From b63de52f9239a9b91db4ad222945c307158bbac2 Mon Sep 17 00:00:00 2001 From: Alejandro Soto Date: Sat, 27 Jul 2024 16:26:07 -0600 Subject: sys/env, sys/pki: generate full list of certs by path --- sys/pki/by-path.nix | 15 +++++++++++++++ sys/pki/default.nix | 1 + 2 files changed, 16 insertions(+) create mode 100644 sys/pki/by-path.nix (limited to 'sys/pki') diff --git a/sys/pki/by-path.nix b/sys/pki/by-path.nix new file mode 100644 index 0000000..baca142 --- /dev/null +++ b/sys/pki/by-path.nix @@ -0,0 +1,15 @@ +{ config, lib, ... }: +with lib; { + options.local.pki.byPath = mkOption { + type = with lib.types; attrsOf unspecified; + readOnly = true; + }; + + config.local.pki.byPath = + let + caWithLeaves = ca: + singleton { "${ca.path}" = ca; } + ++ map (leaf: { "${leaf.path}" = leaf; }) (attrValues ca.leaves); + in + mergeAttrsList (flatten (map caWithLeaves (attrValues config.local.pki.ca))); +} diff --git a/sys/pki/default.nix b/sys/pki/default.nix index cca5964..75f7e52 100644 --- a/sys/pki/default.nix +++ b/sys/pki/default.nix @@ -1,5 +1,6 @@ { imports = [ ./ca.nix + ./by-path.nix ]; } -- cgit v1.2.3