diff options
| author | tv <tv@krebsco.de> | 2020-08-04 22:22:43 +0200 |
|---|---|---|
| committer | tv <tv@krebsco.de> | 2020-08-05 11:16:45 +0200 |
| commit | e08c388b692c86a398f82dd399c7af9acaf76c99 (patch) | |
| tree | b4c010e63200190da8c232b0c6e07f84372c9016 /tv/3modules/charybdis | |
| parent | d200bf09cba4b614390eadc7bb95fbded0ceefbc (diff) | |
krebs.secret: restart units on secret change
Diffstat (limited to 'tv/3modules/charybdis')
| -rw-r--r-- | tv/3modules/charybdis/default.nix | 4 |
1 files changed, 3 insertions, 1 deletions
diff --git a/tv/3modules/charybdis/default.nix b/tv/3modules/charybdis/default.nix index 3809da4..a0638e1 100644 --- a/tv/3modules/charybdis/default.nix +++ b/tv/3modules/charybdis/default.nix @@ -17,6 +17,7 @@ in { ssl_dh_params = mkOption { type = types.secret-file; default = { + name = "charybdis-ssl_dh_params"; path = "${cfg.user.home}/dh.pem"; owner = cfg.user; source-path = toString <secrets> + "/charybdis.dh.pem"; @@ -25,6 +26,7 @@ in { ssl_private_key = mkOption { type = types.secret-file; default = { + name = "charybdis-ssl_private_key"; path = "${cfg.user.home}/ssl.key.pem"; owner = cfg.user; source-path = toString <secrets> + "/charybdis.key.pem"; @@ -56,7 +58,7 @@ in { config.krebs.secret.files.charybdis-ssl_private_key.service "network-online.target" ]; - requires = [ + partOf = [ config.krebs.secret.files.charybdis-ssl_dh_params.service config.krebs.secret.files.charybdis-ssl_private_key.service ]; |
