summaryrefslogtreecommitdiff
path: root/hostnix/elmo/web.nix
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2025-04-01 23:07:02 -0400
committerJoe Mou <dev@mou.fo>2025-04-08 23:58:43 -0400
commit44f020a0e89518f6370298bfc312aa3e53d8ae63 (patch)
treeeee5b50bd7bb340bb4511d88fc543e09e0b3d1c2 /hostnix/elmo/web.nix
parent7a309cd69d99417b58781a8692e1fa2228f26612 (diff)
Synchronize /user served by nginx with Syncthing
Add ACLs for nginx that only allow read access. This is more limited than allowing all users read access to /srv/syncthing, or adding nginx as a writable user to the syncthing group.
Diffstat (limited to 'hostnix/elmo/web.nix')
-rw-r--r--hostnix/elmo/web.nix34
1 files changed, 34 insertions, 0 deletions
diff --git a/hostnix/elmo/web.nix b/hostnix/elmo/web.nix
new file mode 100644
index 0000000..e63d336
--- /dev/null
+++ b/hostnix/elmo/web.nix
@@ -0,0 +1,34 @@
+{ ... }:
+
+# TODO serve /srv behind authentication
+
+{
+ systemd.tmpfiles.rules = [
+ "L /home/joe/Public - - - - /srv/syncthing/Public/"
+ # It's quite hard to allow granular access to nginx using classic UNIX
+ # permissions, so use ACLs instead.
+ "A+ /srv/syncthing - - - - d:u:nginx:rX"
+ "A+ /srv/syncthing - - - - u:nginx:rX"
+ ];
+
+ services.nginx = {
+ enable = true;
+ recommendedGzipSettings = true;
+ recommendedOptimisation = true;
+ recommendedProxySettings = true;
+ recommendedTlsSettings = true;
+ virtualHosts."elmo.mou.fo" = {
+ default = true;
+ enableACME = true;
+ forceSSL = true;
+ root = "/var/www";
+ locations = {
+ "/user/".extraConfig = ''
+ autoindex on;
+ autoindex_exact_size off;
+ autoindex_localtime on;
+ '';
+ };
+ };
+ };
+}