summaryrefslogtreecommitdiffstats
path: root/lass/2configs/syncthing.nix
blob: fc10b2cb4c150c674e56ea4fb7ead1b9164bc7bc (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
{ config, pkgs, ... }:
with import <stockholm/lib>;
{
  services.syncthing = {
    enable = true;
    group = "syncthing";
    configDir = "/var/lib/syncthing";
  };
  krebs.iptables.tables.filter.INPUT.rules = [
    { predicate = "-p tcp --dport 22000"; target = "ACCEPT";}
    { predicate = "-p udp --dport 21027"; target = "ACCEPT";}
  ];
  krebs.syncthing = {
    enable = true;
    cert = toString <secrets/syncthing.cert>;
    key = toString <secrets/syncthing.key>;
    peers = mapAttrs (n: v: { id = v.syncthing.id; }) (filterAttrs (n: v: v.syncthing.id != null) config.krebs.hosts);
    folders = [
      { path = "/home/lass/sync"; peers = [ "icarus" "mors" "skynet" "blue" "green" "littleT" "prism" "shodan" ]; }
    ];
  };

  system.activationScripts.syncthing-home = ''
    ${pkgs.coreutils}/bin/chmod a+x /home/lass
  '';

  lass.ensure-permissions = [
    { folder = "/home/lass/sync"; owner = "lass"; group = "syncthing"; }
  ];
}