diff --git a/nixos/modules/services/monitoring/osquery.nix b/nixos/modules/services/monitoring/osquery.nix index fe6c79a79fe5..a54f4f4ecbbf 100644 --- a/nixos/modules/services/monitoring/osquery.nix +++ b/nixos/modules/services/monitoring/osquery.nix @@ -65,13 +65,27 @@ in database_path = lib.mkOption { default = "/var/lib/osquery/osquery.db"; readOnly = true; - description = "Path used for the database file."; + description = '' + Path used for the database file. + + ::: {.note} + If left as the default value, this directory will be automatically created before the + service starts, otherwise you are responsible for ensuring the directory exists with + the appropriate ownership and permissions. + ''; type = path; }; logger_path = lib.mkOption { default = "/var/log/osquery"; readOnly = true; - description = "Base directory used for logging."; + description = '' + Base directory used for logging. + + ::: {.note} + If left as the default value, this directory will be automatically created before the + service starts, otherwise you are responsible for ensuring the directory exists with + the appropriate ownership and permissions. + ''; type = path; }; pidfile = lib.mkOption { @@ -96,8 +110,8 @@ in serviceConfig = { ExecStart = "${pkgs.osquery}/bin/osqueryd --flagfile ${flagfile}"; PIDFile = cfg.flags.pidfile; - LogsDirectory = cfg.flags.logger_path; - StateDirectory = dirname cfg.flags.database_path; + LogsDirectory = lib.mkIf (cfg.flags.logger_path == "/var/log/osquery") [ "osquery" ]; + StateDirectory = lib.mkIf (cfg.flags.database_path == "/var/lib/osquery/osquery.db") [ "osquery" ]; Restart = "always"; }; wantedBy = [ "multi-user.target" ];