From 52f7e42262adb0760a79a3e60d891b131d2c813f Mon Sep 17 00:00:00 2001 From: Seth Flynn Date: Sat, 8 Feb 2025 20:48:49 -0500 Subject: nixos/acme: actually act as a mixin --- modules/nixos/mixins/acme.nix | 49 +++++-------------------------------------- 1 file changed, 5 insertions(+), 44 deletions(-) (limited to 'modules/nixos/mixins') diff --git a/modules/nixos/mixins/acme.nix b/modules/nixos/mixins/acme.nix index 3b49caf..7c39eed 100644 --- a/modules/nixos/mixins/acme.nix +++ b/modules/nixos/mixins/acme.nix @@ -1,52 +1,13 @@ { - config, lib, - secretsDir, ... }: -let - cfg = config.mixins.acme; -in -{ - options.mixins.acme = { - enable = lib.mkEnableOption "ACME mixin"; - - manageSecrets = lib.mkEnableOption "automatic management of secrets" // { - default = config.traits.secrets.enable; - defaultText = lib.literalExpression "config.traits.secrets.enable"; - }; - useDns = lib.mkEnableOption "the use of Cloudflare to obtain certs" // { - default = true; +{ + security.acme = { + acceptTerms = lib.mkDefault true; + defaults = { + email = lib.mkDefault "getchoo@tuta.io"; }; }; - - config = lib.mkIf cfg.enable ( - lib.mkMerge [ - { - security.acme = { - acceptTerms = true; - defaults = { - email = "getchoo@tuta.io"; - }; - }; - } - - (lib.mkIf cfg.useDns { - security.acme.defaults = { - dnsProvider = "cloudflare"; - }; - }) - - (lib.mkIf cfg.manageSecrets { - age.secrets = { - cloudflareApiKey.file = secretsDir + "/cloudflareApiKey.age"; - }; - - security.acme.defaults = { - credentialsFile = config.age.secrets.cloudflareApiKey.path; - }; - }) - ] - ); } -- cgit v1.2.3