From f8f5478bfb8b143a2cc5c234ee9e9a2e8a8104ef Mon Sep 17 00:00:00 2001 From: Elias Coppens Date: Sun, 9 Mar 2025 00:40:36 +0100 Subject: [PATCH] feat(machines/storage01): init openbao Signed-off-by: Elias Coppens --- machines/nixos/storage01/vault.nix | 37 ++++++++++++++++++++++++++++++ meta/dns.nix | 1 + 2 files changed, 38 insertions(+) create mode 100644 machines/nixos/storage01/vault.nix diff --git a/machines/nixos/storage01/vault.nix b/machines/nixos/storage01/vault.nix new file mode 100644 index 0000000..ef5fb09 --- /dev/null +++ b/machines/nixos/storage01/vault.nix @@ -0,0 +1,37 @@ +# SPDX-FileCopyrightText: 2025 Elias Coppens +# +# SPDX-License-Identifier: EUPL-1.2 + +let + host = "vault.dgnum.eu"; + port = 3100; + clusterPort = 3101; +in +{ + config = { + services.openbao = { + enable = true; + address = "127.0.0.1:${toString port}"; + storageBackend = "raft"; + + listenerExtraConfig = '' + cluster_address = "0.0.0.0:${toString clusterPort}" + ''; + + storageConfig = '' + path = "/var/lib/raft" + node_id = "raft_storage01" + ''; + + extraConfig = '' + cluster_addr = "http://${host}:${toString clusterPort}" + api_addr = "https://${host}" + ''; + }; + + dgn-web.simpleProxies.openbao = { + inherit host port; + }; + + }; +} diff --git a/meta/dns.nix b/meta/dns.nix index f30f942..40f3de6 100644 --- a/meta/dns.nix +++ b/meta/dns.nix @@ -110,6 +110,7 @@ let "victoria-metrics" # Victoria Metrics "videos" # Peertube "pub" + "vault" # OpenBAO # Garage S3 "*.cdn"