From f0ff407c05bd422dc0ca9c26baee74579f28a987 Mon Sep 17 00:00:00 2001 From: Kristoffer Dalby Date: Mon, 28 Sep 2026 13:35:13 +0000 Subject: [PATCH] nix: stop module.nix writing the deprecated ephemeral key Its default made headscale warn on every start. The camelCase rename now targets node.ephemeral.inactivity_timeout, and the old path asserts. --- CHANGELOG.md | 4 ++++ nix/module.nix | 16 +++++----------- 2 files changed, 9 insertions(+), 11 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index aead3897..c2e82de1 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -87,6 +87,10 @@ removed on this schedule: - `--output json` / `--output yaml` now emit the API's shape — camelCase fields, string-encoded IDs, RFC3339 timestamps — instead of the old Protobuf encoding [#3324](https://github.com/juanfont/headscale/pull/3324) - `headscale policy` renames the database-bypass flag from `--bypass-grpc-and-access-database-directly` to `--bypass-server-and-access-database-directly` [#3324](https://github.com/juanfont/headscale/pull/3324) +#### NixOS module + +- `settings.ephemeral_node_inactivity_timeout` is removed; set `settings.node.ephemeral.inactivity_timeout`, which headscale reads instead + ### Changes - Expiring or deleting a non-existent pre-auth key now returns an error instead of silently succeeding [#3324](https://github.com/juanfont/headscale/pull/3324) diff --git a/nix/module.nix b/nix/module.nix index 8180c76c..2233d971 100644 --- a/nix/module.nix +++ b/nix/module.nix @@ -203,16 +203,6 @@ in }; }; - ephemeral_node_inactivity_timeout = lib.mkOption { - type = lib.types.str; - default = "30m"; - description = '' - Time before an inactive ephemeral node is deleted. - Deprecated: use node.ephemeral.inactivity_timeout instead. - ''; - example = "5m"; - }; - node = { expiry = lib.mkOption { type = lib.types.str; @@ -629,7 +619,7 @@ in ) (mkRenamedOptionModule [ "services" "headscale" "ephemeralNodeInactivityTimeout" ] - [ "services" "headscale" "settings" "ephemeral_node_inactivity_timeout" ] + [ "services" "headscale" "settings" "node" "ephemeral" "inactivity_timeout" ] ) (mkRenamedOptionModule [ "services" "headscale" "logLevel" ] @@ -710,6 +700,10 @@ in "oidc" "strip_email_domain" ] "The strip_email_domain option got removed upstream") + (assertRemovedOption [ + "settings" + "ephemeral_node_inactivity_timeout" + ] "Use `node.ephemeral.inactivity_timeout` instead.") ]; services.headscale.settings = lib.mkMerge [