160 subdomain = mkOption { type = nullOr str; description = "Subdomain name (mx-*)"; };
161 priority = mkOption { type = nullOr str; description = "Priority"; };
162 };
163 };
164 };
165 ips = mkOption {
166 description = ''
167 attrs of ip4/ip6 grouped by section
168 '';
169 type = attrsOf (submodule {
170 options = {
171 ip4 = mkOption {
172 type = str;
173 description = ''
174 ip4 address of the host
175 '';
176 };
177 ip6 = mkOption {
178 type = listOf str;
179 default = [];
180 description = ''
181 ip6 addresses of the host
182 '';
183 };
184 };
185 });
186 };
187 };
188 };
189 in
190 {
191 options.myEnv = {
192 servers = mkOption {
193 description = ''
194 Attrs of servers information in the cluster (not necessarily handled by nixops)
195 '';
196 default = {};
197 type = attrsOf hostEnv;
198 };
199 hetznerCloud = mkOption {
200 description = ''
201 Hetzner Cloud credential information
202 '';
203 type = submodule {
204 options = {
205 authToken = mkOption {
206 type = str;
207 description = ''
208 The API auth token.
209 '';
210 };
211 };
212 };
213 };
214 hetzner = mkOption {
215 description = ''
216 Hetzner credential information
217 '';
218 type = submodule {
219 options = {
220 user = mkOption { type = str; description = "User"; };
221 pass = mkOption { type = str; description = "Password"; };
222 };
223 };
224 };
225 sshd = mkOption {
226 description = ''
227 sshd service credential information
228 '';
229 type = submodule {
230 options = {
231 rootKeys = mkOption { type = attrsOf str; description = "Keys of root users"; };
232 ldap = mkOption {
233 description = ''
234 LDAP credentials for cn=ssh,ou=services,dc=immae,dc=eu dn
235 '';
236 type = submodule {
237 options = {
238 password = mkOption { description = "Password"; type = str; };
239 };
240 };
241 };
242 };
243 };
244 };
245 ports = mkOption {
246 description = ''
247 non-standard reserved ports. Must be unique!
248 '';
249 type = attrsOf port;
250 default = {};
251 apply = let
252 noDupl = x: builtins.length (builtins.attrValues x) == builtins.length (unique (builtins.attrValues x));
253 in
254 x: if isAttrs x && noDupl x then x else throw "Non unique values for ports";
255 };
256 httpd = mkOption {
257 description = ''
258 httpd service credential information
259 '';
260 type = submodule {
261 options = {
262 ldap = mkOption {
263 description = ''
264 LDAP credentials for cn=httpd,ou=services,dc=immae,dc=eu dn
265 '';
266 type = submodule {
267 options = {
268 password = mkOption { description = "Password"; type = str; };
269 };
270 };
271 };
272 };
273 };
274 };
275 smtp = mkOption {
276 type = submodule { options = smtpOptions; };
277 description = "SMTP configuration";
278 };
279 ldap = mkOption {
280 description = ''
281 LDAP server configuration
282 '';
283 type = submodule {
284 options = ldapOptions;
285 };
286 };
287 databases = mkOption {
288 description = "Databases configuration";
289 type = submodule {
290 options = {
291 mysql = mkOption {
292 type = submodule { options = mysqlOptions; };
293 description = "Mysql configuration";
294 };
295 redis = mkOption {
296 type = submodule { options = redisOptions; };
297 description = "Redis configuration";
298 };
299 postgresql = mkOption {
300 type = submodule { options = psqlOptions; };
301 description = "Postgresql configuration";
302 };
303 };
304 };
305 };
306 jabber = mkOption {
307 description = "Jabber configuration";
308 type = submodule {
309 options = {
310 postfix_user_filter = mkOption { type = str; description = "Postfix filter to get xmpp users"; };
311 ldap = mkLdapOptions "Jabber" {};
312 postgresql = mkPsqlOptions "Jabber";
313 };
314 };
315 };
316 realUsers = mkOption {
317 description = ''
318 Attrset of function taking pkgs as argument.
319 Real users settings, should provide a subattr of users.users.<name>
320 with at least: name, (hashed)Password, shell
321 '';
322 type = attrsOf unspecified;
323 };
324 users = mkOption {
325 description = "System and regular users uid/gid";
326 type = attrsOf (submodule {
327 options = {
328 uid = mkOption {
329 description = "user uid";
330 type = int;
331 };
332 gid = mkOption {
333 description = "user gid";
334 type = int;
335 };
336 };
337 });
338 };
339 dns = mkOption {
340 description = "DNS configuration";
341 type = submodule {
342 options = {
343 soa = mkOption {
344 description = "SOA information";
345 type = submodule {
346 options = {
347 serial = mkOption {
348 description = "Serial number. Should be incremented at each change and unique";
349 type = str;
350 };
351 refresh = mkOption {
352 description = "Refresh time";
353 type = str;
354 };
355 retry = mkOption {
356 description = "Retry time";
357 type = str;
358 };
359 expire = mkOption {
360 description = "Expire time";
361 type = str;
362 };
363 ttl = mkOption {
364 description = "Default TTL time";
365 type = str;
366 };
367 email = mkOption {
368 description = "hostmaster e-mail";
369 type = str;
370 };
371 primary = mkOption {
372 description = "Primary NS";
373 type = str;
374 };
375 };
376 };
377 };
378 ns = mkOption {
379 description = "Attrs of NS servers group";
380 example = {
381 foo = {
382 "ns1.foo.com" = [ "198.51.100.10" "2001:db8:abcd::1" ];
383 "ns2.foo.com" = [ "198.51.100.15" "2001:db8:1234::1" ];
384 };
385 };
386 type = attrsOf (attrsOf (listOf str));
387 };
388 keys = mkOption {
389 default = {};
390 description = "DNS keys";
391 type = attrsOf (submodule {
392 options = {
393 algorithm = mkOption { type = str; description = "Algorithm"; };
394 secret = mkOption { type = str; description = "Secret"; };
395 };
396 });
397 };
398 slaveZones = mkOption {
399 description = "List of slave zones";
400 type = listOf (submodule {
401 options = {
402 name = mkOption { type = str; description = "zone name"; };
403 masters = mkOption {
404 description = "NS master groups of this zone";
405 type = listOf str;
406 };
407 keys = mkOption {
408 default = [];
409 description = "Keys associated to the server";
410 type = listOf str;
411 };
412 };
413 });
414 };
415 masterZones = mkOption {
416 description = "List of master zones";
417 type = listOf (submodule {
418 options = {
419 name = mkOption { type = str; description = "zone name"; };
420 withCAA = mkOption { type = nullOr str; description = "CAA entry"; default = null; };
421 slaves = mkOption {
422 description = "NS slave groups of this zone";
423 type = listOf str;
424 };
425 ns = mkOption {
426 description = "groups names that should have their NS entries listed here";
427 type = listOf str;
428 };
429 extra = mkOption {
430 description = "Extra zone configuration for bind";
431 example = ''
432 notify yes;
433 '';
434 type = lines;
435 };
436 entries = mkOption { type = lines; description = "Regular entries of the NS zone"; };
437 withEmail = mkOption {
438 description = "List of domains that should have mail entries (MX, dkim, SPF, ...)";
439 default = [];
440 type = listOf (submodule {
441 options = {
442 domain = mkOption { type = str; description = "Which subdomain is concerned"; };
443 send = mkOption { type = bool; description = "Whether there can be e-mails originating from the subdomain"; };
444 receive = mkOption { type = bool; description = "Whether there can be e-mails arriving to the subdomain"; };
445 };
446 });
447 };
448 };
449 });
450 };
451 };
452 };
453 };
454 backup = mkOption {
455 description = ''
456 Remote backup with duplicity
457 '';
458 type = submodule {
459 options = {
460 password = mkOption { type = str; description = "Password for encrypting files"; };
461 remotes = mkOption {
462 type = attrsOf (submodule {
463 options = {
464 remote = mkOption {
465 type = unspecified;
466 example = literalExample ''
467 bucket: "s3://some_host/${bucket}";
468 '';
469 description = ''
470 Function.
471 Takes a bucket name as argument and returns a url
472 '';
473 };
474 accessKeyId = mkOption { type = str; description = "Remote access-key"; };
475 secretAccessKey = mkOption { type = str; description = "Remote access secret"; };
476 };
477 });
478 };
479 };
480 };
481 };
482 zrepl_backup = mkOption {
483 type = submodule {
484 options = {
485 ssh_key = mkOption {
486 description = "SSH key information";
487 type = submodule {
488 options = {
489 public = mkOption { type = str; description = "Public part of the key"; };
490 private = mkOption { type = lines; description = "Private part of the key"; };
491 };
492 };
493 };
494 mysql = mkMysqlOptions "Zrepl" {};
495 };
496 };
497 };
498 rsync_backup = mkOption {
499 description =''
500 Rsync backup configuration from controlled host
501 '';
502 type = submodule {
503 options = {
504 ssh_key = mkOption {
505 description = "SSH key information";
506 type = submodule {
507 options = {
508 public = mkOption { type = str; description = "Public part of the key"; };
509 private = mkOption { type = lines; description = "Private part of the key"; };
510 };
511 };
512 };
513 profiles = mkOption {
514 description = "Attrs of profiles to backup";
515 type = attrsOf (submodule {
516 options = {
517 keep = mkOption { type = int; description = "Number of backups to keep"; };
518 check_command = mkOption { type = str; description = "command to check if backup needs to be done"; default = "backup"; };
519 login = mkOption { type = str; description = "Login to connect to host"; };
520 port = mkOption { type = str; default = "22"; description = "Port to connect to host"; };
521 host = mkOption { type = str; description = "Host to connect to"; };
522 host_key = mkOption { type = str; description = "Host key"; };
523 host_key_type = mkOption { type = str; description = "Host key type"; };
524 parts = mkOption {
525 description = "Parts to backup for this host";
526 type = attrsOf (submodule {
527 options = {
528 remote_folder = mkOption { type = path; description = "Remote folder to backup";};
529 exclude_from = mkOption {
530 type = listOf path;
531 default = [];
532 description = "List of folders/files to exclude from the backup";
533 };
534 files_from = mkOption {
535 type = listOf path;
536 default = [];
537 description = "List of folders/files to backup in the base folder";
538 };
539 args = mkOption {
540 type = nullOr str;
541 default = null;
542 description = "Extra arguments to pass to rsync";
543 };
544 };
545 });
546 };
547 };
548 });
549 };
550 };
551 };
552 };
553 monitoring = mkOption {
554 description = "Monitoring configuration";
555 type = submodule {
556 options = {
557 status_url = mkOption { type = str; description = "URL to push status to"; };
558 status_token = mkOption { type = str; description = "Token for the status url"; };
559 http_user_password = mkOption { type = str; description = "HTTP credentials to check services behind wall"; };
560 email = mkOption { type = str; description = "Admin E-mail"; };
561 ssh_public_key = mkOption { type = str; description = "SSH public key"; };
562 ssh_secret_key = mkOption { type = str; description = "SSH secret key"; };
563 imap_login = mkOption { type = str; description = "IMAP login"; };
564 imap_password = mkOption { type = str; description = "IMAP password"; };
565 eriomem_keys = mkOption { type = listOf (listOf str); description = "Eriomem keys"; default = []; };
566 ovh_sms = mkOption {
567 description = "OVH credentials for sms script";
568 type = submodule {
569 options = {
570 endpoint = mkOption { type = str; default = "ovh-eu"; description = "OVH endpoint"; };
571 application_key = mkOption { type = str; description = "Application key"; };
572 application_secret = mkOption { type = str; description = "Application secret"; };
573 consumer_key = mkOption { type = str; description = "Consumer key"; };
574 account = mkOption { type = str; description = "Account"; };
575 };
576 };
577 };
578 eban = mkOption {
579 description = "Eban credentials for webhook";
580 type = submodule {
581 options = {
582 user = mkOption { type = str; description = "User"; };
583 password = mkOption { type = str; description = "Password"; };
584 };
585 };
586 };
587 nrdp_tokens = mkOption { type = listOf str; description = "Tokens allowed to push status update"; };
588 slack_url = mkOption { type = str; description = "Slack webhook url to push status update"; };
589 slack_channel = mkOption { type = str; description = "Slack channel to push status update"; };
590 netdata_aggregator = mkOption { type = str; description = "Url where netdata information should be sent"; };
591 netdata_keys = mkOption { type = attrsOf str; description = "netdata host keys"; };
592 contacts = mkOption { type = attrsOf unspecified; description = "Contact dicts to fill naemon objects"; };
593 email_check = mkOption {
594 description = "Emails services to check";
595 type = attrsOf (submodule {
596 options = {
597 local = mkOption { type = bool; default = false; description = "Use local configuration"; };
598 port = mkOption { type = nullOr str; default = null; description = "Port to connect to ssh"; };
599 login = mkOption { type = nullOr str; default = null; description = "Login to connect to ssh"; };
600 targets = mkOption { type = listOf str; description = "Hosts to send E-mails to"; };
601 mail_address = mkOption { type = nullOr str; default = null; description = "E-mail recipient part to send e-mail to"; };
602 mail_domain = mkOption { type = nullOr str; default = null; description = "E-mail domain part to send e-mail to"; };
603 };
604 });
605 };
606 };
607 };
608 };
609 mpd = mkOption {
610 description = "MPD configuration";
611 type = submodule {
612 options = {
613 folder = mkOption { type = str; description = "Folder to serve from the MPD instance"; };
614 password = mkOption { type = str; description = "Password to connect to the MPD instance"; };
615 host = mkOption { type = str; description = "Host to connect to the MPD instance"; };
616 port = mkOption { type = str; description = "Port to connect to the MPD instance"; };
617 };
618 };
619 };
620 ftp = mkOption {
621 description = "FTP configuration";
622 type = submodule {
623 options = {
624 ldap = mkLdapOptions "FTP" {
625 proftpd_filter = mkOption { type = str; description = "Filter for proftpd listing in LDAP"; };
626 pure-ftpd_filter = mkOption { type = str; description = "Filter for pure-ftpd listing in LDAP"; };
627 };
628 };
629 };
630 };
631 vpn = mkOption {
632 description = "VPN configuration";
633 type = attrsOf (submodule {
634 options = {
635 prefix = mkOption { type = str; description = "ipv6 prefix for the vpn subnet"; };
636 privateKey = mkOption { type = str; description = "Private key for the host"; };
637 publicKey = mkOption { type = str; description = "Public key for the host"; };
638 };
639 });
640 };
641 mail = mkOption {
642 description = "Mail configuration";
643 type = submodule {
644 options = {
645 dmarc = mkOption {
646 description = "DMARC configuration";
647 type = submodule {
648 options = {
649 ignore_hosts = mkOption {
650 type = lines;
651 description = ''
652 Hosts to ignore when checking for dmarc
653 '';
654 };
655 };
656 };
657 };
658 dkim = mkOption {
659 description = "DKIM configuration";
660 type = attrsOf (submodule {
661 options = {
662 public = mkOption {
663 type = str;
664 example = ''
665 ( "v=DKIM1; k=rsa; "
666 "p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC3w1a2aMxWw9+hdcmbqX4UevcVqr204y0K73Wdc7MPZiOOlUJQYsMNSYR1Y/SC7jmPKeitpcJCpQgn/cveJZbuikjjPLsDReHyFEYmC278ZLRTELHx6f1IXM8WE08JIRT69CfZiMi1rVcOh9qRT4F93PyjCauU8Y5hJjtg9ThsWwIDAQAB" )
667 '';
668 description = "Public entry to put in DNS TXT field";
669 };
670 private = mkOption { type = str; description = "Private key"; };
671 };
672 });
673 };
674 postfix = mkOption {
675 description = "Postfix configuration";
676 type = submodule {
677 options = {
678 additional_mailbox_domains = mkOption {
679 description = ''
680 List of domains that are used as mailbox final destination, in addition to those defined in the DNS records
681 '';
682 type = listOf str;
683 };
684 mysql = mkMysqlOptions "Postfix" {
685 password_encrypt = mkOption { type = str; description = "Key to encrypt relay password in database"; };
686 };
687 backup_domains = mkOption {
688 description = ''
689 Domains that are accepted for relay as backup domain
690 '';
691 type = attrsOf (submodule {
692 options = {
693 domains = mkOption { type = listOf str; description = "Domains list"; };
694 relay_restrictions = mkOption {
695 type = lines;
696 description = ''
697 Restrictions for relaying the e-mails from the domains
698 '';
699 };
700 recipient_maps = mkOption {
701 description = ''
702 Recipient map to accept relay for.
703 Must be specified for domain, the rules apply to everyone!
704 '';
705 type = listOf (submodule {
706 options = {
707 type = mkOption {
708 type = enum [ "hash" ];
709 description = "Map type";
710 };
711 content = mkOption {
712 type = str;
713 description = "Map content";
714 };
715 };
716 });
717 };
718 };
719 });
720 };
721 };
722 };
723 };
724 dovecot = mkOption {
725 description = "Dovecot configuration";
726 type = submodule {
727 options = {
728 ldap = mkLdapOptions "Dovecot" {
729 pass_attrs = mkOption { type = str; description = "Password attribute in LDAP"; };
730 user_attrs = mkOption { type = str; description = "User attribute mapping in LDAP"; };
731 iterate_attrs = mkOption { type = str; description = "User attribute mapping for listing in LDAP"; };
732 iterate_filter = mkOption { type = str; description = "User attribute filter for listing in LDAP"; };
733 postfix_mailbox_filter = mkOption { type = str; description = "Postfix filter to get mailboxes"; };
734 };
735 };
736 };
737 };
738 rspamd = mkOption {
739 description = "rspamd configuration";
740 type = submodule {
741 options = {
742 redis = mkRedisOptions "Redis";
743 read_password_hashed = mkOption { type = str; description = "Hashed read password for rspamd"; };
744 write_password_hashed = mkOption { type = str; description = "Hashed write password for rspamd"; };
745 read_password = mkOption {
746 type = str;
747 description = "Read password for rspamd. Unused";
748 apply = x: "";
749 };
750 write_password = mkOption {
751 type = str;
752 description = "Write password for rspamd. Unused";
753 apply = x: "";
754 };
755 };
756 };
757 };
758 scripts = mkOption {
759 description = "Mail script recipients";
760 type = attrsOf (submodule {
761 options = {
762 external = mkEnableOption "Create a script_<name>@mail.immae.eu external address";
763 src = mkOption {
764 description = ''
765 git source to fetch the script from.
766 It must have a default.nix file as its root accepting a scriptEnv parameter
767 '';
768 type = submodule {
769 options = {
770 url = mkOption { type = str; description = "git url to fetch"; };
771 rev = mkOption { type = str; description = "git reference to fetch"; };
772 };
773 };
774 };
775 env = mkOption {
776 description = "Variables to pass to the script";
777 type = unspecified;
778 };
779 };
780 });
781 };
782 sympa = mkOption {
783 description = "Sympa configuration";
784 type = submodule {
785 options = {
786 listmasters = mkOption {
787 type = listOf str;
788 description = "Listmasters";
789 };
790 postgresql = mkPsqlOptions "Sympa";
791 data_sources = mkOption {
792 type = attrsOf str;
793 default = {};
794 description = "Data sources to make available to sympa";
795 };
796 scenari = mkOption {
797 type = attrsOf str;
798 default = {};
799 description = "Scenari to make available to sympa";
800 };
801 };
802 };
803 };
804 };
805 };
806 };
807 coturn = mkOption {
808 description = "Coturn configuration";
809 type = submodule {
810 options = {
811 auth_access_key = mkOption { type = str; description = "key to access coturn"; };
812 };
813 };
814 };
815 buildbot = mkOption {
816 description = "Buildbot configuration";
817 type = submodule {
818 options = {
819 ssh_key = mkOption {
820 description = "SSH key information";
821 type = submodule {
822 options = {
823 public = mkOption { type = str; description = "Public part of the key"; };
824 private = mkOption { type = lines; description = "Private part of the key"; };
825 };
826 };
827 };
828 workerPassword = mkOption { description = "Buildbot worker password"; type = str; };
829 user = mkOption {
830 description = "Buildbot user";
831 type = submodule {
832 options = {
833 uid = mkOption {
834 description = "user uid";
835 type = int;
836 };
837 gid = mkOption {
838 description = "user gid";
839 type = int;
840 };
841 };
842 };
843 };
844 ldap = mkOption {
845 description = "Ldap configuration for buildbot";
846 type = submodule {
847 options = {
848 password = mkOption { type = str; description = "Buildbot password"; };
849 };
850 };
851 };
852 projects = mkOption {
853 description = "Projects to make a buildbot for";
854 type = attrsOf (submodule {
855 options = {
856 name = mkOption { type = str; description = "Project name"; };
857 packages = mkOption {
858 type = unspecified;
859 example = literalExample ''
860 pkgs: [ pkgs.bash pkgs.git pkgs.gzip pkgs.openssh ];
861 '';
862 description = ''
863 Function.
864 Builds packages list to make available to buildbot project.
865 Takes pkgs as argument.
866 '';
867 };
868 pythonPackages = mkOption {
869 type = unspecified;
870 example = literalExample ''
871 p: pkgs: [ pkgs.python3Packages.pip ];
872 '';
873 description = ''
874 Function.
875 Builds python packages list to make available to buildbot project.
876 Takes buildbot python module as first argument and pkgs as second argument in order to augment the python modules list.
877 '';
878 };
879 pythonPathHome = mkOption { type = bool; description = "Whether to add project’s python home to python path"; };
880 workerPort = mkOption { type = port; description = "Port for the worker"; };
881 secrets = mkOption {
882 #type = attrsOf (either str (functionTo str));
883 type = attrsOf unspecified;
884 description = "Secrets for the project to dump as files. Might be a function that takes pkgs as argument";
885 };
886 environment = mkOption {
887 #type = attrsOf (either str (functionTo str));
888 type = attrsOf unspecified;
889 description = ''
890 Environment variables for the project. Might be a function that takes pkgs as argument.
891 BUILDBOT_ is prefixed to the variable names
892 '';
893 };
894 activationScript = mkOption {
895 type = lines;
896 description = ''
897 Activation script to run during deployment
898 '';
899 };
900 builderPaths = mkOption {
901 type = attrsOf unspecified;
902 default = {};
903 description = ''
904 Attrs of functions to make accessible specifically per builder.
905 Takes pkgs as argument and should return a single path containing binaries.
906 This path will be accessible as BUILDBOT_PATH_<attrskey>
907 '';
908 };
909 webhookTokens = mkOption {
910 type = nullOr (listOf str);
911 default = null;
912 description = ''
913 List of tokens allowed to push to project’s change_hook/base endpoint
914 '';
915 };
916 };
917 });
918 };
919 };
920 };
921 };
922 tools = mkOption {
923 description = "Tools configurations";
924 type = submodule {
925 options = {
926 contact = mkOption { type = str; description = "Contact e-mail address"; };
927 assets = mkOption {
928 default = {};
929 type = attrsOf (submodule {
930 options = {
931 url = mkOption { type = str; description = "URL to fetch"; };
932 sha256 = mkOption { type = str; description = "Hash of the url"; };
933 };
934 });
935 description = "Assets to provide on assets.immae.eu";
936 };
937 davical = mkOption {
938 description = "Davical configuration";
939 type = submodule {
940 options = {
941 postgresql = mkPsqlOptions "Davical";
942 ldap = mkLdapOptions "Davical" {};
943 };
944 };
945 };
946 diaspora = mkOption {
947 description = "Diaspora configuration";
948 type = submodule {
949 options = {
950 postgresql = mkPsqlOptions "Diaspora";
951 redis = mkRedisOptions "Diaspora";
952 ldap = mkLdapOptions "Diaspora" {};
953 secret_token = mkOption { type = str; description = "Secret token"; };
954 };
955 };
956 };
957 dmarc_reports = mkOption {
958 description = "DMARC reports configuration";
959 type = submodule {
960 options = {
961 mysql = mkMysqlOptions "DMARC" {};
962 anonymous_key = mkOption { type = str; description = "Anonymous hashing key"; };
963 };
964 };
965 };
966 etherpad-lite = mkOption {
967 description = "Etherpad configuration";
968 type = submodule {
969 options = {
970 postgresql = mkPsqlOptions "Etherpad";
971 ldap = mkLdapOptions "Etherpad" {
972 group_filter = mkOption { type = str; description = "Filter for groups"; };
973 };
974 adminPassword = mkOption { type = str; description = "Admin password for mypads / admin"; };
975 session_key = mkOption { type = str; description = "Session key"; };
976 api_key = mkOption { type = str; description = "API key"; };
977 redirects = mkOption { type = str; description = "Redirects for apache"; };
978 };
979 };
980 };
981 gitolite = mkOption {
982 description = "Gitolite configuration";
983 type = submodule {
984 options = {
985 ldap = mkLdapOptions "Gitolite" {};
986 ssh_key = mkOption {
987 description = "SSH key information";
988 type = submodule {
989 options = {
990 public = mkOption { type = str; description = "Public part of the key"; };
991 private = mkOption { type = lines; description = "Private part of the key"; };
992 };
993 };
994 };
995 };
996 };
997 };
998 kanboard = mkOption {
999 description = "Kanboard configuration";
1000 type = submodule {
1001 options = {
1002 postgresql = mkPsqlOptions "Kanboard";
1003 ldap = mkLdapOptions "Kanboard" {
1004 admin_dn = mkOption { type = str; description = "Admin DN"; };
1005 };
1006 };
1007 };
1008 };
1009 mantisbt = mkOption {
1010 description = "Mantisbt configuration";
1011 type = submodule {
1012 options = {
1013 postgresql = mkPsqlOptions "Mantisbt";
1014 ldap = mkLdapOptions "Mantisbt" {};
1015 master_salt = mkOption { type = str; description = "Master salt for password hash"; };
1016 };
1017 };
1018 };
1019 mastodon = mkOption {
1020 description = "Mastodon configuration";
1021 type = submodule {
1022 options = {
1023 postgresql = mkPsqlOptions "Mastodon";
1024 redis = mkRedisOptions "Mastodon";
1025 ldap = mkLdapOptions "Mastodon" {};
1026 paperclip_secret = mkOption { type = str; description = "Paperclip secret"; };
1027 otp_secret = mkOption { type = str; description = "OTP secret"; };
1028 secret_key_base = mkOption { type = str; description = "Secret key base"; };
1029 vapid = mkOption {
1030 description = "vapid key";
1031 type = submodule {
1032 options = {
1033 private = mkOption { type = str; description = "Private key"; };
1034 public = mkOption { type = str; description = "Public key"; };
1035 };
1036 };
1037 };
1038 };
1039 };
1040 };
1041 mediagoblin = mkOption {
1042 description = "Mediagoblin configuration";
1043 type = submodule {
1044 options = {
1045 postgresql = mkPsqlOptions "Mediagoblin";
1046 redis = mkRedisOptions "Mediagoblin";
1047 ldap = mkLdapOptions "Mediagoblin" {};
1048 };
1049 };
1050 };
1051 nextcloud = mkOption {
1052 description = "Nextcloud configuration";
1053 type = submodule {
1054 options = {
1055 postgresql = mkPsqlOptions "Peertube";
1056 redis = mkRedisOptions "Peertube";
1057 password_salt = mkOption { type = str; description = "Password salt"; };
1058 instance_id = mkOption { type = str; description = "Instance ID"; };
1059 secret = mkOption { type = str; description = "App secret"; };
1060 };
1061 };
1062 };
1063 peertube = mkOption {
1064 description = "Peertube configuration";
1065 type = submodule {
1066 options = {
1067 listenPort = mkOption { type = port; description = "Port to listen to"; };
1068 postgresql = mkPsqlOptions "Peertube";
1069 redis = mkRedisOptions "Peertube";
1070 ldap = mkLdapOptions "Peertube" {};
1071 };
1072 };
1073 };
1074 syden_peertube = mkOption {
1075 description = "Peertube Syden configuration";
1076 type = submodule {
1077 options = {
1078 listenPort = mkOption { type = port; description = "Port to listen to"; };
1079 postgresql = mkPsqlOptions "Peertube";
1080 redis = mkRedisOptions "Peertube";
1081 };
1082 };
1083 };
1084 phpldapadmin = mkOption {
1085 description = "phpLdapAdmin configuration";
1086 type = submodule {
1087 options = {
1088 ldap = mkLdapOptions "phpldapadmin" {};
1089 };
1090 };
1091 };
1092 rompr = mkOption {
1093 description = "Rompr configuration";
1094 type = submodule {
1095 options = {
1096 mpd = mkOption {
1097 description = "MPD configuration";
1098 type = submodule {
1099 options = {
1100 host = mkOption { type = str; description = "Host for MPD"; };
1101 port = mkOption { type = port; description = "Port to access MPD host"; };
1102 };
1103 };
1104 };
1105 };
1106 };
1107 };
1108 roundcubemail = mkOption {
1109 description = "Roundcubemail configuration";
1110 type = submodule {
1111 options = {
1112 postgresql = mkPsqlOptions "TT-RSS";
1113 secret = mkOption { type = str; description = "Secret"; };
1114 };
1115 };
1116 };
1117 shaarli = mkOption {
1118 description = "Shaarli configuration";
1119 type = submodule {
1120 options = {
1121 ldap = mkLdapOptions "Shaarli" {};
1122 };
1123 };
1124 };
1125 status_engine = mkOption {
1126 description = "Status Engine configuration";
1127 type = submodule {
1128 options = {
1129 mysql = mkMysqlOptions "StatusEngine" {};
1130 ldap = mkLdapOptions "StatusEngine" {};
1131 };
1132 };
1133 };
1134 task = mkOption {
1135 description = "Taskwarrior configuration";
1136 type = submodule {
1137 options = {
1138 ldap = mkLdapOptions "Taskwarrior" {};
1139 taskwarrior-web = mkOption {
1140 description = "taskwarrior-web profiles";
1141 type = attrsOf (submodule {
1142 options = {
1143 uid = mkOption {
1144 type = listOf str;
1145 description = "List of ldap uids having access to this profile";
1146 };
1147 org = mkOption { type = str; description = "Taskd organisation"; };
1148 key = mkOption { type = str; description = "Taskd key"; };
1149 date = mkOption { type = str; description = "Preferred date format"; };
1150 };
1151 });
1152 };
1153 };
1154 };
1155 };
1156 ttrss = mkOption {
1157 description = "TT-RSS configuration";
1158 type = submodule {
1159 options = {
1160 postgresql = mkPsqlOptions "TT-RSS";
1161 ldap = mkLdapOptions "TT-RSS" {};
1162 };
1163 };
1164 };
1165 wallabag = mkOption {
1166 description = "Wallabag configuration";
1167 type = submodule {
1168 options = {
1169 postgresql = mkPsqlOptions "Wallabag";
1170 ldap = mkLdapOptions "Wallabag" {
1171 admin_filter = mkOption { type = str; description = "Admin users filter"; };
1172 };
1173 redis = mkRedisOptions "Wallabag";
1174 secret = mkOption { type = str; description = "App secret"; };
1175 };
1176 };
1177 };
1178 webhooks = mkOption {
1179 type = attrsOf str;
1180 description = "Mapping 'name'.php => script for webhooks";
1181 };
1182 csp_reports = mkOption {
1183 description = "CSP report configuration";
1184 type = submodule {
1185 options = {
1186 report_uri = mkOption { type = str; description = "URI to report CSP violations to"; };
1187 policies = mkOption { type = attrsOf str; description = "CSP policies to apply"; };
1188 postgresql = mkPsqlOptions "CSP reports";
1189 };
1190 };
1191 };
1192 commento = mkOption {
1193 description = "Commento configuration";
1194 type = submodule {
1195 options = {
1196 listenPort = mkOption { type = port; description = "Port to listen to"; };
1197 postgresql = mkPsqlOptions "Commento";
1198 smtp = mkSmtpOptions "Commento";
1199 };
1200 };
1201 };
1202 cryptpad = mkOption {
1203 description = "Cryptpad configuration";
1204 type = attrsOf (submodule {
1205 options = {
1206 email = mkOption { type = str; description = "Admin e-mail"; };
1207 admins = mkOption { type = listOf str; description = "Instance admin public keys"; };
1208 port = mkOption { type = port; description = "Port to listen to"; };
1209 };
1210 });
1211 };
1212 ympd = mkOption {
1213 description = "Ympd configuration";
1214 type = submodule {
1215 options = {
1216 listenPort = mkOption { type = port; description = "Port to listen to"; };
1217 mpd = mkOption {
1218 description = "MPD configuration";
1219 type = submodule {
1220 options = {
1221 password = mkOption { type = str; description = "Password to access MPD host"; };
1222 host = mkOption { type = str; description = "Host for MPD"; };
1223 port = mkOption { type = port; description = "Port to access MPD host"; };
1224 };
1225 };
1226 };
1227 };
1228 };
1229 };
1230 umami = mkOption {
1231 description = "Umami configuration";
1232 type = submodule {
1233 options = {
1234 listenPort = mkOption { type = port; description = "Port to listen to"; };
1235 postgresql = mkPsqlOptions "Umami";
1236 hashSalt = mkOption { type = str; description = "Hash salt"; };
1237 };
1238 };
1239 };
1240 yourls = mkOption {
1241 description = "Yourls configuration";
1242 type = submodule {
1243 options = {
1244 mysql = mkMysqlOptions "Yourls" {};
1245 ldap = mkLdapOptions "Yourls" {};
1246 cookieKey = mkOption { type = str; description = "Cookie key"; };
1247 };
1248 };
1249 };
1250 };
1251 };
1252 };
1253 serverSpecific = mkOption { type = attrsOf unspecified; description = "Server specific configuration"; };
1254 websites = mkOption {
1255 description = "Websites configurations";
1256 type = submodule {
1257 options = {
1258 christophe_carpentier = mkOption {
1259 description = "Christophe Carpentier configuration by environment";
1260 type = submodule {
1261 options = {
1262 agorakit = mkOption {
1263 description = "Agorakit configuration";
1264 type = submodule {
1265 options = {
1266 mysql = mkMysqlOptions "Agorakit" {};
1267 smtp = mkSmtpOptions "Agorakit";
1268 appkey = mkOption { type = str; description = "App key"; };
1269 };
1270 };
1271 };
1272 };
1273 };
1274 };
1275 immae = mkOption {
1276 description = "Immae configuration by environment";
1277 type = submodule {
1278 options = {
1279 temp = mkOption {
1280 description = "Temp configuration";
1281 type = submodule {
1282 options = {
1283 ldap = mkLdapOptions "Immae temp" {
1284 filter = mkOption { type = str; description = "Filter for user access"; };
1285 };
1286 };
1287 };
1288 };
1289 };
1290 };
1291 };
1292 isabelle = mkOption {
1293 description = "Isabelle configurations by environment";
1294 type =
1295 let
1296 atenSubmodule = mkOption {
1297 description = "environment configuration";
1298 type = submodule {
1299 options = {
1300 environment = mkOption { type = str; description = "Symfony environment"; };
1301 secret = mkOption { type = str; description = "Symfony App secret"; };
1302 postgresql = mkPsqlOptions "Aten";
1303 };
1304 };
1305 };
1306 in
1307 submodule {
1308 options = {
1309 aten_production = atenSubmodule;
1310 aten_integration = atenSubmodule;
1311 iridologie = mkOption {
1312 description = "environment configuration";
1313 type = submodule {
1314 options = {
1315 environment = mkOption { type = str; description = "SPIP environment"; };
1316 mysql = mkMysqlOptions "Iridologie" {};
1317 ldap = mkLdapOptions "Iridologie" {};
1318 };
1319 };
1320 };
1321 };
1322 };
1323 };
1324 chloe = mkOption {
1325 description = "Chloe configurations by environment";
1326 type =
1327 let
1328 chloeSubmodule = mkOption {
1329 description = "environment configuration";
1330 type = submodule {
1331 options = {
1332 environment = mkOption { type = str; description = "SPIP environment"; };
1333 mysql = mkMysqlOptions "Chloe" {};
1334 ldap = mkLdapOptions "Chloe" {};
1335 };
1336 };
1337 };
1338 in
1339 submodule {
1340 options = {
1341 production = chloeSubmodule;
1342 integration = chloeSubmodule;
1343 new = mkOption {
1344 description = "environment configuration";
1345 type = submodule {
1346 options = {
1347 mysql = mkMysqlOptions "ChloeNew" {};
1348 ldap = mkLdapOptions "ChloeNew" {};
1349 secret = mkOption { type = str; description = "Symfony App secret"; };
1350 };
1351 };
1352 };
1353 };
1354 };
1355 };
1356 connexionswing = mkOption {
1357 description = "Connexionswing configurations by environment";
1358 type =
1359 let
1360 csSubmodule = mkOption {
1361 description = "environment configuration";
1362 type = submodule {
1363 options = {
1364 environment = mkOption { type = str; description = "Symfony environment"; };
1365 mysql = mkMysqlOptions "Connexionswing" {};
1366 secret = mkOption { type = str; description = "Symfony App secret"; };
1367 email = mkOption { type = str; description = "Symfony email notification"; };
1368 };
1369 };
1370 };
1371 in
1372 submodule {
1373 options = {
1374 production = csSubmodule;
1375 integration = csSubmodule;
1376 };
1377 };
1378 };
1379 jerome = mkOption {
1380 description = "Naturaloutil configuration";
1381 type = submodule {
1382 options = {
1383 mysql = mkMysqlOptions "Naturaloutil" {};
1384 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1385 };
1386 };
1387 };
1388 telio_tortay = mkOption {
1389 description = "Telio Tortay configuration";
1390 type = submodule {
1391 options = {
1392 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1393 };
1394 };
1395 };
1396 ludivine = mkOption {
1397 description = "Ludivinecassal configurations by environment";
1398 type =
1399 let
1400 lcSubmodule = mkOption {
1401 description = "environment configuration";
1402 type = submodule {
1403 options = {
1404 environment = mkOption { type = str; description = "Symfony environment"; };
1405 mysql = mkMysqlOptions "LudivineCassal" {};
1406 ldap = mkLdapOptions "LudivineCassal" {};
1407 secret = mkOption { type = str; description = "Symfony App secret"; };
1408 };
1409 };
1410 };
1411 in
1412 submodule {
1413 options = {
1414 production = lcSubmodule;
1415 integration = lcSubmodule;
1416 };
1417 };
1418 };
1419 nicecoop = mkOption {
1420 description = "Nicecoop configuration";
1421 type = submodule {
1422 options = {
1423 odoo = {
1424 port = mkOption { description = "Port to listen to"; type = port; };
1425 longpoll_port = mkOption { description = "Port to listen to"; type = port; };
1426 postgresql = mkPsqlOptions "Odoo";
1427 admin_password = mkOption { type = str; description = "Admin password"; };
1428 };
1429 gestion-compte = {
1430 smtp = mkSmtpOptions "GestionCompte";
1431 mysql = mkMysqlOptions "gestion-compte" {};
1432 secret = mkOption { type = str; description = "Application secret"; };
1433 adminpassword = mkOption { type = str; description = "Admin password"; };
1434 };
1435 gestion-compte-integration = {
1436 smtp = mkSmtpOptions "GestionCompte";
1437 mysql = mkMysqlOptions "gestion-compte" {};
1438 secret = mkOption { type = str; description = "Application secret"; };
1439 adminpassword = mkOption { type = str; description = "Admin password"; };
1440 };
1441 copanier = {
1442 smtp = mkSmtpOptions "Copanier";
1443 staff = mkOption { type = listOf str; description = "List of staff members"; };
1444 };
1445 };
1446 };
1447 };
1448 emilia = mkOption {
1449 description = "Emilia configuration";
1450 type = submodule {
1451 options = {
1452 postgresql = mkPsqlOptions "Emilia";
1453 };
1454 };
1455 };
1456 florian = mkOption {
1457 description = "Florian configuration";
1458 type = submodule {
1459 options = {
1460 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1461 };
1462 };
1463 };
1464 nassime = mkOption {
1465 description = "Nassime configuration";
1466 type = submodule {
1467 options = {
1468 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1469 };
1470 };
1471 };
1472 piedsjaloux = mkOption {
1473 description = "Piedsjaloux configurations by environment";
1474 type =
1475 let
1476 pjSubmodule = mkOption {
1477 description = "environment configuration";
1478 type = submodule {
1479 options = {
1480 environment = mkOption { type = str; description = "Symfony environment"; };
1481 mysql = mkMysqlOptions "Piedsjaloux" {};
1482 secret = mkOption { type = str; description = "Symfony App secret"; };
1483 };
1484 };
1485 };
1486 in
1487 submodule {
1488 options = {
1489 production = pjSubmodule;
1490 integration = pjSubmodule;
1491 };
1492 };
1493 };
1494 richie = mkOption {
1495 description = "Europe Richie configurations by environment";
1496 type = submodule {
1497 options = {
1498 mysql = mkMysqlOptions "Richie" {};
1499 smtp_mailer = mkOption {
1500 description = "SMTP mailer configuration";
1501 type = submodule {
1502 options = {
1503 user = mkOption { type = str; description = "Username"; };
1504 password = mkOption { type = str; description = "Password"; };
1505 };
1506 };
1507 };
1508 };
1509 };
1510 };
1511 caldance = mkOption {
1512 description = "Caldance configurations by environment";
1513 type = submodule {
1514 options = {
1515 integration = mkOption {
1516 description = "environment configuration";
1517 type = submodule {
1518 options = {
1519 password = mkOption { type = str; description = "Password file content for basic auth"; };
1520 };
1521 };
1522 };
1523 };
1524 };
1525 };
1526 tellesflorian = mkOption {
1527 description = "Tellesflorian configurations by environment";
1528 type =
1529 let
1530 tfSubmodule = mkOption {
1531 description = "environment configuration";
1532 type = submodule {
1533 options = {
1534 environment = mkOption { type = str; description = "Symfony environment"; };
1535 mysql = mkMysqlOptions "Tellesflorian" {};
1536 secret = mkOption { type = str; description = "Symfony App secret"; };
1537 invite_passwords = mkOption { type = str; description = "Password basic auth"; };
1538 };
1539 };
1540 };
1541 in
1542 submodule {
1543 options = {
1544 integration = tfSubmodule;
1545 };
1546 };
1547 };
1548 };
1549 };
1550 };
1551 };
1552 options.hostEnv = mkOption {
1553 readOnly = true;
1554 type = hostEnv;
1555 default = config.myEnv.servers."${name}";
1556 description = "Host environment";
1557 };
1558 }