]> git.immae.eu Git - perso/Immae/Config/Nix.git/blob - modules/private/environment.nix
65d9f0a5ab0975737185da7ba96470a9d7080582
[perso/Immae/Config/Nix.git] / modules / private / environment.nix
1 { config, lib, name, ... }:
2 with lib;
3 with types;
4 with lists;
5 let
6 ldapOptions = {
7 base = mkOption { description = "Base of the LDAP tree"; type = str; };
8 host = mkOption { description = "Host to access LDAP"; type = str; };
9 root_dn = mkOption { description = "DN of the root user"; type = str; };
10 root_pw = mkOption { description = "Hashed password of the root user"; type = str; };
11 replication_dn = mkOption { description = "DN of the user allowed to replicate the LDAP directory"; type = str; };
12 replication_pw = mkOption { description = "Password of the user allowed to replicate the LDAP directory"; type = str; };
13 };
14 mkLdapOptions = name: more: mkOption {
15 description = "${name} LDAP configuration";
16 type = submodule {
17 options = ldapOptions // {
18 dn = mkOption { description = "DN of the ${name} user"; type = str; };
19 password = mkOption { description = "password of the ${name} user"; type = str; };
20 filter = mkOption { description = "Filter for ${name} users"; type = str; default = ""; };
21 } // more;
22 };
23 };
24 mysqlOptions = {
25 host = mkOption { description = "Host to access Mysql"; type = str; };
26 remoteHost = mkOption { description = "Host to access Mysql from outside"; type = str; };
27 port = mkOption { description = "Port to access Mysql"; type = str; };
28 socket = mkOption { description = "Socket to access Mysql"; type = path; };
29 systemUsers = mkOption {
30 description = "Attrs of user-passwords allowed to access mysql";
31 type = attrsOf str;
32 };
33 pam = mkOption {
34 description = "PAM configuration for mysql";
35 type = submodule {
36 options = {
37 dn = mkOption { description = "DN to connect as to check users"; type = str; };
38 password = mkOption { description = "DN password to connect as to check users"; type = str; };
39 filter = mkOption { description = "filter to match users"; type = str; };
40 };
41 };
42 };
43 };
44 mkMysqlOptions = name: more: mkOption {
45 description = "${name} mysql configuration";
46 type = submodule {
47 options = mysqlOptions // {
48 database = mkOption { description = "${name} database"; type = str; };
49 user = mkOption { description = "${name} user"; type = str; };
50 password = mkOption { description = "mysql password of the ${name} user"; type = str; };
51 } // more;
52 };
53 };
54 psqlOptions = {
55 host = mkOption { description = "Host to access Postgresql"; type = str; };
56 port = mkOption { description = "Port to access Postgresql"; type = str; };
57 socket = mkOption { description = "Socket to access Postgresql"; type = path; };
58 pam = mkOption {
59 description = "PAM configuration for psql";
60 type = submodule {
61 options = {
62 dn = mkOption { description = "DN to connect as to check users"; type = str; };
63 password = mkOption { description = "DN password to connect as to check users"; type = str; };
64 filter = mkOption { description = "filter to match users"; type = str; };
65 };
66 };
67 };
68 };
69 mkPsqlOptions = name: mkOption {
70 description = "${name} psql configuration";
71 type = submodule {
72 options = psqlOptions // {
73 database = mkOption { description = "${name} database"; type = str; };
74 schema = mkOption { description = "${name} schema"; type = nullOr str; default = null; };
75 user = mkOption { description = "${name} user"; type = str; };
76 password = mkOption { description = "psql password of the ${name} user"; type = str; };
77 };
78 };
79 };
80 redisOptions = {
81 host = mkOption { description = "Host to access Redis"; type = str; };
82 port = mkOption { description = "Port to access Redis"; type = str; };
83 socket = mkOption { description = "Socket to access Redis"; type = path; };
84 dbs = mkOption {
85 description = "Attrs of db number. Each number should be unique to avoid collision!";
86 type = attrsOf str;
87 };
88 spiped_key = mkOption {
89 type = str;
90 description = ''
91 Key to use with spiped to make a secure channel to replication
92 '';
93 };
94 predixy = mkOption {
95 description = "Predixy configuration. Unused yet";
96 type = submodule {
97 options = {
98 read = mkOption { type = str; description = "Read password"; };
99 };
100 };
101 };
102 };
103 mkRedisOptions = name: mkOption {
104 description = "${name} redis configuration";
105 type = submodule {
106 options = redisOptions // {
107 db = mkOption { description = "${name} database"; type = str; };
108 };
109 };
110 };
111 smtpOptions = {
112 host = mkOption { description = "Host to access SMTP"; type = str; };
113 port = mkOption { description = "Port to access SMTP"; type = str; };
114 };
115 mkSmtpOptions = name: mkOption {
116 description = "${name} smtp configuration";
117 type = submodule {
118 options = smtpOptions // {
119 email = mkOption { description = "${name} email"; type = str; };
120 password = mkOption { description = "SMTP password of the ${name} user"; type = str; };
121 };
122 };
123 };
124 hostEnv = submodule {
125 options = {
126 fqdn = mkOption {
127 description = "Host FQDN";
128 type = str;
129 };
130 users = mkOption {
131 type = unspecified;
132 default = pkgs: [];
133 description = ''
134 Sublist of users from realUsers. Function that takes pkgs as
135 argument and gives an array as a result
136 '';
137 };
138 emails = mkOption {
139 default = [];
140 description = "List of e-mails that the server can be a sender of";
141 type = listOf str;
142 };
143 ldap = mkOption {
144 description = ''
145 LDAP credentials for the host
146 '';
147 type = submodule {
148 options = {
149 password = mkOption { type = str; description = "Password for the LDAP connection"; };
150 dn = mkOption { type = str; description = "DN for the LDAP connection"; };
151 };
152 };
153 };
154 mx = mkOption {
155 description = "subdomain and priority for MX server";
156 default = { enable = false; };
157 type = submodule {
158 options = {
159 enable = mkEnableOption "Enable MX";
160 subdomain = mkOption { type = nullOr str; description = "Subdomain name (mx-*)"; };
161 priority = mkOption { type = nullOr str; description = "Priority"; };
162 };
163 };
164 };
165 ips = mkOption {
166 description = ''
167 attrs of ip4/ip6 grouped by section
168 '';
169 type = attrsOf (submodule {
170 options = {
171 ip4 = mkOption {
172 type = str;
173 description = ''
174 ip4 address of the host
175 '';
176 };
177 ip6 = mkOption {
178 type = listOf str;
179 default = [];
180 description = ''
181 ip6 addresses of the host
182 '';
183 };
184 };
185 });
186 };
187 };
188 };
189 in
190 {
191 options.myEnv = {
192 servers = mkOption {
193 description = ''
194 Attrs of servers information in the cluster (not necessarily handled by nixops)
195 '';
196 default = {};
197 type = attrsOf hostEnv;
198 };
199 hetznerCloud = mkOption {
200 description = ''
201 Hetzner Cloud credential information
202 '';
203 type = submodule {
204 options = {
205 authToken = mkOption {
206 type = str;
207 description = ''
208 The API auth token.
209 '';
210 };
211 };
212 };
213 };
214 hetzner = mkOption {
215 description = ''
216 Hetzner credential information
217 '';
218 type = submodule {
219 options = {
220 user = mkOption { type = str; description = "User"; };
221 pass = mkOption { type = str; description = "Password"; };
222 };
223 };
224 };
225 sshd = mkOption {
226 description = ''
227 sshd service credential information
228 '';
229 type = submodule {
230 options = {
231 rootKeys = mkOption { type = attrsOf str; description = "Keys of root users"; };
232 ldap = mkOption {
233 description = ''
234 LDAP credentials for cn=ssh,ou=services,dc=immae,dc=eu dn
235 '';
236 type = submodule {
237 options = {
238 password = mkOption { description = "Password"; type = str; };
239 };
240 };
241 };
242 };
243 };
244 };
245 ports = mkOption {
246 description = ''
247 non-standard reserved ports. Must be unique!
248 '';
249 type = attrsOf port;
250 default = {};
251 apply = let
252 noDupl = x: builtins.length (builtins.attrValues x) == builtins.length (unique (builtins.attrValues x));
253 in
254 x: if isAttrs x && noDupl x then x else throw "Non unique values for ports";
255 };
256 httpd = mkOption {
257 description = ''
258 httpd service credential information
259 '';
260 type = submodule {
261 options = {
262 ldap = mkOption {
263 description = ''
264 LDAP credentials for cn=httpd,ou=services,dc=immae,dc=eu dn
265 '';
266 type = submodule {
267 options = {
268 password = mkOption { description = "Password"; type = str; };
269 };
270 };
271 };
272 };
273 };
274 };
275 smtp = mkOption {
276 type = submodule { options = smtpOptions; };
277 description = "SMTP configuration";
278 };
279 ldap = mkOption {
280 description = ''
281 LDAP server configuration
282 '';
283 type = submodule {
284 options = ldapOptions;
285 };
286 };
287 databases = mkOption {
288 description = "Databases configuration";
289 type = submodule {
290 options = {
291 mysql = mkOption {
292 type = submodule { options = mysqlOptions; };
293 description = "Mysql configuration";
294 };
295 redis = mkOption {
296 type = submodule { options = redisOptions; };
297 description = "Redis configuration";
298 };
299 postgresql = mkOption {
300 type = submodule { options = psqlOptions; };
301 description = "Postgresql configuration";
302 };
303 };
304 };
305 };
306 jabber = mkOption {
307 description = "Jabber configuration";
308 type = submodule {
309 options = {
310 postfix_user_filter = mkOption { type = str; description = "Postfix filter to get xmpp users"; };
311 ldap = mkLdapOptions "Jabber" {};
312 postgresql = mkPsqlOptions "Jabber";
313 };
314 };
315 };
316 realUsers = mkOption {
317 description = ''
318 Attrset of function taking pkgs as argument.
319 Real users settings, should provide a subattr of users.users.<name>
320 with at least: name, (hashed)Password, shell
321 '';
322 type = attrsOf unspecified;
323 };
324 users = mkOption {
325 description = "System and regular users uid/gid";
326 type = attrsOf (submodule {
327 options = {
328 uid = mkOption {
329 description = "user uid";
330 type = int;
331 };
332 gid = mkOption {
333 description = "user gid";
334 type = int;
335 };
336 };
337 });
338 };
339 dns = mkOption {
340 description = "DNS configuration";
341 type = submodule {
342 options = {
343 soa = mkOption {
344 description = "SOA information";
345 type = submodule {
346 options = {
347 serial = mkOption {
348 description = "Serial number. Should be incremented at each change and unique";
349 type = str;
350 };
351 refresh = mkOption {
352 description = "Refresh time";
353 type = str;
354 };
355 retry = mkOption {
356 description = "Retry time";
357 type = str;
358 };
359 expire = mkOption {
360 description = "Expire time";
361 type = str;
362 };
363 ttl = mkOption {
364 description = "Default TTL time";
365 type = str;
366 };
367 email = mkOption {
368 description = "hostmaster e-mail";
369 type = str;
370 };
371 primary = mkOption {
372 description = "Primary NS";
373 type = str;
374 };
375 };
376 };
377 };
378 ns = mkOption {
379 description = "Attrs of NS servers group";
380 example = {
381 foo = {
382 "ns1.foo.com" = [ "198.51.100.10" "2001:db8:abcd::1" ];
383 "ns2.foo.com" = [ "198.51.100.15" "2001:db8:1234::1" ];
384 };
385 };
386 type = attrsOf (attrsOf (listOf str));
387 };
388 keys = mkOption {
389 default = {};
390 description = "DNS keys";
391 type = attrsOf (submodule {
392 options = {
393 algorithm = mkOption { type = str; description = "Algorithm"; };
394 secret = mkOption { type = str; description = "Secret"; };
395 };
396 });
397 };
398 slaveZones = mkOption {
399 description = "List of slave zones";
400 type = listOf (submodule {
401 options = {
402 name = mkOption { type = str; description = "zone name"; };
403 masters = mkOption {
404 description = "NS master groups of this zone";
405 type = listOf str;
406 };
407 keys = mkOption {
408 default = [];
409 description = "Keys associated to the server";
410 type = listOf str;
411 };
412 };
413 });
414 };
415 masterZones = mkOption {
416 description = "List of master zones";
417 type = listOf (submodule {
418 options = {
419 name = mkOption { type = str; description = "zone name"; };
420 withCAA = mkOption { type = nullOr str; description = "CAA entry"; default = null; };
421 slaves = mkOption {
422 description = "NS slave groups of this zone";
423 type = listOf str;
424 };
425 ns = mkOption {
426 description = "groups names that should have their NS entries listed here";
427 type = listOf str;
428 };
429 extra = mkOption {
430 description = "Extra zone configuration for bind";
431 example = ''
432 notify yes;
433 '';
434 type = lines;
435 };
436 entries = mkOption { type = lines; description = "Regular entries of the NS zone"; };
437 withEmail = mkOption {
438 description = "List of domains that should have mail entries (MX, dkim, SPF, ...)";
439 default = [];
440 type = listOf (submodule {
441 options = {
442 domain = mkOption { type = str; description = "Which subdomain is concerned"; };
443 send = mkOption { type = bool; description = "Whether there can be e-mails originating from the subdomain"; };
444 receive = mkOption { type = bool; description = "Whether there can be e-mails arriving to the subdomain"; };
445 };
446 });
447 };
448 };
449 });
450 };
451 };
452 };
453 };
454 backup = mkOption {
455 description = ''
456 Remote backup with duplicity
457 '';
458 type = submodule {
459 options = {
460 password = mkOption { type = str; description = "Password for encrypting files"; };
461 remotes = mkOption {
462 type = attrsOf (submodule {
463 options = {
464 remote = mkOption {
465 type = unspecified;
466 example = literalExample ''
467 bucket: "s3://some_host/${bucket}";
468 '';
469 description = ''
470 Function.
471 Takes a bucket name as argument and returns a url
472 '';
473 };
474 accessKeyId = mkOption { type = str; description = "Remote access-key"; };
475 secretAccessKey = mkOption { type = str; description = "Remote access secret"; };
476 };
477 });
478 };
479 };
480 };
481 };
482 zrepl_backup = mkOption {
483 type = submodule {
484 options = {
485 ssh_key = mkOption {
486 description = "SSH key information";
487 type = submodule {
488 options = {
489 public = mkOption { type = str; description = "Public part of the key"; };
490 private = mkOption { type = lines; description = "Private part of the key"; };
491 };
492 };
493 };
494 mysql = mkMysqlOptions "Zrepl" {};
495 };
496 };
497 };
498 rsync_backup = mkOption {
499 description =''
500 Rsync backup configuration from controlled host
501 '';
502 type = submodule {
503 options = {
504 ssh_key = mkOption {
505 description = "SSH key information";
506 type = submodule {
507 options = {
508 public = mkOption { type = str; description = "Public part of the key"; };
509 private = mkOption { type = lines; description = "Private part of the key"; };
510 };
511 };
512 };
513 profiles = mkOption {
514 description = "Attrs of profiles to backup";
515 type = attrsOf (submodule {
516 options = {
517 keep = mkOption { type = int; description = "Number of backups to keep"; };
518 check_command = mkOption { type = str; description = "command to check if backup needs to be done"; default = "backup"; };
519 login = mkOption { type = str; description = "Login to connect to host"; };
520 port = mkOption { type = str; default = "22"; description = "Port to connect to host"; };
521 host = mkOption { type = str; description = "Host to connect to"; };
522 host_key = mkOption { type = str; description = "Host key"; };
523 host_key_type = mkOption { type = str; description = "Host key type"; };
524 parts = mkOption {
525 description = "Parts to backup for this host";
526 type = attrsOf (submodule {
527 options = {
528 remote_folder = mkOption { type = path; description = "Remote folder to backup";};
529 exclude_from = mkOption {
530 type = listOf path;
531 default = [];
532 description = "List of folders/files to exclude from the backup";
533 };
534 files_from = mkOption {
535 type = listOf path;
536 default = [];
537 description = "List of folders/files to backup in the base folder";
538 };
539 args = mkOption {
540 type = nullOr str;
541 default = null;
542 description = "Extra arguments to pass to rsync";
543 };
544 };
545 });
546 };
547 };
548 });
549 };
550 };
551 };
552 };
553 monitoring = mkOption {
554 description = "Monitoring configuration";
555 type = submodule {
556 options = {
557 status_url = mkOption { type = str; description = "URL to push status to"; };
558 status_token = mkOption { type = str; description = "Token for the status url"; };
559 http_user_password = mkOption { type = str; description = "HTTP credentials to check services behind wall"; };
560 email = mkOption { type = str; description = "Admin E-mail"; };
561 ssh_public_key = mkOption { type = str; description = "SSH public key"; };
562 ssh_secret_key = mkOption { type = str; description = "SSH secret key"; };
563 imap_login = mkOption { type = str; description = "IMAP login"; };
564 imap_password = mkOption { type = str; description = "IMAP password"; };
565 eriomem_keys = mkOption { type = listOf (listOf str); description = "Eriomem keys"; default = []; };
566 ovh_sms = mkOption {
567 description = "OVH credentials for sms script";
568 type = submodule {
569 options = {
570 endpoint = mkOption { type = str; default = "ovh-eu"; description = "OVH endpoint"; };
571 application_key = mkOption { type = str; description = "Application key"; };
572 application_secret = mkOption { type = str; description = "Application secret"; };
573 consumer_key = mkOption { type = str; description = "Consumer key"; };
574 account = mkOption { type = str; description = "Account"; };
575 };
576 };
577 };
578 eban = mkOption {
579 description = "Eban credentials for webhook";
580 type = submodule {
581 options = {
582 user = mkOption { type = str; description = "User"; };
583 password = mkOption { type = str; description = "Password"; };
584 };
585 };
586 };
587 nrdp_tokens = mkOption { type = listOf str; description = "Tokens allowed to push status update"; };
588 slack_url = mkOption { type = str; description = "Slack webhook url to push status update"; };
589 slack_channel = mkOption { type = str; description = "Slack channel to push status update"; };
590 netdata_aggregator = mkOption { type = str; description = "Url where netdata information should be sent"; };
591 netdata_keys = mkOption { type = attrsOf str; description = "netdata host keys"; };
592 contacts = mkOption { type = attrsOf unspecified; description = "Contact dicts to fill naemon objects"; };
593 email_check = mkOption {
594 description = "Emails services to check";
595 type = attrsOf (submodule {
596 options = {
597 local = mkOption { type = bool; default = false; description = "Use local configuration"; };
598 port = mkOption { type = nullOr str; default = null; description = "Port to connect to ssh"; };
599 login = mkOption { type = nullOr str; default = null; description = "Login to connect to ssh"; };
600 targets = mkOption { type = listOf str; description = "Hosts to send E-mails to"; };
601 mail_address = mkOption { type = nullOr str; default = null; description = "E-mail recipient part to send e-mail to"; };
602 mail_domain = mkOption { type = nullOr str; default = null; description = "E-mail domain part to send e-mail to"; };
603 };
604 });
605 };
606 };
607 };
608 };
609 mpd = mkOption {
610 description = "MPD configuration";
611 type = submodule {
612 options = {
613 folder = mkOption { type = str; description = "Folder to serve from the MPD instance"; };
614 password = mkOption { type = str; description = "Password to connect to the MPD instance"; };
615 host = mkOption { type = str; description = "Host to connect to the MPD instance"; };
616 port = mkOption { type = str; description = "Port to connect to the MPD instance"; };
617 };
618 };
619 };
620 ftp = mkOption {
621 description = "FTP configuration";
622 type = submodule {
623 options = {
624 ldap = mkLdapOptions "FTP" {};
625 };
626 };
627 };
628 vpn = mkOption {
629 description = "VPN configuration";
630 type = attrsOf (submodule {
631 options = {
632 prefix = mkOption { type = str; description = "ipv6 prefix for the vpn subnet"; };
633 privateKey = mkOption { type = str; description = "Private key for the host"; };
634 publicKey = mkOption { type = str; description = "Public key for the host"; };
635 };
636 });
637 };
638 mail = mkOption {
639 description = "Mail configuration";
640 type = submodule {
641 options = {
642 dmarc = mkOption {
643 description = "DMARC configuration";
644 type = submodule {
645 options = {
646 ignore_hosts = mkOption {
647 type = lines;
648 description = ''
649 Hosts to ignore when checking for dmarc
650 '';
651 };
652 };
653 };
654 };
655 dkim = mkOption {
656 description = "DKIM configuration";
657 type = attrsOf (submodule {
658 options = {
659 public = mkOption {
660 type = str;
661 example = ''
662 ( "v=DKIM1; k=rsa; "
663 "p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC3w1a2aMxWw9+hdcmbqX4UevcVqr204y0K73Wdc7MPZiOOlUJQYsMNSYR1Y/SC7jmPKeitpcJCpQgn/cveJZbuikjjPLsDReHyFEYmC278ZLRTELHx6f1IXM8WE08JIRT69CfZiMi1rVcOh9qRT4F93PyjCauU8Y5hJjtg9ThsWwIDAQAB" )
664 '';
665 description = "Public entry to put in DNS TXT field";
666 };
667 private = mkOption { type = str; description = "Private key"; };
668 };
669 });
670 };
671 postfix = mkOption {
672 description = "Postfix configuration";
673 type = submodule {
674 options = {
675 additional_mailbox_domains = mkOption {
676 description = ''
677 List of domains that are used as mailbox final destination, in addition to those defined in the DNS records
678 '';
679 type = listOf str;
680 };
681 mysql = mkMysqlOptions "Postfix" {
682 password_encrypt = mkOption { type = str; description = "Key to encrypt relay password in database"; };
683 };
684 backup_domains = mkOption {
685 description = ''
686 Domains that are accepted for relay as backup domain
687 '';
688 type = attrsOf (submodule {
689 options = {
690 domains = mkOption { type = listOf str; description = "Domains list"; };
691 relay_restrictions = mkOption {
692 type = lines;
693 description = ''
694 Restrictions for relaying the e-mails from the domains
695 '';
696 };
697 recipient_maps = mkOption {
698 description = ''
699 Recipient map to accept relay for.
700 Must be specified for domain, the rules apply to everyone!
701 '';
702 type = listOf (submodule {
703 options = {
704 type = mkOption {
705 type = enum [ "hash" ];
706 description = "Map type";
707 };
708 content = mkOption {
709 type = str;
710 description = "Map content";
711 };
712 };
713 });
714 };
715 };
716 });
717 };
718 };
719 };
720 };
721 dovecot = mkOption {
722 description = "Dovecot configuration";
723 type = submodule {
724 options = {
725 ldap = mkLdapOptions "Dovecot" {
726 pass_attrs = mkOption { type = str; description = "Password attribute in LDAP"; };
727 user_attrs = mkOption { type = str; description = "User attribute mapping in LDAP"; };
728 iterate_attrs = mkOption { type = str; description = "User attribute mapping for listing in LDAP"; };
729 iterate_filter = mkOption { type = str; description = "User attribute filter for listing in LDAP"; };
730 postfix_mailbox_filter = mkOption { type = str; description = "Postfix filter to get mailboxes"; };
731 };
732 };
733 };
734 };
735 rspamd = mkOption {
736 description = "rspamd configuration";
737 type = submodule {
738 options = {
739 redis = mkRedisOptions "Redis";
740 read_password_hashed = mkOption { type = str; description = "Hashed read password for rspamd"; };
741 write_password_hashed = mkOption { type = str; description = "Hashed write password for rspamd"; };
742 read_password = mkOption {
743 type = str;
744 description = "Read password for rspamd. Unused";
745 apply = x: "";
746 };
747 write_password = mkOption {
748 type = str;
749 description = "Write password for rspamd. Unused";
750 apply = x: "";
751 };
752 };
753 };
754 };
755 scripts = mkOption {
756 description = "Mail script recipients";
757 type = attrsOf (submodule {
758 options = {
759 external = mkEnableOption "Create a script_<name>@mail.immae.eu external address";
760 src = mkOption {
761 description = ''
762 git source to fetch the script from.
763 It must have a default.nix file as its root accepting a scriptEnv parameter
764 '';
765 type = submodule {
766 options = {
767 url = mkOption { type = str; description = "git url to fetch"; };
768 rev = mkOption { type = str; description = "git reference to fetch"; };
769 };
770 };
771 };
772 env = mkOption {
773 description = "Variables to pass to the script";
774 type = unspecified;
775 };
776 };
777 });
778 };
779 sympa = mkOption {
780 description = "Sympa configuration";
781 type = submodule {
782 options = {
783 listmasters = mkOption {
784 type = listOf str;
785 description = "Listmasters";
786 };
787 postgresql = mkPsqlOptions "Sympa";
788 data_sources = mkOption {
789 type = attrsOf str;
790 default = {};
791 description = "Data sources to make available to sympa";
792 };
793 scenari = mkOption {
794 type = attrsOf str;
795 default = {};
796 description = "Scenari to make available to sympa";
797 };
798 };
799 };
800 };
801 };
802 };
803 };
804 buildbot = mkOption {
805 description = "Buildbot configuration";
806 type = submodule {
807 options = {
808 ssh_key = mkOption {
809 description = "SSH key information";
810 type = submodule {
811 options = {
812 public = mkOption { type = str; description = "Public part of the key"; };
813 private = mkOption { type = lines; description = "Private part of the key"; };
814 };
815 };
816 };
817 workerPassword = mkOption { description = "Buildbot worker password"; type = str; };
818 user = mkOption {
819 description = "Buildbot user";
820 type = submodule {
821 options = {
822 uid = mkOption {
823 description = "user uid";
824 type = int;
825 };
826 gid = mkOption {
827 description = "user gid";
828 type = int;
829 };
830 };
831 };
832 };
833 ldap = mkOption {
834 description = "Ldap configuration for buildbot";
835 type = submodule {
836 options = {
837 password = mkOption { type = str; description = "Buildbot password"; };
838 };
839 };
840 };
841 projects = mkOption {
842 description = "Projects to make a buildbot for";
843 type = attrsOf (submodule {
844 options = {
845 name = mkOption { type = str; description = "Project name"; };
846 packages = mkOption {
847 type = unspecified;
848 example = literalExample ''
849 pkgs: [ pkgs.bash pkgs.git pkgs.gzip pkgs.openssh ];
850 '';
851 description = ''
852 Function.
853 Builds packages list to make available to buildbot project.
854 Takes pkgs as argument.
855 '';
856 };
857 pythonPackages = mkOption {
858 type = unspecified;
859 example = literalExample ''
860 p: pkgs: [ pkgs.python3Packages.pip ];
861 '';
862 description = ''
863 Function.
864 Builds python packages list to make available to buildbot project.
865 Takes buildbot python module as first argument and pkgs as second argument in order to augment the python modules list.
866 '';
867 };
868 pythonPathHome = mkOption { type = bool; description = "Whether to add project’s python home to python path"; };
869 workerPort = mkOption { type = port; description = "Port for the worker"; };
870 secrets = mkOption {
871 type = attrsOf str;
872 description = "Secrets for the project to dump as files";
873 };
874 environment = mkOption {
875 type = attrsOf str;
876 description = ''
877 Environment variables for the project.
878 BUILDBOT_ is prefixed to the variable names
879 '';
880 };
881 activationScript = mkOption {
882 type = lines;
883 description = ''
884 Activation script to run during deployment
885 '';
886 };
887 builderPaths = mkOption {
888 type = attrsOf unspecified;
889 default = {};
890 description = ''
891 Attrs of functions to make accessible specifically per builder.
892 Takes pkgs as argument and should return a single path containing binaries.
893 This path will be accessible as BUILDBOT_PATH_<attrskey>
894 '';
895 };
896 webhookTokens = mkOption {
897 type = nullOr (listOf str);
898 default = null;
899 description = ''
900 List of tokens allowed to push to project’s change_hook/base endpoint
901 '';
902 };
903 };
904 });
905 };
906 };
907 };
908 };
909 tools = mkOption {
910 description = "Tools configurations";
911 type = submodule {
912 options = {
913 contact = mkOption { type = str; description = "Contact e-mail address"; };
914 assets = mkOption {
915 default = {};
916 type = attrsOf (submodule {
917 options = {
918 url = mkOption { type = str; description = "URL to fetch"; };
919 sha256 = mkOption { type = str; description = "Hash of the url"; };
920 };
921 });
922 description = "Assets to provide on assets.immae.eu";
923 };
924 davical = mkOption {
925 description = "Davical configuration";
926 type = submodule {
927 options = {
928 postgresql = mkPsqlOptions "Davical";
929 ldap = mkLdapOptions "Davical" {};
930 };
931 };
932 };
933 diaspora = mkOption {
934 description = "Diaspora configuration";
935 type = submodule {
936 options = {
937 postgresql = mkPsqlOptions "Diaspora";
938 redis = mkRedisOptions "Diaspora";
939 ldap = mkLdapOptions "Diaspora" {};
940 secret_token = mkOption { type = str; description = "Secret token"; };
941 };
942 };
943 };
944 dmarc_reports = mkOption {
945 description = "DMARC reports configuration";
946 type = submodule {
947 options = {
948 mysql = mkMysqlOptions "DMARC" {};
949 anonymous_key = mkOption { type = str; description = "Anonymous hashing key"; };
950 };
951 };
952 };
953 etherpad-lite = mkOption {
954 description = "Etherpad configuration";
955 type = submodule {
956 options = {
957 postgresql = mkPsqlOptions "Etherpad";
958 ldap = mkLdapOptions "Etherpad" {
959 group_filter = mkOption { type = str; description = "Filter for groups"; };
960 };
961 adminPassword = mkOption { type = str; description = "Admin password for mypads / admin"; };
962 session_key = mkOption { type = str; description = "Session key"; };
963 api_key = mkOption { type = str; description = "API key"; };
964 redirects = mkOption { type = str; description = "Redirects for apache"; };
965 };
966 };
967 };
968 gitolite = mkOption {
969 description = "Gitolite configuration";
970 type = submodule {
971 options = {
972 ldap = mkLdapOptions "Gitolite" {};
973 ssh_key = mkOption {
974 description = "SSH key information";
975 type = submodule {
976 options = {
977 public = mkOption { type = str; description = "Public part of the key"; };
978 private = mkOption { type = lines; description = "Private part of the key"; };
979 };
980 };
981 };
982 };
983 };
984 };
985 kanboard = mkOption {
986 description = "Kanboard configuration";
987 type = submodule {
988 options = {
989 postgresql = mkPsqlOptions "Kanboard";
990 ldap = mkLdapOptions "Kanboard" {
991 admin_dn = mkOption { type = str; description = "Admin DN"; };
992 };
993 };
994 };
995 };
996 mantisbt = mkOption {
997 description = "Mantisbt configuration";
998 type = submodule {
999 options = {
1000 postgresql = mkPsqlOptions "Mantisbt";
1001 ldap = mkLdapOptions "Mantisbt" {};
1002 master_salt = mkOption { type = str; description = "Master salt for password hash"; };
1003 };
1004 };
1005 };
1006 mastodon = mkOption {
1007 description = "Mastodon configuration";
1008 type = submodule {
1009 options = {
1010 postgresql = mkPsqlOptions "Mastodon";
1011 redis = mkRedisOptions "Mastodon";
1012 ldap = mkLdapOptions "Mastodon" {};
1013 paperclip_secret = mkOption { type = str; description = "Paperclip secret"; };
1014 otp_secret = mkOption { type = str; description = "OTP secret"; };
1015 secret_key_base = mkOption { type = str; description = "Secret key base"; };
1016 vapid = mkOption {
1017 description = "vapid key";
1018 type = submodule {
1019 options = {
1020 private = mkOption { type = str; description = "Private key"; };
1021 public = mkOption { type = str; description = "Public key"; };
1022 };
1023 };
1024 };
1025 };
1026 };
1027 };
1028 mediagoblin = mkOption {
1029 description = "Mediagoblin configuration";
1030 type = submodule {
1031 options = {
1032 postgresql = mkPsqlOptions "Mediagoblin";
1033 redis = mkRedisOptions "Mediagoblin";
1034 ldap = mkLdapOptions "Mediagoblin" {};
1035 };
1036 };
1037 };
1038 nextcloud = mkOption {
1039 description = "Nextcloud configuration";
1040 type = submodule {
1041 options = {
1042 postgresql = mkPsqlOptions "Peertube";
1043 redis = mkRedisOptions "Peertube";
1044 password_salt = mkOption { type = str; description = "Password salt"; };
1045 instance_id = mkOption { type = str; description = "Instance ID"; };
1046 secret = mkOption { type = str; description = "App secret"; };
1047 };
1048 };
1049 };
1050 peertube = mkOption {
1051 description = "Peertube configuration";
1052 type = submodule {
1053 options = {
1054 listenPort = mkOption { type = port; description = "Port to listen to"; };
1055 postgresql = mkPsqlOptions "Peertube";
1056 redis = mkRedisOptions "Peertube";
1057 ldap = mkLdapOptions "Peertube" {};
1058 };
1059 };
1060 };
1061 syden_peertube = mkOption {
1062 description = "Peertube Syden configuration";
1063 type = submodule {
1064 options = {
1065 listenPort = mkOption { type = port; description = "Port to listen to"; };
1066 postgresql = mkPsqlOptions "Peertube";
1067 redis = mkRedisOptions "Peertube";
1068 };
1069 };
1070 };
1071 phpldapadmin = mkOption {
1072 description = "phpLdapAdmin configuration";
1073 type = submodule {
1074 options = {
1075 ldap = mkLdapOptions "phpldapadmin" {};
1076 };
1077 };
1078 };
1079 rompr = mkOption {
1080 description = "Rompr configuration";
1081 type = submodule {
1082 options = {
1083 mpd = mkOption {
1084 description = "MPD configuration";
1085 type = submodule {
1086 options = {
1087 host = mkOption { type = str; description = "Host for MPD"; };
1088 port = mkOption { type = port; description = "Port to access MPD host"; };
1089 };
1090 };
1091 };
1092 };
1093 };
1094 };
1095 roundcubemail = mkOption {
1096 description = "Roundcubemail configuration";
1097 type = submodule {
1098 options = {
1099 postgresql = mkPsqlOptions "TT-RSS";
1100 secret = mkOption { type = str; description = "Secret"; };
1101 };
1102 };
1103 };
1104 shaarli = mkOption {
1105 description = "Shaarli configuration";
1106 type = submodule {
1107 options = {
1108 ldap = mkLdapOptions "Shaarli" {};
1109 };
1110 };
1111 };
1112 status_engine = mkOption {
1113 description = "Status Engine configuration";
1114 type = submodule {
1115 options = {
1116 mysql = mkMysqlOptions "StatusEngine" {};
1117 ldap = mkLdapOptions "StatusEngine" {};
1118 };
1119 };
1120 };
1121 task = mkOption {
1122 description = "Taskwarrior configuration";
1123 type = submodule {
1124 options = {
1125 ldap = mkLdapOptions "Taskwarrior" {};
1126 taskwarrior-web = mkOption {
1127 description = "taskwarrior-web profiles";
1128 type = attrsOf (submodule {
1129 options = {
1130 uid = mkOption {
1131 type = listOf str;
1132 description = "List of ldap uids having access to this profile";
1133 };
1134 org = mkOption { type = str; description = "Taskd organisation"; };
1135 key = mkOption { type = str; description = "Taskd key"; };
1136 date = mkOption { type = str; description = "Preferred date format"; };
1137 };
1138 });
1139 };
1140 };
1141 };
1142 };
1143 ttrss = mkOption {
1144 description = "TT-RSS configuration";
1145 type = submodule {
1146 options = {
1147 postgresql = mkPsqlOptions "TT-RSS";
1148 ldap = mkLdapOptions "TT-RSS" {};
1149 };
1150 };
1151 };
1152 wallabag = mkOption {
1153 description = "Wallabag configuration";
1154 type = submodule {
1155 options = {
1156 postgresql = mkPsqlOptions "Wallabag";
1157 ldap = mkLdapOptions "Wallabag" {
1158 admin_filter = mkOption { type = str; description = "Admin users filter"; };
1159 };
1160 redis = mkRedisOptions "Wallabag";
1161 secret = mkOption { type = str; description = "App secret"; };
1162 };
1163 };
1164 };
1165 webhooks = mkOption {
1166 type = attrsOf str;
1167 description = "Mapping 'name'.php => script for webhooks";
1168 };
1169 csp_reports = mkOption {
1170 description = "CSP report configuration";
1171 type = submodule {
1172 options = {
1173 report_uri = mkOption { type = str; description = "URI to report CSP violations to"; };
1174 policies = mkOption { type = attrsOf str; description = "CSP policies to apply"; };
1175 postgresql = mkPsqlOptions "CSP reports";
1176 };
1177 };
1178 };
1179 commento = mkOption {
1180 description = "Commento configuration";
1181 type = submodule {
1182 options = {
1183 listenPort = mkOption { type = port; description = "Port to listen to"; };
1184 postgresql = mkPsqlOptions "Commento";
1185 smtp = mkSmtpOptions "Commento";
1186 };
1187 };
1188 };
1189 cryptpad = mkOption {
1190 description = "Cryptpad configuration";
1191 type = attrsOf (submodule {
1192 options = {
1193 email = mkOption { type = str; description = "Admin e-mail"; };
1194 admins = mkOption { type = listOf str; description = "Instance admin public keys"; };
1195 port = mkOption { type = port; description = "Port to listen to"; };
1196 };
1197 });
1198 };
1199 ympd = mkOption {
1200 description = "Ympd configuration";
1201 type = submodule {
1202 options = {
1203 listenPort = mkOption { type = port; description = "Port to listen to"; };
1204 mpd = mkOption {
1205 description = "MPD configuration";
1206 type = submodule {
1207 options = {
1208 password = mkOption { type = str; description = "Password to access MPD host"; };
1209 host = mkOption { type = str; description = "Host for MPD"; };
1210 port = mkOption { type = port; description = "Port to access MPD host"; };
1211 };
1212 };
1213 };
1214 };
1215 };
1216 };
1217 umami = mkOption {
1218 description = "Umami configuration";
1219 type = submodule {
1220 options = {
1221 listenPort = mkOption { type = port; description = "Port to listen to"; };
1222 postgresql = mkPsqlOptions "Umami";
1223 hashSalt = mkOption { type = str; description = "Hash salt"; };
1224 };
1225 };
1226 };
1227 yourls = mkOption {
1228 description = "Yourls configuration";
1229 type = submodule {
1230 options = {
1231 mysql = mkMysqlOptions "Yourls" {};
1232 ldap = mkLdapOptions "Yourls" {};
1233 cookieKey = mkOption { type = str; description = "Cookie key"; };
1234 };
1235 };
1236 };
1237 };
1238 };
1239 };
1240 serverSpecific = mkOption { type = attrsOf unspecified; description = "Server specific configuration"; };
1241 websites = mkOption {
1242 description = "Websites configurations";
1243 type = submodule {
1244 options = {
1245 immae = mkOption {
1246 description = "Immae configuration by environment";
1247 type = submodule {
1248 options = {
1249 temp = mkOption {
1250 description = "Temp configuration";
1251 type = submodule {
1252 options = {
1253 ldap = mkLdapOptions "Immae temp" {
1254 filter = mkOption { type = str; description = "Filter for user access"; };
1255 };
1256 };
1257 };
1258 };
1259 };
1260 };
1261 };
1262 isabelle = mkOption {
1263 description = "Isabelle configurations by environment";
1264 type =
1265 let
1266 atenSubmodule = mkOption {
1267 description = "environment configuration";
1268 type = submodule {
1269 options = {
1270 environment = mkOption { type = str; description = "Symfony environment"; };
1271 secret = mkOption { type = str; description = "Symfony App secret"; };
1272 postgresql = mkPsqlOptions "Aten";
1273 };
1274 };
1275 };
1276 in
1277 submodule {
1278 options = {
1279 aten_production = atenSubmodule;
1280 aten_integration = atenSubmodule;
1281 iridologie = mkOption {
1282 description = "environment configuration";
1283 type = submodule {
1284 options = {
1285 environment = mkOption { type = str; description = "SPIP environment"; };
1286 mysql = mkMysqlOptions "Iridologie" {};
1287 ldap = mkLdapOptions "Iridologie" {};
1288 };
1289 };
1290 };
1291 };
1292 };
1293 };
1294 chloe = mkOption {
1295 description = "Chloe configurations by environment";
1296 type =
1297 let
1298 chloeSubmodule = mkOption {
1299 description = "environment configuration";
1300 type = submodule {
1301 options = {
1302 environment = mkOption { type = str; description = "SPIP environment"; };
1303 mysql = mkMysqlOptions "Chloe" {};
1304 ldap = mkLdapOptions "Chloe" {};
1305 };
1306 };
1307 };
1308 in
1309 submodule {
1310 options = {
1311 production = chloeSubmodule;
1312 integration = chloeSubmodule;
1313 };
1314 };
1315 };
1316 connexionswing = mkOption {
1317 description = "Connexionswing configurations by environment";
1318 type =
1319 let
1320 csSubmodule = mkOption {
1321 description = "environment configuration";
1322 type = submodule {
1323 options = {
1324 environment = mkOption { type = str; description = "Symfony environment"; };
1325 mysql = mkMysqlOptions "Connexionswing" {};
1326 secret = mkOption { type = str; description = "Symfony App secret"; };
1327 email = mkOption { type = str; description = "Symfony email notification"; };
1328 };
1329 };
1330 };
1331 in
1332 submodule {
1333 options = {
1334 production = csSubmodule;
1335 integration = csSubmodule;
1336 };
1337 };
1338 };
1339 jerome = mkOption {
1340 description = "Naturaloutil configuration";
1341 type = submodule {
1342 options = {
1343 mysql = mkMysqlOptions "Naturaloutil" {};
1344 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1345 };
1346 };
1347 };
1348 telio_tortay = mkOption {
1349 description = "Telio Tortay configuration";
1350 type = submodule {
1351 options = {
1352 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1353 };
1354 };
1355 };
1356 ludivine = mkOption {
1357 description = "Ludivinecassal configurations by environment";
1358 type =
1359 let
1360 lcSubmodule = mkOption {
1361 description = "environment configuration";
1362 type = submodule {
1363 options = {
1364 environment = mkOption { type = str; description = "Symfony environment"; };
1365 mysql = mkMysqlOptions "LudivineCassal" {};
1366 ldap = mkLdapOptions "LudivineCassal" {};
1367 secret = mkOption { type = str; description = "Symfony App secret"; };
1368 };
1369 };
1370 };
1371 in
1372 submodule {
1373 options = {
1374 production = lcSubmodule;
1375 integration = lcSubmodule;
1376 };
1377 };
1378 };
1379 emilia = mkOption {
1380 description = "Emilia configuration";
1381 type = submodule {
1382 options = {
1383 postgresql = mkPsqlOptions "Emilia";
1384 };
1385 };
1386 };
1387 florian = mkOption {
1388 description = "Florian configuration";
1389 type = submodule {
1390 options = {
1391 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1392 };
1393 };
1394 };
1395 nassime = mkOption {
1396 description = "Nassime configuration";
1397 type = submodule {
1398 options = {
1399 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1400 };
1401 };
1402 };
1403 piedsjaloux = mkOption {
1404 description = "Piedsjaloux configurations by environment";
1405 type =
1406 let
1407 pjSubmodule = mkOption {
1408 description = "environment configuration";
1409 type = submodule {
1410 options = {
1411 environment = mkOption { type = str; description = "Symfony environment"; };
1412 mysql = mkMysqlOptions "Piedsjaloux" {};
1413 secret = mkOption { type = str; description = "Symfony App secret"; };
1414 };
1415 };
1416 };
1417 in
1418 submodule {
1419 options = {
1420 production = pjSubmodule;
1421 integration = pjSubmodule;
1422 };
1423 };
1424 };
1425 richie = mkOption {
1426 description = "Europe Richie configurations by environment";
1427 type = submodule {
1428 options = {
1429 mysql = mkMysqlOptions "Richie" {};
1430 smtp_mailer = mkOption {
1431 description = "SMTP mailer configuration";
1432 type = submodule {
1433 options = {
1434 user = mkOption { type = str; description = "Username"; };
1435 password = mkOption { type = str; description = "Password"; };
1436 };
1437 };
1438 };
1439 };
1440 };
1441 };
1442 caldance = mkOption {
1443 description = "Caldance configurations by environment";
1444 type = submodule {
1445 options = {
1446 integration = mkOption {
1447 description = "environment configuration";
1448 type = submodule {
1449 options = {
1450 password = mkOption { type = str; description = "Password file content for basic auth"; };
1451 };
1452 };
1453 };
1454 };
1455 };
1456 };
1457 tellesflorian = mkOption {
1458 description = "Tellesflorian configurations by environment";
1459 type =
1460 let
1461 tfSubmodule = mkOption {
1462 description = "environment configuration";
1463 type = submodule {
1464 options = {
1465 environment = mkOption { type = str; description = "Symfony environment"; };
1466 mysql = mkMysqlOptions "Tellesflorian" {};
1467 secret = mkOption { type = str; description = "Symfony App secret"; };
1468 invite_passwords = mkOption { type = str; description = "Password basic auth"; };
1469 };
1470 };
1471 };
1472 in
1473 submodule {
1474 options = {
1475 integration = tfSubmodule;
1476 };
1477 };
1478 };
1479 };
1480 };
1481 };
1482 };
1483 options.hostEnv = mkOption {
1484 readOnly = true;
1485 type = hostEnv;
1486 default = config.myEnv.servers."${name}";
1487 description = "Host environment";
1488 };
1489 }