nixpkgs/nixos/modules/misc/ids.nix

638 lines
15 KiB
Nix
Raw Normal View History

# This module defines the global list of uids and gids. We keep a
# central list to prevent id collisions.
# IMPORTANT!
# We only add static uids and gids for services where it is not feasible
# to change uids/gids on service start, in example a service with a lot of
# files. Please also check if the service is applicable for systemd's
# DynamicUser option and does not need a uid/gid allocation at all.
# Systemd can also change ownership of service directories using the
# RuntimeDirectory/StateDirectory options.
{ lib, ... }:
{
options = {
ids.uids = lib.mkOption {
2013-10-30 17:37:45 +01:00
internal = true;
description = ''
The user IDs used in NixOS.
'';
};
ids.gids = lib.mkOption {
2013-10-30 17:37:45 +01:00
internal = true;
description = ''
The group IDs used in NixOS.
'';
};
};
config = {
ids.uids = {
root = 0;
#wheel = 1; # unused
#kmem = 2; # unused
#tty = 3; # unused
messagebus = 4; # D-Bus
haldaemon = 5;
#disk = 6; # unused
vsftpd = 7;
ftp = 8;
bitlbee = 9;
avahi = 10;
nagios = 11;
atd = 12;
postfix = 13;
#postdrop = 14; # unused
dovecot = 15;
tomcat = 16;
#audio = 17; # unused
#floppy = 18; # unused
modules: HylaFAX server configuration This commit adds the following * the uucp user * options for HylaFAX server to control startup and modems * systemd services for HylaFAX server processes including faxgettys for modems * systemd services to maintain the HylaFAX spool area, including cleanup with faxcron and faxqclean * default configuration for all server processes for a minimal working configuration Some notes: * HylaFAX configuration cannot be initialized with faxsetup (as it would be common on other Linux distributions). The hylafaxplus package contains a template spool area. * Modems are controlled by faxgetty. Send-only configuration (modems controlled by faxq) is not supported by this configuration setup. * To enable the service, one or more modems must be defined with config.services.hylafax.modems . * Sending mail *should* work: HylaFAX will use whatever is in config.services.mail.sendmailSetuidWrapper.program unless overridden with the sendmailPath option. * The admin has to create a hosts.hfaxd file somewhere (e.g. in /etc) before enabling HylaFAX. This file controls access to the server (see hosts.hfaxd(5) ). Sadly, HylaFAX does not permit account-based access control as is accepts connections via TCP only. * Active fax polling should work; I can't test it. * Passive fax polling is not supported by HylaFAX. * Pager transmissions (with sendpage) are disabled by default. I have never tested or used these. * Incoming data/voice/"extern"al calls won't be handled by default. I have never tested or used these.
2018-08-04 17:08:54 +02:00
uucp = 19;
#lp = 20; # unused
#proc = 21; # unused
pulseaudio = 22; # must match `pulseaudio' GID
gpsd = 23;
#cdrom = 24; # unused
#tape = 25; # unused
#video = 26; # unused
#dialout = 27; # unused
polkituser = 28;
#utmp = 29; # unused
# ddclient = 30; # converted to DynamicUser = true
davfs2 = 31;
#disnix = 33; # unused
osgi = 34;
tor = 35;
cups = 36;
foldingathome = 37;
sabnzbd = 38;
2017-02-11 19:55:09 +01:00
#kdm = 39; # dropped in 17.03
#ghostone = 40; # dropped in 18.03
git = 41;
fourstore = 42;
fourstorehttp = 43;
virtuoso = 44;
rtkit = 45;
dovecot2 = 46;
dovenull2 = 47;
prayer = 49;
mpd = 50;
clamav = 51;
fprot = 52;
bind = 53;
wwwrun = 54;
#adm = 55; # unused
spamd = 56;
#networkmanager = 57; # unused
nslcd = 58;
2016-11-11 01:49:02 +01:00
scanner = 59;
nginx = 60;
chrony = 61;
#systemd-journal = 62; # unused
smtpd = 63;
smtpq = 64;
supybot = 65;
iodined = 66;
#libvirtd = 67; # unused
graphite = 68;
statsd = 69;
transmission = 70;
postgres = 71;
#vboxusers = 72; # unused
#vboxsf = 73; # unused
smbguest = 74; # unused
varnish = 75;
datadog = 76;
lighttpd = 77;
lightdm = 78;
freenet = 79;
ircd = 80;
bacula = 81;
#almir = 82; # removed 2018-03-25, the almir package was removed in 30291227f2411abaca097773eedb49b8f259e297 during 2017-08
deluge = 83;
mysql = 84;
rabbitmq = 85;
activemq = 86;
gnunet = 87;
oidentd = 88;
quassel = 89;
amule = 90;
minidlna = 91;
elasticsearch = 92;
tcpcryptd = 93; # tcpcryptd uses a hard-coded uid. We patch it in Nixpkgs to match this choice.
firebird = 95;
#keys = 96; # unused
2013-10-29 15:55:25 +01:00
haproxy = 97;
mongodb = 98;
openldap = 99;
#users = 100; # unused
2014-01-13 00:18:05 +01:00
cgminer = 101;
munin = 102;
logcheck = 103;
nix-ssh = 104;
dictd = 105;
2014-02-27 14:33:30 +01:00
couchdb = 106;
2014-03-07 20:09:59 +01:00
searx = 107;
2014-03-12 08:32:56 +01:00
kippo = 108;
jenkins = 109;
systemd-journal-gateway = 110;
#notbit = 111; # unused
aerospike = 111;
2014-03-20 03:04:35 +01:00
ngircd = 112;
btsync = 113;
minecraft = 114;
2017-06-27 16:54:25 +02:00
vault = 115;
rippled = 116;
murmur = 117;
foundationdb = 118;
newrelic = 119;
starbound = 120;
hydra = 122;
spiped = 123;
teamspeak = 124;
2014-05-27 22:54:43 +02:00
influxdb = 125;
nsd = 126;
gitolite = 127;
znc = 128;
2014-07-15 16:16:58 +02:00
polipo = 129;
mopidy = 130;
#docker = 131; # unused
gdm = 132;
dhcpd = 133;
2014-07-10 20:08:38 +02:00
siproxd = 134;
2014-07-09 00:43:26 +02:00
mlmmj = 135;
2014-08-16 23:53:26 +02:00
neo4j = 136;
riemann = 137;
riemanndash = 138;
radvd = 139;
2014-08-24 17:43:45 +02:00
zookeeper = 140;
dnsmasq = 141;
2014-09-01 08:53:00 +02:00
uhub = 142;
2014-09-26 10:44:09 +02:00
yandexdisk = 143;
#collectd = 144; #unused
2014-09-26 10:44:09 +02:00
consul = 145;
2014-09-26 10:03:29 +02:00
mailpile = 146;
2014-10-07 10:53:01 +02:00
redmine = 147;
2014-10-06 21:25:10 +02:00
seeks = 148;
prosody = 149;
2014-11-09 09:44:47 +01:00
i2pd = 150;
2014-11-20 00:01:44 +01:00
systemd-network = 152;
systemd-resolve = 153;
systemd-timesync = 154;
2014-11-20 23:30:24 +01:00
liquidsoap = 155;
2014-11-15 16:27:27 +01:00
etcd = 156;
2014-11-20 12:29:07 +01:00
hbase = 158;
2014-11-20 13:00:53 +01:00
opentsdb = 159;
2014-11-20 15:38:04 +01:00
scollector = 160;
2014-11-20 15:49:45 +01:00
bosun = 161;
2014-11-29 16:46:39 +01:00
kubernetes = 162;
2014-12-01 16:40:42 +01:00
peerflix = 163;
2014-12-03 15:49:14 +01:00
chronos = 164;
gitlab = 165;
2014-12-20 23:38:52 +01:00
tox-bootstrapd = 166;
2014-12-28 20:21:41 +01:00
cadvisor = 167;
nylon = 168;
apache-kafka = 169;
#panamax = 170; # unused
exim = 172;
#fleet = 173; # unused
#input = 174; # unused
2015-03-02 18:58:35 +01:00
sddm = 175;
tss = 176;
#memcached = 177; removed 2018-01-03
ntp = 179;
zabbix = 180;
#redis = 181; removed 2018-01-03
unifi = 183;
uptimed = 184;
zope2 = 185;
ripple-data-api = 186;
2015-03-27 11:48:50 +01:00
mediatomb = 187;
rdnssd = 188;
2017-11-06 07:29:56 +01:00
ihaskell = 189;
2015-04-15 12:52:06 +02:00
i2p = 190;
2015-04-14 01:06:37 +02:00
lambdabot = 191;
2015-04-17 00:53:26 +02:00
asterisk = 192;
plex = 193;
2017-10-30 13:13:58 +01:00
plexpy = 195;
2015-04-25 16:02:44 +02:00
grafana = 196;
2015-06-08 13:36:05 +02:00
skydns = 197;
# ripple-rest = 198; # unused, removed 2017-08-12
nix-serve = 199;
2015-06-20 22:33:57 +02:00
tvheadend = 200;
uwsgi = 201;
2015-06-09 00:11:24 +02:00
gitit = 202;
riemanntools = 203;
subsonic = 204;
2015-07-21 12:16:18 +02:00
riak = 205;
2015-08-01 01:15:18 +02:00
shout = 206;
2015-07-31 06:22:44 +02:00
gateone = 207;
2015-09-08 19:24:40 +02:00
namecoin = 208;
2015-09-10 18:10:06 +02:00
dnschain = 209;
2015-09-14 08:27:31 +02:00
#lxd = 210; # unused
2015-09-19 00:18:43 +02:00
kibana = 211;
2015-09-13 14:49:19 +02:00
xtreemfs = 212;
2015-09-28 05:31:17 +02:00
calibre-server = 213;
2015-11-16 15:26:07 +01:00
heapster = 214;
bepasty = 215;
# pumpio = 216; # unused, removed 2018-02-24
nm-openvpn = 217;
2015-09-08 09:17:21 +02:00
mathics = 218;
2016-01-03 03:36:19 +01:00
ejabberd = 219;
2016-01-06 04:04:50 +01:00
postsrsd = 220;
2016-01-06 23:10:56 +01:00
opendkim = 221;
2016-01-07 02:17:42 +01:00
dspam = 222;
2015-08-03 19:04:10 +02:00
gale = 223;
2016-01-08 15:12:00 +01:00
matrix-synapse = 224;
2016-01-12 10:06:46 +01:00
rspamd = 225;
2016-01-14 10:17:27 +01:00
rmilter = 226;
2016-01-17 13:11:09 +01:00
cfdyndns = 227;
gammu-smsd = 228;
pdnsd = 229;
2016-02-14 12:58:09 +01:00
octoprint = 230;
avahi-autoipd = 231;
2016-02-26 15:19:46 +01:00
nntp-proxy = 232;
2016-03-12 15:38:13 +01:00
mjpg-streamer = 233;
radicale = 234;
hydra-queue-runner = 235;
hydra-www = 236;
syncthing = 237;
2016-04-05 03:30:21 +02:00
caddy = 239;
taskd = 240;
2016-04-12 06:17:05 +02:00
factorio = 241;
2016-04-23 15:49:33 +02:00
emby = 242;
graylog = 243;
2016-05-11 06:18:38 +02:00
sniproxy = 244;
nzbget = 245;
mosquitto = 246;
toxvpn = 247;
2016-06-11 14:46:02 +02:00
squeezelite = 248;
2016-06-21 12:59:29 +02:00
turnserver = 249;
smokeping = 250;
gocd-agent = 251;
gocd-server = 252;
2016-08-07 03:58:38 +02:00
terraria = 253;
2016-08-15 03:17:53 +02:00
mattermost = 254;
prometheus = 255;
telegraf = 256;
2016-09-17 13:08:18 +02:00
gitlab-runner = 257;
postgrey = 258;
2016-10-13 00:58:56 +02:00
hound = 259;
2016-11-06 10:33:21 +01:00
leaps = 260;
ipfs = 261;
2016-11-03 17:49:36 +01:00
stanchion = 262;
riak-cs = 263;
infinoted = 264;
sickbeard = 265;
2017-12-13 19:22:33 +01:00
# glance = 266; # unused, removed 2017-12-13
2017-01-16 12:53:53 +01:00
couchpotato = 267;
2016-10-09 19:04:42 +02:00
gogs = 268;
2017-01-18 00:29:59 +01:00
pdns-recursor = 269;
kresd = 270;
rpc = 271;
geoip = 272;
fcron = 273;
sonarr = 274;
radarr = 275;
jackett = 276;
aria2 = 277;
2017-05-01 07:33:31 +02:00
clickhouse = 278;
rslsync = 279;
minio = 280;
2017-10-09 13:44:32 +02:00
kanboard = 281;
2017-07-25 09:20:24 +02:00
pykms = 282;
2017-10-13 04:34:27 +02:00
kodi = 283;
2017-11-22 12:11:46 +01:00
restya-board = 284;
2018-01-04 18:19:54 +01:00
mighttpd2 = 285;
2018-01-23 10:51:13 +01:00
hass = 286;
2018-02-05 22:02:14 +01:00
monero = 287;
ceph = 288;
2018-04-07 21:23:04 +02:00
duplicati = 289;
2018-05-01 16:44:12 +02:00
monetdb = 290;
2018-05-03 21:30:06 +02:00
restic = 291;
2018-05-26 05:11:48 +02:00
openvpn = 292;
2018-05-18 01:56:58 +02:00
meguca = 293;
yarn = 294;
hdfs = 295;
mapred = 296;
hadoop = 297;
2018-07-11 01:10:02 +02:00
hydron = 298;
cfssl = 299;
cassandra = 300;
qemu-libvirtd = 301;
# kvm = 302; # unused
# render = 303; # unused
2018-08-31 12:40:23 +02:00
zeronet = 304;
2017-11-25 22:41:19 +01:00
lirc = 305;
lidarr = 306;
2014-12-08 10:02:57 +01:00
# When adding a uid, make sure it doesn't match an existing gid. And don't use uids above 399!
nixbld = 30000; # start of range of uids
nobody = 65534;
};
ids.gids = {
root = 0;
wheel = 1;
kmem = 2;
tty = 3;
messagebus = 4; # D-Bus
haldaemon = 5;
disk = 6;
vsftpd = 7;
ftp = 8;
bitlbee = 9;
avahi = 10;
#nagios = 11; # unused
atd = 12;
postfix = 13;
postdrop = 14;
dovecot = 15;
tomcat = 16;
audio = 17;
floppy = 18;
uucp = 19;
lp = 20;
proc = 21;
pulseaudio = 22; # must match `pulseaudio' UID
gpsd = 23;
cdrom = 24;
tape = 25;
video = 26;
dialout = 27;
#polkituser = 28; # currently unused, polkitd doesn't need a group
utmp = 29;
# ddclient = 30; # converted to DynamicUser = true
davfs2 = 31;
disnix = 33;
osgi = 34;
tor = 35;
#cups = 36; # unused
#foldingathome = 37; # unused
#sabnzd = 38; # unused
2017-02-11 19:55:09 +01:00
#kdm = 39; # unused, even before 17.03
#ghostone = 40; # dropped in 18.03
git = 41;
fourstore = 42;
fourstorehttp = 43;
virtuoso = 44;
#rtkit = 45; # unused
dovecot2 = 46;
#dovenull = 47; # unused
prayer = 49;
mpd = 50;
clamav = 51;
fprot = 52;
#bind = 53; # unused
wwwrun = 54;
adm = 55;
spamd = 56;
networkmanager = 57;
nslcd = 58;
scanner = 59;
nginx = 60;
chrony = 61;
systemd-journal = 62;
smtpd = 63;
smtpq = 64;
supybot = 65;
iodined = 66;
libvirtd = 67;
graphite = 68;
#statsd = 69; # unused
transmission = 70;
postgres = 71;
vboxusers = 72;
vboxsf = 73;
smbguest = 74; # unused
varnish = 75;
datadog = 76;
lighttpd = 77;
lightdm = 78;
freenet = 79;
ircd = 80;
bacula = 81;
#almir = 82; # removed 2018-03-25, the almir package was removed in 30291227f2411abaca097773eedb49b8f259e297 during 2017-08
deluge = 83;
mysql = 84;
rabbitmq = 85;
activemq = 86;
gnunet = 87;
oidentd = 88;
quassel = 89;
amule = 90;
minidlna = 91;
elasticsearch = 92;
#tcpcryptd = 93; # unused
firebird = 95;
keys = 96;
haproxy = 97;
#mongodb = 98; # unused
openldap = 99;
munin = 102;
#logcheck = 103; # unused
#nix-ssh = 104; # unused
dictd = 105;
2014-02-27 14:33:30 +01:00
couchdb = 106;
2014-03-07 20:09:59 +01:00
searx = 107;
2014-03-12 08:32:56 +01:00
kippo = 108;
jenkins = 109;
systemd-journal-gateway = 110;
#notbit = 111; # unused
aerospike = 111;
#ngircd = 112; # unused
2014-12-28 12:47:12 +01:00
btsync = 113;
#minecraft = 114; # unused
2017-06-27 16:54:25 +02:00
vault = 115;
#ripped = 116; # unused
#murmur = 117; # unused
foundationdb = 118;
newrelic = 119;
starbound = 120;
hydra = 122;
spiped = 123;
teamspeak = 124;
2014-05-27 22:54:43 +02:00
influxdb = 125;
nsd = 126;
gitolite = 127;
znc = 128;
2014-07-15 16:16:58 +02:00
polipo = 129;
mopidy = 130;
docker = 131;
gdm = 132;
#dhcpcd = 133; # unused
2014-07-10 20:08:38 +02:00
siproxd = 134;
2014-07-09 00:43:26 +02:00
mlmmj = 135;
#neo4j = 136; # unused
riemann = 137;
riemanndash = 138;
#radvd = 139; # unused
#zookeeper = 140; # unused
#dnsmasq = 141; # unused
2014-09-01 08:53:00 +02:00
uhub = 142;
#yandexdisk = 143; # unused
#collectd = 144; # unused
#consul = 145; # unused
2014-09-26 10:03:29 +02:00
mailpile = 146;
2014-10-07 10:53:01 +02:00
redmine = 147;
2014-10-06 21:25:10 +02:00
seeks = 148;
prosody = 149;
2014-11-09 09:44:47 +01:00
i2pd = 150;
2014-11-20 00:01:44 +01:00
systemd-network = 152;
systemd-resolve = 153;
systemd-timesync = 154;
2014-11-20 23:30:24 +01:00
liquidsoap = 155;
#etcd = 156; # unused
2015-03-03 20:21:36 +01:00
hbase = 158;
opentsdb = 159;
2015-01-05 11:58:17 +01:00
scollector = 160;
bosun = 161;
kubernetes = 162;
#peerflix = 163; # unused
#chronos = 164; # unused
2015-01-05 11:58:17 +01:00
gitlab = 165;
2015-03-03 20:21:36 +01:00
nylon = 168;
#panamax = 170; # unused
exim = 172;
#fleet = 173; # unused
input = 174;
2015-03-02 18:58:35 +01:00
sddm = 175;
tss = 176;
#memcached = 177; # unused, removed 2018-01-03
#ntp = 179; # unused
#zabbix = 180; # unused
#redis = 181; # unused, removed 2018-01-03
#unifi = 183; # unused
#uptimed = 184; # unused
#zope2 = 185; # unused
#ripple-data-api = 186; #unused
2015-03-27 11:48:50 +01:00
mediatomb = 187;
#rdnssd = 188; # unused
2017-11-06 07:29:56 +01:00
ihaskell = 189;
2015-04-15 12:52:06 +02:00
i2p = 190;
2015-04-14 01:06:37 +02:00
lambdabot = 191;
asterisk = 192;
plex = 193;
sabnzbd = 194;
2015-04-25 16:02:44 +02:00
#grafana = 196; #unused
2015-06-08 13:36:05 +02:00
#skydns = 197; #unused
# ripple-rest = 198; # unused, removed 2017-08-12
#nix-serve = 199; #unused
2015-06-20 22:33:57 +02:00
#tvheadend = 200; #unused
uwsgi = 201;
2015-06-09 00:11:24 +02:00
gitit = 202;
riemanntools = 203;
subsonic = 204;
2015-07-21 12:16:18 +02:00
riak = 205;
2015-08-01 01:15:18 +02:00
#shout = 206; #unused
2015-07-31 06:22:44 +02:00
gateone = 207;
namecoin = 208;
2015-09-10 18:10:06 +02:00
#dnschain = 209; #unused
2015-09-14 08:27:31 +02:00
lxd = 210; # unused
2015-09-19 00:18:43 +02:00
#kibana = 211;
2015-09-13 14:49:19 +02:00
xtreemfs = 212;
2015-09-28 05:31:17 +02:00
calibre-server = 213;
bepasty = 215;
# pumpio = 216; # unused, removed 2018-02-24
nm-openvpn = 217;
2015-09-08 09:17:21 +02:00
mathics = 218;
2016-01-03 03:36:19 +01:00
ejabberd = 219;
2016-01-06 04:04:50 +01:00
postsrsd = 220;
2016-01-06 23:10:56 +01:00
opendkim = 221;
2016-01-07 02:17:42 +01:00
dspam = 222;
2015-08-03 19:04:10 +02:00
gale = 223;
2016-01-08 15:12:00 +01:00
matrix-synapse = 224;
2016-01-12 10:06:46 +01:00
rspamd = 225;
2016-01-14 10:17:27 +01:00
rmilter = 226;
2016-01-17 13:11:09 +01:00
cfdyndns = 227;
pdnsd = 229;
2016-02-14 12:58:09 +01:00
octoprint = 230;
radicale = 234;
syncthing = 237;
2016-04-05 03:30:21 +02:00
caddy = 239;
taskd = 240;
2016-04-12 06:17:05 +02:00
factorio = 241;
2016-04-23 15:49:33 +02:00
emby = 242;
2016-05-11 06:18:38 +02:00
sniproxy = 244;
nzbget = 245;
mosquitto = 246;
#toxvpn = 247; # unused
2016-06-11 14:46:02 +02:00
#squeezelite = 248; #unused
2016-06-21 12:59:29 +02:00
turnserver = 249;
smokeping = 250;
gocd-agent = 251;
gocd-server = 252;
2016-08-07 03:58:38 +02:00
terraria = 253;
2016-08-15 03:17:53 +02:00
mattermost = 254;
prometheus = 255;
#telegraf = 256; # unused
2016-09-17 13:08:18 +02:00
gitlab-runner = 257;
postgrey = 258;
2016-10-13 00:58:56 +02:00
hound = 259;
2016-11-06 10:33:21 +01:00
leaps = 260;
ipfs = 261;
2016-11-03 17:49:36 +01:00
stanchion = 262;
riak-cs = 263;
infinoted = 264;
sickbeard = 265;
2017-12-13 19:22:33 +01:00
# glance = 266; # unused, removed 2017-12-13
2017-01-16 12:53:53 +01:00
couchpotato = 267;
2016-10-09 19:04:42 +02:00
gogs = 268;
kresd = 270;
#rpc = 271; # unused
#geoip = 272; # unused
fcron = 273;
sonarr = 274;
radarr = 275;
jackett = 276;
aria2 = 277;
2017-05-01 07:33:31 +02:00
clickhouse = 278;
rslsync = 279;
minio = 280;
2017-10-09 13:44:32 +02:00
kanboard = 281;
2017-07-25 09:20:24 +02:00
pykms = 282;
2017-10-13 04:34:27 +02:00
kodi = 283;
2017-11-22 12:11:46 +01:00
restya-board = 284;
2018-01-04 18:19:54 +01:00
mighttpd2 = 285;
2018-01-23 10:51:13 +01:00
hass = 286;
2018-02-05 22:02:14 +01:00
monero = 287;
ceph = 288;
2018-04-07 21:23:04 +02:00
duplicati = 289;
2018-05-01 16:44:12 +02:00
monetdb = 290;
2018-05-03 21:30:06 +02:00
restic = 291;
2018-05-26 05:11:48 +02:00
openvpn = 292;
2018-05-18 01:56:58 +02:00
meguca = 293;
yarn = 294;
hdfs = 295;
mapred = 296;
hadoop = 297;
2018-07-11 01:10:02 +02:00
hydron = 298;
cfssl = 299;
cassandra = 300;
qemu-libvirtd = 301;
kvm = 302; # default udev rules from systemd requires these
render = 303; # default udev rules from systemd requires these
2018-08-31 12:40:23 +02:00
zeronet = 304;
2017-11-25 22:41:19 +01:00
lirc = 305;
lidarr = 306;
2015-01-05 11:58:17 +01:00
# When adding a gid, make sure it doesn't match an existing
# uid. Users and groups with the same name should have equal
# uids and gids. Also, don't use gids above 399!
users = 100;
nixbld = 30000;
nogroup = 65534;
};
};
}