summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2025-04-01 23:07:02 -0400
committerJoe Mou <dev@mou.fo>2025-04-08 23:58:43 -0400
commit44f020a0e89518f6370298bfc312aa3e53d8ae63 (patch)
treeeee5b50bd7bb340bb4511d88fc543e09e0b3d1c2
parent7a309cd69d99417b58781a8692e1fa2228f26612 (diff)
Synchronize /user served by nginx with Syncthing
Add ACLs for nginx that only allow read access. This is more limited than allowing all users read access to /srv/syncthing, or adding nginx as a writable user to the syncthing group.
-rw-r--r--hostnix/elmo/configuration.nix15
-rw-r--r--hostnix/elmo/syncthing.nix7
-rw-r--r--hostnix/elmo/web.nix34
3 files changed, 42 insertions, 14 deletions
diff --git a/hostnix/elmo/configuration.nix b/hostnix/elmo/configuration.nix
index 7b34054..f414cda 100644
--- a/hostnix/elmo/configuration.nix
+++ b/hostnix/elmo/configuration.nix
@@ -15,6 +15,7 @@
./syncthing.nix
./system.nix
./usenet.nix
+ ./web.nix
./wireguard.nix
];
@@ -77,20 +78,6 @@
package = pkgs.postgresql_15;
};
- services.nginx = {
- enable = true;
- recommendedGzipSettings = true;
- recommendedOptimisation = true;
- recommendedProxySettings = true;
- recommendedTlsSettings = true;
- virtualHosts."elmo.mou.fo" = {
- default = true;
- enableACME = true;
- forceSSL = true;
- root = "/var/www";
- };
- };
-
systemd.services.duperemove = {
serviceConfig = {
Type = "simple";
diff --git a/hostnix/elmo/syncthing.nix b/hostnix/elmo/syncthing.nix
index 578762e..ca91d5a 100644
--- a/hostnix/elmo/syncthing.nix
+++ b/hostnix/elmo/syncthing.nix
@@ -14,6 +14,7 @@ in
"d /srv/syncthing 0770 syncthing syncthing" # defaults to 0700
];
+ # May be of limited usefulness because Syncthing generally ignores umask.
systemd.services.syncthing = {
serviceConfig.UMask = "0002";
};
@@ -102,6 +103,12 @@ in
versioning = staggeredVersioning;
devices = [ "sparky" ];
};
+ "Public" = {
+ id = "f6iys-eunyf";
+ path = "~/Public";
+ versioning = staggeredVersioning;
+ devices = [ "sparky" ];
+ };
"Sync" = {
id = "7thks-5badk";
path = "~/Sync";
diff --git a/hostnix/elmo/web.nix b/hostnix/elmo/web.nix
new file mode 100644
index 0000000..e63d336
--- /dev/null
+++ b/hostnix/elmo/web.nix
@@ -0,0 +1,34 @@
+{ ... }:
+
+# TODO serve /srv behind authentication
+
+{
+ systemd.tmpfiles.rules = [
+ "L /home/joe/Public - - - - /srv/syncthing/Public/"
+ # It's quite hard to allow granular access to nginx using classic UNIX
+ # permissions, so use ACLs instead.
+ "A+ /srv/syncthing - - - - d:u:nginx:rX"
+ "A+ /srv/syncthing - - - - u:nginx:rX"
+ ];
+
+ services.nginx = {
+ enable = true;
+ recommendedGzipSettings = true;
+ recommendedOptimisation = true;
+ recommendedProxySettings = true;
+ recommendedTlsSettings = true;
+ virtualHosts."elmo.mou.fo" = {
+ default = true;
+ enableACME = true;
+ forceSSL = true;
+ root = "/var/www";
+ locations = {
+ "/user/".extraConfig = ''
+ autoindex on;
+ autoindex_exact_size off;
+ autoindex_localtime on;
+ '';
+ };
+ };
+ };
+}