2015-10-04 16:42:04 +02:00
|
|
|
{ config, lib, pkgs, ... }:
|
|
|
|
|
|
|
|
with lib;
|
|
|
|
let
|
2015-10-22 15:33:05 +02:00
|
|
|
cfg = config.krebs.tinc_graphs;
|
2015-10-04 16:42:04 +02:00
|
|
|
internal_dir = "${cfg.workingDir}/internal";
|
|
|
|
external_dir = "${cfg.workingDir}/external";
|
|
|
|
|
|
|
|
out = {
|
2015-10-22 15:33:05 +02:00
|
|
|
options.krebs.tinc_graphs = api;
|
2015-10-04 18:55:36 +02:00
|
|
|
config = mkIf cfg.enable imp ;
|
2015-10-04 16:42:04 +02:00
|
|
|
};
|
|
|
|
|
|
|
|
api = {
|
2015-10-04 18:55:36 +02:00
|
|
|
enable = mkEnableOption "tinc graphs";
|
2015-10-04 16:42:04 +02:00
|
|
|
|
|
|
|
geodbPath = mkOption {
|
|
|
|
type = types.str;
|
|
|
|
description = "Path to geocitydb, defaults to geolite-legacy";
|
2015-10-04 18:55:36 +02:00
|
|
|
default = "${pkgs.geolite-legacy}/share/GeoIP/GeoIPCity.dat";
|
|
|
|
};
|
|
|
|
|
2015-10-21 17:13:12 +02:00
|
|
|
nginx = {
|
|
|
|
enable = mkEnableOption "enable tinc_graphs to be served with nginx";
|
|
|
|
|
|
|
|
anonymous = {
|
|
|
|
server-names = mkOption {
|
|
|
|
type = with types; listOf str;
|
|
|
|
description = "hostnames which serve anonymous graphs";
|
|
|
|
default = [ "graphs.${config.krebs.build.host.name}" ];
|
|
|
|
};
|
|
|
|
|
|
|
|
listen = mkOption {
|
2015-10-21 18:47:26 +02:00
|
|
|
# use the type of the nginx listen option
|
2015-10-21 17:13:12 +02:00
|
|
|
type = with types; listOf str;
|
|
|
|
description = "listen address for anonymous graphs";
|
|
|
|
default = [ "80" ];
|
|
|
|
};
|
2015-10-04 18:55:36 +02:00
|
|
|
|
|
|
|
};
|
|
|
|
|
2015-10-21 17:13:12 +02:00
|
|
|
complete = {
|
|
|
|
server-names = mkOption {
|
|
|
|
type = with types; listOf str;
|
|
|
|
description = "hostname which serves complete graphs";
|
|
|
|
default = [ "graphs.${config.krebs.build.host.name}" ];
|
|
|
|
};
|
|
|
|
|
|
|
|
listen = mkOption {
|
|
|
|
type = with types; listOf str;
|
|
|
|
description = "listen address for complete graphs";
|
|
|
|
default = [ "127.0.0.1:80" ];
|
|
|
|
};
|
|
|
|
|
2015-10-04 18:55:36 +02:00
|
|
|
};
|
2015-10-04 16:42:04 +02:00
|
|
|
};
|
|
|
|
|
|
|
|
workingDir = mkOption {
|
|
|
|
type = types.str;
|
|
|
|
description = ''
|
|
|
|
Path to working dir, will create interal and external/.
|
|
|
|
Defaults to the new users home dir which defaults to
|
|
|
|
/var/cache/tinc_graphs'';
|
2015-10-04 18:55:36 +02:00
|
|
|
default = config.users.extraUsers.tinc_graphs.home;
|
2015-10-04 16:42:04 +02:00
|
|
|
};
|
|
|
|
|
|
|
|
timerConfig = mkOption {
|
|
|
|
type = with types; attrsOf str;
|
|
|
|
default = {
|
|
|
|
OnCalendar = "*:0/15";
|
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
imp = {
|
2015-10-04 18:55:36 +02:00
|
|
|
environment.systemPackages = [ pkgs.tinc_graphs];
|
2015-10-04 16:42:04 +02:00
|
|
|
systemd.timers.tinc_graphs = {
|
|
|
|
description = "Build Tinc Graphs via via timer";
|
2015-10-07 15:21:24 +02:00
|
|
|
wantedBy = [ "timers.target"];
|
2015-10-04 16:42:04 +02:00
|
|
|
timerConfig = cfg.timerConfig;
|
|
|
|
};
|
|
|
|
systemd.services.tinc_graphs = {
|
|
|
|
description = "Build Tinc Graphs";
|
2015-10-04 18:55:36 +02:00
|
|
|
environment = {
|
|
|
|
EXTERNAL_FOLDER = external_dir;
|
|
|
|
INTERNAL_FOLDER = internal_dir;
|
|
|
|
GEODB = cfg.geodbPath;
|
2015-10-04 22:29:30 +02:00
|
|
|
TINC_HOSTPATH=config.krebs.retiolum.hosts;
|
2015-10-04 18:55:36 +02:00
|
|
|
};
|
2015-10-04 16:42:04 +02:00
|
|
|
|
|
|
|
restartIfChanged = true;
|
|
|
|
serviceConfig = {
|
|
|
|
Type = "simple";
|
2015-12-03 20:39:29 +01:00
|
|
|
TimeoutSec = 300; # we will wait 5 minutes, kill otherwise
|
2015-11-13 12:24:43 +01:00
|
|
|
restart = "always";
|
2015-10-04 22:29:30 +02:00
|
|
|
|
2015-10-04 18:55:36 +02:00
|
|
|
ExecStartPre = pkgs.writeScript "tinc_graphs-init" ''
|
2015-10-04 16:42:04 +02:00
|
|
|
#!/bin/sh
|
2015-10-25 21:54:59 +01:00
|
|
|
mkdir -p "${internal_dir}" "${external_dir}"
|
2015-10-17 23:51:02 +02:00
|
|
|
if ! test -e "${cfg.workingDir}/internal/index.html"; then
|
2015-10-25 21:54:59 +01:00
|
|
|
cp -fr "$(${pkgs.tinc_graphs}/bin/tincstats-static-dir)/internal/." "${internal_dir}"
|
|
|
|
fi
|
|
|
|
if ! test -e "${cfg.workingDir}/external/index.html"; then
|
|
|
|
cp -fr "$(${pkgs.tinc_graphs}/bin/tincstats-static-dir)/external/." "${external_dir}"
|
2015-10-17 23:51:02 +02:00
|
|
|
fi
|
2015-10-04 16:42:04 +02:00
|
|
|
'';
|
|
|
|
ExecStart = "${pkgs.tinc_graphs}/bin/all-the-graphs";
|
2015-10-04 22:29:30 +02:00
|
|
|
|
|
|
|
ExecStartPost = pkgs.writeScript "tinc_graphs-post" ''
|
|
|
|
#!/bin/sh
|
|
|
|
# TODO: this may break if workingDir is set to something stupid
|
|
|
|
# this is needed because homedir is created with 700
|
|
|
|
chmod 755 "${cfg.workingDir}"
|
|
|
|
'';
|
2015-10-17 23:51:02 +02:00
|
|
|
PrivateTmp = "yes";
|
2015-10-04 22:29:30 +02:00
|
|
|
|
|
|
|
User = "root"; # tinc cannot be queried as user,
|
2015-10-04 18:55:36 +02:00
|
|
|
# seems to be a tinc-pre issue
|
2015-10-04 16:42:04 +02:00
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
users.extraUsers.tinc_graphs = {
|
2015-12-26 05:55:13 +01:00
|
|
|
uid = genid "tinc_graphs";
|
2015-10-04 22:29:30 +02:00
|
|
|
home = "/var/spool/tinc_graphs";
|
2015-10-04 16:42:04 +02:00
|
|
|
};
|
2015-10-04 18:55:36 +02:00
|
|
|
|
2015-10-21 18:47:26 +02:00
|
|
|
krebs.nginx.servers = mkIf cfg.nginx.enable {
|
|
|
|
tinc_graphs_complete = mkMerge [ cfg.nginx.complete {
|
2015-10-04 18:55:36 +02:00
|
|
|
locations = [
|
|
|
|
(nameValuePair "/" ''
|
2015-10-04 22:29:30 +02:00
|
|
|
autoindex on;
|
2015-10-04 18:55:36 +02:00
|
|
|
root ${internal_dir};
|
|
|
|
'')
|
|
|
|
];
|
2015-10-21 18:47:26 +02:00
|
|
|
}] ;
|
|
|
|
tinc_graphs_anonymous = mkMerge [ cfg.nginx.anonymous {
|
2015-10-04 18:55:36 +02:00
|
|
|
locations = [
|
|
|
|
(nameValuePair "/" ''
|
2015-10-04 22:29:30 +02:00
|
|
|
autoindex on;
|
2015-10-04 18:55:36 +02:00
|
|
|
root ${external_dir};
|
|
|
|
'')
|
|
|
|
];
|
2015-10-21 18:47:26 +02:00
|
|
|
}];
|
2015-10-04 18:55:36 +02:00
|
|
|
};
|
2015-10-04 16:42:04 +02:00
|
|
|
};
|
|
|
|
|
|
|
|
in
|
|
|
|
out
|