nixos-module/server/lxc-containers: update permissions
This commit is contained in:
parent
24b36568ca
commit
b87b73d358
|
@ -168,16 +168,18 @@ in
|
|||
|
||||
lxc.autodev = 1
|
||||
lxc.tty.max = 0
|
||||
lxc.pty.max = 8
|
||||
|
||||
lxc.cap.drop = sys_module sys_time sys_nice sys_pacct sys_rawio sys_time mknod
|
||||
lxc.apparmor.profile = unchanged
|
||||
lxc.cap.drop = sys_module sys_time sys_nice sys_pacct sys_rawio
|
||||
security.privileged = false
|
||||
lxc.apparmor.profile = lxc-container-default-with-mounting
|
||||
|
||||
lxc.cgroup.memory.limit_in_bytes = 1G
|
||||
lxc.cgroup.memory.kmem.tcp.limit_in_bytes = 128M
|
||||
|
||||
# tuntap
|
||||
lxc.cgroup.devices.allow = c 10:200 rw
|
||||
lxc.cgroup2.devices.allow = c 10:200 rw
|
||||
|
||||
${netConfig ctName containers.${ctName}.physicalInterfaces}
|
||||
'';
|
||||
|
|
Loading…
Reference in New Issue