started optionModules.mtls

This commit is contained in:
John Lancaster
2026-07-05 23:58:16 -05:00
parent 118e1d8f4f
commit 4f9e67208b
2 changed files with 57 additions and 43 deletions
+49
View File
@@ -0,0 +1,49 @@
{ lib, ... }: {
options.optionModules.mtls = lib.mkOption {
type = lib.types.deferredModule;
description = "Shared mTLS certificate option definitions, imported by the mTLS wrapper modules.";
};
config.optionModules.mtls = { config, lib, pkgs, ... }: {
key = "mtls-config";
_file = "modules/features/mtls/config.nix";
options = {
certDir = lib.mkOption {
description = "String path to the directory where the certs will be stored";
type = lib.types.str;
default = "/etc/mtls";
};
keyFile = lib.mkOption {
description = "String path for the private key";
type = lib.types.str;
default = "${config.certDir}/key.pem";
};
certFile = lib.mkOption {
description = "String path for the public cert";
type = lib.types.str;
default = "${config.certDir}/cert.pem";
};
bundleFile = lib.mkOption {
description = "String path for the mTLS key bundle";
type = lib.types.str;
default = "${config.certDir}/mtls.pem";
};
subject = lib.mkOption {
description = "Subject for the cert";
type = lib.types.str;
};
provisioner = lib.mkOption {
type = lib.types.nullOr lib.types.str;
};
provisionerPasswordFile = lib.mkOption {
type = lib.types.nullOr lib.types.str;
};
overwrite = lib.mkEnableOption "Overwrite existing cert file?";
SANs = lib.mkOption {
description = "A list of Subject Alternative Names";
type = lib.types.listOf lib.types.str;
default = [ ];
};
};
};
}
+8 -43
View File
@@ -1,49 +1,12 @@
{ self, inputs, lib, ... }:
{ self, inputs, lib, config, ... }:
let
mtlsConfigModule = config.optionModules.mtls;
mkSANArgs = sans: builtins.concatLists (map (name: [ "--san" name ]) sans);
mkOpts = config: let cfg = config.mtls; in {
certDir = lib.mkOption {
description = "String path to the directory where the certs will be stored";
type = lib.types.str;
default = "/etc/mtls";
};
keyFile = lib.mkOption {
description = "String path for the private key";
type = lib.types.str;
default = "${config.certDir}/key.pem";
};
certFile = lib.mkOption {
description = "String path for the public cert";
type = lib.types.str;
default = "${config.certDir}/cert.pem";
};
bundleFile = lib.mkOption {
description = "String path for the mTLS key bundle";
type = lib.types.str;
default = "${config.certDir}/mtls.pem";
};
subject = lib.mkOption {
description = "Subject for the cert";
type = lib.types.str;
};
provisioner = lib.mkOption {
type = lib.types.nullOr lib.types.str;
};
provisionerPasswordFile = lib.mkOption {
type = lib.types.nullOr lib.types.str;
};
overwrite = lib.mkEnableOption "Overwrite existing cert file?";
SANs = lib.mkOption {
description = "A list of Subject Alternative Names";
type = lib.types.listOf lib.types.str;
default = [ ];
};
};
in
{
flake.wrappers.mtls = {
generate = inputs.wrappers.lib.wrapModule ({ config, lib, wlib, ... }: {
options = (mkOpts config);
imports = [ mtlsConfigModule ];
config = {
binName = "mtls-generate";
package = config.pkgs.step-cli;
@@ -69,8 +32,10 @@ in
renew = inputs.wrappers.lib.wrapModule ({ config, lib, wlib, ... }: {
# https://github.com/Lassulus/wrappers#generating-systemd-services
imports = [ wlib.modules.systemd ];
options = (mkOpts config);
imports = [
wlib.modules.systemd mtlsConfigModule
mtlsConfigModule
];
config = {
binName = "mtls-renew";
package = config.pkgs.step-cli;
@@ -101,7 +66,7 @@ in
});
check = inputs.wrappers.lib.wrapModule ({ config, lib, wlib, ... }: {
options = (mkOpts config);
imports = [ mtlsConfigModule ];
config = {
binName = "mtls-check";
# This pattern is necessary to wrap packages like openssl that provide more than one binary