Compare commits

..

5 commits

Author SHA1 Message Date
c0d7867aa5
strace pkg 2025-08-04 16:46:00 +02:00
839f528491
container dns
rm dns
2025-08-04 16:46:00 +02:00
2b75d9adb5
enable firewall 2025-08-04 16:46:00 +02:00
ea792d4395
rm agent exec
plug hole in firewall

format
2025-08-04 16:46:00 +02:00
5b4f15c6f0
disable exec agent
make service group setting conditional

make secrets conditional

make things conditional

rm group
2025-08-04 16:44:46 +02:00

View file

@ -204,6 +204,7 @@
networking = { networking = {
nftables.enable = lib.mkForce false; nftables.enable = lib.mkForce false;
firewall = { firewall = {
enable = lib.mkForce true;
allowedTCPPorts = [ allowedTCPPorts = [
22 22
80 80
@ -226,7 +227,6 @@
defaultNetwork.settings = { defaultNetwork.settings = {
dns_enabled = true; dns_enabled = true;
ipv6_enabled = true; ipv6_enabled = true;
dns = "95.215.185.6";
}; };
}; };
@ -234,9 +234,6 @@
woodpecker-agent-docker = { woodpecker-agent-docker = {
wants = [ "podman.socket" ]; wants = [ "podman.socket" ];
after = [ "podman.socket" ]; after = [ "podman.socket" ];
serviceConfig = {
SupplementaryGroups = [ "podman" ];
};
}; };
}; };
} }