colin
d13bcc49ab
longer-term, i want hosts/by-name to define host-specific data that's accessible via the other hosts (things like pubkeys). also the secrets management needs some rethinking. there's really not much point in me specifiying where *exactly* a secret comes from at its use site. i should really be specifying secret store manifests; i.e. "servo.yaml contains secrets X Y and Z", and leaving the rest up to auto-computing.
28 lines
700 B
Nix
28 lines
700 B
Nix
{ config, lib, pkgs, ... }:
|
|
|
|
# using manual ddns now
|
|
lib.mkIf false
|
|
{
|
|
systemd.services.ddns-afraid = {
|
|
description = "update dynamic DNS entries for freedns.afraid.org";
|
|
serviceConfig = {
|
|
EnvironmentFile = config.sops.secrets.ddns_afraid.path;
|
|
# TODO: ProtectSystem = "strict";
|
|
# TODO: ProtectHome = "full";
|
|
# TODO: PrivateTmp = true;
|
|
};
|
|
script = let
|
|
curl = "${pkgs.curl}/bin/curl -4";
|
|
in ''
|
|
${curl} "https://freedns.afraid.org/dynamic/update.php?$AFRAID_KEY"
|
|
'';
|
|
};
|
|
systemd.timers.ddns-afraid = {
|
|
wantedBy = [ "multi-user.target" ];
|
|
timerConfig = {
|
|
OnStartupSec = "2min";
|
|
OnUnitActiveSec = "10min";
|
|
};
|
|
};
|
|
}
|