Uses standard NixOS user config merging. Work in progress: The slave config does not actually start the slave agent. This just configures a jenkins user if required. Bare minimum to enable a nice jenkins SSH slave.wip/yesman
parent
4b6e67f6c4
commit
40de28afca
@ -0,0 +1,67 @@ |
||||
{ config, pkgs, ... }: |
||||
with pkgs.lib; |
||||
let |
||||
cfg = config.services.jenkinsSlave; |
||||
masterCfg = config.services.jenkins; |
||||
in { |
||||
options = { |
||||
services.jenkinsSlave = { |
||||
# todo: |
||||
# * assure the profile of the jenkins user has a JRE and any specified packages. This would |
||||
# enable ssh slaves. |
||||
# * Optionally configure the node as a jenkins ad-hoc slave. This would imply configuration |
||||
# properties for the master node. |
||||
enable = mkOption { |
||||
type = types.bool; |
||||
default = false; |
||||
description = '' |
||||
If true the system will be configured to work as a jenkins slave. |
||||
If the system is also configured to work as a jenkins master then this has no effect. |
||||
In progress: Currently only assures the jenkins user is configured. |
||||
''; |
||||
}; |
||||
|
||||
user = mkOption { |
||||
default = "jenkins"; |
||||
type = with types; string; |
||||
description = '' |
||||
User the jenkins slave agent should execute under. |
||||
''; |
||||
}; |
||||
|
||||
group = mkOption { |
||||
default = "jenkins"; |
||||
type = with types; string; |
||||
description = '' |
||||
User the jenkins slave agent should execute under. |
||||
''; |
||||
}; |
||||
|
||||
home = mkOption { |
||||
default = "/var/lib/jenkins"; |
||||
type = with types; string; |
||||
description = '' |
||||
The path to use as JENKINS_HOME. If the default user "jenkins" is configured then |
||||
this is the home of the "jenkins" user. |
||||
''; |
||||
}; |
||||
}; |
||||
}; |
||||
|
||||
config = mkIf (cfg.enable && !masterCfg.enable) { |
||||
users.extraGroups = optional (cfg.group == "jenkins") { |
||||
name = "jenkins"; |
||||
gid = config.ids.gids.jenkins; |
||||
}; |
||||
|
||||
users.extraUsers = optional (cfg.user == "jenkins") { |
||||
name = "jenkins"; |
||||
description = "jenkins user"; |
||||
createHome = true; |
||||
home = cfg.home; |
||||
group = cfg.group; |
||||
useDefaultShell = true; |
||||
uid = config.ids.uids.jenkins; |
||||
}; |
||||
}; |
||||
} |
@ -1,61 +0,0 @@ |
||||
{ config, pkgs, ... }: |
||||
with pkgs.lib; |
||||
let |
||||
cfg = config.users.jenkins; |
||||
in { |
||||
options = { |
||||
users.jenkins = { |
||||
enable = mkOption { |
||||
type = types.bool; |
||||
default = false; |
||||
description = '' |
||||
Whether to enable the jenkins user. By default enabling a jenkins service enables the |
||||
jenkins user. The "user" config property of the service can be used to select a different |
||||
user. |
||||
''; |
||||
}; |
||||
|
||||
extraGroups = mkOption { |
||||
default = []; |
||||
type = with types; listOf string; |
||||
description = '' |
||||
Extra groups of the "jenkins" user. |
||||
''; |
||||
}; |
||||
|
||||
group = mkOption { |
||||
default = "jenkins"; |
||||
description = '' |
||||
Default group of "jenkins" user. |
||||
''; |
||||
}; |
||||
|
||||
home = mkOption { |
||||
default = "/var/lib/jenkins"; |
||||
type = types.string; |
||||
description = '' |
||||
Home of the "jenkins" user and JENKINS_HOME. |
||||
''; |
||||
}; |
||||
}; |
||||
}; |
||||
|
||||
config = mkIf cfg.enable { |
||||
users.extraGroups = optional (cfg.group == "jenkins") { |
||||
name = "jenkins"; |
||||
gid = config.ids.gids.jenkins; |
||||
}; |
||||
|
||||
users.extraUsers = { |
||||
jenkins = { |
||||
description = "jenkins user"; |
||||
createHome = true; |
||||
home = cfg.home; |
||||
group = cfg.group; |
||||
extraGroups = cfg.extraGroups; |
||||
useDefaultShell = true; |
||||
uid = config.ids.uids.jenkins; |
||||
}; |
||||
}; |
||||
}; |
||||
} |
Loading…
Reference in new issue