forked from mirrors/nixpkgs
29027fd1e1
Using pkgs.lib on the spine of module evaluation is problematic because the pkgs argument depends on the result of module evaluation. To prevent an infinite recursion, pkgs and some of the modules are evaluated twice, which is inefficient. Using ‘with lib’ prevents this problem.
96 lines
1.8 KiB
Nix
96 lines
1.8 KiB
Nix
{ config, lib, pkgs, ... }:
|
|
|
|
with lib;
|
|
|
|
let
|
|
|
|
inherit (pkgs) privoxy;
|
|
|
|
stateDir = "/var/spool/privoxy";
|
|
|
|
privoxyUser = "privoxy";
|
|
|
|
privoxyFlags = "--no-daemon --user ${privoxyUser} ${privoxyCfg}";
|
|
|
|
privoxyCfg = pkgs.writeText "privoxy.conf" ''
|
|
listen-address ${config.services.privoxy.listenAddress}
|
|
logdir ${config.services.privoxy.logDir}
|
|
confdir ${privoxy}/etc
|
|
filterfile default.filter
|
|
|
|
${config.services.privoxy.extraConfig}
|
|
'';
|
|
|
|
in
|
|
|
|
{
|
|
|
|
###### interface
|
|
|
|
options = {
|
|
|
|
services.privoxy = {
|
|
|
|
enable = mkOption {
|
|
default = false;
|
|
description = ''
|
|
Whether to run the machine as a HTTP proxy server.
|
|
'';
|
|
};
|
|
|
|
listenAddress = mkOption {
|
|
default = "127.0.0.1:8118";
|
|
description = ''
|
|
Address the proxy server is listening to.
|
|
'';
|
|
};
|
|
|
|
logDir = mkOption {
|
|
default = "/var/log/privoxy" ;
|
|
description = ''
|
|
Location for privoxy log files.
|
|
'';
|
|
};
|
|
|
|
extraConfig = mkOption {
|
|
default = "" ;
|
|
description = ''
|
|
Extra configuration. Contents will be added verbatim to the configuration file.
|
|
'';
|
|
};
|
|
};
|
|
|
|
};
|
|
|
|
|
|
###### implementation
|
|
|
|
config = mkIf config.services.privoxy.enable {
|
|
|
|
environment.systemPackages = [ privoxy ];
|
|
|
|
users.extraUsers = singleton
|
|
{ name = privoxyUser;
|
|
uid = config.ids.uids.privoxy;
|
|
description = "Privoxy daemon user";
|
|
home = stateDir;
|
|
};
|
|
|
|
jobs.privoxy =
|
|
{ name = "privoxy";
|
|
|
|
startOn = "startup";
|
|
|
|
preStart =
|
|
''
|
|
mkdir -m 0755 -p ${stateDir}
|
|
chown ${privoxyUser} ${stateDir}
|
|
'';
|
|
|
|
exec = "${privoxy}/sbin/privoxy ${privoxyFlags}";
|
|
};
|
|
|
|
};
|
|
|
|
}
|