nixos/anubis: Fix defaultOptions not applying user-defined settings (#398790)
This commit is contained in:
@@ -122,12 +122,6 @@ let
|
||||
example = "tcp";
|
||||
type = types.str;
|
||||
};
|
||||
SOCKET_MODE = mkDefaultOption "settings.SOCKET_MODE" {
|
||||
default = "0770";
|
||||
description = "The permissions on the Unix domain sockets created.";
|
||||
example = "0700";
|
||||
type = types.str;
|
||||
};
|
||||
DIFFICULTY = mkDefaultOption "settings.DIFFICULTY" {
|
||||
default = 4;
|
||||
description = ''
|
||||
@@ -146,6 +140,26 @@ let
|
||||
'';
|
||||
type = types.bool;
|
||||
};
|
||||
OG_PASSTHROUGH = mkDefaultOption "settings.OG_PASSTHROUGH" {
|
||||
default = false;
|
||||
description = ''
|
||||
Whether to enable Open Graph tag passthrough.
|
||||
|
||||
This enables social previews of resources protected by
|
||||
Anubis without having to exempt each scraper individually.
|
||||
'';
|
||||
type = types.bool;
|
||||
};
|
||||
WEBMASTER_EMAIL = mkDefaultOption "settings.WEBMASTER_EMAIL" {
|
||||
default = null;
|
||||
description = ''
|
||||
If set, shows a contact email address when rendering error pages.
|
||||
|
||||
This email address will be how users can get in contact with administrators.
|
||||
'';
|
||||
example = "alice@example.com";
|
||||
type = types.nullOr types.str;
|
||||
};
|
||||
|
||||
# generated by default
|
||||
POLICY_FNAME = mkDefaultOption "settings.POLICY_FNAME" {
|
||||
@@ -224,6 +238,9 @@ in
|
||||
and socket paths.
|
||||
'';
|
||||
type = types.attrsOf (types.submodule (commonSubmodule false));
|
||||
|
||||
# Merge defaultOptions into each instance
|
||||
apply = lib.mapAttrs (_: lib.recursiveUpdate cfg.defaultOptions);
|
||||
};
|
||||
};
|
||||
|
||||
@@ -309,6 +326,9 @@ in
|
||||
) enabledInstances;
|
||||
};
|
||||
|
||||
meta.maintainers = with lib.maintainers; [ soopyc ];
|
||||
meta.maintainers = with lib.maintainers; [
|
||||
soopyc
|
||||
nullcube
|
||||
];
|
||||
meta.doc = ./anubis.md;
|
||||
}
|
||||
|
||||
+42
-17
@@ -1,7 +1,10 @@
|
||||
{ lib, ... }:
|
||||
{
|
||||
name = "anubis";
|
||||
meta.maintainers = [ lib.maintainers.soopyc ];
|
||||
meta.maintainers = with lib.maintainers; [
|
||||
soopyc
|
||||
nullcube
|
||||
];
|
||||
|
||||
nodes.machine =
|
||||
{
|
||||
@@ -10,24 +13,34 @@
|
||||
...
|
||||
}:
|
||||
{
|
||||
services.anubis.instances = {
|
||||
"".settings.TARGET = "http://localhost:8080";
|
||||
|
||||
"tcp" = {
|
||||
user = "anubis-tcp";
|
||||
group = "anubis-tcp";
|
||||
settings = {
|
||||
TARGET = "http://localhost:8080";
|
||||
BIND = ":9000";
|
||||
BIND_NETWORK = "tcp";
|
||||
METRICS_BIND = ":9001";
|
||||
METRICS_BIND_NETWORK = "tcp";
|
||||
};
|
||||
services.anubis = {
|
||||
defaultOptions.settings = {
|
||||
DIFFICULTY = 3;
|
||||
USER_DEFINED_DEFAULT = true;
|
||||
};
|
||||
instances = {
|
||||
"".settings = {
|
||||
TARGET = "http://localhost:8080";
|
||||
DIFFICULTY = 5;
|
||||
USER_DEFINED_INSTANCE = true;
|
||||
};
|
||||
|
||||
"unix-upstream" = {
|
||||
group = "nginx";
|
||||
settings.TARGET = "unix:///run/nginx/nginx.sock";
|
||||
"tcp" = {
|
||||
user = "anubis-tcp";
|
||||
group = "anubis-tcp";
|
||||
settings = {
|
||||
TARGET = "http://localhost:8080";
|
||||
BIND = ":9000";
|
||||
BIND_NETWORK = "tcp";
|
||||
METRICS_BIND = ":9001";
|
||||
METRICS_BIND_NETWORK = "tcp";
|
||||
};
|
||||
};
|
||||
|
||||
"unix-upstream" = {
|
||||
group = "nginx";
|
||||
settings.TARGET = "unix:///run/nginx/nginx.sock";
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
@@ -94,5 +107,17 @@
|
||||
|
||||
# Upstream is a unix socket mode
|
||||
machine.succeed('curl -f http://unix.localhost/index.html | grep "it works"')
|
||||
|
||||
# Default user-defined environment variables
|
||||
machine.succeed('cat /run/current-system/etc/systemd/system/anubis.service | grep "USER_DEFINED_DEFAULT"')
|
||||
machine.succeed('cat /run/current-system/etc/systemd/system/anubis-tcp.service | grep "USER_DEFINED_DEFAULT"')
|
||||
|
||||
# Instance-specific user-specified environment variables
|
||||
machine.succeed('cat /run/current-system/etc/systemd/system/anubis.service | grep "USER_DEFINED_INSTANCE"')
|
||||
machine.fail('cat /run/current-system/etc/systemd/system/anubis-tcp.service | grep "USER_DEFINED_INSTANCE"')
|
||||
|
||||
# Make sure defaults don't overwrite themselves
|
||||
machine.succeed('cat /run/current-system/etc/systemd/system/anubis.service | grep "DIFFICULTY=5"')
|
||||
machine.succeed('cat /run/current-system/etc/systemd/system/anubis-tcp.service | grep "DIFFICULTY=3"')
|
||||
'';
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user