matrix: fix synapse/signal permissions

This commit is contained in:
colin 2023-01-18 01:50:28 +00:00
parent 9202345beb
commit 6967c331e2
2 changed files with 4 additions and 0 deletions

View File

@ -9,6 +9,9 @@
./signal.nix
];
# allow synapse to read the registration files of its appservices
users.users.matrix-synapse.extraGroups = [ "mautrix-signal" ];
sane.persist.sys.plaintext = [
{ user = "matrix-synapse"; group = "matrix-synapse"; directory = "/var/lib/matrix-synapse"; }
];

View File

@ -43,6 +43,7 @@
};
};
# TODO: should use a dedicated user
systemd.services.mx-puppet-discord.serviceConfig = {
# fix up to not use /var/lib/private, but just /var/lib
DynamicUser = lib.mkForce false;