nixos/kanidm: fix trying to create backup dir when server is not enabled (#459685)
This commit is contained in:
@@ -59,6 +59,7 @@ let
|
||||
cfg.serverSettings.tls_key
|
||||
]
|
||||
++ optionals cfg.provision.enable provisionSecretFiles;
|
||||
enableServerBackup = cfg.enableServer && (cfg.serverSettings.online_backup.versions != 0);
|
||||
|
||||
# Merge bind mount paths and remove paths where a prefix is already mounted.
|
||||
# This makes sure that if e.g. the tls_chain is in the nix store and /nix/store is already in the mount
|
||||
@@ -873,7 +874,7 @@ in
|
||||
|
||||
environment.systemPackages = mkIf cfg.enableClient [ cfg.package ];
|
||||
|
||||
systemd.tmpfiles.settings."10-kanidm" = {
|
||||
systemd.tmpfiles.settings."10-kanidm" = mkIf enableServerBackup {
|
||||
${cfg.serverSettings.online_backup.path}.d = {
|
||||
mode = "0700";
|
||||
user = "kanidm";
|
||||
@@ -909,13 +910,13 @@ in
|
||||
User = "kanidm";
|
||||
Group = "kanidm";
|
||||
|
||||
BindPaths = [
|
||||
BindPaths =
|
||||
[ ]
|
||||
# To store backups
|
||||
cfg.serverSettings.online_backup.path
|
||||
]
|
||||
++ optional (
|
||||
cfg.enablePam && cfg.unixSettings ? home_mount_prefix
|
||||
) cfg.unixSettings.home_mount_prefix;
|
||||
++ optional enableServerBackup cfg.serverSettings.online_backup.path
|
||||
++ optional (
|
||||
cfg.enablePam && cfg.unixSettings ? home_mount_prefix
|
||||
) cfg.unixSettings.home_mount_prefix;
|
||||
|
||||
AmbientCapabilities = [ "CAP_NET_BIND_SERVICE" ];
|
||||
CapabilityBoundingSet = [ "CAP_NET_BIND_SERVICE" ];
|
||||
|
||||
Reference in New Issue
Block a user