diff options
| author | Joe Mou <dev@mou.fo> | 2025-04-01 23:07:02 -0400 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2025-04-08 23:58:43 -0400 |
| commit | 44f020a0e89518f6370298bfc312aa3e53d8ae63 (patch) | |
| tree | eee5b50bd7bb340bb4511d88fc543e09e0b3d1c2 /hostnix/elmo/syncthing.nix | |
| parent | 7a309cd69d99417b58781a8692e1fa2228f26612 (diff) | |
Synchronize /user served by nginx with Syncthing
Add ACLs for nginx that only allow read access. This is more limited
than allowing all users read access to /srv/syncthing, or adding nginx
as a writable user to the syncthing group.
Diffstat (limited to 'hostnix/elmo/syncthing.nix')
| -rw-r--r-- | hostnix/elmo/syncthing.nix | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/hostnix/elmo/syncthing.nix b/hostnix/elmo/syncthing.nix index 578762e..ca91d5a 100644 --- a/hostnix/elmo/syncthing.nix +++ b/hostnix/elmo/syncthing.nix @@ -14,6 +14,7 @@ in "d /srv/syncthing 0770 syncthing syncthing" # defaults to 0700 ]; + # May be of limited usefulness because Syncthing generally ignores umask. systemd.services.syncthing = { serviceConfig.UMask = "0002"; }; @@ -102,6 +103,12 @@ in versioning = staggeredVersioning; devices = [ "sparky" ]; }; + "Public" = { + id = "f6iys-eunyf"; + path = "~/Public"; + versioning = staggeredVersioning; + devices = [ "sparky" ]; + }; "Sync" = { id = "7thks-5badk"; path = "~/Sync"; |
