summary refs log tree commit diff
diff options
context:
space:
mode:
authorIzorkin <izorkin@elven.pw>2021-05-04 23:13:51 +0300
committerIzorkin <izorkin@elven.pw>2021-05-05 20:46:07 +0300
commit53651179b922485330a96a13cacfe7d08ec0938b (patch)
tree0d7d48c4a617266b77ec865d3a02217811423ec4
parent360ed28868f665a73f3b08801df38c6af984df74 (diff)
downloadnixpkgs-53651179b922485330a96a13cacfe7d08ec0938b.tar
nixpkgs-53651179b922485330a96a13cacfe7d08ec0938b.tar.gz
nixpkgs-53651179b922485330a96a13cacfe7d08ec0938b.tar.bz2
nixpkgs-53651179b922485330a96a13cacfe7d08ec0938b.tar.lz
nixpkgs-53651179b922485330a96a13cacfe7d08ec0938b.tar.xz
nixpkgs-53651179b922485330a96a13cacfe7d08ec0938b.tar.zst
nixpkgs-53651179b922485330a96a13cacfe7d08ec0938b.zip
nixos/netdata: update capabilities
-rw-r--r--nixos/modules/services/monitoring/netdata.nix5
1 files changed, 5 insertions, 0 deletions
diff --git a/nixos/modules/services/monitoring/netdata.nix b/nixos/modules/services/monitoring/netdata.nix
index a6ecc2a566c..c2ee1c0df7f 100644
--- a/nixos/modules/services/monitoring/netdata.nix
+++ b/nixos/modules/services/monitoring/netdata.nix
@@ -183,6 +183,9 @@ in {
         ConfigurationDirectory = "netdata";
         ConfigurationDirectoryMode = "0755";
         # Capabilities
+        AmbientCapabilities = [
+          "CAP_SETUID"            # is required for cgroups and cgroups-network plugins
+        ];
         CapabilityBoundingSet = [
           "CAP_DAC_OVERRIDE"      # is required for freeipmi and slabinfo plugins
           "CAP_DAC_READ_SEARCH"   # is required for apps plugin
@@ -192,6 +195,8 @@ in {
           "CAP_SYS_PTRACE"        # is required for apps plugin
           "CAP_SYS_RESOURCE"      # is required for ebpf plugin
           "CAP_NET_RAW"           # is required for fping app
+          "CAP_SYS_CHROOT"        # is required for cgroups plugin
+          "CAP_SETUID"            # is required for cgroups and cgroups-network plugins
         ];
         # Sandboxing
         ProtectSystem = "full";