2015-05-16 23:22:35 +02:00
|
|
|
{ config, lib, pkgs, ... }:
|
|
|
|
|
|
|
|
let
|
2021-03-18 14:17:43 +01:00
|
|
|
inherit (lib) mkEnableOption mkIf mkOption optionalString types;
|
2016-12-09 10:48:54 +01:00
|
|
|
|
2022-02-21 09:21:12 +01:00
|
|
|
cfg = config.services.bird2;
|
2022-02-27 09:19:22 +01:00
|
|
|
caps = [ "CAP_NET_ADMIN" "CAP_NET_BIND_SERVICE" "CAP_NET_RAW" ];
|
2022-02-21 09:21:12 +01:00
|
|
|
in
|
|
|
|
{
|
|
|
|
###### interface
|
|
|
|
options = {
|
|
|
|
services.bird2 = {
|
|
|
|
enable = mkEnableOption "BIRD Internet Routing Daemon";
|
|
|
|
config = mkOption {
|
|
|
|
type = types.lines;
|
|
|
|
description = ''
|
|
|
|
BIRD Internet Routing Daemon configuration file.
|
|
|
|
<link xlink:href='http://bird.network.cz/'/>
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
checkConfig = mkOption {
|
|
|
|
type = types.bool;
|
|
|
|
default = true;
|
|
|
|
description = ''
|
|
|
|
Whether the config should be checked at build time.
|
|
|
|
When the config can't be checked during build time, for example when it includes
|
|
|
|
other files, either disable this option or use <code>preCheckConfig</code> to create
|
|
|
|
the included files before checking.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
preCheckConfig = mkOption {
|
|
|
|
type = types.lines;
|
|
|
|
default = "";
|
|
|
|
example = ''
|
|
|
|
echo "cost 100;" > include.conf
|
|
|
|
'';
|
|
|
|
description = ''
|
|
|
|
Commands to execute before the config file check. The file to be checked will be
|
|
|
|
available as <code>bird2.conf</code> in the current directory.
|
2022-01-25 14:58:26 +01:00
|
|
|
|
2022-02-21 09:21:12 +01:00
|
|
|
Files created with this option will not be available at service runtime, only during
|
|
|
|
build time checking.
|
|
|
|
'';
|
2015-05-16 23:22:35 +02:00
|
|
|
};
|
2022-02-21 09:21:12 +01:00
|
|
|
};
|
|
|
|
};
|
2015-05-16 23:22:35 +02:00
|
|
|
|
2019-05-31 01:19:35 +02:00
|
|
|
|
2022-02-21 09:21:12 +01:00
|
|
|
imports = [
|
|
|
|
(lib.mkRemovedOptionModule [ "services" "bird" ] "Use services.bird2 instead")
|
|
|
|
(lib.mkRemovedOptionModule [ "services" "bird6" ] "Use services.bird2 instead")
|
|
|
|
];
|
2019-05-31 01:19:35 +02:00
|
|
|
|
2022-02-21 09:21:12 +01:00
|
|
|
###### implementation
|
|
|
|
config = mkIf cfg.enable {
|
|
|
|
environment.systemPackages = [ pkgs.bird ];
|
2015-05-16 23:22:35 +02:00
|
|
|
|
2022-02-21 09:21:12 +01:00
|
|
|
environment.etc."bird/bird2.conf".source = pkgs.writeTextFile {
|
|
|
|
name = "bird2";
|
|
|
|
text = cfg.config;
|
|
|
|
checkPhase = optionalString cfg.checkConfig ''
|
|
|
|
ln -s $out bird2.conf
|
|
|
|
${cfg.preCheckConfig}
|
|
|
|
${pkgs.bird}/bin/bird -d -p -c bird2.conf
|
|
|
|
'';
|
|
|
|
};
|
2018-02-11 23:28:00 +01:00
|
|
|
|
2022-02-21 09:21:12 +01:00
|
|
|
systemd.services.bird2 = {
|
|
|
|
description = "BIRD Internet Routing Daemon";
|
|
|
|
wantedBy = [ "multi-user.target" ];
|
2022-04-03 18:57:04 +02:00
|
|
|
reloadTriggers = [ config.environment.etc."bird/bird2.conf".source ];
|
2022-02-21 09:21:12 +01:00
|
|
|
serviceConfig = {
|
|
|
|
Type = "forking";
|
|
|
|
Restart = "on-failure";
|
2022-02-27 09:19:22 +01:00
|
|
|
User = "bird2";
|
|
|
|
Group = "bird2";
|
|
|
|
ExecStart = "${pkgs.bird}/bin/bird -c /etc/bird/bird2.conf";
|
|
|
|
ExecReload = "${pkgs.bird}/bin/birdc configure";
|
2022-02-21 09:21:12 +01:00
|
|
|
ExecStop = "${pkgs.bird}/bin/birdc down";
|
2022-02-23 07:00:33 +01:00
|
|
|
RuntimeDirectory = "bird";
|
2022-02-27 09:19:22 +01:00
|
|
|
CapabilityBoundingSet = caps;
|
|
|
|
AmbientCapabilities = caps;
|
2022-02-21 09:21:12 +01:00
|
|
|
ProtectSystem = "full";
|
|
|
|
ProtectHome = "yes";
|
2022-02-23 07:00:33 +01:00
|
|
|
ProtectKernelTunables = true;
|
|
|
|
ProtectControlGroups = true;
|
|
|
|
PrivateTmp = true;
|
|
|
|
PrivateDevices = true;
|
2022-02-21 09:21:12 +01:00
|
|
|
SystemCallFilter = "~@cpu-emulation @debug @keyring @module @mount @obsolete @raw-io";
|
|
|
|
MemoryDenyWriteExecute = "yes";
|
|
|
|
};
|
|
|
|
};
|
|
|
|
users = {
|
|
|
|
users.bird2 = {
|
|
|
|
description = "BIRD Internet Routing Daemon user";
|
|
|
|
group = "bird2";
|
|
|
|
isSystemUser = true;
|
|
|
|
};
|
|
|
|
groups.bird2 = { };
|
|
|
|
};
|
|
|
|
};
|
2015-05-16 23:22:35 +02:00
|
|
|
}
|