~ruther/guix-local

078f5bfae7ee174177791defcfd350117a503a6d — Marius Bakke 4 years ago 440ad14
services: zabbix-server: Do not write database password to the store.

* gnu/services/monitoring.scm (zabbix-front-end-config): Read the secret file
from zabbix.conf.php at runtime instead of embedding the contents.
1 files changed, 5 insertions(+), 6 deletions(-)

M gnu/services/monitoring.scm
M gnu/services/monitoring.scm => gnu/services/monitoring.scm +5 -6
@@ 577,7 577,7 @@ $DB['SERVER']   = '" db-host "';
$DB['PORT']     = '" (number->string db-port) "';
$DB['DATABASE'] = '" db-name "';
$DB['USER']     = '" db-user "';
$DB['PASSWORD'] = '" (let ((file (location-file %location))
$DB['PASSWORD'] = " (let ((file (location-file %location))
                           (line (location-line %location))
                           (column (location-column %location)))
                       (if (string-null? db-password)


@@ 592,15 592,14 @@ $DB['PASSWORD'] = '" (let ((file (location-file %location))
                                       (condition
                                        (&error-location
                                         (location %location)))))
                               (string-trim-both
                                (with-input-from-file db-secret-file
                                  read-string)))
                               (string-append "trim(file_get_contents('"
                                              db-secret-file "'));\n"))
                           (begin
                             (display-hint (format #f (G_ "~a:~a:~a: ~a:
Consider using @code{db-secret-file} instead of @code{db-password} for better
security.") file line column 'zabbix-front-end-configuration))
                             db-password))) "';

                             db-password)))
"
// Schema name. Used for IBM DB2 and PostgreSQL.
$DB['SCHEMA'] = '';