summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2026-08-13 03:32:53 -0400
committerJoe Mou <dev@mou.fo>2026-08-26 13:38:22 -0400
commit608fe9ccc6e7ea4ab1a458287261021dac1b742c (patch)
tree9fdc7c2b31d1f72ccdeaf8578cf8b786c20394d9
parentd167bc15da3bc3da355d69eadb9420abb3a637e1 (diff)
ytdl-sub & pinchflat permissions
-rw-r--r--hostnix/elmo/media.nix11
-rw-r--r--hostnix/elmo/pinchflat.nix2
2 files changed, 13 insertions, 0 deletions
diff --git a/hostnix/elmo/media.nix b/hostnix/elmo/media.nix
index 1bf4542..7a60030 100644
--- a/hostnix/elmo/media.nix
+++ b/hostnix/elmo/media.nix
@@ -30,9 +30,17 @@
locations."/".proxyPass = "http://127.0.0.1:8096";
};
+ systemd.tmpfiles.rules = [
+ "d /srv/media/incoming/YouTube 2775 ytdl-sub media -"
+ ];
+
services.ytdl-sub.instances.main = {
enable = true;
# TODO schedule = null;
+ # The unit runs with ProtectSystem=strict, which leaves the whole
+ # filesystem read-only apart from its own state and runtime directories.
+ # Without this the output tree is unwritable however it is chowned.
+ readWritePaths = [ "/srv/media/incoming/YouTube" ];
config = {
presets = {
"YouTube Channel" = {
@@ -69,10 +77,13 @@
url = "https://www.youtube.com/@moon-channel";
date_range_after = "20241201";
};
+ "Pinchflat" = "https://www.youtube.com/playlist?list=PLOqoltSk7NvI";
};
};
};
+ systemd.services.ytdl-sub-main.serviceConfig.UMask = "0002";
+
# TODO kavita vs komga?
services.kavita = {
enable = true;
diff --git a/hostnix/elmo/pinchflat.nix b/hostnix/elmo/pinchflat.nix
index 4374607..6ec4d0f 100644
--- a/hostnix/elmo/pinchflat.nix
+++ b/hostnix/elmo/pinchflat.nix
@@ -48,6 +48,8 @@ in
extraConfig.EXPOSE_FEED_ENDPOINTS = "yes";
};
+ systemd.services.pinchflat.serviceConfig.UMask = "0002";
+
users.users.pinchflat = {
extraGroups = [ "media" ];
};