From 44f020a0e89518f6370298bfc312aa3e53d8ae63 Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Tue, 1 Apr 2025 23:07:02 -0400 Subject: Synchronize /user served by nginx with Syncthing Add ACLs for nginx that only allow read access. This is more limited than allowing all users read access to /srv/syncthing, or adding nginx as a writable user to the syncthing group. --- hostnix/elmo/web.nix | 34 ++++++++++++++++++++++++++++++++++ 1 file changed, 34 insertions(+) create mode 100644 hostnix/elmo/web.nix (limited to 'hostnix/elmo/web.nix') diff --git a/hostnix/elmo/web.nix b/hostnix/elmo/web.nix new file mode 100644 index 0000000..e63d336 --- /dev/null +++ b/hostnix/elmo/web.nix @@ -0,0 +1,34 @@ +{ ... }: + +# TODO serve /srv behind authentication + +{ + systemd.tmpfiles.rules = [ + "L /home/joe/Public - - - - /srv/syncthing/Public/" + # It's quite hard to allow granular access to nginx using classic UNIX + # permissions, so use ACLs instead. + "A+ /srv/syncthing - - - - d:u:nginx:rX" + "A+ /srv/syncthing - - - - u:nginx:rX" + ]; + + services.nginx = { + enable = true; + recommendedGzipSettings = true; + recommendedOptimisation = true; + recommendedProxySettings = true; + recommendedTlsSettings = true; + virtualHosts."elmo.mou.fo" = { + default = true; + enableACME = true; + forceSSL = true; + root = "/var/www"; + locations = { + "/user/".extraConfig = '' + autoindex on; + autoindex_exact_size off; + autoindex_localtime on; + ''; + }; + }; + }; +} -- cgit v1.3.1