diff options
| author | adikro <adikro@disroot.org> | 2026-06-27 02:41:27 +0200 |
|---|---|---|
| committer | adikro <adikro@disroot.org> | 2026-06-27 02:41:27 +0200 |
| commit | 9b8f9a4bf5e13efe49ec101f127d0df3d7bb3cf3 (patch) | |
| tree | b857cd260647dea82b0c63367eef9fa18cd63b8d /os/srv/redis.nix | |
| parent | 30f34740891096471b5663704fbbd9bf67ebe885 (diff) | |
revamped sanoid, syncoid and nfs
Diffstat (limited to 'os/srv/redis.nix')
| -rw-r--r-- | os/srv/redis.nix | 37 |
1 files changed, 37 insertions, 0 deletions
diff --git a/os/srv/redis.nix b/os/srv/redis.nix new file mode 100644 index 0000000..a51f9db --- /dev/null +++ b/os/srv/redis.nix @@ -0,0 +1,37 @@ +{ config, lib, ... }: +let + cfg = config.os.srv.redis; +in +{ + options.os.srv.redis.enable = lib.mkEnableOption ""; + config = lib.mkIf cfg.enable { + assertions = [ + { + assertion = config.os.srv.sops.enable; + message = "Required for password secure password storing"; + } + { + assertion = config.os.core.network.enableFirewall; + message = "Requires firewall"; + } + ]; + + sops.secrets."redis/password" = { + owner = "redis-main"; + restartUnits = [ "redis-servers-main.service" ]; + }; + + services.redis.servers."main" = { + enable = true; + bind = config.os.core.network.ips.database-vm; + port = 6379; + + requirePassFile = config.sops.secrets."redis/password".path; + }; + + networking.firewall.extraInputRules = '' + ip saddr 10.0.0.0/24 tcp dport 6379 accept + ''; + + }; +} |
