buildkite-agent: demotivate potential secrecy regressions through documentation

# Conflicts:
#	nixos/modules/services/continuous-integration/buildkite-agent.nix
This commit is contained in:
Kosyrev Serge
2017-11-24 21:01:36 +03:00
committed by Domen Kožar
parent 815dc9dd02
commit d6069f88bd

View File

@@ -86,10 +86,13 @@ in
wantedBy = [ "multi-user.target" ];
after = [ "network.target" ];
environment.HOME = "/var/lib/buildkite-agent";
## NB: maximum care is taken so that secrets (ssh keys and the CI token)
## don't end up in the Nix store.
preStart = ''
${pkgs.coreutils}/bin/mkdir -m 0700 -p /var/lib/buildkite-agent/.ssh
${copyOrEcho cfg.openssh.privateKey "/var/lib/buildkite-agent/.ssh/id_rsa" 600}
${copyOrEcho cfg.openssh.publicKey "/var/lib/buildkite-agent/.ssh/id_rsa.pub" 600}
${copyOrEcho (toString cfg.openssh.privateKey) "/var/lib/buildkite-agent/.ssh/id_rsa" 600}
${copyOrEcho (toString cfg.openssh.publicKey) "/var/lib/buildkite-agent/.ssh/id_rsa.pub" 600}
cat > "/var/lib/buildkite-agent/buildkite-agent.cfg" <<EOF
token="${catOrLiteral cfg.token}"