-{ lib, pkgs, config, myconfig, mylibs, ... }:
+{ lib, pkgs, config, myconfig, ... }:
let
env = myconfig.env.tools.mediagoblin;
- socketsDir = "/run/mediagoblin";
- varDir = "/var/lib/mediagoblin";
cfg = config.services.myWebsites.tools.mediagoblin;
- mediagoblin_init = "/var/secrets/webapps/tools-mediagoblin";
- paste_local = pkgs.writeText "paste_local.ini" ''
- [DEFAULT]
- debug = false
-
- [pipeline:main]
- pipeline = mediagoblin
-
- [app:mediagoblin]
- use = egg:mediagoblin#app
- config = ${mediagoblin_init} ${pythonRoot}/mediagoblin.ini
- /mgoblin_static = ${pythonRoot}/mediagoblin/static
-
- [loggers]
- keys = root
-
- [handlers]
- keys = console
-
- [formatters]
- keys = generic
-
- [logger_root]
- level = INFO
- handlers = console
-
- [handler_console]
- class = StreamHandler
- args = (sys.stderr,)
- level = NOTSET
- formatter = generic
-
- [formatter_generic]
- format = %(levelname)-7.7s [%(name)s] %(message)s
-
- [filter:errors]
- use = egg:mediagoblin#errors
- debug = false
-
- [server:main]
- use = egg:waitress#main
- unix_socket = ${socketsDir}/mediagoblin.sock
- unix_socket_perms = 777
- url_scheme = https
- '';
- pythonRoot = pkgs.webapps.mediagoblin-with-plugins;
+ mcfg = config.services.mediagoblin;
in {
options.services.myWebsites.tools.mediagoblin = {
enable = lib.mkEnableOption "enable mediagoblin's website";
};
config = lib.mkIf cfg.enable {
- mySecrets.keys = [{
+ secrets.keys = [{
dest = "webapps/tools-mediagoblin";
user = "mediagoblin";
group = "mediagoblin";
permissions = "0400";
text = ''
[DEFAULT]
- data_basedir = "${varDir}"
+ data_basedir = "${mcfg.dataDir}"
[mediagoblin]
direct_remote_path = /mgoblin_static/
'';
}];
- ids.uids.mediagoblin = myconfig.env.tools.mediagoblin.user.uid;
- ids.gids.mediagoblin = myconfig.env.tools.mediagoblin.user.gid;
+ users.users.mediagoblin.extraGroups = [ "keys" ];
- users.users.mediagoblin = {
- name = "mediagoblin";
- uid = config.ids.uids.mediagoblin;
- group = "mediagoblin";
- description = "Mediagoblin user";
- home = varDir;
- useDefaultShell = true;
- extraGroups = [ "keys" ];
- };
-
- users.groups.mediagoblin.gid = config.ids.gids.mediagoblin;
-
- systemd.services.mediagoblin-web = {
- description = "Mediagoblin service";
- wantedBy = [ "multi-user.target" ];
- after = [ "network.target" ];
- wants = [ "postgresql.service" "redis.service" ];
-
- environment.SCRIPT_NAME = "/mediagoblin/";
-
- script = ''
- exec ./bin/paster serve \
- ${paste_local} \
- --pid-file=${socketsDir}/mediagoblin.pid
- '';
-
- preStop = ''
- exec ./bin/paster serve \
- --pid-file=${socketsDir}/mediagoblin.pid \
- ${paste_local} stop
- '';
- preStart = ''
- ./bin/gmg -cf ${mediagoblin_init} dbupdate
- '';
-
- serviceConfig = {
- User = "mediagoblin";
- PrivateTmp = true;
- Restart = "always";
- TimeoutSec = 15;
- Type = "simple";
- WorkingDirectory = pythonRoot;
- PIDFile = "${socketsDir}/mediagoblin.pid";
- };
-
- unitConfig.RequiresMountsFor = varDir;
- };
-
- systemd.services.mediagoblin-celeryd = {
- description = "Mediagoblin service";
- wantedBy = [ "multi-user.target" ];
- after = [ "network.target" "mediagoblin-web.service" ];
-
- environment.MEDIAGOBLIN_CONFIG = mediagoblin_init;
- environment.CELERY_CONFIG_MODULE = "mediagoblin.init.celery.from_celery";
-
- script = ''
- exec ./bin/celery worker \
- --logfile=${varDir}/celery.log \
- --loglevel=INFO
- '';
-
- serviceConfig = {
- User = "mediagoblin";
- PrivateTmp = true;
- Restart = "always";
- TimeoutSec = 60;
- Type = "simple";
- WorkingDirectory = pythonRoot;
- PIDFile = "${socketsDir}/mediagoblin-celeryd.pid";
- };
-
- unitConfig.RequiresMountsFor = varDir;
- };
-
- system.activationScripts.mediagoblin = {
- deps = [ "users" ];
- text = ''
- install -m 0755 -o mediagoblin -g mediagoblin -d ${socketsDir}
- install -m 0755 -o mediagoblin -g mediagoblin -d ${varDir}
- if [ -d ${varDir}/plugin_static/ ]; then
- rm ${varDir}/plugin_static/coreplugin_basic_auth
- ln -sf ${pythonRoot}/mediagoblin/plugins/basic_auth/static ${varDir}/plugin_static/coreplugin_basic_auth
- fi
- '';
+ services.mediagoblin = {
+ enable = true;
+ plugins = builtins.attrValues pkgs.webapps.mediagoblin-plugins;
+ configFile = "/var/secrets/webapps/tools-mediagoblin";
};
- services.myWebsites.tools.modules = [
+ services.websites.tools.modules = [
"proxy" "proxy_http"
];
users.users.wwwrun.extraGroups = [ "mediagoblin" ];
- security.acme.certs."eldiron".extraDomains."mgoblin.immae.eu" = null;
- services.myWebsites.tools.vhostConfs.mgoblin = {
+ services.websites.tools.vhostConfs.mgoblin = {
certName = "eldiron";
+ addToCerts = true;
hosts = ["mgoblin.immae.eu" ];
root = null;
extraConfig = [ ''
- Alias /mgoblin_media ${varDir}/media/public
- <Directory ${varDir}/media/public>
+ Alias /mgoblin_media ${mcfg.dataDir}/media/public
+ <Directory ${mcfg.dataDir}/media/public>
Options -Indexes +FollowSymLinks +MultiViews +Includes
Require all granted
</Directory>
- Alias /theme_static ${varDir}/theme_static
- <Directory ${varDir}/theme_static>
+ Alias /theme_static ${mcfg.dataDir}/theme_static
+ <Directory ${mcfg.dataDir}/theme_static>
Options -Indexes +FollowSymLinks +MultiViews +Includes
Require all granted
</Directory>
- Alias /plugin_static ${varDir}/plugin_static
- <Directory ${varDir}/plugin_static>
+ Alias /plugin_static ${mcfg.dataDir}/plugin_static
+ <Directory ${mcfg.dataDir}/plugin_static>
Options -Indexes +FollowSymLinks +MultiViews +Includes
Require all granted
</Directory>
ProxyPass /theme_static !
ProxyPass /plugin_static !
ProxyPassMatch ^/.well-known/acme-challenge !
- ProxyPass / unix://${socketsDir}/mediagoblin.sock|http://mgoblin.immae.eu/
- ProxyPassReverse / unix://${socketsDir}/mediagoblin.sock|http://mgoblin.immae.eu/
+ ProxyPass / unix://${mcfg.sockets.paster}|http://mgoblin.immae.eu/
+ ProxyPassReverse / unix://${mcfg.sockets.paster}|http://mgoblin.immae.eu/
'' ];
};
};