From c85bdc7e3db257ad05a1143c433fd114c7f75306 Mon Sep 17 00:00:00 2001 From: Roy Dumblauskas Date: Wed, 19 Nov 2025 02:02:16 -0600 Subject: [PATCH] override auth options --- homelab-services/postgresql-db/flake.nix | 22 +++++++++++++++++++--- 1 file changed, 19 insertions(+), 3 deletions(-) diff --git a/homelab-services/postgresql-db/flake.nix b/homelab-services/postgresql-db/flake.nix index cb13b7b..8be7935 100644 --- a/homelab-services/postgresql-db/flake.nix +++ b/homelab-services/postgresql-db/flake.nix @@ -61,17 +61,33 @@ settings.port = opts.port; identMap = '' postgres roy postgres + dev roy devuser + prod roy produser ''; # allow remote connections to dev DBs - authentication = '' - ${lib.concatStringsSep "" (map (db: "host ${db}_dev all samenet md5\n") opts.databases) } + authentication = pkgs.lib.mkOverride '' + # TYPE DATABASE USER ADDRESS METHOD + + # "local" is for Unix domain socket connections only + local all all trust + # IPv4 local connections: + host all all 127.0.0.1/32 trust + # IPv6 local connections: + host all all ::1/128 trust + # Allow replication connections from localhost, by a user with the + # replication privilege. + local replication all trust + host replication all 127.0.0.1/32 trust + host replication all ::1/128 trust + # Connections via LAN + ${lib.concatStringsSep " " (map (db: "host ${db}_dev all samenet md5\n") opts.databases) } ''; }; systemd.services.bootstrap-psql = { - description = "Bootstrap psql dbs and users"; + description = "Bootstrap psql databases and users"; after = [ "postgresql.service" ]; requires = [ "postgresql.service" ]; wantedBy = [ "multi-user.target" ];