summaryrefslogtreecommitdiff
path: root/hostnix
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2025-04-16 16:32:37 -0400
committerJoe Mou <dev@mou.fo>2025-06-16 13:58:57 -0400
commitab1be6d042aba753dbb0041a0316ac3541c4daf2 (patch)
tree16889a10efa444190738f28c5c392df6cbd3129a /hostnix
parenta64f3bf8d165f8ef1a1e0aa8b4686219d6c98d59 (diff)
Fix /srv/syncthing ACLs
Disable home directory creation, which clobbers directory permissions. Interestingly, after the ACLs are added the classic directory permissions appear as 770; but happily it works fine. Tip off was from https://discourse.nixos.org/t/home-facl-is-always-reset-in-21-05/13408 Also tried setting the ACL mask which wasn't the issue.
Diffstat (limited to 'hostnix')
-rw-r--r--hostnix/elmo/syncthing.nix16
1 files changed, 11 insertions, 5 deletions
diff --git a/hostnix/elmo/syncthing.nix b/hostnix/elmo/syncthing.nix
index 664179b..357179a 100644
--- a/hostnix/elmo/syncthing.nix
+++ b/hostnix/elmo/syncthing.nix
@@ -1,4 +1,6 @@
-{ ... }:
+{ lib, ... }:
+
+# TODO iCloud bridge
let
staggeredVersioning = {
@@ -15,16 +17,20 @@ in
# difficult to grant granular access with classic permissions.
systemd.tmpfiles.rules = let
acls = builtins.concatStringsSep "," [
- "d:u:joe:rwX"
- "u:joe:rwX"
- "d:u:nginx:rX"
- "u:nginx:rX"
+ "user:joe:rwX"
+ "default:user:joe:rwX"
+ "user:nginx:rX"
+ "default:user:nginx:rX"
];
in
[
+ "d /srv/syncthing 0700 syncthing syncthing"
"A /srv/syncthing - - - - ${acls}"
];
+ # Disable Syncthing service home creation which clobbers above permissions.
+ users.users.syncthing.createHome = lib.mkForce false;
+
services.syncthing = {
enable = true;
openDefaultPorts = true;