1 ;;; GNU Guix --- Functional package management for GNU
2 ;;; Copyright © 2016 Jan Nieuwenhuizen <janneke@gnu.org>
3 ;;; Copyright © 2016, 2017 Ludovic Courtès <ludo@gnu.org>
5 ;;; This file is part of GNU Guix.
7 ;;; GNU Guix is free software; you can redistribute it and/or modify it
8 ;;; under the terms of the GNU General Public License as published by
9 ;;; the Free Software Foundation; either version 3 of the License, or (at
10 ;;; your option) any later version.
12 ;;; GNU Guix is distributed in the hope that it will be useful, but
13 ;;; WITHOUT ANY WARRANTY; without even the implied warranty of
14 ;;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 ;;; GNU General Public License for more details.
17 ;;; You should have received a copy of thye GNU General Public License
18 ;;; along with GNU Guix. If not, see <http://www.gnu.org/licenses/>.
20 (define-module (gnu services admin)
21 #:use-module (gnu packages admin)
22 #:use-module (gnu packages base)
23 #:use-module (gnu packages logging)
24 #:use-module (gnu services)
25 #:use-module (gnu services mcron)
26 #:use-module (gnu services shepherd)
27 #:use-module (gnu services web)
28 #:use-module (gnu system shadow)
29 #:use-module (guix gexp)
30 #:use-module (guix store)
31 #:use-module (guix packages)
32 #:use-module (guix records)
33 #:use-module (srfi srfi-1)
34 #:use-module (ice-9 vlist)
35 #:use-module (ice-9 match)
36 #:export (%default-rotations
41 log-rotation-frequency
44 log-rotation-post-rotate
47 rottlog-configuration?
51 <tailon-configuration-file>
52 tailon-configuration-file
53 tailon-configuration-file?
54 tailon-configuration-file-files
55 tailon-configuration-file-bind
56 tailon-configuration-file-relative-root
57 tailon-configuration-file-allow-transfers?
58 tailon-configuration-file-follow-names?
59 tailon-configuration-file-tail-lines
60 tailon-configuration-file-allowed-commands
61 tailon-configuration-file-debug?
62 tailon-configuration-file-http-auth
63 tailon-configuration-file-users
65 <tailon-configuration>
68 tailon-configuration-config-file
69 tailon-configuration-package
75 ;;; This module implements configuration of rottlog by writing
76 ;;; /etc/rottlog/{rc,hourly|daily|weekly}. Example usage
79 ;;; (service rottlog-service-type)
83 (define-record-type* <log-rotation> log-rotation make-log-rotation
85 (files log-rotation-files) ;list of strings
86 (frequency log-rotation-frequency ;symbol
88 (post-rotate log-rotation-post-rotate ;#f | gexp
90 (options log-rotation-options ;list of strings
93 (define %rotated-files
94 ;; Syslog files subject to rotation.
95 '("/var/log/messages" "/var/log/secure" "/var/log/maillog"))
97 (define %default-rotations
98 (list (log-rotation ;syslog files
99 (files %rotated-files)
101 ;; Restart syslogd after rotation.
102 (options '("sharedscripts"))
103 (post-rotate #~(let ((pid (call-with-input-file "/var/run/syslog.pid"
107 (files '("/var/log/shepherd.log" "/var/log/guix-daemon.log")))))
109 (define (log-rotation->config rotation)
110 "Return a string-valued gexp representing the rottlog configuration snippet
113 (let ((post (log-rotation-post-rotate rotation)))
115 (program-file "rottlog-post-rotate.scm" post))))
117 #~(let ((post #$post-rotate))
118 (string-append (string-join '#$(log-rotation-files rotation) ",")
120 #$(string-join (log-rotation-options rotation)
123 (string-append "\n postrotate\n " post
128 (define (log-rotations->/etc-entries rotations)
129 "Return the list of /etc entries for ROTATIONS, a list of <log-rotation>."
130 (define (frequency-file frequency rotations)
131 (computed-file (string-append "rottlog." (symbol->string frequency))
132 #~(call-with-output-file #$output
134 (for-each (lambda (str)
136 (list #$@(map log-rotation->config
139 (let* ((frequencies (delete-duplicates
140 (map log-rotation-frequency rotations)))
141 (table (fold (lambda (rotation table)
142 (vhash-consq (log-rotation-frequency rotation)
146 (map (lambda (frequency)
147 `(,(symbol->string frequency)
148 ,(frequency-file frequency
149 (vhash-foldq* cons '() frequency table))))
152 (define (default-jobs rottlog)
153 (list #~(job '(next-hour '(0)) ;midnight
155 (system* #$(file-append rottlog "/sbin/rottlog"))))
156 #~(job '(next-hour '(12)) ;noon
158 (system* #$(file-append rottlog "/sbin/rottlog"))))))
160 (define-record-type* <rottlog-configuration>
161 rottlog-configuration make-rottlog-configuration
162 rottlog-configuration?
163 (rottlog rottlog-rottlog ;package
165 (rc-file rottlog-rc-file ;file-like
166 (default (file-append rottlog "/etc/rc")))
167 (rotations rottlog-rotations ;list of <log-rotation>
168 (default %default-rotations))
169 (jobs rottlog-jobs ;list of <mcron-job>
172 (define (rottlog-etc config)
174 ,(file-union "rottlog"
175 (cons `("rc" ,(rottlog-rc-file config))
176 (log-rotations->/etc-entries
177 (rottlog-rotations config)))))))
179 (define (rottlog-jobs-or-default config)
180 (or (rottlog-jobs config)
181 (default-jobs (rottlog-rottlog config))))
183 (define rottlog-service-type
186 (extensions (list (service-extension etc-service-type rottlog-etc)
187 (service-extension mcron-service-type
188 rottlog-jobs-or-default)
190 ;; Add Rottlog to the global profile so users can access
191 ;; the documentation.
192 (service-extension profile-service-type
193 (compose list rottlog-rottlog))))
194 (compose concatenate)
195 (extend (lambda (config rotations)
196 (rottlog-configuration
198 (rotations (append (rottlog-rotations config)
200 (default-value (rottlog-configuration))))
207 (define-record-type* <tailon-configuration-file>
208 tailon-configuration-file make-tailon-configuration-file
209 tailon-configuration-file?
210 (files tailon-configuration-file-files
211 (default '("/var/log")))
212 (bind tailon-configuration-file-bind
213 (default "localhost:8080"))
214 (relative-root tailon-configuration-file-relative-root
216 (allow-transfers? tailon-configuration-file-allow-transfers?
218 (follow-names? tailon-configuration-file-follow-names?
220 (tail-lines tailon-configuration-file-tail-lines
222 (allowed-commands tailon-configuration-file-allowed-commands
223 (default '("tail" "grep" "awk")))
224 (debug? tailon-configuration-file-debug?
226 (wrap-lines tailon-configuration-file-wrap-lines
228 (http-auth tailon-configuration-file-http-auth
230 (users tailon-configuration-file-users
233 (define (tailon-configuration-files-string files)
243 (simple-format #f "'~A'" x))
246 (cons (simple-format #f "'~A':" (car x))
248 (lambda (x) (simple-format #f " - '~A'" x))
255 (define-gexp-compiler (tailon-configuration-file-compiler
256 (file <tailon-configuration-file>) system target)
258 (($ <tailon-configuration-file> files bind relative-root
259 allow-transfers? follow-names?
260 tail-lines allowed-commands debug?
261 wrap-lines http-auth users)
268 ((key . value) (string-append key ": " value "\n")))
270 `(("files" . ,(tailon-configuration-files-string files))
272 ("relative-root" . ,relative-root)
273 ("allow-transfers" . ,(if allow-transfers? "true" "false"))
274 ("follow-names" . ,(if follow-names? "true" "false"))
275 ("tail-lines" . ,(number->string tail-lines))
276 ("commands" . ,(string-append "["
277 (string-join allowed-commands ", ")
279 ("debug" . ,(if debug? "true" #f))
280 ("wrap-lines" . ,(if wrap-lines "true" "false"))
281 ("http-auth" . ,http-auth)
282 ("users" . ,(if users
292 (define-record-type* <tailon-configuration>
293 tailon-configuration make-tailon-configuration
294 tailon-configuration?
295 (config-file tailon-configuration-config-file
296 (default (tailon-configuration-file)))
297 (package tailon-configuration-package
300 (define tailon-shepherd-service
302 (($ <tailon-configuration> config-file package)
303 (list (shepherd-service
304 (provision '(tailon))
305 (documentation "Run the tailon daemon.")
306 (start #~(make-forkexec-constructor
307 `(,(string-append #$package "/bin/tailon")
311 (stop #~(make-kill-destructor)))))))
313 (define %tailon-accounts
314 (list (user-group (name "tailon") (system? #t))
320 (home-directory "/var/empty")
321 (shell (file-append shadow "/sbin/nologin")))))
323 (define tailon-service-type
327 (list (service-extension shepherd-root-service-type
328 tailon-shepherd-service)
329 (service-extension account-service-type
330 (const %tailon-accounts))))
331 (compose concatenate)
332 (extend (lambda (parameter files)
333 (tailon-configuration
336 (let ((old-config-file
337 (tailon-configuration-config-file parameter)))
338 (tailon-configuration-file
339 (inherit old-config-file)
340 (files (append (tailon-configuration-file-files old-config-file)
342 (default-value (tailon-configuration))))
344 ;;; admin.scm ends here