diff options
author | Robert Hensing <robert@roberthensing.nl> | 2021-05-25 10:22:29 +0200 |
---|---|---|
committer | Robert Hensing <robert@roberthensing.nl> | 2021-05-30 11:21:05 +0200 |
commit | fb8b0a38433c8e83a53c1dc0a739c5a7ad64e2fc (patch) | |
tree | 6ebf1463e684606d801c57b2f8b66a3b48ff16a2 | |
parent | bfdf04bd21bb99b05bb10f0de8876ad4baca48e4 (diff) | |
download | nixpkgs-fb8b0a38433c8e83a53c1dc0a739c5a7ad64e2fc.tar nixpkgs-fb8b0a38433c8e83a53c1dc0a739c5a7ad64e2fc.tar.gz nixpkgs-fb8b0a38433c8e83a53c1dc0a739c5a7ad64e2fc.tar.bz2 nixpkgs-fb8b0a38433c8e83a53c1dc0a739c5a7ad64e2fc.tar.lz nixpkgs-fb8b0a38433c8e83a53c1dc0a739c5a7ad64e2fc.tar.xz nixpkgs-fb8b0a38433c8e83a53c1dc0a739c5a7ad64e2fc.tar.zst nixpkgs-fb8b0a38433c8e83a53c1dc0a739c5a7ad64e2fc.zip |
nixos/podman: Change podman socket to new podman group
-rw-r--r-- | nixos/modules/virtualisation/podman.nix | 15 |
1 files changed, 13 insertions, 2 deletions
diff --git a/nixos/modules/virtualisation/podman.nix b/nixos/modules/virtualisation/podman.nix index d6421d488b8..e879b5ad8f9 100644 --- a/nixos/modules/virtualisation/podman.nix +++ b/nixos/modules/virtualisation/podman.nix @@ -111,8 +111,19 @@ in }; systemd.sockets.podman.wantedBy = [ "sockets.target" ]; - - systemd.tmpfiles.packages = [ cfg.package ]; + systemd.sockets.podman.socketConfig.SocketGroup = "podman"; + + systemd.tmpfiles.packages = [ + # The /run/podman rule interferes with our podman group, so we remove + # it and let the systemd socket logic take care of it. + (pkgs.runCommand "podman-tmpfiles-nixos" { package = cfg.package; } '' + mkdir -p $out/lib/tmpfiles.d/ + grep -v 'D! /run/podman 0700 root root' \ + <$package/lib/tmpfiles.d/podman.conf \ + >$out/lib/tmpfiles.d/podman.conf + '') ]; + + users.groups.podman = {}; assertions = [ { |