summaryrefslogtreecommitdiffstats
path: root/krebs/3modules/systemd.nix
blob: c30b2264a29316e8787067f42558fa247faa942e (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
{ config, options, pkgs, ... }: let {
  lib = import ../../lib;

  body.options.krebs.systemd.services = lib.mkOption {
    default = {};
    type = lib.types.attrs;
    description = ''
      Definition of systemd service units with bonus features.

      Services defined using this option will be restarted whenever any file
      (described by an absolute path) used in LoadCredential changes.
    '';
  };

  body.config.systemd =
    lib.mkMerge
      (lib.flatten
        (lib.mapAttrsToList (serviceName: cfg: let
          prefix = [ "krebs" "systemd" "services" serviceName ];
          opts = options.systemd.services.type.getSubOptions prefix;

          paths =
            lib.filter
              lib.types.absolute-pathname.check
              (map
                (lib.compose [ lib.maybeHead (lib.match "[^:]*:(.*)") ])
                (cfg.serviceConfig.LoadCredential or []));
        in
          lib.singleton {
            services.${serviceName} = cfg;
          }
          ++
          lib.optionals (cfg.enable or opts.enable.default) (map (path: let
            triggerName = "trigger-${lib.systemd.encodeName path}";
          in {
            paths.${triggerName} = {
              wantedBy = ["multi-user.target"];
              pathConfig.PathChanged = path;
            };
            services.${triggerName} = {
              serviceConfig = {
                Type = "oneshot";
                ExecStart = lib.singleton (toString [
                  "${pkgs.systemd}/bin/systemctl restart"
                  (lib.shell.escape serviceName)
                ]);
              };
            };
          }) paths)
        ) config.krebs.systemd.services));
}