{ ... }: # TODO serve /srv behind authentication { systemd.tmpfiles.rules = [ "L /home/joe/Public - - - - /srv/syncthing/Public/" # It's quite hard to allow granular access to nginx using classic UNIX # permissions, so use ACLs instead. "A+ /srv/syncthing - - - - d:u:nginx:rX" "A+ /srv/syncthing - - - - u:nginx:rX" ]; services.nginx = { enable = true; recommendedGzipSettings = true; recommendedOptimisation = true; recommendedProxySettings = true; recommendedTlsSettings = true; virtualHosts."elmo.mou.fo" = { default = true; enableACME = true; forceSSL = true; root = "/var/www"; locations = { "/user/".extraConfig = '' autoindex on; autoindex_exact_size off; autoindex_localtime on; ''; }; }; }; }