diff --git a/hosts/netty/forgejo-runner.nix b/hosts/netty/forgejo-runner.nix index 1720269..276f6e6 100644 --- a/hosts/netty/forgejo-runner.nix +++ b/hosts/netty/forgejo-runner.nix @@ -8,6 +8,10 @@ let cacheRoot = "/var/cache/forgejo-runner"; in { + systemd.services.gitea-runner-netty.serviceConfig = { + NoNewPrivileges = lib.mkForce false; + }; + security.sudo.extraRules = [ { users = [ "gitea-runner" ];