diff options
| author | Kyren223 <Kyren223@proton.me> | 2025-07-22 17:05:08 +0300 |
|---|---|---|
| committer | Kyren223 <Kyren223@proton.me> | 2025-07-22 17:05:08 +0300 |
| commit | e6cfdac5a83d8d2e2664e3b313900b7b1a145114 (patch) | |
| tree | ea2e23feb6945b5900483611d5577b5fe287a145 | |
| parent | c2db60b773ad54e6991ca21b2775f9ed408c1cf9 (diff) | |
Improved flake.nix and added service.nix to run the server as a NixOS
systemd service
| -rw-r--r-- | flake.nix | 28 | ||||
| -rw-r--r-- | service.nix | 118 |
2 files changed, 144 insertions, 2 deletions
@@ -1,5 +1,6 @@ { description = "Localias is a tool for developers to securely manage local aliases for development servers."; + inputs = { nixpkgs.url = "github:nixos/nixpkgs"; @@ -23,9 +24,14 @@ version = (builtins.readFile ./VERSION); buildDate = builtins.readFile ( pkgs.runCommand "build-date" { } '' - date -u +'%Y-%m-%d' > $out + ${pkgs.coreutils}/bin/date --date=@${toString self.lastModified} +%Y-%m-%d -u > $out '' ); + # buildDate = builtins.readFile ( + # pkgs.runCommand "build-date" { } '' + # date -u +'%Y-%m-%d' > $out + # '' + # ); commit = if (builtins.hasAttr "rev" self) then (builtins.substring 0 7 self.rev) else "unknown"; # vendorHash = pkgs.lib.fakeHash; vendorHash = "sha256-2yCQ40T5N90lKpPOc+i6vz+1mI/p4Ey6PdRCJbGD+TE="; @@ -82,15 +88,33 @@ eko = { type = "app"; program = "${packages.eko}/bin/eko"; + meta = { + description = "A terminal-native social media platform (client)"; + homepage = "https://github.com/kyren223/eko"; + license = pkgs.lib.licenses.agpl3Plus; + maintainers = with pkgs.lib.maintainers; [ kyren223 ]; + platforms = pkgs.lib.platforms.all; + }; }; eko-server = { type = "service"; program = "${packages.eko}/bin/eko-server"; - # TODO: add systemd service + meta = { + description = "A terminal-native social media platform (server)"; + homepage = "https://github.com/kyren223/eko"; + license = pkgs.lib.licenses.agpl3Plus; + maintainers = with pkgs.lib.maintainers; [ kyren223 ]; + platforms = pkgs.lib.platforms.all; + }; }; default = eko; }; + nixosModules = rec { + default = eko; + eko = import ./service.nix inputs; + }; + # TODO: make my own devshell? # devShells = rec { # default = pkgs.mkShell { diff --git a/service.nix b/service.nix new file mode 100644 index 0000000..9e9e437 --- /dev/null +++ b/service.nix @@ -0,0 +1,118 @@ +inputs: +{ + config, + pkgs, + lib, + ... +}: +let + cfg = config.services.eko; +in +{ + meta.maintainers = with lib.maintainers; [ kyren223 ]; + + options.services.eko = { + enable = lib.mkEnableOption "eko service"; + + package = lib.mkPackageOption inputs.self.packages.${pkgs.stdenv.hostPlatform.system}.eko-server { }; + + dataDir = lib.mkOption { + description = "Eko data directory"; + default = "/var/lib/eko"; + type = lib.types.path; + }; + + logDir = lib.mkOption { + description = "Eko logs directory"; + default = "/var/log/eko"; + type = lib.types.path; + }; + + tosFile = lib.mkOption { + description = "Eko terms of service file"; + default = "/etc/eko/tos.md"; + type = lib.types.path; + }; + + privacyFile = lib.mkOption { + description = "Eko privacy policy file"; + default = "/etc/eko/privacy.md"; + type = lib.types.path; + }; + + certFile = lib.mkOption { + description = "Eko certificate key file"; + type = lib.types.path; + }; + + }; + + config = lib.mkIf cfg.enable { + + systemd.services.eko = { + description = "Eko - a secure terminal-native social media platform"; + + wants = [ "network-online.target" ]; + after = [ "network-online.target" ]; + wantedBy = [ "multi-user.target" ]; + + reloadTriggers = lib.mapAttrsToList (_: v: v.source or null) ( + lib.filterAttrs (n: _: lib.hasPrefix "eko/" n) config.environment.etc + ); + + environment = { + EKO_SERVER_CERT_FILE = cfg.certFile; + EKO_SERVER_LOG_DIR = cfg.logDir; + EKO_SERVER_TOS_FILE = cfg.tosFile; + EKO_SERVER_PRIVACY_FILE = cfg.privacyFile; + }; + + serviceConfig = { + Restart = "on-failure"; + RestartSec = "10s"; + + ExecStart = "${cfg.package}/bin/eko-server"; + ExecReload = "${pkgs.coreutils}/bin/kill -SIGHUP $MAINPID"; + + ConfigurationDirectory = "eko"; + StateDirectory = "eko"; + StateDirectoryMode = "0700"; + LogsDirectory = "eko"; + LogDirectoryMode = "0700"; + WorkingDirectory = cfg.dataDir; + Type = "simple"; + + User = "eko"; + Group = "eko"; + + # Hardening + ProtectHome = true; + ProtectHostname = true; + ProtectKernelLogs = true; + ProtectKernelModules = true; + ProtectKernelTunables = true; + ProtectProc = "invisible"; + RestrictAddressFamilies = [ + "AF_INET" + "AF_INET6" + "AF_UNIX" + ]; + RestrictNamespaces = true; + RestrictRealtime = true; + RestrictSUIDSGID = true; + PrivateUsers = true; + PrivateTmp = true; + ProtectSystem = "strict"; + NoNewPrivileges = true; + }; + }; + + users.groups.eko = { }; + users.users.eko = { + createHome = false; + isNormalUser = true; + group = "eko"; + }; + }; + +} |
