feat: expanded all lists

This commit is contained in:
Nick 2025-01-08 19:11:58 -06:00
parent bb0b55b011
commit 4d8d534088
20 changed files with 107 additions and 28 deletions

View file

@ -96,7 +96,9 @@ in {
options = [
"bind"
];
depends = [server.storage0.mount];
depends = [
server.storage0.mount
];
};
systemd.tmpfiles.rules = [

View file

@ -48,7 +48,9 @@ in {
options = [
"bind"
];
depends = [server.storage0.mount];
depends = [
server.storage0.mount
];
};
in {
"/var/lib/${service.name}" =

View file

@ -160,7 +160,10 @@ in {
};
};
systemd.services.caddy.serviceConfig.ReadWriteDirectories = lib.mkForce ["/var/lib/caddy" "/run/mastodon-web"];
systemd.services.caddy.serviceConfig.ReadWriteDirectories = lib.mkForce [
"/var/lib/caddy"
"/run/mastodon-web"
];
sops = let
sopsPath = secret: {
@ -189,7 +192,9 @@ in {
options = [
"bind"
];
depends = [server.storage0.mount];
depends = [
server.storage0.mount
];
};
systemd.tmpfiles.rules = [

View file

@ -113,7 +113,9 @@ in {
options = [
"bind"
];
depends = [server.storage0.mount];
depends = [
server.storage0.mount
];
};
systemd.tmpfiles.rules = [

View file

@ -55,7 +55,9 @@ in {
options = [
"bind"
];
depends = [server.storage0.mount];
depends = [
server.storage0.mount
];
};
systemd.tmpfiles.rules = [

View file

@ -120,7 +120,9 @@ in {
options = [
"bind"
];
depends = [server.storage0.mount];
depends = [
server.storage0.mount
];
};
systemd.tmpfiles.rules = [
@ -128,7 +130,10 @@ in {
"Z ${service.sops.path0} 755 ${service.name} ${service.name} -"
];
users.users.${service.name}.extraGroups = ["nginx" "caddy"];
users.users.${service.name}.extraGroups = [
"nginx"
"caddy"
];
networking = {
firewall = {