aboutsummaryrefslogtreecommitdiff
path: root/modules/actual.nix
diff options
context:
space:
mode:
Diffstat (limited to 'modules/actual.nix')
-rw-r--r--modules/actual.nix20
1 files changed, 20 insertions, 0 deletions
diff --git a/modules/actual.nix b/modules/actual.nix
index 95bbc7d..b072518 100644
--- a/modules/actual.nix
+++ b/modules/actual.nix
@@ -11,12 +11,32 @@
#
# All budget data is persisted in /var/lib/actual on the host (the module's
# own StateDirectory).
+#
+# Uses a static user rather than the module's default DynamicUser: this
+# server previously ran Actual via a hand-rolled Podman container (root
+# inside the container = host root), so /var/lib/actual's existing budget
+# data is owned by root:root. A DynamicUser gets a fresh ephemeral UID each
+# start and can't read pre-existing root-owned files, so the service would
+# fail to see the existing budget on switch-over. The tmpfiles rule below
+# reclaims ownership for the static user once, recursively.
{
services.actual = {
enable = true;
+ user = "actual";
+ group = "actual";
settings = {
hostname = "127.0.0.1";
port = 5006;
};
};
+
+ users.users.actual = {
+ isSystemUser = true;
+ group = "actual";
+ };
+ users.groups.actual = { };
+
+ systemd.tmpfiles.rules = [
+ "Z /var/lib/actual 0700 actual actual - -"
+ ];
}