nixos/cfssl: don't create user/group unless service is enabled

+2 -2
+2 -2
nixos/modules/services/security/cfssl.nix
··· 146 146 }; 147 147 }; 148 148 149 - config = { 149 + config = mkIf cfg.enable { 150 150 users.extraGroups.cfssl = { 151 151 gid = config.ids.gids.cfssl; 152 152 }; ··· 159 159 uid = config.ids.uids.cfssl; 160 160 }; 161 161 162 - systemd.services.cfssl = mkIf cfg.enable { 162 + systemd.services.cfssl = { 163 163 description = "CFSSL CA API server"; 164 164 wantedBy = [ "multi-user.target" ]; 165 165 after = [ "network.target" ];