summaryrefslogtreecommitdiff
path: root/service.nix
blob: 4cc39b3bdb7396fe583a0d030ac43d9bf8d4631b (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
inputs:
{
  config,
  pkgs,
  lib,
  ...
}:
let
  cfg = config.services.eko;
in
{
  meta.maintainers = with lib.maintainers; [ kyren223 ];

  options.services.eko = {
    enable = lib.mkEnableOption "eko service";

    package = lib.mkOption {
      description = "Eko package to use as the server executable";
      default = inputs.self.packages.${pkgs.system}.eko-server;
      type = lib.types.package;
    };

    dataDir = lib.mkOption {
      description = "Eko data directory";
      default = "/var/lib/eko";
      type = lib.types.path;
    };

    logDir = lib.mkOption {
      description = "Eko logs directory";
      default = "/var/log/eko";
      type = lib.types.path;
    };

    tosFile = lib.mkOption {
      description = "Eko terms of service file";
      default = "/etc/eko/tos.md";
      type = lib.types.path;
    };

    privacyFile = lib.mkOption {
      description = "Eko privacy policy file";
      default = "/etc/eko/privacy.md";
      type = lib.types.path;
    };

    certFile = lib.mkOption {
      description = "Eko certificate key file";
      type = lib.types.path;
    };

  };

  config = lib.mkIf cfg.enable {

    systemd.services.eko = {
      description = "Eko - a secure terminal-native social media platform";

      wants = [ "network-online.target" ];
      after = [ "network-online.target" ];
      wantedBy = [ "multi-user.target" ];

      reloadTriggers = lib.mapAttrsToList (_: v: v.source or null) (
        lib.filterAttrs (n: _: lib.hasPrefix "eko/" n) config.environment.etc
      );

      environment = {
        EKO_SERVER_CERT_FILE = cfg.certFile;
        EKO_SERVER_LOG_DIR = cfg.logDir;
        EKO_SERVER_TOS_FILE = cfg.tosFile;
        EKO_SERVER_PRIVACY_FILE = cfg.privacyFile;
      };

      serviceConfig = {
        Restart = "on-failure";
        RestartSec = "10s";

        ExecStart = "${cfg.package}/bin/eko-server";
        ExecReload = "${pkgs.coreutils}/bin/kill -SIGHUP $MAINPID";

        ConfigurationDirectory = "eko";
        StateDirectory = "eko";
        StateDirectoryMode = "0700";
        LogsDirectory = "eko";
        LogDirectoryMode = "0700";
        WorkingDirectory = cfg.dataDir;
        Type = "simple";

        User = "eko";
        Group = "eko";

        # Hardening
        ProtectHome = true;
        ProtectHostname = true;
        ProtectKernelLogs = true;
        ProtectKernelModules = true;
        ProtectKernelTunables = true;
        ProtectProc = "invisible";
        RestrictAddressFamilies = [
          "AF_INET"
          "AF_INET6"
          "AF_UNIX"
        ];
        RestrictNamespaces = true;
        RestrictRealtime = true;
        RestrictSUIDSGID = true;
        PrivateUsers = true;
        PrivateTmp = true;
        ProtectSystem = "strict";
        NoNewPrivileges = true;
      };
    };

    users.groups.eko = { };
    users.users.eko = {
      createHome = false;
      isNormalUser = true;
      group = "eko";
    };
  };

}