2019-04-18 10:16:02 +02:00
|
|
|
{ config, pkgs, ... }: with import <stockholm/lib>; let
|
2019-05-29 15:47:34 +02:00
|
|
|
all_peers = filterAttrs (n: v: v.syncthing.id != null) config.krebs.hosts;
|
|
|
|
own_peers = filterAttrs (n: v: v.owner.name == "lass") all_peers;
|
|
|
|
mk_peers = mapAttrs (n: v: { id = v.syncthing.id; });
|
2019-04-18 10:16:02 +02:00
|
|
|
in {
|
2017-04-16 23:35:25 +02:00
|
|
|
services.syncthing = {
|
|
|
|
enable = true;
|
2019-04-07 18:44:57 +02:00
|
|
|
group = "syncthing";
|
2019-04-13 16:37:21 +02:00
|
|
|
configDir = "/var/lib/syncthing";
|
2020-04-08 12:33:08 +02:00
|
|
|
declarative = {
|
|
|
|
key = toString <secrets/syncthing.key>;
|
|
|
|
cert = toString <secrets/syncthing.cert>;
|
|
|
|
devices = mk_peers all_peers;
|
|
|
|
folders."/home/lass/sync" = {
|
|
|
|
devices = attrNames (filterAttrs (n: v: n != "phone") own_peers);
|
|
|
|
# ignorePerms = false;
|
|
|
|
};
|
|
|
|
};
|
2017-04-16 23:35:25 +02:00
|
|
|
};
|
|
|
|
krebs.iptables.tables.filter.INPUT.rules = [
|
|
|
|
{ predicate = "-p tcp --dport 22000"; target = "ACCEPT";}
|
|
|
|
{ predicate = "-p udp --dport 21027"; target = "ACCEPT";}
|
|
|
|
];
|
2019-04-07 18:44:57 +02:00
|
|
|
|
|
|
|
system.activationScripts.syncthing-home = ''
|
|
|
|
${pkgs.coreutils}/bin/chmod a+x /home/lass
|
|
|
|
'';
|
|
|
|
|
2019-04-18 10:16:02 +02:00
|
|
|
krebs.permown."/home/lass/sync" = {
|
2019-05-29 15:47:58 +02:00
|
|
|
file-mode = "u+rw,g+rw";
|
2019-04-18 10:16:02 +02:00
|
|
|
owner = "lass";
|
|
|
|
group = "syncthing";
|
2019-05-29 15:47:58 +02:00
|
|
|
umask = "0002";
|
2019-04-18 10:16:02 +02:00
|
|
|
};
|
2017-04-16 23:35:25 +02:00
|
|
|
}
|