diff --git a/common/network/pia-vpn/default.nix b/common/network/pia-vpn/default.nix index b89bd45..ea01e1e 100644 --- a/common/network/pia-vpn/default.nix +++ b/common/network/pia-vpn/default.nix @@ -230,7 +230,11 @@ in Port = cfg.proxyPort; }; }; - systemd.services.tinyproxy.before = [ "container@pia-vpn.service" ]; + systemd.services.tinyproxy = { + before = [ "container@pia-vpn.service" ]; + after = [ "systemd-networkd.service" ]; + requires = [ "systemd-networkd.service" ]; + }; # WireGuard interface creation (host-side oneshot) # Creates the interface in the host namespace so encrypted UDP stays in host netns.