From f7990beee6375cdd503865abcb7e4d8ed67e62d0 Mon Sep 17 00:00:00 2001 From: Alex Mickelson Date: Wed, 18 Feb 2026 21:05:55 -0700 Subject: [PATCH] updates --- nix/modules/gitea-runner.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nix/modules/gitea-runner.nix b/nix/modules/gitea-runner.nix index 3ec3d37..cb88cf3 100644 --- a/nix/modules/gitea-runner.nix +++ b/nix/modules/gitea-runner.nix @@ -27,7 +27,6 @@ kubectl kubernetes-helm curl - sudo ]; settings = { container = { @@ -115,6 +114,7 @@ RestrictAddressFamilies = lib.mkForce [ ]; ReadWritePaths = lib.mkForce [ ]; BindReadOnlyPaths = lib.mkForce [ ]; + BindPaths = lib.mkForce [ "/run/wrappers" ]; DeviceAllow = lib.mkForce [ "/dev/zfs rw" ]; DevicePolicy = lib.mkForce "auto";