nixos/pdns-recursor: add api.enable to start the built-in webserver

The `api.address`, `api.port` and `api.allowFrom` options render
`webservice.{address,port,allow_from}`, but the module never set
`webservice.webserver`, which defaults to false. The webserver therefore
never started and those options had no effect — both the REST API and the
Prometheus `/metrics` endpoint were unreachable no matter how `api.*` was
configured.

Add an `api.enable` option that sets `webservice.webserver`. It defaults to
false, so existing configurations are unchanged; setting `api.enable = true`
now makes the pre-existing `api.*` options functional.
This commit is contained in:
randomizedcoder dave.seddon.ca@gmail.com
2026-08-24 15:37:38 -07:00
parent 7bf2c026aa
commit ec361a648d
2 changed files with 18 additions and 0 deletions

View File

@@ -94,6 +94,13 @@ in
'';
};
api.enable = mkEnableOption ''
the built-in webserver. It serves the REST API (which additionally needs
an API key set via {option}`services.pdns-recursor.settings.webservice.api_key`)
and, at `/metrics`, statistics in Prometheus format. Without this the
`api.address`, `api.port` and `api.allowFrom` options have no effect, as
the webserver stays disabled'';
api.address = mkOption {
type = types.str;
default = "0.0.0.0";
@@ -222,6 +229,7 @@ in
};
webservice = mkDefaultAttrs {
webserver = cfg.api.enable;
address = cfg.api.address;
port = cfg.api.port;
allow_from = cfg.api.allowFrom;

View File

@@ -6,7 +6,9 @@
nodes.server = {
services.pdns-recursor.enable = true;
services.pdns-recursor.api.enable = true;
services.pdns-recursor.exportHosts = true;
services.pdns-recursor.settings.webservice.api_key = "supersecret";
networking.hosts."192.0.2.1" = [ "example.com" ];
};
@@ -17,5 +19,13 @@
with subtest("can resolve names"):
assert "192.0.2.1" in server.succeed("host example.com localhost")
with subtest("api is working"):
server.wait_for_open_port(8082)
server.succeed("curl -f -H 'X-API-Key: supersecret' http://localhost:8082/api/v1/servers")
server.fail("curl -f http://localhost:8082/api/v1/servers")
with subtest("metrics are exported"):
assert "pdns_recursor_" in server.succeed("curl -f -H 'X-API-Key: supersecret' http://localhost:8082/metrics")
'';
}