diff options
| author | Joe Mou <dev@mou.fo> | 2025-09-02 11:12:31 -0400 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2025-12-24 23:56:37 -0800 |
| commit | a9be51fc044e91ebcba6bd0e85cd34822b5ae419 (patch) | |
| tree | 1d5938418844fa030e243d25f1d0e8d570ffc99d /hostnix/elmo/yakatak.nix | |
| parent | f40776ccccae509c8ba8ea0335539127bd912c9f (diff) | |
yakatak service
Getting the right permissions set on the socket is quite awkward.
Perhaps listening on a port would have been preferable. systemd socket
activation would require us to support file descriptor handoff (which
would need to be changed in Nitro).
Diffstat (limited to 'hostnix/elmo/yakatak.nix')
| -rw-r--r-- | hostnix/elmo/yakatak.nix | 41 |
1 files changed, 41 insertions, 0 deletions
diff --git a/hostnix/elmo/yakatak.nix b/hostnix/elmo/yakatak.nix new file mode 100644 index 0000000..2057a92 --- /dev/null +++ b/hostnix/elmo/yakatak.nix @@ -0,0 +1,41 @@ +{ pkgs, ... }: + +{ + systemd.tmpfiles.rules = [ + "d /opt/yakatak 0755 joe users" + ]; + + systemd.services.yakatak = { + wantedBy = [ "multi-user.target" ]; + serviceConfig = { + Type = "exec"; + DynamicUser = true; + SupplementaryGroups = "nginx"; + RuntimeDirectory = "yakatak"; + StateDirectory = "yakatak"; + WorkingDirectory = "/opt/yakatak"; + }; + environment = { + NITRO_UNIX_SOCKET = "/run/yakatak/socket"; + NUXT_DB_PATH = "/var/lib/yakatak/yakatak.db"; + }; + script = '' + # Hack to make our socket connectable by nginx. + ( + sleep 5 + chown :nginx /run/yakatak/socket + chmod g+w /run/yakatak/socket + ) & + + ${pkgs.nodejs_22}/bin/node .output/server/index.mjs + ''; + }; + + services.nginx.virtualHosts."yakatak.app" = { + enableACME = true; + forceSSL = true; + locations."/" = { + proxyPass = "http://unix:/run/yakatak/socket"; + }; + }; +} |
