-{ config, lib, pkgs, ... }:
+{ config, lib, pkgs, name, ... }:
let
cfg = config.services.zrepl;
in
user = config.systemd.services.zrepl.serviceConfig.User or "root";
group = config.systemd.services.zrepl.serviceConfig.Group or "root";
};
- };
+ "zrepl/${name}.key" = {
+ permissions = "0400";
+ text = config.myEnv.zrepl_backup.certs."${name}".key;
+ user = config.systemd.services.zrepl.serviceConfig.User or "root";
+ group = config.systemd.services.zrepl.serviceConfig.Group or "root";
+ };
+ } // builtins.listToAttrs (map (x: lib.attrsets.nameValuePair "zrepl/certificates/${x}.crt" {
+ permissions = "0400";
+ text = config.myEnv.zrepl_backup.certs."${x}".certificate;
+ user = config.systemd.services.zrepl.serviceConfig.User or "root";
+ group = config.systemd.services.zrepl.serviceConfig.Group or "root";
+ }) (builtins.attrNames config.myEnv.zrepl_backup.certs));
+
services.filesWatcher.zrepl = {
restart = true;
paths = [ config.secrets.fullPaths."zrepl/zrepl.yml" ];