summaryrefslogtreecommitdiff
path: root/hosts/surtr/postgresql.nix
blob: 4899b9720a114448a5ea21c1cc7c4f7b08fa4feb (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
{ pkgs, sources, ... }:
let
  versioning = sources.psql-versioning.src;
in {
  config = {
    services.postgresql = {
      enable = true;
      package = pkgs.postgresql_14;
      initialScript = pkgs.writeText "schema.sql" ''
        CREATE DATABASE "matrix-synapse" WITH TEMPLATE "template0" ENCODING "UTF8" LOCALE "C";
        CREATE USER "matrix-synapse";
        GRANT ALL PRIVILEGES ON DATABASE "matrix-synapse" TO "matrix-synapse";
        GRANT ALL PRIVILEGES ON ALL TABLES IN SCHEMA public TO "matrix-synapse";

        CREATE DATABASE "email" WITH TEMPLATE "template0" ENCODING "UTF8" LOCALE "C";
        CREATE USER "postfix";
        GRANT CONNECT ON DATABASE "email" TO "postfix";
        ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT SELECT ON TABLES TO "postfix";
        CREATE USER "dovecot2";
        GRANT CONNECT ON DATABASE "email" TO "dovecot2";
        ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT SELECT ON TABLES TO "dovecot2";
      '';
    };

    systemd.services.postgresql = {
      postStart = ''
        psql email postgres -eXf ${pkgs.writeText "email.sql" ''
          \i ${versioning + "/install.versioning.sql"}

          BEGIN;
          SELECT _v.register_patch('000-base', null, null);

          CREATE TABLE mailbox (
            id uuid PRIMARY KEY NOT NULL DEFAULT gen_random_uuid(),
            mailbox text NOT NULL CONSTRAINT mailbox_non_empty CHECK (mailbox <> '''),
            quota_bytes bigint CONSTRAINT quota_bytes_positive CHECK (CASE WHEN quota_bytes IS NOT NULL THEN quota_bytes > 0 ELSE true END),
            CONSTRAINT mailbox_unique UNIQUE (mailbox)
          );
          CREATE TABLE mailbox_mapping (
            id uuid PRIMARY KEY NOT NULL DEFAULT gen_random_uuid(),
            local text CONSTRAINT local_non_empty CHECK (local IS DISTINCT FROM '''),
            domain text NOT NULL CONSTRAINT domain_non_empty CHECK (domain <> '''),
            mailbox uuid REFERENCES mailbox(id),
            CONSTRAINT local_domain_unique UNIQUE (local, domain)
          );
          CREATE UNIQUE INDEX domain_unique ON mailbox_mapping (domain) WHERE local IS NULL;

          CREATE VIEW virtual_mailbox_domain (domain) AS SELECT DISTINCT domain FROM mailbox_mapping;
          CREATE VIEW virtual_mailbox_mapping (mailbox, lookup) AS SELECT mailbox.mailbox as mailbox, (CASE WHEN local IS NULL THEN ''' ELSE local END) || '@' || domain AS lookup FROM mailbox_mapping INNER JOIN mailbox on mailbox.id = mailbox_mapping.mailbox;

          CREATE VIEW imap_user ("user", quota_rule) AS SELECT mailbox AS "user", (CASE WHEN quota_bytes IS NULL THEN '*:ignore' ELSE '*:bytes=' || quota_bytes END) AS quota_rule FROM mailbox;
          COMMIT;

          BEGIN;
          SELECT _v.register_patch('001-lmtp-mapping', ARRAY['000-base'], null);

          CREATE VIEW lmtp_mapping ("user", quota_rule, local, domain) AS SELECT mailbox.mailbox AS "user", (CASE WHEN quota_bytes IS NULL THEN '*:ignore' ELSE '*:bytes=' || quota_bytes END) AS quota_rule FROM mailbox INNER JOIN mailbox_mapping ON mailbox.id = mailbox_mapping.mailbox;
          COMMIT;
        ''}
      '';
    };
  };
}