summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorKyren223 <Kyren223@proton.me>2025-07-22 17:05:08 +0300
committerKyren223 <Kyren223@proton.me>2025-07-22 17:05:08 +0300
commite6cfdac5a83d8d2e2664e3b313900b7b1a145114 (patch)
treeea2e23feb6945b5900483611d5577b5fe287a145
parentc2db60b773ad54e6991ca21b2775f9ed408c1cf9 (diff)
Improved flake.nix and added service.nix to run the server as a NixOS
systemd service
-rw-r--r--flake.nix28
-rw-r--r--service.nix118
2 files changed, 144 insertions, 2 deletions
diff --git a/flake.nix b/flake.nix
index be0ab9b..988a4fd 100644
--- a/flake.nix
+++ b/flake.nix
@@ -1,5 +1,6 @@
{
description = "Localias is a tool for developers to securely manage local aliases for development servers.";
+
inputs = {
nixpkgs.url = "github:nixos/nixpkgs";
@@ -23,9 +24,14 @@
version = (builtins.readFile ./VERSION);
buildDate = builtins.readFile (
pkgs.runCommand "build-date" { } ''
- date -u +'%Y-%m-%d' > $out
+ ${pkgs.coreutils}/bin/date --date=@${toString self.lastModified} +%Y-%m-%d -u > $out
''
);
+ # buildDate = builtins.readFile (
+ # pkgs.runCommand "build-date" { } ''
+ # date -u +'%Y-%m-%d' > $out
+ # ''
+ # );
commit = if (builtins.hasAttr "rev" self) then (builtins.substring 0 7 self.rev) else "unknown";
# vendorHash = pkgs.lib.fakeHash;
vendorHash = "sha256-2yCQ40T5N90lKpPOc+i6vz+1mI/p4Ey6PdRCJbGD+TE=";
@@ -82,15 +88,33 @@
eko = {
type = "app";
program = "${packages.eko}/bin/eko";
+ meta = {
+ description = "A terminal-native social media platform (client)";
+ homepage = "https://github.com/kyren223/eko";
+ license = pkgs.lib.licenses.agpl3Plus;
+ maintainers = with pkgs.lib.maintainers; [ kyren223 ];
+ platforms = pkgs.lib.platforms.all;
+ };
};
eko-server = {
type = "service";
program = "${packages.eko}/bin/eko-server";
- # TODO: add systemd service
+ meta = {
+ description = "A terminal-native social media platform (server)";
+ homepage = "https://github.com/kyren223/eko";
+ license = pkgs.lib.licenses.agpl3Plus;
+ maintainers = with pkgs.lib.maintainers; [ kyren223 ];
+ platforms = pkgs.lib.platforms.all;
+ };
};
default = eko;
};
+ nixosModules = rec {
+ default = eko;
+ eko = import ./service.nix inputs;
+ };
+
# TODO: make my own devshell?
# devShells = rec {
# default = pkgs.mkShell {
diff --git a/service.nix b/service.nix
new file mode 100644
index 0000000..9e9e437
--- /dev/null
+++ b/service.nix
@@ -0,0 +1,118 @@
+inputs:
+{
+ config,
+ pkgs,
+ lib,
+ ...
+}:
+let
+ cfg = config.services.eko;
+in
+{
+ meta.maintainers = with lib.maintainers; [ kyren223 ];
+
+ options.services.eko = {
+ enable = lib.mkEnableOption "eko service";
+
+ package = lib.mkPackageOption inputs.self.packages.${pkgs.stdenv.hostPlatform.system}.eko-server { };
+
+ dataDir = lib.mkOption {
+ description = "Eko data directory";
+ default = "/var/lib/eko";
+ type = lib.types.path;
+ };
+
+ logDir = lib.mkOption {
+ description = "Eko logs directory";
+ default = "/var/log/eko";
+ type = lib.types.path;
+ };
+
+ tosFile = lib.mkOption {
+ description = "Eko terms of service file";
+ default = "/etc/eko/tos.md";
+ type = lib.types.path;
+ };
+
+ privacyFile = lib.mkOption {
+ description = "Eko privacy policy file";
+ default = "/etc/eko/privacy.md";
+ type = lib.types.path;
+ };
+
+ certFile = lib.mkOption {
+ description = "Eko certificate key file";
+ type = lib.types.path;
+ };
+
+ };
+
+ config = lib.mkIf cfg.enable {
+
+ systemd.services.eko = {
+ description = "Eko - a secure terminal-native social media platform";
+
+ wants = [ "network-online.target" ];
+ after = [ "network-online.target" ];
+ wantedBy = [ "multi-user.target" ];
+
+ reloadTriggers = lib.mapAttrsToList (_: v: v.source or null) (
+ lib.filterAttrs (n: _: lib.hasPrefix "eko/" n) config.environment.etc
+ );
+
+ environment = {
+ EKO_SERVER_CERT_FILE = cfg.certFile;
+ EKO_SERVER_LOG_DIR = cfg.logDir;
+ EKO_SERVER_TOS_FILE = cfg.tosFile;
+ EKO_SERVER_PRIVACY_FILE = cfg.privacyFile;
+ };
+
+ serviceConfig = {
+ Restart = "on-failure";
+ RestartSec = "10s";
+
+ ExecStart = "${cfg.package}/bin/eko-server";
+ ExecReload = "${pkgs.coreutils}/bin/kill -SIGHUP $MAINPID";
+
+ ConfigurationDirectory = "eko";
+ StateDirectory = "eko";
+ StateDirectoryMode = "0700";
+ LogsDirectory = "eko";
+ LogDirectoryMode = "0700";
+ WorkingDirectory = cfg.dataDir;
+ Type = "simple";
+
+ User = "eko";
+ Group = "eko";
+
+ # Hardening
+ ProtectHome = true;
+ ProtectHostname = true;
+ ProtectKernelLogs = true;
+ ProtectKernelModules = true;
+ ProtectKernelTunables = true;
+ ProtectProc = "invisible";
+ RestrictAddressFamilies = [
+ "AF_INET"
+ "AF_INET6"
+ "AF_UNIX"
+ ];
+ RestrictNamespaces = true;
+ RestrictRealtime = true;
+ RestrictSUIDSGID = true;
+ PrivateUsers = true;
+ PrivateTmp = true;
+ ProtectSystem = "strict";
+ NoNewPrivileges = true;
+ };
+ };
+
+ users.groups.eko = { };
+ users.users.eko = {
+ createHome = false;
+ isNormalUser = true;
+ group = "eko";
+ };
+ };
+
+}