+ phpPackage = pkgs.php72.withExtensions ({ enabled, all }: enabled ++ [all.redis]);
+ };
+ systemd.services."phpfpm-isabelle_aten_production" = {
+ after = lib.mkAfter ["postgresql.service"];
+ wants = ["postgresql.service"];
+ path = lib.mkAfter [ pkgs.gnutar pkgs.gzip pkgs.php72 ];
+ preStart = let
+ script = pkgs.writeScriptBin "isabelle-aten-production" ''
+ #! ${pkgs.stdenv.shell}
+
+ [ -f ${packagePath}/${branch}.tar.gz ] || exit 1
+
+ cd ${ftpRoot}
+ if ! [ -f .tarball_sum ] || ! sha256sum -c .tarball_sum; then
+ tar -xf ${packagePath}/${branch}.tar.gz --one-top-level=php_new
+ if [ -d php ]; then
+ mv php php_old
+ fi
+ mv php_new php
+ fi
+ cd php
+ rm -rf var/{log,cache}
+ ln -sf ${varDir}/{log,cache} var/
+ APP_ENV=${secrets.environment} ./bin/console --env=${secrets.environment} cache:clear --no-warmup
+ sha256sum ${packagePath}/${branch}.tar.gz > ${ftpRoot}/.tarball_sum
+ '';
+ in
+ "/run/wrappers/bin/sudo -u ${config.services.httpd.Prod.user} ${script}/bin/isabelle-aten-production";
+ postStart = let
+ script = pkgs.writeScriptBin "isabelle-aten-production-post" ''
+ #! ${pkgs.stdenv.shell}
+
+ cd ${ftpRoot}
+ if [ -d php_old ]; then
+ rm -rf php_old
+ fi
+ '';
+ in
+ "/run/wrappers/bin/sudo -u ${config.services.httpd.Prod.user} ${script}/bin/isabelle-aten-production-post";
+ serviceConfig.TimeoutStartSec="infinity";
+ };
+ services.filesWatcher.phpfpm-isabelle_aten_production = {
+ restart = true;
+ paths = [ "${packagePath}/${branch}.tar.gz" ];
+ };
+
+ system.activationScripts.isabelle_aten_production = {
+ deps = ["users"];
+ text = ''
+ install -m 0700 -o ${config.services.httpd.Prod.user} -g ${config.services.httpd.Prod.group} -d ${ftpRoot}
+ '';