summaryrefslogtreecommitdiff
path: root/services/mysql.nix
blob: 8a7b5e249653cae9d87085faf26ddd8eaa408252 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
{
  pkgs,
  config,
  lib,
  ...
}:
let
  cfg = config.wilkuu.services.mysql;

  create_users_ensure =
    uname:
    (lib.genAttrs (lib.map (dn: "${dn}.*") (
      lib.attrNames (lib.filterAttrs (_: dcfg: (builtins.elem uname dcfg.allowedUsers)) cfg.databases)
    )) (_: "ALL PRIVILEGES"));

  priviledge_clause =
    name: db: priv:
    ("GRANT ${priv} ON ${db} TO ${name};");

  add-user-clauses =
    name: ucfg:
    if (!isNull ucfg.sopsPlaceholder) then
      (
        ''
          -- Clauses for user ${name}
          ALTER USER IF EXISTS '${name}'@'%' IDENTIFIED BY '${ucfg.sopsPlaceholder}'; 
          CREATE USER IF NOT EXISTS '${name}'@'%' IDENTIFIED BY '${ucfg.sopsPlaceholder}';  
        ''
        + (lib.concatMapAttrsStringSep "\n" (priviledge_clause name) (create_users_ensure name))
      )
    else
      " -- Ommitted user ${name}";
  
  add-unix-user-clauses =
    name: ''
          -- Clauses for user ${name}
          ALTER USER IF EXISTS '${name}'@'localhost' IDENTIFIED BY unix_socket'; 
          CREATE USER IF NOT EXISTS '${name}'@'localhost' IDENTIFIED BY unix_socket';  
        ''
        + (lib.concatMapAttrsStringSep "\n" (priviledge_clause name) (create_users_ensure name));

in
{
  options.wilkuu.services.mysql = {
    enable = lib.mkEnableOption "Enable database for containers";
    port =
      with lib;
      mkOption {
        type = types.port;
        default = 3306;
      };
    databases =
      with lib;
      mkOption {
        type = types.attrsOf (
          types.submodule {
            options = {
              enable = mkEnableOption "Enable the database";
              allowedUsers = mkOption {
                type = types.listOf types.str;
              };
            };
          }
        );
        default = { };
      };
    users =
      with lib;
      mkOption {
        type = types.attrsOf (
          types.submodule {
            options = {
              scramPassword = mkOption {
                type = types.nullOr types.str;
                default = null;
              };
              sopsPlaceholder = mkOption {
                type = types.nullOr types.str;
                default = null;
              };
              allowedRanges = mkOption {
                type = types.listOf types.str;
              };
            };
          }
        );
        default = { };
      };
    unix_users = lib.mkOption {
      type = lib.types.listOf lib.types.str; 
      description = "Users that can identify using the unix socket";
      default = []; 
      example = ["wakapi"];
    };
  };
  # config.sops.secrets = lib.mkIf cfg.enable {
  #   "database/root_pass" = {
  #     sopsFile = ../secrets/${config.networking.hostName}/secrets.yaml;
  #   };
  # };
  config.sops.templates."init-mysql" = {
    owner = config.systemd.services.mysql.serviceConfig.User;
    content = (lib.concatLines ((builtins.attrValues (builtins.mapAttrs add-user-clauses cfg.users)) ++ (map add-unix-user-clauses cfg.unix_users)));
  };

  config.services.mysql = {
    enable = cfg.enable;
    ensureDatabases = builtins.attrNames cfg.databases;
    initialScript = config.sops.templates."init-mysql".path;
    package = pkgs.mariadb;
    settings = {
      mysqld = {
        log_error = "/var/log/mysql_err.log";
        log_warnings = 2;
      };
    };
  };

  # config.host-config.utilpkgs = lib.mkIf (cfg.enable) (
  #   with pkgs;
  #   [
  #     mycli
  #   ]
  # );
}