diff options
author | tv <tv@krebsco.de> | 2020-08-04 22:22:43 +0200 |
---|---|---|
committer | tv <tv@krebsco.de> | 2020-08-05 11:16:45 +0200 |
commit | ec91d1b83cfad151033433159a04eb7b5381bc73 (patch) | |
tree | 4da4eefa1d14a8cd5cca42e9d78a81262ff1fe03 /lass | |
parent | 4227cadb6823bd4b945b8ea9e766f22b95d26468 (diff) |
krebs.secret: restart units on secret change
Diffstat (limited to 'lass')
-rw-r--r-- | lass/2configs/binary-cache/server.nix | 2 | ||||
-rw-r--r-- | lass/2configs/websites/sqlBackup.nix | 2 | ||||
-rw-r--r-- | lass/3modules/ejabberd/default.nix | 4 |
3 files changed, 5 insertions, 3 deletions
diff --git a/lass/2configs/binary-cache/server.nix b/lass/2configs/binary-cache/server.nix index fbaf16a3c..9b91035a8 100644 --- a/lass/2configs/binary-cache/server.nix +++ b/lass/2configs/binary-cache/server.nix @@ -12,7 +12,7 @@ after = [ config.krebs.secret.files.nix-serve-key.service ]; - requires = [ + partOf = [ config.krebs.secret.files.nix-serve-key.service ]; }; diff --git a/lass/2configs/websites/sqlBackup.nix b/lass/2configs/websites/sqlBackup.nix index 72d7c7b9a..c9783bece 100644 --- a/lass/2configs/websites/sqlBackup.nix +++ b/lass/2configs/websites/sqlBackup.nix @@ -17,7 +17,7 @@ after = [ config.krebs.secret.files.mysql_rootPassword.service ]; - requires = [ + partOf = [ config.krebs.secret.files.mysql_rootPassword.service ]; }; diff --git a/lass/3modules/ejabberd/default.nix b/lass/3modules/ejabberd/default.nix index 9642c64c9..20a38d572 100644 --- a/lass/3modules/ejabberd/default.nix +++ b/lass/3modules/ejabberd/default.nix @@ -17,6 +17,7 @@ in { certfile = mkOption { type = types.secret-file; default = { + name = "ejabberd-certfile"; path = "${cfg.user.home}/ejabberd.pem"; owner = cfg.user; source-path = "/var/lib/acme/lassul.us/full.pem"; @@ -25,6 +26,7 @@ in { dhfile = mkOption { type = types.secret-file; default = { + name = "ejabberd-dhfile"; path = "${cfg.user.home}/dhparams.pem"; owner = cfg.user; source-path = "/dev/null"; @@ -79,7 +81,7 @@ in { config.krebs.secret.files.ejabberd-s2s_certfile.service "network.target" ]; - requires = [ + partOf = [ config.krebs.secret.files.ejabberd-certfile.service config.krebs.secret.files.ejabberd-s2s_certfile.service ]; |