Compare commits
4 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
2bb0d725fc
|
|||
|
9a837d210d
|
|||
|
d3c9fabbc2
|
|||
|
950b163869
|
@@ -1,4 +1,22 @@
|
|||||||
{ ... }:
|
{ config, pkgs, lib, ... }:
|
||||||
|
let
|
||||||
|
cfg = config.services.irqbalance;
|
||||||
|
in
|
||||||
{
|
{
|
||||||
services.irqbalance.enable = true;
|
services.irqbalance.enable = true;
|
||||||
}
|
|
||||||
|
# irqbalance only has meaningful work to do on multi-socket machines, so
|
||||||
|
# skip starting it pointlessly everywhere else.
|
||||||
|
systemd.services.irqbalance.serviceConfig.ExecCondition = let
|
||||||
|
isMultiSocket = pkgs.writeShellApplication {
|
||||||
|
name = "irqbalance-is-multi-socket";
|
||||||
|
runtimeInputs = [ pkgs.coreutils ];
|
||||||
|
text = ''
|
||||||
|
sockets=$(cat /sys/devices/system/cpu/cpu*/topology/physical_package_id | sort -u | wc -l)
|
||||||
|
[ "$sockets" -gt 1 ]
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
in lib.mkIf cfg.enable [
|
||||||
|
(lib.getExe isMultiSocket)
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|||||||
@@ -14,6 +14,7 @@ in
|
|||||||
extensions = ps: with ps; [ pg_repack ];
|
extensions = ps: with ps; [ pg_repack ];
|
||||||
enableTCPIP = true;
|
enableTCPIP = true;
|
||||||
|
|
||||||
|
# NOTE: md5 accepts both md5 and scram-sha-256
|
||||||
authentication = ''
|
authentication = ''
|
||||||
host all all ${values.ipv4-space} md5
|
host all all ${values.ipv4-space} md5
|
||||||
host all all ${values.ipv6-space} md5
|
host all all ${values.ipv6-space} md5
|
||||||
@@ -76,6 +77,15 @@ in
|
|||||||
maintenance_io_concurrency = 100;
|
maintenance_io_concurrency = 100;
|
||||||
wal_recycle = true;
|
wal_recycle = true;
|
||||||
|
|
||||||
|
# -------------------------------- #
|
||||||
|
|
||||||
|
# Authentication
|
||||||
|
password_encryption = "scram-sha-256";
|
||||||
|
|
||||||
|
# Logging
|
||||||
|
log_connections = "authorization";
|
||||||
|
log_disconnections = true;
|
||||||
|
|
||||||
# SSL
|
# SSL
|
||||||
ssl = true;
|
ssl = true;
|
||||||
ssl_cert_file = "/run/credentials/postgresql.service/cert";
|
ssl_cert_file = "/run/credentials/postgresql.service/cert";
|
||||||
|
|||||||
@@ -138,6 +138,15 @@ in
|
|||||||
|
|
||||||
ExecStart =
|
ExecStart =
|
||||||
let
|
let
|
||||||
|
mkRespawningCommand = name: command: pkgs.writeShellScript "drumknotty-${name}-watchdog" ''
|
||||||
|
while true; do
|
||||||
|
${command}
|
||||||
|
echo
|
||||||
|
echo "${name} exited, restarting in 3s..." >&2
|
||||||
|
sleep 3
|
||||||
|
done
|
||||||
|
'';
|
||||||
|
|
||||||
screenrc = let
|
screenrc = let
|
||||||
convertToFile = lines: lib.pipe lines [
|
convertToFile = lines: lib.pipe lines [
|
||||||
lib.concatLists
|
lib.concatLists
|
||||||
@@ -157,8 +166,7 @@ in
|
|||||||
config = "/etc/dibbler/dibbler.toml";
|
config = "/etc/dibbler/dibbler.toml";
|
||||||
};
|
};
|
||||||
in lib.optionals cfg.dibbler.enable [
|
in lib.optionals cfg.dibbler.enable [
|
||||||
"screen -t dibbler ${lib.getExe cfg.dibbler.package} ${dibblerArgs} loop"
|
"screen -t dibbler ${mkRespawningCommand "dibbler" "${lib.getExe cfg.dibbler.package} ${dibblerArgs} loop"}"
|
||||||
|
|
||||||
])
|
])
|
||||||
|
|
||||||
(let
|
(let
|
||||||
@@ -166,7 +174,7 @@ in
|
|||||||
config = "/etc/worblehat/config.toml";
|
config = "/etc/worblehat/config.toml";
|
||||||
};
|
};
|
||||||
in lib.optionals cfg.worblehat.enable [
|
in lib.optionals cfg.worblehat.enable [
|
||||||
"screen -t worblehat ${lib.getExe cfg.worblehat.package} ${worblehatArgs} cli"
|
"screen -t worblehat ${mkRespawningCommand "worblehat" "${lib.getExe cfg.worblehat.package} ${worblehatArgs} cli"}"
|
||||||
])
|
])
|
||||||
|
|
||||||
[ "select 0" ]
|
[ "select 0" ]
|
||||||
|
|||||||
Reference in New Issue
Block a user