1 { config, lib, name, ... }:
7 base = mkOption { description = "Base of the LDAP tree"; type = str; };
8 host = mkOption { description = "Host to access LDAP"; type = str; };
9 root_dn = mkOption { description = "DN of the root user"; type = str; };
10 root_pw = mkOption { description = "Hashed password of the root user"; type = str; };
11 replication_dn = mkOption { description = "DN of the user allowed to replicate the LDAP directory"; type = str; };
12 replication_pw = mkOption { description = "Password of the user allowed to replicate the LDAP directory"; type = str; };
14 mkLdapOptions = name: more: mkOption {
15 description = "${name} LDAP configuration";
17 options = ldapOptions // {
18 dn = mkOption { description = "DN of the ${name} user"; type = str; };
19 password = mkOption { description = "password of the ${name} user"; type = str; };
20 filter = mkOption { description = "Filter for ${name} users"; type = str; default = ""; };
25 host = mkOption { description = "Host to access Mysql"; type = str; };
26 remoteHost = mkOption { description = "Host to access Mysql from outside"; type = str; };
27 port = mkOption { description = "Port to access Mysql"; type = str; };
28 socket = mkOption { description = "Socket to access Mysql"; type = path; };
29 systemUsers = mkOption {
30 description = "Attrs of user-passwords allowed to access mysql";
34 description = "PAM configuration for mysql";
37 dn = mkOption { description = "DN to connect as to check users"; type = str; };
38 password = mkOption { description = "DN password to connect as to check users"; type = str; };
39 filter = mkOption { description = "filter to match users"; type = str; };
44 mkMysqlOptions = name: more: mkOption {
45 description = "${name} mysql configuration";
47 options = mysqlOptions // {
48 database = mkOption { description = "${name} database"; type = str; };
49 user = mkOption { description = "${name} user"; type = str; };
50 password = mkOption { description = "mysql password of the ${name} user"; type = str; };
55 host = mkOption { description = "Host to access Postgresql"; type = str; };
56 port = mkOption { description = "Port to access Postgresql"; type = str; };
57 socket = mkOption { description = "Socket to access Postgresql"; type = path; };
59 description = "PAM configuration for psql";
62 dn = mkOption { description = "DN to connect as to check users"; type = str; };
63 password = mkOption { description = "DN password to connect as to check users"; type = str; };
64 filter = mkOption { description = "filter to match users"; type = str; };
69 mkPsqlOptions = name: mkOption {
70 description = "${name} psql configuration";
72 options = psqlOptions // {
73 database = mkOption { description = "${name} database"; type = str; };
74 schema = mkOption { description = "${name} schema"; type = nullOr str; default = null; };
75 user = mkOption { description = "${name} user"; type = str; };
76 password = mkOption { description = "psql password of the ${name} user"; type = str; };
81 host = mkOption { description = "Host to access Redis"; type = str; };
82 port = mkOption { description = "Port to access Redis"; type = str; };
83 socket = mkOption { description = "Socket to access Redis"; type = path; };
85 description = "Attrs of db number. Each number should be unique to avoid collision!";
88 spiped_key = mkOption {
91 Key to use with spiped to make a secure channel to replication
95 description = "Predixy configuration. Unused yet";
98 read = mkOption { type = str; description = "Read password"; };
103 mkRedisOptions = name: mkOption {
104 description = "${name} redis configuration";
106 options = redisOptions // {
107 db = mkOption { description = "${name} database"; type = str; };
111 hostEnv = submodule {
114 description = "Host FQDN";
119 description = "List of e-mails that the server can be a sender of";
124 LDAP credentials for the host
128 password = mkOption { type = string; description = "Password for the LDAP connection"; };
129 dn = mkOption { type = string; description = "DN for the LDAP connection"; };
134 description = "subdomain and priority for MX server";
135 default = { enable = false; };
138 enable = mkEnableOption "Enable MX";
139 subdomain = mkOption { type = nullOr str; description = "Subdomain name (mx-*)"; };
140 priority = mkOption { type = nullOr str; description = "Priority"; };
146 attrs of ip4/ip6 grouped by section
148 type = attrsOf (submodule {
153 ip4 address of the host
157 type = listOf string;
160 ip6 addresses of the host
173 Attrs of servers information in the cluster (not necessarily handled by nixops)
176 type = attrsOf hostEnv;
178 hetznerCloud = mkOption {
180 Hetzner Cloud credential information
184 authToken = mkOption {
195 Hetzner credential information
199 user = mkOption { type = str; description = "User"; };
200 pass = mkOption { type = str; description = "Password"; };
206 sshd service credential information
212 LDAP credentials for cn=ssh,ou=services,dc=immae,dc=eu dn
216 password = mkOption { description = "Password"; type = str; };
225 non-standard reserved ports. Must be unique!
230 noDupl = x: builtins.length (builtins.attrValues x) == builtins.length (unique (builtins.attrValues x));
232 x: if isAttrs x && noDupl x then x else throw "Non unique values for ports";
236 httpd service credential information
242 LDAP credentials for cn=httpd,ou=services,dc=immae,dc=eu dn
246 password = mkOption { description = "Password"; type = str; };
255 LDAP server configuration
258 options = ldapOptions;
261 databases = mkOption {
262 description = "Databases configuration";
266 type = submodule { options = mysqlOptions; };
267 description = "Mysql configuration";
270 type = submodule { options = redisOptions; };
271 description = "Redis configuration";
273 postgresql = mkOption {
274 type = submodule { options = psqlOptions; };
275 description = "Postgresql configuration";
281 description = "Jabber configuration";
284 postfix_user_filter = mkOption { type = str; description = "Postfix filter to get xmpp users"; };
285 ldap = mkLdapOptions "Jabber" {};
286 postgresql = mkPsqlOptions "Jabber";
291 description = "System and regular users uid/gid";
292 type = attrsOf (submodule {
295 description = "user uid";
299 description = "user gid";
306 description = "DNS configuration";
310 description = "SOA information";
314 description = "Serial number. Should be incremented at each change and unique";
318 description = "Refresh time";
322 description = "Retry time";
326 description = "Expire time";
330 description = "Default TTL time";
334 description = "hostmaster e-mail";
338 description = "Primary NS";
345 description = "Attrs of NS servers group";
348 "ns1.foo.com" = [ "198.51.100.10" "2001:db8:abcd::1" ];
349 "ns2.foo.com" = [ "198.51.100.15" "2001:db8:1234::1" ];
352 type = attrsOf (attrsOf (listOf str));
354 slaveZones = mkOption {
355 description = "List of slave zones";
356 type = listOf (submodule {
358 name = mkOption { type = str; description = "zone name"; };
360 description = "NS master groups of this zone";
366 masterZones = mkOption {
367 description = "List of master zones";
368 type = listOf (submodule {
370 name = mkOption { type = str; description = "zone name"; };
372 description = "NS slave groups of this zone";
376 description = "groups names that should have their NS entries listed here";
380 description = "Extra zone configuration for bind";
386 entries = mkOption { type = lines; description = "Regular entries of the NS zone"; };
387 withEmail = mkOption {
388 description = "List of domains that should have mail entries (MX, dkim, SPF, ...)";
390 type = listOf (submodule {
392 domain = mkOption { type = str; description = "Which subdomain is concerned"; };
393 send = mkOption { type = bool; description = "Whether there can be e-mails originating from the subdomain"; };
394 receive = mkOption { type = bool; description = "Whether there can be e-mails arriving to the subdomain"; };
406 Remote backup with duplicity
410 password = mkOption { type = str; description = "Password for encrypting files"; };
411 remote = mkOption { type = str; description = "Remote url access"; };
412 accessKeyId = mkOption { type = str; description = "Remote access-key"; };
413 secretAccessKey = mkOption { type = str; description = "Remote access secret"; };
417 rsync_backup = mkOption {
419 Rsync backup configuration from controlled host
423 mailto = mkOption { type = str; description = "Where to e-mail on error"; };
425 description = "SSH key information";
428 public = mkOption { type = str; description = "Public part of the key"; };
429 private = mkOption { type = lines; description = "Private part of the key"; };
433 profiles = mkOption {
434 description = "Attrs of profiles to backup";
435 type = attrsOf (submodule {
437 keep = mkOption { type = int; description = "Number of backups to keep"; };
438 login = mkOption { type = str; description = "Login to connect to host"; };
439 port = mkOption { type = str; default = "22"; description = "Port to connect to host"; };
440 host = mkOption { type = str; description = "Host to connect to"; };
441 host_key = mkOption { type = str; description = "Host key"; };
442 host_key_type = mkOption { type = str; description = "Host key type"; };
444 description = "Parts to backup for this host";
445 type = attrsOf (submodule {
447 remote_folder = mkOption { type = path; description = "Remote folder to backup";};
448 exclude_from = mkOption {
451 description = "List of folders/files to exclude from the backup";
453 files_from = mkOption {
456 description = "List of folders/files to backup in the base folder";
461 description = "Extra arguments to pass to rsync";
472 monitoring = mkOption {
473 description = "Monitoring configuration";
476 status_url = mkOption { type = str; description = "URL to push status to"; };
477 status_token = mkOption { type = str; description = "Token for the status url"; };
478 http_user_password = mkOption { type = str; description = "HTTP credentials to check services behind wall"; };
479 email = mkOption { type = str; description = "Admin E-mail"; };
480 ssh_public_key = mkOption { type = str; description = "SSH public key"; };
481 ssh_secret_key = mkOption { type = str; description = "SSH secret key"; };
482 imap_login = mkOption { type = str; description = "IMAP login"; };
483 imap_password = mkOption { type = str; description = "IMAP password"; };
484 eriomem_keys = mkOption { type = listOf (listOf str); description = "Eriomem keys"; default = []; };
485 nrdp_tokens = mkOption { type = listOf str; description = "Tokens allowed to push status update"; };
486 slack_url = mkOption { type = str; description = "Slack webhook url to push status update"; };
487 slack_channel = mkOption { type = str; description = "Slack channel to push status update"; };
488 contacts = mkOption { type = attrsOf unspecified; description = "Contact dicts to fill naemon objects"; };
493 description = "MPD configuration";
496 folder = mkOption { type = str; description = "Folder to serve from the MPD instance"; };
497 password = mkOption { type = str; description = "Password to connect to the MPD instance"; };
498 host = mkOption { type = str; description = "Host to connect to the MPD instance"; };
499 port = mkOption { type = str; description = "Port to connect to the MPD instance"; };
504 description = "FTP configuration";
507 ldap = mkLdapOptions "FTP" {};
512 description = "Mail configuration";
516 description = "DMARC configuration";
519 ignore_hosts = mkOption {
522 Hosts to ignore when checking for dmarc
529 description = "DKIM configuration";
530 type = attrsOf (submodule {
536 "p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC3w1a2aMxWw9+hdcmbqX4UevcVqr204y0K73Wdc7MPZiOOlUJQYsMNSYR1Y/SC7jmPKeitpcJCpQgn/cveJZbuikjjPLsDReHyFEYmC278ZLRTELHx6f1IXM8WE08JIRT69CfZiMi1rVcOh9qRT4F93PyjCauU8Y5hJjtg9ThsWwIDAQAB" )
538 description = "Public entry to put in DNS TXT field";
540 private = mkOption { type = str; description = "Private key"; };
545 description = "Postfix configuration";
548 additional_mailbox_domains = mkOption {
550 List of domains that are used as mailbox final destination, in addition to those defined in the DNS records
554 mysql = mkMysqlOptions "Postfix" {
555 password_encrypt = mkOption { type = str; description = "Key to encrypt relay password in database"; };
557 backup_domains = mkOption {
559 Domains that are accepted for relay as backup domain
561 type = attrsOf (submodule {
563 domains = mkOption { type = listOf str; description = "Domains list"; };
564 relay_restrictions = mkOption {
567 Restrictions for relaying the e-mails from the domains
570 recipient_maps = mkOption {
572 Recipient map to accept relay for.
573 Must be specified for domain, the rules apply to everyone!
575 type = listOf (submodule {
578 type = enum [ "hash" ];
579 description = "Map type";
583 description = "Map content";
595 description = "Dovecot configuration";
598 ldap = mkLdapOptions "Dovecot" {
599 pass_attrs = mkOption { type = str; description = "Password attribute in LDAP"; };
600 user_attrs = mkOption { type = str; description = "User attribute mapping in LDAP"; };
601 iterate_attrs = mkOption { type = str; description = "User attribute mapping for listing in LDAP"; };
602 iterate_filter = mkOption { type = str; description = "User attribute filter for listing in LDAP"; };
608 description = "rspamd configuration";
611 redis = mkRedisOptions "Redis";
612 read_password_hashed = mkOption { type = str; description = "Hashed read password for rspamd"; };
613 write_password_hashed = mkOption { type = str; description = "Hashed write password for rspamd"; };
614 read_password = mkOption {
616 description = "Read password for rspamd. Unused";
619 write_password = mkOption {
621 description = "Write password for rspamd. Unused";
628 description = "Mail script recipients";
629 type = attrsOf (submodule {
631 external = mkEnableOption "Create a script_<name>@mail.immae.eu external address";
634 git source to fetch the script from.
635 It must have a default.nix file as its root accepting a scriptEnv parameter
639 url = mkOption { type = str; description = "git url to fetch"; };
640 rev = mkOption { type = str; description = "git reference to fetch"; };
645 description = "Variables to pass to the script";
654 buildbot = mkOption {
655 description = "Buildbot configuration";
659 description = "Buildbot user";
663 description = "user uid";
667 description = "user gid";
674 description = "Ldap configuration for buildbot";
677 password = mkOption { type = str; description = "Buildbot password"; };
681 projects = mkOption {
682 description = "Projects to make a buildbot for";
683 type = attrsOf (submodule {
685 name = mkOption { type = str; description = "Project name"; };
686 packages = mkOption {
688 example = literalExample ''
689 pkgs: [ pkgs.bash pkgs.git pkgs.gzip pkgs.openssh ];
693 Builds packages list to make available to buildbot project.
694 Takes pkgs as argument.
697 pythonPackages = mkOption {
699 example = literalExample ''
700 p: pkgs: [ pkgs.python3Packages.pip ];
704 Builds python packages list to make available to buildbot project.
705 Takes buildbot python module as first argument and pkgs as second argument in order to augment the python modules list.
708 pythonPathHome = mkOption { type = bool; description = "Whether to add project’s python home to python path"; };
711 description = "Secrets for the project to dump as files";
713 environment = mkOption {
716 Environment variables for the project.
717 BUILDBOT_ is prefixed to the variable names
720 activationScript = mkOption {
723 Activation script to run during deployment
726 builderPaths = mkOption {
727 type = attrsOf unspecified;
730 Attrs of functions to make accessible specifically per builder.
731 Takes pkgs as argument and should return a single path containing binaries.
732 This path will be accessible as BUILDBOT_PATH_<attrskey>
735 webhookTokens = mkOption {
736 type = nullOr (listOf str);
739 List of tokens allowed to push to project’s change_hook/base endpoint
749 description = "Tools configurations";
753 description = "Davical configuration";
756 postgresql = mkPsqlOptions "Davical";
757 ldap = mkLdapOptions "Davical" {};
761 diaspora = mkOption {
762 description = "Diaspora configuration";
765 postgresql = mkPsqlOptions "Diaspora";
766 redis = mkRedisOptions "Diaspora";
767 ldap = mkLdapOptions "Diaspora" {};
768 secret_token = mkOption { type = str; description = "Secret token"; };
772 etherpad-lite = mkOption {
773 description = "Etherpad configuration";
776 postgresql = mkPsqlOptions "Etherpad";
777 ldap = mkLdapOptions "Etherpad" {
778 group_filter = mkOption { type = str; description = "Filter for groups"; };
780 session_key = mkOption { type = str; description = "Session key"; };
781 api_key = mkOption { type = str; description = "API key"; };
782 redirects = mkOption { type = str; description = "Redirects for apache"; };
786 gitolite = mkOption {
787 description = "Gitolite configuration";
790 ldap = mkLdapOptions "Gitolite" {};
794 kanboard = mkOption {
795 description = "Kanboard configuration";
798 postgresql = mkPsqlOptions "Kanboard";
799 ldap = mkLdapOptions "Kanboard" {
800 admin_dn = mkOption { type = str; description = "Admin DN"; };
805 mantisbt = mkOption {
806 description = "Mantisbt configuration";
809 postgresql = mkPsqlOptions "Mantisbt";
810 ldap = mkLdapOptions "Mantisbt" {};
811 master_salt = mkOption { type = str; description = "Master salt for password hash"; };
815 mastodon = mkOption {
816 description = "Mastodon configuration";
819 postgresql = mkPsqlOptions "Mastodon";
820 redis = mkRedisOptions "Mastodon";
821 ldap = mkLdapOptions "Mastodon" {};
822 paperclip_secret = mkOption { type = str; description = "Paperclip secret"; };
823 otp_secret = mkOption { type = str; description = "OTP secret"; };
824 secret_key_base = mkOption { type = str; description = "Secret key base"; };
826 description = "vapid key";
829 private = mkOption { type = str; description = "Private key"; };
830 public = mkOption { type = str; description = "Public key"; };
837 mediagoblin = mkOption {
838 description = "Mediagoblin configuration";
841 postgresql = mkPsqlOptions "Mediagoblin";
842 redis = mkRedisOptions "Mediagoblin";
843 ldap = mkLdapOptions "Mediagoblin" {};
847 nextcloud = mkOption {
848 description = "Nextcloud configuration";
851 postgresql = mkPsqlOptions "Peertube";
852 redis = mkRedisOptions "Peertube";
853 password_salt = mkOption { type = str; description = "Password salt"; };
854 instance_id = mkOption { type = str; description = "Instance ID"; };
855 secret = mkOption { type = str; description = "App secret"; };
859 peertube = mkOption {
860 description = "Peertube configuration";
863 listenPort = mkOption { type = port; description = "Port to listen to"; };
864 postgresql = mkPsqlOptions "Peertube";
865 redis = mkRedisOptions "Peertube";
866 ldap = mkLdapOptions "Peertube" {};
870 phpldapadmin = mkOption {
871 description = "phpLdapAdmin configuration";
874 ldap = mkLdapOptions "phpldapadmin" {};
879 description = "Rompr configuration";
883 description = "MPD configuration";
886 host = mkOption { type = str; description = "Host for MPD"; };
887 port = mkOption { type = port; description = "Port to access MPD host"; };
894 roundcubemail = mkOption {
895 description = "Roundcubemail configuration";
898 postgresql = mkPsqlOptions "TT-RSS";
899 secret = mkOption { type = str; description = "Secret"; };
904 description = "Shaarli configuration";
907 ldap = mkLdapOptions "Shaarli" {};
912 description = "Taskwarrior configuration";
915 ldap = mkLdapOptions "Taskwarrior" {};
916 taskwarrior-web = mkOption {
917 description = "taskwarrior-web profiles";
918 type = attrsOf (submodule {
922 description = "List of ldap uids having access to this profile";
924 org = mkOption { type = str; description = "Taskd organisation"; };
925 key = mkOption { type = str; description = "Taskd key"; };
926 date = mkOption { type = str; description = "Preferred date format"; };
934 description = "TT-RSS configuration";
937 postgresql = mkPsqlOptions "TT-RSS";
938 ldap = mkLdapOptions "TT-RSS" {};
942 wallabag = mkOption {
943 description = "Wallabag configuration";
946 postgresql = mkPsqlOptions "Wallabag";
947 ldap = mkLdapOptions "Wallabag" {
948 admin_filter = mkOption { type = str; description = "Admin users filter"; };
950 redis = mkRedisOptions "Wallabag";
951 secret = mkOption { type = str; description = "App secret"; };
956 description = "Ympd configuration";
959 listenPort = mkOption { type = port; description = "Port to listen to"; };
961 description = "MPD configuration";
964 password = mkOption { type = str; description = "Password to access MPD host"; };
965 host = mkOption { type = str; description = "Host for MPD"; };
966 port = mkOption { type = port; description = "Port to access MPD host"; };
974 description = "Yourls configuration";
977 mysql = mkMysqlOptions "Yourls" {};
978 ldap = mkLdapOptions "Yourls" {};
979 cookieKey = mkOption { type = str; description = "Cookie key"; };
986 websites = mkOption {
987 description = "Websites configurations";
990 isabelle = mkOption {
991 description = "Isabelle configurations by environment";
994 atenSubmodule = mkOption {
995 description = "environment configuration";
998 environment = mkOption { type = str; description = "Symfony environment"; };
999 secret = mkOption { type = str; description = "Symfony App secret"; };
1000 postgresql = mkPsqlOptions "Aten";
1007 aten_production = atenSubmodule;
1008 aten_integration = atenSubmodule;
1009 iridologie = mkOption {
1010 description = "environment configuration";
1013 environment = mkOption { type = str; description = "SPIP environment"; };
1014 mysql = mkMysqlOptions "Iridologie" {};
1015 ldap = mkLdapOptions "Iridologie" {};
1023 description = "Chloe configurations by environment";
1026 chloeSubmodule = mkOption {
1027 description = "environment configuration";
1030 environment = mkOption { type = str; description = "SPIP environment"; };
1031 mysql = mkMysqlOptions "Chloe" {};
1032 ldap = mkLdapOptions "Chloe" {};
1039 production = chloeSubmodule;
1040 integration = chloeSubmodule;
1044 connexionswing = mkOption {
1045 description = "Connexionswing configurations by environment";
1048 csSubmodule = mkOption {
1049 description = "environment configuration";
1052 environment = mkOption { type = str; description = "Symfony environment"; };
1053 mysql = mkMysqlOptions "Connexionswing" {};
1054 secret = mkOption { type = str; description = "Symfony App secret"; };
1055 email = mkOption { type = str; description = "Symfony email notification"; };
1062 production = csSubmodule;
1063 integration = csSubmodule;
1068 description = "Naturaloutil configuration";
1071 mysql = mkMysqlOptions "Naturaloutil" {};
1072 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1076 telioTortay = mkOption {
1077 description = "Telio Tortay configuration";
1080 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1084 ludivinecassal = mkOption {
1085 description = "Ludivinecassal configurations by environment";
1088 lcSubmodule = mkOption {
1089 description = "environment configuration";
1092 environment = mkOption { type = str; description = "Symfony environment"; };
1093 mysql = mkMysqlOptions "LudivineCassal" {};
1094 ldap = mkLdapOptions "LudivineCassal" {};
1095 secret = mkOption { type = str; description = "Symfony App secret"; };
1102 production = lcSubmodule;
1103 integration = lcSubmodule;
1108 description = "Emilia configuration";
1111 postgresql = mkPsqlOptions "Emilia";
1115 florian = mkOption {
1116 description = "Florian configuration";
1119 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1123 nassime = mkOption {
1124 description = "Nassime configuration";
1127 server_admin = mkOption { type = str; description = "Server admin e-mail"; };
1131 piedsjaloux = mkOption {
1132 description = "Piedsjaloux configurations by environment";
1135 pjSubmodule = mkOption {
1136 description = "environment configuration";
1139 environment = mkOption { type = str; description = "Symfony environment"; };
1140 mysql = mkMysqlOptions "Piedsjaloux" {};
1141 secret = mkOption { type = str; description = "Symfony App secret"; };
1148 production = pjSubmodule;
1149 integration = pjSubmodule;
1154 description = "Europe Richie configurations by environment";
1157 mysql = mkMysqlOptions "Richie" {};
1158 smtp_mailer = mkOption {
1159 description = "SMTP mailer configuration";
1162 user = mkOption { type = str; description = "Username"; };
1163 password = mkOption { type = str; description = "Password"; };
1170 tellesflorian = mkOption {
1171 description = "Tellesflorian configurations by environment";
1174 tfSubmodule = mkOption {
1175 description = "environment configuration";
1178 environment = mkOption { type = str; description = "Symfony environment"; };
1179 mysql = mkMysqlOptions "Tellesflorian" {};
1180 secret = mkOption { type = str; description = "Symfony App secret"; };
1181 invite_passwords = mkOption { type = str; description = "Password basic auth"; };
1188 integration = tfSubmodule;
1196 privateFiles = mkOption {
1199 Path to secret files to make available during build
1203 options.hostEnv = mkOption {
1206 default = config.myEnv.servers."${name}";
1207 description = "Host environment";