mirror of
https://github.com/harivansh-afk/nix.git
synced 2026-04-19 18:04:47 +00:00
ci(netty): disable DynamicUser on runner (implies NoNewPrivileges + RestrictSUIDSGID that break sudo)
Made-with: Cursor
This commit is contained in:
parent
bac6f96814
commit
94c8e91190
1 changed files with 12 additions and 0 deletions
|
|
@ -9,9 +9,21 @@ let
|
|||
in
|
||||
{
|
||||
systemd.services.gitea-runner-netty.serviceConfig = {
|
||||
DynamicUser = lib.mkForce false;
|
||||
User = lib.mkForce "gitea-runner";
|
||||
Group = lib.mkForce "gitea-runner";
|
||||
NoNewPrivileges = lib.mkForce false;
|
||||
RestrictSUIDSGID = lib.mkForce false;
|
||||
};
|
||||
|
||||
users.users.gitea-runner = {
|
||||
isSystemUser = true;
|
||||
group = "gitea-runner";
|
||||
home = "/var/lib/gitea-runner";
|
||||
createHome = true;
|
||||
};
|
||||
users.groups.gitea-runner = { };
|
||||
|
||||
security.sudo.extraRules = [
|
||||
{
|
||||
users = [ "gitea-runner" ];
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue