summaryrefslogtreecommitdiff
path: root/services/mysql.nix
diff options
context:
space:
mode:
authorJakub Stachurski <jakub@wilkuu.xyz>2026-02-11 15:35:44 +0100
committerGitHub <noreply@github.com>2026-02-11 15:35:44 +0100
commit04707c728441000d64d3d750916354310ff2d2ab (patch)
treea6855656f35bc4c351e215827b58a83b4f2a99ec /services/mysql.nix
parent2f65e7f40e97f6ccb3d164169698033ce1692a76 (diff)
Omega-Relay host replacement for Ubuntu VM on Feox
* Add omega-relay prototype host * Add omega-relay prototype host * Inital commit for working omega-relay host. This commit includes: - Mysql module from umbriel - Disko configuration for the Ferox VM - Freshrss module - Stalwart module - Vaultwarden module - Wakapi module - Uptime Kuma module - Support for using mysql socket - Server user that does not depend on full home-manager preset. - ACME for wilkuu.xyz domains, including all the services. * Nix fmt * Fixes in secrets and services. Mostly fixes connection to mysql and the unix-socket auth for it. * Little fixes and update * Format and do fixes * Update secrets and keys for omega-relay * Apply changes from messing around and making things work
Diffstat (limited to 'services/mysql.nix')
-rw-r--r--services/mysql.nix139
1 files changed, 139 insertions, 0 deletions
diff --git a/services/mysql.nix b/services/mysql.nix
new file mode 100644
index 0000000..06edfcb
--- /dev/null
+++ b/services/mysql.nix
@@ -0,0 +1,139 @@
+{
+ pkgs,
+ config,
+ lib,
+ ...
+}:
+let
+ cfg = config.wilkuu.services.mysql;
+
+ create_users_ensure =
+ uname:
+ (lib.genAttrs (lib.map (dn: "${dn}.*") (
+ lib.attrNames (lib.filterAttrs (_: dcfg: (builtins.elem uname dcfg.allowedUsers)) cfg.databases)
+ )) (_: "ALL PRIVILEGES"));
+
+ priviledge_clause =
+ name: db: priv:
+ ("GRANT ${priv} ON ${db} TO ${name};");
+
+ add-user-clauses =
+ name: ucfg:
+ if (!isNull ucfg.sopsPlaceholder) then
+ (
+ ''
+ -- Clauses for user ${name}
+ ALTER USER IF EXISTS '${name}'@'${ucfg.host}' IDENTIFIED BY '${ucfg.sopsPlaceholder}';
+ CREATE USER IF NOT EXISTS '${name}'@'${ucfg.host}' IDENTIFIED BY '${ucfg.sopsPlaceholder}';
+ ''
+ + (lib.concatMapAttrsStringSep "\n" (priviledge_clause "'${name}'@'${ucfg.host}'") (create_users_ensure name))
+ )
+ else
+ " -- Ommitted user ${name}";
+
+ add-unix-user-clauses =
+ name:
+ ''
+ -- Clauses for user ${name}
+ ALTER USER IF EXISTS '${name}'@'localhost' IDENTIFIED VIA unix_socket;
+ CREATE USER IF NOT EXISTS '${name}'@'localhost' IDENTIFIED VIA unix_socket;
+ ''
+ + (lib.concatMapAttrsStringSep "\n" (priviledge_clause "'${name}'@'localhost'") (
+ create_users_ensure name
+ ));
+
+in
+{
+ options.wilkuu.services.mysql = {
+ enable = lib.mkEnableOption "Enable database for containers";
+ port =
+ with lib;
+ mkOption {
+ type = types.port;
+ default = 3306;
+ };
+ databases =
+ with lib;
+ mkOption {
+ type = types.attrsOf (
+ types.submodule {
+ options = {
+ enable = mkEnableOption "Enable the database";
+ allowedUsers = mkOption {
+ type = types.listOf types.str;
+ };
+ };
+ }
+ );
+ default = { };
+ };
+ users =
+ with lib;
+ mkOption {
+ type = types.attrsOf (
+ types.submodule {
+ options = {
+ scramPassword = mkOption {
+ type = types.nullOr types.str;
+ default = null;
+ };
+ sopsPlaceholder = mkOption {
+ type = types.nullOr types.str;
+ default = null;
+ };
+ allowedRanges = mkOption {
+ type = types.listOf types.str;
+ };
+ host = mkOption {
+ type = types.str;
+ default = "%";
+ };
+ };
+ }
+ );
+ default = { };
+ };
+ unix_users = lib.mkOption {
+ type = lib.types.listOf lib.types.str;
+ description = "Users that can identify using the unix socket";
+ default = [ ];
+ example = [ "wakapi" ];
+ };
+ };
+ # config.sops.secrets = lib.mkIf cfg.enable {
+ # "database/root_pass" = {
+ # sopsFile = ../secrets/${config.networking.hostName}/secrets.yaml;
+ # };
+ # };
+ config.sops.templates."init-mysql" = lib.mkIf cfg.enable {
+ owner = config.systemd.services.mysql.serviceConfig.User;
+ content = (
+ lib.concatLines (
+ (builtins.attrValues (builtins.mapAttrs add-user-clauses cfg.users))
+ ++ (map add-unix-user-clauses cfg.unix_users)
+ ++ [ "FLUSH PRIVILEGES;" ]
+ )
+ );
+ };
+
+ config.services.mysql = {
+ enable = cfg.enable;
+ ensureDatabases = builtins.attrNames cfg.databases;
+ initialScript = config.sops.templates."init-mysql".path;
+ package = pkgs.mariadb;
+ settings = {
+ mysqld = {
+ # socket="/var/lib/mysql/mysql.sock";
+ log_error = "/var/log/mysql_err.log";
+ log_warnings = 2;
+ };
+ };
+ };
+
+ # config.host-config.utilpkgs = lib.mkIf (cfg.enable) (
+ # with pkgs;
+ # [
+ # mycli
+ # ]
+ # );
+}