Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion nixos/modules/services/mail/mailman.nix
Original file line number Diff line number Diff line change
Expand Up @@ -547,7 +547,9 @@ in
mv $out/bin/mailman $out/bin/.mailman-wrapped
echo '#!${pkgs.runtimeShell}
sudo=exec
if [[ "$USER" != mailman ]]; then
if [[ "''${USER:-root}" == 'root' ]]; then
sudo='exec runuser -u mailman --'
elif [[ "$USER" != "mediagoblin" ]]; then
sudo="exec /run/wrappers/bin/sudo -u mailman"
fi
$sudo ${placeholder "out"}/bin/.mailman-wrapped "$@"
Expand Down
4 changes: 3 additions & 1 deletion nixos/modules/services/misc/omnom.nix
Original file line number Diff line number Diff line change
Expand Up @@ -259,7 +259,9 @@ in
#! ${pkgs.runtimeShell}
cd ${cfg.dataDir}
sudo=exec
if [[ "$USER" != ${cfg.user} ]]; then
if [[ "''${USER:-root}" == 'root' ]]; then
sudo='exec runuser -u ${cfg.user} --'
elif [[ "$USER" != "${cfg.user}" ]]; then
sudo='exec /run/wrappers/bin/sudo -u ${cfg.user}'
fi
$sudo ${lib.getExe cfg.package} "$@"
Expand Down
4 changes: 3 additions & 1 deletion nixos/modules/services/misc/paperless.nix
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,9 @@ let

cd '${cfg.dataDir}'
sudo=exec
if [[ "$USER" != ${cfg.user} ]]; then
if [[ "''${USER:-root}" == 'root' ]]; then
sudo='exec runuser -u ${cfg.user} --'
elif [[ "$USER" != "${cfg.user}" ]]; then
${
if config.security.sudo.enable then
"sudo='exec ${config.security.wrapperDir}/sudo -u ${cfg.user} -E'"
Expand Down
10 changes: 7 additions & 3 deletions nixos/modules/services/monitoring/librenms.nix
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,9 @@ let
artisanWrapper = pkgs.writeShellScriptBin "librenms-artisan" ''
cd ${package}
sudo=exec
if [[ "$USER" != ${cfg.user} ]]; then
if [[ "''${USER:-root}" == 'root' ]]; then
sudo='exec runuser -u ${cfg.user} --'
elif [[ "$USER" != "${cfg.user}" ]]; then
sudo='exec /run/wrappers/bin/sudo -u ${cfg.user}'
fi
$sudo ${package}/artisan "$@"
Expand All @@ -50,8 +52,10 @@ let
lnmsWrapper = pkgs.writeShellScriptBin "lnms" ''
cd ${package}
sudo=exec
if [[ "$USER" != ${cfg.user} ]]; then
sudo='exec /run/wrappers/bin/sudo -u ${cfg.user}'
if [[ "''${USER:-root}" == 'root' ]]; then
sudo='exec runuser -u ${cfg.user} --'
elif [[ "$USER" != "${cfg.user}" ]]; then
sudo='exec /run/wrappers/bin/sudo -u ${cfg.user}'
fi
$sudo ${package}/lnms "$@"
'';
Expand Down
4 changes: 3 additions & 1 deletion nixos/modules/services/networking/pihole-ftl.nix
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,9 @@ let

piholeScript = pkgs.writeScriptBin "pihole" ''
sudo=exec
if [[ "$USER" != '${cfg.user}' ]]; then
if [[ "''${USER:-root}" == 'root' ]]; then
sudo='exec runuser -u ${cfg.user} --'
elif [[ "$USER" != "${cfg.user}" ]]; then
sudo='exec /run/wrappers/bin/sudo -u ${cfg.user}'
fi
$sudo ${getExe cfg.piholePackage} "$@"
Expand Down
4 changes: 3 additions & 1 deletion nixos/modules/services/security/crowdsec.nix
Original file line number Diff line number Diff line change
Expand Up @@ -513,7 +513,9 @@ in
# cscli needs crowdsec on it's path in order to be able to run `cscli explain`
export PATH="$PATH:${lib.makeBinPath [ cfg.package ]}"
sudo=exec
if [ "$USER" != "${cfg.user}" ]; then
if [[ "''${USER:-root}" == 'root' ]]; then
sudo='exec runuser -u ${cfg.user} --'
elif [[ "$USER" != "${cfg.user}" ]]; then
${
if config.security.sudo.enable then
"sudo='exec ${config.security.wrapperDir}/sudo -u ${cfg.user}'"
Expand Down
4 changes: 3 additions & 1 deletion nixos/modules/services/web-apps/gancio.nix
Original file line number Diff line number Diff line change
Expand Up @@ -171,7 +171,9 @@ in
echo '#!${pkgs.runtimeShell}
cd /var/lib/gancio/
sudo=exec
if [[ "$USER" != ${cfg.user} ]]; then
if [[ "''${USER:-root}" == 'root' ]]; then
sudo='exec runuser -u ${cfg.user} --'
elif [[ "$USER" != "${cfg.user}" ]]; then
sudo="exec /run/wrappers/bin/sudo -u ${cfg.user}"
fi
$sudo ${lib.getExe cfg.package} "''${@:--help}"
Expand Down
4 changes: 3 additions & 1 deletion nixos/modules/services/web-apps/healthchecks.nix
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,9 @@ let

healthchecksManageScript = pkgs.writeShellScriptBin "healthchecks-manage" ''
sudo=exec
if [[ "$USER" != "${cfg.user}" ]]; then
if [[ "''${USER:-root}" == 'root' ]]; then
sudo='exec runuser -u ${cfg.user} --preserve-environment --'
elif [[ "$USER" != "${cfg.user}" ]]; then
sudo='exec /run/wrappers/bin/sudo -u ${cfg.user} --preserve-env --preserve-env=PYTHONPATH'
fi
export $(cat ${environmentFile} | xargs)
Expand Down
4 changes: 3 additions & 1 deletion nixos/modules/services/web-apps/libretranslate.nix
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,9 @@ let
set -a
export HOME="/var/lib/libretranslate"
sudo=exec
if [[ "$USER" != ${cfg.user} ]]; then
if [[ "''${USER:-root}" == 'root' ]]; then
sudo='exec runuser -u ${cfg.user} --preserve-environment --'
elif [[ "$USER" != "${cfg.user}" ]]; then
sudo='exec /run/wrappers/bin/sudo -u ${cfg.user} --preserve-env'
fi
$sudo ${cfg.package}/bin/ltmanage keys --api-keys-db-path ${cfg.dataDir}/db/api_keys.db "$@"
Expand Down
4 changes: 3 additions & 1 deletion nixos/modules/services/web-apps/mastodon.nix
Original file line number Diff line number Diff line change
Expand Up @@ -150,7 +150,9 @@ let
${sourceExtraEnv}

sudo=exec
if [[ "$USER" != ${cfg.user} ]]; then
if [[ "''${USER:-root}" == 'root' ]]; then
sudo='exec runuser -u ${cfg.user} --preserve-environment --'
elif [[ "$USER" != "${cfg.user}" ]]; then
sudo='exec /run/wrappers/bin/sudo -u ${cfg.user} --preserve-env'
fi
$sudo ${cfg.package}/bin/tootctl "$@"
Expand Down
4 changes: 3 additions & 1 deletion nixos/modules/services/web-apps/mediagoblin.nix
Original file line number Diff line number Diff line change
Expand Up @@ -196,7 +196,9 @@ in
environment.systemPackages = [
(pkgs.writeShellScriptBin "mediagoblin-gmg" ''
sudo=exec
if [[ "$USER" != mediagoblin ]]; then
if [[ "''${USER:-root}" == 'root' ]]; then
sudo='exec runuser -u mediagoblin --'
elif [[ "$USER" != "mediagoblin" ]]; then
sudo='exec /run/wrappers/bin/sudo -u mediagoblin'
fi
$sudo sh -c "cd /var/lib/mediagoblin; env GI_TYPELIB_PATH=${GI_TYPELIB_PATH} GST_PLUGIN_PATH=${GST_PLUGIN_PATH} PATH=$PATH:${lib.makeBinPath path} ${lib.getExe' finalPackage "gmg"} $*"
Expand Down
4 changes: 3 additions & 1 deletion nixos/modules/services/web-apps/pdfding.nix
Original file line number Diff line number Diff line change
Expand Up @@ -302,7 +302,9 @@ in
set +a
${loadCreds}
sudo=exec
if [[ "$USER" != ${cfg.user} ]]; then
if [[ "''${USER:-root}" == 'root' ]]; then
sudo='exec runuser -u ${cfg.user} --preserve-environment --'
elif [[ "$USER" != "${cfg.user}" ]]; then
sudo='${config.security.wrapperDir}/sudo -E -u ${cfg.user}'
fi
${cmd}
Expand Down
4 changes: 3 additions & 1 deletion nixos/modules/services/web-apps/pixelfed.nix
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,9 @@ let
pixelfed-manage = pkgs.writeShellScriptBin "pixelfed-manage" ''
cd ${pixelfed}
sudo=exec
if [[ "$USER" != ${user} ]]; then
if [[ "''${USER:-root}" == 'root' ]]; then
sudo='exec runuser -u ${cfg.user} --'
elif [[ "$USER" != "${cfg.user}" ]]; then
sudo='exec /run/wrappers/bin/sudo -u ${user}'
fi
$sudo ${phpPackage}/bin/php artisan "$@"
Expand Down
4 changes: 3 additions & 1 deletion nixos/modules/services/web-apps/pretalx.nix
Original file line number Diff line number Diff line change
Expand Up @@ -328,7 +328,9 @@ in
(pkgs.writeScriptBin "pretalx-manage" ''
cd ${cfg.settings.filesystem.data}
sudo=exec
if [[ "$USER" != ${cfg.user} ]]; then
if [[ "''${USER:-root}" == 'root' ]]; then
sudo='exec runuser -u ${cfg.user} --preserve-environment --'
elif [[ "$USER" != "${cfg.user}" ]]; then
sudo='exec /run/wrappers/bin/sudo -u ${cfg.user} --preserve-env=PRETALX_CONFIG_FILE'
fi
set -a
Expand Down
4 changes: 3 additions & 1 deletion nixos/modules/services/web-apps/pretix.nix
Original file line number Diff line number Diff line change
Expand Up @@ -399,7 +399,9 @@ in
(pkgs.writeScriptBin "pretix-manage" ''
cd ${cfg.settings.pretix.datadir}
sudo=exec
if [[ "$USER" != ${cfg.user} ]]; then
if [[ "''${USER:-root}" == 'root' ]]; then
sudo='exec runuser -u ${cfg.user} --preserve-environment --'
elif [[ "$USER" != "${cfg.user}" ]]; then
sudo='exec /run/wrappers/bin/sudo -u ${cfg.user} ${optionalString withRedis "-g redis-pretix"} --preserve-env=PRETIX_CONFIG_FILE'
fi
export PRETIX_CONFIG_FILE=${configFile}
Expand Down
4 changes: 3 additions & 1 deletion nixos/modules/services/web-apps/snipe-it.nix
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,9 @@ let
#! ${pkgs.runtimeShell}
cd "${snipe-it}/share/php/snipe-it"
sudo=exec
if [[ "$USER" != ${user} ]]; then
if [[ "''${USER:-root}" == 'root' ]]; then
sudo='exec runuser -u ${cfg.user} --'
elif [[ "$USER" != "${cfg.user}" ]]; then
sudo='exec /run/wrappers/bin/sudo -u ${user}'
fi
$sudo ${phpPackage}/bin/php artisan $*
Expand Down
12 changes: 3 additions & 9 deletions nixos/tests/web-apps/mastodon/remote-databases.nix
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ import ../../make-test-python.nix (
izorkin
];

nodes = {
containers = {
databases =
{ config, ... }:
{
Expand Down Expand Up @@ -76,7 +76,7 @@ import ../../make-test-python.nix (
};

nginx =
{ nodes, ... }:
{ containers, ... }:
{
networking = {
interfaces.eth1 = {
Expand Down Expand Up @@ -111,7 +111,7 @@ import ../../make-test-python.nix (
tryFiles = "$uri @proxy";
};
locations."@proxy" = {
proxyPass = "http://192.168.2.201:${toString nodes.server.services.mastodon.webPort}";
proxyPass = "http://192.168.2.201:${toString containers.server.services.mastodon.webPort}";
proxyWebsockets = true;
};
};
Expand All @@ -121,8 +121,6 @@ import ../../make-test-python.nix (
server =
{ config, pkgs, ... }:
{
virtualisation.memorySize = 2048;

environment = {
etc = {
"mastodon/password-redis-db".text = redisPassword;
Expand Down Expand Up @@ -211,10 +209,6 @@ import ../../make-test-python.nix (
databases.wait_for_open_port(31637)
databases.wait_for_open_port(5432)
'';
extraShutdown = ''
nginx.shutdown()
databases.shutdown()
'';
};
}
)
5 changes: 0 additions & 5 deletions nixos/tests/web-apps/mastodon/script.nix
Original file line number Diff line number Diff line change
Expand Up @@ -45,9 +45,4 @@
client.fail("curl --fail https://mastodon.local/about")
server.succeed("mastodon-tootctl ip_blocks remove 192.168.0.0/16")
client.succeed("curl --fail https://mastodon.local/about")
server.shutdown()
client.shutdown()
${extraShutdown}
''
4 changes: 1 addition & 3 deletions nixos/tests/web-apps/mastodon/standard.nix
Original file line number Diff line number Diff line change
Expand Up @@ -22,13 +22,11 @@ import ../../make-test-python.nix (
turion
];

nodes = {
containers = {
server =
{ pkgs, ... }:
{

virtualisation.memorySize = 2048;

networking = {
interfaces.eth1 = {
ipv4.addresses = [
Expand Down
Loading