nixos/kubernetes: adds argument to mkCert defaulting to kubernetes group

This commit is contained in:
Pedro O. A. Regis 2024-06-21 21:26:08 -03:00
parent 1b1de8b52b
commit a5deaf9e93

View File

@ -61,13 +61,13 @@ let
etcdEndpoints = ["https://${cfg.masterAddress}:2379"];
mkCert = { name, CN, hosts ? [], fields ? {}, action ? "",
privateKeyOwner ? "kubernetes" }: rec {
privateKeyOwner ? "kubernetes", privateKeyGroup ? "kubernetes" }: rec {
inherit name caCert CN hosts fields action;
cert = secret name;
key = secret "${name}-key";
privateKeyOptions = {
owner = privateKeyOwner;
group = "nogroup";
group = privateKeyGroup;
mode = "0600";
path = key;
};