2016-10-20 20:54:38 +02:00
|
|
|
{ config, lib, pkgs, ... }@args: with import <stockholm/lib>; let
|
2016-02-21 06:23:06 +01:00
|
|
|
cfg = config.tv.charybdis;
|
|
|
|
in {
|
|
|
|
options.tv.charybdis = {
|
|
|
|
enable = mkEnableOption "tv.charybdis";
|
|
|
|
motd = mkOption {
|
|
|
|
type = types.str;
|
|
|
|
default = "/join #retiolum";
|
|
|
|
};
|
|
|
|
port = mkOption {
|
|
|
|
type = types.int;
|
|
|
|
default = 6667;
|
|
|
|
};
|
|
|
|
ssl_cert = mkOption {
|
|
|
|
type = types.path;
|
|
|
|
};
|
|
|
|
ssl_dh_params = mkOption {
|
|
|
|
type = types.secret-file;
|
|
|
|
default = {
|
2020-08-04 22:22:43 +02:00
|
|
|
name = "charybdis-ssl_dh_params";
|
2016-02-21 06:23:06 +01:00
|
|
|
path = "${cfg.user.home}/dh.pem";
|
2016-02-21 07:18:13 +01:00
|
|
|
owner = cfg.user;
|
2016-02-21 06:23:06 +01:00
|
|
|
source-path = toString <secrets> + "/charybdis.dh.pem";
|
|
|
|
};
|
|
|
|
};
|
|
|
|
ssl_private_key = mkOption {
|
|
|
|
type = types.secret-file;
|
|
|
|
default = {
|
2020-08-04 22:22:43 +02:00
|
|
|
name = "charybdis-ssl_private_key";
|
2016-02-21 06:23:06 +01:00
|
|
|
path = "${cfg.user.home}/ssl.key.pem";
|
2016-02-21 07:18:13 +01:00
|
|
|
owner = cfg.user;
|
2016-02-21 06:23:06 +01:00
|
|
|
source-path = toString <secrets> + "/charybdis.key.pem";
|
|
|
|
};
|
|
|
|
};
|
|
|
|
sslport = mkOption {
|
|
|
|
type = types.int;
|
|
|
|
default = 6697;
|
|
|
|
};
|
|
|
|
user = mkOption {
|
2016-02-21 06:39:12 +01:00
|
|
|
type = types.user;
|
2016-02-21 06:23:06 +01:00
|
|
|
default = {
|
|
|
|
name = "charybdis";
|
|
|
|
home = "/var/lib/charybdis";
|
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
config = lib.mkIf cfg.enable {
|
|
|
|
|
|
|
|
krebs.secret.files.charybdis-ssl_dh_params = cfg.ssl_dh_params;
|
|
|
|
krebs.secret.files.charybdis-ssl_private_key = cfg.ssl_private_key;
|
|
|
|
|
|
|
|
environment.etc."charybdis-ircd.motd".text = cfg.motd;
|
|
|
|
|
|
|
|
systemd.services.charybdis = {
|
|
|
|
wantedBy = [ "multi-user.target" ];
|
2020-08-04 20:28:04 +02:00
|
|
|
after = [
|
|
|
|
config.krebs.secret.files.charybdis-ssl_dh_params.service
|
|
|
|
config.krebs.secret.files.charybdis-ssl_private_key.service
|
|
|
|
"network-online.target"
|
|
|
|
];
|
2020-08-04 22:22:43 +02:00
|
|
|
partOf = [
|
2020-08-04 20:28:04 +02:00
|
|
|
config.krebs.secret.files.charybdis-ssl_dh_params.service
|
|
|
|
config.krebs.secret.files.charybdis-ssl_private_key.service
|
|
|
|
];
|
2016-02-21 06:23:06 +01:00
|
|
|
environment = {
|
|
|
|
BANDB_DBPATH = "${cfg.user.home}/ban.db";
|
|
|
|
};
|
|
|
|
serviceConfig = {
|
|
|
|
SyslogIdentifier = "charybdis";
|
|
|
|
User = cfg.user.name;
|
|
|
|
PrivateTmp = true;
|
|
|
|
Restart = "always";
|
|
|
|
ExecStartPre =
|
|
|
|
"${pkgs.coreutils}/bin/ln -s /etc/charybdis-ircd.motd /tmp/ircd.motd";
|
|
|
|
ExecStart = toString [
|
2018-10-06 23:48:20 +02:00
|
|
|
"${pkgs.charybdis}/bin/charybdis"
|
2016-02-21 06:23:06 +01:00
|
|
|
"-configfile ${import ./config.nix args}"
|
|
|
|
"-foreground"
|
|
|
|
"-logfile /dev/stderr"
|
|
|
|
];
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
users.users.${cfg.user.name} = {
|
2016-02-21 06:56:57 +01:00
|
|
|
inherit (cfg.user) home name uid;
|
2016-02-21 06:23:06 +01:00
|
|
|
createHome = true;
|
|
|
|
};
|
|
|
|
};
|
|
|
|
}
|