Compare commits

..

5 commits

Author SHA1 Message Date
38b13d9cbf
strace pkg 2025-08-04 16:41:59 +02:00
16ea02bac9
container dns 2025-08-04 16:41:59 +02:00
e21a9ea70a
plug hole in firewall
format
2025-08-04 16:41:59 +02:00
a99de6c626
rm agent exec 2025-08-04 16:41:59 +02:00
3d93cb597d
disable exec agent
make service group setting conditional

make secrets conditional

make things conditional
2025-08-04 16:34:55 +02:00

View file

@ -204,7 +204,6 @@
networking = { networking = {
nftables.enable = lib.mkForce false; nftables.enable = lib.mkForce false;
firewall = { firewall = {
enable = lib.mkForce true;
allowedTCPPorts = [ allowedTCPPorts = [
22 22
80 80
@ -227,6 +226,7 @@
defaultNetwork.settings = { defaultNetwork.settings = {
dns_enabled = true; dns_enabled = true;
ipv6_enabled = true; ipv6_enabled = true;
dns = "95.215.185.6";
}; };
}; };
@ -234,6 +234,9 @@
woodpecker-agent-docker = { woodpecker-agent-docker = {
wants = [ "podman.socket" ]; wants = [ "podman.socket" ];
after = [ "podman.socket" ]; after = [ "podman.socket" ];
serviceConfig = {
SupplementaryGroups = [ "podman" ];
};
}; };
}; };
} }