nixos/modules/services/groupshare.nix

38 lines
1.4 KiB
Nix
Raw Normal View History

2023-09-12 22:43:38 +08:00
inputs:
{
options.nixos.services.groupshare = let inherit (inputs.lib) mkOption types; in
{
enable = mkOption { type = types.bool; default = false; };
2023-09-13 02:12:41 +08:00
# hard to read value from inputs.config.users.users.xxx.home, causing infinite recursion
mountPoints = mkOption { type = types.listOf types.str; default = []; };
2023-09-12 22:43:38 +08:00
};
config =
let
inherit (inputs.lib) mkIf;
inherit (builtins) listToAttrs map concatLists;
inherit (inputs.config.nixos.services) groupshare;
users = inputs.config.users.groups.groupshare.members;
in mkIf groupshare.enable
{
users.groups.groupshare = {};
systemd.tmpfiles.rules = [ "d /var/lib/groupshare" ]
2023-09-13 02:12:41 +08:00
++ (concatLists (map
(user:
[
2023-09-13 21:32:02 +08:00
"d /var/lib/groupshare/${user} 7750 ${user} groupshare"
# systemd 253 does not support 'X' bit, it should be manually set
# sudo setfacl -m 'xxx' dir
# ("a /var/lib/groupshare/${user} - - - - "
# + "d:u:${user}:rwX,u:${user}:rwX,d:g:groupshare:r-X,g:groupshare:r-X,d:o::---,o::---")
2023-09-13 02:12:41 +08:00
])
users));
2023-09-12 22:43:38 +08:00
fileSystems = listToAttrs (map
2023-09-13 02:12:41 +08:00
(mountPoint:
2023-09-12 22:43:38 +08:00
{
2023-09-13 02:12:41 +08:00
name = mountPoint;
value = { device = "/var/lib/groupshare"; options = [ "bind" ]; depends = [ "/home" "/var/lib" ]; };
2023-09-12 22:43:38 +08:00
})
2023-09-13 02:12:41 +08:00
groupshare.mountPoints);
2023-09-12 22:43:38 +08:00
};
2023-09-13 02:12:41 +08:00
}