Something went wrong. Try again.
Monorepo for Tangled tangled.org
Something went wrong. Try again.
Nix
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122{ config, pkgs, lib, ...}: let cfg = config.services.tangled.tranquil-gate;in with lib; { options.services.tangled.tranquil-gate = { enable = mkEnableOption "tranquil-gate delegated account provisioning service";
package = mkOption { type = types.package; description = "tranquil-gate package to run"; };
bind = mkOption { type = types.str; default = "0.0.0.0:3100"; description = "address the xrpc server binds to"; };
did = mkOption { type = types.str; description = "gate's own service DID"; };
tranquilUrl = mkOption { type = types.str; description = "base url of the tranquil PDS"; };
tranquilDid = mkOption { type = types.str; description = "service DID of the tranquil PDS"; };
deliberiUrl = mkOption { type = types.str; description = "base url of deliberi, used to check email verification"; };
deliberiDid = mkOption { type = types.str; description = "service DID of deliberi"; };
plcUrl = mkOption { type = types.str; default = "https://plc.directory"; };
extraCaFile = mkOption { type = types.nullOr types.path; default = null; description = "additional CA certificate trusted when calling tranquil and deliberi"; };
requireVerifiedEmail = mkOption { type = types.bool; default = true; description = "require a verified email before provisioning an account"; };
logFormat = mkOption { type = types.enum ["text" "json"]; default = "text"; };
logFilter = mkOption { type = types.str; default = "info"; description = "tracing env-filter directives"; };
environmentFile = mkOption { type = types.nullOr types.path; default = null; description = "file with secret env vars (GATE_SIGNING_KEY, ...)"; }; };
config = mkIf cfg.enable { systemd.services.tranquil-gate = { description = "tranquil-gate delegated account provisioning service"; after = ["network.target"]; wantedBy = ["multi-user.target"]; serviceConfig = { DynamicUser = true; LogsDirectory = "tranquil-gate"; EnvironmentFile = mkIf (cfg.environmentFile != null) cfg.environmentFile; Environment = [ "GATE_BIND=${cfg.bind}" "GATE_DID=${cfg.did}" "GATE_TRANQUIL_URL=${cfg.tranquilUrl}" "GATE_TRANQUIL_DID=${cfg.tranquilDid}" "GATE_DELIBERI_URL=${cfg.deliberiUrl}" "GATE_DELIBERI_DID=${cfg.deliberiDid}" "GATE_PLC_URL=${cfg.plcUrl}" "GATE_REQUIRE_VERIFIED_EMAIL=${boolToString cfg.requireVerifiedEmail}" "GATE_LOG_FORMAT=${cfg.logFormat}" "RUST_LOG=${cfg.logFilter}" ] ++ optional (cfg.extraCaFile != null) "GATE_EXTRA_CA_FILE=${cfg.extraCaFile}"; ExecStart = getExe cfg.package; Restart = "always"; NoNewPrivileges = true; PrivateTmp = true; ProtectSystem = "strict"; ProtectHome = true; ProtectKernelTunables = true; ProtectKernelModules = true; ProtectControlGroups = true; RestrictAddressFamilies = ["AF_INET" "AF_INET6"]; SystemCallFilter = ["@system-service"]; }; }; }; }