diff options
author | xeji <xeji@cat3.de> | 2018-02-25 14:22:23 +0100 |
---|---|---|
committer | xeji <xeji@cat3.de> | 2018-04-12 23:29:20 +0200 |
commit | a82aae30846c9531058a767fd8cab90fd59fafe7 (patch) | |
tree | 6c7969d92e8c96de0bcc04248b85dc8c34df2679 /nixos/modules/virtualisation/containers.nix | |
parent | 65e6a5081d17b878d530e053e7876c19c8c1a0da (diff) | |
download | nixpkgs-a82aae30846c9531058a767fd8cab90fd59fafe7.tar nixpkgs-a82aae30846c9531058a767fd8cab90fd59fafe7.tar.gz nixpkgs-a82aae30846c9531058a767fd8cab90fd59fafe7.tar.bz2 nixpkgs-a82aae30846c9531058a767fd8cab90fd59fafe7.tar.lz nixpkgs-a82aae30846c9531058a767fd8cab90fd59fafe7.tar.xz nixpkgs-a82aae30846c9531058a767fd8cab90fd59fafe7.tar.zst nixpkgs-a82aae30846c9531058a767fd8cab90fd59fafe7.zip |
nixos/containers: add extraFlags option
to pass extra flags to systemd-nspawn
Diffstat (limited to 'nixos/modules/virtualisation/containers.nix')
-rw-r--r-- | nixos/modules/virtualisation/containers.nix | 14 |
1 files changed, 13 insertions, 1 deletions
diff --git a/nixos/modules/virtualisation/containers.nix b/nixos/modules/virtualisation/containers.nix index e54a5fe7d40..0753aa25ce4 100644 --- a/nixos/modules/virtualisation/containers.nix +++ b/nixos/modules/virtualisation/containers.nix @@ -575,6 +575,16 @@ in ''; }; + extraFlags = mkOption { + type = types.listOf types.str; + default = []; + example = [ "--drop-capability=CAP_SYS_CHROOT" ]; + description = '' + Extra flags passed to the systemd-nspawn command. + See systemd-nspawn(1) for details. + ''; + }; + } // networkOptions; config = mkMerge @@ -714,7 +724,9 @@ in ${optionalString cfg.autoStart '' AUTO_START=1 ''} - EXTRA_NSPAWN_FLAGS="${mkBindFlags cfg.bindMounts}" + EXTRA_NSPAWN_FLAGS="${mkBindFlags cfg.bindMounts + + optionalString (cfg.extraFlags != []) + (" " + concatStringsSep " " cfg.extraFlags)}" ''; }) config.containers; |