diff options
Diffstat (limited to 'os/srv/redis.nix')
| -rw-r--r-- | os/srv/redis.nix | 37 |
1 files changed, 37 insertions, 0 deletions
diff --git a/os/srv/redis.nix b/os/srv/redis.nix new file mode 100644 index 0000000..a51f9db --- /dev/null +++ b/os/srv/redis.nix @@ -0,0 +1,37 @@ +{ config, lib, ... }: +let + cfg = config.os.srv.redis; +in +{ + options.os.srv.redis.enable = lib.mkEnableOption ""; + config = lib.mkIf cfg.enable { + assertions = [ + { + assertion = config.os.srv.sops.enable; + message = "Required for password secure password storing"; + } + { + assertion = config.os.core.network.enableFirewall; + message = "Requires firewall"; + } + ]; + + sops.secrets."redis/password" = { + owner = "redis-main"; + restartUnits = [ "redis-servers-main.service" ]; + }; + + services.redis.servers."main" = { + enable = true; + bind = config.os.core.network.ips.database-vm; + port = 6379; + + requirePassFile = config.sops.secrets."redis/password".path; + }; + + networking.firewall.extraInputRules = '' + ip saddr 10.0.0.0/24 tcp dport 6379 accept + ''; + + }; +} |
