nixos/cfssl: don't create user/group unless service is enabled

This commit is contained in:
Ben Wolsieffer 2018-08-21 16:21:11 -04:00
parent 8395f9aa85
commit c6191c8abf

View File

@ -146,7 +146,7 @@ in {
}; };
}; };
config = { config = mkIf cfg.enable {
users.extraGroups.cfssl = { users.extraGroups.cfssl = {
gid = config.ids.gids.cfssl; gid = config.ids.gids.cfssl;
}; };
@ -159,7 +159,7 @@ in {
uid = config.ids.uids.cfssl; uid = config.ids.uids.cfssl;
}; };
systemd.services.cfssl = mkIf cfg.enable { systemd.services.cfssl = {
description = "CFSSL CA API server"; description = "CFSSL CA API server";
wantedBy = [ "multi-user.target" ]; wantedBy = [ "multi-user.target" ];
after = [ "network.target" ]; after = [ "network.target" ];