summary refs log tree commit diff
diff options
context:
space:
mode:
authorRobert Hensing <robert@roberthensing.nl>2021-05-25 10:22:29 +0200
committerRobert Hensing <robert@roberthensing.nl>2021-05-30 11:21:05 +0200
commitfb8b0a38433c8e83a53c1dc0a739c5a7ad64e2fc (patch)
tree6ebf1463e684606d801c57b2f8b66a3b48ff16a2
parentbfdf04bd21bb99b05bb10f0de8876ad4baca48e4 (diff)
downloadnixpkgs-fb8b0a38433c8e83a53c1dc0a739c5a7ad64e2fc.tar
nixpkgs-fb8b0a38433c8e83a53c1dc0a739c5a7ad64e2fc.tar.gz
nixpkgs-fb8b0a38433c8e83a53c1dc0a739c5a7ad64e2fc.tar.bz2
nixpkgs-fb8b0a38433c8e83a53c1dc0a739c5a7ad64e2fc.tar.lz
nixpkgs-fb8b0a38433c8e83a53c1dc0a739c5a7ad64e2fc.tar.xz
nixpkgs-fb8b0a38433c8e83a53c1dc0a739c5a7ad64e2fc.tar.zst
nixpkgs-fb8b0a38433c8e83a53c1dc0a739c5a7ad64e2fc.zip
nixos/podman: Change podman socket to new podman group
-rw-r--r--nixos/modules/virtualisation/podman.nix15
1 files changed, 13 insertions, 2 deletions
diff --git a/nixos/modules/virtualisation/podman.nix b/nixos/modules/virtualisation/podman.nix
index d6421d488b8..e879b5ad8f9 100644
--- a/nixos/modules/virtualisation/podman.nix
+++ b/nixos/modules/virtualisation/podman.nix
@@ -111,8 +111,19 @@ in
       };
 
       systemd.sockets.podman.wantedBy = [ "sockets.target" ];
-
-      systemd.tmpfiles.packages = [ cfg.package ];
+      systemd.sockets.podman.socketConfig.SocketGroup = "podman";
+
+      systemd.tmpfiles.packages = [
+        # The /run/podman rule interferes with our podman group, so we remove
+        # it and let the systemd socket logic take care of it.
+        (pkgs.runCommand "podman-tmpfiles-nixos" { package = cfg.package; } ''
+          mkdir -p $out/lib/tmpfiles.d/
+          grep -v 'D! /run/podman 0700 root root' \
+            <$package/lib/tmpfiles.d/podman.conf \
+            >$out/lib/tmpfiles.d/podman.conf
+        '') ];
+
+      users.groups.podman = {};
 
       assertions = [
         {