summaryrefslogtreecommitdiff
path: root/hostnix/elmo/configuration.nix
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2025-04-01 23:07:02 -0400
committerJoe Mou <dev@mou.fo>2025-04-08 23:58:43 -0400
commit44f020a0e89518f6370298bfc312aa3e53d8ae63 (patch)
treeeee5b50bd7bb340bb4511d88fc543e09e0b3d1c2 /hostnix/elmo/configuration.nix
parent7a309cd69d99417b58781a8692e1fa2228f26612 (diff)
Synchronize /user served by nginx with Syncthing
Add ACLs for nginx that only allow read access. This is more limited than allowing all users read access to /srv/syncthing, or adding nginx as a writable user to the syncthing group.
Diffstat (limited to 'hostnix/elmo/configuration.nix')
-rw-r--r--hostnix/elmo/configuration.nix15
1 files changed, 1 insertions, 14 deletions
diff --git a/hostnix/elmo/configuration.nix b/hostnix/elmo/configuration.nix
index 7b34054..f414cda 100644
--- a/hostnix/elmo/configuration.nix
+++ b/hostnix/elmo/configuration.nix
@@ -15,6 +15,7 @@
./syncthing.nix
./system.nix
./usenet.nix
+ ./web.nix
./wireguard.nix
];
@@ -77,20 +78,6 @@
package = pkgs.postgresql_15;
};
- services.nginx = {
- enable = true;
- recommendedGzipSettings = true;
- recommendedOptimisation = true;
- recommendedProxySettings = true;
- recommendedTlsSettings = true;
- virtualHosts."elmo.mou.fo" = {
- default = true;
- enableACME = true;
- forceSSL = true;
- root = "/var/www";
- };
- };
-
systemd.services.duperemove = {
serviceConfig = {
Type = "simple";