1 { config, lib, name, ... }:
7 base = mkOption { description = "Base of the LDAP tree"; type = str; };
8 host = mkOption { description = "Host to access LDAP"; type = str; };
9 root_dn = mkOption { description = "DN of the root user"; type = str; };
10 root_pw = mkOption { description = "Hashed password of the root user"; type = str; };
11 replication_dn = mkOption { description = "DN of the user allowed to replicate the LDAP directory"; type = str; };
12 replication_pw = mkOption { description = "Password of the user allowed to replicate the LDAP directory"; type = str; };
14 mkLdapOptions = name: more: mkOption {
15 description = "${name} LDAP configuration";
17 options = ldapOptions // {
18 dn = mkOption { description = "DN of the ${name} user"; type = str; };
19 password = mkOption { description = "password of the ${name} user"; type = str; };
20 filter = mkOption { description = "Filter for ${name} users"; type = str; default = ""; };
25 host = mkOption { description = "Host to access Mysql"; type = str; };
26 remoteHost = mkOption { description = "Host to access Mysql from outside"; type = str; };
27 port = mkOption { description = "Port to access Mysql"; type = str; };
28 socket = mkOption { description = "Socket to access Mysql"; type = path; };
29 systemUsers = mkOption {
30 description = "Attrs of user-passwords allowed to access mysql";
34 description = "PAM configuration for mysql";
37 dn = mkOption { description = "DN to connect as to check users"; type = str; };
38 password = mkOption { description = "DN password to connect as to check users"; type = str; };
39 filter = mkOption { description = "filter to match users"; type = str; };
44 mkMysqlOptions = name: more: mkOption {
45 description = "${name} mysql configuration";
47 options = mysqlOptions // {
48 database = mkOption { description = "${name} database"; type = str; };
49 user = mkOption { description = "${name} user"; type = str; };
50 password = mkOption { description = "mysql password of the ${name} user"; type = str; };
55 host = mkOption { description = "Host to access Postgresql"; type = str; };
56 port = mkOption { description = "Port to access Postgresql"; type = str; };
57 socket = mkOption { description = "Socket to access Postgresql"; type = path; };
59 description = "PAM configuration for psql";
62 dn = mkOption { description = "DN to connect as to check users"; type = str; };
63 password = mkOption { description = "DN password to connect as to check users"; type = str; };
64 filter = mkOption { description = "filter to match users"; type = str; };
69 mkPsqlOptions = name: mkOption {
70 description = "${name} psql configuration";
72 options = psqlOptions // {
73 database = mkOption { description = "${name} database"; type = str; };
74 schema = mkOption { description = "${name} schema"; type = nullOr str; default = null; };
75 user = mkOption { description = "${name} user"; type = str; };
76 password = mkOption { description = "psql password of the ${name} user"; type = str; };
81 host = mkOption { description = "Host to access Redis"; type = str; };
82 port = mkOption { description = "Port to access Redis"; type = str; };
83 socket = mkOption { description = "Socket to access Redis"; type = path; };
85 description = "Attrs of db number. Each number should be unique to avoid collision!";
88 spiped_key = mkOption {
91 Key to use with spiped to make a secure channel to replication
95 description = "Predixy configuration. Unused yet";
98 read = mkOption { type = str; description = "Read password"; };
103 mkRedisOptions = name: mkOption {
104 description = "${name} redis configuration";
106 options = redisOptions // {
107 db = mkOption { description = "${name} database"; type = str; };
112 host = mkOption { description = "Host to access SMTP"; type = str; };
113 port = mkOption { description = "Port to access SMTP"; type = str; };
115 mkSmtpOptions = name: mkOption {
116 description = "${name} smtp configuration";
118 options = smtpOptions // {
119 email = mkOption { description = "${name} email"; type = str; };
120 password = mkOption { description = "SMTP password of the ${name} user"; type = str; };
124 hostEnv = submodule {
127 description = "Host FQDN";
134 Sublist of users from realUsers. Function that takes pkgs as
135 argument and gives an array as a result
140 description = "List of e-mails that the server can be a sender of";
145 LDAP credentials for the host
149 password = mkOption { type = str; description = "Password for the LDAP connection"; };
150 dn = mkOption { type = str; description = "DN for the LDAP connection"; };
155 description = "subdomain and priority for MX server";
156 default = { enable = false; };
159 enable = mkEnableOption "Enable MX";
160 subdomain = mkOption { type = nullOr str; description = "Subdomain name (mx-*)"; };
161 priority = mkOption { type = nullOr str; description = "Priority"; };
167 attrs of ip4/ip6 grouped by section
169 type = attrsOf (submodule {
174 ip4 address of the host
181 ip6 addresses of the host
194 Attrs of servers information in the cluster (not necessarily handled by nixops)
197 type = attrsOf hostEnv;
199 hetznerCloud = mkOption {
201 Hetzner Cloud credential information
205 authToken = mkOption {
216 Hetzner credential information
220 user = mkOption { type = str; description = "User"; };
221 pass = mkOption { type = str; description = "Password"; };
227 sshd service credential information
231 rootKeys = mkOption { type = attrsOf str; description = "Keys of root users"; };
234 LDAP credentials for cn=ssh,ou=services,dc=immae,dc=eu dn
238 password = mkOption { description = "Password"; type = str; };
247 non-standard reserved ports. Must be unique!
252 noDupl = x: builtins.length (builtins.attrValues x) == builtins.length (unique (builtins.attrValues x));
254 x: if isAttrs x && noDupl x then x else throw "Non unique values for ports";
258 httpd service credential information
264 LDAP credentials for cn=httpd,ou=services,dc=immae,dc=eu dn
268 password = mkOption { description = "Password"; type = str; };
276 type = submodule { options = smtpOptions; };
277 description = "SMTP configuration";
281 LDAP server configuration
284 options = ldapOptions;
287 databases = mkOption {
288 description = "Databases configuration";
292 type = submodule { options = mysqlOptions; };
293 description = "Mysql configuration";
296 type = submodule { options = redisOptions; };
297 description = "Redis configuration";
299 postgresql = mkOption {
300 type = submodule { options = psqlOptions; };
301 description = "Postgresql configuration";
307 description = "Jabber configuration";
310 postfix_user_filter = mkOption { type = str; description = "Postfix filter to get xmpp users"; };
311 ldap = mkLdapOptions "Jabber" {};
312 postgresql = mkPsqlOptions "Jabber";
316 realUsers = mkOption {
318 Attrset of function taking pkgs as argument.
319 Real users settings, should provide a subattr of users.users.<name>
320 with at least: name, (hashed)Password, shell
322 type = attrsOf unspecified;
325 description = "System and regular users uid/gid";
326 type = attrsOf (submodule {
329 description = "user uid";
333 description = "user gid";
340 description = "DNS configuration";
344 description = "SOA information";
348 description = "Serial number. Should be incremented at each change and unique";
352 description = "Refresh time";
356 description = "Retry time";
360 description = "Expire time";
364 description = "Default TTL time";
368 description = "hostmaster e-mail";
372 description = "Primary NS";
379 description = "Attrs of NS servers group";
382 "ns1.foo.com" = [ "198.51.100.10" "2001:db8:abcd::1" ];
383 "ns2.foo.com" = [ "198.51.100.15" "2001:db8:1234::1" ];
386 type = attrsOf (attrsOf (listOf str));
390 description = "DNS keys";
391 type = attrsOf (submodule {
393 algorithm = mkOption { type = str; description = "Algorithm"; };
394 secret = mkOption { type = str; description = "Secret"; };
398 slaveZones = mkOption {
399 description = "List of slave zones";
400 type = listOf (submodule {
402 name = mkOption { type = str; description = "zone name"; };
404 description = "NS master groups of this zone";
409 description = "Keys associated to the server";
415 masterZones = mkOption {
416 description = "List of master zones";
417 type = listOf (submodule {
419 name = mkOption { type = str; description = "zone name"; };
420 withCAA = mkOption { type = nullOr str; description = "CAA entry"; default = null; };
422 description = "NS slave groups of this zone";
426 description = "groups names that should have their NS entries listed here";
430 description = "Extra zone configuration for bind";
436 entries = mkOption { type = lines; description = "Regular entries of the NS zone"; };
437 withEmail = mkOption {
438 description = "List of domains that should have mail entries (MX, dkim, SPF, ...)";
440 type = listOf (submodule {
442 domain = mkOption { type = str; description = "Which subdomain is concerned"; };
443 send = mkOption { type = bool; description = "Whether there can be e-mails originating from the subdomain"; };
444 receive = mkOption { type = bool; description = "Whether there can be e-mails arriving to the subdomain"; };
456 Remote backup with duplicity
460 password = mkOption { type = str; description = "Password for encrypting files"; };
462 type = attrsOf (submodule {
466 example = literalExample ''
467 bucket: "s3://some_host/${bucket}";
471 Takes a bucket name as argument and returns a url
474 accessKeyId = mkOption { type = str; description = "Remote access-key"; };
475 secretAccessKey = mkOption { type = str; description = "Remote access secret"; };
482 zrepl_backup = mkOption {
486 description = "SSH key information";
489 public = mkOption { type = str; description = "Public part of the key"; };
490 private = mkOption { type = lines; description = "Private part of the key"; };
494 mysql = mkMysqlOptions "Zrepl" {};
498 rsync_backup = mkOption {
500 Rsync backup configuration from controlled host
505 description = "SSH key information";
508 public = mkOption { type = str; description = "Public part of the key"; };
509 private = mkOption { type = lines; description = "Private part of the key"; };
513 profiles = mkOption {
514 description = "Attrs of profiles to backup";
515 type = attrsOf (submodule {
517 keep = mkOption { type = int; description = "Number of backups to keep"; };
518 check_command = mkOption { type = str; description = "command to check if backup needs to be done"; default = "backup"; };
519 login = mkOption { type = str; description = "Login to connect to host"; };
520 port = mkOption { type = str; default = "22"; description = "Port to connect to host"; };
521 host = mkOption { type = str; description = "Host to connect to"; };
522 host_key = mkOption { type = str; description = "Host key"; };
523 host_key_type = mkOption { type = str; description = "Host key type"; };
525 description = "Parts to backup for this host";
526 type = attrsOf (submodule {
528 remote_folder = mkOption { type = path; description = "Remote folder to backup";};
529 exclude_from = mkOption {
532 description = "List of folders/files to exclude from the backup";
534 files_from = mkOption {
537 description = "List of folders/files to backup in the base folder";
542 description = "Extra arguments to pass to rsync";
553 monitoring = mkOption {
554 description = "Monitoring configuration";
557 status_url = mkOption { type = str; description = "URL to push status to"; };
558 status_token = mkOption { type = str; description = "Token for the status url"; };
559 http_user_password = mkOption { type = str; description = "HTTP credentials to check services behind wall"; };
560 email = mkOption { type = str; description = "Admin E-mail"; };
561 ssh_public_key = mkOption { type = str; description = "SSH public key"; };
562 ssh_secret_key = mkOption { type = str; description = "SSH secret key"; };
563 imap_login = mkOption { type = str; description = "IMAP login"; };
564 imap_password = mkOption { type = str; description = "IMAP password"; };
565 eriomem_keys = mkOption { type = listOf (listOf str); description = "Eriomem keys"; default = []; };
567 description = "OVH credentials for sms script";
570 endpoint = mkOption { type = str; default = "ovh-eu"; description = "OVH endpoint"; };
571 application_key = mkOption { type = str; description = "Application key"; };
572 application_secret = mkOption { type = str; description = "Application secret"; };
573 consumer_key = mkOption { type = str; description = "Consumer key"; };
574 account = mkOption { type = str; description = "Account"; };
579 description = "Eban credentials for webhook";
582 user = mkOption { type = str; description = "User"; };
583 password = mkOption { type = str; description = "Password"; };
587 nrdp_tokens = mkOption { type = listOf str; description = "Tokens allowed to push status update"; };
588 slack_url = mkOption { type = str; description = "Slack webhook url to push status update"; };
589 slack_channel = mkOption { type = str; description = "Slack channel to push status update"; };
590 netdata_aggregator = mkOption { type = str; description = "Url where netdata information should be sent"; };
591 netdata_keys = mkOption { type = attrsOf str; description = "netdata host keys"; };
592 contacts = mkOption { type = attrsOf unspecified; description = "Contact dicts to fill naemon objects"; };
593 email_check = mkOption {
594 description = "Emails services to check";
595 type = attrsOf (submodule {
597 local = mkOption { type = bool; default = false; description = "Use local configuration"; };
598 port = mkOption { type = nullOr str; default = null; description = "Port to connect to ssh"; };
599 login = mkOption { type = nullOr str; default = null; description = "Login to connect to ssh"; };
600 targets = mkOption { type = listOf str; description = "Hosts to send E-mails to"; };
601 mail_address = mkOption { type = nullOr str; default = null; description = "E-mail recipient part to send e-mail to"; };
602 mail_domain = mkOption { type = nullOr str; default = null; description = "E-mail domain part to send e-mail to"; };
610 description = "MPD configuration";
613 folder = mkOption { type = str; description = "Folder to serve from the MPD instance"; };
614 password = mkOption { type = str; description = "Password to connect to the MPD instance"; };
615 host = mkOption { type = str; description = "Host to connect to the MPD instance"; };
616 port = mkOption { type = str; description = "Port to connect to the MPD instance"; };
621 description = "FTP configuration";
624 ldap = mkLdapOptions "FTP" {
625 proftpd_filter = mkOption { type = str; description = "Filter for proftpd listing in LDAP"; };
626 pure-ftpd_filter = mkOption { type = str; description = "Filter for pure-ftpd listing in LDAP"; };
632 description = "VPN configuration";
633 type = attrsOf (submodule {
635 prefix = mkOption { type = str; description = "ipv6 prefix for the vpn subnet"; };
636 privateKey = mkOption { type = str; description = "Private key for the host"; };
637 publicKey = mkOption { type = str; description = "Public key for the host"; };
642 description = "Mail configuration";
646 description = "DMARC configuration";
649 ignore_hosts = mkOption {
652 Hosts to ignore when checking for dmarc
659 description = "DKIM configuration";
660 type = attrsOf (submodule {
666 "p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC3w1a2aMxWw9+hdcmbqX4UevcVqr204y0K73Wdc7MPZiOOlUJQYsMNSYR1Y/SC7jmPKeitpcJCpQgn/cveJZbuikjjPLsDReHyFEYmC278ZLRTELHx6f1IXM8WE08JIRT69CfZiMi1rVcOh9qRT4F93PyjCauU8Y5hJjtg9ThsWwIDAQAB" )
668 description = "Public entry to put in DNS TXT field";
670 private = mkOption { type = str; description = "Private key"; };
675 description = "Postfix configuration";
678 additional_mailbox_domains = mkOption {
680 List of domains that are used as mailbox final destination, in addition to those defined in the DNS records
684 mysql = mkMysqlOptions "Postfix" {
685 password_encrypt = mkOption { type = str; description = "Key to encrypt relay password in database"; };
687 backup_domains = mkOption {
689 Domains that are accepted for relay as backup domain
691 type = attrsOf (submodule {
693 domains = mkOption { type = listOf str; description = "Domains list"; };
694 relay_restrictions = mkOption {
697 Restrictions for relaying the e-mails from the domains
700 recipient_maps = mkOption {
702 Recipient map to accept relay for.
703 Must be specified for domain, the rules apply to everyone!
705 type = listOf (submodule {
708 type = enum [ "hash" ];
709 description = "Map type";
713 description = "Map content";
725 description = "Dovecot configuration";
728 ldap = mkLdapOptions "Dovecot" {
729 pass_attrs = mkOption { type = str; description = "Password attribute in LDAP"; };
730 user_attrs = mkOption { type = str; description = "User attribute mapping in LDAP"; };
731 iterate_attrs = mkOption { type = str; description = "User attribute mapping for listing in LDAP"; };
732 iterate_filter = mkOption { type = str; description = "User attribute filter for listing in LDAP"; };
733 postfix_mailbox_filter = mkOption { type = str; description = "Postfix filter to get mailboxes"; };
739 description = "rspamd configuration";
742 redis = mkRedisOptions "Redis";
743 read_password_hashed = mkOption { type = str; description = "Hashed read password for rspamd"; };
744 write_password_hashed = mkOption { type = str; description = "Hashed write password for rspamd"; };
745 read_password = mkOption {
747 description = "Read password for rspamd. Unused";
750 write_password = mkOption {
752 description = "Write password for rspamd. Unused";
759 description = "Mail script recipients";
760 type = attrsOf (submodule {
762 external = mkEnableOption "Create a script_<name>@mail.immae.eu external address";
765 git source to fetch the script from.
766 It must have a default.nix file as its root accepting a scriptEnv parameter
770 url = mkOption { type = str; description = "git url to fetch"; };
771 rev = mkOption { type = str; description = "git reference to fetch"; };
776 description = "Variables to pass to the script";
783 description = "Sympa configuration";
786 listmasters = mkOption {
788 description = "Listmasters";
790 postgresql = mkPsqlOptions "Sympa";
791 data_sources = mkOption {
794 description = "Data sources to make available to sympa";
799 description = "Scenari to make available to sympa";
807 buildbot = mkOption {
808 description = "Buildbot configuration";
812 description = "SSH key information";
815 public = mkOption { type = str; description = "Public part of the key"; };
816 private = mkOption { type = lines; description = "Private part of the key"; };
820 workerPassword = mkOption { description = "Buildbot worker password"; type = str; };
822 description = "Buildbot user";
826 description = "user uid";
830 description = "user gid";
837 description = "Ldap configuration for buildbot";
840 password = mkOption { type = str; description = "Buildbot password"; };
844 projects = mkOption {
845 description = "Projects to make a buildbot for";
846 type = attrsOf (submodule {
848 name = mkOption { type = str; description = "Project name"; };
849 packages = mkOption {
851 example = literalExample ''
852 pkgs: [ pkgs.bash pkgs.git pkgs.gzip pkgs.openssh ];
856 Builds packages list to make available to buildbot project.
857 Takes pkgs as argument.
860 pythonPackages = mkOption {
862 example = literalExample ''
863 p: pkgs: [ pkgs.python3Packages.pip ];
867 Builds python packages list to make available to buildbot project.
868 Takes buildbot python module as first argument and pkgs as second argument in order to augment the python modules list.
871 pythonPathHome = mkOption { type = bool; description = "Whether to add project’s python home to python path"; };
872 workerPort = mkOption { type = port; description = "Port for the worker"; };
875 description = "Secrets for the project to dump as files";
877 environment = mkOption {
880 Environment variables for the project.
881 BUILDBOT_ is prefixed to the variable names
884 activationScript = mkOption {
887 Activation script to run during deployment
890 builderPaths = mkOption {
891 type = attrsOf unspecified;
894 Attrs of functions to make accessible specifically per builder.
895 Takes pkgs as argument and should return a single path containing binaries.
896 This path will be accessible as BUILDBOT_PATH_<attrskey>
899 webhookTokens = mkOption {
900 type = nullOr (listOf str);
903 List of tokens allowed to push to project’s change_hook/base endpoint
913 description = "Tools configurations";
916 contact = mkOption { type = str; description = "Contact e-mail address"; };
919 type = attrsOf (submodule {
921 url = mkOption { type = str; description = "URL to fetch"; };
922 sha256 = mkOption { type = str; description = "Hash of the url"; };
925 description = "Assets to provide on assets.immae.eu";
928 description = "Davical configuration";
931 postgresql = mkPsqlOptions "Davical";
932 ldap = mkLdapOptions "Davical" {};
936 diaspora = mkOption {
937 description = "Diaspora configuration";
940 postgresql = mkPsqlOptions "Diaspora";
941 redis = mkRedisOptions "Diaspora";
942 ldap = mkLdapOptions "Diaspora" {};
943 secret_token = mkOption { type = str; description = "Secret token"; };
947 dmarc_reports = mkOption {
948 description = "DMARC reports configuration";
951 mysql = mkMysqlOptions "DMARC" {};
952 anonymous_key = mkOption { type = str; description = "Anonymous hashing key"; };
956 etherpad-lite = mkOption {
957 description = "Etherpad configuration";
960 postgresql = mkPsqlOptions "Etherpad";
961 ldap = mkLdapOptions "Etherpad" {
962 group_filter = mkOption { type = str; description = "Filter for groups"; };
964 adminPassword = mkOption { type = str; description = "Admin password for mypads / admin"; };
965 session_key = mkOption { type = str; description = "Session key"; };
966 api_key = mkOption { type = str; description = "API key"; };
967 redirects = mkOption { type = str; description = "Redirects for apache"; };
971 gitolite = mkOption {
972 description = "Gitolite configuration";
975 ldap = mkLdapOptions "Gitolite" {};
977 description = "SSH key information";
980 public = mkOption { type = str; description = "Public part of the key"; };
981 private = mkOption { type = lines; description = "Private part of the key"; };
988 kanboard = mkOption {
989 description = "Kanboard configuration";
992 postgresql = mkPsqlOptions "Kanboard";
993 ldap = mkLdapOptions "Kanboard" {
994 admin_dn = mkOption { type = str; description = "Admin DN"; };
999 mantisbt = mkOption {
1000 description = "Mantisbt configuration";
1003 postgresql = mkPsqlOptions "Mantisbt";
1004 ldap = mkLdapOptions "Mantisbt" {};
1005 master_salt = mkOption { type = str; description = "Master salt for password hash"; };
1009 mastodon = mkOption {
1010 description = "Mastodon configuration";
1013 postgresql = mkPsqlOptions "Mastodon";
1014 redis = mkRedisOptions "Mastodon";
1015 ldap = mkLdapOptions "Mastodon" {};
1016 paperclip_secret = mkOption { type = str; description = "Paperclip secret"; };
1017 otp_secret = mkOption { type = str; description = "OTP secret"; };
1018 secret_key_base = mkOption { type = str; description = "Secret key base"; };
1020 description = "vapid key";
1023 private = mkOption { type = str; description = "Private key"; };
1024 public = mkOption { type = str; description = "Public key"; };
1031 mediagoblin = mkOption {
1032 description = "Mediagoblin configuration";
1035 postgresql = mkPsqlOptions "Mediagoblin";
1036 redis = mkRedisOptions "Mediagoblin";
1037 ldap = mkLdapOptions "Mediagoblin" {};
1041 nextcloud = mkOption {
1042 description = "Nextcloud configuration";
1045 postgresql = mkPsqlOptions "Peertube";
1046 redis = mkRedisOptions "Peertube";
1047 password_salt = mkOption { type = str; description = "Password salt"; };
1048 instance_id = mkOption { type = str; description = "Instance ID"; };
1049 secret = mkOption { type = str; description = "App secret"; };
1053 peertube = mkOption {
1054 description = "Peertube configuration";
1057 listenPort = mkOption { type = port; description = "Port to listen to"; };
1058 postgresql = mkPsqlOptions "Peertube";
1059 redis = mkRedisOptions "Peertube";
1060 ldap = mkLdapOptions "Peertube" {};
1064 syden_peertube = mkOption {
1065 description = "Peertube Syden configuration";
1068 listenPort = mkOption { type = port; description = "Port to listen to"; };
1069 postgresql = mkPsqlOptions "Peertube";
1070 redis = mkRedisOptions "Peertube";
1074 phpldapadmin = mkOption {
1075 description = "phpLdapAdmin configuration";
1078 ldap = mkLdapOptions "phpldapadmin" {};
1083 description = "Rompr configuration";
1087 description = "MPD configuration";
1090 host = mkOption { type = str; description = "Host for MPD"; };
1091 port = mkOption { type = port; description = "Port to access MPD host"; };
1098 roundcubemail = mkOption {
1099 description = "Roundcubemail configuration";
1102 postgresql = mkPsqlOptions "TT-RSS";
1103 secret = mkOption { type = str; description = "Secret"; };
1107 shaarli = mkOption {
1108 description = "Shaarli configuration";
1111 ldap = mkLdapOptions "Shaarli" {};
1115 status_engine = mkOption {
1116 description = "Status Engine configuration";
1119 mysql = mkMysqlOptions "StatusEngine" {};
1120 ldap = mkLdapOptions "StatusEngine" {};
1125 description = "Taskwarrior configuration";
1128 ldap = mkLdapOptions "Taskwarrior" {};
1129 taskwarrior-web = mkOption {
1130 description = "taskwarrior-web profiles";
1131 type = attrsOf (submodule {
1135 description = "List of ldap uids having access to this profile";
1137 org = mkOption { type = str; description = "Taskd organisation"; };
1138 key = mkOption { type = str; description = "Taskd key"; };
1139 date = mkOption { type = str; description = "Preferred date format"; };
1147 description = "TT-RSS configuration";
1150 postgresql = mkPsqlOptions "TT-RSS";
1151 ldap = mkLdapOptions "TT-RSS" {};
1155 wallabag = mkOption {
1156 description = "Wallabag configuration";
1159 postgresql = mkPsqlOptions "Wallabag";
1160 ldap = mkLdapOptions "Wallabag" {
1161 admin_filter = mkOption { type = str; description = "Admin users filter"; };
1163 redis = mkRedisOptions "Wallabag";
1164 secret = mkOption { type = str; description = "App secret"; };
1168 webhooks = mkOption {
1170 description = "Mapping 'name'.php => script for webhooks";
1172 csp_reports = mkOption {
1173 description = "CSP report configuration";
1176 report_uri = mkOption { type = str; description = "URI to report CSP violations to"; };
1177 policies = mkOption { type = attrsOf str; description = "CSP policies to apply"; };
1178 postgresql = mkPsqlOptions "CSP reports";
1182 commento = mkOption {
1183 description = "Commento configuration";
1186 listenPort = mkOption { type = port; description = "Port to listen to"; };
1187 postgresql = mkPsqlOptions "Commento";
1188 smtp = mkSmtpOptions "Commento";
1192 cryptpad = mkOption {
1193 description = "Cryptpad configuration";
1194 type = attrsOf (submodule {
1196 email = mkOption { type = str; description = "Admin e-mail"; };
1197 admins = mkOption { type = listOf str; description = "Instance admin public keys"; };
1198 port = mkOption { type = port; description = "Port to listen to"; };
1203 description = "Ympd configuration";
1206 listenPort = mkOption { type = port; description = "Port to listen to"; };
1208 description = "MPD configuration";
1211 password = mkOption { type = str; description = "Password to access MPD host"; };
1212 host = mkOption { type = str; description = "Host for MPD"; };
1213 port = mkOption { type = port; description = "Port to access MPD host"; };
1221 description = "Umami configuration";
1224 listenPort = mkOption { type = port; description = "Port to listen to"; };
1225 postgresql = mkPsqlOptions "Umami";
1226 hashSalt = mkOption { type = str; description = "Hash salt"; };
1231 description = "Yourls configuration";
1234 mysql = mkMysqlOptions "Yourls" {};
1235 ldap = mkLdapOptions "Yourls" {};
1236 cookieKey = mkOption { type = str; description = "Cookie key"; };
1243 serverSpecific = mkOption { type = attrsOf unspecified; description = "Server specific configuration"; };
1244 websites = mkOption {
1245 description = "Websites configurations";
1248 christophe_carpentier = mkOption {
1249 description = "Christophe Carpentier configuration by environment";
1252 agorakit = mkOption {
1253 description = "Agorakit configuration";
1256 mysql = mkMysqlOptions "Agorakit" {};
1257 smtp = mkSmtpOptions "Agorakit";
1258 appkey = mkOption { type = str; description = "App key"; };
1266 description = "Immae configuration by environment";
1270 description = "Temp configuration";
1273 ldap = mkLdapOptions "Immae temp" {
1274 filter = mkOption { type = str; description = "Filter for user access"; };
1282 isabelle = mkOption {
1283 description = "Isabelle configurations by environment";
1286 atenSubmodule = mkOption {
1287 description = "environment configuration";
1290 environment = mkOption { type = str; description = "Symfony environment"; };
1291 secret = mkOption { type = str; description = "Symfony App secret"; };
1292 postgresql = mkPsqlOptions "Aten";
1299 aten_production = atenSubmodule;
1300 aten_integration = atenSubmodule;
1301 iridologie = mkOption {
1302 description = "environment configuration";
1305 environment = mkOption { type = str; description = "SPIP environment"; };
1306 mysql = mkMysqlOptions "Iridologie" {};
1307 ldap = mkLdapOptions "Iridologie" {};
1315 description = "Chloe configurations by environment";
1318 chloeSubmodule = mkOption {
1319 description = "environment configuration";
1322 environment = mkOption { type = str; description = "SPIP environment"; };
1323 mysql = mkMysqlOptions "Chloe" {};
1324 ldap = mkLdapOptions "Chloe" {};
1331 production = chloeSubmodule;
1332 integration = chloeSubmodule;
1336 connexionswing = mkOption {
1337 description = "Connexionswing configurations by environment";
1340 csSubmodule = mkOption {
1341 description = "environment configuration";
1344 environment = mkOption { type = str; description = "Symfony environment"; };
1345 mysql = mkMysqlOptions "Connexionswing" {};
1346 secret = mkOption { type = str; description = "Symfony App secret"; };
1347 email = mkOption { type = str; description = "Symfony email notification"; };
1354 production = csSubmodule;
1355 integration = csSubmodule;
1360 description = "Naturaloutil configuration";
1363 mysql = mkMysqlOptions "Naturaloutil" {};
1364 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1368 telio_tortay = mkOption {
1369 description = "Telio Tortay configuration";
1372 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1376 ludivine = mkOption {
1377 description = "Ludivinecassal configurations by environment";
1380 lcSubmodule = mkOption {
1381 description = "environment configuration";
1384 environment = mkOption { type = str; description = "Symfony environment"; };
1385 mysql = mkMysqlOptions "LudivineCassal" {};
1386 ldap = mkLdapOptions "LudivineCassal" {};
1387 secret = mkOption { type = str; description = "Symfony App secret"; };
1394 production = lcSubmodule;
1395 integration = lcSubmodule;
1399 nicecoop = mkOption {
1400 description = "Nicecoop configuration";
1404 port = mkOption { description = "Port to listen to"; type = port; };
1405 longpoll_port = mkOption { description = "Port to listen to"; type = port; };
1406 postgresql = mkPsqlOptions "Odoo";
1407 admin_password = mkOption { type = str; description = "Admin password"; };
1410 smtp = mkSmtpOptions "GestionCompte";
1411 mysql = mkMysqlOptions "gestion-compte" {};
1412 secret = mkOption { type = str; description = "Application secret"; };
1413 adminpassword = mkOption { type = str; description = "Admin password"; };
1415 gestion-compte-integration = {
1416 smtp = mkSmtpOptions "GestionCompte";
1417 mysql = mkMysqlOptions "gestion-compte" {};
1418 secret = mkOption { type = str; description = "Application secret"; };
1419 adminpassword = mkOption { type = str; description = "Admin password"; };
1422 smtp = mkSmtpOptions "Copanier";
1423 staff = mkOption { type = listOf str; description = "List of staff members"; };
1429 description = "Emilia configuration";
1432 postgresql = mkPsqlOptions "Emilia";
1436 florian = mkOption {
1437 description = "Florian configuration";
1440 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1444 nassime = mkOption {
1445 description = "Nassime configuration";
1448 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1452 piedsjaloux = mkOption {
1453 description = "Piedsjaloux configurations by environment";
1456 pjSubmodule = mkOption {
1457 description = "environment configuration";
1460 environment = mkOption { type = str; description = "Symfony environment"; };
1461 mysql = mkMysqlOptions "Piedsjaloux" {};
1462 secret = mkOption { type = str; description = "Symfony App secret"; };
1469 production = pjSubmodule;
1470 integration = pjSubmodule;
1475 description = "Europe Richie configurations by environment";
1478 mysql = mkMysqlOptions "Richie" {};
1479 smtp_mailer = mkOption {
1480 description = "SMTP mailer configuration";
1483 user = mkOption { type = str; description = "Username"; };
1484 password = mkOption { type = str; description = "Password"; };
1491 caldance = mkOption {
1492 description = "Caldance configurations by environment";
1495 integration = mkOption {
1496 description = "environment configuration";
1499 password = mkOption { type = str; description = "Password file content for basic auth"; };
1506 tellesflorian = mkOption {
1507 description = "Tellesflorian configurations by environment";
1510 tfSubmodule = mkOption {
1511 description = "environment configuration";
1514 environment = mkOption { type = str; description = "Symfony environment"; };
1515 mysql = mkMysqlOptions "Tellesflorian" {};
1516 secret = mkOption { type = str; description = "Symfony App secret"; };
1517 invite_passwords = mkOption { type = str; description = "Password basic auth"; };
1524 integration = tfSubmodule;
1532 options.hostEnv = mkOption {
1535 default = config.myEnv.servers."${name}";
1536 description = "Host environment";