summary refs log tree commit diff
diff options
context:
space:
mode:
authorJörg Thalheim <joerg@thalheim.io>2020-02-28 14:31:18 +0000
committerJörg Thalheim <joerg@thalheim.io>2020-02-28 15:34:37 +0000
commit8b7f4fa8a64b141cd103689789909a30a7b972d1 (patch)
tree240a5c800f6791b8bfbf58025341ea871d72242d
parent250daba4bec759451feaaa5eba778bb53e9c389e (diff)
downloadnixpkgs-8b7f4fa8a64b141cd103689789909a30a7b972d1.tar
nixpkgs-8b7f4fa8a64b141cd103689789909a30a7b972d1.tar.gz
nixpkgs-8b7f4fa8a64b141cd103689789909a30a7b972d1.tar.bz2
nixpkgs-8b7f4fa8a64b141cd103689789909a30a7b972d1.tar.lz
nixpkgs-8b7f4fa8a64b141cd103689789909a30a7b972d1.tar.xz
nixpkgs-8b7f4fa8a64b141cd103689789909a30a7b972d1.tar.zst
nixpkgs-8b7f4fa8a64b141cd103689789909a30a7b972d1.zip
nixos/buildkite-agents: don't run as nogroup
-rw-r--r--nixos/modules/services/continuous-integration/buildkite-agents.nix4
1 files changed, 4 insertions, 0 deletions
diff --git a/nixos/modules/services/continuous-integration/buildkite-agents.nix b/nixos/modules/services/continuous-integration/buildkite-agents.nix
index c17d89c387a..b0045409ae6 100644
--- a/nixos/modules/services/continuous-integration/buildkite-agents.nix
+++ b/nixos/modules/services/continuous-integration/buildkite-agents.nix
@@ -208,8 +208,12 @@ in
       description = "Buildkite agent user";
       extraGroups = [ "keys" ];
       isSystemUser = true;
+      group = "buildkite-agent-${name}";
     };
   });
+  config.users.groups = mapAgents (name: cfg: {
+    "buildkite-agent-${name}" = {};
+  });
 
   config.systemd.services = mapAgents (name: cfg: {
     "buildkite-agent-${name}" =