From 174da9362d11414adc970079f61cf8e7fb355e63 Mon Sep 17 00:00:00 2001 From: Felix Singer Date: Mon, 22 Sep 2025 20:43:10 +0200 Subject: [PATCH 1/2] nixos/murmur: Rename TLS related options Instead of prefixing these options with "ssl", group them by "tls" which also allows to group more options later and adjust description texts. Also, while on it, rename the options themselves that their name reflect their purpose better. Signed-off-by: Felix Singer --- nixos/modules/services/networking/murmur.nix | 54 +++++++++++--------- 1 file changed, 31 insertions(+), 23 deletions(-) diff --git a/nixos/modules/services/networking/murmur.nix b/nixos/modules/services/networking/murmur.nix index 9b1cf76860e3..f9f3f87e4163 100644 --- a/nixos/modules/services/networking/murmur.nix +++ b/nixos/modules/services/networking/murmur.nix @@ -41,9 +41,9 @@ let ${lib.optionalString (cfg.registerHostname != "") "registerHostname=${cfg.registerHostname}"} certrequired=${lib.boolToString cfg.clientCertRequired} - ${lib.optionalString (cfg.sslCert != null) "sslCert=${cfg.sslCert}"} - ${lib.optionalString (cfg.sslKey != null) "sslKey=${cfg.sslKey}"} - ${lib.optionalString (cfg.sslCa != null) "sslCA=${cfg.sslCa}"} + ${lib.optionalString (cfg.tls.certPath != null) "sslCert=${cfg.tls.certPath}"} + ${lib.optionalString (cfg.tls.keyPath != null) "sslKey=${cfg.tls.keyPath}"} + ${lib.optionalString (cfg.tls.caPath != null) "sslCA=${cfg.tls.caPath}"} ${lib.optionalString (cfg.dbus != null) "dbus=${cfg.dbus}"} @@ -58,6 +58,12 @@ in "murmur" "logFile" ] "This option has been superseded by services.murmur.logToFile") + (lib.mkRenamedOptionModule [ "services" "murmur" "sslCa" ] [ "services" "murmur" "tls" "caPath" ]) + (lib.mkRenamedOptionModule [ "services" "murmur" "sslKey" ] [ "services" "murmur" "tls" "keyPath" ]) + (lib.mkRenamedOptionModule + [ "services" "murmur" "sslCert" ] + [ "services" "murmur" "tls" "certPath" ] + ) ]; options = { @@ -237,22 +243,24 @@ in clientCertRequired = lib.mkEnableOption "requiring clients to authenticate via certificates"; - sslCert = lib.mkOption { - type = lib.types.nullOr lib.types.path; - default = null; - description = "Path to your SSL certificate."; - }; + tls = { + certPath = lib.mkOption { + type = lib.types.nullOr lib.types.path; + default = null; + description = "Path to your TLS certificate."; + }; - sslKey = lib.mkOption { - type = lib.types.nullOr lib.types.path; - default = null; - description = "Path to your SSL key."; - }; + keyPath = lib.mkOption { + type = lib.types.nullOr lib.types.path; + default = null; + description = "Path to your TLS key."; + }; - sslCa = lib.mkOption { - type = lib.types.nullOr lib.types.path; - default = null; - description = "Path to your SSL CA certificate."; + caPath = lib.mkOption { + type = lib.types.nullOr lib.types.path; + default = null; + description = "Path to your TLS CA certificate."; + }; }; extraConfig = lib.mkOption { @@ -422,14 +430,14 @@ in ${lib.optionalString cfg.logToFile '' /var/log/murmur/murmurd.log rw, ''} - ${lib.optionalString (cfg.sslCert != null) '' - ${cfg.sslCert} r, + ${lib.optionalString (cfg.tls.certPath != null) '' + ${cfg.tls.certPath} r, ''} - ${lib.optionalString (cfg.sslKey != null) '' - ${cfg.sslKey} r, + ${lib.optionalString (cfg.tls.keyPath != null) '' + ${cfg.tls.keyPath} r, ''} - ${lib.optionalString (cfg.sslCa != null) '' - ${cfg.sslCa} r, + ${lib.optionalString (cfg.tls.caPath != null) '' + ${cfg.tls.caPath} r, ''} ${lib.optionalString (cfg.dbus != null) '' dbus bus=${cfg.dbus}, From 309bf1db8096585751bbf55eba6b3b639699c095 Mon Sep 17 00:00:00 2001 From: Felix Singer Date: Wed, 24 Sep 2025 06:44:38 +0200 Subject: [PATCH 2/2] nixos/murmur: Allow hooking up to ACME certificate service In order to simplify using certificates provided by ACME, add the option `services.murmur.tls.useACMEHost`. If set, the options keyPath, certPath and caPath are pre-configured appropriately. Also, add the appriopriate ACME systemd service to Murmur's dependencies if useACMEHost is set. Signed-off-by: Felix Singer --- nixos/modules/services/networking/murmur.nix | 35 +++++++++++++++++--- 1 file changed, 31 insertions(+), 4 deletions(-) diff --git a/nixos/modules/services/networking/murmur.nix b/nixos/modules/services/networking/murmur.nix index f9f3f87e4163..8f72e3c52b84 100644 --- a/nixos/modules/services/networking/murmur.nix +++ b/nixos/modules/services/networking/murmur.nix @@ -7,6 +7,8 @@ let cfg = config.services.murmur; + acmeHostDir = config.security.acme.certs."${cfg.tls.useACMEHost}".directory; + forking = cfg.logToFile; configFile = pkgs.writeText "murmurd.ini" '' database=${cfg.stateDir}/murmur.sqlite @@ -246,21 +248,38 @@ in tls = { certPath = lib.mkOption { type = lib.types.nullOr lib.types.path; - default = null; + default = if (cfg.tls.useACMEHost != null) then "${acmeHostDir}/cert.pem" else null; + defaultText = lib.literalMD "If {option}`services.murmur.tls.useACMEHost` is set, defaults to what's provided by the ACME module."; description = "Path to your TLS certificate."; }; keyPath = lib.mkOption { type = lib.types.nullOr lib.types.path; - default = null; + default = if (cfg.tls.useACMEHost != null) then "${acmeHostDir}/key.pem" else null; + defaultText = lib.literalMD "If {option}`services.murmur.tls.useACMEHost` is set, defaults to what's provided by the ACME module."; description = "Path to your TLS key."; }; caPath = lib.mkOption { type = lib.types.nullOr lib.types.path; - default = null; + default = if (cfg.tls.useACMEHost != null) then "${acmeHostDir}/chain.pem" else null; + defaultText = lib.literalMD "If {option}`services.murmur.tls.useACMEHost` is set, defaults to what's provided by the ACME module."; description = "Path to your TLS CA certificate."; }; + + useACMEHost = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + example = "mumble.example.com"; + description = '' + Host of an existing Let's Encrypt certificate to use for TLS. + Make sure that the certificate directory is readable by the + `murmur` user or group. *Note that this option does not + create any certificates and it doesn't add subdomains to + existing ones – you will need to create them manually using + {option}`security.acme.certs`.* + ''; + }; }; extraConfig = lib.mkOption { @@ -324,10 +343,18 @@ in allowedUDPPorts = [ cfg.port ]; }; + security.acme.certs = lib.mkIf (cfg.tls.useACMEHost != null) { + "${cfg.tls.useACMEHost}".reloadServices = [ "murmur.service" ]; + }; + systemd.services.murmur = { description = "Murmur Chat Service"; wantedBy = [ "multi-user.target" ]; - after = [ "network.target" ]; + after = [ + "network.target" + ] + ++ lib.optional (cfg.tls.useACMEHost != null) "acme-${cfg.tls.useACMEHost}.service"; + wants = lib.mkIf (cfg.tls.useACMEHost != null) [ "acme-${cfg.tls.useACMEHost}.service" ]; preStart = '' ${pkgs.envsubst}/bin/envsubst \ -o /run/murmur/murmurd.ini \