]> git.immae.eu Git - perso/Immae/Config/Nix.git/blame - modules/private/environment.nix
Upgrade roundcube
[perso/Immae/Config/Nix.git] / modules / private / environment.nix
CommitLineData
619e4f46 1{ config, lib, name, ... }:
ab8f306d
IB
2with lib;
3with types;
4with lists;
5let
6 ldapOptions = {
7 base = mkOption { description = "Base of the LDAP tree"; type = str; };
8 host = mkOption { description = "Host to access LDAP"; type = str; };
9 root_dn = mkOption { description = "DN of the root user"; type = str; };
10 root_pw = mkOption { description = "Hashed password of the root user"; type = str; };
11 replication_dn = mkOption { description = "DN of the user allowed to replicate the LDAP directory"; type = str; };
12 replication_pw = mkOption { description = "Password of the user allowed to replicate the LDAP directory"; type = str; };
13 };
14 mkLdapOptions = name: more: mkOption {
15 description = "${name} LDAP configuration";
16 type = submodule {
17 options = ldapOptions // {
18 dn = mkOption { description = "DN of the ${name} user"; type = str; };
19 password = mkOption { description = "password of the ${name} user"; type = str; };
20 filter = mkOption { description = "Filter for ${name} users"; type = str; default = ""; };
21 } // more;
22 };
23 };
24 mysqlOptions = {
25 host = mkOption { description = "Host to access Mysql"; type = str; };
619e4f46 26 remoteHost = mkOption { description = "Host to access Mysql from outside"; type = str; };
ab8f306d
IB
27 port = mkOption { description = "Port to access Mysql"; type = str; };
28 socket = mkOption { description = "Socket to access Mysql"; type = path; };
29 systemUsers = mkOption {
30 description = "Attrs of user-passwords allowed to access mysql";
31 type = attrsOf str;
32 };
33 pam = mkOption {
34 description = "PAM configuration for mysql";
35 type = submodule {
36 options = {
37 dn = mkOption { description = "DN to connect as to check users"; type = str; };
38 password = mkOption { description = "DN password to connect as to check users"; type = str; };
39 filter = mkOption { description = "filter to match users"; type = str; };
40 };
41 };
42 };
43 };
87a8bffd 44 mkMysqlOptions = name: more: mkOption {
ab8f306d
IB
45 description = "${name} mysql configuration";
46 type = submodule {
47 options = mysqlOptions // {
48 database = mkOption { description = "${name} database"; type = str; };
49 user = mkOption { description = "${name} user"; type = str; };
50 password = mkOption { description = "mysql password of the ${name} user"; type = str; };
87a8bffd 51 } // more;
ab8f306d
IB
52 };
53 };
54 psqlOptions = {
55 host = mkOption { description = "Host to access Postgresql"; type = str; };
56 port = mkOption { description = "Port to access Postgresql"; type = str; };
57 socket = mkOption { description = "Socket to access Postgresql"; type = path; };
58 pam = mkOption {
59 description = "PAM configuration for psql";
60 type = submodule {
61 options = {
62 dn = mkOption { description = "DN to connect as to check users"; type = str; };
63 password = mkOption { description = "DN password to connect as to check users"; type = str; };
64 filter = mkOption { description = "filter to match users"; type = str; };
65 };
66 };
67 };
68 };
69 mkPsqlOptions = name: mkOption {
70 description = "${name} psql configuration";
71 type = submodule {
72 options = psqlOptions // {
73 database = mkOption { description = "${name} database"; type = str; };
74 schema = mkOption { description = "${name} schema"; type = nullOr str; default = null; };
75 user = mkOption { description = "${name} user"; type = str; };
76 password = mkOption { description = "psql password of the ${name} user"; type = str; };
77 };
78 };
79 };
80 redisOptions = {
81 host = mkOption { description = "Host to access Redis"; type = str; };
82 port = mkOption { description = "Port to access Redis"; type = str; };
83 socket = mkOption { description = "Socket to access Redis"; type = path; };
84 dbs = mkOption {
85 description = "Attrs of db number. Each number should be unique to avoid collision!";
86 type = attrsOf str;
87 };
88 spiped_key = mkOption {
89 type = str;
90 description = ''
91 Key to use with spiped to make a secure channel to replication
92 '';
93 };
94 predixy = mkOption {
95 description = "Predixy configuration. Unused yet";
96 type = submodule {
97 options = {
98 read = mkOption { type = str; description = "Read password"; };
99 };
100 };
101 };
102 };
103 mkRedisOptions = name: mkOption {
104 description = "${name} redis configuration";
105 type = submodule {
106 options = redisOptions // {
107 db = mkOption { description = "${name} database"; type = str; };
108 };
109 };
110 };
619e4f46
IB
111 hostEnv = submodule {
112 options = {
113 fqdn = mkOption {
114 description = "Host FQDN";
115 type = str;
116 };
8a304ef4
IB
117 users = mkOption {
118 type = unspecified;
119 default = pkgs: [];
120 description = ''
121 Sublist of users from realUsers. Function that takes pkgs as
122 argument and gives an array as a result
123 '';
124 };
619e4f46
IB
125 emails = mkOption {
126 default = [];
127 description = "List of e-mails that the server can be a sender of";
128 type = listOf str;
129 };
130 ldap = mkOption {
131 description = ''
132 LDAP credentials for the host
133 '';
134 type = submodule {
135 options = {
5400b9b6
IB
136 password = mkOption { type = str; description = "Password for the LDAP connection"; };
137 dn = mkOption { type = str; description = "DN for the LDAP connection"; };
619e4f46
IB
138 };
139 };
140 };
141 mx = mkOption {
142 description = "subdomain and priority for MX server";
143 default = { enable = false; };
144 type = submodule {
145 options = {
146 enable = mkEnableOption "Enable MX";
147 subdomain = mkOption { type = nullOr str; description = "Subdomain name (mx-*)"; };
148 priority = mkOption { type = nullOr str; description = "Priority"; };
149 };
150 };
151 };
152 ips = mkOption {
153 description = ''
154 attrs of ip4/ip6 grouped by section
155 '';
156 type = attrsOf (submodule {
157 options = {
158 ip4 = mkOption {
5400b9b6 159 type = str;
619e4f46
IB
160 description = ''
161 ip4 address of the host
162 '';
163 };
164 ip6 = mkOption {
5400b9b6 165 type = listOf str;
619e4f46
IB
166 default = [];
167 description = ''
168 ip6 addresses of the host
169 '';
170 };
171 };
172 });
173 };
174 };
175 };
ab8f306d
IB
176in
177{
178 options.myEnv = {
179 servers = mkOption {
180 description = ''
181 Attrs of servers information in the cluster (not necessarily handled by nixops)
182 '';
183 default = {};
619e4f46 184 type = attrsOf hostEnv;
ab8f306d
IB
185 };
186 hetznerCloud = mkOption {
187 description = ''
188 Hetzner Cloud credential information
189 '';
190 type = submodule {
191 options = {
192 authToken = mkOption {
193 type = str;
194 description = ''
195 The API auth token.
196 '';
197 };
198 };
199 };
200 };
201 hetzner = mkOption {
202 description = ''
203 Hetzner credential information
204 '';
205 type = submodule {
206 options = {
207 user = mkOption { type = str; description = "User"; };
208 pass = mkOption { type = str; description = "Password"; };
209 };
210 };
211 };
212 sshd = mkOption {
213 description = ''
214 sshd service credential information
215 '';
216 type = submodule {
217 options = {
218 ldap = mkOption {
219 description = ''
220 LDAP credentials for cn=ssh,ou=services,dc=immae,dc=eu dn
221 '';
222 type = submodule {
223 options = {
224 password = mkOption { description = "Password"; type = str; };
225 };
226 };
227 };
228 };
229 };
230 };
231 ports = mkOption {
232 description = ''
233 non-standard reserved ports. Must be unique!
234 '';
235 type = attrsOf port;
236 default = {};
237 apply = let
238 noDupl = x: builtins.length (builtins.attrValues x) == builtins.length (unique (builtins.attrValues x));
239 in
240 x: if isAttrs x && noDupl x then x else throw "Non unique values for ports";
241 };
242 httpd = mkOption {
243 description = ''
244 httpd service credential information
245 '';
246 type = submodule {
247 options = {
248 ldap = mkOption {
249 description = ''
250 LDAP credentials for cn=httpd,ou=services,dc=immae,dc=eu dn
251 '';
252 type = submodule {
253 options = {
254 password = mkOption { description = "Password"; type = str; };
255 };
256 };
257 };
258 };
259 };
260 };
261 ldap = mkOption {
262 description = ''
263 LDAP server configuration
264 '';
265 type = submodule {
266 options = ldapOptions;
267 };
268 };
269 databases = mkOption {
270 description = "Databases configuration";
271 type = submodule {
272 options = {
273 mysql = mkOption {
274 type = submodule { options = mysqlOptions; };
275 description = "Mysql configuration";
276 };
277 redis = mkOption {
278 type = submodule { options = redisOptions; };
279 description = "Redis configuration";
280 };
281 postgresql = mkOption {
282 type = submodule { options = psqlOptions; };
283 description = "Postgresql configuration";
284 };
285 };
286 };
287 };
288 jabber = mkOption {
289 description = "Jabber configuration";
290 type = submodule {
291 options = {
5b53d86f 292 postfix_user_filter = mkOption { type = str; description = "Postfix filter to get xmpp users"; };
ab8f306d
IB
293 ldap = mkLdapOptions "Jabber" {};
294 postgresql = mkPsqlOptions "Jabber";
295 };
296 };
297 };
8a304ef4
IB
298 realUsers = mkOption {
299 description = ''
300 Attrset of function taking pkgs as argument.
301 Real users settings, should provide a subattr of users.users.<name>
302 with at least: name, (hashed)Password, shell
303 '';
304 type = attrsOf unspecified;
305 };
ab8f306d
IB
306 users = mkOption {
307 description = "System and regular users uid/gid";
308 type = attrsOf (submodule {
309 options = {
310 uid = mkOption {
311 description = "user uid";
312 type = int;
313 };
314 gid = mkOption {
315 description = "user gid";
316 type = int;
317 };
318 };
319 });
320 };
321 dns = mkOption {
322 description = "DNS configuration";
323 type = submodule {
324 options = {
325 soa = mkOption {
326 description = "SOA information";
327 type = submodule {
328 options = {
329 serial = mkOption {
330 description = "Serial number. Should be incremented at each change and unique";
331 type = str;
332 };
333 refresh = mkOption {
334 description = "Refresh time";
335 type = str;
336 };
337 retry = mkOption {
338 description = "Retry time";
339 type = str;
340 };
341 expire = mkOption {
342 description = "Expire time";
343 type = str;
344 };
345 ttl = mkOption {
346 description = "Default TTL time";
347 type = str;
348 };
349 email = mkOption {
350 description = "hostmaster e-mail";
351 type = str;
352 };
353 primary = mkOption {
354 description = "Primary NS";
355 type = str;
356 };
357 };
358 };
359 };
360 ns = mkOption {
361 description = "Attrs of NS servers group";
362 example = {
363 foo = {
364 "ns1.foo.com" = [ "198.51.100.10" "2001:db8:abcd::1" ];
365 "ns2.foo.com" = [ "198.51.100.15" "2001:db8:1234::1" ];
366 };
367 };
368 type = attrsOf (attrsOf (listOf str));
369 };
370 slaveZones = mkOption {
371 description = "List of slave zones";
372 type = listOf (submodule {
373 options = {
374 name = mkOption { type = str; description = "zone name"; };
375 masters = mkOption {
376 description = "NS master groups of this zone";
377 type = listOf str;
378 };
379 };
380 });
381 };
382 masterZones = mkOption {
383 description = "List of master zones";
384 type = listOf (submodule {
385 options = {
386 name = mkOption { type = str; description = "zone name"; };
387 slaves = mkOption {
388 description = "NS slave groups of this zone";
389 type = listOf str;
390 };
391 ns = mkOption {
392 description = "groups names that should have their NS entries listed here";
393 type = listOf str;
394 };
395 extra = mkOption {
396 description = "Extra zone configuration for bind";
397 example = ''
398 notify yes;
399 '';
400 type = lines;
401 };
402 entries = mkOption { type = lines; description = "Regular entries of the NS zone"; };
403 withEmail = mkOption {
404 description = "List of domains that should have mail entries (MX, dkim, SPF, ...)";
405 default = [];
406 type = listOf (submodule {
407 options = {
408 domain = mkOption { type = str; description = "Which subdomain is concerned"; };
409 send = mkOption { type = bool; description = "Whether there can be e-mails originating from the subdomain"; };
410 receive = mkOption { type = bool; description = "Whether there can be e-mails arriving to the subdomain"; };
411 };
412 });
413 };
414 };
415 });
416 };
417 };
418 };
419 };
420 backup = mkOption {
421 description = ''
422 Remote backup with duplicity
423 '';
424 type = submodule {
425 options = {
426 password = mkOption { type = str; description = "Password for encrypting files"; };
427 remote = mkOption { type = str; description = "Remote url access"; };
428 accessKeyId = mkOption { type = str; description = "Remote access-key"; };
429 secretAccessKey = mkOption { type = str; description = "Remote access secret"; };
430 };
431 };
432 };
433 rsync_backup = mkOption {
434 description =''
435 Rsync backup configuration from controlled host
436 '';
437 type = submodule {
438 options = {
ab8f306d
IB
439 ssh_key = mkOption {
440 description = "SSH key information";
441 type = submodule {
442 options = {
443 public = mkOption { type = str; description = "Public part of the key"; };
444 private = mkOption { type = lines; description = "Private part of the key"; };
445 };
446 };
447 };
448 profiles = mkOption {
449 description = "Attrs of profiles to backup";
450 type = attrsOf (submodule {
451 options = {
452 keep = mkOption { type = int; description = "Number of backups to keep"; };
453 login = mkOption { type = str; description = "Login to connect to host"; };
454 port = mkOption { type = str; default = "22"; description = "Port to connect to host"; };
455 host = mkOption { type = str; description = "Host to connect to"; };
456 host_key = mkOption { type = str; description = "Host key"; };
457 host_key_type = mkOption { type = str; description = "Host key type"; };
458 parts = mkOption {
459 description = "Parts to backup for this host";
460 type = attrsOf (submodule {
461 options = {
462 remote_folder = mkOption { type = path; description = "Remote folder to backup";};
463 exclude_from = mkOption {
464 type = listOf path;
465 default = [];
466 description = "List of folders/files to exclude from the backup";
467 };
468 files_from = mkOption {
469 type = listOf path;
470 default = [];
471 description = "List of folders/files to backup in the base folder";
472 };
473 args = mkOption {
474 type = nullOr str;
475 default = null;
476 description = "Extra arguments to pass to rsync";
477 };
478 };
479 });
480 };
481 };
482 });
483 };
484 };
485 };
486 };
487 monitoring = mkOption {
488 description = "Monitoring configuration";
489 type = submodule {
490 options = {
491 status_url = mkOption { type = str; description = "URL to push status to"; };
492 status_token = mkOption { type = str; description = "Token for the status url"; };
e820134d 493 http_user_password = mkOption { type = str; description = "HTTP credentials to check services behind wall"; };
ab8f306d 494 email = mkOption { type = str; description = "Admin E-mail"; };
e820134d
IB
495 ssh_public_key = mkOption { type = str; description = "SSH public key"; };
496 ssh_secret_key = mkOption { type = str; description = "SSH secret key"; };
497 imap_login = mkOption { type = str; description = "IMAP login"; };
498 imap_password = mkOption { type = str; description = "IMAP password"; };
25844101 499 eriomem_keys = mkOption { type = listOf (listOf str); description = "Eriomem keys"; default = []; };
6191bdeb
IB
500 ovh_sms = mkOption {
501 description = "OVH credentials for sms script";
502 type = submodule {
503 options = {
504 endpoint = mkOption { type = str; default = "ovh-eu"; description = "OVH endpoint"; };
505 application_key = mkOption { type = str; description = "Application key"; };
506 application_secret = mkOption { type = str; description = "Application secret"; };
507 consumer_key = mkOption { type = str; description = "Consumer key"; };
508 account = mkOption { type = str; description = "Account"; };
509 };
510 };
511 };
e820134d
IB
512 nrdp_tokens = mkOption { type = listOf str; description = "Tokens allowed to push status update"; };
513 slack_url = mkOption { type = str; description = "Slack webhook url to push status update"; };
514 slack_channel = mkOption { type = str; description = "Slack channel to push status update"; };
515 contacts = mkOption { type = attrsOf unspecified; description = "Contact dicts to fill naemon objects"; };
71a2425e
IB
516 email_check = mkOption {
517 description = "Emails services to check";
518 type = attrsOf (submodule {
519 options = {
520 local = mkOption { type = bool; default = false; description = "Use local configuration"; };
521 port = mkOption { type = nullOr str; default = null; description = "Port to connect to ssh"; };
522 login = mkOption { type = nullOr str; default = null; description = "Login to connect to ssh"; };
523 targets = mkOption { type = listOf str; description = "Hosts to send E-mails to"; };
ef0a9217
IB
524 mail_address = mkOption { type = nullOr str; default = null; description = "E-mail recipient part to send e-mail to"; };
525 mail_domain = mkOption { type = nullOr str; default = null; description = "E-mail domain part to send e-mail to"; };
71a2425e
IB
526 };
527 });
528 };
ab8f306d
IB
529 };
530 };
531 };
532 mpd = mkOption {
533 description = "MPD configuration";
534 type = submodule {
535 options = {
536 folder = mkOption { type = str; description = "Folder to serve from the MPD instance"; };
537 password = mkOption { type = str; description = "Password to connect to the MPD instance"; };
538 host = mkOption { type = str; description = "Host to connect to the MPD instance"; };
539 port = mkOption { type = str; description = "Port to connect to the MPD instance"; };
540 };
541 };
542 };
543 ftp = mkOption {
544 description = "FTP configuration";
545 type = submodule {
546 options = {
547 ldap = mkLdapOptions "FTP" {};
548 };
549 };
550 };
ea9c6fe8
IB
551 vpn = mkOption {
552 description = "VPN configuration";
553 type = attrsOf (submodule {
554 options = {
555 prefix = mkOption { type = str; description = "ipv6 prefix for the vpn subnet"; };
556 privateKey = mkOption { type = str; description = "Private key for the host"; };
557 publicKey = mkOption { type = str; description = "Public key for the host"; };
558 };
559 });
560 };
ab8f306d
IB
561 mail = mkOption {
562 description = "Mail configuration";
563 type = submodule {
564 options = {
565 dmarc = mkOption {
566 description = "DMARC configuration";
567 type = submodule {
568 options = {
569 ignore_hosts = mkOption {
570 type = lines;
571 description = ''
572 Hosts to ignore when checking for dmarc
573 '';
574 };
575 };
576 };
577 };
578 dkim = mkOption {
579 description = "DKIM configuration";
580 type = attrsOf (submodule {
581 options = {
582 public = mkOption {
583 type = str;
584 example = ''
585 ( "v=DKIM1; k=rsa; "
586 "p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC3w1a2aMxWw9+hdcmbqX4UevcVqr204y0K73Wdc7MPZiOOlUJQYsMNSYR1Y/SC7jmPKeitpcJCpQgn/cveJZbuikjjPLsDReHyFEYmC278ZLRTELHx6f1IXM8WE08JIRT69CfZiMi1rVcOh9qRT4F93PyjCauU8Y5hJjtg9ThsWwIDAQAB" )
587 '';
588 description = "Public entry to put in DNS TXT field";
589 };
590 private = mkOption { type = str; description = "Private key"; };
591 };
592 });
593 };
594 postfix = mkOption {
595 description = "Postfix configuration";
596 type = submodule {
597 options = {
598 additional_mailbox_domains = mkOption {
599 description = ''
600 List of domains that are used as mailbox final destination, in addition to those defined in the DNS records
601 '';
602 type = listOf str;
603 };
87a8bffd
IB
604 mysql = mkMysqlOptions "Postfix" {
605 password_encrypt = mkOption { type = str; description = "Key to encrypt relay password in database"; };
606 };
ab8f306d
IB
607 backup_domains = mkOption {
608 description = ''
609 Domains that are accepted for relay as backup domain
610 '';
611 type = attrsOf (submodule {
612 options = {
613 domains = mkOption { type = listOf str; description = "Domains list"; };
614 relay_restrictions = mkOption {
615 type = lines;
616 description = ''
617 Restrictions for relaying the e-mails from the domains
618 '';
619 };
620 recipient_maps = mkOption {
621 description = ''
622 Recipient map to accept relay for.
623 Must be specified for domain, the rules apply to everyone!
624 '';
625 type = listOf (submodule {
626 options = {
627 type = mkOption {
628 type = enum [ "hash" ];
629 description = "Map type";
630 };
631 content = mkOption {
632 type = str;
633 description = "Map content";
634 };
635 };
636 });
637 };
638 };
639 });
640 };
641 };
642 };
643 };
644 dovecot = mkOption {
645 description = "Dovecot configuration";
646 type = submodule {
647 options = {
648 ldap = mkLdapOptions "Dovecot" {
649 pass_attrs = mkOption { type = str; description = "Password attribute in LDAP"; };
650 user_attrs = mkOption { type = str; description = "User attribute mapping in LDAP"; };
651 iterate_attrs = mkOption { type = str; description = "User attribute mapping for listing in LDAP"; };
652 iterate_filter = mkOption { type = str; description = "User attribute filter for listing in LDAP"; };
653 };
654 };
655 };
656 };
657 rspamd = mkOption {
658 description = "rspamd configuration";
659 type = submodule {
660 options = {
661 redis = mkRedisOptions "Redis";
662 read_password_hashed = mkOption { type = str; description = "Hashed read password for rspamd"; };
663 write_password_hashed = mkOption { type = str; description = "Hashed write password for rspamd"; };
664 read_password = mkOption {
665 type = str;
666 description = "Read password for rspamd. Unused";
667 apply = x: "";
668 };
669 write_password = mkOption {
670 type = str;
671 description = "Write password for rspamd. Unused";
672 apply = x: "";
673 };
674 };
675 };
676 };
677 scripts = mkOption {
678 description = "Mail script recipients";
679 type = attrsOf (submodule {
680 options = {
5b53d86f 681 external = mkEnableOption "Create a script_<name>@mail.immae.eu external address";
ab8f306d
IB
682 src = mkOption {
683 description = ''
684 git source to fetch the script from.
685 It must have a default.nix file as its root accepting a scriptEnv parameter
686 '';
687 type = submodule {
688 options = {
689 url = mkOption { type = str; description = "git url to fetch"; };
690 rev = mkOption { type = str; description = "git reference to fetch"; };
691 };
692 };
693 };
694 env = mkOption {
695 description = "Variables to pass to the script";
696 type = unspecified;
697 };
698 };
699 });
700 };
418a4ed7
IB
701 sympa = mkOption {
702 description = "Sympa configuration";
703 type = submodule {
704 options = {
705 listmasters = mkOption {
706 type = listOf str;
707 description = "Listmasters";
708 };
709 postgresql = mkPsqlOptions "Sympa";
710 data_sources = mkOption {
711 type = attrsOf str;
712 default = {};
713 description = "Data sources to make available to sympa";
714 };
715 scenari = mkOption {
716 type = attrsOf str;
717 default = {};
718 description = "Scenari to make available to sympa";
719 };
720 };
721 };
722 };
ab8f306d
IB
723 };
724 };
725 };
726 buildbot = mkOption {
727 description = "Buildbot configuration";
728 type = submodule {
729 options = {
730 user = mkOption {
731 description = "Buildbot user";
732 type = submodule {
733 options = {
734 uid = mkOption {
735 description = "user uid";
736 type = int;
737 };
738 gid = mkOption {
739 description = "user gid";
740 type = int;
741 };
742 };
743 };
744 };
745 ldap = mkOption {
746 description = "Ldap configuration for buildbot";
747 type = submodule {
748 options = {
749 password = mkOption { type = str; description = "Buildbot password"; };
750 };
751 };
752 };
753 projects = mkOption {
754 description = "Projects to make a buildbot for";
755 type = attrsOf (submodule {
756 options = {
757 name = mkOption { type = str; description = "Project name"; };
758 packages = mkOption {
759 type = unspecified;
760 example = literalExample ''
761 pkgs: [ pkgs.bash pkgs.git pkgs.gzip pkgs.openssh ];
762 '';
763 description = ''
764 Function.
765 Builds packages list to make available to buildbot project.
766 Takes pkgs as argument.
767 '';
768 };
769 pythonPackages = mkOption {
770 type = unspecified;
771 example = literalExample ''
772 p: pkgs: [ pkgs.python3Packages.pip ];
773 '';
774 description = ''
775 Function.
776 Builds python packages list to make available to buildbot project.
777 Takes buildbot python module as first argument and pkgs as second argument in order to augment the python modules list.
778 '';
779 };
780 pythonPathHome = mkOption { type = bool; description = "Whether to add project’s python home to python path"; };
781 secrets = mkOption {
782 type = attrsOf str;
783 description = "Secrets for the project to dump as files";
784 };
785 environment = mkOption {
786 type = attrsOf str;
787 description = ''
788 Environment variables for the project.
789 BUILDBOT_ is prefixed to the variable names
790 '';
791 };
792 activationScript = mkOption {
793 type = lines;
794 description = ''
795 Activation script to run during deployment
796 '';
797 };
798 builderPaths = mkOption {
799 type = attrsOf unspecified;
800 default = {};
801 description = ''
802 Attrs of functions to make accessible specifically per builder.
803 Takes pkgs as argument and should return a single path containing binaries.
804 This path will be accessible as BUILDBOT_PATH_<attrskey>
805 '';
806 };
807 webhookTokens = mkOption {
808 type = nullOr (listOf str);
809 default = null;
810 description = ''
811 List of tokens allowed to push to project’s change_hook/base endpoint
812 '';
813 };
814 };
815 });
816 };
817 };
818 };
819 };
820 tools = mkOption {
821 description = "Tools configurations";
822 type = submodule {
823 options = {
251c0a13 824 contact = mkOption { type = str; description = "Contact e-mail address"; };
ab8f306d
IB
825 davical = mkOption {
826 description = "Davical configuration";
827 type = submodule {
828 options = {
829 postgresql = mkPsqlOptions "Davical";
830 ldap = mkLdapOptions "Davical" {};
831 };
832 };
833 };
834 diaspora = mkOption {
835 description = "Diaspora configuration";
836 type = submodule {
837 options = {
838 postgresql = mkPsqlOptions "Diaspora";
839 redis = mkRedisOptions "Diaspora";
840 ldap = mkLdapOptions "Diaspora" {};
841 secret_token = mkOption { type = str; description = "Secret token"; };
842 };
843 };
844 };
7df5e532
IB
845 dmarc_reports = mkOption {
846 description = "DMARC reports configuration";
847 type = submodule {
848 options = {
849 mysql = mkMysqlOptions "DMARC" {};
9c08c3bc 850 anonymous_key = mkOption { type = str; description = "Anonymous hashing key"; };
7df5e532
IB
851 };
852 };
853 };
ab8f306d
IB
854 etherpad-lite = mkOption {
855 description = "Etherpad configuration";
856 type = submodule {
857 options = {
858 postgresql = mkPsqlOptions "Etherpad";
859 ldap = mkLdapOptions "Etherpad" {
860 group_filter = mkOption { type = str; description = "Filter for groups"; };
861 };
f0d942ac 862 adminPassword = mkOption { type = str; description = "Admin password for mypads / admin"; };
ab8f306d
IB
863 session_key = mkOption { type = str; description = "Session key"; };
864 api_key = mkOption { type = str; description = "API key"; };
865 redirects = mkOption { type = str; description = "Redirects for apache"; };
866 };
867 };
868 };
869 gitolite = mkOption {
870 description = "Gitolite configuration";
871 type = submodule {
872 options = {
873 ldap = mkLdapOptions "Gitolite" {};
874 };
875 };
876 };
877 kanboard = mkOption {
878 description = "Kanboard configuration";
879 type = submodule {
880 options = {
881 postgresql = mkPsqlOptions "Kanboard";
882 ldap = mkLdapOptions "Kanboard" {
883 admin_dn = mkOption { type = str; description = "Admin DN"; };
884 };
885 };
886 };
887 };
888 mantisbt = mkOption {
889 description = "Mantisbt configuration";
890 type = submodule {
891 options = {
892 postgresql = mkPsqlOptions "Mantisbt";
893 ldap = mkLdapOptions "Mantisbt" {};
894 master_salt = mkOption { type = str; description = "Master salt for password hash"; };
895 };
896 };
897 };
898 mastodon = mkOption {
899 description = "Mastodon configuration";
900 type = submodule {
901 options = {
902 postgresql = mkPsqlOptions "Mastodon";
903 redis = mkRedisOptions "Mastodon";
904 ldap = mkLdapOptions "Mastodon" {};
905 paperclip_secret = mkOption { type = str; description = "Paperclip secret"; };
906 otp_secret = mkOption { type = str; description = "OTP secret"; };
907 secret_key_base = mkOption { type = str; description = "Secret key base"; };
908 vapid = mkOption {
909 description = "vapid key";
910 type = submodule {
911 options = {
912 private = mkOption { type = str; description = "Private key"; };
913 public = mkOption { type = str; description = "Public key"; };
914 };
915 };
916 };
917 };
918 };
919 };
920 mediagoblin = mkOption {
921 description = "Mediagoblin configuration";
922 type = submodule {
923 options = {
924 postgresql = mkPsqlOptions "Mediagoblin";
925 redis = mkRedisOptions "Mediagoblin";
926 ldap = mkLdapOptions "Mediagoblin" {};
927 };
928 };
929 };
930 nextcloud = mkOption {
931 description = "Nextcloud configuration";
932 type = submodule {
933 options = {
934 postgresql = mkPsqlOptions "Peertube";
935 redis = mkRedisOptions "Peertube";
936 password_salt = mkOption { type = str; description = "Password salt"; };
937 instance_id = mkOption { type = str; description = "Instance ID"; };
938 secret = mkOption { type = str; description = "App secret"; };
939 };
940 };
941 };
942 peertube = mkOption {
943 description = "Peertube configuration";
944 type = submodule {
945 options = {
946 listenPort = mkOption { type = port; description = "Port to listen to"; };
947 postgresql = mkPsqlOptions "Peertube";
948 redis = mkRedisOptions "Peertube";
949 ldap = mkLdapOptions "Peertube" {};
950 };
951 };
952 };
8a05c7fb
IB
953 syden_peertube = mkOption {
954 description = "Peertube Syden configuration";
955 type = submodule {
956 options = {
957 listenPort = mkOption { type = port; description = "Port to listen to"; };
958 postgresql = mkPsqlOptions "Peertube";
959 redis = mkRedisOptions "Peertube";
960 };
961 };
962 };
ab8f306d
IB
963 phpldapadmin = mkOption {
964 description = "phpLdapAdmin configuration";
965 type = submodule {
966 options = {
967 ldap = mkLdapOptions "phpldapadmin" {};
968 };
969 };
970 };
971 rompr = mkOption {
972 description = "Rompr configuration";
973 type = submodule {
974 options = {
975 mpd = mkOption {
976 description = "MPD configuration";
977 type = submodule {
978 options = {
979 host = mkOption { type = str; description = "Host for MPD"; };
980 port = mkOption { type = port; description = "Port to access MPD host"; };
981 };
982 };
983 };
984 };
985 };
986 };
987 roundcubemail = mkOption {
988 description = "Roundcubemail configuration";
989 type = submodule {
990 options = {
991 postgresql = mkPsqlOptions "TT-RSS";
992 secret = mkOption { type = str; description = "Secret"; };
993 };
994 };
995 };
996 shaarli = mkOption {
997 description = "Shaarli configuration";
998 type = submodule {
999 options = {
1000 ldap = mkLdapOptions "Shaarli" {};
1001 };
1002 };
1003 };
1004 task = mkOption {
1005 description = "Taskwarrior configuration";
1006 type = submodule {
1007 options = {
1008 ldap = mkLdapOptions "Taskwarrior" {};
1009 taskwarrior-web = mkOption {
1010 description = "taskwarrior-web profiles";
1011 type = attrsOf (submodule {
1012 options = {
1013 uid = mkOption {
1014 type = listOf str;
1015 description = "List of ldap uids having access to this profile";
1016 };
1017 org = mkOption { type = str; description = "Taskd organisation"; };
1018 key = mkOption { type = str; description = "Taskd key"; };
1019 date = mkOption { type = str; description = "Preferred date format"; };
1020 };
1021 });
1022 };
1023 };
1024 };
1025 };
1026 ttrss = mkOption {
1027 description = "TT-RSS configuration";
1028 type = submodule {
1029 options = {
1030 postgresql = mkPsqlOptions "TT-RSS";
1031 ldap = mkLdapOptions "TT-RSS" {};
1032 };
1033 };
1034 };
1035 wallabag = mkOption {
1036 description = "Wallabag configuration";
1037 type = submodule {
1038 options = {
1039 postgresql = mkPsqlOptions "Wallabag";
1040 ldap = mkLdapOptions "Wallabag" {
1041 admin_filter = mkOption { type = str; description = "Admin users filter"; };
1042 };
1043 redis = mkRedisOptions "Wallabag";
1044 secret = mkOption { type = str; description = "App secret"; };
1045 };
1046 };
1047 };
251c0a13
IB
1048 webhooks = mkOption {
1049 type = attrsOf str;
1050 description = "Mapping 'name'.php => script for webhooks";
1051 };
ab8f306d
IB
1052 ympd = mkOption {
1053 description = "Ympd configuration";
1054 type = submodule {
1055 options = {
1056 listenPort = mkOption { type = port; description = "Port to listen to"; };
1057 mpd = mkOption {
1058 description = "MPD configuration";
1059 type = submodule {
1060 options = {
1061 password = mkOption { type = str; description = "Password to access MPD host"; };
1062 host = mkOption { type = str; description = "Host for MPD"; };
1063 port = mkOption { type = port; description = "Port to access MPD host"; };
1064 };
1065 };
1066 };
1067 };
1068 };
1069 };
1070 yourls = mkOption {
1071 description = "Yourls configuration";
1072 type = submodule {
1073 options = {
87a8bffd 1074 mysql = mkMysqlOptions "Yourls" {};
ab8f306d
IB
1075 ldap = mkLdapOptions "Yourls" {};
1076 cookieKey = mkOption { type = str; description = "Cookie key"; };
1077 };
1078 };
1079 };
1080 };
1081 };
1082 };
1083 websites = mkOption {
1084 description = "Websites configurations";
1085 type = submodule {
1086 options = {
829ef7f1
IB
1087 isabelle = mkOption {
1088 description = "Isabelle configurations by environment";
ab8f306d
IB
1089 type =
1090 let
1091 atenSubmodule = mkOption {
1092 description = "environment configuration";
1093 type = submodule {
1094 options = {
1095 environment = mkOption { type = str; description = "Symfony environment"; };
1096 secret = mkOption { type = str; description = "Symfony App secret"; };
1097 postgresql = mkPsqlOptions "Aten";
1098 };
1099 };
1100 };
1101 in
1102 submodule {
1103 options = {
829ef7f1
IB
1104 aten_production = atenSubmodule;
1105 aten_integration = atenSubmodule;
423c3f1c
IB
1106 iridologie = mkOption {
1107 description = "environment configuration";
1108 type = submodule {
1109 options = {
1110 environment = mkOption { type = str; description = "SPIP environment"; };
1111 mysql = mkMysqlOptions "Iridologie" {};
1112 ldap = mkLdapOptions "Iridologie" {};
1113 };
1114 };
1115 };
ab8f306d
IB
1116 };
1117 };
1118 };
1119 chloe = mkOption {
1120 description = "Chloe configurations by environment";
1121 type =
1122 let
1123 chloeSubmodule = mkOption {
1124 description = "environment configuration";
1125 type = submodule {
1126 options = {
423c3f1c 1127 environment = mkOption { type = str; description = "SPIP environment"; };
87a8bffd 1128 mysql = mkMysqlOptions "Chloe" {};
ab8f306d
IB
1129 ldap = mkLdapOptions "Chloe" {};
1130 };
1131 };
1132 };
1133 in
1134 submodule {
1135 options = {
1136 production = chloeSubmodule;
1137 integration = chloeSubmodule;
1138 };
1139 };
1140 };
1141 connexionswing = mkOption {
1142 description = "Connexionswing configurations by environment";
1143 type =
1144 let
1145 csSubmodule = mkOption {
1146 description = "environment configuration";
1147 type = submodule {
1148 options = {
1149 environment = mkOption { type = str; description = "Symfony environment"; };
87a8bffd 1150 mysql = mkMysqlOptions "Connexionswing" {};
ab8f306d
IB
1151 secret = mkOption { type = str; description = "Symfony App secret"; };
1152 email = mkOption { type = str; description = "Symfony email notification"; };
1153 };
1154 };
1155 };
1156 in
1157 submodule {
1158 options = {
1159 production = csSubmodule;
1160 integration = csSubmodule;
1161 };
1162 };
1163 };
1164 jerome = mkOption {
1165 description = "Naturaloutil configuration";
1166 type = submodule {
1167 options = {
87a8bffd 1168 mysql = mkMysqlOptions "Naturaloutil" {};
ab8f306d
IB
1169 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1170 };
1171 };
1172 };
d3452fc5 1173 telio_tortay = mkOption {
ab8f306d
IB
1174 description = "Telio Tortay configuration";
1175 type = submodule {
1176 options = {
1177 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1178 };
1179 };
1180 };
d3452fc5 1181 ludivine = mkOption {
ab8f306d
IB
1182 description = "Ludivinecassal configurations by environment";
1183 type =
1184 let
1185 lcSubmodule = mkOption {
1186 description = "environment configuration";
1187 type = submodule {
1188 options = {
1189 environment = mkOption { type = str; description = "Symfony environment"; };
87a8bffd 1190 mysql = mkMysqlOptions "LudivineCassal" {};
ab8f306d
IB
1191 ldap = mkLdapOptions "LudivineCassal" {};
1192 secret = mkOption { type = str; description = "Symfony App secret"; };
1193 };
1194 };
1195 };
1196 in
1197 submodule {
1198 options = {
1199 production = lcSubmodule;
1200 integration = lcSubmodule;
1201 };
1202 };
1203 };
1204 emilia = mkOption {
1205 description = "Emilia configuration";
1206 type = submodule {
1207 options = {
1208 postgresql = mkPsqlOptions "Emilia";
1209 };
1210 };
1211 };
1212 florian = mkOption {
1213 description = "Florian configuration";
1214 type = submodule {
1215 options = {
1216 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1217 };
1218 };
1219 };
1220 nassime = mkOption {
1221 description = "Nassime configuration";
1222 type = submodule {
1223 options = {
1224 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1225 };
1226 };
1227 };
1228 piedsjaloux = mkOption {
1229 description = "Piedsjaloux configurations by environment";
1230 type =
1231 let
1232 pjSubmodule = mkOption {
1233 description = "environment configuration";
1234 type = submodule {
1235 options = {
1236 environment = mkOption { type = str; description = "Symfony environment"; };
87a8bffd 1237 mysql = mkMysqlOptions "Piedsjaloux" {};
ab8f306d
IB
1238 secret = mkOption { type = str; description = "Symfony App secret"; };
1239 };
1240 };
1241 };
1242 in
1243 submodule {
1244 options = {
1245 production = pjSubmodule;
1246 integration = pjSubmodule;
1247 };
1248 };
1249 };
91b75ffe
IB
1250 richie = mkOption {
1251 description = "Europe Richie configurations by environment";
1252 type = submodule {
1253 options = {
87a8bffd 1254 mysql = mkMysqlOptions "Richie" {};
91b75ffe
IB
1255 smtp_mailer = mkOption {
1256 description = "SMTP mailer configuration";
1257 type = submodule {
1258 options = {
1259 user = mkOption { type = str; description = "Username"; };
1260 password = mkOption { type = str; description = "Password"; };
1261 };
1262 };
1263 };
1264 };
1265 };
1266 };
ab8f306d
IB
1267 tellesflorian = mkOption {
1268 description = "Tellesflorian configurations by environment";
1269 type =
1270 let
1271 tfSubmodule = mkOption {
1272 description = "environment configuration";
1273 type = submodule {
1274 options = {
1275 environment = mkOption { type = str; description = "Symfony environment"; };
87a8bffd 1276 mysql = mkMysqlOptions "Tellesflorian" {};
ab8f306d
IB
1277 secret = mkOption { type = str; description = "Symfony App secret"; };
1278 invite_passwords = mkOption { type = str; description = "Password basic auth"; };
1279 };
1280 };
1281 };
1282 in
1283 submodule {
1284 options = {
1285 integration = tfSubmodule;
1286 };
1287 };
1288 };
1289 };
1290 };
1291 };
1292
1293 privateFiles = mkOption {
1294 type = path;
1295 description = ''
1296 Path to secret files to make available during build
1297 '';
1298 };
1299 };
619e4f46
IB
1300 options.hostEnv = mkOption {
1301 readOnly = true;
1302 type = hostEnv;
1303 default = config.myEnv.servers."${name}";
1304 description = "Host environment";
ab8f306d
IB
1305 };
1306}