summaryrefslogtreecommitdiff
path: root/service.nix
diff options
context:
space:
mode:
authorKyren223 <Kyren223@proton.me>2025-07-22 17:05:08 +0300
committerKyren223 <Kyren223@proton.me>2025-07-22 17:05:08 +0300
commite6cfdac5a83d8d2e2664e3b313900b7b1a145114 (patch)
treeea2e23feb6945b5900483611d5577b5fe287a145 /service.nix
parentc2db60b773ad54e6991ca21b2775f9ed408c1cf9 (diff)
Improved flake.nix and added service.nix to run the server as a NixOS
systemd service
Diffstat (limited to 'service.nix')
-rw-r--r--service.nix118
1 files changed, 118 insertions, 0 deletions
diff --git a/service.nix b/service.nix
new file mode 100644
index 0000000..9e9e437
--- /dev/null
+++ b/service.nix
@@ -0,0 +1,118 @@
+inputs:
+{
+ config,
+ pkgs,
+ lib,
+ ...
+}:
+let
+ cfg = config.services.eko;
+in
+{
+ meta.maintainers = with lib.maintainers; [ kyren223 ];
+
+ options.services.eko = {
+ enable = lib.mkEnableOption "eko service";
+
+ package = lib.mkPackageOption inputs.self.packages.${pkgs.stdenv.hostPlatform.system}.eko-server { };
+
+ dataDir = lib.mkOption {
+ description = "Eko data directory";
+ default = "/var/lib/eko";
+ type = lib.types.path;
+ };
+
+ logDir = lib.mkOption {
+ description = "Eko logs directory";
+ default = "/var/log/eko";
+ type = lib.types.path;
+ };
+
+ tosFile = lib.mkOption {
+ description = "Eko terms of service file";
+ default = "/etc/eko/tos.md";
+ type = lib.types.path;
+ };
+
+ privacyFile = lib.mkOption {
+ description = "Eko privacy policy file";
+ default = "/etc/eko/privacy.md";
+ type = lib.types.path;
+ };
+
+ certFile = lib.mkOption {
+ description = "Eko certificate key file";
+ type = lib.types.path;
+ };
+
+ };
+
+ config = lib.mkIf cfg.enable {
+
+ systemd.services.eko = {
+ description = "Eko - a secure terminal-native social media platform";
+
+ wants = [ "network-online.target" ];
+ after = [ "network-online.target" ];
+ wantedBy = [ "multi-user.target" ];
+
+ reloadTriggers = lib.mapAttrsToList (_: v: v.source or null) (
+ lib.filterAttrs (n: _: lib.hasPrefix "eko/" n) config.environment.etc
+ );
+
+ environment = {
+ EKO_SERVER_CERT_FILE = cfg.certFile;
+ EKO_SERVER_LOG_DIR = cfg.logDir;
+ EKO_SERVER_TOS_FILE = cfg.tosFile;
+ EKO_SERVER_PRIVACY_FILE = cfg.privacyFile;
+ };
+
+ serviceConfig = {
+ Restart = "on-failure";
+ RestartSec = "10s";
+
+ ExecStart = "${cfg.package}/bin/eko-server";
+ ExecReload = "${pkgs.coreutils}/bin/kill -SIGHUP $MAINPID";
+
+ ConfigurationDirectory = "eko";
+ StateDirectory = "eko";
+ StateDirectoryMode = "0700";
+ LogsDirectory = "eko";
+ LogDirectoryMode = "0700";
+ WorkingDirectory = cfg.dataDir;
+ Type = "simple";
+
+ User = "eko";
+ Group = "eko";
+
+ # Hardening
+ ProtectHome = true;
+ ProtectHostname = true;
+ ProtectKernelLogs = true;
+ ProtectKernelModules = true;
+ ProtectKernelTunables = true;
+ ProtectProc = "invisible";
+ RestrictAddressFamilies = [
+ "AF_INET"
+ "AF_INET6"
+ "AF_UNIX"
+ ];
+ RestrictNamespaces = true;
+ RestrictRealtime = true;
+ RestrictSUIDSGID = true;
+ PrivateUsers = true;
+ PrivateTmp = true;
+ ProtectSystem = "strict";
+ NoNewPrivileges = true;
+ };
+ };
+
+ users.groups.eko = { };
+ users.users.eko = {
+ createHome = false;
+ isNormalUser = true;
+ group = "eko";
+ };
+ };
+
+}