nixos/autobrr: remove secretFile

autobrr no longer uses a session secret since version 1.82.0.
This commit is contained in:
silentpager-rocks
2026-09-29 15:17:14 +02:00
parent 2e995dc90d
commit 64eb5ef748
3 changed files with 17 additions and 36 deletions

View File

@@ -148,6 +148,8 @@
<!-- To avoid merge conflicts, consider adding your item at an arbitrary place in the list instead. -->
- `services.autobrr.secretFile` has been removed, as autobrr no longer uses a session secret since version 1.82.0. Remove the option from your configuration.
- Artalk has been updated to 2.10.0. Its default configuration and data
directory discovery changed; see the [upstream migration
guide](https://artalk.js.org/en/guide/releases/v2.10.0.html) when invoking

View File

@@ -11,6 +11,14 @@ let
configFile = configFormat.generate "autobrr.toml" cfg.settings;
in
{
imports = [
(lib.mkRemovedOptionModule [
"services"
"autobrr"
"secretFile"
] "autobrr no longer uses a session secret since version 1.82.0.")
];
options = {
services.autobrr = {
enable = lib.mkEnableOption "Autobrr";
@@ -21,11 +29,6 @@ in
description = "Open ports in the firewall for the Autobrr web interface.";
};
secretFile = lib.mkOption {
type = lib.types.path;
description = "File containing the session secret for the Autobrr web interface.";
};
settings = lib.mkOption {
type = lib.types.submodule {
freeformType = configFormat.type;
@@ -67,17 +70,6 @@ in
};
config = lib.mkIf cfg.enable {
assertions = [
{
assertion = !(cfg.settings ? sessionSecret);
message = ''
Session secrets should not be passed via settings, as
these are stored in the world-readable nix store.
Use the secretFile option instead.'';
}
];
systemd = {
tmpfiles.settings = {
"10-autobrr" = {
@@ -101,8 +93,6 @@ in
serviceConfig = {
Type = "simple";
DynamicUser = true;
LoadCredential = "sessionSecret:${cfg.secretFile}";
Environment = [ "AUTOBRR__SESSION_SECRET_FILE=%d/sessionSecret" ];
StateDirectory = "autobrr";
ExecStart = "${lib.getExe cfg.package} --config %S/autobrr";
Restart = "on-failure";

View File

@@ -4,28 +4,17 @@
name = "autobrr";
meta.maintainers = with lib.maintainers; [ av-gal ];
nodes.machine =
{ pkgs, ... }:
let
# We create this secret in the Nix store (making it readable by everyone).
# DO NOT DO THIS OUTSIDE OF TESTS!!
testSecretFile = pkgs.writeText "session_secret" "not-secret";
in
{
nodes.machine = {
services.autobrr.enable = true;
# Use port other than default to test if settings options work.
specialisation.settingsPort.configuration = {
services.autobrr = {
enable = true;
secretFile = testSecretFile;
};
# Use port other than default to test if settings options work.
specialisation.settingsPort.configuration = {
services.autobrr = {
enable = true;
secretFile = testSecretFile;
settings.port = 7777;
};
settings.port = 7777;
};
};
};
testScript =
{ nodes, ... }: