diff options
Diffstat (limited to 'modules/actual.nix')
| -rw-r--r-- | modules/actual.nix | 20 |
1 files changed, 20 insertions, 0 deletions
diff --git a/modules/actual.nix b/modules/actual.nix index 95bbc7d..b072518 100644 --- a/modules/actual.nix +++ b/modules/actual.nix @@ -11,12 +11,32 @@ # # All budget data is persisted in /var/lib/actual on the host (the module's # own StateDirectory). +# +# Uses a static user rather than the module's default DynamicUser: this +# server previously ran Actual via a hand-rolled Podman container (root +# inside the container = host root), so /var/lib/actual's existing budget +# data is owned by root:root. A DynamicUser gets a fresh ephemeral UID each +# start and can't read pre-existing root-owned files, so the service would +# fail to see the existing budget on switch-over. The tmpfiles rule below +# reclaims ownership for the static user once, recursively. { services.actual = { enable = true; + user = "actual"; + group = "actual"; settings = { hostname = "127.0.0.1"; port = 5006; }; }; + + users.users.actual = { + isSystemUser = true; + group = "actual"; + }; + users.groups.actual = { }; + + systemd.tmpfiles.rules = [ + "Z /var/lib/actual 0700 actual actual - -" + ]; } |
