There is nothing in this commit except for the changes made by nix-shell -p nixfmt-rfc-style --run "nixfmt ." If this has mucked up your open branches then sorry about that. You can probably nixfmt them to match before merging
30 lines
624 B
Nix
30 lines
624 B
Nix
{
|
|
liminix,
|
|
certifix-client,
|
|
svc,
|
|
lib,
|
|
writeText,
|
|
serviceFns,
|
|
}:
|
|
{
|
|
caCertificate,
|
|
secret,
|
|
subject,
|
|
serviceUrl,
|
|
}:
|
|
let
|
|
inherit (builtins) filter isString split;
|
|
inherit (liminix.services) oneshot;
|
|
name = "certifix-${lib.strings.sanitizeDerivationName subject}";
|
|
caCertFile = writeText "ca.crt" caCertificate;
|
|
secretFile = writeText "secret" secret;
|
|
in
|
|
oneshot {
|
|
inherit name;
|
|
up = ''
|
|
(in_outputs ${name}
|
|
SSL_CA_CERT_FILE=${caCertFile} ${certifix-client}/bin/certifix-client --subject ${subject} --secret ${secretFile} --key-out key --certificate-out cert ${serviceUrl}
|
|
)
|
|
'';
|
|
}
|