From 44f020a0e89518f6370298bfc312aa3e53d8ae63 Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Tue, 1 Apr 2025 23:07:02 -0400 Subject: Synchronize /user served by nginx with Syncthing Add ACLs for nginx that only allow read access. This is more limited than allowing all users read access to /srv/syncthing, or adding nginx as a writable user to the syncthing group. --- hostnix/elmo/configuration.nix | 15 +-------------- 1 file changed, 1 insertion(+), 14 deletions(-) (limited to 'hostnix/elmo/configuration.nix') diff --git a/hostnix/elmo/configuration.nix b/hostnix/elmo/configuration.nix index 7b34054..f414cda 100644 --- a/hostnix/elmo/configuration.nix +++ b/hostnix/elmo/configuration.nix @@ -15,6 +15,7 @@ ./syncthing.nix ./system.nix ./usenet.nix + ./web.nix ./wireguard.nix ]; @@ -77,20 +78,6 @@ package = pkgs.postgresql_15; }; - services.nginx = { - enable = true; - recommendedGzipSettings = true; - recommendedOptimisation = true; - recommendedProxySettings = true; - recommendedTlsSettings = true; - virtualHosts."elmo.mou.fo" = { - default = true; - enableACME = true; - forceSSL = true; - root = "/var/www"; - }; - }; - systemd.services.duperemove = { serviceConfig = { Type = "simple"; -- cgit v1.3.1