nixpkgs/nixos/modules/services/monitoring/vnstat.nix

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

61 lines
1.4 KiB
Nix
Raw Normal View History

2017-01-24 13:45:01 +00:00
{ config, lib, pkgs, ... }:
with lib;
let
cfg = config.services.vnstat;
in {
options.services.vnstat = {
enable = mkEnableOption "update of network usage statistics via vnstatd";
2017-01-24 13:45:01 +00:00
};
config = mkIf cfg.enable {
environment.systemPackages = [ pkgs.vnstat ];
users = {
groups.vnstatd = {};
users.vnstatd = {
isSystemUser = true;
group = "vnstatd";
description = "vnstat daemon user";
};
2017-01-24 13:45:01 +00:00
};
systemd.services.vnstat = {
description = "vnStat network traffic monitor";
path = [ pkgs.coreutils ];
after = [ "network.target" ];
wantedBy = [ "multi-user.target" ];
documentation = [
"man:vnstatd(1)"
"man:vnstat(1)"
"man:vnstat.conf(5)"
];
2017-01-24 13:45:01 +00:00
serviceConfig = {
ExecStart = "${pkgs.vnstat}/bin/vnstatd -n";
ExecReload = "${pkgs.procps}/bin/kill -HUP $MAINPID";
# Hardening (from upstream example service)
ProtectSystem = "strict";
StateDirectory = "vnstat";
2017-01-24 13:45:01 +00:00
PrivateDevices = true;
ProtectKernelTunables = true;
ProtectControlGroups = true;
ProtectHome = true;
ProtectKernelModules = true;
2017-01-24 13:45:01 +00:00
PrivateTmp = true;
MemoryDenyWriteExecute = true;
RestrictRealtime = true;
RestrictNamespaces = true;
2017-01-24 13:45:01 +00:00
User = "vnstatd";
Group = "vnstatd";
2017-01-24 13:45:01 +00:00
};
};
};
meta.maintainers = [ maintainers.evils ];
2017-01-24 13:45:01 +00:00
}