{ ... }: # TODO serve /srv behind authentication { # Assumes proper permissions set by syncthing.nix systemd.tmpfiles.rules = [ "L /home/joe/Public - - - - /srv/syncthing/Public/" ]; services.nginx = { enable = true; recommendedGzipSettings = true; recommendedOptimisation = true; recommendedProxySettings = true; recommendedTlsSettings = true; virtualHosts."elmo.mou.fo" = { default = true; enableACME = true; forceSSL = true; root = "/var/www"; locations = { "/user/".extraConfig = '' autoindex on; autoindex_exact_size off; autoindex_localtime on; ''; }; }; }; }