diff options
| author | Akshay Nair <phenax5@gmail.com> | 2024-10-30 18:24:26 +0530 |
|---|---|---|
| committer | Akshay Nair <phenax5@gmail.com> | 2024-10-30 18:24:26 +0530 |
| commit | 3aa67e03ad7affb057bfe2ab3cbecbd16dfa1ad4 (patch) | |
| tree | 3c242af745fc5632b666675e5bde9f0e25545243 /modules | |
| parent | 8719ec65106731191a99238eaf841d003d574a2a (diff) | |
| download | nixos-config-3aa67e03ad7affb057bfe2ab3cbecbd16dfa1ad4.tar.gz nixos-config-3aa67e03ad7affb057bfe2ab3cbecbd16dfa1ad4.zip | |
Add secfix agent to work config
Diffstat (limited to 'modules')
| -rw-r--r-- | modules/secfix/.gitignore | 1 | ||||
| -rw-r--r-- | modules/secfix/default.nix | 58 | ||||
| -rw-r--r-- | modules/work.nix | 13 |
3 files changed, 62 insertions, 10 deletions
diff --git a/modules/secfix/.gitignore b/modules/secfix/.gitignore new file mode 100644 index 0000000..c00df13 --- /dev/null +++ b/modules/secfix/.gitignore @@ -0,0 +1 @@ +*.deb diff --git a/modules/secfix/default.nix b/modules/secfix/default.nix new file mode 100644 index 0000000..0fef70a --- /dev/null +++ b/modules/secfix/default.nix @@ -0,0 +1,58 @@ +{ config , lib , pkgs , ... }: +let + secfix-agent = pkgs.stdenv.mkDerivation { + pname = "secfix-agent"; + version = "1.0.0"; + + src = ./secfix.linux-systemd-deb.deb; + + nativeBuildInputs = with pkgs; [ autoPatchelfHook zlib dpkg ]; + + sourceRoot = "."; + unpackCmd = ''dpkg-deb -x "$src" .''; + + dontBuild = true; + installPhase = '' + mkdir -p $out/; + cp -r ./* $out/; + sed -i \ + -e "s|/var/|$out/var/|" \ + -e "s|/etc/|$out/etc/|" \ + -e "s|/usr/|$out/usr/|" \ + $out/etc/secfix/launcher.flags; + ''; + }; +in + +{ + options.services.secfix = { + enable = lib.mkOption { + type = lib.types.bool; + default = false; + description = ''Secfix agent''; + }; + }; + + config = let + cfg = config.services.secfix; + in + lib.mkIf cfg.enable { + environment.systemPackages = [ secfix-agent ]; + + systemd.services.secfix = { + unitConfig = { + Description = "The Kolide Launcher"; + After = "network.service syslog.service"; + }; + + serviceConfig = { + ExecStart = + "${secfix-agent}/usr/local/secfix/bin/launcher -config ${secfix-agent}/etc/secfix/launcher.flags --root_directory /var/run/secfix/"; + Restart = "on-failure"; + RestartSec = 3; + }; + + wantedBy = ["multi-user.target"]; + }; + }; +} diff --git a/modules/work.nix b/modules/work.nix index a900b65..4a3468c 100644 --- a/modules/work.nix +++ b/modules/work.nix @@ -1,15 +1,8 @@ -{ config, pkgs, ... }: -let - vantaCreds = import ./vanta-daemon/credentials.nix; -in +{ ... }: { imports = [ - ./vanta-daemon/module.nix + ./secfix/default.nix ]; - services.vanta = { - enable = false; - agentKey = vantaCreds.VANTA_KEY; - email = vantaCreds.VANTA_OWNER_EMAIL; - }; + services.secfix.enable = true; } |
