From cedd54f9013a824cb21ee18b69bfed324b612646 Mon Sep 17 00:00:00 2001 From: Alex Mickelson Date: Wed, 18 Feb 2026 21:08:00 -0700 Subject: [PATCH] updates --- nix/modules/gitea-runner.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/nix/modules/gitea-runner.nix b/nix/modules/gitea-runner.nix index 9b60f76..1a3fb39 100644 --- a/nix/modules/gitea-runner.nix +++ b/nix/modules/gitea-runner.nix @@ -90,6 +90,8 @@ User = lib.mkForce "gitea-runner"; Group = lib.mkForce "gitea-runner"; + Environment = lib.mkForce [ "PATH=/run/wrappers/bin:/run/current-system/sw/bin" ]; + DynamicUser = lib.mkForce false; PrivateDevices = lib.mkForce false; PrivateMounts = lib.mkForce false; @@ -114,7 +116,6 @@ RestrictAddressFamilies = lib.mkForce [ ]; ReadWritePaths = lib.mkForce [ ]; BindReadOnlyPaths = lib.mkForce [ ]; - BindPaths = lib.mkForce [ "/run/wrappers" ]; DeviceAllow = lib.mkForce [ "/dev/zfs rw" ]; DevicePolicy = lib.mkForce "auto";