Compare commits
3 Commits
5a8daad590
...
43ec75741d
| Author | SHA1 | Date | |
|---|---|---|---|
| 43ec75741d | |||
| 000bbd7f4d | |||
| e4f0d065f9 |
@@ -234,6 +234,9 @@ in
|
||||
before = [ "container@pia-vpn.service" ];
|
||||
after = [ "systemd-networkd.service" ];
|
||||
requires = [ "systemd-networkd.service" ];
|
||||
serviceConfig.ExecStartPre = [
|
||||
"+${pkgs.systemd}/lib/systemd/systemd-networkd-wait-online --interface=${cfg.bridgeName}:no-carrier --timeout=60"
|
||||
];
|
||||
};
|
||||
|
||||
# WireGuard interface creation (host-side oneshot)
|
||||
|
||||
@@ -341,7 +341,8 @@
|
||||
enable = true;
|
||||
settings.MEMOS_PORT = "57643";
|
||||
};
|
||||
systemd.services.memos.serviceConfig.PrivateUsers = lib.mkForce false;
|
||||
# ReadWritePaths doesn't work with ProtectSystem=strict on ZFS submounts (/var/lib is a separate dataset)
|
||||
systemd.services.memos.serviceConfig.ProtectSystem = lib.mkForce "full";
|
||||
|
||||
services.outline = {
|
||||
enable = true;
|
||||
|
||||
Reference in New Issue
Block a user