krebs.secret: restart units on secret change

This commit is contained in:
tv 2020-08-04 22:22:43 +02:00
parent 4227cadb68
commit ec91d1b83c
15 changed files with 67 additions and 42 deletions

View file

@ -26,6 +26,7 @@ let
private_key = mkOption { private_key = mkOption {
type = types.secret-file; type = types.secret-file;
default = { default = {
name = "exim.dkim_private_key/${config.domain}";
path = "/run/krebs.secret/${config.domain}.dkim_private_key"; path = "/run/krebs.secret/${config.domain}.dkim_private_key";
owner.name = "exim"; owner.name = "exim";
source-path = toString <secrets> + "/${config.domain}.dkim.priv"; source-path = toString <secrets> + "/${config.domain}.dkim.priv";
@ -118,7 +119,7 @@ let
after = flip map cfg.dkim (dkim: after = flip map cfg.dkim (dkim:
config.krebs.secret.files."exim.dkim_private_key/${dkim.domain}".service config.krebs.secret.files."exim.dkim_private_key/${dkim.domain}".service
); );
requires = flip map cfg.dkim (dkim: partOf = flip map cfg.dkim (dkim:
config.krebs.secret.files."exim.dkim_private_key/${dkim.domain}".service config.krebs.secret.files."exim.dkim_private_key/${dkim.domain}".service
); );
}; };

View file

@ -124,6 +124,7 @@ let
privateKeyFile = mkOption { privateKeyFile = mkOption {
type = types.secret-file; type = types.secret-file;
default = { default = {
name = "repo-sync-key";
path = "${cfg.stateDir}/ssh.priv"; path = "${cfg.stateDir}/ssh.priv";
owner = cfg.user; owner = cfg.user;
source-path = toString <secrets> + "/repo-sync.ssh.key"; source-path = toString <secrets> + "/repo-sync.ssh.key";
@ -170,7 +171,7 @@ let
config.krebs.secret.files.repo-sync-key.service config.krebs.secret.files.repo-sync-key.service
"network.target" "network.target"
]; ];
requires = [ partOf = [
config.krebs.secret.files.repo-sync-key.service config.krebs.secret.files.repo-sync-key.service
]; ];

View file

@ -1,4 +1,5 @@
{ config, lib, pkgs, ... }@args: with import <stockholm/lib>; let with import <stockholm/lib>;
{ config, lib, pkgs, ... }: let
cfg = config.krebs.secret; cfg = config.krebs.secret;
in { in {
options.krebs.secret = { options.krebs.secret = {
@ -8,32 +9,43 @@ in {
}; };
}; };
config = lib.mkIf (cfg.files != {}) { config = lib.mkIf (cfg.files != {}) {
systemd.services.secret = let systemd.paths =
# TODO fail if two files have the same path but differ otherwise mapAttrs'
files = unique (map (flip removeAttrs ["_module"]) (name: file: nameValuePair "secret-trigger-${systemd.encodeName name}" {
(attrValues cfg.files)); wantedBy = ["multi-user.target"];
in { pathConfig.PathChanged = file.source-path;
serviceConfig = { })
Type = "oneshot"; cfg.files;
RemainAfterExit = "yes"; systemd.services =
SyslogIdentifier = "secret"; mapAttrs'
ExecStart = pkgs.writeDash "install-secret-files" '' (name: file: nameValuePair "secret-trigger-${systemd.encodeName name}" {
exit_code=0 wantedBy = ["multi-user.target"];
${concatMapStringsSep "\n" (file: '' serviceConfig = {
${pkgs.coreutils}/bin/install \ Type = "oneshot";
-D \ ExecStart = "${pkgs.systemd}/bin/systemctl restart ${file.service}";
--compare \ };
--verbose \ })
--mode=${shell.escape file.mode} \ cfg.files
--owner=${shell.escape file.owner.name} \ //
--group=${shell.escape file.group-name} \ mapAttrs'
${shell.escape file.source-path} \ (name: file: nameValuePair "secret-${systemd.encodeName name}" {
${shell.escape file.path} \ wantedBy = ["multi-user.target"];
|| exit_code=1 serviceConfig = {
'') files} Type = "oneshot";
exit $exit_code RemainAfterExit = "yes";
''; ExecStart = toString [
}; "${pkgs.coreutils}/bin/install"
}; "-D"
"--compare"
"--verbose"
"--mode=${file.mode}"
"--owner=${file.owner.name}"
"--group=${file.group-name}"
file.source-path
file.path
];
};
})
cfg.files;
}; };
} }

View file

@ -158,6 +158,7 @@ let
privkey = mkOption { privkey = mkOption {
type = types.secret-file; type = types.secret-file;
default = { default = {
name = "${tinc.config.netname}.rsa_key.priv";
path = "${tinc.config.user.home}/tinc.rsa_key.priv"; path = "${tinc.config.user.home}/tinc.rsa_key.priv";
owner = tinc.config.user; owner = tinc.config.user;
source-path = toString <secrets> + "/${tinc.config.netname}.rsa_key.priv"; source-path = toString <secrets> + "/${tinc.config.netname}.rsa_key.priv";
@ -223,7 +224,7 @@ let
config.krebs.secret.files."${netname}.rsa_key.priv".service config.krebs.secret.files."${netname}.rsa_key.priv".service
"network.target" "network.target"
]; ];
requires = [ partOf = [
config.krebs.secret.files."${netname}.rsa_key.priv".service config.krebs.secret.files."${netname}.rsa_key.priv".service
]; ];
wantedBy = [ "multi-user.target" ]; wantedBy = [ "multi-user.target" ];

View file

@ -12,7 +12,7 @@
after = [ after = [
config.krebs.secret.files.nix-serve-key.service config.krebs.secret.files.nix-serve-key.service
]; ];
requires = [ partOf = [
config.krebs.secret.files.nix-serve-key.service config.krebs.secret.files.nix-serve-key.service
]; ];
}; };

View file

@ -17,7 +17,7 @@
after = [ after = [
config.krebs.secret.files.mysql_rootPassword.service config.krebs.secret.files.mysql_rootPassword.service
]; ];
requires = [ partOf = [
config.krebs.secret.files.mysql_rootPassword.service config.krebs.secret.files.mysql_rootPassword.service
]; ];
}; };

View file

@ -17,6 +17,7 @@ in {
certfile = mkOption { certfile = mkOption {
type = types.secret-file; type = types.secret-file;
default = { default = {
name = "ejabberd-certfile";
path = "${cfg.user.home}/ejabberd.pem"; path = "${cfg.user.home}/ejabberd.pem";
owner = cfg.user; owner = cfg.user;
source-path = "/var/lib/acme/lassul.us/full.pem"; source-path = "/var/lib/acme/lassul.us/full.pem";
@ -25,6 +26,7 @@ in {
dhfile = mkOption { dhfile = mkOption {
type = types.secret-file; type = types.secret-file;
default = { default = {
name = "ejabberd-dhfile";
path = "${cfg.user.home}/dhparams.pem"; path = "${cfg.user.home}/dhparams.pem";
owner = cfg.user; owner = cfg.user;
source-path = "/dev/null"; source-path = "/dev/null";
@ -79,7 +81,7 @@ in {
config.krebs.secret.files.ejabberd-s2s_certfile.service config.krebs.secret.files.ejabberd-s2s_certfile.service
"network.target" "network.target"
]; ];
requires = [ partOf = [
config.krebs.secret.files.ejabberd-certfile.service config.krebs.secret.files.ejabberd-certfile.service
config.krebs.secret.files.ejabberd-s2s_certfile.service config.krebs.secret.files.ejabberd-s2s_certfile.service
]; ];

View file

@ -8,6 +8,9 @@ let
krebs = import ./krebs lib; krebs = import ./krebs lib;
krops = import ../submodules/krops/lib; krops = import ../submodules/krops/lib;
shell = import ./shell.nix { inherit lib; }; shell = import ./shell.nix { inherit lib; };
systemd = {
encodeName = replaceChars ["/"] ["\\x2f"];
};
types = nixpkgs-lib.types // import ./types.nix { inherit lib; }; types = nixpkgs-lib.types // import ./types.nix { inherit lib; };
xml = import ./xml.nix { inherit lib; }; xml = import ./xml.nix { inherit lib; };

View file

@ -238,7 +238,7 @@ rec {
secret-file = submodule ({ config, ... }: { secret-file = submodule ({ config, ... }: {
options = { options = {
name = mkOption { name = mkOption {
type = filename; type = pathname;
default = config._module.args.name; default = config._module.args.name;
}; };
path = mkOption { path = mkOption {
@ -257,8 +257,8 @@ rec {
default = "root"; default = "root";
}; };
service = mkOption { service = mkOption {
type = filename; type = systemd.unit-name;
default = "secret.service"; default = "secret-${lib.systemd.encodeName config.name}.service";
}; };
source-path = mkOption { source-path = mkOption {
type = str; type = str;

View file

@ -12,7 +12,7 @@
after = [ after = [
config.krebs.secret.files.nix-serve-key.service config.krebs.secret.files.nix-serve-key.service
]; ];
requires = [ partOf = [
config.krebs.secret.files.nix-serve-key.service config.krebs.secret.files.nix-serve-key.service
]; ];
}; };

View file

@ -74,7 +74,7 @@ in
after = [ after = [
config.krebs.secret.files.netdata-stream.service config.krebs.secret.files.netdata-stream.service
]; ];
requires = [ partOf = [
config.krebs.secret.files.netdata-stream.service config.krebs.secret.files.netdata-stream.service
]; ];
}; };

View file

@ -12,7 +12,7 @@
after = [ after = [
config.krebs.secret.files.binary-cache-seckey.service config.krebs.secret.files.binary-cache-seckey.service
]; ];
requires = [ partOf = [
config.krebs.secret.files.binary-cache-seckey.service config.krebs.secret.files.binary-cache-seckey.service
]; ];
}; };

View file

@ -17,6 +17,7 @@ in {
ssl_dh_params = mkOption { ssl_dh_params = mkOption {
type = types.secret-file; type = types.secret-file;
default = { default = {
name = "charybdis-ssl_dh_params";
path = "${cfg.user.home}/dh.pem"; path = "${cfg.user.home}/dh.pem";
owner = cfg.user; owner = cfg.user;
source-path = toString <secrets> + "/charybdis.dh.pem"; source-path = toString <secrets> + "/charybdis.dh.pem";
@ -25,6 +26,7 @@ in {
ssl_private_key = mkOption { ssl_private_key = mkOption {
type = types.secret-file; type = types.secret-file;
default = { default = {
name = "charybdis-ssl_private_key";
path = "${cfg.user.home}/ssl.key.pem"; path = "${cfg.user.home}/ssl.key.pem";
owner = cfg.user; owner = cfg.user;
source-path = toString <secrets> + "/charybdis.key.pem"; source-path = toString <secrets> + "/charybdis.key.pem";
@ -56,7 +58,7 @@ in {
config.krebs.secret.files.charybdis-ssl_private_key.service config.krebs.secret.files.charybdis-ssl_private_key.service
"network-online.target" "network-online.target"
]; ];
requires = [ partOf = [
config.krebs.secret.files.charybdis-ssl_dh_params.service config.krebs.secret.files.charybdis-ssl_dh_params.service
config.krebs.secret.files.charybdis-ssl_private_key.service config.krebs.secret.files.charybdis-ssl_private_key.service
]; ];

View file

@ -18,6 +18,7 @@ in {
certfile = mkOption { certfile = mkOption {
type = types.secret-file; type = types.secret-file;
default = { default = {
name = "ejabberd-certfile";
path = "${cfg.user.home}/ejabberd.pem"; path = "${cfg.user.home}/ejabberd.pem";
owner = cfg.user; owner = cfg.user;
source-path = toString <secrets> + "/ejabberd.pem"; source-path = toString <secrets> + "/ejabberd.pem";
@ -26,6 +27,7 @@ in {
dhfile = mkOption { dhfile = mkOption {
type = types.secret-file; type = types.secret-file;
default = { default = {
name = "ejabberd-dhfile";
path = "${cfg.user.home}/dhparams.pem"; path = "${cfg.user.home}/dhparams.pem";
owner = cfg.user; owner = cfg.user;
source-path = "/dev/null"; source-path = "/dev/null";
@ -100,7 +102,7 @@ in {
config.krebs.secret.files.ejabberd-s2s_certfile.service config.krebs.secret.files.ejabberd-s2s_certfile.service
"network.target" "network.target"
]; ];
requires = [ partOf = [
config.krebs.secret.files.ejabberd-certfile.service config.krebs.secret.files.ejabberd-certfile.service
config.krebs.secret.files.ejabberd-s2s_certfile.service config.krebs.secret.files.ejabberd-s2s_certfile.service
]; ];

View file

@ -12,6 +12,7 @@ in {
enable = mkEnableOption "tv.x0vncserver"; enable = mkEnableOption "tv.x0vncserver";
pwfile = mkOption { pwfile = mkOption {
default = { default = {
name = "x0vncserver-pwfile";
owner = cfg.user; owner = cfg.user;
path = "${cfg.user.home}/.vncpasswd"; path = "${cfg.user.home}/.vncpasswd";
source-path = toString <secrets> + "/vncpasswd"; source-path = toString <secrets> + "/vncpasswd";