nixos/acme: Fix allowKeysForGroup not applying immediately #72056
+6
−0
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Motivation for this change
Previously setting
allowKeysForGroup = true; group = "foo"
would notapply the group permission change of the certificates until the service
gets restarted. This commit fixes this by making systemd restart the
service every time it changes.
Note that applying this commit to a system with an already running acme
systemd service doesn't fix this immediately and you still need to wait
for the next refresh (or call
systemctl restart acme-<domain>
). Onceeverybody's service has restarted once this should be a problem of the
past.
Fixes #48845, which I think has been broken since the introduction of the option in #12283
Ping @tmplt @arianvp @abbradar
Things done
enableACME
on a new domain withoutallowKeysForGroup
. Then rebuilding with the option and checking that the directory has the correct group permissions.