add security context for privileged ports idk
All checks were successful
gitea-deepak/nixconf/pipeline/head This commit looks good
testing nix stuff / nix (ubuntu-latest) (push) Successful in 8m17s

This commit is contained in:
Deepak Mallubhotla 2025-03-21 12:43:35 -05:00
parent c40724190e
commit b0efda8b01
Signed by: deepak
GPG Key ID: 47831B15427F5A55

View File

@ -101,9 +101,20 @@ in
time.timeZone = "America/Chicago";
virtualisation.docker.rootless = pkgs.lib.mkIf withDocker {
virtualisation.docker = pkgs.lib.mkIf withDocker {
enable = true;
rootless = {
enable = true;
setSocketVariable = true;
};
};
security.wrappers = pkgs.lib.mkIf withDocker {
docker-rootlesskit = {
owner = "root";
group = "root";
capabilities = "cap_net_bind_service+ep";
source = "${pkgs.rootlesskit}/bin/rootlesskit";
};
};
}