X-Git-Url: https://git.immae.eu/?a=blobdiff_plain;f=nixops%2Fmodules%2Fwebsites%2Ftools%2Fdiaspora%2Fdiaspora.nix;h=01aac89e4339e33f7168c8522eb6925473ab46ff;hb=452c23140ea93ce301e7fafdc37d28009bd6f613;hp=82bca8c7cabfea7c7b49539bcc68a755ce563c1e;hpb=0f466f6d5aec0d3fcf406fe2bb71effa5a1a1386;p=perso%2FImmae%2FConfig%2FNix.git diff --git a/nixops/modules/websites/tools/diaspora/diaspora.nix b/nixops/modules/websites/tools/diaspora/diaspora.nix index 82bca8c..01aac89 100644 --- a/nixops/modules/websites/tools/diaspora/diaspora.nix +++ b/nixops/modules/websites/tools/diaspora/diaspora.nix @@ -29,10 +29,22 @@ let }; }; }; - secret_token = writeText "secret_token.rb" '' - Diaspora::Application.config.secret_key_base = '${env.secret_token}' - ''; - config = writeText "diaspora.yml" '' + keys = { + secret_token = { + dest = "webapps/tools-diaspora-secret_token"; + user = "diaspora"; + group = "diaspora"; + permissions = "0400"; + text = '' + Diaspora::Application.config.secret_key_base = '${env.secret_token}' + ''; + }; + config = { + dest = "webapps/tools-diaspora-config"; + user = "diaspora"; + group = "diaspora"; + permissions = "0400"; + text = '' configuration: environment: url: "https://diaspora.immae.eu/" @@ -104,8 +116,14 @@ let environment: development: environment: - ''; - database_config = writeText "database.yml" '' + ''; + }; + database = { + dest = "webapps/tools-diaspora-database_config"; + user = "diaspora"; + group = "diaspora"; + permissions = "0400"; + text = '' postgresql: &postgresql adapter: postgresql host: "${env.postgresql.socket}" @@ -132,24 +150,29 @@ let integration2: <<: *combined database: diaspora_integration2 - ''; - + ''; + }; + }; railsRoot = stdenv.mkDerivation { name = "diaspora_immae"; inherit diaspora; + # FIXME: build machine will contain some passwords in the nix store builder = writeText "build_diaspora_immae" '' source $stdenv/setup cp -a $diaspora $out cd $out chmod -R u+rwX . tar -czf public/source.tar.gz ./{app,db,lib,script,Gemfile,Gemfile.lock,Rakefile,config.ru} - ln -s ${database_config} config/database.yml - ln -s ${config} config/diaspora.yml - ln -s ${secret_token} config/initializers/secret_token.rb + ln -s ${writeText "database.yml" keys.database.text} config/database.yml + ln -s ${writeText "diaspora.yml" keys.config.text} config/diaspora.yml + ln -s ${writeText "secret_token.rb" keys.secret_token.text} config/initializers/secret_token.rb ln -sf ${varDir}/schedule.yml config/schedule.yml ln -sf ${varDir}/oidc_key.pem config/oidc_key.pem ln -sf ${varDir}/uploads public/uploads RAILS_ENV=production ${gems}/bin/rake assets:precompile + ln -sf /var/secrets/webapps/tools-diaspora-database_config config/database.yml + ln -sf /var/secrets/webapps/tools-diaspora-config config/diaspora.yml + ln -sf /var/secrets/webapps/tools-diaspora-secret_token config/initializers/secret_token.rb rm -rf tmp log ln -sf ${varDir}/tmp tmp ln -sf ${varDir}/log log @@ -159,5 +182,6 @@ let in { inherit railsRoot varDir socketsDir gems; + keys = builtins.attrValues keys; railsSocket = "${socketsDir}/diaspora.sock"; }