diff options
| author | Joe Mou <dev@mou.fo> | 2025-04-15 16:52:42 -0400 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2025-04-16 00:13:55 -0400 |
| commit | ae381a3ddecfcf28284be2afa009adbab4ca934f (patch) | |
| tree | 3197b6a494ada2df819261e5b972e3292e094803 /hostnix/elmo | |
| parent | 61779313cfdf8556daf3a460a7781da432c0bbc3 (diff) | |
Use ACLs to grant user access to /src/syncthing
Diffstat (limited to 'hostnix/elmo')
| -rw-r--r-- | hostnix/elmo/configuration.nix | 2 | ||||
| -rw-r--r-- | hostnix/elmo/syncthing.nix | 20 | ||||
| -rw-r--r-- | hostnix/elmo/web.nix | 5 |
3 files changed, 16 insertions, 11 deletions
diff --git a/hostnix/elmo/configuration.nix b/hostnix/elmo/configuration.nix index b68ed67..9218996 100644 --- a/hostnix/elmo/configuration.nix +++ b/hostnix/elmo/configuration.nix @@ -28,7 +28,7 @@ users.users.joe = { isNormalUser = true; description = "Joe Mou"; - extraGroups = [ "networkmanager" "wheel" "syncthing" ]; + extraGroups = [ "networkmanager" "wheel" ]; packages = with pkgs; [ jq sqlite-interactive diff --git a/hostnix/elmo/syncthing.nix b/hostnix/elmo/syncthing.nix index 5767fd7..77da89e 100644 --- a/hostnix/elmo/syncthing.nix +++ b/hostnix/elmo/syncthing.nix @@ -10,12 +10,20 @@ let }; in { - users.users.syncthing.homeMode = "0750"; - - # May be of limited usefulness because Syncthing generally ignores umask. - systemd.services.syncthing = { - serviceConfig.UMask = "0002"; - }; + # Syncthing generally ignores umask and makes it hard to set permission bits + # by default, so use ACLs to grant access. Also nginx is particularly + # difficult to grant granular access with classic permissions. + systemd.tmpfiles.rules = let + acls = builtins.concatStringsSep "," [ + "d:u:joe:rwX" + "u:joe:rwX" + "d:u:nginx:rX" + "u:nginx:rX" + ]; + in + [ + "A /srv/syncthing - - - - ${acls}" + ]; services.syncthing = { enable = true; diff --git a/hostnix/elmo/web.nix b/hostnix/elmo/web.nix index e63d336..09aa588 100644 --- a/hostnix/elmo/web.nix +++ b/hostnix/elmo/web.nix @@ -3,12 +3,9 @@ # TODO serve /srv behind authentication { + # Assumes proper permissions set by syncthing.nix systemd.tmpfiles.rules = [ "L /home/joe/Public - - - - /srv/syncthing/Public/" - # It's quite hard to allow granular access to nginx using classic UNIX - # permissions, so use ACLs instead. - "A+ /srv/syncthing - - - - d:u:nginx:rX" - "A+ /srv/syncthing - - - - u:nginx:rX" ]; services.nginx = { |
