mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-10-02 13:00:23 +00:00
[Backport release-25.05] nixos/step-ca: Allow not configuring the intermediatePasswordFile (#459700)
This commit is contained in:
@@ -60,10 +60,13 @@ in
|
||||
'';
|
||||
};
|
||||
intermediatePasswordFile = lib.mkOption {
|
||||
type = lib.types.pathWith {
|
||||
inStore = false;
|
||||
absolute = true;
|
||||
};
|
||||
type = lib.types.nullOr (
|
||||
lib.types.pathWith {
|
||||
inStore = false;
|
||||
absolute = true;
|
||||
}
|
||||
);
|
||||
default = null;
|
||||
example = "/run/keys/smallstep-password";
|
||||
description = ''
|
||||
Path to the file containing the password for the intermediate
|
||||
@@ -109,11 +112,18 @@ in
|
||||
ReadWritePaths = ""; # override upstream
|
||||
|
||||
# LocalCredential handles file permission problems arising from the use of DynamicUser.
|
||||
LoadCredential = "intermediate_password:${cfg.intermediatePasswordFile}";
|
||||
LoadCredential = lib.mkIf (
|
||||
cfg.intermediatePasswordFile != null
|
||||
) "intermediate_password:${cfg.intermediatePasswordFile}";
|
||||
|
||||
ExecStart = [
|
||||
"" # override upstream
|
||||
"${cfg.package}/bin/step-ca /etc/smallstep/ca.json --password-file \${CREDENTIALS_DIRECTORY}/intermediate_password"
|
||||
(
|
||||
"${cfg.package}/bin/step-ca /etc/smallstep/ca.json"
|
||||
+ lib.optionalString (
|
||||
cfg.intermediatePasswordFile != null
|
||||
) " --password-file \${CREDENTIALS_DIRECTORY}/intermediate_password"
|
||||
)
|
||||
];
|
||||
|
||||
# ProtectProc = "invisible"; # not supported by upstream yet
|
||||
|
||||
Reference in New Issue
Block a user