summaryrefslogtreecommitdiff
path: root/hostnix/elmo/syncthing.nix
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2025-04-01 23:07:02 -0400
committerJoe Mou <dev@mou.fo>2025-04-08 23:58:43 -0400
commit44f020a0e89518f6370298bfc312aa3e53d8ae63 (patch)
treeeee5b50bd7bb340bb4511d88fc543e09e0b3d1c2 /hostnix/elmo/syncthing.nix
parent7a309cd69d99417b58781a8692e1fa2228f26612 (diff)
Synchronize /user served by nginx with Syncthing
Add ACLs for nginx that only allow read access. This is more limited than allowing all users read access to /srv/syncthing, or adding nginx as a writable user to the syncthing group.
Diffstat (limited to 'hostnix/elmo/syncthing.nix')
-rw-r--r--hostnix/elmo/syncthing.nix7
1 files changed, 7 insertions, 0 deletions
diff --git a/hostnix/elmo/syncthing.nix b/hostnix/elmo/syncthing.nix
index 578762e..ca91d5a 100644
--- a/hostnix/elmo/syncthing.nix
+++ b/hostnix/elmo/syncthing.nix
@@ -14,6 +14,7 @@ in
"d /srv/syncthing 0770 syncthing syncthing" # defaults to 0700
];
+ # May be of limited usefulness because Syncthing generally ignores umask.
systemd.services.syncthing = {
serviceConfig.UMask = "0002";
};
@@ -102,6 +103,12 @@ in
versioning = staggeredVersioning;
devices = [ "sparky" ];
};
+ "Public" = {
+ id = "f6iys-eunyf";
+ path = "~/Public";
+ versioning = staggeredVersioning;
+ devices = [ "sparky" ];
+ };
"Sync" = {
id = "7thks-5badk";
path = "~/Sync";