summary refs log tree commit diff
path: root/gnu/services
diff options
context:
space:
mode:
authorDavid Thompson <dthompson2@worcester.edu>2015-05-03 17:02:59 -0400
committerDavid Thompson <dthompson2@worcester.edu>2015-05-07 08:44:36 -0400
commit105369a46b6baf94aec5382cad6c70509e3ce1fc (patch)
treea22cb44ac5180185bbb813e000b835d4a51e4639 /gnu/services
parent6e6e9f2551a4b9be255ebbe1528126916b7d34e1 (diff)
downloadguix-105369a46b6baf94aec5382cad6c70509e3ce1fc.tar.gz
gnu: Add postgresql-service.
* gnu/services/databases.scm: New file.
* gnu-system.am (GNU_SYSTEM_MODULES): Add it.
* doc/guix.texi ("Database Services"): New subsubsection.
Diffstat (limited to 'gnu/services')
-rw-r--r--gnu/services/databases.scm121
1 files changed, 121 insertions, 0 deletions
diff --git a/gnu/services/databases.scm b/gnu/services/databases.scm
new file mode 100644
index 0000000000..18f41e74da
--- /dev/null
+++ b/gnu/services/databases.scm
@@ -0,0 +1,121 @@
+;;; GNU Guix --- Functional package management for GNU
+;;; Copyright © 2015 David Thompson <davet@gnu.org>
+;;;
+;;; This file is part of GNU Guix.
+;;;
+;;; GNU Guix is free software; you can redistribute it and/or modify it
+;;; under the terms of the GNU General Public License as published by
+;;; the Free Software Foundation; either version 3 of the License, or (at
+;;; your option) any later version.
+;;;
+;;; GNU Guix is distributed in the hope that it will be useful, but
+;;; WITHOUT ANY WARRANTY; without even the implied warranty of
+;;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+;;; GNU General Public License for more details.
+;;;
+;;; You should have received a copy of the GNU General Public License
+;;; along with GNU Guix.  If not, see <http://www.gnu.org/licenses/>.
+
+(define-module (gnu services databases)
+  #:use-module (gnu services)
+  #:use-module (gnu system shadow)
+  #:use-module (gnu packages admin)
+  #:use-module (gnu packages databases)
+  #:use-module (guix records)
+  #:use-module (guix monads)
+  #:use-module (guix store)
+  #:use-module (guix gexp)
+  #:export (postgresql-service))
+
+;;; Commentary:
+;;;
+;;; Database services.
+;;;
+;;; Code:
+
+(define %default-postgres-hba
+  (text-file "pg_hba.conf"
+             "
+local	all	all			trust
+host	all	all	127.0.0.1/32 	trust
+host	all	all	::1/128 	trust"))
+
+(define %default-postgres-ident
+  (text-file "pg_ident.conf"
+             "# MAPNAME       SYSTEM-USERNAME         PG-USERNAME"))
+
+(define %default-postgres-config
+  (mlet %store-monad ((hba %default-postgres-hba)
+                      (ident %default-postgres-ident))
+    (text-file* "postgresql.conf"
+                ;; The daemon will not start without these.
+                "hba_file = '" hba "'\n"
+                "ident_file = '" ident "'\n")))
+
+(define* (postgresql-service #:key (postgresql postgresql)
+                             (config-file %default-postgres-config)
+                             (data-directory "/var/lib/postgresql/data"))
+  "Return a service that runs @var{postgresql}, the PostgreSQL database server.
+
+The PostgreSQL daemon loads its runtime configuration from @var{config-file}
+and stores the database cluster in @var{data-directory}."
+  ;; Wrapper script that switches to the 'postgres' user before launching
+  ;; daemon.
+  (define start-script
+    (mlet %store-monad ((config-file config-file))
+      (gexp->script "start-postgres"
+                    #~(let ((user (getpwnam "postgres"))
+                            (postgres (string-append #$postgresql
+                                                     "/bin/postgres")))
+                        (setgid (passwd:gid user))
+                        (setuid (passwd:uid user))
+                        (system* postgres
+                                 (string-append "--config-file=" #$config-file)
+                                 "-D" #$data-directory)))))
+
+  (define activate
+    #~(begin
+        (use-modules (guix build utils)
+                     (ice-9 match))
+
+        (let ((user (getpwnam "postgres"))
+              (initdb (string-append #$postgresql "/bin/initdb")))
+          ;; Create db state directory.
+          (mkdir-p #$data-directory)
+          (chown #$data-directory (passwd:uid user) (passwd:gid user))
+
+          ;; Drop privileges and init state directory in a new
+          ;; process.  Wait for it to finish before proceeding.
+          (match (primitive-fork)
+            (0
+             ;; Exit with a non-zero status code if an exception is thrown.
+             (dynamic-wind
+               (const #t)
+               (lambda ()
+                 (setgid (passwd:gid user))
+                 (setuid (passwd:uid user))
+                 (primitive-exit (system* initdb "-D" #$data-directory)))
+               (lambda ()
+                 (primitive-exit 1))))
+            (pid (waitpid pid))))))
+
+  (mlet %store-monad ((start-script start-script))
+    (return
+     (service
+      (provision '(postgres))
+      (documentation "Run the PostgreSQL daemon.")
+      (requirement '(user-processes loopback))
+      (start #~(make-forkexec-constructor #$start-script))
+      (stop #~(make-kill-destructor))
+      (activate activate)
+      (user-groups (list (user-group
+                          (name "postgres")
+                          (system? #t))))
+      (user-accounts (list (user-account
+                            (name "postgres")
+                            (group "postgres")
+                            (system? #t)
+                            (comment "PostgreSQL server user")
+                            (home-directory "/var/empty")
+                            (shell
+                             #~(string-append #$shadow "/sbin/nologin")))))))))