1 { config, lib, name, ... }:
7 base = mkOption { description = "Base of the LDAP tree"; type = str; };
8 host = mkOption { description = "Host to access LDAP"; type = str; };
9 root_dn = mkOption { description = "DN of the root user"; type = str; };
10 root_pw = mkOption { description = "Hashed password of the root user"; type = str; };
11 replication_dn = mkOption { description = "DN of the user allowed to replicate the LDAP directory"; type = str; };
12 replication_pw = mkOption { description = "Password of the user allowed to replicate the LDAP directory"; type = str; };
14 mkLdapOptions = name: more: mkOption {
15 description = "${name} LDAP configuration";
17 options = ldapOptions // {
18 dn = mkOption { description = "DN of the ${name} user"; type = str; };
19 password = mkOption { description = "password of the ${name} user"; type = str; };
20 filter = mkOption { description = "Filter for ${name} users"; type = str; default = ""; };
25 host = mkOption { description = "Host to access Mysql"; type = str; };
26 remoteHost = mkOption { description = "Host to access Mysql from outside"; type = str; };
27 port = mkOption { description = "Port to access Mysql"; type = str; };
28 socket = mkOption { description = "Socket to access Mysql"; type = path; };
29 systemUsers = mkOption {
30 description = "Attrs of user-passwords allowed to access mysql";
34 description = "PAM configuration for mysql";
37 dn = mkOption { description = "DN to connect as to check users"; type = str; };
38 password = mkOption { description = "DN password to connect as to check users"; type = str; };
39 filter = mkOption { description = "filter to match users"; type = str; };
44 mkMysqlOptions = name: more: mkOption {
45 description = "${name} mysql configuration";
47 options = mysqlOptions // {
48 database = mkOption { description = "${name} database"; type = str; };
49 user = mkOption { description = "${name} user"; type = str; };
50 password = mkOption { description = "mysql password of the ${name} user"; type = str; };
55 host = mkOption { description = "Host to access Postgresql"; type = str; };
56 port = mkOption { description = "Port to access Postgresql"; type = str; };
57 socket = mkOption { description = "Socket to access Postgresql"; type = path; };
59 description = "PAM configuration for psql";
62 dn = mkOption { description = "DN to connect as to check users"; type = str; };
63 password = mkOption { description = "DN password to connect as to check users"; type = str; };
64 filter = mkOption { description = "filter to match users"; type = str; };
69 mkPsqlOptions = name: mkOption {
70 description = "${name} psql configuration";
72 options = psqlOptions // {
73 database = mkOption { description = "${name} database"; type = str; };
74 schema = mkOption { description = "${name} schema"; type = nullOr str; default = null; };
75 user = mkOption { description = "${name} user"; type = str; };
76 password = mkOption { description = "psql password of the ${name} user"; type = str; };
81 host = mkOption { description = "Host to access Redis"; type = str; };
82 port = mkOption { description = "Port to access Redis"; type = str; };
83 socket = mkOption { description = "Socket to access Redis"; type = path; };
85 description = "Attrs of db number. Each number should be unique to avoid collision!";
88 spiped_key = mkOption {
91 Key to use with spiped to make a secure channel to replication
95 description = "Predixy configuration. Unused yet";
98 read = mkOption { type = str; description = "Read password"; };
103 mkRedisOptions = name: mkOption {
104 description = "${name} redis configuration";
106 options = redisOptions // {
107 db = mkOption { description = "${name} database"; type = str; };
111 hostEnv = submodule {
114 description = "Host FQDN";
119 description = "List of e-mails that the server can be a sender of";
124 LDAP credentials for the host
128 password = mkOption { type = string; description = "Password for the LDAP connection"; };
129 dn = mkOption { type = string; description = "DN for the LDAP connection"; };
134 description = "subdomain and priority for MX server";
135 default = { enable = false; };
138 enable = mkEnableOption "Enable MX";
139 subdomain = mkOption { type = nullOr str; description = "Subdomain name (mx-*)"; };
140 priority = mkOption { type = nullOr str; description = "Priority"; };
146 attrs of ip4/ip6 grouped by section
148 type = attrsOf (submodule {
153 ip4 address of the host
157 type = listOf string;
160 ip6 addresses of the host
173 Attrs of servers information in the cluster (not necessarily handled by nixops)
176 type = attrsOf hostEnv;
178 hetznerCloud = mkOption {
180 Hetzner Cloud credential information
184 authToken = mkOption {
195 Hetzner credential information
199 user = mkOption { type = str; description = "User"; };
200 pass = mkOption { type = str; description = "Password"; };
206 sshd service credential information
212 LDAP credentials for cn=ssh,ou=services,dc=immae,dc=eu dn
216 password = mkOption { description = "Password"; type = str; };
225 non-standard reserved ports. Must be unique!
230 noDupl = x: builtins.length (builtins.attrValues x) == builtins.length (unique (builtins.attrValues x));
232 x: if isAttrs x && noDupl x then x else throw "Non unique values for ports";
236 httpd service credential information
242 LDAP credentials for cn=httpd,ou=services,dc=immae,dc=eu dn
246 password = mkOption { description = "Password"; type = str; };
255 LDAP server configuration
258 options = ldapOptions;
261 databases = mkOption {
262 description = "Databases configuration";
266 type = submodule { options = mysqlOptions; };
267 description = "Mysql configuration";
270 type = submodule { options = redisOptions; };
271 description = "Redis configuration";
273 postgresql = mkOption {
274 type = submodule { options = psqlOptions; };
275 description = "Postgresql configuration";
281 description = "Jabber configuration";
284 postfix_user_filter = mkOption { type = str; description = "Postfix filter to get xmpp users"; };
285 ldap = mkLdapOptions "Jabber" {};
286 postgresql = mkPsqlOptions "Jabber";
291 description = "System and regular users uid/gid";
292 type = attrsOf (submodule {
295 description = "user uid";
299 description = "user gid";
306 description = "DNS configuration";
310 description = "SOA information";
314 description = "Serial number. Should be incremented at each change and unique";
318 description = "Refresh time";
322 description = "Retry time";
326 description = "Expire time";
330 description = "Default TTL time";
334 description = "hostmaster e-mail";
338 description = "Primary NS";
345 description = "Attrs of NS servers group";
348 "ns1.foo.com" = [ "198.51.100.10" "2001:db8:abcd::1" ];
349 "ns2.foo.com" = [ "198.51.100.15" "2001:db8:1234::1" ];
352 type = attrsOf (attrsOf (listOf str));
354 slaveZones = mkOption {
355 description = "List of slave zones";
356 type = listOf (submodule {
358 name = mkOption { type = str; description = "zone name"; };
360 description = "NS master groups of this zone";
366 masterZones = mkOption {
367 description = "List of master zones";
368 type = listOf (submodule {
370 name = mkOption { type = str; description = "zone name"; };
372 description = "NS slave groups of this zone";
376 description = "groups names that should have their NS entries listed here";
380 description = "Extra zone configuration for bind";
386 entries = mkOption { type = lines; description = "Regular entries of the NS zone"; };
387 withEmail = mkOption {
388 description = "List of domains that should have mail entries (MX, dkim, SPF, ...)";
390 type = listOf (submodule {
392 domain = mkOption { type = str; description = "Which subdomain is concerned"; };
393 send = mkOption { type = bool; description = "Whether there can be e-mails originating from the subdomain"; };
394 receive = mkOption { type = bool; description = "Whether there can be e-mails arriving to the subdomain"; };
406 Remote backup with duplicity
410 password = mkOption { type = str; description = "Password for encrypting files"; };
411 remote = mkOption { type = str; description = "Remote url access"; };
412 accessKeyId = mkOption { type = str; description = "Remote access-key"; };
413 secretAccessKey = mkOption { type = str; description = "Remote access secret"; };
417 rsync_backup = mkOption {
419 Rsync backup configuration from controlled host
423 mailto = mkOption { type = str; description = "Where to e-mail on error"; };
425 description = "SSH key information";
428 public = mkOption { type = str; description = "Public part of the key"; };
429 private = mkOption { type = lines; description = "Private part of the key"; };
433 profiles = mkOption {
434 description = "Attrs of profiles to backup";
435 type = attrsOf (submodule {
437 keep = mkOption { type = int; description = "Number of backups to keep"; };
438 login = mkOption { type = str; description = "Login to connect to host"; };
439 port = mkOption { type = str; default = "22"; description = "Port to connect to host"; };
440 host = mkOption { type = str; description = "Host to connect to"; };
441 host_key = mkOption { type = str; description = "Host key"; };
442 host_key_type = mkOption { type = str; description = "Host key type"; };
444 description = "Parts to backup for this host";
445 type = attrsOf (submodule {
447 remote_folder = mkOption { type = path; description = "Remote folder to backup";};
448 exclude_from = mkOption {
451 description = "List of folders/files to exclude from the backup";
453 files_from = mkOption {
456 description = "List of folders/files to backup in the base folder";
461 description = "Extra arguments to pass to rsync";
472 monitoring = mkOption {
473 description = "Monitoring configuration";
476 status_url = mkOption { type = str; description = "URL to push status to"; };
477 status_token = mkOption { type = str; description = "Token for the status url"; };
478 http_user_password = mkOption { type = str; description = "HTTP credentials to check services behind wall"; };
479 email = mkOption { type = str; description = "Admin E-mail"; };
480 ssh_public_key = mkOption { type = str; description = "SSH public key"; };
481 ssh_secret_key = mkOption { type = str; description = "SSH secret key"; };
482 imap_login = mkOption { type = str; description = "IMAP login"; };
483 imap_password = mkOption { type = str; description = "IMAP password"; };
484 nrdp_tokens = mkOption { type = listOf str; description = "Tokens allowed to push status update"; };
485 slack_url = mkOption { type = str; description = "Slack webhook url to push status update"; };
486 slack_channel = mkOption { type = str; description = "Slack channel to push status update"; };
487 contacts = mkOption { type = attrsOf unspecified; description = "Contact dicts to fill naemon objects"; };
492 description = "MPD configuration";
495 folder = mkOption { type = str; description = "Folder to serve from the MPD instance"; };
496 password = mkOption { type = str; description = "Password to connect to the MPD instance"; };
497 host = mkOption { type = str; description = "Host to connect to the MPD instance"; };
498 port = mkOption { type = str; description = "Port to connect to the MPD instance"; };
503 description = "FTP configuration";
506 ldap = mkLdapOptions "FTP" {};
511 description = "Mail configuration";
515 description = "DMARC configuration";
518 ignore_hosts = mkOption {
521 Hosts to ignore when checking for dmarc
528 description = "DKIM configuration";
529 type = attrsOf (submodule {
535 "p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC3w1a2aMxWw9+hdcmbqX4UevcVqr204y0K73Wdc7MPZiOOlUJQYsMNSYR1Y/SC7jmPKeitpcJCpQgn/cveJZbuikjjPLsDReHyFEYmC278ZLRTELHx6f1IXM8WE08JIRT69CfZiMi1rVcOh9qRT4F93PyjCauU8Y5hJjtg9ThsWwIDAQAB" )
537 description = "Public entry to put in DNS TXT field";
539 private = mkOption { type = str; description = "Private key"; };
544 description = "Postfix configuration";
547 additional_mailbox_domains = mkOption {
549 List of domains that are used as mailbox final destination, in addition to those defined in the DNS records
553 mysql = mkMysqlOptions "Postfix" {
554 password_encrypt = mkOption { type = str; description = "Key to encrypt relay password in database"; };
556 backup_domains = mkOption {
558 Domains that are accepted for relay as backup domain
560 type = attrsOf (submodule {
562 domains = mkOption { type = listOf str; description = "Domains list"; };
563 relay_restrictions = mkOption {
566 Restrictions for relaying the e-mails from the domains
569 recipient_maps = mkOption {
571 Recipient map to accept relay for.
572 Must be specified for domain, the rules apply to everyone!
574 type = listOf (submodule {
577 type = enum [ "hash" ];
578 description = "Map type";
582 description = "Map content";
594 description = "Dovecot configuration";
597 ldap = mkLdapOptions "Dovecot" {
598 pass_attrs = mkOption { type = str; description = "Password attribute in LDAP"; };
599 user_attrs = mkOption { type = str; description = "User attribute mapping in LDAP"; };
600 iterate_attrs = mkOption { type = str; description = "User attribute mapping for listing in LDAP"; };
601 iterate_filter = mkOption { type = str; description = "User attribute filter for listing in LDAP"; };
607 description = "rspamd configuration";
610 redis = mkRedisOptions "Redis";
611 read_password_hashed = mkOption { type = str; description = "Hashed read password for rspamd"; };
612 write_password_hashed = mkOption { type = str; description = "Hashed write password for rspamd"; };
613 read_password = mkOption {
615 description = "Read password for rspamd. Unused";
618 write_password = mkOption {
620 description = "Write password for rspamd. Unused";
627 description = "Mail script recipients";
628 type = attrsOf (submodule {
630 external = mkEnableOption "Create a script_<name>@mail.immae.eu external address";
633 git source to fetch the script from.
634 It must have a default.nix file as its root accepting a scriptEnv parameter
638 url = mkOption { type = str; description = "git url to fetch"; };
639 rev = mkOption { type = str; description = "git reference to fetch"; };
644 description = "Variables to pass to the script";
653 buildbot = mkOption {
654 description = "Buildbot configuration";
658 description = "Buildbot user";
662 description = "user uid";
666 description = "user gid";
673 description = "Ldap configuration for buildbot";
676 password = mkOption { type = str; description = "Buildbot password"; };
680 projects = mkOption {
681 description = "Projects to make a buildbot for";
682 type = attrsOf (submodule {
684 name = mkOption { type = str; description = "Project name"; };
685 packages = mkOption {
687 example = literalExample ''
688 pkgs: [ pkgs.bash pkgs.git pkgs.gzip pkgs.openssh ];
692 Builds packages list to make available to buildbot project.
693 Takes pkgs as argument.
696 pythonPackages = mkOption {
698 example = literalExample ''
699 p: pkgs: [ pkgs.python3Packages.pip ];
703 Builds python packages list to make available to buildbot project.
704 Takes buildbot python module as first argument and pkgs as second argument in order to augment the python modules list.
707 pythonPathHome = mkOption { type = bool; description = "Whether to add project’s python home to python path"; };
710 description = "Secrets for the project to dump as files";
712 environment = mkOption {
715 Environment variables for the project.
716 BUILDBOT_ is prefixed to the variable names
719 activationScript = mkOption {
722 Activation script to run during deployment
725 builderPaths = mkOption {
726 type = attrsOf unspecified;
729 Attrs of functions to make accessible specifically per builder.
730 Takes pkgs as argument and should return a single path containing binaries.
731 This path will be accessible as BUILDBOT_PATH_<attrskey>
734 webhookTokens = mkOption {
735 type = nullOr (listOf str);
738 List of tokens allowed to push to project’s change_hook/base endpoint
748 description = "Tools configurations";
752 description = "Davical configuration";
755 postgresql = mkPsqlOptions "Davical";
756 ldap = mkLdapOptions "Davical" {};
760 diaspora = mkOption {
761 description = "Diaspora configuration";
764 postgresql = mkPsqlOptions "Diaspora";
765 redis = mkRedisOptions "Diaspora";
766 ldap = mkLdapOptions "Diaspora" {};
767 secret_token = mkOption { type = str; description = "Secret token"; };
771 etherpad-lite = mkOption {
772 description = "Etherpad configuration";
775 postgresql = mkPsqlOptions "Etherpad";
776 ldap = mkLdapOptions "Etherpad" {
777 group_filter = mkOption { type = str; description = "Filter for groups"; };
779 session_key = mkOption { type = str; description = "Session key"; };
780 api_key = mkOption { type = str; description = "API key"; };
781 redirects = mkOption { type = str; description = "Redirects for apache"; };
785 gitolite = mkOption {
786 description = "Gitolite configuration";
789 ldap = mkLdapOptions "Gitolite" {};
793 kanboard = mkOption {
794 description = "Kanboard configuration";
797 postgresql = mkPsqlOptions "Kanboard";
798 ldap = mkLdapOptions "Kanboard" {
799 admin_dn = mkOption { type = str; description = "Admin DN"; };
804 mantisbt = mkOption {
805 description = "Mantisbt configuration";
808 postgresql = mkPsqlOptions "Mantisbt";
809 ldap = mkLdapOptions "Mantisbt" {};
810 master_salt = mkOption { type = str; description = "Master salt for password hash"; };
814 mastodon = mkOption {
815 description = "Mastodon configuration";
818 postgresql = mkPsqlOptions "Mastodon";
819 redis = mkRedisOptions "Mastodon";
820 ldap = mkLdapOptions "Mastodon" {};
821 paperclip_secret = mkOption { type = str; description = "Paperclip secret"; };
822 otp_secret = mkOption { type = str; description = "OTP secret"; };
823 secret_key_base = mkOption { type = str; description = "Secret key base"; };
825 description = "vapid key";
828 private = mkOption { type = str; description = "Private key"; };
829 public = mkOption { type = str; description = "Public key"; };
836 mediagoblin = mkOption {
837 description = "Mediagoblin configuration";
840 postgresql = mkPsqlOptions "Mediagoblin";
841 redis = mkRedisOptions "Mediagoblin";
842 ldap = mkLdapOptions "Mediagoblin" {};
846 nextcloud = mkOption {
847 description = "Nextcloud configuration";
850 postgresql = mkPsqlOptions "Peertube";
851 redis = mkRedisOptions "Peertube";
852 password_salt = mkOption { type = str; description = "Password salt"; };
853 instance_id = mkOption { type = str; description = "Instance ID"; };
854 secret = mkOption { type = str; description = "App secret"; };
858 peertube = mkOption {
859 description = "Peertube configuration";
862 listenPort = mkOption { type = port; description = "Port to listen to"; };
863 postgresql = mkPsqlOptions "Peertube";
864 redis = mkRedisOptions "Peertube";
865 ldap = mkLdapOptions "Peertube" {};
869 phpldapadmin = mkOption {
870 description = "phpLdapAdmin configuration";
873 ldap = mkLdapOptions "phpldapadmin" {};
878 description = "Rompr configuration";
882 description = "MPD configuration";
885 host = mkOption { type = str; description = "Host for MPD"; };
886 port = mkOption { type = port; description = "Port to access MPD host"; };
893 roundcubemail = mkOption {
894 description = "Roundcubemail configuration";
897 postgresql = mkPsqlOptions "TT-RSS";
898 secret = mkOption { type = str; description = "Secret"; };
903 description = "Shaarli configuration";
906 ldap = mkLdapOptions "Shaarli" {};
911 description = "Taskwarrior configuration";
914 ldap = mkLdapOptions "Taskwarrior" {};
915 taskwarrior-web = mkOption {
916 description = "taskwarrior-web profiles";
917 type = attrsOf (submodule {
921 description = "List of ldap uids having access to this profile";
923 org = mkOption { type = str; description = "Taskd organisation"; };
924 key = mkOption { type = str; description = "Taskd key"; };
925 date = mkOption { type = str; description = "Preferred date format"; };
933 description = "TT-RSS configuration";
936 postgresql = mkPsqlOptions "TT-RSS";
937 ldap = mkLdapOptions "TT-RSS" {};
941 wallabag = mkOption {
942 description = "Wallabag configuration";
945 postgresql = mkPsqlOptions "Wallabag";
946 ldap = mkLdapOptions "Wallabag" {
947 admin_filter = mkOption { type = str; description = "Admin users filter"; };
949 redis = mkRedisOptions "Wallabag";
950 secret = mkOption { type = str; description = "App secret"; };
955 description = "Ympd configuration";
958 listenPort = mkOption { type = port; description = "Port to listen to"; };
960 description = "MPD configuration";
963 password = mkOption { type = str; description = "Password to access MPD host"; };
964 host = mkOption { type = str; description = "Host for MPD"; };
965 port = mkOption { type = port; description = "Port to access MPD host"; };
973 description = "Yourls configuration";
976 mysql = mkMysqlOptions "Yourls" {};
977 ldap = mkLdapOptions "Yourls" {};
978 cookieKey = mkOption { type = str; description = "Cookie key"; };
985 websites = mkOption {
986 description = "Websites configurations";
989 isabelle = mkOption {
990 description = "Isabelle configurations by environment";
993 atenSubmodule = mkOption {
994 description = "environment configuration";
997 environment = mkOption { type = str; description = "Symfony environment"; };
998 secret = mkOption { type = str; description = "Symfony App secret"; };
999 postgresql = mkPsqlOptions "Aten";
1006 aten_production = atenSubmodule;
1007 aten_integration = atenSubmodule;
1008 iridologie = mkOption {
1009 description = "environment configuration";
1012 environment = mkOption { type = str; description = "SPIP environment"; };
1013 mysql = mkMysqlOptions "Iridologie" {};
1014 ldap = mkLdapOptions "Iridologie" {};
1022 description = "Chloe configurations by environment";
1025 chloeSubmodule = mkOption {
1026 description = "environment configuration";
1029 environment = mkOption { type = str; description = "SPIP environment"; };
1030 mysql = mkMysqlOptions "Chloe" {};
1031 ldap = mkLdapOptions "Chloe" {};
1038 production = chloeSubmodule;
1039 integration = chloeSubmodule;
1043 connexionswing = mkOption {
1044 description = "Connexionswing configurations by environment";
1047 csSubmodule = mkOption {
1048 description = "environment configuration";
1051 environment = mkOption { type = str; description = "Symfony environment"; };
1052 mysql = mkMysqlOptions "Connexionswing" {};
1053 secret = mkOption { type = str; description = "Symfony App secret"; };
1054 email = mkOption { type = str; description = "Symfony email notification"; };
1061 production = csSubmodule;
1062 integration = csSubmodule;
1067 description = "Naturaloutil configuration";
1070 mysql = mkMysqlOptions "Naturaloutil" {};
1071 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1075 telioTortay = mkOption {
1076 description = "Telio Tortay configuration";
1079 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1083 ludivinecassal = mkOption {
1084 description = "Ludivinecassal configurations by environment";
1087 lcSubmodule = mkOption {
1088 description = "environment configuration";
1091 environment = mkOption { type = str; description = "Symfony environment"; };
1092 mysql = mkMysqlOptions "LudivineCassal" {};
1093 ldap = mkLdapOptions "LudivineCassal" {};
1094 secret = mkOption { type = str; description = "Symfony App secret"; };
1101 production = lcSubmodule;
1102 integration = lcSubmodule;
1107 description = "Emilia configuration";
1110 postgresql = mkPsqlOptions "Emilia";
1114 florian = mkOption {
1115 description = "Florian configuration";
1118 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1122 nassime = mkOption {
1123 description = "Nassime configuration";
1126 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1130 piedsjaloux = mkOption {
1131 description = "Piedsjaloux configurations by environment";
1134 pjSubmodule = mkOption {
1135 description = "environment configuration";
1138 environment = mkOption { type = str; description = "Symfony environment"; };
1139 mysql = mkMysqlOptions "Piedsjaloux" {};
1140 secret = mkOption { type = str; description = "Symfony App secret"; };
1147 production = pjSubmodule;
1148 integration = pjSubmodule;
1153 description = "Europe Richie configurations by environment";
1156 mysql = mkMysqlOptions "Richie" {};
1157 smtp_mailer = mkOption {
1158 description = "SMTP mailer configuration";
1161 user = mkOption { type = str; description = "Username"; };
1162 password = mkOption { type = str; description = "Password"; };
1169 tellesflorian = mkOption {
1170 description = "Tellesflorian configurations by environment";
1173 tfSubmodule = mkOption {
1174 description = "environment configuration";
1177 environment = mkOption { type = str; description = "Symfony environment"; };
1178 mysql = mkMysqlOptions "Tellesflorian" {};
1179 secret = mkOption { type = str; description = "Symfony App secret"; };
1180 invite_passwords = mkOption { type = str; description = "Password basic auth"; };
1187 integration = tfSubmodule;
1195 privateFiles = mkOption {
1198 Path to secret files to make available during build
1202 options.hostEnv = mkOption {
1205 default = config.myEnv.servers."${name}";
1206 description = "Host environment";