services.xray: pass the settings file with systemd loadCredential #368763
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Pass the settings file with systemd loadCredential
It enables passing a sops-nix secret as a
settingsFile
. For more context of the problem see Mic92/sops-nix#198.Problem:
By default sops-nix secrets are accessible by only root. We can change owner to another user, but the xray service is defined with
dynamicUser=true
, which means, there is no user at compile time.Solution:
Systemd
loadCredential
passes the secret file to the service, which is exactly what we need here.Things done
nix.conf
? (See Nix manual)sandbox = relaxed
sandbox = true
nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD"
. Note: all changes have to be committed, also see nixpkgs-review usage./result/bin/
)Add a 👍 reaction to pull requests you find important.