about summary refs log tree commit diff
path: root/nixos
diff options
context:
space:
mode:
authorFlorian Klink <flokli@flokli.de>2019-11-23 16:28:26 +0100
committerFlorian Klink <flokli@flokli.de>2020-04-03 00:34:18 +0200
commitf25a301a0a98a96b54b1a221c2dd410a3b32c4f1 (patch)
tree5911dae6d2465eedcc1d30452b61997f67ea54f0 /nixos
parent98906dfdefe322cb573c7c54b4744ef781bdd2cd (diff)
downloadnixlib-f25a301a0a98a96b54b1a221c2dd410a3b32c4f1.tar
nixlib-f25a301a0a98a96b54b1a221c2dd410a3b32c4f1.tar.gz
nixlib-f25a301a0a98a96b54b1a221c2dd410a3b32c4f1.tar.bz2
nixlib-f25a301a0a98a96b54b1a221c2dd410a3b32c4f1.tar.lz
nixlib-f25a301a0a98a96b54b1a221c2dd410a3b32c4f1.tar.xz
nixlib-f25a301a0a98a96b54b1a221c2dd410a3b32c4f1.tar.zst
nixlib-f25a301a0a98a96b54b1a221c2dd410a3b32c4f1.zip
nixos/chrony: move to StateDirectory and tmpfiles.d
Diffstat (limited to 'nixos')
-rw-r--r--nixos/modules/services/networking/ntp/chrony.nix14
1 files changed, 6 insertions, 8 deletions
diff --git a/nixos/modules/services/networking/ntp/chrony.nix b/nixos/modules/services/networking/ntp/chrony.nix
index da9d960cc142..f1062edaa05b 100644
--- a/nixos/modules/services/networking/ntp/chrony.nix
+++ b/nixos/modules/services/networking/ntp/chrony.nix
@@ -92,6 +92,11 @@ in
 
     systemd.services.systemd-timedated.environment = { SYSTEMD_TIMEDATED_NTP_SERVICES = "chronyd.service"; };
 
+    systemd.tmpfiles.rules = [
+      "d ${stateDir} 0755 chrony chrony - -"
+      "f ${keyFile} 0640 chrony chrony -"
+    ];
+
     systemd.services.chronyd =
       { description = "chrony NTP daemon";
 
@@ -103,13 +108,6 @@ in
 
         path = [ pkgs.chrony ];
 
-        preStart = ''
-          mkdir -m 0755 -p ${stateDir}
-          touch ${keyFile}
-          chmod 0640 ${keyFile}
-          chown chrony:chrony ${stateDir} ${keyFile}
-        '';
-
         unitConfig.ConditionCapability = "CAP_SYS_TIME";
         serviceConfig =
           { Type = "simple";
@@ -118,7 +116,7 @@ in
             ProtectHome = "yes";
             ProtectSystem = "full";
             PrivateTmp = "yes";
-
+            StateDirectory = "chrony";
           };
 
       };