1 { config, lib, name, ... }:
7 base = mkOption { description = "Base of the LDAP tree"; type = str; };
8 host = mkOption { description = "Host to access LDAP"; type = str; };
9 root_dn = mkOption { description = "DN of the root user"; type = str; };
10 root_pw = mkOption { description = "Hashed password of the root user"; type = str; };
11 replication_dn = mkOption { description = "DN of the user allowed to replicate the LDAP directory"; type = str; };
12 replication_pw = mkOption { description = "Password of the user allowed to replicate the LDAP directory"; type = str; };
14 mkLdapOptions = name: more: mkOption {
15 description = "${name} LDAP configuration";
17 options = ldapOptions // {
18 dn = mkOption { description = "DN of the ${name} user"; type = str; };
19 password = mkOption { description = "password of the ${name} user"; type = str; };
20 filter = mkOption { description = "Filter for ${name} users"; type = str; default = ""; };
25 host = mkOption { description = "Host to access Mysql"; type = str; };
26 remoteHost = mkOption { description = "Host to access Mysql from outside"; type = str; };
27 port = mkOption { description = "Port to access Mysql"; type = str; };
28 socket = mkOption { description = "Socket to access Mysql"; type = path; };
29 systemUsers = mkOption {
30 description = "Attrs of user-passwords allowed to access mysql";
34 description = "PAM configuration for mysql";
37 dn = mkOption { description = "DN to connect as to check users"; type = str; };
38 password = mkOption { description = "DN password to connect as to check users"; type = str; };
39 filter = mkOption { description = "filter to match users"; type = str; };
44 mkMysqlOptions = name: more: mkOption {
45 description = "${name} mysql configuration";
47 options = mysqlOptions // {
48 database = mkOption { description = "${name} database"; type = str; };
49 user = mkOption { description = "${name} user"; type = str; };
50 password = mkOption { description = "mysql password of the ${name} user"; type = str; };
55 host = mkOption { description = "Host to access Postgresql"; type = str; };
56 port = mkOption { description = "Port to access Postgresql"; type = str; };
57 socket = mkOption { description = "Socket to access Postgresql"; type = path; };
59 description = "PAM configuration for psql";
62 dn = mkOption { description = "DN to connect as to check users"; type = str; };
63 password = mkOption { description = "DN password to connect as to check users"; type = str; };
64 filter = mkOption { description = "filter to match users"; type = str; };
69 mkPsqlOptions = name: mkOption {
70 description = "${name} psql configuration";
72 options = psqlOptions // {
73 database = mkOption { description = "${name} database"; type = str; };
74 schema = mkOption { description = "${name} schema"; type = nullOr str; default = null; };
75 user = mkOption { description = "${name} user"; type = str; };
76 password = mkOption { description = "psql password of the ${name} user"; type = str; };
81 host = mkOption { description = "Host to access Redis"; type = str; };
82 port = mkOption { description = "Port to access Redis"; type = str; };
83 socket = mkOption { description = "Socket to access Redis"; type = path; };
85 description = "Attrs of db number. Each number should be unique to avoid collision!";
88 spiped_key = mkOption {
91 Key to use with spiped to make a secure channel to replication
95 description = "Predixy configuration. Unused yet";
98 read = mkOption { type = str; description = "Read password"; };
103 mkRedisOptions = name: mkOption {
104 description = "${name} redis configuration";
106 options = redisOptions // {
107 db = mkOption { description = "${name} database"; type = str; };
112 host = mkOption { description = "Host to access SMTP"; type = str; };
113 port = mkOption { description = "Port to access SMTP"; type = str; };
115 mkSmtpOptions = name: mkOption {
116 description = "${name} smtp configuration";
118 options = smtpOptions // {
119 email = mkOption { description = "${name} email"; type = str; };
120 password = mkOption { description = "SMTP password of the ${name} user"; type = str; };
124 hostEnv = submodule {
127 description = "Host FQDN";
134 Sublist of users from realUsers. Function that takes pkgs as
135 argument and gives an array as a result
140 description = "List of e-mails that the server can be a sender of";
145 LDAP credentials for the host
149 password = mkOption { type = str; description = "Password for the LDAP connection"; };
150 dn = mkOption { type = str; description = "DN for the LDAP connection"; };
155 description = "subdomain and priority for MX server";
156 default = { enable = false; };
159 enable = mkEnableOption "Enable MX";
160 subdomain = mkOption { type = nullOr str; description = "Subdomain name (mx-*)"; };
161 priority = mkOption { type = nullOr str; description = "Priority"; };
167 attrs of ip4/ip6 grouped by section
169 type = attrsOf (submodule {
174 ip4 address of the host
181 ip6 addresses of the host
194 Attrs of servers information in the cluster (not necessarily handled by nixops)
197 type = attrsOf hostEnv;
199 hetznerCloud = mkOption {
201 Hetzner Cloud credential information
205 authToken = mkOption {
216 Hetzner credential information
220 user = mkOption { type = str; description = "User"; };
221 pass = mkOption { type = str; description = "Password"; };
227 sshd service credential information
233 LDAP credentials for cn=ssh,ou=services,dc=immae,dc=eu dn
237 password = mkOption { description = "Password"; type = str; };
246 non-standard reserved ports. Must be unique!
251 noDupl = x: builtins.length (builtins.attrValues x) == builtins.length (unique (builtins.attrValues x));
253 x: if isAttrs x && noDupl x then x else throw "Non unique values for ports";
257 httpd service credential information
263 LDAP credentials for cn=httpd,ou=services,dc=immae,dc=eu dn
267 password = mkOption { description = "Password"; type = str; };
275 type = submodule { options = smtpOptions; };
276 description = "SMTP configuration";
280 LDAP server configuration
283 options = ldapOptions;
286 databases = mkOption {
287 description = "Databases configuration";
291 type = submodule { options = mysqlOptions; };
292 description = "Mysql configuration";
295 type = submodule { options = redisOptions; };
296 description = "Redis configuration";
298 postgresql = mkOption {
299 type = submodule { options = psqlOptions; };
300 description = "Postgresql configuration";
306 description = "Jabber configuration";
309 postfix_user_filter = mkOption { type = str; description = "Postfix filter to get xmpp users"; };
310 ldap = mkLdapOptions "Jabber" {};
311 postgresql = mkPsqlOptions "Jabber";
315 realUsers = mkOption {
317 Attrset of function taking pkgs as argument.
318 Real users settings, should provide a subattr of users.users.<name>
319 with at least: name, (hashed)Password, shell
321 type = attrsOf unspecified;
324 description = "System and regular users uid/gid";
325 type = attrsOf (submodule {
328 description = "user uid";
332 description = "user gid";
339 description = "DNS configuration";
343 description = "SOA information";
347 description = "Serial number. Should be incremented at each change and unique";
351 description = "Refresh time";
355 description = "Retry time";
359 description = "Expire time";
363 description = "Default TTL time";
367 description = "hostmaster e-mail";
371 description = "Primary NS";
378 description = "Attrs of NS servers group";
381 "ns1.foo.com" = [ "198.51.100.10" "2001:db8:abcd::1" ];
382 "ns2.foo.com" = [ "198.51.100.15" "2001:db8:1234::1" ];
385 type = attrsOf (attrsOf (listOf str));
387 slaveZones = mkOption {
388 description = "List of slave zones";
389 type = listOf (submodule {
391 name = mkOption { type = str; description = "zone name"; };
393 description = "NS master groups of this zone";
399 masterZones = mkOption {
400 description = "List of master zones";
401 type = listOf (submodule {
403 name = mkOption { type = str; description = "zone name"; };
405 description = "NS slave groups of this zone";
409 description = "groups names that should have their NS entries listed here";
413 description = "Extra zone configuration for bind";
419 entries = mkOption { type = lines; description = "Regular entries of the NS zone"; };
420 withEmail = mkOption {
421 description = "List of domains that should have mail entries (MX, dkim, SPF, ...)";
423 type = listOf (submodule {
425 domain = mkOption { type = str; description = "Which subdomain is concerned"; };
426 send = mkOption { type = bool; description = "Whether there can be e-mails originating from the subdomain"; };
427 receive = mkOption { type = bool; description = "Whether there can be e-mails arriving to the subdomain"; };
439 Remote backup with duplicity
443 password = mkOption { type = str; description = "Password for encrypting files"; };
445 type = attrsOf (submodule {
449 example = literalExample ''
450 bucket: "s3://some_host/${bucket}";
454 Takes a bucket name as argument and returns a url
457 accessKeyId = mkOption { type = str; description = "Remote access-key"; };
458 secretAccessKey = mkOption { type = str; description = "Remote access secret"; };
465 rsync_backup = mkOption {
467 Rsync backup configuration from controlled host
472 description = "SSH key information";
475 public = mkOption { type = str; description = "Public part of the key"; };
476 private = mkOption { type = lines; description = "Private part of the key"; };
480 profiles = mkOption {
481 description = "Attrs of profiles to backup";
482 type = attrsOf (submodule {
484 keep = mkOption { type = int; description = "Number of backups to keep"; };
485 check_command = mkOption { type = str; description = "command to check if backup needs to be done"; default = "backup"; };
486 login = mkOption { type = str; description = "Login to connect to host"; };
487 port = mkOption { type = str; default = "22"; description = "Port to connect to host"; };
488 host = mkOption { type = str; description = "Host to connect to"; };
489 host_key = mkOption { type = str; description = "Host key"; };
490 host_key_type = mkOption { type = str; description = "Host key type"; };
492 description = "Parts to backup for this host";
493 type = attrsOf (submodule {
495 remote_folder = mkOption { type = path; description = "Remote folder to backup";};
496 exclude_from = mkOption {
499 description = "List of folders/files to exclude from the backup";
501 files_from = mkOption {
504 description = "List of folders/files to backup in the base folder";
509 description = "Extra arguments to pass to rsync";
520 monitoring = mkOption {
521 description = "Monitoring configuration";
524 status_url = mkOption { type = str; description = "URL to push status to"; };
525 status_token = mkOption { type = str; description = "Token for the status url"; };
526 http_user_password = mkOption { type = str; description = "HTTP credentials to check services behind wall"; };
527 email = mkOption { type = str; description = "Admin E-mail"; };
528 ssh_public_key = mkOption { type = str; description = "SSH public key"; };
529 ssh_secret_key = mkOption { type = str; description = "SSH secret key"; };
530 imap_login = mkOption { type = str; description = "IMAP login"; };
531 imap_password = mkOption { type = str; description = "IMAP password"; };
532 eriomem_keys = mkOption { type = listOf (listOf str); description = "Eriomem keys"; default = []; };
534 description = "OVH credentials for sms script";
537 endpoint = mkOption { type = str; default = "ovh-eu"; description = "OVH endpoint"; };
538 application_key = mkOption { type = str; description = "Application key"; };
539 application_secret = mkOption { type = str; description = "Application secret"; };
540 consumer_key = mkOption { type = str; description = "Consumer key"; };
541 account = mkOption { type = str; description = "Account"; };
545 nrdp_tokens = mkOption { type = listOf str; description = "Tokens allowed to push status update"; };
546 slack_url = mkOption { type = str; description = "Slack webhook url to push status update"; };
547 slack_channel = mkOption { type = str; description = "Slack channel to push status update"; };
548 contacts = mkOption { type = attrsOf unspecified; description = "Contact dicts to fill naemon objects"; };
549 email_check = mkOption {
550 description = "Emails services to check";
551 type = attrsOf (submodule {
553 local = mkOption { type = bool; default = false; description = "Use local configuration"; };
554 port = mkOption { type = nullOr str; default = null; description = "Port to connect to ssh"; };
555 login = mkOption { type = nullOr str; default = null; description = "Login to connect to ssh"; };
556 targets = mkOption { type = listOf str; description = "Hosts to send E-mails to"; };
557 mail_address = mkOption { type = nullOr str; default = null; description = "E-mail recipient part to send e-mail to"; };
558 mail_domain = mkOption { type = nullOr str; default = null; description = "E-mail domain part to send e-mail to"; };
566 description = "MPD configuration";
569 folder = mkOption { type = str; description = "Folder to serve from the MPD instance"; };
570 password = mkOption { type = str; description = "Password to connect to the MPD instance"; };
571 host = mkOption { type = str; description = "Host to connect to the MPD instance"; };
572 port = mkOption { type = str; description = "Port to connect to the MPD instance"; };
577 description = "FTP configuration";
580 ldap = mkLdapOptions "FTP" {};
585 description = "VPN configuration";
586 type = attrsOf (submodule {
588 prefix = mkOption { type = str; description = "ipv6 prefix for the vpn subnet"; };
589 privateKey = mkOption { type = str; description = "Private key for the host"; };
590 publicKey = mkOption { type = str; description = "Public key for the host"; };
595 description = "Mail configuration";
599 description = "DMARC configuration";
602 ignore_hosts = mkOption {
605 Hosts to ignore when checking for dmarc
612 description = "DKIM configuration";
613 type = attrsOf (submodule {
619 "p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC3w1a2aMxWw9+hdcmbqX4UevcVqr204y0K73Wdc7MPZiOOlUJQYsMNSYR1Y/SC7jmPKeitpcJCpQgn/cveJZbuikjjPLsDReHyFEYmC278ZLRTELHx6f1IXM8WE08JIRT69CfZiMi1rVcOh9qRT4F93PyjCauU8Y5hJjtg9ThsWwIDAQAB" )
621 description = "Public entry to put in DNS TXT field";
623 private = mkOption { type = str; description = "Private key"; };
628 description = "Postfix configuration";
631 additional_mailbox_domains = mkOption {
633 List of domains that are used as mailbox final destination, in addition to those defined in the DNS records
637 mysql = mkMysqlOptions "Postfix" {
638 password_encrypt = mkOption { type = str; description = "Key to encrypt relay password in database"; };
640 backup_domains = mkOption {
642 Domains that are accepted for relay as backup domain
644 type = attrsOf (submodule {
646 domains = mkOption { type = listOf str; description = "Domains list"; };
647 relay_restrictions = mkOption {
650 Restrictions for relaying the e-mails from the domains
653 recipient_maps = mkOption {
655 Recipient map to accept relay for.
656 Must be specified for domain, the rules apply to everyone!
658 type = listOf (submodule {
661 type = enum [ "hash" ];
662 description = "Map type";
666 description = "Map content";
678 description = "Dovecot configuration";
681 ldap = mkLdapOptions "Dovecot" {
682 pass_attrs = mkOption { type = str; description = "Password attribute in LDAP"; };
683 user_attrs = mkOption { type = str; description = "User attribute mapping in LDAP"; };
684 iterate_attrs = mkOption { type = str; description = "User attribute mapping for listing in LDAP"; };
685 iterate_filter = mkOption { type = str; description = "User attribute filter for listing in LDAP"; };
686 postfix_mailbox_filter = mkOption { type = str; description = "Postfix filter to get mailboxes"; };
692 description = "rspamd configuration";
695 redis = mkRedisOptions "Redis";
696 read_password_hashed = mkOption { type = str; description = "Hashed read password for rspamd"; };
697 write_password_hashed = mkOption { type = str; description = "Hashed write password for rspamd"; };
698 read_password = mkOption {
700 description = "Read password for rspamd. Unused";
703 write_password = mkOption {
705 description = "Write password for rspamd. Unused";
712 description = "Mail script recipients";
713 type = attrsOf (submodule {
715 external = mkEnableOption "Create a script_<name>@mail.immae.eu external address";
718 git source to fetch the script from.
719 It must have a default.nix file as its root accepting a scriptEnv parameter
723 url = mkOption { type = str; description = "git url to fetch"; };
724 rev = mkOption { type = str; description = "git reference to fetch"; };
729 description = "Variables to pass to the script";
736 description = "Sympa configuration";
739 listmasters = mkOption {
741 description = "Listmasters";
743 postgresql = mkPsqlOptions "Sympa";
744 data_sources = mkOption {
747 description = "Data sources to make available to sympa";
752 description = "Scenari to make available to sympa";
760 buildbot = mkOption {
761 description = "Buildbot configuration";
765 description = "Buildbot user";
769 description = "user uid";
773 description = "user gid";
780 description = "Ldap configuration for buildbot";
783 password = mkOption { type = str; description = "Buildbot password"; };
787 projects = mkOption {
788 description = "Projects to make a buildbot for";
789 type = attrsOf (submodule {
791 name = mkOption { type = str; description = "Project name"; };
792 packages = mkOption {
794 example = literalExample ''
795 pkgs: [ pkgs.bash pkgs.git pkgs.gzip pkgs.openssh ];
799 Builds packages list to make available to buildbot project.
800 Takes pkgs as argument.
803 pythonPackages = mkOption {
805 example = literalExample ''
806 p: pkgs: [ pkgs.python3Packages.pip ];
810 Builds python packages list to make available to buildbot project.
811 Takes buildbot python module as first argument and pkgs as second argument in order to augment the python modules list.
814 pythonPathHome = mkOption { type = bool; description = "Whether to add project’s python home to python path"; };
817 description = "Secrets for the project to dump as files";
819 environment = mkOption {
822 Environment variables for the project.
823 BUILDBOT_ is prefixed to the variable names
826 activationScript = mkOption {
829 Activation script to run during deployment
832 builderPaths = mkOption {
833 type = attrsOf unspecified;
836 Attrs of functions to make accessible specifically per builder.
837 Takes pkgs as argument and should return a single path containing binaries.
838 This path will be accessible as BUILDBOT_PATH_<attrskey>
841 webhookTokens = mkOption {
842 type = nullOr (listOf str);
845 List of tokens allowed to push to project’s change_hook/base endpoint
855 description = "Tools configurations";
858 contact = mkOption { type = str; description = "Contact e-mail address"; };
860 description = "Davical configuration";
863 postgresql = mkPsqlOptions "Davical";
864 ldap = mkLdapOptions "Davical" {};
868 diaspora = mkOption {
869 description = "Diaspora configuration";
872 postgresql = mkPsqlOptions "Diaspora";
873 redis = mkRedisOptions "Diaspora";
874 ldap = mkLdapOptions "Diaspora" {};
875 secret_token = mkOption { type = str; description = "Secret token"; };
879 dmarc_reports = mkOption {
880 description = "DMARC reports configuration";
883 mysql = mkMysqlOptions "DMARC" {};
884 anonymous_key = mkOption { type = str; description = "Anonymous hashing key"; };
888 etherpad-lite = mkOption {
889 description = "Etherpad configuration";
892 postgresql = mkPsqlOptions "Etherpad";
893 ldap = mkLdapOptions "Etherpad" {
894 group_filter = mkOption { type = str; description = "Filter for groups"; };
896 adminPassword = mkOption { type = str; description = "Admin password for mypads / admin"; };
897 session_key = mkOption { type = str; description = "Session key"; };
898 api_key = mkOption { type = str; description = "API key"; };
899 redirects = mkOption { type = str; description = "Redirects for apache"; };
903 gitolite = mkOption {
904 description = "Gitolite configuration";
907 ldap = mkLdapOptions "Gitolite" {};
911 kanboard = mkOption {
912 description = "Kanboard configuration";
915 postgresql = mkPsqlOptions "Kanboard";
916 ldap = mkLdapOptions "Kanboard" {
917 admin_dn = mkOption { type = str; description = "Admin DN"; };
922 mantisbt = mkOption {
923 description = "Mantisbt configuration";
926 postgresql = mkPsqlOptions "Mantisbt";
927 ldap = mkLdapOptions "Mantisbt" {};
928 master_salt = mkOption { type = str; description = "Master salt for password hash"; };
932 mastodon = mkOption {
933 description = "Mastodon configuration";
936 postgresql = mkPsqlOptions "Mastodon";
937 redis = mkRedisOptions "Mastodon";
938 ldap = mkLdapOptions "Mastodon" {};
939 paperclip_secret = mkOption { type = str; description = "Paperclip secret"; };
940 otp_secret = mkOption { type = str; description = "OTP secret"; };
941 secret_key_base = mkOption { type = str; description = "Secret key base"; };
943 description = "vapid key";
946 private = mkOption { type = str; description = "Private key"; };
947 public = mkOption { type = str; description = "Public key"; };
954 mediagoblin = mkOption {
955 description = "Mediagoblin configuration";
958 postgresql = mkPsqlOptions "Mediagoblin";
959 redis = mkRedisOptions "Mediagoblin";
960 ldap = mkLdapOptions "Mediagoblin" {};
964 nextcloud = mkOption {
965 description = "Nextcloud configuration";
968 postgresql = mkPsqlOptions "Peertube";
969 redis = mkRedisOptions "Peertube";
970 password_salt = mkOption { type = str; description = "Password salt"; };
971 instance_id = mkOption { type = str; description = "Instance ID"; };
972 secret = mkOption { type = str; description = "App secret"; };
976 peertube = mkOption {
977 description = "Peertube configuration";
980 listenPort = mkOption { type = port; description = "Port to listen to"; };
981 postgresql = mkPsqlOptions "Peertube";
982 redis = mkRedisOptions "Peertube";
983 ldap = mkLdapOptions "Peertube" {};
987 syden_peertube = mkOption {
988 description = "Peertube Syden configuration";
991 listenPort = mkOption { type = port; description = "Port to listen to"; };
992 postgresql = mkPsqlOptions "Peertube";
993 redis = mkRedisOptions "Peertube";
997 phpldapadmin = mkOption {
998 description = "phpLdapAdmin configuration";
1001 ldap = mkLdapOptions "phpldapadmin" {};
1006 description = "Rompr configuration";
1010 description = "MPD configuration";
1013 host = mkOption { type = str; description = "Host for MPD"; };
1014 port = mkOption { type = port; description = "Port to access MPD host"; };
1021 roundcubemail = mkOption {
1022 description = "Roundcubemail configuration";
1025 postgresql = mkPsqlOptions "TT-RSS";
1026 secret = mkOption { type = str; description = "Secret"; };
1030 shaarli = mkOption {
1031 description = "Shaarli configuration";
1034 ldap = mkLdapOptions "Shaarli" {};
1038 status_engine = mkOption {
1039 description = "Status Engine configuration";
1042 mysql = mkMysqlOptions "StatusEngine" {};
1043 ldap = mkLdapOptions "StatusEngine" {};
1048 description = "Taskwarrior configuration";
1051 ldap = mkLdapOptions "Taskwarrior" {};
1052 taskwarrior-web = mkOption {
1053 description = "taskwarrior-web profiles";
1054 type = attrsOf (submodule {
1058 description = "List of ldap uids having access to this profile";
1060 org = mkOption { type = str; description = "Taskd organisation"; };
1061 key = mkOption { type = str; description = "Taskd key"; };
1062 date = mkOption { type = str; description = "Preferred date format"; };
1070 description = "TT-RSS configuration";
1073 postgresql = mkPsqlOptions "TT-RSS";
1074 ldap = mkLdapOptions "TT-RSS" {};
1078 wallabag = mkOption {
1079 description = "Wallabag configuration";
1082 postgresql = mkPsqlOptions "Wallabag";
1083 ldap = mkLdapOptions "Wallabag" {
1084 admin_filter = mkOption { type = str; description = "Admin users filter"; };
1086 redis = mkRedisOptions "Wallabag";
1087 secret = mkOption { type = str; description = "App secret"; };
1091 webhooks = mkOption {
1093 description = "Mapping 'name'.php => script for webhooks";
1095 csp_reports = mkOption {
1096 description = "CSP report configuration";
1099 report_uri = mkOption { type = str; description = "URI to report CSP violations to"; };
1100 policies = mkOption { type = attrsOf str; description = "CSP policies to apply"; };
1101 postgresql = mkPsqlOptions "CSP reports";
1105 commento = mkOption {
1106 description = "Commento configuration";
1109 listenPort = mkOption { type = port; description = "Port to listen to"; };
1110 postgresql = mkPsqlOptions "Commento";
1111 smtp = mkSmtpOptions "Commento";
1116 description = "Ympd configuration";
1119 listenPort = mkOption { type = port; description = "Port to listen to"; };
1121 description = "MPD configuration";
1124 password = mkOption { type = str; description = "Password to access MPD host"; };
1125 host = mkOption { type = str; description = "Host for MPD"; };
1126 port = mkOption { type = port; description = "Port to access MPD host"; };
1134 description = "Yourls configuration";
1137 mysql = mkMysqlOptions "Yourls" {};
1138 ldap = mkLdapOptions "Yourls" {};
1139 cookieKey = mkOption { type = str; description = "Cookie key"; };
1146 websites = mkOption {
1147 description = "Websites configurations";
1151 description = "Immae configuration by environment";
1155 description = "Temp configuration";
1158 ldap = mkLdapOptions "Immae temp" {
1159 filter = mkOption { type = str; description = "Filter for user access"; };
1167 isabelle = mkOption {
1168 description = "Isabelle configurations by environment";
1171 atenSubmodule = mkOption {
1172 description = "environment configuration";
1175 environment = mkOption { type = str; description = "Symfony environment"; };
1176 secret = mkOption { type = str; description = "Symfony App secret"; };
1177 postgresql = mkPsqlOptions "Aten";
1184 aten_production = atenSubmodule;
1185 aten_integration = atenSubmodule;
1186 iridologie = mkOption {
1187 description = "environment configuration";
1190 environment = mkOption { type = str; description = "SPIP environment"; };
1191 mysql = mkMysqlOptions "Iridologie" {};
1192 ldap = mkLdapOptions "Iridologie" {};
1200 description = "Chloe configurations by environment";
1203 chloeSubmodule = mkOption {
1204 description = "environment configuration";
1207 environment = mkOption { type = str; description = "SPIP environment"; };
1208 mysql = mkMysqlOptions "Chloe" {};
1209 ldap = mkLdapOptions "Chloe" {};
1216 production = chloeSubmodule;
1217 integration = chloeSubmodule;
1221 connexionswing = mkOption {
1222 description = "Connexionswing configurations by environment";
1225 csSubmodule = mkOption {
1226 description = "environment configuration";
1229 environment = mkOption { type = str; description = "Symfony environment"; };
1230 mysql = mkMysqlOptions "Connexionswing" {};
1231 secret = mkOption { type = str; description = "Symfony App secret"; };
1232 email = mkOption { type = str; description = "Symfony email notification"; };
1239 production = csSubmodule;
1240 integration = csSubmodule;
1245 description = "Naturaloutil configuration";
1248 mysql = mkMysqlOptions "Naturaloutil" {};
1249 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1253 telio_tortay = mkOption {
1254 description = "Telio Tortay configuration";
1257 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1261 ludivine = mkOption {
1262 description = "Ludivinecassal configurations by environment";
1265 lcSubmodule = mkOption {
1266 description = "environment configuration";
1269 environment = mkOption { type = str; description = "Symfony environment"; };
1270 mysql = mkMysqlOptions "LudivineCassal" {};
1271 ldap = mkLdapOptions "LudivineCassal" {};
1272 secret = mkOption { type = str; description = "Symfony App secret"; };
1279 production = lcSubmodule;
1280 integration = lcSubmodule;
1285 description = "Emilia configuration";
1288 postgresql = mkPsqlOptions "Emilia";
1292 florian = mkOption {
1293 description = "Florian configuration";
1296 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1300 nassime = mkOption {
1301 description = "Nassime configuration";
1304 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1308 piedsjaloux = mkOption {
1309 description = "Piedsjaloux configurations by environment";
1312 pjSubmodule = mkOption {
1313 description = "environment configuration";
1316 environment = mkOption { type = str; description = "Symfony environment"; };
1317 mysql = mkMysqlOptions "Piedsjaloux" {};
1318 secret = mkOption { type = str; description = "Symfony App secret"; };
1325 production = pjSubmodule;
1326 integration = pjSubmodule;
1331 description = "Europe Richie configurations by environment";
1334 mysql = mkMysqlOptions "Richie" {};
1335 smtp_mailer = mkOption {
1336 description = "SMTP mailer configuration";
1339 user = mkOption { type = str; description = "Username"; };
1340 password = mkOption { type = str; description = "Password"; };
1347 tellesflorian = mkOption {
1348 description = "Tellesflorian configurations by environment";
1351 tfSubmodule = mkOption {
1352 description = "environment configuration";
1355 environment = mkOption { type = str; description = "Symfony environment"; };
1356 mysql = mkMysqlOptions "Tellesflorian" {};
1357 secret = mkOption { type = str; description = "Symfony App secret"; };
1358 invite_passwords = mkOption { type = str; description = "Password basic auth"; };
1365 integration = tfSubmodule;
1373 privateFiles = mkOption {
1376 Path to secret files to make available during build
1380 options.hostEnv = mkOption {
1383 default = config.myEnv.servers."${name}";
1384 description = "Host environment";