2024-10-14 08:49:12 +02:00
|
|
|
(define-module (glicid services caddy)
|
2024-10-14 08:38:35 +02:00
|
|
|
#:use-module (guix gexp)
|
|
|
|
#:use-module (gnu packages bash)
|
|
|
|
#:use-module (gnu services)
|
|
|
|
#:use-module (gnu services shepherd)
|
|
|
|
#:use-module (guix records)
|
|
|
|
#:use-module (gnu system shadow)
|
2024-10-14 15:25:39 +02:00
|
|
|
#:use-module (gnu system privilege)
|
|
|
|
#:use-module (ice-9 match)
|
2024-10-14 15:36:02 +02:00
|
|
|
#:use-module (glicid packages caddy)
|
|
|
|
#:export (%caddy-accounts
|
|
|
|
caddy-configuration
|
|
|
|
caddy-configuration?
|
|
|
|
caddy-shepherd-service
|
|
|
|
caddy-service-type
|
2024-10-14 15:52:49 +02:00
|
|
|
))
|
2024-10-14 08:38:35 +02:00
|
|
|
|
2024-10-14 15:25:39 +02:00
|
|
|
|
|
|
|
(define %caddy-accounts
|
|
|
|
(list
|
|
|
|
(user-group (name "caddy")(system? #t))
|
|
|
|
(user-account
|
|
|
|
(name "caddy")
|
|
|
|
(group "caddy")
|
|
|
|
(system? #t)
|
|
|
|
(home-directory "/var/lib/caddy")
|
|
|
|
(shell (file-append bash "/sbin/nologin")))))
|
|
|
|
|
2024-10-14 08:38:35 +02:00
|
|
|
(define-record-type* <caddy-configuration> caddy-configuration
|
|
|
|
make-caddy-configuration
|
|
|
|
caddy-configuration?
|
|
|
|
(caddy caddy-configuration-caddy (default caddy-dirty))
|
|
|
|
(config-file caddy-config-file (default "/etc/caddy/Caddyfile"))
|
2024-10-14 15:52:49 +02:00
|
|
|
(log-file caddy-log-file (default "/var/log/caddy.log"))
|
2024-10-14 08:38:35 +02:00
|
|
|
)
|
|
|
|
|
2024-10-14 15:52:49 +02:00
|
|
|
(define caddy-service
|
|
|
|
(match-lambda
|
|
|
|
(($ <caddy-configuration> caddy config-file log-file)
|
|
|
|
(list (shepherd-service (provision '(caddy))
|
|
|
|
(documentation "Run caddy.")
|
|
|
|
(requirement '(user-processes))
|
|
|
|
(respawn? #t)
|
|
|
|
(start #~(make-forkexec-constructor (list #$(file-append caddy "/sbin/caddy")
|
|
|
|
"-c"
|
|
|
|
#$config-file)
|
|
|
|
#:log-file #$log-file
|
|
|
|
#:environment-variables (list
|
|
|
|
(string-append "PATH="
|
|
|
|
"/run/current-system/profile/bin"
|
|
|
|
":/run/current-system/profile/sbin"
|
|
|
|
":/run/current-system/profile/libexec"))))
|
|
|
|
(stop #~(make-kill-destructor)))))))
|
|
|
|
|
2024-10-14 08:38:35 +02:00
|
|
|
|
|
|
|
(define caddy-service-type
|
|
|
|
(service-type
|
|
|
|
(name 'caddy)
|
|
|
|
(default-value (caddy-configuration))
|
|
|
|
(extensions (list
|
2024-10-14 15:52:49 +02:00
|
|
|
(service-extension shepherd-root-service-type (compose list caddy-service))
|
2024-10-14 15:25:39 +02:00
|
|
|
(service-extension privileged-program-service-type (const (list
|
|
|
|
(privileged-program
|
|
|
|
(program (file-append caddy-dirty "/sbin/caddy"))
|
|
|
|
(capabilities "cap_net_bind_service=+ep")
|
|
|
|
(user "caddy")
|
|
|
|
(group "caddy")
|
|
|
|
))))
|
|
|
|
))
|
2024-10-14 08:38:35 +02:00
|
|
|
(description "run caddy web server service")))
|