lightning-charge: add dedicated user

This commit is contained in:
nixbitcoin 2020-05-18 14:32:17 +00:00
parent e67a818297
commit 81a04a4ef1
No known key found for this signature in database
GPG Key ID: DD11F9AD5308B3BA

View File

@ -5,6 +5,8 @@ with lib;
let let
cfg = config.services.lightning-charge; cfg = config.services.lightning-charge;
inherit (config) nix-bitcoin-services; inherit (config) nix-bitcoin-services;
user = config.users.users.lightning-charge.name;
group = config.users.users.lightning-charge.group;
in { in {
options.services.lightning-charge = { options.services.lightning-charge = {
enable = mkOption { enable = mkOption {
@ -14,35 +16,51 @@ in {
If enabled, the lightning-charge service will be installed. If enabled, the lightning-charge service will be installed.
''; '';
}; };
clightning-datadir = mkOption { dataDir = mkOption {
type = types.str; type = types.path;
default = "/var/lib/clighting/"; default = "/var/lib/lightning-charge";
description = '' description = "The data directory for lightning-charge.";
Data directory of the clightning service
'';
}; };
}; };
config = mkIf cfg.enable { config = mkIf cfg.enable {
users.users.lightning-charge = {
description = "lightning-charge User";
group = "lightning-charge";
extraGroups = [ "clightning" ];
};
users.groups.lightning-charge = {};
systemd.tmpfiles.rules = [
"d '${cfg.dataDir}' 0700 ${user} ${group} - -"
];
environment.systemPackages = [ pkgs.nix-bitcoin.lightning-charge ]; environment.systemPackages = [ pkgs.nix-bitcoin.lightning-charge ];
systemd.services.lightning-charge = { systemd.services.lightning-charge = {
description = "Run lightning-charge"; description = "Run lightning-charge";
wantedBy = [ "multi-user.target" ]; wantedBy = [ "multi-user.target" ];
requires = [ "clightning.service" ]; requires = [ "clightning.service" ];
after = [ "clightning.service" ]; after = [ "clightning.service" ];
preStart = ''
# Move existing lightning-charge.db
# TODO: Remove eventually
if [[ -e ${config.services.clightning.dataDir}/lightning-charge.db ]]; then
mv ${config.services.clightning.dataDir}/lightning-charge.db ${cfg.dataDir}/lightning-charge.db
chown ${user}: ${cfg.dataDir}/lightning-charge.db
chmod 600 ${cfg.dataDir}/lightning-charge.db
fi
'';
serviceConfig = { serviceConfig = {
PermissionsStartOnly = "true";
EnvironmentFile = "${config.nix-bitcoin.secretsDir}/lightning-charge-env"; EnvironmentFile = "${config.nix-bitcoin.secretsDir}/lightning-charge-env";
ExecStart = "${pkgs.nix-bitcoin.lightning-charge}/bin/charged -l ${config.services.clightning.dataDir}/bitcoin -d ${config.services.clightning.dataDir}/lightning-charge.db"; ExecStart = "${pkgs.nix-bitcoin.lightning-charge}/bin/charged -l ${config.services.clightning.dataDir}/bitcoin -d ${cfg.dataDir}/lightning-charge.db";
# Unfortunately c-lightning doesn't allow setting the permissions of the rpc socket, User = user;
# so this must run as the clightning user
# https://github.com/ElementsProject/lightning/issues/1366
User = "clightning";
Restart = "on-failure"; Restart = "on-failure";
RestartSec = "10s"; RestartSec = "10s";
} // nix-bitcoin-services.defaultHardening } // nix-bitcoin-services.defaultHardening
// nix-bitcoin-services.nodejs // nix-bitcoin-services.nodejs
// nix-bitcoin-services.allowTor; // nix-bitcoin-services.allowTor;
}; };
nix-bitcoin.secrets.lightning-charge-env.user = "clightning"; nix-bitcoin.secrets.lightning-charge-env.user = user;
}; };
} }