1 { config, lib, name, ... }:
7 base = mkOption { description = "Base of the LDAP tree"; type = str; };
8 host = mkOption { description = "Host to access LDAP"; type = str; };
9 root_dn = mkOption { description = "DN of the root user"; type = str; };
10 root_pw = mkOption { description = "Hashed password of the root user"; type = str; };
11 replication_dn = mkOption { description = "DN of the user allowed to replicate the LDAP directory"; type = str; };
12 replication_pw = mkOption { description = "Password of the user allowed to replicate the LDAP directory"; type = str; };
14 mkLdapOptions = name: more: mkOption {
15 description = "${name} LDAP configuration";
17 options = ldapOptions // {
18 dn = mkOption { description = "DN of the ${name} user"; type = str; };
19 password = mkOption { description = "password of the ${name} user"; type = str; };
20 filter = mkOption { description = "Filter for ${name} users"; type = str; default = ""; };
25 host = mkOption { description = "Host to access Mysql"; type = str; };
26 remoteHost = mkOption { description = "Host to access Mysql from outside"; type = str; };
27 port = mkOption { description = "Port to access Mysql"; type = str; };
28 socket = mkOption { description = "Socket to access Mysql"; type = path; };
29 systemUsers = mkOption {
30 description = "Attrs of user-passwords allowed to access mysql";
34 description = "PAM configuration for mysql";
37 dn = mkOption { description = "DN to connect as to check users"; type = str; };
38 password = mkOption { description = "DN password to connect as to check users"; type = str; };
39 filter = mkOption { description = "filter to match users"; type = str; };
44 mkMysqlOptions = name: more: mkOption {
45 description = "${name} mysql configuration";
47 options = mysqlOptions // {
48 database = mkOption { description = "${name} database"; type = str; };
49 user = mkOption { description = "${name} user"; type = str; };
50 password = mkOption { description = "mysql password of the ${name} user"; type = str; };
55 host = mkOption { description = "Host to access Postgresql"; type = str; };
56 port = mkOption { description = "Port to access Postgresql"; type = str; };
57 socket = mkOption { description = "Socket to access Postgresql"; type = path; };
59 description = "PAM configuration for psql";
62 dn = mkOption { description = "DN to connect as to check users"; type = str; };
63 password = mkOption { description = "DN password to connect as to check users"; type = str; };
64 filter = mkOption { description = "filter to match users"; type = str; };
69 mkPsqlOptions = name: mkOption {
70 description = "${name} psql configuration";
72 options = psqlOptions // {
73 database = mkOption { description = "${name} database"; type = str; };
74 schema = mkOption { description = "${name} schema"; type = nullOr str; default = null; };
75 user = mkOption { description = "${name} user"; type = str; };
76 password = mkOption { description = "psql password of the ${name} user"; type = str; };
81 host = mkOption { description = "Host to access Redis"; type = str; };
82 port = mkOption { description = "Port to access Redis"; type = str; };
83 socket = mkOption { description = "Socket to access Redis"; type = path; };
85 description = "Attrs of db number. Each number should be unique to avoid collision!";
88 spiped_key = mkOption {
91 Key to use with spiped to make a secure channel to replication
95 description = "Predixy configuration. Unused yet";
98 read = mkOption { type = str; description = "Read password"; };
103 mkRedisOptions = name: mkOption {
104 description = "${name} redis configuration";
106 options = redisOptions // {
107 db = mkOption { description = "${name} database"; type = str; };
112 host = mkOption { description = "Host to access SMTP"; type = str; };
113 port = mkOption { description = "Port to access SMTP"; type = str; };
115 mkSmtpOptions = name: mkOption {
116 description = "${name} smtp configuration";
118 options = smtpOptions // {
119 email = mkOption { description = "${name} email"; type = str; };
120 password = mkOption { description = "SMTP password of the ${name} user"; type = str; };
124 hostEnv = submodule {
127 description = "Host FQDN";
134 Sublist of users from realUsers. Function that takes pkgs as
135 argument and gives an array as a result
140 description = "List of e-mails that the server can be a sender of";
145 LDAP credentials for the host
149 password = mkOption { type = str; description = "Password for the LDAP connection"; };
150 dn = mkOption { type = str; description = "DN for the LDAP connection"; };
155 description = "subdomain and priority for MX server";
156 default = { enable = false; };
159 enable = mkEnableOption "Enable MX";
160 subdomain = mkOption { type = nullOr str; description = "Subdomain name (mx-*)"; };
161 priority = mkOption { type = nullOr str; description = "Priority"; };
167 attrs of ip4/ip6 grouped by section
169 type = attrsOf (submodule {
174 ip4 address of the host
181 ip6 addresses of the host
194 Attrs of servers information in the cluster (not necessarily handled by nixops)
197 type = attrsOf hostEnv;
199 hetznerCloud = mkOption {
201 Hetzner Cloud credential information
205 authToken = mkOption {
216 Hetzner credential information
220 user = mkOption { type = str; description = "User"; };
221 pass = mkOption { type = str; description = "Password"; };
227 sshd service credential information
231 rootKeys = mkOption { type = attrsOf str; description = "Keys of root users"; };
234 LDAP credentials for cn=ssh,ou=services,dc=immae,dc=eu dn
238 password = mkOption { description = "Password"; type = str; };
247 non-standard reserved ports. Must be unique!
252 noDupl = x: builtins.length (builtins.attrValues x) == builtins.length (unique (builtins.attrValues x));
254 x: if isAttrs x && noDupl x then x else throw "Non unique values for ports";
258 httpd service credential information
264 LDAP credentials for cn=httpd,ou=services,dc=immae,dc=eu dn
268 password = mkOption { description = "Password"; type = str; };
276 type = submodule { options = smtpOptions; };
277 description = "SMTP configuration";
281 LDAP server configuration
284 options = ldapOptions;
287 databases = mkOption {
288 description = "Databases configuration";
292 type = submodule { options = mysqlOptions; };
293 description = "Mysql configuration";
296 type = submodule { options = redisOptions; };
297 description = "Redis configuration";
299 postgresql = mkOption {
300 type = submodule { options = psqlOptions; };
301 description = "Postgresql configuration";
307 description = "Jabber configuration";
310 postfix_user_filter = mkOption { type = str; description = "Postfix filter to get xmpp users"; };
311 ldap = mkLdapOptions "Jabber" {};
312 postgresql = mkPsqlOptions "Jabber";
316 realUsers = mkOption {
318 Attrset of function taking pkgs as argument.
319 Real users settings, should provide a subattr of users.users.<name>
320 with at least: name, (hashed)Password, shell
322 type = attrsOf unspecified;
325 description = "System and regular users uid/gid";
326 type = attrsOf (submodule {
329 description = "user uid";
333 description = "user gid";
340 description = "DNS configuration";
344 description = "SOA information";
348 description = "Serial number. Should be incremented at each change and unique";
352 description = "Refresh time";
356 description = "Retry time";
360 description = "Expire time";
364 description = "Default TTL time";
368 description = "hostmaster e-mail";
372 description = "Primary NS";
379 description = "Attrs of NS servers group";
382 "ns1.foo.com" = [ "198.51.100.10" "2001:db8:abcd::1" ];
383 "ns2.foo.com" = [ "198.51.100.15" "2001:db8:1234::1" ];
386 type = attrsOf (attrsOf (listOf str));
390 description = "DNS keys";
391 type = attrsOf (submodule {
393 algorithm = mkOption { type = str; description = "Algorithm"; };
394 secret = mkOption { type = str; description = "Secret"; };
398 slaveZones = mkOption {
399 description = "List of slave zones";
400 type = listOf (submodule {
402 name = mkOption { type = str; description = "zone name"; };
404 description = "NS master groups of this zone";
409 description = "Keys associated to the server";
415 masterZones = mkOption {
416 description = "List of master zones";
417 type = listOf (submodule {
419 name = mkOption { type = str; description = "zone name"; };
420 withCAA = mkOption { type = nullOr str; description = "CAA entry"; default = null; };
422 description = "NS slave groups of this zone";
426 description = "groups names that should have their NS entries listed here";
430 description = "Extra zone configuration for bind";
436 entries = mkOption { type = lines; description = "Regular entries of the NS zone"; };
437 withEmail = mkOption {
438 description = "List of domains that should have mail entries (MX, dkim, SPF, ...)";
440 type = listOf (submodule {
442 domain = mkOption { type = str; description = "Which subdomain is concerned"; };
443 send = mkOption { type = bool; description = "Whether there can be e-mails originating from the subdomain"; };
444 receive = mkOption { type = bool; description = "Whether there can be e-mails arriving to the subdomain"; };
456 Remote backup with duplicity
460 password = mkOption { type = str; description = "Password for encrypting files"; };
462 type = attrsOf (submodule {
466 example = literalExample ''
467 bucket: "s3://some_host/${bucket}";
471 Takes a bucket name as argument and returns a url
474 accessKeyId = mkOption { type = str; description = "Remote access-key"; };
475 secretAccessKey = mkOption { type = str; description = "Remote access secret"; };
482 zrepl_backup = mkOption {
486 description = "SSH key information";
489 public = mkOption { type = str; description = "Public part of the key"; };
490 private = mkOption { type = lines; description = "Private part of the key"; };
494 mysql = mkMysqlOptions "Zrepl" {};
498 rsync_backup = mkOption {
500 Rsync backup configuration from controlled host
505 description = "SSH key information";
508 public = mkOption { type = str; description = "Public part of the key"; };
509 private = mkOption { type = lines; description = "Private part of the key"; };
513 profiles = mkOption {
514 description = "Attrs of profiles to backup";
515 type = attrsOf (submodule {
517 keep = mkOption { type = int; description = "Number of backups to keep"; };
518 check_command = mkOption { type = str; description = "command to check if backup needs to be done"; default = "backup"; };
519 login = mkOption { type = str; description = "Login to connect to host"; };
520 port = mkOption { type = str; default = "22"; description = "Port to connect to host"; };
521 host = mkOption { type = str; description = "Host to connect to"; };
522 host_key = mkOption { type = str; description = "Host key"; };
523 host_key_type = mkOption { type = str; description = "Host key type"; };
525 description = "Parts to backup for this host";
526 type = attrsOf (submodule {
528 remote_folder = mkOption { type = path; description = "Remote folder to backup";};
529 exclude_from = mkOption {
532 description = "List of folders/files to exclude from the backup";
534 files_from = mkOption {
537 description = "List of folders/files to backup in the base folder";
542 description = "Extra arguments to pass to rsync";
553 monitoring = mkOption {
554 description = "Monitoring configuration";
557 status_url = mkOption { type = str; description = "URL to push status to"; };
558 status_token = mkOption { type = str; description = "Token for the status url"; };
559 http_user_password = mkOption { type = str; description = "HTTP credentials to check services behind wall"; };
560 email = mkOption { type = str; description = "Admin E-mail"; };
561 ssh_public_key = mkOption { type = str; description = "SSH public key"; };
562 ssh_secret_key = mkOption { type = str; description = "SSH secret key"; };
563 imap_login = mkOption { type = str; description = "IMAP login"; };
564 imap_password = mkOption { type = str; description = "IMAP password"; };
565 eriomem_keys = mkOption { type = listOf (listOf str); description = "Eriomem keys"; default = []; };
567 description = "OVH credentials for sms script";
570 endpoint = mkOption { type = str; default = "ovh-eu"; description = "OVH endpoint"; };
571 application_key = mkOption { type = str; description = "Application key"; };
572 application_secret = mkOption { type = str; description = "Application secret"; };
573 consumer_key = mkOption { type = str; description = "Consumer key"; };
574 account = mkOption { type = str; description = "Account"; };
579 description = "Eban credentials for webhook";
582 user = mkOption { type = str; description = "User"; };
583 password = mkOption { type = str; description = "Password"; };
587 nrdp_tokens = mkOption { type = listOf str; description = "Tokens allowed to push status update"; };
588 slack_url = mkOption { type = str; description = "Slack webhook url to push status update"; };
589 slack_channel = mkOption { type = str; description = "Slack channel to push status update"; };
590 netdata_aggregator = mkOption { type = str; description = "Url where netdata information should be sent"; };
591 netdata_keys = mkOption { type = attrsOf str; description = "netdata host keys"; };
592 contacts = mkOption { type = attrsOf unspecified; description = "Contact dicts to fill naemon objects"; };
593 email_check = mkOption {
594 description = "Emails services to check";
595 type = attrsOf (submodule {
597 local = mkOption { type = bool; default = false; description = "Use local configuration"; };
598 port = mkOption { type = nullOr str; default = null; description = "Port to connect to ssh"; };
599 login = mkOption { type = nullOr str; default = null; description = "Login to connect to ssh"; };
600 targets = mkOption { type = listOf str; description = "Hosts to send E-mails to"; };
601 mail_address = mkOption { type = nullOr str; default = null; description = "E-mail recipient part to send e-mail to"; };
602 mail_domain = mkOption { type = nullOr str; default = null; description = "E-mail domain part to send e-mail to"; };
610 description = "MPD configuration";
613 folder = mkOption { type = str; description = "Folder to serve from the MPD instance"; };
614 password = mkOption { type = str; description = "Password to connect to the MPD instance"; };
615 host = mkOption { type = str; description = "Host to connect to the MPD instance"; };
616 port = mkOption { type = str; description = "Port to connect to the MPD instance"; };
621 description = "FTP configuration";
624 ldap = mkLdapOptions "FTP" {};
629 description = "VPN configuration";
630 type = attrsOf (submodule {
632 prefix = mkOption { type = str; description = "ipv6 prefix for the vpn subnet"; };
633 privateKey = mkOption { type = str; description = "Private key for the host"; };
634 publicKey = mkOption { type = str; description = "Public key for the host"; };
639 description = "Mail configuration";
643 description = "DMARC configuration";
646 ignore_hosts = mkOption {
649 Hosts to ignore when checking for dmarc
656 description = "DKIM configuration";
657 type = attrsOf (submodule {
663 "p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC3w1a2aMxWw9+hdcmbqX4UevcVqr204y0K73Wdc7MPZiOOlUJQYsMNSYR1Y/SC7jmPKeitpcJCpQgn/cveJZbuikjjPLsDReHyFEYmC278ZLRTELHx6f1IXM8WE08JIRT69CfZiMi1rVcOh9qRT4F93PyjCauU8Y5hJjtg9ThsWwIDAQAB" )
665 description = "Public entry to put in DNS TXT field";
667 private = mkOption { type = str; description = "Private key"; };
672 description = "Postfix configuration";
675 additional_mailbox_domains = mkOption {
677 List of domains that are used as mailbox final destination, in addition to those defined in the DNS records
681 mysql = mkMysqlOptions "Postfix" {
682 password_encrypt = mkOption { type = str; description = "Key to encrypt relay password in database"; };
684 backup_domains = mkOption {
686 Domains that are accepted for relay as backup domain
688 type = attrsOf (submodule {
690 domains = mkOption { type = listOf str; description = "Domains list"; };
691 relay_restrictions = mkOption {
694 Restrictions for relaying the e-mails from the domains
697 recipient_maps = mkOption {
699 Recipient map to accept relay for.
700 Must be specified for domain, the rules apply to everyone!
702 type = listOf (submodule {
705 type = enum [ "hash" ];
706 description = "Map type";
710 description = "Map content";
722 description = "Dovecot configuration";
725 ldap = mkLdapOptions "Dovecot" {
726 pass_attrs = mkOption { type = str; description = "Password attribute in LDAP"; };
727 user_attrs = mkOption { type = str; description = "User attribute mapping in LDAP"; };
728 iterate_attrs = mkOption { type = str; description = "User attribute mapping for listing in LDAP"; };
729 iterate_filter = mkOption { type = str; description = "User attribute filter for listing in LDAP"; };
730 postfix_mailbox_filter = mkOption { type = str; description = "Postfix filter to get mailboxes"; };
736 description = "rspamd configuration";
739 redis = mkRedisOptions "Redis";
740 read_password_hashed = mkOption { type = str; description = "Hashed read password for rspamd"; };
741 write_password_hashed = mkOption { type = str; description = "Hashed write password for rspamd"; };
742 read_password = mkOption {
744 description = "Read password for rspamd. Unused";
747 write_password = mkOption {
749 description = "Write password for rspamd. Unused";
756 description = "Mail script recipients";
757 type = attrsOf (submodule {
759 external = mkEnableOption "Create a script_<name>@mail.immae.eu external address";
762 git source to fetch the script from.
763 It must have a default.nix file as its root accepting a scriptEnv parameter
767 url = mkOption { type = str; description = "git url to fetch"; };
768 rev = mkOption { type = str; description = "git reference to fetch"; };
773 description = "Variables to pass to the script";
780 description = "Sympa configuration";
783 listmasters = mkOption {
785 description = "Listmasters";
787 postgresql = mkPsqlOptions "Sympa";
788 data_sources = mkOption {
791 description = "Data sources to make available to sympa";
796 description = "Scenari to make available to sympa";
804 buildbot = mkOption {
805 description = "Buildbot configuration";
808 workerPassword = mkOption { description = "Buildbot worker password"; type = str; };
810 description = "Buildbot user";
814 description = "user uid";
818 description = "user gid";
825 description = "Ldap configuration for buildbot";
828 password = mkOption { type = str; description = "Buildbot password"; };
832 projects = mkOption {
833 description = "Projects to make a buildbot for";
834 type = attrsOf (submodule {
836 name = mkOption { type = str; description = "Project name"; };
837 packages = mkOption {
839 example = literalExample ''
840 pkgs: [ pkgs.bash pkgs.git pkgs.gzip pkgs.openssh ];
844 Builds packages list to make available to buildbot project.
845 Takes pkgs as argument.
848 pythonPackages = mkOption {
850 example = literalExample ''
851 p: pkgs: [ pkgs.python3Packages.pip ];
855 Builds python packages list to make available to buildbot project.
856 Takes buildbot python module as first argument and pkgs as second argument in order to augment the python modules list.
859 pythonPathHome = mkOption { type = bool; description = "Whether to add project’s python home to python path"; };
860 workerPort = mkOption { type = port; description = "Port for the worker"; };
863 description = "Secrets for the project to dump as files";
865 environment = mkOption {
868 Environment variables for the project.
869 BUILDBOT_ is prefixed to the variable names
872 activationScript = mkOption {
875 Activation script to run during deployment
878 builderPaths = mkOption {
879 type = attrsOf unspecified;
882 Attrs of functions to make accessible specifically per builder.
883 Takes pkgs as argument and should return a single path containing binaries.
884 This path will be accessible as BUILDBOT_PATH_<attrskey>
887 webhookTokens = mkOption {
888 type = nullOr (listOf str);
891 List of tokens allowed to push to project’s change_hook/base endpoint
901 description = "Tools configurations";
904 contact = mkOption { type = str; description = "Contact e-mail address"; };
907 type = attrsOf (submodule {
909 url = mkOption { type = str; description = "URL to fetch"; };
910 sha256 = mkOption { type = str; description = "Hash of the url"; };
913 description = "Assets to provide on assets.immae.eu";
916 description = "Davical configuration";
919 postgresql = mkPsqlOptions "Davical";
920 ldap = mkLdapOptions "Davical" {};
924 diaspora = mkOption {
925 description = "Diaspora configuration";
928 postgresql = mkPsqlOptions "Diaspora";
929 redis = mkRedisOptions "Diaspora";
930 ldap = mkLdapOptions "Diaspora" {};
931 secret_token = mkOption { type = str; description = "Secret token"; };
935 dmarc_reports = mkOption {
936 description = "DMARC reports configuration";
939 mysql = mkMysqlOptions "DMARC" {};
940 anonymous_key = mkOption { type = str; description = "Anonymous hashing key"; };
944 etherpad-lite = mkOption {
945 description = "Etherpad configuration";
948 postgresql = mkPsqlOptions "Etherpad";
949 ldap = mkLdapOptions "Etherpad" {
950 group_filter = mkOption { type = str; description = "Filter for groups"; };
952 adminPassword = mkOption { type = str; description = "Admin password for mypads / admin"; };
953 session_key = mkOption { type = str; description = "Session key"; };
954 api_key = mkOption { type = str; description = "API key"; };
955 redirects = mkOption { type = str; description = "Redirects for apache"; };
959 gitolite = mkOption {
960 description = "Gitolite configuration";
963 ldap = mkLdapOptions "Gitolite" {};
967 kanboard = mkOption {
968 description = "Kanboard configuration";
971 postgresql = mkPsqlOptions "Kanboard";
972 ldap = mkLdapOptions "Kanboard" {
973 admin_dn = mkOption { type = str; description = "Admin DN"; };
978 mantisbt = mkOption {
979 description = "Mantisbt configuration";
982 postgresql = mkPsqlOptions "Mantisbt";
983 ldap = mkLdapOptions "Mantisbt" {};
984 master_salt = mkOption { type = str; description = "Master salt for password hash"; };
988 mastodon = mkOption {
989 description = "Mastodon configuration";
992 postgresql = mkPsqlOptions "Mastodon";
993 redis = mkRedisOptions "Mastodon";
994 ldap = mkLdapOptions "Mastodon" {};
995 paperclip_secret = mkOption { type = str; description = "Paperclip secret"; };
996 otp_secret = mkOption { type = str; description = "OTP secret"; };
997 secret_key_base = mkOption { type = str; description = "Secret key base"; };
999 description = "vapid key";
1002 private = mkOption { type = str; description = "Private key"; };
1003 public = mkOption { type = str; description = "Public key"; };
1010 mediagoblin = mkOption {
1011 description = "Mediagoblin configuration";
1014 postgresql = mkPsqlOptions "Mediagoblin";
1015 redis = mkRedisOptions "Mediagoblin";
1016 ldap = mkLdapOptions "Mediagoblin" {};
1020 nextcloud = mkOption {
1021 description = "Nextcloud configuration";
1024 postgresql = mkPsqlOptions "Peertube";
1025 redis = mkRedisOptions "Peertube";
1026 password_salt = mkOption { type = str; description = "Password salt"; };
1027 instance_id = mkOption { type = str; description = "Instance ID"; };
1028 secret = mkOption { type = str; description = "App secret"; };
1032 peertube = mkOption {
1033 description = "Peertube configuration";
1036 listenPort = mkOption { type = port; description = "Port to listen to"; };
1037 postgresql = mkPsqlOptions "Peertube";
1038 redis = mkRedisOptions "Peertube";
1039 ldap = mkLdapOptions "Peertube" {};
1043 syden_peertube = mkOption {
1044 description = "Peertube Syden configuration";
1047 listenPort = mkOption { type = port; description = "Port to listen to"; };
1048 postgresql = mkPsqlOptions "Peertube";
1049 redis = mkRedisOptions "Peertube";
1053 phpldapadmin = mkOption {
1054 description = "phpLdapAdmin configuration";
1057 ldap = mkLdapOptions "phpldapadmin" {};
1062 description = "Rompr configuration";
1066 description = "MPD configuration";
1069 host = mkOption { type = str; description = "Host for MPD"; };
1070 port = mkOption { type = port; description = "Port to access MPD host"; };
1077 roundcubemail = mkOption {
1078 description = "Roundcubemail configuration";
1081 postgresql = mkPsqlOptions "TT-RSS";
1082 secret = mkOption { type = str; description = "Secret"; };
1086 shaarli = mkOption {
1087 description = "Shaarli configuration";
1090 ldap = mkLdapOptions "Shaarli" {};
1094 status_engine = mkOption {
1095 description = "Status Engine configuration";
1098 mysql = mkMysqlOptions "StatusEngine" {};
1099 ldap = mkLdapOptions "StatusEngine" {};
1104 description = "Taskwarrior configuration";
1107 ldap = mkLdapOptions "Taskwarrior" {};
1108 taskwarrior-web = mkOption {
1109 description = "taskwarrior-web profiles";
1110 type = attrsOf (submodule {
1114 description = "List of ldap uids having access to this profile";
1116 org = mkOption { type = str; description = "Taskd organisation"; };
1117 key = mkOption { type = str; description = "Taskd key"; };
1118 date = mkOption { type = str; description = "Preferred date format"; };
1126 description = "TT-RSS configuration";
1129 postgresql = mkPsqlOptions "TT-RSS";
1130 ldap = mkLdapOptions "TT-RSS" {};
1134 wallabag = mkOption {
1135 description = "Wallabag configuration";
1138 postgresql = mkPsqlOptions "Wallabag";
1139 ldap = mkLdapOptions "Wallabag" {
1140 admin_filter = mkOption { type = str; description = "Admin users filter"; };
1142 redis = mkRedisOptions "Wallabag";
1143 secret = mkOption { type = str; description = "App secret"; };
1147 webhooks = mkOption {
1149 description = "Mapping 'name'.php => script for webhooks";
1151 csp_reports = mkOption {
1152 description = "CSP report configuration";
1155 report_uri = mkOption { type = str; description = "URI to report CSP violations to"; };
1156 policies = mkOption { type = attrsOf str; description = "CSP policies to apply"; };
1157 postgresql = mkPsqlOptions "CSP reports";
1161 commento = mkOption {
1162 description = "Commento configuration";
1165 listenPort = mkOption { type = port; description = "Port to listen to"; };
1166 postgresql = mkPsqlOptions "Commento";
1167 smtp = mkSmtpOptions "Commento";
1171 cryptpad = mkOption {
1172 description = "Cryptpad configuration";
1173 type = attrsOf (submodule {
1175 email = mkOption { type = str; description = "Admin e-mail"; };
1176 admins = mkOption { type = listOf str; description = "Instance admin public keys"; };
1177 port = mkOption { type = port; description = "Port to listen to"; };
1182 description = "Ympd configuration";
1185 listenPort = mkOption { type = port; description = "Port to listen to"; };
1187 description = "MPD configuration";
1190 password = mkOption { type = str; description = "Password to access MPD host"; };
1191 host = mkOption { type = str; description = "Host for MPD"; };
1192 port = mkOption { type = port; description = "Port to access MPD host"; };
1200 description = "Umami configuration";
1203 listenPort = mkOption { type = port; description = "Port to listen to"; };
1204 postgresql = mkPsqlOptions "Umami";
1205 hashSalt = mkOption { type = str; description = "Hash salt"; };
1210 description = "Yourls configuration";
1213 mysql = mkMysqlOptions "Yourls" {};
1214 ldap = mkLdapOptions "Yourls" {};
1215 cookieKey = mkOption { type = str; description = "Cookie key"; };
1222 serverSpecific = mkOption { type = attrsOf unspecified; description = "Server specific configuration"; };
1223 websites = mkOption {
1224 description = "Websites configurations";
1228 description = "Immae configuration by environment";
1232 description = "Temp configuration";
1235 ldap = mkLdapOptions "Immae temp" {
1236 filter = mkOption { type = str; description = "Filter for user access"; };
1244 isabelle = mkOption {
1245 description = "Isabelle configurations by environment";
1248 atenSubmodule = mkOption {
1249 description = "environment configuration";
1252 environment = mkOption { type = str; description = "Symfony environment"; };
1253 secret = mkOption { type = str; description = "Symfony App secret"; };
1254 postgresql = mkPsqlOptions "Aten";
1261 aten_production = atenSubmodule;
1262 aten_integration = atenSubmodule;
1263 iridologie = mkOption {
1264 description = "environment configuration";
1267 environment = mkOption { type = str; description = "SPIP environment"; };
1268 mysql = mkMysqlOptions "Iridologie" {};
1269 ldap = mkLdapOptions "Iridologie" {};
1277 description = "Chloe configurations by environment";
1280 chloeSubmodule = mkOption {
1281 description = "environment configuration";
1284 environment = mkOption { type = str; description = "SPIP environment"; };
1285 mysql = mkMysqlOptions "Chloe" {};
1286 ldap = mkLdapOptions "Chloe" {};
1293 production = chloeSubmodule;
1294 integration = chloeSubmodule;
1298 connexionswing = mkOption {
1299 description = "Connexionswing configurations by environment";
1302 csSubmodule = mkOption {
1303 description = "environment configuration";
1306 environment = mkOption { type = str; description = "Symfony environment"; };
1307 mysql = mkMysqlOptions "Connexionswing" {};
1308 secret = mkOption { type = str; description = "Symfony App secret"; };
1309 email = mkOption { type = str; description = "Symfony email notification"; };
1316 production = csSubmodule;
1317 integration = csSubmodule;
1322 description = "Naturaloutil configuration";
1325 mysql = mkMysqlOptions "Naturaloutil" {};
1326 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1330 telio_tortay = mkOption {
1331 description = "Telio Tortay configuration";
1334 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1338 ludivine = mkOption {
1339 description = "Ludivinecassal configurations by environment";
1342 lcSubmodule = mkOption {
1343 description = "environment configuration";
1346 environment = mkOption { type = str; description = "Symfony environment"; };
1347 mysql = mkMysqlOptions "LudivineCassal" {};
1348 ldap = mkLdapOptions "LudivineCassal" {};
1349 secret = mkOption { type = str; description = "Symfony App secret"; };
1356 production = lcSubmodule;
1357 integration = lcSubmodule;
1362 description = "Emilia configuration";
1365 postgresql = mkPsqlOptions "Emilia";
1369 florian = mkOption {
1370 description = "Florian configuration";
1373 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1377 nassime = mkOption {
1378 description = "Nassime configuration";
1381 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1385 piedsjaloux = mkOption {
1386 description = "Piedsjaloux configurations by environment";
1389 pjSubmodule = mkOption {
1390 description = "environment configuration";
1393 environment = mkOption { type = str; description = "Symfony environment"; };
1394 mysql = mkMysqlOptions "Piedsjaloux" {};
1395 secret = mkOption { type = str; description = "Symfony App secret"; };
1402 production = pjSubmodule;
1403 integration = pjSubmodule;
1408 description = "Europe Richie configurations by environment";
1411 mysql = mkMysqlOptions "Richie" {};
1412 smtp_mailer = mkOption {
1413 description = "SMTP mailer configuration";
1416 user = mkOption { type = str; description = "Username"; };
1417 password = mkOption { type = str; description = "Password"; };
1424 caldance = mkOption {
1425 description = "Caldance configurations by environment";
1428 integration = mkOption {
1429 description = "environment configuration";
1432 password = mkOption { type = str; description = "Password file content for basic auth"; };
1439 tellesflorian = mkOption {
1440 description = "Tellesflorian configurations by environment";
1443 tfSubmodule = mkOption {
1444 description = "environment configuration";
1447 environment = mkOption { type = str; description = "Symfony environment"; };
1448 mysql = mkMysqlOptions "Tellesflorian" {};
1449 secret = mkOption { type = str; description = "Symfony App secret"; };
1450 invite_passwords = mkOption { type = str; description = "Password basic auth"; };
1457 integration = tfSubmodule;
1465 privateFiles = mkOption {
1468 Path to secret files to make available during build
1472 options.hostEnv = mkOption {
1475 default = config.myEnv.servers."${name}";
1476 description = "Host environment";