diff options
| author | Jakub Stachurski <jakub@wilkuu.xyz> | 2026-02-11 15:35:44 +0100 |
|---|---|---|
| committer | GitHub <noreply@github.com> | 2026-02-11 15:35:44 +0100 |
| commit | 04707c728441000d64d3d750916354310ff2d2ab (patch) | |
| tree | a6855656f35bc4c351e215827b58a83b4f2a99ec /services/mysql.nix | |
| parent | 2f65e7f40e97f6ccb3d164169698033ce1692a76 (diff) | |
Omega-Relay host replacement for Ubuntu VM on Feox
* Add omega-relay prototype host
* Add omega-relay prototype host
* Inital commit for working omega-relay host.
This commit includes:
- Mysql module from umbriel
- Disko configuration for the Ferox VM
- Freshrss module
- Stalwart module
- Vaultwarden module
- Wakapi module
- Uptime Kuma module
- Support for using mysql socket
- Server user that does not depend on full home-manager preset.
- ACME for wilkuu.xyz domains, including all the services.
* Nix fmt
* Fixes in secrets and services.
Mostly fixes connection to mysql and the unix-socket auth for it.
* Little fixes and update
* Format and do fixes
* Update secrets and keys for omega-relay
* Apply changes from messing around and making things work
Diffstat (limited to 'services/mysql.nix')
| -rw-r--r-- | services/mysql.nix | 139 |
1 files changed, 139 insertions, 0 deletions
diff --git a/services/mysql.nix b/services/mysql.nix new file mode 100644 index 0000000..06edfcb --- /dev/null +++ b/services/mysql.nix @@ -0,0 +1,139 @@ +{ + pkgs, + config, + lib, + ... +}: +let + cfg = config.wilkuu.services.mysql; + + create_users_ensure = + uname: + (lib.genAttrs (lib.map (dn: "${dn}.*") ( + lib.attrNames (lib.filterAttrs (_: dcfg: (builtins.elem uname dcfg.allowedUsers)) cfg.databases) + )) (_: "ALL PRIVILEGES")); + + priviledge_clause = + name: db: priv: + ("GRANT ${priv} ON ${db} TO ${name};"); + + add-user-clauses = + name: ucfg: + if (!isNull ucfg.sopsPlaceholder) then + ( + '' + -- Clauses for user ${name} + ALTER USER IF EXISTS '${name}'@'${ucfg.host}' IDENTIFIED BY '${ucfg.sopsPlaceholder}'; + CREATE USER IF NOT EXISTS '${name}'@'${ucfg.host}' IDENTIFIED BY '${ucfg.sopsPlaceholder}'; + '' + + (lib.concatMapAttrsStringSep "\n" (priviledge_clause "'${name}'@'${ucfg.host}'") (create_users_ensure name)) + ) + else + " -- Ommitted user ${name}"; + + add-unix-user-clauses = + name: + '' + -- Clauses for user ${name} + ALTER USER IF EXISTS '${name}'@'localhost' IDENTIFIED VIA unix_socket; + CREATE USER IF NOT EXISTS '${name}'@'localhost' IDENTIFIED VIA unix_socket; + '' + + (lib.concatMapAttrsStringSep "\n" (priviledge_clause "'${name}'@'localhost'") ( + create_users_ensure name + )); + +in +{ + options.wilkuu.services.mysql = { + enable = lib.mkEnableOption "Enable database for containers"; + port = + with lib; + mkOption { + type = types.port; + default = 3306; + }; + databases = + with lib; + mkOption { + type = types.attrsOf ( + types.submodule { + options = { + enable = mkEnableOption "Enable the database"; + allowedUsers = mkOption { + type = types.listOf types.str; + }; + }; + } + ); + default = { }; + }; + users = + with lib; + mkOption { + type = types.attrsOf ( + types.submodule { + options = { + scramPassword = mkOption { + type = types.nullOr types.str; + default = null; + }; + sopsPlaceholder = mkOption { + type = types.nullOr types.str; + default = null; + }; + allowedRanges = mkOption { + type = types.listOf types.str; + }; + host = mkOption { + type = types.str; + default = "%"; + }; + }; + } + ); + default = { }; + }; + unix_users = lib.mkOption { + type = lib.types.listOf lib.types.str; + description = "Users that can identify using the unix socket"; + default = [ ]; + example = [ "wakapi" ]; + }; + }; + # config.sops.secrets = lib.mkIf cfg.enable { + # "database/root_pass" = { + # sopsFile = ../secrets/${config.networking.hostName}/secrets.yaml; + # }; + # }; + config.sops.templates."init-mysql" = lib.mkIf cfg.enable { + owner = config.systemd.services.mysql.serviceConfig.User; + content = ( + lib.concatLines ( + (builtins.attrValues (builtins.mapAttrs add-user-clauses cfg.users)) + ++ (map add-unix-user-clauses cfg.unix_users) + ++ [ "FLUSH PRIVILEGES;" ] + ) + ); + }; + + config.services.mysql = { + enable = cfg.enable; + ensureDatabases = builtins.attrNames cfg.databases; + initialScript = config.sops.templates."init-mysql".path; + package = pkgs.mariadb; + settings = { + mysqld = { + # socket="/var/lib/mysql/mysql.sock"; + log_error = "/var/log/mysql_err.log"; + log_warnings = 2; + }; + }; + }; + + # config.host-config.utilpkgs = lib.mkIf (cfg.enable) ( + # with pkgs; + # [ + # mycli + # ] + # ); +} |
