{ config, lib, pkgs, ... }: let stateDir = "/var/lib/dnsmasq"; blocklist = "${stateDir}/dnsmasq.blacklist.txt"; in { # PostgreSQL daily backups services.postgresqlBackup = { enable = true; backupAll = true; location = "/vault/backups/zion/databases"; startAt = "*-*-* 05:15:00"; }; # Fetch hosts-blocklists daily systemd.services.download-dns-blocklist = { description = "Download hosts-blocklists"; wantedBy = [ "default.target" ]; path = with pkgs; [ curl ]; script = "curl -L https://github.com/notracking/hosts-blocklists/raw/master/dnsmasq/dnsmasq.blacklist.txt -o ${blocklist}"; serviceConfig.Type = "oneshot"; postStop = '' chown -R dnsmasq ${stateDir} systemctl restart dnsmasq ''; startAt = "02:00:00"; }; # Enable SATA HAT systemd.services.sata-hat = { description = "Enable software support for SATA Hat"; wantedBy = [ "zfs-import.target" ]; script = '' ${pkgs.bash}/bin/bash -c "/etc/nixos/scripts/SATA-hat.sh on" ''; serviceConfig = { Type = "oneshot"; RemainAfterExit = "yes"; ExecStop = '' ${pkgs.bash}/bin/bash -c "/etc/nixos/scripts/SATA-hat.sh off" ''; }; before = [ "zfs-import.target" "zfs-import-vault.service" ]; requires = [ "systemd-udev-settle.service" ]; after = [ "systemd-udev-settle.service" ]; }; # HACK: restart services dependent on ZFS afer mount systemd.services.restart-services-mount = { description = "Restart services after the ZFS dataset is mounted"; wantedBy = [ "default.target" ]; script = '' sleep 5 systemctl restart syncthing systemctl restart radicale systemctl restart gitea ''; serviceConfig.Type = "oneshot"; requires = [ "sata-hat.service" ]; after = [ "vault.mount" ]; }; }