summaryrefslogtreecommitdiff
path: root/hostnix/elmo/yakatak.nix
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2025-09-02 11:12:31 -0400
committerJoe Mou <dev@mou.fo>2025-12-24 23:56:37 -0800
commita9be51fc044e91ebcba6bd0e85cd34822b5ae419 (patch)
tree1d5938418844fa030e243d25f1d0e8d570ffc99d /hostnix/elmo/yakatak.nix
parentf40776ccccae509c8ba8ea0335539127bd912c9f (diff)
yakatak service
Getting the right permissions set on the socket is quite awkward. Perhaps listening on a port would have been preferable. systemd socket activation would require us to support file descriptor handoff (which would need to be changed in Nitro).
Diffstat (limited to 'hostnix/elmo/yakatak.nix')
-rw-r--r--hostnix/elmo/yakatak.nix41
1 files changed, 41 insertions, 0 deletions
diff --git a/hostnix/elmo/yakatak.nix b/hostnix/elmo/yakatak.nix
new file mode 100644
index 0000000..2057a92
--- /dev/null
+++ b/hostnix/elmo/yakatak.nix
@@ -0,0 +1,41 @@
+{ pkgs, ... }:
+
+{
+ systemd.tmpfiles.rules = [
+ "d /opt/yakatak 0755 joe users"
+ ];
+
+ systemd.services.yakatak = {
+ wantedBy = [ "multi-user.target" ];
+ serviceConfig = {
+ Type = "exec";
+ DynamicUser = true;
+ SupplementaryGroups = "nginx";
+ RuntimeDirectory = "yakatak";
+ StateDirectory = "yakatak";
+ WorkingDirectory = "/opt/yakatak";
+ };
+ environment = {
+ NITRO_UNIX_SOCKET = "/run/yakatak/socket";
+ NUXT_DB_PATH = "/var/lib/yakatak/yakatak.db";
+ };
+ script = ''
+ # Hack to make our socket connectable by nginx.
+ (
+ sleep 5
+ chown :nginx /run/yakatak/socket
+ chmod g+w /run/yakatak/socket
+ ) &
+
+ ${pkgs.nodejs_22}/bin/node .output/server/index.mjs
+ '';
+ };
+
+ services.nginx.virtualHosts."yakatak.app" = {
+ enableACME = true;
+ forceSSL = true;
+ locations."/" = {
+ proxyPass = "http://unix:/run/yakatak/socket";
+ };
+ };
+}