Even less security

This commit is contained in:
Sarah 2021-10-17 14:13:04 +02:00
parent 4ee7a3abc1
commit 1743539d93
No known key found for this signature in database
GPG key ID: 708F7ACE058F0186

View file

@ -61,7 +61,7 @@ in
User = cfg.user;
Group = cfg.group;
PrivateMounts = true;
# PrivateMounts = true;
# PrivateDevices = true;
# PrivateTmp = true;
# PrivateIPC = true;
@ -90,20 +90,20 @@ in
# ProtectControlGroups = true;
# RestrictNamespaces = "";
NoNewPrivileges = true;
ReadOnlyPaths = lib.mkMerge [
([
"/nix/var"
"/nix/store"
])
# NoNewPrivileges = true;
# ReadOnlyPaths = lib.mkMerge [
# ([
# "/nix/var"
# "/nix/store"
# ])
(lib.mkIf (cfg.privateKeyFile != null) [
(toString cfg.privateKeyFile)
])
];
ExecPaths = [
"/nix/store"
];
# (lib.mkIf (cfg.privateKeyFile != null) [
# (toString cfg.privateKeyFile)
# ])
# ];
# ExecPaths = [
# "/nix/store"
# ];
Environment = lib.mkIf (cfg.privateKeyFile != null) [
"NIX_SECRET_KEY_FILE=${toString cfg.privateKeyFile}"
];