# SPDX-FileCopyrightText: 2024 Tom Hubrecht # # SPDX-License-Identifier: EUPL-1.2 { config, lib, dgn-keys, name, ... }: let inherit (lib) getExe' mkEnableOption mkOption remove ; inherit (lib.types) attrs attrsOf listOf str submodule ; cfg = config.dgn-backups; homes = { compute01 = "/data/slow/bupstash"; geo01 = "/data/bupstash"; geo02 = "/data/bupstash"; storage01 = "/data/slow/bupstash"; }; starts = { compute01 = "*-*-* *:38:00"; storage01 = "*-*-* *:21:00"; web01 = "*-*-* *:47:00"; web03 = "*-*-* *:13:00"; }; mkJobs = builtins.mapAttrs ( _: { to, settings }: { startAt = starts.${name}; key = config.age.secrets."bupstash-put_key".path; repositoryCommands = lib.extra.mapSingleFuse ( host: "ssh -i /etc/ssh/ssh_host_ed25519_key bupstash-repo@${host}.dgnum" ) to; } // settings ); in { options.dgn-backups = { enable = mkEnableOption "DGNum backup service."; postgresDatabases = mkOption { type = listOf str; default = [ ]; description = '' List of postgres databases to dump into bupstash. ''; }; jobs = mkOption { type = attrsOf (submodule { options = { to = mkOption { type = listOf str; default = remove name [ "compute01" "geo01" "geo02" "storage01" ]; description = "Hosts to send the backups to."; }; settings = mkOption { type = attrs; default = { }; description = "Base bupstash job config."; }; }; }); default = { }; description = "List of bupstash jobs."; }; }; config = { dgn-backups.jobs = lib.extra.mapFuse (db: { "${db}-db".settings = { user = "postgres"; command = [ (getExe' config.services.postgresql.package "pg_dump") db ]; }; }) cfg.postgresDatabases; services.bupstash = { repositories = { inherit (cfg) enable; home = homes.${name}; access = [ { repo = "default"; keys = dgn-keys.getKeys [ "compute01" "storage01" "vault01" "web01" "web02" "web03" ]; allowed = [ "put" ]; } ]; }; jobs = mkJobs cfg.jobs; }; programs.ssh.knownHosts = lib.extra.mapFuse (host: { "${host}.dgnum".publicKey = builtins.head dgn-keys._keys.${host}; }) [ "compute01" "geo01" "geo02" "storage01" ]; }; }