From ae381a3ddecfcf28284be2afa009adbab4ca934f Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Tue, 15 Apr 2025 16:52:42 -0400 Subject: Use ACLs to grant user access to /src/syncthing --- hostnix/elmo/syncthing.nix | 20 ++++++++++++++------ 1 file changed, 14 insertions(+), 6 deletions(-) (limited to 'hostnix/elmo/syncthing.nix') diff --git a/hostnix/elmo/syncthing.nix b/hostnix/elmo/syncthing.nix index 5767fd7..77da89e 100644 --- a/hostnix/elmo/syncthing.nix +++ b/hostnix/elmo/syncthing.nix @@ -10,12 +10,20 @@ let }; in { - users.users.syncthing.homeMode = "0750"; - - # May be of limited usefulness because Syncthing generally ignores umask. - systemd.services.syncthing = { - serviceConfig.UMask = "0002"; - }; + # Syncthing generally ignores umask and makes it hard to set permission bits + # by default, so use ACLs to grant access. Also nginx is particularly + # difficult to grant granular access with classic permissions. + systemd.tmpfiles.rules = let + acls = builtins.concatStringsSep "," [ + "d:u:joe:rwX" + "u:joe:rwX" + "d:u:nginx:rX" + "u:nginx:rX" + ]; + in + [ + "A /srv/syncthing - - - - ${acls}" + ]; services.syncthing = { enable = true; -- cgit v1.3.1