X-Git-Url: http://git.scottworley.com/nixos-make-certs/blobdiff_plain/54ddb367272714195a7eca5651d43aa7e4e9c024..e10d7b9d963339e07bbe5edcb7a9065442f96437:/modules/make-certs.nix diff --git a/modules/make-certs.nix b/modules/make-certs.nix index a7dae4b..53e621f 100644 --- a/modules/make-certs.nix +++ b/modules/make-certs.nix @@ -1,61 +1,76 @@ -{ lib, config, pkgs, ... }: +{ + lib, + config, + pkgs, + ... +}: let inherit (lib) escapeShellArg stringAfter; - mkActvationScript = name: cert-cfg: + mkActvationScript = + name: cert-cfg: let pem-path = "${cert-cfg.dir}/${name}.pem"; key-path = "${cert-cfg.dir}/${name}.key"; - in { + in + { name = "make-cert-${name}"; - value = stringAfter [ "users" ] ('' - if [[ ! -e ${escapeShellArg pem-path} ]];then - ${pkgs.coreutils}/bin/mkdir -p ${escapeShellArg cert-cfg.dir} - ${pkgs.openssl}/bin/openssl req -batch -x509 -newkey rsa:4096 \ - -keyout ${escapeShellArg key-path} \ - -out ${escapeShellArg pem-path} \ - -days ${escapeShellArg cert-cfg.lifetime} \ - -noenc - ${pkgs.coreutils}/bin/chown ${escapeShellArg cert-cfg.user} ${ - escapeShellArg key-path - } - fi - '' + lib.optionalString cert-cfg.print '' - echo Public certificate for ${escapeShellArg name}: >&2 - ${pkgs.coreutils}/bin/cat ${escapeShellArg pem-path} >&2 - ''); + value = stringAfter [ "users" ] ( + '' + if [[ ! -e ${escapeShellArg pem-path} ]];then + ${pkgs.coreutils}/bin/mkdir -p ${escapeShellArg cert-cfg.dir} + ${pkgs.openssl}/bin/openssl req -batch -x509 -newkey rsa:4096 \ + -keyout ${escapeShellArg key-path} \ + -out ${escapeShellArg pem-path} \ + -days ${escapeShellArg cert-cfg.lifetime} \ + -noenc + ${pkgs.coreutils}/bin/chown ${escapeShellArg cert-cfg.user} ${escapeShellArg key-path} + fi + '' + + lib.optionalString cert-cfg.print '' + echo Public certificate for ${escapeShellArg name}: >&2 + ${pkgs.coreutils}/bin/cat ${escapeShellArg pem-path} >&2 + '' + ); }; -in { +in +{ options = { chkno.make-certs = lib.mkOption { - type = lib.types.attrsOf (lib.types.submodule { - options = { - dir = lib.mkOption { - type = lib.types.str; - description = "Where to put the certificate and key."; - default = "/secrets"; + description = "Certificates to generate."; + example = { + send-email.user = "stunnel"; + send-print.user = "stunnel"; + }; + type = lib.types.attrsOf ( + lib.types.submodule { + options = { + dir = lib.mkOption { + type = lib.types.str; + description = "Where to put the certificate and key."; + default = "/secrets"; + }; + lifetime = lib.mkOption { + type = lib.types.str; + description = "Lifetime of the generated certificate (in days)."; + # This doesn't yet include any notion of certificate rotation, + # so just make really long-lived certificates for now. + default = "99999"; + }; + print = lib.mkOption { + type = lib.types.bool; + description = "If set, print the certificate (public key) during activation."; + default = false; + }; + user = lib.mkOption { + type = lib.types.str; + description = "The username that owns (can read) the secret key."; + }; }; - lifetime = lib.mkOption { - type = lib.types.str; - description = "Lifetime of the generated certificate (in days)."; - # This doesn't yet include any notion of certificate rotation, - # so just make really long-lived certificates for now. - default = "99999"; - }; - print = lib.mkOption { - type = lib.types.bool; - description = "If set, print the certificate (public key) during activation."; - default = false; - }; - user = lib.mkOption { - type = lib.types.str; - description = "The username that owns (can read) the secret key."; - }; - }; - }); + } + ); }; }; config = { - system.activationScripts = - lib.mapAttrs' mkActvationScript config.chkno.make-certs; + system.activationScripts = lib.mapAttrs' mkActvationScript config.chkno.make-certs; }; }