summaryrefslogtreecommitdiffstats
path: root/krebs/3modules/systemd.nix
blob: 0ce44391eb5f22afa143f65d44032555b1a19ee4 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
{ config, pkgs, ... }: let {
  lib = import ../../lib;

  body.options.krebs.systemd.services = lib.mkOption {
    default = {};
    type = lib.types.attrsOf (lib.types.submodule {
      options = {
        ifCredentialsChange = lib.mkOption {
          default = "restart";
          description = ''
            Whether to reload or restart the service whenever any its
            credentials change.  Only credentials with an absolute path in
            LoadCredential= are supported.
          '';
          type = lib.types.enum [
            "reload"
            "restart"
            null
          ];
        };
      };
    });
  };

  body.config = {
    systemd.paths = lib.mapAttrs' (serviceName: _:
      lib.nameValuePair "trigger-${lib.systemd.encodeName serviceName}" {
        wantedBy = [ "multi-user.target" ];
        pathConfig.PathChanged =
          lib.filter
            lib.types.absolute-pathname.check
            (map
              (lib.compose [ lib.maybeHead (lib.match "[^:]*:(.*)") ])
              config.systemd.services.${serviceName}.serviceConfig.LoadCredential);
      }
    ) config.krebs.systemd.services;

    systemd.services = lib.mapAttrs' (serviceName: cfg:
      lib.nameValuePair "trigger-${lib.systemd.encodeName serviceName}" {
        serviceConfig = {
          Type = "oneshot";
          ExecStart = "${pkgs.systemd}/bin/systemctl ${cfg.ifCredentialsChange} ${lib.shell.escape serviceName}";
        };
      }
    ) config.krebs.systemd.services;
  };
}