]> git.immae.eu Git - perso/Immae/Config/Nix.git/blob - modules/private/websites/christophe_carpentier/ateliersduchangement.nix
Ateliers du changement
[perso/Immae/Config/Nix.git] / modules / private / websites / christophe_carpentier / ateliersduchangement.nix
1 { lib, config, pkgs, ... }:
2 let
3 cfg = config.myServices.websites.christophe_carpentier.ateliersduchangement;
4 varDir = "/var/lib/ftp/christophe_carpentier/lesateliersduchangement";
5 apacheUser = config.services.httpd.Prod.user;
6 apacheGroup = config.services.httpd.Prod.group;
7 in {
8 options.myServices.websites.christophe_carpentier.ateliersduchangement.enable = lib.mkEnableOption "enable Christophe Carpentier's Ateliers du changement website";
9
10 config = lib.mkIf cfg.enable {
11 system.activationScripts.christophe_carpentier_ateliers_du_changement = {
12 deps = [ "httpd" "users" ];
13 text = ''
14 install -m 0755 -o ${apacheUser} -g ${apacheGroup} -d ${varDir}
15 '';
16 };
17 services.phpfpm.pools.christophe_carpentier_ateliers_du_changement = {
18 user = apacheUser;
19 group = apacheGroup;
20 settings = {
21 "listen.owner" = apacheUser;
22 "listen.group" = apacheGroup;
23
24 "pm" = "ondemand";
25 "pm.max_children" = "5";
26 "pm.process_idle_timeout" = "60";
27
28 "php_admin_value[session.save_handler]" = "redis";
29 "php_admin_value[session.save_path]" = "'unix:///run/redis-php-sessions/redis.sock?persistent=1&prefix=ChristopheCarpentier:ateliersduchangement:'";
30 "php_admin_value[open_basedir]" = "${varDir}:/tmp";
31 };
32 phpOptions = config.services.phpfpm.phpOptions + ''
33 disable_functions = "mail"
34 '';
35 phpPackage = pkgs.php74.withExtensions ({ enabled, all }: enabled ++ [all.redis all.gd]);
36 };
37 services.websites.env.production.modules = [ "proxy_fcgi" ];
38 services.websites.env.production.vhostConfs.christophe_carpentier_ateliersduchangement = {
39 certName = "christophe_carpentier";
40 addToCerts = true;
41 hosts = ["lesateliersduchangement.org" "www.lesateliersduchangement.org"];
42 root = varDir;
43 extraConfig = [
44 ''
45 <FilesMatch "\.php$">
46 SetHandler "proxy:unix:${config.services.phpfpm.pools.christophe_carpentier_ateliers_du_changement.socket}|fcgi://localhost"
47 </FilesMatch>
48
49 <Directory ${varDir}>
50 DirectoryIndex index.php index.htm index.html
51 Options Indexes FollowSymLinks MultiViews Includes
52 AllowOverride All
53 Require all granted
54 </Directory>
55 ''
56 ];
57 };
58 };
59 }
60