From 8c9a0efe30c03a93ed98cdf66631066d0f45756c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Wed, 11 Oct 2023 21:28:46 +0200 Subject: [PATCH 1/3] nixos/prosody: deadnix, remove extra new lines, minor cleanup --- nixos/modules/services/networking/prosody.nix | 474 ++++++++---------- 1 file changed, 220 insertions(+), 254 deletions(-) diff --git a/nixos/modules/services/networking/prosody.nix b/nixos/modules/services/networking/prosody.nix index f4d9172bab3f..1e3a395a9ace 100644 --- a/nixos/modules/services/networking/prosody.nix +++ b/nixos/modules/services/networking/prosody.nix @@ -9,31 +9,26 @@ with lib; let cfg = config.services.prosody; - sslOpts = - { ... }: - { + sslOpts = _: { + options = { + key = mkOption { + type = types.path; + description = "Path to the key file."; + }; - options = { - - key = mkOption { - type = types.path; - description = "Path to the key file."; - }; - - # TODO: rename to certificate to match the prosody config - cert = mkOption { - type = types.path; - description = "Path to the certificate file."; - }; - - extraOptions = mkOption { - type = types.attrs; - default = { }; - description = "Extra SSL configuration options."; - }; + # TODO: rename to certificate to match the prosody config + cert = mkOption { + type = types.path; + description = "Path to the certificate file."; + }; + extraOptions = mkOption { + type = types.attrs; + default = { }; + description = "Extra SSL configuration options."; }; }; + }; discoOpts = { options = { @@ -301,240 +296,221 @@ let }; ''; - mucOpts = - { ... }: - { - options = { - domain = mkOption { - type = types.str; - description = "Domain name of the MUC"; - }; - name = mkOption { - type = types.str; - description = "The name to return in service discovery responses for the MUC service itself"; - default = "Prosody Chatrooms"; - }; - restrictRoomCreation = mkOption { - type = types.enum [ - true - false - "admin" - "local" - ]; - default = false; - description = "Restrict room creation to server admins"; - }; - maxHistoryMessages = mkOption { - type = types.int; - default = 20; - description = "Specifies a limit on what each room can be configured to keep"; - }; - roomLocking = mkOption { - type = types.bool; - default = true; - description = '' - Enables room locking, which means that a room must be - configured before it can be used. Locked rooms are invisible - and cannot be entered by anyone but the creator - ''; - }; - roomLockTimeout = mkOption { - type = types.int; - default = 300; - description = '' - Timeout after which the room is destroyed or unlocked if not - configured, in seconds - ''; - }; - tombstones = mkOption { - type = types.bool; - default = true; - description = '' - When a room is destroyed, it leaves behind a tombstone which - prevents the room being entered or recreated. It also allows - anyone who was not in the room at the time it was destroyed - to learn about it, and to update their bookmarks. Tombstones - prevents the case where someone could recreate a previously - semi-anonymous room in order to learn the real JIDs of those - who often join there. - ''; - }; - tombstoneExpiry = mkOption { - type = types.int; - default = 2678400; - description = '' - This settings controls how long a tombstone is considered - valid. It defaults to 31 days. After this time, the room in - question can be created again. - ''; - }; - allowners_muc = mkOption { - type = types.bool; - default = false; - description = '' - Add module allowners, any user in chat is able to - kick other. Usefull in jitsi-meet to kick ghosts. - ''; - }; - vcard_muc = mkOption { - type = types.bool; - default = true; - description = "Adds the ability to set vCard for Multi User Chat rooms"; - }; - - # Extra parameters. Defaulting to prosody default values. - # Adding them explicitly to make them visible from the options - # documentation. - # - # See https://prosody.im/doc/modules/mod_muc for more details. - roomDefaultPublic = mkOption { - type = types.bool; - default = true; - description = "If set, the MUC rooms will be public by default."; - }; - roomDefaultMembersOnly = mkOption { - type = types.bool; - default = false; - description = "If set, the MUC rooms will only be accessible to the members by default."; - }; - roomDefaultModerated = mkOption { - type = types.bool; - default = false; - description = "If set, the MUC rooms will be moderated by default."; - }; - roomDefaultPublicJids = mkOption { - type = types.bool; - default = false; - description = "If set, the MUC rooms will display the public JIDs by default."; - }; - roomDefaultChangeSubject = mkOption { - type = types.bool; - default = false; - description = "If set, the rooms will display the public JIDs by default."; - }; - roomDefaultHistoryLength = mkOption { - type = types.int; - default = 20; - description = "Number of history message sent to participants by default."; - }; - roomDefaultLanguage = mkOption { - type = types.str; - default = "en"; - description = "Default room language."; - }; - extraConfig = mkOption { - type = types.lines; - default = ""; - description = "Additional MUC specific configuration"; - }; + mucOpts = _: { + options = { + domain = mkOption { + type = types.str; + description = "Domain name of the MUC"; }; - }; - - uploadHttpOpts = - { ... }: - { - options = { - domain = mkOption { - type = types.nullOr types.str; - description = "Domain name for the http-upload service"; - }; - uploadFileSizeLimit = mkOption { - type = types.str; - default = "50 * 1024 * 1024"; - description = "Maximum file size, in bytes. Defaults to 50MB."; - }; - uploadExpireAfter = mkOption { - type = types.str; - default = "60 * 60 * 24 * 7"; - description = "Max age of a file before it gets deleted, in seconds."; - }; - userQuota = mkOption { - type = types.nullOr types.int; - default = null; - example = 1234; - description = '' - Maximum size of all uploaded files per user, in bytes. There - will be no quota if this option is set to null. - ''; - }; - httpUploadPath = mkOption { - type = types.str; - description = '' - Directory where the uploaded files will be stored when the http_upload module is used. - By default, uploaded files are put in a sub-directory of the default Prosody storage path (usually /var/lib/prosody). - ''; - default = "/var/lib/prosody"; - }; + name = mkOption { + type = types.str; + description = "The name to return in service discovery responses for the MUC service itself"; + default = "Prosody Chatrooms"; }; - }; - - httpFileShareOpts = - { ... }: - { - freeformType = - with types; - let - atom = oneOf [ - int - bool - str - (listOf atom) - ]; - in - attrsOf (nullOr atom) - // { - description = "int, bool, string or list of them"; - }; - options.domain = mkOption { - type = with types; nullOr str; - description = "Domain name for a http_file_share service."; + restrictRoomCreation = mkOption { + type = types.enum [ + true + false + "admin" + "local" + ]; + default = false; + description = "Restrict room creation to server admins"; }; - }; - - vHostOpts = - { ... }: - { - - options = { - - # TODO: require attribute - domain = mkOption { - type = types.str; - description = "Domain name"; - }; - - enabled = mkOption { - type = types.bool; - default = false; - description = "Whether to enable the virtual host"; - }; - - ssl = mkOption { - type = types.nullOr (types.submodule sslOpts); - default = null; - description = "Paths to SSL files"; - }; - - extraConfig = mkOption { - type = types.lines; - default = ""; - description = "Additional virtual host specific configuration"; - }; - + maxHistoryMessages = mkOption { + type = types.int; + default = 20; + description = "Specifies a limit on what each room can be configured to keep"; + }; + roomLocking = mkOption { + type = types.bool; + default = true; + description = '' + Enables room locking, which means that a room must be + configured before it can be used. Locked rooms are invisible + and cannot be entered by anyone but the creator + ''; + }; + roomLockTimeout = mkOption { + type = types.int; + default = 300; + description = '' + Timeout after which the room is destroyed or unlocked if not + configured, in seconds + ''; + }; + tombstones = mkOption { + type = types.bool; + default = true; + description = '' + When a room is destroyed, it leaves behind a tombstone which + prevents the room being entered or recreated. It also allows + anyone who was not in the room at the time it was destroyed + to learn about it, and to update their bookmarks. Tombstones + prevents the case where someone could recreate a previously + semi-anonymous room in order to learn the real JIDs of those + who often join there. + ''; + }; + tombstoneExpiry = mkOption { + type = types.int; + default = 2678400; + description = '' + This settings controls how long a tombstone is considered + valid. It defaults to 31 days. After this time, the room in + question can be created again. + ''; + }; + allowners_muc = mkOption { + type = types.bool; + default = false; + description = '' + Add module allowners, any user in chat is able to + kick other. Useful in jitsi-meet to kick ghosts. + ''; + }; + vcard_muc = mkOption { + type = types.bool; + default = true; + description = "Adds the ability to set vCard for Multi User Chat rooms"; }; + # Extra parameters. Defaulting to prosody default values. + # Adding them explicitly to make them visible from the options + # documentation. + # + # See https://prosody.im/doc/modules/mod_muc for more details. + roomDefaultPublic = mkOption { + type = types.bool; + default = true; + description = "If set, the MUC rooms will be public by default."; + }; + roomDefaultMembersOnly = mkOption { + type = types.bool; + default = false; + description = "If set, the MUC rooms will only be accessible to the members by default."; + }; + roomDefaultModerated = mkOption { + type = types.bool; + default = false; + description = "If set, the MUC rooms will be moderated by default."; + }; + roomDefaultPublicJids = mkOption { + type = types.bool; + default = false; + description = "If set, the MUC rooms will display the public JIDs by default."; + }; + roomDefaultChangeSubject = mkOption { + type = types.bool; + default = false; + description = "If set, the rooms will display the public JIDs by default."; + }; + roomDefaultHistoryLength = mkOption { + type = types.int; + default = 20; + description = "Number of history message sent to participants by default."; + }; + roomDefaultLanguage = mkOption { + type = types.str; + default = "en"; + description = "Default room language."; + }; + extraConfig = mkOption { + type = types.lines; + default = ""; + description = "Additional MUC specific configuration"; + }; }; + }; + uploadHttpOpts = _: { + options = { + domain = mkOption { + type = types.nullOr types.str; + description = "Domain name for the http-upload service"; + }; + uploadFileSizeLimit = mkOption { + type = types.str; + default = "50 * 1024 * 1024"; + description = "Maximum file size, in bytes. Defaults to 50MB."; + }; + uploadExpireAfter = mkOption { + type = types.str; + default = "60 * 60 * 24 * 7"; + description = "Max age of a file before it gets deleted, in seconds."; + }; + userQuota = mkOption { + type = types.nullOr types.int; + default = null; + example = 1234; + description = '' + Maximum size of all uploaded files per user, in bytes. There + will be no quota if this option is set to null. + ''; + }; + httpUploadPath = mkOption { + type = types.str; + description = '' + Directory where the uploaded files will be stored when the http_upload module is used. + By default, uploaded files are put in a sub-directory of the default Prosody storage path (usually /var/lib/prosody). + ''; + default = "/var/lib/prosody"; + }; + }; + }; + + httpFileShareOpts = _: { + freeformType = + with types; + let + atom = oneOf [ + int + bool + str + (listOf atom) + ]; + in + attrsOf (nullOr atom) + // { + description = "int, bool, string or list of them"; + }; + options.domain = mkOption { + type = with types; nullOr str; + description = "Domain name for a http_file_share service."; + }; + }; + + vHostOpts = _: { + options = { + # TODO: require attribute + domain = mkOption { + type = types.str; + description = "Domain name"; + }; + + enabled = mkOption { + type = types.bool; + default = false; + description = "Whether to enable the virtual host"; + }; + + ssl = mkOption { + type = types.nullOr (types.submodule sslOpts); + default = null; + description = "Paths to SSL files"; + }; + + extraConfig = mkOption { + type = types.lines; + default = ""; + description = "Additional virtual host specific configuration"; + }; + }; + }; in - { - - ###### interface - options = { - services.prosody = { - enable = mkOption { type = types.bool; default = false; @@ -818,14 +794,10 @@ in } ''; }; - }; }; - ###### implementation - config = mkIf cfg.enable { - assertions = let genericErrMsg = '' @@ -916,21 +888,16 @@ in c2s_require_encryption = ${toLua cfg.c2sRequireEncryption} s2s_require_encryption = ${toLua cfg.s2sRequireEncryption} - s2s_secure_auth = ${toLua cfg.s2sSecureAuth} - s2s_insecure_domains = ${toLua cfg.s2sInsecureDomains} - s2s_secure_domains = ${toLua cfg.s2sSecureDomains} authentication = ${toLua cfg.authentication} http_interfaces = ${toLua cfg.httpInterfaces} - https_interfaces = ${toLua cfg.httpsInterfaces} http_ports = ${toLua cfg.httpPorts} - https_ports = ${toLua cfg.httpsPorts} ${cfg.extraConfig} @@ -1025,7 +992,6 @@ in }) ]; }; - }; meta.doc = ./prosody.md; From e2e3e77ab00f8443f565ce769097ed167bf670bb Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Wed, 11 Oct 2023 22:26:51 +0200 Subject: [PATCH 2/3] nixos/prosody: add config check option --- nixos/modules/services/networking/prosody.nix | 247 ++++++++++-------- 1 file changed, 134 insertions(+), 113 deletions(-) diff --git a/nixos/modules/services/networking/prosody.nix b/nixos/modules/services/networking/prosody.nix index 1e3a395a9ace..40ae4c647760 100644 --- a/nixos/modules/services/networking/prosody.nix +++ b/nixos/modules/services/networking/prosody.nix @@ -507,6 +507,121 @@ let }; }; }; + + configFile = + let + httpDiscoItems = + optional (cfg.uploadHttp != null) { + url = cfg.uploadHttp.domain; + description = "HTTP upload endpoint"; + } + ++ optional (cfg.httpFileShare != null) { + url = cfg.httpFileShare.domain; + description = "HTTP file share endpoint"; + }; + mucDiscoItems = builtins.foldl' ( + acc: muc: + [ + { + url = muc.domain; + description = "${muc.domain} MUC endpoint"; + } + ] + ++ acc + ) [ ] cfg.muc; + discoItems = cfg.disco_items ++ httpDiscoItems ++ mucDiscoItems; + in + pkgs.writeText "prosody.cfg.lua" '' + pidfile = "/run/prosody/prosody.pid" + + log = ${cfg.log} + + data_path = "${cfg.dataDir}" + plugin_paths = { + ${lib.concatStringsSep ", " (map (n: "\"${n}\"") cfg.extraPluginPaths)} + } + + ${optionalString (cfg.ssl != null) (createSSLOptsStr cfg.ssl)} + + admins = ${toLua cfg.admins} + + modules_enabled = { + + ${lib.concatStringsSep "\n " ( + lib.mapAttrsToList (name: val: optionalString val "${toLua name};") cfg.modules + )} + ${lib.concatStringsSep "\n" (map (x: "${toLua x};") cfg.package.communityModules)} + ${lib.concatStringsSep "\n" (map (x: "${toLua x};") cfg.extraModules)} + }; + + disco_items = { + ${lib.concatStringsSep "\n" (builtins.map (x: ''{ "${x.url}", "${x.description}"};'') discoItems)} + }; + + allow_registration = ${toLua cfg.allowRegistration} + + c2s_require_encryption = ${toLua cfg.c2sRequireEncryption} + + s2s_require_encryption = ${toLua cfg.s2sRequireEncryption} + s2s_secure_auth = ${toLua cfg.s2sSecureAuth} + s2s_insecure_domains = ${toLua cfg.s2sInsecureDomains} + s2s_secure_domains = ${toLua cfg.s2sSecureDomains} + + authentication = ${toLua cfg.authentication} + + http_interfaces = ${toLua cfg.httpInterfaces} + https_interfaces = ${toLua cfg.httpsInterfaces} + + http_ports = ${toLua cfg.httpPorts} + https_ports = ${toLua cfg.httpsPorts} + + ${cfg.extraConfig} + + ${lib.concatMapStrings (muc: '' + Component ${toLua muc.domain} "muc" + modules_enabled = { "muc_mam"; ${optionalString muc.vcard_muc ''"vcard_muc";''} ${optionalString muc.allowners_muc ''"muc_allowners";''} } + name = ${toLua muc.name} + restrict_room_creation = ${toLua muc.restrictRoomCreation} + max_history_messages = ${toLua muc.maxHistoryMessages} + muc_room_locking = ${toLua muc.roomLocking} + muc_room_lock_timeout = ${toLua muc.roomLockTimeout} + muc_tombstones = ${toLua muc.tombstones} + muc_tombstone_expiry = ${toLua muc.tombstoneExpiry} + muc_room_default_public = ${toLua muc.roomDefaultPublic} + muc_room_default_members_only = ${toLua muc.roomDefaultMembersOnly} + muc_room_default_moderated = ${toLua muc.roomDefaultModerated} + muc_room_default_public_jids = ${toLua muc.roomDefaultPublicJids} + muc_room_default_change_subject = ${toLua muc.roomDefaultChangeSubject} + muc_room_default_history_length = ${toLua muc.roomDefaultHistoryLength} + muc_room_default_language = ${toLua muc.roomDefaultLanguage} + ${muc.extraConfig} + '') cfg.muc} + + ${lib.optionalString (cfg.uploadHttp != null) '' + Component ${toLua cfg.uploadHttp.domain} "http_upload" + http_upload_file_size_limit = ${cfg.uploadHttp.uploadFileSizeLimit} + http_upload_expire_after = ${cfg.uploadHttp.uploadExpireAfter} + ${lib.optionalString ( + cfg.uploadHttp.userQuota != null + ) "http_upload_quota = ${toLua cfg.uploadHttp.userQuota}"} + http_upload_path = ${toLua cfg.uploadHttp.httpUploadPath} + ''} + + ${lib.optionalString (cfg.httpFileShare != null) '' + Component ${toLua cfg.httpFileShare.domain} "http_file_share" + ${settingsToLua " http_file_share_" (cfg.httpFileShare // { domain = null; })} + ''} + + ${lib.concatStringsSep "\n" ( + lib.mapAttrsToList (n: v: '' + VirtualHost "${v.domain}" + enabled = ${boolToString v.enabled}; + ${optionalString (v.ssl != null) (createSSLOptsStr v.ssl)} + ${v.extraConfig} + '') cfg.virtualHosts + )} + ''; + in { options = { @@ -517,6 +632,13 @@ in description = "Whether to enable the prosody server"; }; + checkConfig = mkOption { + type = types.bool; + default = true; + example = false; + description = "Check the configuration file with `prosodyctl check config`"; + }; + xmppComplianceSuite = mkOption { type = types.bool; default = true; @@ -832,120 +954,19 @@ in environment.systemPackages = [ cfg.package ]; - environment.etc."prosody/prosody.cfg.lua".text = - let - httpDiscoItems = - optional (cfg.uploadHttp != null) { - url = cfg.uploadHttp.domain; - description = "HTTP upload endpoint"; + environment.etc."prosody/prosody.cfg.lua".source = + if cfg.checkConfig then + pkgs.runCommandLocal "prosody.cfg.lua-checked" + { + nativeBuildInputs = [ cfg.package ]; } - ++ optional (cfg.httpFileShare != null) { - url = cfg.httpFileShare.domain; - description = "HTTP file share endpoint"; - }; - mucDiscoItems = builtins.foldl' ( - acc: muc: - [ - { - url = muc.domain; - description = "${muc.domain} MUC endpoint"; - } - ] - ++ acc - ) [ ] cfg.muc; - discoItems = cfg.disco_items ++ httpDiscoItems ++ mucDiscoItems; - in - '' - - pidfile = "/run/prosody/prosody.pid" - - log = ${cfg.log} - - data_path = "${cfg.dataDir}" - plugin_paths = { - ${lib.concatStringsSep ", " (map (n: "\"${n}\"") cfg.extraPluginPaths)} - } - - ${optionalString (cfg.ssl != null) (createSSLOptsStr cfg.ssl)} - - admins = ${toLua cfg.admins} - - modules_enabled = { - - ${lib.concatStringsSep "\n " ( - lib.mapAttrsToList (name: val: optionalString val "${toLua name};") cfg.modules - )} - ${lib.concatStringsSep "\n" (map (x: "${toLua x};") cfg.package.communityModules)} - ${lib.concatStringsSep "\n" (map (x: "${toLua x};") cfg.extraModules)} - }; - - disco_items = { - ${lib.concatStringsSep "\n" (builtins.map (x: ''{ "${x.url}", "${x.description}"};'') discoItems)} - }; - - allow_registration = ${toLua cfg.allowRegistration} - - c2s_require_encryption = ${toLua cfg.c2sRequireEncryption} - - s2s_require_encryption = ${toLua cfg.s2sRequireEncryption} - s2s_secure_auth = ${toLua cfg.s2sSecureAuth} - s2s_insecure_domains = ${toLua cfg.s2sInsecureDomains} - s2s_secure_domains = ${toLua cfg.s2sSecureDomains} - - authentication = ${toLua cfg.authentication} - - http_interfaces = ${toLua cfg.httpInterfaces} - https_interfaces = ${toLua cfg.httpsInterfaces} - - http_ports = ${toLua cfg.httpPorts} - https_ports = ${toLua cfg.httpsPorts} - - ${cfg.extraConfig} - - ${lib.concatMapStrings (muc: '' - Component ${toLua muc.domain} "muc" - modules_enabled = { "muc_mam"; ${optionalString muc.vcard_muc ''"vcard_muc";''} ${optionalString muc.allowners_muc ''"muc_allowners";''} } - name = ${toLua muc.name} - restrict_room_creation = ${toLua muc.restrictRoomCreation} - max_history_messages = ${toLua muc.maxHistoryMessages} - muc_room_locking = ${toLua muc.roomLocking} - muc_room_lock_timeout = ${toLua muc.roomLockTimeout} - muc_tombstones = ${toLua muc.tombstones} - muc_tombstone_expiry = ${toLua muc.tombstoneExpiry} - muc_room_default_public = ${toLua muc.roomDefaultPublic} - muc_room_default_members_only = ${toLua muc.roomDefaultMembersOnly} - muc_room_default_moderated = ${toLua muc.roomDefaultModerated} - muc_room_default_public_jids = ${toLua muc.roomDefaultPublicJids} - muc_room_default_change_subject = ${toLua muc.roomDefaultChangeSubject} - muc_room_default_history_length = ${toLua muc.roomDefaultHistoryLength} - muc_room_default_language = ${toLua muc.roomDefaultLanguage} - ${muc.extraConfig} - '') cfg.muc} - - ${lib.optionalString (cfg.uploadHttp != null) '' - Component ${toLua cfg.uploadHttp.domain} "http_upload" - http_upload_file_size_limit = ${cfg.uploadHttp.uploadFileSizeLimit} - http_upload_expire_after = ${cfg.uploadHttp.uploadExpireAfter} - ${lib.optionalString ( - cfg.uploadHttp.userQuota != null - ) "http_upload_quota = ${toLua cfg.uploadHttp.userQuota}"} - http_upload_path = ${toLua cfg.uploadHttp.httpUploadPath} - ''} - - ${lib.optionalString (cfg.httpFileShare != null) '' - Component ${toLua cfg.httpFileShare.domain} "http_file_share" - ${settingsToLua " http_file_share_" (cfg.httpFileShare // { domain = null; })} - ''} - - ${lib.concatStringsSep "\n" ( - lib.mapAttrsToList (n: v: '' - VirtualHost "${v.domain}" - enabled = ${boolToString v.enabled}; - ${optionalString (v.ssl != null) (createSSLOptsStr v.ssl)} - ${v.extraConfig} - '') cfg.virtualHosts - )} - ''; + '' + cp ${configFile} prosody.cfg.lua + prosodyctl --config ./prosody.cfg.lua check config + touch $out + '' + else + configFile; users.users.prosody = mkIf (cfg.user == "prosody") { uid = config.ids.uids.prosody; From 0a92661ec32d274258dc038dd1064eb92af0f0df Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Thu, 12 Oct 2023 01:20:37 +0200 Subject: [PATCH 3/3] nixos/release-notes: add entry for services.prosody.checkConfig --- nixos/doc/manual/release-notes/rl-2511.section.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/nixos/doc/manual/release-notes/rl-2511.section.md b/nixos/doc/manual/release-notes/rl-2511.section.md index dce9eed1f083..89da6c4844f8 100644 --- a/nixos/doc/manual/release-notes/rl-2511.section.md +++ b/nixos/doc/manual/release-notes/rl-2511.section.md @@ -141,6 +141,8 @@ - `services.clamsmtp` is unmaintained and was removed from Nixpkgs. +- `prosody` gained a config check option named `services.prosody.checkConfig` which runs `prosodyctl check config` and is turned on by default. + - `services.dependency-track` removed its configuration of the JVM heap size. This lets the JVM choose its maximum heap size automatically, which should work much better in practice for most users. For deployments on systems with little RAM, it may now be necessary to manually configure a maximum heap size using {option}`services.dependency-track.javaArgs`. - `services.dnscrypt-proxy2` gains a `package` option to specify dnscrypt-proxy package to use.