ca4a0b23ab
- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/ X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail upstream copies via header_down on mail.severijnse.eu - tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync _25/_465/_993, fail-safe placeholders; coredns zone updated - pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint, ...); CI pre-commit job over x86_64 + aarch64 matrix - gitea: enable Gitea Actions + self-hosted runner (native:host, aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook - fix statix warnings (merge repeated systemd/database/configFile keys, inherit, bool-compare guards); add missing trailing newlines
24 lines
759 B
Nix
24 lines
759 B
Nix
{...}: {
|
|
virtualisation.oci-containers.containers.snappymail = {
|
|
image = "djmaze/snappymail:latest";
|
|
autoStart = true;
|
|
ports = ["127.0.0.1:8888:8888"];
|
|
volumes = [
|
|
"/home/admin/snappymail-data:/var/lib/snappymail:Z"
|
|
];
|
|
environment = {
|
|
TZ = "Europe/Berlin";
|
|
};
|
|
extraOptions = [
|
|
"--label=com.centurylinklabs.watchtower.enable=true"
|
|
];
|
|
};
|
|
|
|
# Ensure the persistent data dir exists so podman's :Z relabel (statfs) succeeds on first boot.
|
|
# Owned by 82:82 (www-data) because the container's PHP worker runs as UID 82 and must be
|
|
# able to write to /var/lib/snappymail (SnappyMail checks is_writable on that path).
|
|
systemd.tmpfiles.rules = [
|
|
"d /home/admin/snappymail-data 0755 82 82 - -"
|
|
];
|
|
}
|