clanModules: migrate dyndns to vars.

This commit is contained in:
Qubasa
2024-12-30 19:27:46 +01:00
parent 4717c46662
commit 52b40797d5

View File

@@ -1,5 +1,4 @@
{ {
inputs,
config, config,
pkgs, pkgs,
lib, lib,
@@ -13,7 +12,7 @@ let
# We dedup secrets if they have the same provider + base domain # We dedup secrets if they have the same provider + base domain
secret_id = opt: "${name}-${opt.provider}-${opt.domain}"; secret_id = opt: "${name}-${opt.provider}-${opt.domain}";
secret_path = secret_path =
opt: config.clan.core.facts.services."${secret_id opt}".secret."${secret_id opt}".path; opt: config.clan.core.vars.generators."${secret_id opt}".files."${secret_id opt}".path;
# We check that a secret has not been set in extraSettings. # We check that a secret has not been set in extraSettings.
extraSettingsSafe = extraSettingsSafe =
@@ -49,11 +48,12 @@ let
secret_generator = _: opt: { secret_generator = _: opt: {
name = secret_id opt; name = secret_id opt;
value = { value = {
secret.${secret_id opt} = { }; share = true;
generator.prompt = "Dyndns passphrase for ${secret_id opt}"; migrateFact = "${secret_id opt}";
generator.script = '' prompts.${secret_id opt} = {
echo "$prompt_value" > $secrets/${secret_id opt} type = "hidden";
''; createFile = true;
};
}; };
}; };
in in
@@ -128,13 +128,12 @@ in
}; };
imports = [ imports = [
#../nginx ../nginx
inputs.clan-core.clanModules.nginx
]; ];
config = lib.mkMerge [ config = lib.mkMerge [
(lib.mkIf (cfg.settings != { }) { (lib.mkIf (cfg.settings != { }) {
clan.core.facts.services = lib.mapAttrs' secret_generator cfg.settings; clan.core.vars.generators = lib.mapAttrs' secret_generator cfg.settings;
users.groups.${name} = { }; users.groups.${name} = { };
users.users.${name} = { users.users.${name} = {