diff options
| author | Joe Mou <dev@mou.fo> | 2025-04-01 23:07:02 -0400 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2025-04-08 23:58:43 -0400 |
| commit | 44f020a0e89518f6370298bfc312aa3e53d8ae63 (patch) | |
| tree | eee5b50bd7bb340bb4511d88fc543e09e0b3d1c2 /hostnix/elmo/web.nix | |
| parent | 7a309cd69d99417b58781a8692e1fa2228f26612 (diff) | |
Synchronize /user served by nginx with Syncthing
Add ACLs for nginx that only allow read access. This is more limited
than allowing all users read access to /srv/syncthing, or adding nginx
as a writable user to the syncthing group.
Diffstat (limited to 'hostnix/elmo/web.nix')
| -rw-r--r-- | hostnix/elmo/web.nix | 34 |
1 files changed, 34 insertions, 0 deletions
diff --git a/hostnix/elmo/web.nix b/hostnix/elmo/web.nix new file mode 100644 index 0000000..e63d336 --- /dev/null +++ b/hostnix/elmo/web.nix @@ -0,0 +1,34 @@ +{ ... }: + +# TODO serve /srv behind authentication + +{ + systemd.tmpfiles.rules = [ + "L /home/joe/Public - - - - /srv/syncthing/Public/" + # It's quite hard to allow granular access to nginx using classic UNIX + # permissions, so use ACLs instead. + "A+ /srv/syncthing - - - - d:u:nginx:rX" + "A+ /srv/syncthing - - - - u:nginx:rX" + ]; + + services.nginx = { + enable = true; + recommendedGzipSettings = true; + recommendedOptimisation = true; + recommendedProxySettings = true; + recommendedTlsSettings = true; + virtualHosts."elmo.mou.fo" = { + default = true; + enableACME = true; + forceSSL = true; + root = "/var/www"; + locations = { + "/user/".extraConfig = '' + autoindex on; + autoindex_exact_size off; + autoindex_localtime on; + ''; + }; + }; + }; +} |
