summaryrefslogtreecommitdiff
path: root/hostnix/elmo/syncthing.nix
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix/elmo/syncthing.nix')
-rw-r--r--hostnix/elmo/syncthing.nix20
1 files changed, 14 insertions, 6 deletions
diff --git a/hostnix/elmo/syncthing.nix b/hostnix/elmo/syncthing.nix
index 5767fd7..77da89e 100644
--- a/hostnix/elmo/syncthing.nix
+++ b/hostnix/elmo/syncthing.nix
@@ -10,12 +10,20 @@ let
};
in
{
- users.users.syncthing.homeMode = "0750";
-
- # May be of limited usefulness because Syncthing generally ignores umask.
- systemd.services.syncthing = {
- serviceConfig.UMask = "0002";
- };
+ # Syncthing generally ignores umask and makes it hard to set permission bits
+ # by default, so use ACLs to grant access. Also nginx is particularly
+ # difficult to grant granular access with classic permissions.
+ systemd.tmpfiles.rules = let
+ acls = builtins.concatStringsSep "," [
+ "d:u:joe:rwX"
+ "u:joe:rwX"
+ "d:u:nginx:rX"
+ "u:nginx:rX"
+ ];
+ in
+ [
+ "A /srv/syncthing - - - - ${acls}"
+ ];
services.syncthing = {
enable = true;