summaryrefslogtreecommitdiff
path: root/hostnix/elmo
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2025-04-15 16:52:42 -0400
committerJoe Mou <dev@mou.fo>2025-04-16 00:13:55 -0400
commitae381a3ddecfcf28284be2afa009adbab4ca934f (patch)
tree3197b6a494ada2df819261e5b972e3292e094803 /hostnix/elmo
parent61779313cfdf8556daf3a460a7781da432c0bbc3 (diff)
Use ACLs to grant user access to /src/syncthing
Diffstat (limited to 'hostnix/elmo')
-rw-r--r--hostnix/elmo/configuration.nix2
-rw-r--r--hostnix/elmo/syncthing.nix20
-rw-r--r--hostnix/elmo/web.nix5
3 files changed, 16 insertions, 11 deletions
diff --git a/hostnix/elmo/configuration.nix b/hostnix/elmo/configuration.nix
index b68ed67..9218996 100644
--- a/hostnix/elmo/configuration.nix
+++ b/hostnix/elmo/configuration.nix
@@ -28,7 +28,7 @@
users.users.joe = {
isNormalUser = true;
description = "Joe Mou";
- extraGroups = [ "networkmanager" "wheel" "syncthing" ];
+ extraGroups = [ "networkmanager" "wheel" ];
packages = with pkgs; [
jq
sqlite-interactive
diff --git a/hostnix/elmo/syncthing.nix b/hostnix/elmo/syncthing.nix
index 5767fd7..77da89e 100644
--- a/hostnix/elmo/syncthing.nix
+++ b/hostnix/elmo/syncthing.nix
@@ -10,12 +10,20 @@ let
};
in
{
- users.users.syncthing.homeMode = "0750";
-
- # May be of limited usefulness because Syncthing generally ignores umask.
- systemd.services.syncthing = {
- serviceConfig.UMask = "0002";
- };
+ # Syncthing generally ignores umask and makes it hard to set permission bits
+ # by default, so use ACLs to grant access. Also nginx is particularly
+ # difficult to grant granular access with classic permissions.
+ systemd.tmpfiles.rules = let
+ acls = builtins.concatStringsSep "," [
+ "d:u:joe:rwX"
+ "u:joe:rwX"
+ "d:u:nginx:rX"
+ "u:nginx:rX"
+ ];
+ in
+ [
+ "A /srv/syncthing - - - - ${acls}"
+ ];
services.syncthing = {
enable = true;
diff --git a/hostnix/elmo/web.nix b/hostnix/elmo/web.nix
index e63d336..09aa588 100644
--- a/hostnix/elmo/web.nix
+++ b/hostnix/elmo/web.nix
@@ -3,12 +3,9 @@
# TODO serve /srv behind authentication
{
+ # Assumes proper permissions set by syncthing.nix
systemd.tmpfiles.rules = [
"L /home/joe/Public - - - - /srv/syncthing/Public/"
- # It's quite hard to allow granular access to nginx using classic UNIX
- # permissions, so use ACLs instead.
- "A+ /srv/syncthing - - - - d:u:nginx:rX"
- "A+ /srv/syncthing - - - - u:nginx:rX"
];
services.nginx = {