3
0
Fork 0
forked from mirrors/nixpkgs
nixpkgs/nixos/modules/services/misc
Martin Weinelt 79e675444c
nixos/matrix-synapse: protect created files
Enforce UMask on the systemd unit to restrict the permissions of files
created. Especially the homeserver signing key should not be world
readable, and media is served through synapse itself, so no other user
needs access to these files.

Use a prestart chmod to fixup the permissions on the signing key.
2021-05-22 20:30:49 +02:00
..
taskserver
airsonic.nix airsonic: force use of jre8 2021-05-03 09:41:04 -06:00
ankisyncd.nix
apache-kafka.nix nixos/apache-kafka: Use version-matched jre 2021-03-10 08:10:30 +01:00
autofs.nix nixos/autofs: add timeout type 2021-01-24 13:17:07 +01:00
autorandr.nix treewide: remove gnidorah 2021-04-30 01:48:19 +02:00
bazarr.nix nixos/users: require one of users.users.name.{isSystemUser,isNormalUser} 2021-04-14 20:40:00 +02:00
beanstalkd.nix
bees.nix
bepasty.nix
calibre-server.nix
canto-daemon.nix
cfdyndns.nix nixos/cfdyndns: add apikeyFile option 2020-11-10 14:00:16 +01:00
cgminer.nix nixos/cgminer: add types 2021-01-26 12:24:48 +01:00
clipmenu.nix
confd.nix
couchpotato.nix
cpuminer-cryptonight.nix
dendrite.nix nixos/matrix-dendrite: rename to dendrite 2021-05-05 12:38:02 +02:00
devmon.nix
dictd.nix treewide: fix double quoted strings in meta.description 2021-01-24 19:56:59 +07:00
disnix.nix nixos/disnix: configure the remote client by default, if multi-user mode has been enabled 2021-05-06 19:33:02 +02:00
docker-registry.nix
domoticz.nix
duckling.nix init duckling service 2021-04-27 10:41:07 -07:00
dwm-status.nix
dysnomia.nix nixos/dysnomia: configure systemd unit path 2021-03-28 21:39:23 +02:00
errbot.nix
etcd.nix
etebase-server.nix nixos/etebase-server: do not prompt for input during automatic upgrade 2021-04-16 13:08:42 +02:00
etesync-dav.nix nixos/etesync-dav: init module 2021-02-17 10:43:08 +01:00
ethminer.nix
exhibitor.nix treewide: fix double quoted strings in meta.description 2021-01-24 19:56:59 +07:00
felix.nix nixos/felix: add types 2021-01-27 11:44:59 -08:00
freeswitch.nix
fstrim.nix treewide: remove gnidorah 2021-04-30 01:48:19 +02:00
gammu-smsd.nix
geoip-updater.nix
gitea.nix nixos/gitea: set umask for secret creation 2021-04-30 21:39:11 +02:00
gitit.nix nixos: use functionTo to prevent evaluation errors while merging 2021-01-24 17:18:37 +01:00
gitlab.nix nixos/gitlab: Use replace-secret to avoid leaking secrets 2021-05-19 09:32:12 +02:00
gitlab.xml nixos/gitlab: Document automatic backups 2021-03-30 19:15:33 +02:00
gitolite.nix gitAndTools: move everything to the top level 2021-01-14 21:27:48 +00:00
gitweb.nix treewide: remove gnidorah 2021-04-30 01:48:19 +02:00
gogs.nix gogs: 0.11.91 -> 0.12.3 2020-11-28 06:50:52 +01:00
gollum.nix gollum: Transfer maintainership to erictapen 2021-02-27 21:39:16 +01:00
gpsd.nix
greenclip.nix
headphones.nix
home-assistant.nix nixos/home-assistant: allow netlink sockets and /proc/net inspection 2021-05-06 16:55:53 +02:00
ihaskell.nix nixos: use functionTo to prevent evaluation errors while merging 2021-01-24 17:18:37 +01:00
irkerd.nix
jackett.nix
jellyfin.nix treewide: remove duplicates SystemCallFilters 2021-05-13 15:44:56 +03:00
klipper.nix
leaps.nix
lidarr.nix
lifecycled.nix nixos/lifecycled: init 2021-03-03 11:15:35 -08:00
logkeys.nix
mame.nix treewide: remove gnidorah 2021-04-30 01:48:19 +02:00
matrix-appservice-discord.nix nixos/matrix-appservice-discord: update module for v1.0.0 2020-12-27 12:59:11 +01:00
matrix-appservice-irc.nix modules.matrix-appservice-irc: allow connecting to unix sockets 2021-04-20 15:48:50 +08:00
matrix-synapse-log_config.yaml
matrix-synapse.nix nixos/matrix-synapse: protect created files 2021-05-22 20:30:49 +02:00
matrix-synapse.xml nixos/services/matrix-synapse: fix eval errors in manual example 2021-04-16 18:13:42 +02:00
mautrix-telegram.nix nixos/mautrix-telegram: substitute secrets in config file at runtime (#112966) 2021-03-13 13:56:17 +01:00
mbpfan.nix
mediatomb.nix
metabase.nix
mwlib.nix
n8n.nix nixos/n8n: init module and test 2020-12-05 11:02:40 +01:00
nix-daemon.nix nixos/users: require one of users.users.name.{isSystemUser,isNormalUser} 2021-04-14 20:40:00 +02:00
nix-gc.nix nixos/nix-gc: add persistent and randomizeDelaySec options 2021-02-28 04:21:21 -05:00
nix-optimise.nix
nix-ssh-serve.nix
novacomd.nix
nzbget.nix
nzbhydra2.nix nixos/nzbhydra2: init 2020-12-21 19:41:24 +01:00
octoprint.nix nixos: use functionTo to prevent evaluation errors while merging 2021-01-24 17:18:37 +01:00
ombi.nix nixos/ombi: set ombi as system user 2021-04-29 10:52:02 +03:00
osrm.nix
packagekit.nix nixos/packagekit: RFC42 support and drop pointless setting 2021-04-06 11:41:37 +08:00
paperless.nix
parsoid.nix
pinnwand.nix nixos/pinnwand: add reaper systemd unit/timer 2021-05-03 16:52:05 +02:00
plex.nix
plikd.nix nixos/plikd: Add new service module 2021-02-23 15:35:16 +01:00
podgrab.nix nixos/podgrab: add module 2021-04-15 20:57:21 +00:00
pykms.nix nixos/pykms: fix launcher 2021-02-03 15:59:17 +08:00
radarr.nix
redmine.nix treewide: unzip buldInputs to nativeBuildInputs (2) 2021-03-06 15:18:05 +07:00
ripple-data-api.nix
rippled.nix nixos/rippled: add extraConfig type 2021-01-31 12:10:14 +01:00
safeeyes.nix nixos/modules: fix systemd start rate-limits 2020-10-31 01:35:56 -07:00
serviio.nix
sickbeard.nix
siproxd.nix nixos/*: fix indentation 2020-11-23 08:42:51 +10:00
snapper.nix nixos/snapper: improve config example 2021-01-17 19:13:35 +11:00
sonarr.nix
spice-vdagentd.nix
ssm-agent.nix nixos/ssm-agent: conf files written to /etc 2021-05-10 13:16:41 -07:00
sssd.nix
subsonic.nix
sundtek.nix
svnserve.nix nixos/svnserve: add svnBaseDir type 2021-01-31 12:15:45 +01:00
synergy.nix nixos/synergy: add types 2021-01-31 12:17:41 +01:00
sysprof.nix
tautulli.nix
tiddlywiki.nix
tzupdate.nix
uhub.nix
weechat.nix nixos/weechat: add binary 2021-01-31 12:59:04 +01:00
weechat.xml
xmr-stak.nix
zigbee2mqtt.nix nixos/zigbee2mqtt: start maintaing the module 2021-04-30 20:40:04 +02:00
zoneminder.nix
zookeeper.nix nixos/zookeeper: adapt to zookeeper 3.6.2 2020-12-09 15:46:38 +01:00