1 { config, lib, name, ... }:
7 base = mkOption { description = "Base of the LDAP tree"; type = str; };
8 host = mkOption { description = "Host to access LDAP"; type = str; };
9 root_dn = mkOption { description = "DN of the root user"; type = str; };
10 root_pw = mkOption { description = "Hashed password of the root user"; type = str; };
11 replication_dn = mkOption { description = "DN of the user allowed to replicate the LDAP directory"; type = str; };
12 replication_pw = mkOption { description = "Password of the user allowed to replicate the LDAP directory"; type = str; };
14 mkLdapOptions = name: more: mkOption {
15 description = "${name} LDAP configuration";
17 options = ldapOptions // {
18 dn = mkOption { description = "DN of the ${name} user"; type = str; };
19 password = mkOption { description = "password of the ${name} user"; type = str; };
20 filter = mkOption { description = "Filter for ${name} users"; type = str; default = ""; };
25 host = mkOption { description = "Host to access Mysql"; type = str; };
26 remoteHost = mkOption { description = "Host to access Mysql from outside"; type = str; };
27 port = mkOption { description = "Port to access Mysql"; type = str; };
28 socket = mkOption { description = "Socket to access Mysql"; type = path; };
29 systemUsers = mkOption {
30 description = "Attrs of user-passwords allowed to access mysql";
34 description = "PAM configuration for mysql";
37 dn = mkOption { description = "DN to connect as to check users"; type = str; };
38 password = mkOption { description = "DN password to connect as to check users"; type = str; };
39 filter = mkOption { description = "filter to match users"; type = str; };
44 mkMysqlOptions = name: more: mkOption {
45 description = "${name} mysql configuration";
47 options = mysqlOptions // {
48 database = mkOption { description = "${name} database"; type = str; };
49 user = mkOption { description = "${name} user"; type = str; };
50 password = mkOption { description = "mysql password of the ${name} user"; type = str; };
55 host = mkOption { description = "Host to access Postgresql"; type = str; };
56 port = mkOption { description = "Port to access Postgresql"; type = str; };
57 socket = mkOption { description = "Socket to access Postgresql"; type = path; };
59 description = "PAM configuration for psql";
62 dn = mkOption { description = "DN to connect as to check users"; type = str; };
63 password = mkOption { description = "DN password to connect as to check users"; type = str; };
64 filter = mkOption { description = "filter to match users"; type = str; };
69 mkPsqlOptions = name: mkOption {
70 description = "${name} psql configuration";
72 options = psqlOptions // {
73 database = mkOption { description = "${name} database"; type = str; };
74 schema = mkOption { description = "${name} schema"; type = nullOr str; default = null; };
75 user = mkOption { description = "${name} user"; type = str; };
76 password = mkOption { description = "psql password of the ${name} user"; type = str; };
81 host = mkOption { description = "Host to access Redis"; type = str; };
82 port = mkOption { description = "Port to access Redis"; type = str; };
83 socket = mkOption { description = "Socket to access Redis"; type = path; };
85 description = "Attrs of db number. Each number should be unique to avoid collision!";
88 spiped_key = mkOption {
91 Key to use with spiped to make a secure channel to replication
95 description = "Predixy configuration. Unused yet";
98 read = mkOption { type = str; description = "Read password"; };
103 mkRedisOptions = name: mkOption {
104 description = "${name} redis configuration";
106 options = redisOptions // {
107 db = mkOption { description = "${name} database"; type = str; };
112 host = mkOption { description = "Host to access SMTP"; type = str; };
113 port = mkOption { description = "Port to access SMTP"; type = str; };
115 mkSmtpOptions = name: mkOption {
116 description = "${name} smtp configuration";
118 options = smtpOptions // {
119 email = mkOption { description = "${name} email"; type = str; };
120 password = mkOption { description = "SMTP password of the ${name} user"; type = str; };
124 hostEnv = submodule {
127 description = "Host FQDN";
134 Sublist of users from realUsers. Function that takes pkgs as
135 argument and gives an array as a result
140 description = "List of e-mails that the server can be a sender of";
145 LDAP credentials for the host
149 password = mkOption { type = str; description = "Password for the LDAP connection"; };
150 dn = mkOption { type = str; description = "DN for the LDAP connection"; };
155 description = "subdomain and priority for MX server";
156 default = { enable = false; };
159 enable = mkEnableOption "Enable MX";
160 subdomain = mkOption { type = nullOr str; description = "Subdomain name (mx-*)"; };
161 priority = mkOption { type = nullOr str; description = "Priority"; };
167 attrs of ip4/ip6 grouped by section
169 type = attrsOf (submodule {
174 ip4 address of the host
181 ip6 addresses of the host
194 Attrs of servers information in the cluster (not necessarily handled by nixops)
197 type = attrsOf hostEnv;
199 hetznerCloud = mkOption {
201 Hetzner Cloud credential information
205 authToken = mkOption {
216 Hetzner credential information
220 user = mkOption { type = str; description = "User"; };
221 pass = mkOption { type = str; description = "Password"; };
227 sshd service credential information
233 LDAP credentials for cn=ssh,ou=services,dc=immae,dc=eu dn
237 password = mkOption { description = "Password"; type = str; };
246 non-standard reserved ports. Must be unique!
251 noDupl = x: builtins.length (builtins.attrValues x) == builtins.length (unique (builtins.attrValues x));
253 x: if isAttrs x && noDupl x then x else throw "Non unique values for ports";
257 httpd service credential information
263 LDAP credentials for cn=httpd,ou=services,dc=immae,dc=eu dn
267 password = mkOption { description = "Password"; type = str; };
275 type = submodule { options = smtpOptions; };
276 description = "SMTP configuration";
280 LDAP server configuration
283 options = ldapOptions;
286 databases = mkOption {
287 description = "Databases configuration";
291 type = submodule { options = mysqlOptions; };
292 description = "Mysql configuration";
295 type = submodule { options = redisOptions; };
296 description = "Redis configuration";
298 postgresql = mkOption {
299 type = submodule { options = psqlOptions; };
300 description = "Postgresql configuration";
306 description = "Jabber configuration";
309 postfix_user_filter = mkOption { type = str; description = "Postfix filter to get xmpp users"; };
310 ldap = mkLdapOptions "Jabber" {};
311 postgresql = mkPsqlOptions "Jabber";
315 realUsers = mkOption {
317 Attrset of function taking pkgs as argument.
318 Real users settings, should provide a subattr of users.users.<name>
319 with at least: name, (hashed)Password, shell
321 type = attrsOf unspecified;
324 description = "System and regular users uid/gid";
325 type = attrsOf (submodule {
328 description = "user uid";
332 description = "user gid";
339 description = "DNS configuration";
343 description = "SOA information";
347 description = "Serial number. Should be incremented at each change and unique";
351 description = "Refresh time";
355 description = "Retry time";
359 description = "Expire time";
363 description = "Default TTL time";
367 description = "hostmaster e-mail";
371 description = "Primary NS";
378 description = "Attrs of NS servers group";
381 "ns1.foo.com" = [ "198.51.100.10" "2001:db8:abcd::1" ];
382 "ns2.foo.com" = [ "198.51.100.15" "2001:db8:1234::1" ];
385 type = attrsOf (attrsOf (listOf str));
389 description = "DNS keys";
390 type = attrsOf (submodule {
392 algorithm = mkOption { type = str; description = "Algorithm"; };
393 secret = mkOption { type = str; description = "Secret"; };
397 slaveZones = mkOption {
398 description = "List of slave zones";
399 type = listOf (submodule {
401 name = mkOption { type = str; description = "zone name"; };
403 description = "NS master groups of this zone";
408 description = "Keys associated to the server";
414 masterZones = mkOption {
415 description = "List of master zones";
416 type = listOf (submodule {
418 name = mkOption { type = str; description = "zone name"; };
419 withCAA = mkOption { type = nullOr str; description = "CAA entry"; default = null; };
421 description = "NS slave groups of this zone";
425 description = "groups names that should have their NS entries listed here";
429 description = "Extra zone configuration for bind";
435 entries = mkOption { type = lines; description = "Regular entries of the NS zone"; };
436 withEmail = mkOption {
437 description = "List of domains that should have mail entries (MX, dkim, SPF, ...)";
439 type = listOf (submodule {
441 domain = mkOption { type = str; description = "Which subdomain is concerned"; };
442 send = mkOption { type = bool; description = "Whether there can be e-mails originating from the subdomain"; };
443 receive = mkOption { type = bool; description = "Whether there can be e-mails arriving to the subdomain"; };
455 Remote backup with duplicity
459 password = mkOption { type = str; description = "Password for encrypting files"; };
461 type = attrsOf (submodule {
465 example = literalExample ''
466 bucket: "s3://some_host/${bucket}";
470 Takes a bucket name as argument and returns a url
473 accessKeyId = mkOption { type = str; description = "Remote access-key"; };
474 secretAccessKey = mkOption { type = str; description = "Remote access secret"; };
481 zrepl_backup = mkOption {
485 description = "SSH key information";
488 public = mkOption { type = str; description = "Public part of the key"; };
489 private = mkOption { type = lines; description = "Private part of the key"; };
493 mysql = mkMysqlOptions "Zrepl" {};
497 rsync_backup = mkOption {
499 Rsync backup configuration from controlled host
504 description = "SSH key information";
507 public = mkOption { type = str; description = "Public part of the key"; };
508 private = mkOption { type = lines; description = "Private part of the key"; };
512 profiles = mkOption {
513 description = "Attrs of profiles to backup";
514 type = attrsOf (submodule {
516 keep = mkOption { type = int; description = "Number of backups to keep"; };
517 check_command = mkOption { type = str; description = "command to check if backup needs to be done"; default = "backup"; };
518 login = mkOption { type = str; description = "Login to connect to host"; };
519 port = mkOption { type = str; default = "22"; description = "Port to connect to host"; };
520 host = mkOption { type = str; description = "Host to connect to"; };
521 host_key = mkOption { type = str; description = "Host key"; };
522 host_key_type = mkOption { type = str; description = "Host key type"; };
524 description = "Parts to backup for this host";
525 type = attrsOf (submodule {
527 remote_folder = mkOption { type = path; description = "Remote folder to backup";};
528 exclude_from = mkOption {
531 description = "List of folders/files to exclude from the backup";
533 files_from = mkOption {
536 description = "List of folders/files to backup in the base folder";
541 description = "Extra arguments to pass to rsync";
552 monitoring = mkOption {
553 description = "Monitoring configuration";
556 status_url = mkOption { type = str; description = "URL to push status to"; };
557 status_token = mkOption { type = str; description = "Token for the status url"; };
558 http_user_password = mkOption { type = str; description = "HTTP credentials to check services behind wall"; };
559 email = mkOption { type = str; description = "Admin E-mail"; };
560 ssh_public_key = mkOption { type = str; description = "SSH public key"; };
561 ssh_secret_key = mkOption { type = str; description = "SSH secret key"; };
562 imap_login = mkOption { type = str; description = "IMAP login"; };
563 imap_password = mkOption { type = str; description = "IMAP password"; };
564 eriomem_keys = mkOption { type = listOf (listOf str); description = "Eriomem keys"; default = []; };
566 description = "OVH credentials for sms script";
569 endpoint = mkOption { type = str; default = "ovh-eu"; description = "OVH endpoint"; };
570 application_key = mkOption { type = str; description = "Application key"; };
571 application_secret = mkOption { type = str; description = "Application secret"; };
572 consumer_key = mkOption { type = str; description = "Consumer key"; };
573 account = mkOption { type = str; description = "Account"; };
578 description = "Eban credentials for webhook";
581 user = mkOption { type = str; description = "User"; };
582 password = mkOption { type = str; description = "Password"; };
586 nrdp_tokens = mkOption { type = listOf str; description = "Tokens allowed to push status update"; };
587 slack_url = mkOption { type = str; description = "Slack webhook url to push status update"; };
588 slack_channel = mkOption { type = str; description = "Slack channel to push status update"; };
589 netdata_aggregator = mkOption { type = str; description = "Url where netdata information should be sent"; };
590 netdata_keys = mkOption { type = attrsOf str; description = "netdata host keys"; };
591 contacts = mkOption { type = attrsOf unspecified; description = "Contact dicts to fill naemon objects"; };
592 email_check = mkOption {
593 description = "Emails services to check";
594 type = attrsOf (submodule {
596 local = mkOption { type = bool; default = false; description = "Use local configuration"; };
597 port = mkOption { type = nullOr str; default = null; description = "Port to connect to ssh"; };
598 login = mkOption { type = nullOr str; default = null; description = "Login to connect to ssh"; };
599 targets = mkOption { type = listOf str; description = "Hosts to send E-mails to"; };
600 mail_address = mkOption { type = nullOr str; default = null; description = "E-mail recipient part to send e-mail to"; };
601 mail_domain = mkOption { type = nullOr str; default = null; description = "E-mail domain part to send e-mail to"; };
609 description = "MPD configuration";
612 folder = mkOption { type = str; description = "Folder to serve from the MPD instance"; };
613 password = mkOption { type = str; description = "Password to connect to the MPD instance"; };
614 host = mkOption { type = str; description = "Host to connect to the MPD instance"; };
615 port = mkOption { type = str; description = "Port to connect to the MPD instance"; };
620 description = "FTP configuration";
623 ldap = mkLdapOptions "FTP" {};
628 description = "VPN configuration";
629 type = attrsOf (submodule {
631 prefix = mkOption { type = str; description = "ipv6 prefix for the vpn subnet"; };
632 privateKey = mkOption { type = str; description = "Private key for the host"; };
633 publicKey = mkOption { type = str; description = "Public key for the host"; };
638 description = "Mail configuration";
642 description = "DMARC configuration";
645 ignore_hosts = mkOption {
648 Hosts to ignore when checking for dmarc
655 description = "DKIM configuration";
656 type = attrsOf (submodule {
662 "p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC3w1a2aMxWw9+hdcmbqX4UevcVqr204y0K73Wdc7MPZiOOlUJQYsMNSYR1Y/SC7jmPKeitpcJCpQgn/cveJZbuikjjPLsDReHyFEYmC278ZLRTELHx6f1IXM8WE08JIRT69CfZiMi1rVcOh9qRT4F93PyjCauU8Y5hJjtg9ThsWwIDAQAB" )
664 description = "Public entry to put in DNS TXT field";
666 private = mkOption { type = str; description = "Private key"; };
671 description = "Postfix configuration";
674 additional_mailbox_domains = mkOption {
676 List of domains that are used as mailbox final destination, in addition to those defined in the DNS records
680 mysql = mkMysqlOptions "Postfix" {
681 password_encrypt = mkOption { type = str; description = "Key to encrypt relay password in database"; };
683 backup_domains = mkOption {
685 Domains that are accepted for relay as backup domain
687 type = attrsOf (submodule {
689 domains = mkOption { type = listOf str; description = "Domains list"; };
690 relay_restrictions = mkOption {
693 Restrictions for relaying the e-mails from the domains
696 recipient_maps = mkOption {
698 Recipient map to accept relay for.
699 Must be specified for domain, the rules apply to everyone!
701 type = listOf (submodule {
704 type = enum [ "hash" ];
705 description = "Map type";
709 description = "Map content";
721 description = "Dovecot configuration";
724 ldap = mkLdapOptions "Dovecot" {
725 pass_attrs = mkOption { type = str; description = "Password attribute in LDAP"; };
726 user_attrs = mkOption { type = str; description = "User attribute mapping in LDAP"; };
727 iterate_attrs = mkOption { type = str; description = "User attribute mapping for listing in LDAP"; };
728 iterate_filter = mkOption { type = str; description = "User attribute filter for listing in LDAP"; };
729 postfix_mailbox_filter = mkOption { type = str; description = "Postfix filter to get mailboxes"; };
735 description = "rspamd configuration";
738 redis = mkRedisOptions "Redis";
739 read_password_hashed = mkOption { type = str; description = "Hashed read password for rspamd"; };
740 write_password_hashed = mkOption { type = str; description = "Hashed write password for rspamd"; };
741 read_password = mkOption {
743 description = "Read password for rspamd. Unused";
746 write_password = mkOption {
748 description = "Write password for rspamd. Unused";
755 description = "Mail script recipients";
756 type = attrsOf (submodule {
758 external = mkEnableOption "Create a script_<name>@mail.immae.eu external address";
761 git source to fetch the script from.
762 It must have a default.nix file as its root accepting a scriptEnv parameter
766 url = mkOption { type = str; description = "git url to fetch"; };
767 rev = mkOption { type = str; description = "git reference to fetch"; };
772 description = "Variables to pass to the script";
779 description = "Sympa configuration";
782 listmasters = mkOption {
784 description = "Listmasters";
786 postgresql = mkPsqlOptions "Sympa";
787 data_sources = mkOption {
790 description = "Data sources to make available to sympa";
795 description = "Scenari to make available to sympa";
803 buildbot = mkOption {
804 description = "Buildbot configuration";
808 description = "Buildbot user";
812 description = "user uid";
816 description = "user gid";
823 description = "Ldap configuration for buildbot";
826 password = mkOption { type = str; description = "Buildbot password"; };
830 projects = mkOption {
831 description = "Projects to make a buildbot for";
832 type = attrsOf (submodule {
834 name = mkOption { type = str; description = "Project name"; };
835 packages = mkOption {
837 example = literalExample ''
838 pkgs: [ pkgs.bash pkgs.git pkgs.gzip pkgs.openssh ];
842 Builds packages list to make available to buildbot project.
843 Takes pkgs as argument.
846 pythonPackages = mkOption {
848 example = literalExample ''
849 p: pkgs: [ pkgs.python3Packages.pip ];
853 Builds python packages list to make available to buildbot project.
854 Takes buildbot python module as first argument and pkgs as second argument in order to augment the python modules list.
857 pythonPathHome = mkOption { type = bool; description = "Whether to add project’s python home to python path"; };
860 description = "Secrets for the project to dump as files";
862 environment = mkOption {
865 Environment variables for the project.
866 BUILDBOT_ is prefixed to the variable names
869 activationScript = mkOption {
872 Activation script to run during deployment
875 builderPaths = mkOption {
876 type = attrsOf unspecified;
879 Attrs of functions to make accessible specifically per builder.
880 Takes pkgs as argument and should return a single path containing binaries.
881 This path will be accessible as BUILDBOT_PATH_<attrskey>
884 webhookTokens = mkOption {
885 type = nullOr (listOf str);
888 List of tokens allowed to push to project’s change_hook/base endpoint
898 description = "Tools configurations";
901 contact = mkOption { type = str; description = "Contact e-mail address"; };
904 type = attrsOf (submodule {
906 url = mkOption { type = str; description = "URL to fetch"; };
907 sha256 = mkOption { type = str; description = "Hash of the url"; };
910 description = "Assets to provide on assets.immae.eu";
913 description = "Davical configuration";
916 postgresql = mkPsqlOptions "Davical";
917 ldap = mkLdapOptions "Davical" {};
921 diaspora = mkOption {
922 description = "Diaspora configuration";
925 postgresql = mkPsqlOptions "Diaspora";
926 redis = mkRedisOptions "Diaspora";
927 ldap = mkLdapOptions "Diaspora" {};
928 secret_token = mkOption { type = str; description = "Secret token"; };
932 dmarc_reports = mkOption {
933 description = "DMARC reports configuration";
936 mysql = mkMysqlOptions "DMARC" {};
937 anonymous_key = mkOption { type = str; description = "Anonymous hashing key"; };
941 etherpad-lite = mkOption {
942 description = "Etherpad configuration";
945 postgresql = mkPsqlOptions "Etherpad";
946 ldap = mkLdapOptions "Etherpad" {
947 group_filter = mkOption { type = str; description = "Filter for groups"; };
949 adminPassword = mkOption { type = str; description = "Admin password for mypads / admin"; };
950 session_key = mkOption { type = str; description = "Session key"; };
951 api_key = mkOption { type = str; description = "API key"; };
952 redirects = mkOption { type = str; description = "Redirects for apache"; };
956 gitolite = mkOption {
957 description = "Gitolite configuration";
960 ldap = mkLdapOptions "Gitolite" {};
964 kanboard = mkOption {
965 description = "Kanboard configuration";
968 postgresql = mkPsqlOptions "Kanboard";
969 ldap = mkLdapOptions "Kanboard" {
970 admin_dn = mkOption { type = str; description = "Admin DN"; };
975 mantisbt = mkOption {
976 description = "Mantisbt configuration";
979 postgresql = mkPsqlOptions "Mantisbt";
980 ldap = mkLdapOptions "Mantisbt" {};
981 master_salt = mkOption { type = str; description = "Master salt for password hash"; };
985 mastodon = mkOption {
986 description = "Mastodon configuration";
989 postgresql = mkPsqlOptions "Mastodon";
990 redis = mkRedisOptions "Mastodon";
991 ldap = mkLdapOptions "Mastodon" {};
992 paperclip_secret = mkOption { type = str; description = "Paperclip secret"; };
993 otp_secret = mkOption { type = str; description = "OTP secret"; };
994 secret_key_base = mkOption { type = str; description = "Secret key base"; };
996 description = "vapid key";
999 private = mkOption { type = str; description = "Private key"; };
1000 public = mkOption { type = str; description = "Public key"; };
1007 mediagoblin = mkOption {
1008 description = "Mediagoblin configuration";
1011 postgresql = mkPsqlOptions "Mediagoblin";
1012 redis = mkRedisOptions "Mediagoblin";
1013 ldap = mkLdapOptions "Mediagoblin" {};
1017 nextcloud = mkOption {
1018 description = "Nextcloud configuration";
1021 postgresql = mkPsqlOptions "Peertube";
1022 redis = mkRedisOptions "Peertube";
1023 password_salt = mkOption { type = str; description = "Password salt"; };
1024 instance_id = mkOption { type = str; description = "Instance ID"; };
1025 secret = mkOption { type = str; description = "App secret"; };
1029 peertube = mkOption {
1030 description = "Peertube configuration";
1033 listenPort = mkOption { type = port; description = "Port to listen to"; };
1034 postgresql = mkPsqlOptions "Peertube";
1035 redis = mkRedisOptions "Peertube";
1036 ldap = mkLdapOptions "Peertube" {};
1040 syden_peertube = mkOption {
1041 description = "Peertube Syden configuration";
1044 listenPort = mkOption { type = port; description = "Port to listen to"; };
1045 postgresql = mkPsqlOptions "Peertube";
1046 redis = mkRedisOptions "Peertube";
1050 phpldapadmin = mkOption {
1051 description = "phpLdapAdmin configuration";
1054 ldap = mkLdapOptions "phpldapadmin" {};
1059 description = "Rompr configuration";
1063 description = "MPD configuration";
1066 host = mkOption { type = str; description = "Host for MPD"; };
1067 port = mkOption { type = port; description = "Port to access MPD host"; };
1074 roundcubemail = mkOption {
1075 description = "Roundcubemail configuration";
1078 postgresql = mkPsqlOptions "TT-RSS";
1079 secret = mkOption { type = str; description = "Secret"; };
1083 shaarli = mkOption {
1084 description = "Shaarli configuration";
1087 ldap = mkLdapOptions "Shaarli" {};
1091 status_engine = mkOption {
1092 description = "Status Engine configuration";
1095 mysql = mkMysqlOptions "StatusEngine" {};
1096 ldap = mkLdapOptions "StatusEngine" {};
1101 description = "Taskwarrior configuration";
1104 ldap = mkLdapOptions "Taskwarrior" {};
1105 taskwarrior-web = mkOption {
1106 description = "taskwarrior-web profiles";
1107 type = attrsOf (submodule {
1111 description = "List of ldap uids having access to this profile";
1113 org = mkOption { type = str; description = "Taskd organisation"; };
1114 key = mkOption { type = str; description = "Taskd key"; };
1115 date = mkOption { type = str; description = "Preferred date format"; };
1123 description = "TT-RSS configuration";
1126 postgresql = mkPsqlOptions "TT-RSS";
1127 ldap = mkLdapOptions "TT-RSS" {};
1131 wallabag = mkOption {
1132 description = "Wallabag configuration";
1135 postgresql = mkPsqlOptions "Wallabag";
1136 ldap = mkLdapOptions "Wallabag" {
1137 admin_filter = mkOption { type = str; description = "Admin users filter"; };
1139 redis = mkRedisOptions "Wallabag";
1140 secret = mkOption { type = str; description = "App secret"; };
1144 webhooks = mkOption {
1146 description = "Mapping 'name'.php => script for webhooks";
1148 csp_reports = mkOption {
1149 description = "CSP report configuration";
1152 report_uri = mkOption { type = str; description = "URI to report CSP violations to"; };
1153 policies = mkOption { type = attrsOf str; description = "CSP policies to apply"; };
1154 postgresql = mkPsqlOptions "CSP reports";
1158 commento = mkOption {
1159 description = "Commento configuration";
1162 listenPort = mkOption { type = port; description = "Port to listen to"; };
1163 postgresql = mkPsqlOptions "Commento";
1164 smtp = mkSmtpOptions "Commento";
1169 description = "Ympd configuration";
1172 listenPort = mkOption { type = port; description = "Port to listen to"; };
1174 description = "MPD configuration";
1177 password = mkOption { type = str; description = "Password to access MPD host"; };
1178 host = mkOption { type = str; description = "Host for MPD"; };
1179 port = mkOption { type = port; description = "Port to access MPD host"; };
1187 description = "Yourls configuration";
1190 mysql = mkMysqlOptions "Yourls" {};
1191 ldap = mkLdapOptions "Yourls" {};
1192 cookieKey = mkOption { type = str; description = "Cookie key"; };
1199 serverSpecific = mkOption { type = attrsOf unspecified; description = "Server specific configuration"; };
1200 websites = mkOption {
1201 description = "Websites configurations";
1205 description = "Immae configuration by environment";
1209 description = "Temp configuration";
1212 ldap = mkLdapOptions "Immae temp" {
1213 filter = mkOption { type = str; description = "Filter for user access"; };
1221 isabelle = mkOption {
1222 description = "Isabelle configurations by environment";
1225 atenSubmodule = mkOption {
1226 description = "environment configuration";
1229 environment = mkOption { type = str; description = "Symfony environment"; };
1230 secret = mkOption { type = str; description = "Symfony App secret"; };
1231 postgresql = mkPsqlOptions "Aten";
1238 aten_production = atenSubmodule;
1239 aten_integration = atenSubmodule;
1240 iridologie = mkOption {
1241 description = "environment configuration";
1244 environment = mkOption { type = str; description = "SPIP environment"; };
1245 mysql = mkMysqlOptions "Iridologie" {};
1246 ldap = mkLdapOptions "Iridologie" {};
1254 description = "Chloe configurations by environment";
1257 chloeSubmodule = mkOption {
1258 description = "environment configuration";
1261 environment = mkOption { type = str; description = "SPIP environment"; };
1262 mysql = mkMysqlOptions "Chloe" {};
1263 ldap = mkLdapOptions "Chloe" {};
1270 production = chloeSubmodule;
1271 integration = chloeSubmodule;
1275 connexionswing = mkOption {
1276 description = "Connexionswing configurations by environment";
1279 csSubmodule = mkOption {
1280 description = "environment configuration";
1283 environment = mkOption { type = str; description = "Symfony environment"; };
1284 mysql = mkMysqlOptions "Connexionswing" {};
1285 secret = mkOption { type = str; description = "Symfony App secret"; };
1286 email = mkOption { type = str; description = "Symfony email notification"; };
1293 production = csSubmodule;
1294 integration = csSubmodule;
1299 description = "Naturaloutil configuration";
1302 mysql = mkMysqlOptions "Naturaloutil" {};
1303 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1307 telio_tortay = mkOption {
1308 description = "Telio Tortay configuration";
1311 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1315 ludivine = mkOption {
1316 description = "Ludivinecassal configurations by environment";
1319 lcSubmodule = mkOption {
1320 description = "environment configuration";
1323 environment = mkOption { type = str; description = "Symfony environment"; };
1324 mysql = mkMysqlOptions "LudivineCassal" {};
1325 ldap = mkLdapOptions "LudivineCassal" {};
1326 secret = mkOption { type = str; description = "Symfony App secret"; };
1333 production = lcSubmodule;
1334 integration = lcSubmodule;
1339 description = "Emilia configuration";
1342 postgresql = mkPsqlOptions "Emilia";
1346 florian = mkOption {
1347 description = "Florian configuration";
1350 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1354 nassime = mkOption {
1355 description = "Nassime configuration";
1358 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1362 piedsjaloux = mkOption {
1363 description = "Piedsjaloux configurations by environment";
1366 pjSubmodule = mkOption {
1367 description = "environment configuration";
1370 environment = mkOption { type = str; description = "Symfony environment"; };
1371 mysql = mkMysqlOptions "Piedsjaloux" {};
1372 secret = mkOption { type = str; description = "Symfony App secret"; };
1379 production = pjSubmodule;
1380 integration = pjSubmodule;
1385 description = "Europe Richie configurations by environment";
1388 mysql = mkMysqlOptions "Richie" {};
1389 smtp_mailer = mkOption {
1390 description = "SMTP mailer configuration";
1393 user = mkOption { type = str; description = "Username"; };
1394 password = mkOption { type = str; description = "Password"; };
1401 caldance = mkOption {
1402 description = "Caldance configurations by environment";
1405 integration = mkOption {
1406 description = "environment configuration";
1409 password = mkOption { type = str; description = "Password file content for basic auth"; };
1416 tellesflorian = mkOption {
1417 description = "Tellesflorian configurations by environment";
1420 tfSubmodule = mkOption {
1421 description = "environment configuration";
1424 environment = mkOption { type = str; description = "Symfony environment"; };
1425 mysql = mkMysqlOptions "Tellesflorian" {};
1426 secret = mkOption { type = str; description = "Symfony App secret"; };
1427 invite_passwords = mkOption { type = str; description = "Password basic auth"; };
1434 integration = tfSubmodule;
1442 privateFiles = mkOption {
1445 Path to secret files to make available during build
1449 options.hostEnv = mkOption {
1452 default = config.myEnv.servers."${name}";
1453 description = "Host environment";