From 64eb5ef748c91b21a6f808bbfbdaee48aaf2589e Mon Sep 17 00:00:00 2001 From: silentpager-rocks <259809885+silentpager-rocks@users.noreply.github.com> Date: Tue, 29 Sep 2026 15:17:14 +0200 Subject: [PATCH] nixos/autobrr: remove secretFile autobrr no longer uses a session secret since version 1.82.0. --- .../manual/release-notes/rl-2611.section.md | 2 ++ nixos/modules/services/misc/autobrr.nix | 26 ++++++------------- nixos/tests/autobrr.nix | 25 +++++------------- 3 files changed, 17 insertions(+), 36 deletions(-) diff --git a/nixos/doc/manual/release-notes/rl-2611.section.md b/nixos/doc/manual/release-notes/rl-2611.section.md index 26a2ab83da50..177f8bba68cc 100644 --- a/nixos/doc/manual/release-notes/rl-2611.section.md +++ b/nixos/doc/manual/release-notes/rl-2611.section.md @@ -148,6 +148,8 @@ +- `services.autobrr.secretFile` has been removed, as autobrr no longer uses a session secret since version 1.82.0. Remove the option from your configuration. + - Artalk has been updated to 2.10.0. Its default configuration and data directory discovery changed; see the [upstream migration guide](https://artalk.js.org/en/guide/releases/v2.10.0.html) when invoking diff --git a/nixos/modules/services/misc/autobrr.nix b/nixos/modules/services/misc/autobrr.nix index 47ada630cd82..250808da210f 100644 --- a/nixos/modules/services/misc/autobrr.nix +++ b/nixos/modules/services/misc/autobrr.nix @@ -11,6 +11,14 @@ let configFile = configFormat.generate "autobrr.toml" cfg.settings; in { + imports = [ + (lib.mkRemovedOptionModule [ + "services" + "autobrr" + "secretFile" + ] "autobrr no longer uses a session secret since version 1.82.0.") + ]; + options = { services.autobrr = { enable = lib.mkEnableOption "Autobrr"; @@ -21,11 +29,6 @@ in description = "Open ports in the firewall for the Autobrr web interface."; }; - secretFile = lib.mkOption { - type = lib.types.path; - description = "File containing the session secret for the Autobrr web interface."; - }; - settings = lib.mkOption { type = lib.types.submodule { freeformType = configFormat.type; @@ -67,17 +70,6 @@ in }; config = lib.mkIf cfg.enable { - assertions = [ - { - assertion = !(cfg.settings ? sessionSecret); - message = '' - Session secrets should not be passed via settings, as - these are stored in the world-readable nix store. - - Use the secretFile option instead.''; - } - ]; - systemd = { tmpfiles.settings = { "10-autobrr" = { @@ -101,8 +93,6 @@ in serviceConfig = { Type = "simple"; DynamicUser = true; - LoadCredential = "sessionSecret:${cfg.secretFile}"; - Environment = [ "AUTOBRR__SESSION_SECRET_FILE=%d/sessionSecret" ]; StateDirectory = "autobrr"; ExecStart = "${lib.getExe cfg.package} --config %S/autobrr"; Restart = "on-failure"; diff --git a/nixos/tests/autobrr.nix b/nixos/tests/autobrr.nix index 96f62b892dbd..326be69da816 100644 --- a/nixos/tests/autobrr.nix +++ b/nixos/tests/autobrr.nix @@ -4,28 +4,17 @@ name = "autobrr"; meta.maintainers = with lib.maintainers; [ av-gal ]; - nodes.machine = - { pkgs, ... }: - let - # We create this secret in the Nix store (making it readable by everyone). - # DO NOT DO THIS OUTSIDE OF TESTS!! - testSecretFile = pkgs.writeText "session_secret" "not-secret"; - in - { + nodes.machine = { + services.autobrr.enable = true; + + # Use port other than default to test if settings options work. + specialisation.settingsPort.configuration = { services.autobrr = { enable = true; - secretFile = testSecretFile; - }; - - # Use port other than default to test if settings options work. - specialisation.settingsPort.configuration = { - services.autobrr = { - enable = true; - secretFile = testSecretFile; - settings.port = 7777; - }; + settings.port = 7777; }; }; + }; testScript = { nodes, ... }: