nixos-mailserver/mail-server/common.nix

51 lines
2 KiB
Nix
Raw Normal View History

2017-09-03 11:15:18 +02:00
# nixos-mailserver: a simple mail server
# Copyright (C) 2016-2017 Robin Raymond
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation, either version 3 of the License, or
# (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>
2017-12-22 16:08:42 +01:00
{ config, lib }:
2017-09-03 11:15:18 +02:00
let
cfg = config.mailserver;
2017-12-22 16:08:42 +01:00
# passwd :: [ String ]
passwd = lib.mapAttrsToList
2017-12-22 16:58:35 +01:00
(name: value: "${name}:${value.hashedPassword}:${builtins.toString cfg.vmailUID}:${builtins.toString cfg.vmailUID}::${cfg.mailDirectory}:/run/current-system/sw/bin/nologin:"
+ (if lib.isString value.quota
then "userdb_quota_rule=*:storage=${value.quota}"
else ""))
2017-12-22 16:08:42 +01:00
cfg.loginAccounts;
2017-09-03 11:15:18 +02:00
in
{
# cert :: PATH
certificatePath = if cfg.certificateScheme == 1
then cfg.certificateFile
else if cfg.certificateScheme == 2
then "${cfg.certificateDirectory}/cert-${cfg.fqdn}.pem"
2017-09-23 09:56:09 +02:00
else if cfg.certificateScheme == 3
then "/var/lib/acme/${cfg.fqdn}/fullchain.pem"
2017-09-23 09:56:09 +02:00
else throw "Error: Certificate Scheme must be in { 1, 2, 3 }";
2017-09-03 11:15:18 +02:00
# key :: PATH
keyPath = if cfg.certificateScheme == 1
then cfg.keyFile
else if cfg.certificateScheme == 2
then "${cfg.certificateDirectory}/key-${cfg.fqdn}.pem"
2017-09-23 09:56:09 +02:00
else if cfg.certificateScheme == 3
then "/var/lib/acme/${cfg.fqdn}/key.pem"
2017-09-23 09:56:09 +02:00
else throw "Error: Certificate Scheme must be in { 1, 2, 3 }";
2017-12-22 16:58:35 +01:00
2017-12-22 16:08:42 +01:00
# passwdFile :: PATH
passwdFile = builtins.toFile "passwd" (lib.concatStringsSep "\n" passwd);
2017-09-03 11:15:18 +02:00
}