Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

nixos/acme: extra lego flags #89779

Merged
merged 2 commits into from Aug 22, 2020
Merged

nixos/acme: extra lego flags #89779

merged 2 commits into from Aug 22, 2020

Conversation

jktr
Copy link
Contributor

@jktr jktr commented Jun 8, 2020

Motivation for this change

When using the DNS resolvers of my VPS provider with the cloudflare DNS provider, the DNS-01 challenge always fails because lego does not see the TXT record propagate in time. --dns.disable-cp (security.acme.certs.<name>.dnsPropagationCheck) doesn't seem to help here. Explicitly adding the authorative DNS server via --dns.resolvers "jade.ns.cloudflare.com" to the lego command line would fix this problem, but the acme module does not provide an option to add global options.

#80900 already added extraLegoRenewFlags to allow specifying extra options for the renew subcommand. This PR extends this with a extraLegoRunFlags option for the run subcommand and an extraLegoFlags option for global lego options. These serve to both solve the above problem and expose several lego cli options that are currently inaccessible but may be of interest to advanced users.

Things done
  • Tested using sandboxing (nix.useSandbox on NixOS, or option sandbox in nix.conf on non-NixOS linux)
  • Built on platform(s)
    • NixOS
    • macOS
    • other Linux distributions
  • Tested via one or more NixOS test(s) if existing and applicable for the change (look inside nixos/tests)
  • Tested compilation of all pkgs that depend on this change using nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
  • Tested execution of all binary files (usually in ./result/bin/)
  • Determined the impact on package closure size (by running nix path-info -S before and after)
  • Ensured that relevant documentation is up to date
  • Fits CONTRIBUTING.md.

@Lassulus
Copy link
Member

LGTM

@Lassulus Lassulus merged commit 8a14182 into NixOS:master Aug 22, 2020
@jktr jktr deleted the acme-extra-flags branch August 22, 2020 13:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants