]> git.immae.eu Git - perso/Immae/Config/Nix.git/commitdiff
Move diaspora to new secrets
authorIsmaël Bouya <ismael.bouya@normalesup.org>
Thu, 25 Apr 2019 00:18:32 +0000 (02:18 +0200)
committerIsmaël Bouya <ismael.bouya@normalesup.org>
Thu, 25 Apr 2019 00:18:32 +0000 (02:18 +0200)
nixops/modules/websites/tools/diaspora/default.nix
nixops/modules/websites/tools/diaspora/diaspora.nix

index 5d36ce7490a3891d9d35efac444481e8954e7da1..0a05daf4bfe20a84f3949486abba137c591caa25 100644 (file)
@@ -29,21 +29,15 @@ in {
 
     users.groups.diaspora.gid = config.ids.gids.diaspora;
 
-    deployment.keys = diaspora.keys;
+    mySecrets.keys = diaspora.keys;
     systemd.services.diaspora = {
       description = "Diaspora";
       wantedBy = [ "multi-user.target" ];
       after = [
         "network.target" "redis.service" "postgresql.service"
-        "tools-diaspora-secret_token.service"
-        "tools-diaspora-config.service"
-        "tools-diaspora-database_config.service"
       ];
       wants = [
         "redis.service" "postgresql.service"
-        "tools-diaspora-secret_token.service"
-        "tools-diaspora-config.service"
-        "tools-diaspora-database_config.service"
       ];
 
       environment.RAILS_ENV = "production";
index c7af9dab808f9107737316a369c83dfe16e1e764..01aac89e4339e33f7168c8522eb6925473ab46ff 100644 (file)
@@ -29,21 +29,22 @@ let
       };
     };
   };
-  keys.tools-diaspora-secret_token = {
-    destDir = "/run/keys/webapps";
-    user = "diaspora";
-    group = "diaspora";
-    permissions = "0400";
-    text = ''
-      Diaspora::Application.config.secret_key_base = '${env.secret_token}'
-    '';
-  };
-  keys.tools-diaspora-config = {
-    destDir = "/run/keys/webapps";
-    user = "diaspora";
-    group = "diaspora";
-    permissions = "0400";
-    text = ''
+  keys = {
+    secret_token = {
+      dest = "webapps/tools-diaspora-secret_token";
+      user = "diaspora";
+      group = "diaspora";
+      permissions = "0400";
+      text = ''
+        Diaspora::Application.config.secret_key_base = '${env.secret_token}'
+      '';
+    };
+    config = {
+      dest = "webapps/tools-diaspora-config";
+      user = "diaspora";
+      group = "diaspora";
+      permissions = "0400";
+      text = ''
       configuration:
         environment:
           url: "https://diaspora.immae.eu/"
@@ -115,14 +116,14 @@ let
         environment:
       development:
         environment:
-    '';
-  };
-  keys.tools-diaspora-database_config = {
-    destDir = "/run/keys/webapps";
-    user = "diaspora";
-    group = "diaspora";
-    permissions = "0400";
-    text = ''
+      '';
+    };
+    database = {
+      dest = "webapps/tools-diaspora-database_config";
+      user = "diaspora";
+      group = "diaspora";
+      permissions = "0400";
+      text = ''
       postgresql: &postgresql
         adapter: postgresql
         host: "${env.postgresql.socket}"
@@ -149,7 +150,8 @@ let
       integration2:
         <<: *combined
         database: diaspora_integration2
-    '';
+      '';
+    };
   };
     railsRoot = stdenv.mkDerivation {
       name = "diaspora_immae";
@@ -161,16 +163,16 @@ let
         cd $out
         chmod -R u+rwX .
         tar -czf public/source.tar.gz ./{app,db,lib,script,Gemfile,Gemfile.lock,Rakefile,config.ru}
-        ln -s ${writeText "database.yml" keys.tools-diaspora-database_config.text} config/database.yml
-        ln -s ${writeText "diaspora.yml" keys.tools-diaspora-config.text} config/diaspora.yml
-        ln -s ${writeText "secret_token.rb" keys.tools-diaspora-secret_token.text} config/initializers/secret_token.rb
+        ln -s ${writeText "database.yml" keys.database.text} config/database.yml
+        ln -s ${writeText "diaspora.yml" keys.config.text} config/diaspora.yml
+        ln -s ${writeText "secret_token.rb" keys.secret_token.text} config/initializers/secret_token.rb
         ln -sf ${varDir}/schedule.yml config/schedule.yml
         ln -sf ${varDir}/oidc_key.pem config/oidc_key.pem
         ln -sf ${varDir}/uploads public/uploads
         RAILS_ENV=production ${gems}/bin/rake assets:precompile
-        ln -sf /run/keys/webapps/tools-diaspora-database_config config/database.yml
-        ln -sf /run/keys/webapps/tools-diaspora-config config/diaspora.yml
-        ln -sf /run/keys/webapps/tools-diaspora-secret_token config/initializers/secret_token.rb
+        ln -sf /var/secrets/webapps/tools-diaspora-database_config config/database.yml
+        ln -sf /var/secrets/webapps/tools-diaspora-config config/diaspora.yml
+        ln -sf /var/secrets/webapps/tools-diaspora-secret_token config/initializers/secret_token.rb
         rm -rf tmp log
         ln -sf ${varDir}/tmp tmp
         ln -sf ${varDir}/log log
@@ -179,6 +181,7 @@ let
     };
 in
   {
-    inherit railsRoot varDir socketsDir gems keys;
+    inherit railsRoot varDir socketsDir gems;
+    keys = builtins.attrValues keys;
     railsSocket = "${socketsDir}/diaspora.sock";
   }