updates
This commit is contained in:
@@ -90,6 +90,8 @@
|
|||||||
User = lib.mkForce "gitea-runner";
|
User = lib.mkForce "gitea-runner";
|
||||||
Group = lib.mkForce "gitea-runner";
|
Group = lib.mkForce "gitea-runner";
|
||||||
|
|
||||||
|
Environment = lib.mkForce [ "PATH=/run/wrappers/bin:/run/current-system/sw/bin" ];
|
||||||
|
|
||||||
DynamicUser = lib.mkForce false;
|
DynamicUser = lib.mkForce false;
|
||||||
PrivateDevices = lib.mkForce false;
|
PrivateDevices = lib.mkForce false;
|
||||||
PrivateMounts = lib.mkForce false;
|
PrivateMounts = lib.mkForce false;
|
||||||
@@ -114,7 +116,6 @@
|
|||||||
RestrictAddressFamilies = lib.mkForce [ ];
|
RestrictAddressFamilies = lib.mkForce [ ];
|
||||||
ReadWritePaths = lib.mkForce [ ];
|
ReadWritePaths = lib.mkForce [ ];
|
||||||
BindReadOnlyPaths = lib.mkForce [ ];
|
BindReadOnlyPaths = lib.mkForce [ ];
|
||||||
BindPaths = lib.mkForce [ "/run/wrappers" ];
|
|
||||||
|
|
||||||
DeviceAllow = lib.mkForce [ "/dev/zfs rw" ];
|
DeviceAllow = lib.mkForce [ "/dev/zfs rw" ];
|
||||||
DevicePolicy = lib.mkForce "auto";
|
DevicePolicy = lib.mkForce "auto";
|
||||||
|
|||||||
Reference in New Issue
Block a user