]> git.immae.eu Git - perso/Immae/Config/Nix.git/blob - modules/private/websites/tools/mail/roundcubemail.nix
Use attrs for secrets instead of lists
[perso/Immae/Config/Nix.git] / modules / private / websites / tools / mail / roundcubemail.nix
1 { env, roundcubemail, apacheHttpd, config }:
2 rec {
3 varDir = "/var/lib/roundcubemail";
4 activationScript = {
5 deps = [ "wrappers" ];
6 text = ''
7 install -m 0755 -o ${apache.user} -g ${apache.group} -d ${varDir} \
8 ${varDir}/cache ${varDir}/logs
9 install -m 0750 -o ${apache.user} -g ${apache.group} -d ${varDir}/phpSessions
10 '';
11 };
12 keys."webapps/tools-roundcube" = {
13 user = apache.user;
14 group = apache.group;
15 permissions = "0400";
16 text =
17 let
18 psql_url = with env.postgresql; "pgsql://${user}:${password}@unix(${socket}:${port})/${database}";
19 in ''
20 <?php
21 $config['db_dsnw'] = '${psql_url}';
22 $config['default_host'] = 'ssl://imap.immae.eu';
23 $config['username_domain'] = array(
24 "imap.immae.eu" => "mail.immae.eu"
25 );
26 $config['imap_conn_options'] = array("ssl" => array("verify_peer" => false));
27 $config['smtp_server'] = 'tls://smtp.immae.eu';
28 $config['smtp_port'] = '587';
29 $config['managesieve_host'] = 'imap.immae.eu';
30 $config['managesieve_port'] = '4190';
31 $config['managesieve_usetls'] = true;
32 $config['managesieve_conn_options'] = array("ssl" => array("verify_peer" => false));
33
34 $config['imap_cache'] = 'db';
35 $config['messages_cache'] = 'db';
36
37 $config['support_url'] = ''';
38
39 $config['des_key'] = '${env.secret}';
40
41 $config['skin'] = 'elastic';
42 $config['plugins'] = array(
43 'attachment_reminder',
44 'emoticons',
45 'filesystem_attachments',
46 'hide_blockquote',
47 'identicon',
48 'identity_select',
49 'jqueryui',
50 'markasjunk',
51 'managesieve',
52 'newmail_notifier',
53 'vcard_attachments',
54 'zipdownload',
55
56 'automatic_addressbook',
57 'message_highlight',
58 'carddav',
59 // Ne marche pas ?: 'ident_switch',
60 // Ne marche pas ?: 'thunderbird_labels',
61 );
62
63 $config['language'] = 'fr_FR';
64
65 $config['drafts_mbox'] = 'Drafts';
66 $config['junk_mbox'] = 'Junk';
67 $config['sent_mbox'] = 'Sent';
68 $config['trash_mbox'] = 'Trash';
69 $config['default_folders'] = array('INBOX', 'Drafts', 'Sent', 'Junk', 'Trash');
70 $config['draft_autosave'] = 60;
71 $config['enable_installer'] = false;
72 $config['log_driver'] = 'file';
73 $config['temp_dir'] = '${varDir}/cache';
74 $config['mime_types'] = '${apacheHttpd}/conf/mime.types';
75 '';
76 };
77 webRoot = (roundcubemail.override { roundcube_config = config.secrets.fullPaths."webapps/tools-roundcube"; }).withPlugins (p: [ p.automatic_addressbook p.carddav p.contextmenu p.contextmenu_folder p.html5_notifier p.ident_switch p.message_highlight p.thunderbird_labels ]);
78 apache = rec {
79 user = "wwwrun";
80 group = "wwwrun";
81 modules = [ "proxy_fcgi" ];
82 webappName = "tools_roundcubemail";
83 root = "/run/current-system/webapps/${webappName}";
84 vhostConf = socket: ''
85 Alias /roundcube "${root}"
86 <Directory "${root}">
87 DirectoryIndex index.php
88 AllowOverride All
89 Options FollowSymlinks
90 Require all granted
91
92 <FilesMatch "\.php$">
93 SetHandler "proxy:unix:${socket}|fcgi://localhost"
94 </FilesMatch>
95 </Directory>
96 '';
97 };
98 phpFpm = rec {
99 serviceDeps = [ "postgresql.service" ];
100 basedir = builtins.concatStringsSep ":" (
101 [ webRoot config.secrets.fullPaths."webapps/tools-roundcube" varDir ]
102 ++ webRoot.plugins
103 ++ webRoot.skins);
104 pool = {
105 "listen.owner" = apache.user;
106 "listen.group" = apache.group;
107 "pm" = "ondemand";
108 "pm.max_children" = "60";
109 "pm.process_idle_timeout" = "60";
110
111 # Needed to avoid clashes in browser cookies (same domain)
112 "php_value[session.name]" = "RoundcubemailPHPSESSID";
113 "php_admin_value[upload_max_filesize]" = "200M";
114 "php_admin_value[post_max_size]" = "200M";
115 "php_admin_value[open_basedir]" = "${basedir}:${apacheHttpd}/conf/mime.types:/tmp";
116 "php_admin_value[session.save_path]" = "${varDir}/phpSessions";
117 };
118 };
119 }