aboutsummaryrefslogtreecommitdiff
path: root/modules/private/certificates.nix
diff options
context:
space:
mode:
authorIsmaël Bouya <ismael.bouya@normalesup.org>2020-05-08 00:43:13 +0200
committerIsmaël Bouya <ismael.bouya@normalesup.org>2020-05-08 00:43:13 +0200
commitf5761aac8dbfb4af91c232f2b52d1353c899abda (patch)
treede7b4dea5c75b5c34943e2b75980c7bf040676df /modules/private/certificates.nix
parentdcac3ec730176549cd52a9a42db2001dc652c30d (diff)
downloadNix-f5761aac8dbfb4af91c232f2b52d1353c899abda.tar.gz
Nix-f5761aac8dbfb4af91c232f2b52d1353c899abda.tar.zst
Nix-f5761aac8dbfb4af91c232f2b52d1353c899abda.zip
Upgrade to latest nixos
Diffstat (limited to 'modules/private/certificates.nix')
-rw-r--r--modules/private/certificates.nix3
1 files changed, 2 insertions, 1 deletions
diff --git a/modules/private/certificates.nix b/modules/private/certificates.nix
index c564d34..bbe4c3b 100644
--- a/modules/private/certificates.nix
+++ b/modules/private/certificates.nix
@@ -12,6 +12,7 @@
12 (lib.optionalString config.services.httpd.Inte.enable "systemctl reload httpdInte.service") 12 (lib.optionalString config.services.httpd.Inte.enable "systemctl reload httpdInte.service")
13 (lib.optionalString config.services.nginx.enable "systemctl reload nginx.service") 13 (lib.optionalString config.services.nginx.enable "systemctl reload nginx.service")
14 ]; 14 ];
15 extraLegoRenewFlags = [ "--reuse-key" ];
15 }; 16 };
16 description = "Default configuration for certificates"; 17 description = "Default configuration for certificates";
17 }; 18 };
@@ -77,7 +78,7 @@
77 # https://github.com/NixOS/nixpkgs/issues/84633 78 # https://github.com/NixOS/nixpkgs/issues/84633
78 serviceConfig.RemainAfterExit = lib.mkForce false; 79 serviceConfig.RemainAfterExit = lib.mkForce false;
79 serviceConfig.WorkingDirectory = lib.mkForce "/var/lib/acme/${k}/.lego"; 80 serviceConfig.WorkingDirectory = lib.mkForce "/var/lib/acme/${k}/.lego";
80 serviceConfig.StateDirectory = lib.mkForce "acme/${k}/.lego acme/${k}"; 81 serviceConfig.StateDirectory = lib.mkForce "acme/${k}/.lego acme/${k} acme/.lego/${k} acme/.lego/accounts";
81 serviceConfig.ExecStartPost = 82 serviceConfig.ExecStartPost =
82 let 83 let
83 keyName = builtins.replaceStrings ["*"] ["_"] data.domain; 84 keyName = builtins.replaceStrings ["*"] ["_"] data.domain;