diff options
author | Ismaël Bouya <ismael.bouya@normalesup.org> | 2020-05-08 00:43:13 +0200 |
---|---|---|
committer | Ismaël Bouya <ismael.bouya@normalesup.org> | 2020-05-08 00:43:13 +0200 |
commit | f5761aac8dbfb4af91c232f2b52d1353c899abda (patch) | |
tree | de7b4dea5c75b5c34943e2b75980c7bf040676df /modules/private/certificates.nix | |
parent | dcac3ec730176549cd52a9a42db2001dc652c30d (diff) | |
download | Nix-f5761aac8dbfb4af91c232f2b52d1353c899abda.tar.gz Nix-f5761aac8dbfb4af91c232f2b52d1353c899abda.tar.zst Nix-f5761aac8dbfb4af91c232f2b52d1353c899abda.zip |
Upgrade to latest nixos
Diffstat (limited to 'modules/private/certificates.nix')
-rw-r--r-- | modules/private/certificates.nix | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/modules/private/certificates.nix b/modules/private/certificates.nix index c564d34..bbe4c3b 100644 --- a/modules/private/certificates.nix +++ b/modules/private/certificates.nix | |||
@@ -12,6 +12,7 @@ | |||
12 | (lib.optionalString config.services.httpd.Inte.enable "systemctl reload httpdInte.service") | 12 | (lib.optionalString config.services.httpd.Inte.enable "systemctl reload httpdInte.service") |
13 | (lib.optionalString config.services.nginx.enable "systemctl reload nginx.service") | 13 | (lib.optionalString config.services.nginx.enable "systemctl reload nginx.service") |
14 | ]; | 14 | ]; |
15 | extraLegoRenewFlags = [ "--reuse-key" ]; | ||
15 | }; | 16 | }; |
16 | description = "Default configuration for certificates"; | 17 | description = "Default configuration for certificates"; |
17 | }; | 18 | }; |
@@ -77,7 +78,7 @@ | |||
77 | # https://github.com/NixOS/nixpkgs/issues/84633 | 78 | # https://github.com/NixOS/nixpkgs/issues/84633 |
78 | serviceConfig.RemainAfterExit = lib.mkForce false; | 79 | serviceConfig.RemainAfterExit = lib.mkForce false; |
79 | serviceConfig.WorkingDirectory = lib.mkForce "/var/lib/acme/${k}/.lego"; | 80 | serviceConfig.WorkingDirectory = lib.mkForce "/var/lib/acme/${k}/.lego"; |
80 | serviceConfig.StateDirectory = lib.mkForce "acme/${k}/.lego acme/${k}"; | 81 | serviceConfig.StateDirectory = lib.mkForce "acme/${k}/.lego acme/${k} acme/.lego/${k} acme/.lego/accounts"; |
81 | serviceConfig.ExecStartPost = | 82 | serviceConfig.ExecStartPost = |
82 | let | 83 | let |
83 | keyName = builtins.replaceStrings ["*"] ["_"] data.domain; | 84 | keyName = builtins.replaceStrings ["*"] ["_"] data.domain; |