diff options
| author | Benedikt Peetz <benedikt.peetz@b-peetz.de> | 2026-07-30 14:05:39 +0200 |
|---|---|---|
| committer | Benedikt Peetz <benedikt.peetz@b-peetz.de> | 2026-07-30 14:05:39 +0200 |
| commit | c153a351659e4596acfc31f00bf594343cbfcd68 (patch) | |
| tree | a9ed83de07711d6424fbea09aad28891bae5bfe4 /modules/by-name/ni/nix-sync/module.nix | |
| parent | hosts/server3: Setup prometheus server in agent mode (diff) | |
| download | nixos-server-c153a351659e4596acfc31f00bf594343cbfcd68.zip | |
modules: Use namespaces
That might make it easier in the future to merge different server
configs together (and thusly facilitate code-reuse.).
Diffstat (limited to 'modules/by-name/ni/nix-sync/module.nix')
| -rw-r--r-- | modules/by-name/ni/nix-sync/module.nix | 108 |
1 files changed, 0 insertions, 108 deletions
diff --git a/modules/by-name/ni/nix-sync/module.nix b/modules/by-name/ni/nix-sync/module.nix deleted file mode 100644 index 9ddd210..0000000 --- a/modules/by-name/ni/nix-sync/module.nix +++ /dev/null @@ -1,108 +0,0 @@ -{ - config, - lib, - modulesPath, - nixLib, - ... -}: let - cfg = config.vhack.nix-sync; - - mkNixSyncRepository = { - domain, - repositoryUrl, - extraSettings, - }: { - name = "${domain}"; - value = { - path = "/etc/nginx/websites/${domain}"; - uri = "${repositoryUrl}"; - inherit extraSettings; - }; - }; - nixSyncRepositories = builtins.listToAttrs (builtins.map mkNixSyncRepository cfg.domains); - - mkVirtHost = { - domain, - repositoryUrl, - extraSettings, - }: { - name = "${domain}"; - value = - # FIXME(@bpeetz): We cannot use something like `lib.recursiveUpdate` because the - # `extraSettings` are instantiated from the “real” nginx type. As such the - # `extaSettings` would override our values here. Therefore, the direct merge. <2025-02-07> - extraSettings - // { - forceSSL = true; - enableACME = true; - root = "/etc/nginx/websites/${domain}"; - }; - }; - virtHosts = builtins.listToAttrs (builtins.map mkVirtHost cfg.domains); -in { - imports = [ - ./internal_module.nix - ]; - - options.vhack.nix-sync = { - enable = lib.mkEnableOption '' - a website git ops solution. - ''; - - domains = lib.mkOption { - type = lib.types.listOf (lib.types.submodule { - options = { - domain = lib.mkOption { - type = lib.types.str; - example = "b-peetz.de"; - description = '' - The fully qualified domain to use as base of this website. - ''; - }; - repositoryUrl = lib.mkOption { - type = lib.types.str; - example = "b-peetz.de"; - description = '' - The url used for the source git repository, which is deployed at this domain. - ''; - }; - extraSettings = lib.mkOption { - type = - lib.types.submodule (import (modulesPath + "/services/web-servers/nginx/vhost-options.nix") {inherit config lib;}); - example = { - locations."/.well-known/openpgpkey/".extraConfig = "default_type application/octet-stream"; - }; - default = {}; - description = '' - Extra configuration to add to the nginx virtual host. - ''; - }; - }; - }); - }; - }; - - config = lib.mkIf cfg.enable { - vhack.persist.directories = [ - { - directory = "/var/lib/nix-sync"; - user = "nix-sync"; - group = "nix-sync"; - mode = "0700"; - } - ]; - - services.nix-sync = { - enable = true; - repositories = nixSyncRepositories; - }; - - vhack.nginx.enable = true; - services.nginx.virtualHosts = virtHosts; - - users = { - users.nix-sync.uid = config.vhack.constants.ids.uids.nix-sync; - groups.nix-sync.gid = config.vhack.constants.ids.gids.nix-sync; - }; - }; -} |
