2015-11-17 17:30:10 +00:00
|
|
|
{ config, lib, pkgs, ... }:
|
|
|
|
|
|
|
|
with lib; let
|
|
|
|
|
|
|
|
cfg = config.services.postgrey;
|
|
|
|
|
|
|
|
in {
|
|
|
|
|
|
|
|
options = {
|
2016-09-14 00:18:18 +00:00
|
|
|
services.postgrey = with types; {
|
2015-11-17 17:30:10 +00:00
|
|
|
enable = mkOption {
|
2016-09-14 00:18:18 +00:00
|
|
|
type = bool;
|
2015-11-17 17:30:10 +00:00
|
|
|
default = false;
|
|
|
|
description = "Whether to run the Postgrey daemon";
|
|
|
|
};
|
|
|
|
inetAddr = mkOption {
|
2016-09-14 00:18:18 +00:00
|
|
|
type = nullOr string;
|
2015-11-17 17:30:10 +00:00
|
|
|
default = null;
|
|
|
|
example = "127.0.0.1";
|
|
|
|
description = "The inet address to bind to. If none given, bind to /var/run/postgrey.sock";
|
|
|
|
};
|
|
|
|
inetPort = mkOption {
|
2016-09-14 00:18:18 +00:00
|
|
|
type = int;
|
2015-11-17 17:30:10 +00:00
|
|
|
default = 10030;
|
|
|
|
description = "The tcp port to bind to";
|
|
|
|
};
|
|
|
|
greylistText = mkOption {
|
2016-09-14 00:18:18 +00:00
|
|
|
type = string;
|
2015-11-17 17:30:10 +00:00
|
|
|
default = "Greylisted for %%s seconds";
|
|
|
|
description = "Response status text for greylisted messages";
|
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
config = mkIf cfg.enable {
|
|
|
|
|
|
|
|
environment.systemPackages = [ pkgs.postgrey ];
|
|
|
|
|
|
|
|
users = {
|
|
|
|
extraUsers = {
|
|
|
|
postgrey = {
|
|
|
|
description = "Postgrey Daemon";
|
|
|
|
uid = config.ids.uids.postgrey;
|
|
|
|
group = "postgrey";
|
|
|
|
};
|
|
|
|
};
|
|
|
|
extraGroups = {
|
|
|
|
postgrey = {
|
|
|
|
gid = config.ids.gids.postgrey;
|
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
systemd.services.postgrey = let
|
|
|
|
bind-flag = if isNull cfg.inetAddr then
|
|
|
|
"--unix=/var/run/postgrey.sock"
|
|
|
|
else
|
|
|
|
"--inet=${cfg.inetAddr}:${cfg.inetPort}";
|
|
|
|
in {
|
|
|
|
description = "Postfix Greylisting Service";
|
|
|
|
wantedBy = [ "multi-user.target" ];
|
|
|
|
before = [ "postfix.service" ];
|
|
|
|
preStart = ''
|
|
|
|
mkdir -p /var/postgrey
|
|
|
|
chown postgrey:postgrey /var/postgrey
|
|
|
|
chmod 0770 /var/postgrey
|
|
|
|
'';
|
|
|
|
serviceConfig = {
|
|
|
|
Type = "simple";
|
|
|
|
ExecStart = ''${pkgs.postgrey}/bin/postgrey ${bind-flag} --pidfile=/var/run/postgrey.pid --group=postgrey --user=postgrey --dbdir=/var/postgrey --greylist-text="${cfg.greylistText}"'';
|
|
|
|
Restart = "always";
|
|
|
|
RestartSec = 5;
|
|
|
|
TimeoutSec = 10;
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
};
|
|
|
|
|
|
|
|
}
|