From e6cfdac5a83d8d2e2664e3b313900b7b1a145114 Mon Sep 17 00:00:00 2001 From: Kyren223 Date: Tue, 22 Jul 2025 17:05:08 +0300 Subject: Improved flake.nix and added service.nix to run the server as a NixOS systemd service --- service.nix | 118 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 118 insertions(+) create mode 100644 service.nix (limited to 'service.nix') diff --git a/service.nix b/service.nix new file mode 100644 index 0000000..9e9e437 --- /dev/null +++ b/service.nix @@ -0,0 +1,118 @@ +inputs: +{ + config, + pkgs, + lib, + ... +}: +let + cfg = config.services.eko; +in +{ + meta.maintainers = with lib.maintainers; [ kyren223 ]; + + options.services.eko = { + enable = lib.mkEnableOption "eko service"; + + package = lib.mkPackageOption inputs.self.packages.${pkgs.stdenv.hostPlatform.system}.eko-server { }; + + dataDir = lib.mkOption { + description = "Eko data directory"; + default = "/var/lib/eko"; + type = lib.types.path; + }; + + logDir = lib.mkOption { + description = "Eko logs directory"; + default = "/var/log/eko"; + type = lib.types.path; + }; + + tosFile = lib.mkOption { + description = "Eko terms of service file"; + default = "/etc/eko/tos.md"; + type = lib.types.path; + }; + + privacyFile = lib.mkOption { + description = "Eko privacy policy file"; + default = "/etc/eko/privacy.md"; + type = lib.types.path; + }; + + certFile = lib.mkOption { + description = "Eko certificate key file"; + type = lib.types.path; + }; + + }; + + config = lib.mkIf cfg.enable { + + systemd.services.eko = { + description = "Eko - a secure terminal-native social media platform"; + + wants = [ "network-online.target" ]; + after = [ "network-online.target" ]; + wantedBy = [ "multi-user.target" ]; + + reloadTriggers = lib.mapAttrsToList (_: v: v.source or null) ( + lib.filterAttrs (n: _: lib.hasPrefix "eko/" n) config.environment.etc + ); + + environment = { + EKO_SERVER_CERT_FILE = cfg.certFile; + EKO_SERVER_LOG_DIR = cfg.logDir; + EKO_SERVER_TOS_FILE = cfg.tosFile; + EKO_SERVER_PRIVACY_FILE = cfg.privacyFile; + }; + + serviceConfig = { + Restart = "on-failure"; + RestartSec = "10s"; + + ExecStart = "${cfg.package}/bin/eko-server"; + ExecReload = "${pkgs.coreutils}/bin/kill -SIGHUP $MAINPID"; + + ConfigurationDirectory = "eko"; + StateDirectory = "eko"; + StateDirectoryMode = "0700"; + LogsDirectory = "eko"; + LogDirectoryMode = "0700"; + WorkingDirectory = cfg.dataDir; + Type = "simple"; + + User = "eko"; + Group = "eko"; + + # Hardening + ProtectHome = true; + ProtectHostname = true; + ProtectKernelLogs = true; + ProtectKernelModules = true; + ProtectKernelTunables = true; + ProtectProc = "invisible"; + RestrictAddressFamilies = [ + "AF_INET" + "AF_INET6" + "AF_UNIX" + ]; + RestrictNamespaces = true; + RestrictRealtime = true; + RestrictSUIDSGID = true; + PrivateUsers = true; + PrivateTmp = true; + ProtectSystem = "strict"; + NoNewPrivileges = true; + }; + }; + + users.groups.eko = { }; + users.users.eko = { + createHome = false; + isNormalUser = true; + group = "eko"; + }; + }; + +} -- cgit v1.3.1