Keep Iota runtime config writable
This commit is contained in:
parent
577660884c
commit
6d2114260b
1 changed files with 12 additions and 8 deletions
20
flake.nix
20
flake.nix
|
|
@ -161,11 +161,12 @@
|
||||||
key = "${cfg.stateDir}/tls/key.pem";
|
key = "${cfg.stateDir}/tls/key.pem";
|
||||||
};
|
};
|
||||||
} cfg.settings;
|
} cfg.settings;
|
||||||
configFile =
|
sourceConfigFile =
|
||||||
if cfg.settingsFile != null then
|
if cfg.settingsFile != null then
|
||||||
cfg.settingsFile
|
cfg.settingsFile
|
||||||
else
|
else
|
||||||
configFormat.generate "iota-config.yaml" effectiveSettings;
|
configFormat.generate "iota-config.yaml" effectiveSettings;
|
||||||
|
configFile = "${cfg.stateDir}/config.yaml";
|
||||||
|
|
||||||
descriptionText = "Tensamin Iota daemon";
|
descriptionText = "Tensamin Iota daemon";
|
||||||
in
|
in
|
||||||
|
|
@ -340,7 +341,6 @@
|
||||||
cfg.logDir
|
cfg.logDir
|
||||||
];
|
];
|
||||||
ReadOnlyPaths = [
|
ReadOnlyPaths = [
|
||||||
configFile
|
|
||||||
cfg.assetDir
|
cfg.assetDir
|
||||||
];
|
];
|
||||||
ProtectKernelTunables = true;
|
ProtectKernelTunables = true;
|
||||||
|
|
@ -361,12 +361,16 @@
|
||||||
"IOTA_DEPLOYMENT_MODE=system_socket_activated"
|
"IOTA_DEPLOYMENT_MODE=system_socket_activated"
|
||||||
"IOTA_SUPERVISOR=systemd"
|
"IOTA_SUPERVISOR=systemd"
|
||||||
];
|
];
|
||||||
}
|
ExecStartPre = "+${pkgs.writeShellScript "iota-setup" ''
|
||||||
// lib.optionalAttrs (cfg.certFile != null) {
|
# ponytail: Preserve daemon-assigned IDs; remove config.yaml to reseed changed declarative settings.
|
||||||
ExecStartPre = "+${pkgs.writeShellScript "iota-setup-tls" ''
|
if [ ! -e ${configFile} ]; then
|
||||||
install -d -m 0700 -o iota -g iota ${cfg.stateDir}/tls
|
install -m 0640 -o iota -g iota ${sourceConfigFile} ${configFile}
|
||||||
install -m 0644 -o iota -g iota ${cfg.certFile} ${cfg.stateDir}/tls/cert.pem
|
fi
|
||||||
install -m 0600 -o iota -g iota ${cfg.keyFile} ${cfg.stateDir}/tls/key.pem
|
${lib.optionalString (cfg.certFile != null) ''
|
||||||
|
install -d -m 0700 -o iota -g iota ${cfg.stateDir}/tls
|
||||||
|
install -m 0644 -o iota -g iota ${cfg.certFile} ${cfg.stateDir}/tls/cert.pem
|
||||||
|
install -m 0600 -o iota -g iota ${cfg.keyFile} ${cfg.stateDir}/tls/key.pem
|
||||||
|
''}
|
||||||
''}";
|
''}";
|
||||||
}
|
}
|
||||||
// lib.optionalAttrs (cfg.environmentFiles != [ ]) {
|
// lib.optionalAttrs (cfg.environmentFiles != [ ]) {
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue