2021-12-05 19:40:24 +00:00
|
|
|
{ config, lib, options, pkgs, ... }:
|
2014-11-15 15:27:27 +00:00
|
|
|
|
|
|
|
with lib;
|
|
|
|
|
|
|
|
let
|
|
|
|
cfg = config.services.etcd;
|
2021-12-05 19:40:24 +00:00
|
|
|
opt = options.services.etcd;
|
2014-11-15 15:27:27 +00:00
|
|
|
|
|
|
|
in {
|
|
|
|
|
|
|
|
options.services.etcd = {
|
|
|
|
enable = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Whether to enable etcd.";
|
2014-11-15 15:27:27 +00:00
|
|
|
default = false;
|
2015-04-25 13:29:13 +01:00
|
|
|
type = types.bool;
|
2014-11-15 15:27:27 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
name = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Etcd unique node name.";
|
2014-11-15 15:27:27 +00:00
|
|
|
default = config.networking.hostName;
|
2021-11-26 00:16:05 +00:00
|
|
|
defaultText = literalExpression "config.networking.hostName";
|
2014-11-15 15:27:27 +00:00
|
|
|
type = types.str;
|
|
|
|
};
|
|
|
|
|
|
|
|
advertiseClientUrls = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Etcd list of this member's client URLs to advertise to the rest of the cluster.";
|
2014-11-15 15:27:27 +00:00
|
|
|
default = cfg.listenClientUrls;
|
2021-12-05 19:40:24 +00:00
|
|
|
defaultText = literalExpression "config.${opt.listenClientUrls}";
|
2014-11-15 15:27:27 +00:00
|
|
|
type = types.listOf types.str;
|
|
|
|
};
|
|
|
|
|
|
|
|
listenClientUrls = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Etcd list of URLs to listen on for client traffic.";
|
2016-08-25 13:41:47 +01:00
|
|
|
default = ["http://127.0.0.1:2379"];
|
2014-11-15 15:27:27 +00:00
|
|
|
type = types.listOf types.str;
|
|
|
|
};
|
|
|
|
|
|
|
|
listenPeerUrls = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Etcd list of URLs to listen on for peer traffic.";
|
2016-08-25 13:41:47 +01:00
|
|
|
default = ["http://127.0.0.1:2380"];
|
2014-11-15 15:27:27 +00:00
|
|
|
type = types.listOf types.str;
|
|
|
|
};
|
|
|
|
|
|
|
|
initialAdvertisePeerUrls = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Etcd list of this member's peer URLs to advertise to rest of the cluster.";
|
2014-11-15 15:27:27 +00:00
|
|
|
default = cfg.listenPeerUrls;
|
2021-12-05 19:40:24 +00:00
|
|
|
defaultText = literalExpression "config.${opt.listenPeerUrls}";
|
2014-11-15 15:27:27 +00:00
|
|
|
type = types.listOf types.str;
|
|
|
|
};
|
|
|
|
|
|
|
|
initialCluster = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Etcd initial cluster configuration for bootstrapping.";
|
2016-08-24 19:11:39 +01:00
|
|
|
default = ["${cfg.name}=http://127.0.0.1:2380"];
|
2021-12-05 20:28:49 +00:00
|
|
|
defaultText = literalExpression ''["''${config.${opt.name}}=http://127.0.0.1:2380"]'';
|
2014-11-15 15:27:27 +00:00
|
|
|
type = types.listOf types.str;
|
|
|
|
};
|
|
|
|
|
|
|
|
initialClusterState = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Etcd initial cluster configuration for bootstrapping.";
|
2014-11-15 15:27:27 +00:00
|
|
|
default = "new";
|
|
|
|
type = types.enum ["new" "existing"];
|
|
|
|
};
|
|
|
|
|
|
|
|
initialClusterToken = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Etcd initial cluster token for etcd cluster during bootstrap.";
|
2014-11-15 15:27:27 +00:00
|
|
|
default = "etcd-cluster";
|
|
|
|
type = types.str;
|
|
|
|
};
|
|
|
|
|
|
|
|
discovery = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Etcd discovery url";
|
2014-11-15 15:27:27 +00:00
|
|
|
default = "";
|
|
|
|
type = types.str;
|
|
|
|
};
|
|
|
|
|
2016-08-24 19:11:39 +01:00
|
|
|
clientCertAuth = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Whether to use certs for client authentication";
|
2016-08-24 19:11:39 +01:00
|
|
|
default = false;
|
|
|
|
type = types.bool;
|
|
|
|
};
|
|
|
|
|
|
|
|
trustedCaFile = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Certificate authority file to use for clients";
|
2016-08-24 19:11:39 +01:00
|
|
|
default = null;
|
|
|
|
type = types.nullOr types.path;
|
|
|
|
};
|
|
|
|
|
|
|
|
certFile = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Cert file to use for clients";
|
2016-08-24 19:11:39 +01:00
|
|
|
default = null;
|
|
|
|
type = types.nullOr types.path;
|
|
|
|
};
|
|
|
|
|
|
|
|
keyFile = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Key file to use for clients";
|
2016-08-24 19:11:39 +01:00
|
|
|
default = null;
|
|
|
|
type = types.nullOr types.path;
|
|
|
|
};
|
|
|
|
|
|
|
|
peerCertFile = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Cert file to use for peer to peer communication";
|
2016-08-24 19:11:39 +01:00
|
|
|
default = cfg.certFile;
|
2021-12-05 19:40:24 +00:00
|
|
|
defaultText = literalExpression "config.${opt.certFile}";
|
2016-08-24 19:11:39 +01:00
|
|
|
type = types.nullOr types.path;
|
|
|
|
};
|
|
|
|
|
|
|
|
peerKeyFile = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Key file to use for peer to peer communication";
|
2016-08-24 19:11:39 +01:00
|
|
|
default = cfg.keyFile;
|
2021-12-05 19:40:24 +00:00
|
|
|
defaultText = literalExpression "config.${opt.keyFile}";
|
2016-08-24 19:11:39 +01:00
|
|
|
type = types.nullOr types.path;
|
|
|
|
};
|
|
|
|
|
|
|
|
peerTrustedCaFile = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Certificate authority file to use for peer to peer communication";
|
2016-08-24 19:11:39 +01:00
|
|
|
default = cfg.trustedCaFile;
|
2021-12-05 19:40:24 +00:00
|
|
|
defaultText = literalExpression "config.${opt.trustedCaFile}";
|
2016-08-24 19:11:39 +01:00
|
|
|
type = types.nullOr types.path;
|
|
|
|
};
|
|
|
|
|
|
|
|
peerClientCertAuth = mkOption {
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Whether to check all incoming peer requests from the cluster for valid client certificates signed by the supplied CA";
|
2016-08-24 19:11:39 +01:00
|
|
|
default = false;
|
|
|
|
type = types.bool;
|
|
|
|
};
|
|
|
|
|
2014-11-15 15:27:27 +00:00
|
|
|
extraConf = mkOption {
|
2022-08-03 21:46:41 +01:00
|
|
|
description = lib.mdDoc ''
|
2014-11-15 15:27:27 +00:00
|
|
|
Etcd extra configuration. See
|
2022-08-03 21:46:41 +01:00
|
|
|
<https://github.com/coreos/etcd/blob/master/Documentation/op-guide/configuration.md#configuration-flags>
|
2014-11-15 15:27:27 +00:00
|
|
|
'';
|
|
|
|
type = types.attrsOf types.str;
|
|
|
|
default = {};
|
2021-10-03 17:06:03 +01:00
|
|
|
example = literalExpression ''
|
2014-11-15 15:27:27 +00:00
|
|
|
{
|
2016-01-17 18:34:55 +00:00
|
|
|
"CORS" = "*";
|
|
|
|
"NAME" = "default-name";
|
|
|
|
"MAX_RESULT_BUFFER" = "1024";
|
|
|
|
"MAX_CLUSTER_SIZE" = "9";
|
|
|
|
"MAX_RETRY_ATTEMPTS" = "3";
|
2014-11-15 15:27:27 +00:00
|
|
|
}
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
dataDir = mkOption {
|
|
|
|
type = types.path;
|
|
|
|
default = "/var/lib/etcd";
|
2022-07-28 22:19:15 +01:00
|
|
|
description = lib.mdDoc "Etcd data directory.";
|
2014-11-15 15:27:27 +00:00
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
config = mkIf cfg.enable {
|
2019-02-24 21:04:37 +00:00
|
|
|
systemd.tmpfiles.rules = [
|
|
|
|
"d '${cfg.dataDir}' 0700 etcd - - -"
|
|
|
|
];
|
|
|
|
|
2014-11-15 15:27:27 +00:00
|
|
|
systemd.services.etcd = {
|
2016-09-12 15:34:10 +01:00
|
|
|
description = "etcd key-value store";
|
2014-11-15 15:27:27 +00:00
|
|
|
wantedBy = [ "multi-user.target" ];
|
2016-09-12 15:34:10 +01:00
|
|
|
after = [ "network.target" ];
|
2014-11-15 15:27:27 +00:00
|
|
|
|
2016-08-24 19:11:39 +01:00
|
|
|
environment = (filterAttrs (n: v: v != null) {
|
2014-11-23 00:25:53 +00:00
|
|
|
ETCD_NAME = cfg.name;
|
2014-11-15 15:27:27 +00:00
|
|
|
ETCD_DISCOVERY = cfg.discovery;
|
|
|
|
ETCD_DATA_DIR = cfg.dataDir;
|
|
|
|
ETCD_ADVERTISE_CLIENT_URLS = concatStringsSep "," cfg.advertiseClientUrls;
|
|
|
|
ETCD_LISTEN_CLIENT_URLS = concatStringsSep "," cfg.listenClientUrls;
|
|
|
|
ETCD_LISTEN_PEER_URLS = concatStringsSep "," cfg.listenPeerUrls;
|
|
|
|
ETCD_INITIAL_ADVERTISE_PEER_URLS = concatStringsSep "," cfg.initialAdvertisePeerUrls;
|
2016-08-24 19:11:39 +01:00
|
|
|
ETCD_PEER_TRUSTED_CA_FILE = cfg.peerTrustedCaFile;
|
|
|
|
ETCD_PEER_CERT_FILE = cfg.peerCertFile;
|
|
|
|
ETCD_PEER_KEY_FILE = cfg.peerKeyFile;
|
|
|
|
ETCD_CLIENT_CERT_AUTH = toString cfg.peerClientCertAuth;
|
|
|
|
ETCD_TRUSTED_CA_FILE = cfg.trustedCaFile;
|
|
|
|
ETCD_CERT_FILE = cfg.certFile;
|
|
|
|
ETCD_KEY_FILE = cfg.keyFile;
|
|
|
|
}) // (optionalAttrs (cfg.discovery == ""){
|
2014-11-15 15:27:27 +00:00
|
|
|
ETCD_INITIAL_CLUSTER = concatStringsSep "," cfg.initialCluster;
|
|
|
|
ETCD_INITIAL_CLUSTER_STATE = cfg.initialClusterState;
|
|
|
|
ETCD_INITIAL_CLUSTER_TOKEN = cfg.initialClusterToken;
|
|
|
|
}) // (mapAttrs' (n: v: nameValuePair "ETCD_${n}" v) cfg.extraConf);
|
|
|
|
|
2016-09-12 15:34:10 +01:00
|
|
|
unitConfig = {
|
|
|
|
Documentation = "https://github.com/coreos/etcd";
|
|
|
|
};
|
|
|
|
|
2014-11-15 15:27:27 +00:00
|
|
|
serviceConfig = {
|
2016-03-27 03:01:00 +01:00
|
|
|
Type = "notify";
|
2020-04-28 02:50:34 +01:00
|
|
|
ExecStart = "${pkgs.etcd}/bin/etcd";
|
2014-11-15 15:27:27 +00:00
|
|
|
User = "etcd";
|
2016-09-12 15:34:10 +01:00
|
|
|
LimitNOFILE = 40000;
|
2014-11-15 15:27:27 +00:00
|
|
|
};
|
|
|
|
};
|
|
|
|
|
2021-06-25 23:45:12 +01:00
|
|
|
environment.systemPackages = [ pkgs.etcd ];
|
2014-11-15 15:27:27 +00:00
|
|
|
|
2019-09-14 18:51:29 +01:00
|
|
|
users.users.etcd = {
|
2021-08-08 13:00:00 +01:00
|
|
|
isSystemUser = true;
|
|
|
|
group = "etcd";
|
2014-11-15 15:27:27 +00:00
|
|
|
description = "Etcd daemon user";
|
|
|
|
home = cfg.dataDir;
|
|
|
|
};
|
2021-08-08 13:00:00 +01:00
|
|
|
users.groups.etcd = {};
|
2014-11-15 15:27:27 +00:00
|
|
|
};
|
|
|
|
}
|