From 9b8f9a4bf5e13efe49ec101f127d0df3d7bb3cf3 Mon Sep 17 00:00:00 2001 From: adikro Date: Sat, 27 Jun 2026 02:41:27 +0200 Subject: revamped sanoid, syncoid and nfs --- os/srv/redis.nix | 37 +++++++++++++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) create mode 100644 os/srv/redis.nix (limited to 'os/srv/redis.nix') diff --git a/os/srv/redis.nix b/os/srv/redis.nix new file mode 100644 index 0000000..a51f9db --- /dev/null +++ b/os/srv/redis.nix @@ -0,0 +1,37 @@ +{ config, lib, ... }: +let + cfg = config.os.srv.redis; +in +{ + options.os.srv.redis.enable = lib.mkEnableOption ""; + config = lib.mkIf cfg.enable { + assertions = [ + { + assertion = config.os.srv.sops.enable; + message = "Required for password secure password storing"; + } + { + assertion = config.os.core.network.enableFirewall; + message = "Requires firewall"; + } + ]; + + sops.secrets."redis/password" = { + owner = "redis-main"; + restartUnits = [ "redis-servers-main.service" ]; + }; + + services.redis.servers."main" = { + enable = true; + bind = config.os.core.network.ips.database-vm; + port = 6379; + + requirePassFile = config.sops.secrets."redis/password".path; + }; + + networking.firewall.extraInputRules = '' + ip saddr 10.0.0.0/24 tcp dport 6379 accept + ''; + + }; +} -- cgit v1.3