services: add helper fn setAllowedIPAddresses

Also use 'allowLocalIPAddresses' instead of 'allowTor' in bitcoind-import-banlist
which doesn't use Tor.
This commit is contained in:
Erik Arvstedt 2021-03-22 13:19:45 +01:00
parent cdf27d9d0c
commit 020433cec6
No known key found for this signature in database
GPG key ID: 33312B944DD97846
11 changed files with 22 additions and 45 deletions

View file

@ -155,10 +155,7 @@ in {
RestartSec = "10s";
ReadWritePaths = cfg.nbxplorer.dataDir;
MemoryDenyWriteExecute = "false";
} // (if cfg.nbxplorer.enforceTor
then nbLib.allowTor
else nbLib.allowAnyIP
);
} // nbLib.allowedIPAddresses cfg.nbxplorer.enforceTor;
};
systemd.services.btcpayserver = let
@ -204,10 +201,7 @@ in {
RestartSec = "10s";
ReadWritePaths = cfg.btcpayserver.dataDir;
MemoryDenyWriteExecute = "false";
} // (if cfg.btcpayserver.enforceTor
then nbLib.allowTor
else nbLib.allowAnyIP
);
} // nbLib.allowedIPAddresses cfg.btcpayserver.enforceTor;
}; in self;
users.users.${cfg.nbxplorer.user} = {