indexer/option.nix
Ricardo (XenGi) Band 448552016b
initial dump
2026-09-28 12:21:17 +02:00

57 lines
1.5 KiB
Nix

{
config,
lib,
pkgs,
options,
...
}:
let
cfg = config.services.federated-forge-discovery.indexer;
configFile = pkgs.writeText "config.ini" (pkgs.lib.generators.toINI { } cfg);
execCommand = "${cfg.package}/bin/ffd-indexer -c '${configFile}'";
in
{
options.services.federated-forge-discovery.indexer = {
enable = lib.mkEnableOption "Enables the Federated Forge Discovery Indexer systemd service.";
openFirewall = lib.mkOption {
};
package = lib.mkOption {
description = "Package to use.";
type = lib.types.package;
default = lib.literalExpression ''
pkgs.ffd-indexer
'';
};
port = lib.mkOption {
description = "Port to listen for search engines";
type = lib.types.port;
default = 47810;
};
};
config = lib.mkIf cfg.enable {
systemd.services."ffd-indexer" = {
description = "Federated Forge Discovery Indexer";
wants = [ "network-online.target" ];
after = [ "network-online.target" ];
serviceConfig = {
Restart = "always";
RestartSec = 30;
ExecStart = execCommand;
User = "ffd-indexer";
Group = "ffd-indexer";
AmbientCapabilities = lib.mkIf (cfg.port < 1000) [ "CAP_NET_BIND_SERVICE" ];
CapabilityBoundingSet = lib.mkIf (cfg.port < 1000) [ "CAP_NET_BIND_SERVICE" ];
NoNewPrivileges = true;
};
wantedBy = [ "multi-user.target" ];
};
};
#meta = {
# maintainers = with lib.maintainers; [ xengi ];
# doc = ./default.xml;
#};
}