From 57ade16b9d90199eb1bf7ce1b86cc1ffaebdebba Mon Sep 17 00:00:00 2001 From: Luke Granger-Brown Date: Sun, 5 Jul 2020 19:46:17 +0000 Subject: feat(whitby): add apereo-cas/tvl-sso Change-Id: I29f5e762852593f05b9936d5635aadcc7eba283e Reviewed-on: https://cl.tvl.fyi/c/depot/+/935 Tested-by: BuildkiteCI Reviewed-by: tazjin --- ops/nixos/tvl-sso/default.nix | 23 +++++++++++++++++++++++ ops/nixos/whitby/default.nix | 1 + 2 files changed, 24 insertions(+) create mode 100644 ops/nixos/tvl-sso/default.nix diff --git a/ops/nixos/tvl-sso/default.nix b/ops/nixos/tvl-sso/default.nix new file mode 100644 index 0000000000..4d030285ae --- /dev/null +++ b/ops/nixos/tvl-sso/default.nix @@ -0,0 +1,23 @@ +# Configures an Apereo CAS instance for TVL SSO +{ config, ... }: + +let + inherit (config.depot.third_party) apereo-cas; +in { + config = { + environment.systemPackages = [ apereo-cas ]; + systemd.services.apereo-cas = { + description = "Apereo CAS Single Sign On server"; + wantedBy = [ "multi-user.target" ]; + after = [ "network.target" ]; + serviceConfig = { + User = "apereo-cas"; + Group = "apereo-cas"; + ExecStart = "${apereo-cas}"; + Restart = "always"; + }; + }; + users.users.apereo-cas = {}; + users.groups.apereo-cas = {}; + }; +} diff --git a/ops/nixos/whitby/default.nix b/ops/nixos/whitby/default.nix index e80d5885e1..e909f4d1f6 100644 --- a/ops/nixos/whitby/default.nix +++ b/ops/nixos/whitby/default.nix @@ -18,6 +18,7 @@ in { "${depot.depotPath}/ops/nixos/depot.nix" "${depot.depotPath}/ops/nixos/tvl-slapd/default.nix" "${depot.depotPath}/ops/nixos/www/login.tvl.fyi.nix" + "${depot.depotPath}/ops/nixos/tvl-sso/default.nix" ]; hardware = { -- cgit 1.4.1