Compare commits
3 Commits
5a8daad590
...
43ec75741d
| Author | SHA1 | Date | |
|---|---|---|---|
| 43ec75741d | |||
| 000bbd7f4d | |||
| e4f0d065f9 |
@@ -234,6 +234,9 @@ in
|
|||||||
before = [ "container@pia-vpn.service" ];
|
before = [ "container@pia-vpn.service" ];
|
||||||
after = [ "systemd-networkd.service" ];
|
after = [ "systemd-networkd.service" ];
|
||||||
requires = [ "systemd-networkd.service" ];
|
requires = [ "systemd-networkd.service" ];
|
||||||
|
serviceConfig.ExecStartPre = [
|
||||||
|
"+${pkgs.systemd}/lib/systemd/systemd-networkd-wait-online --interface=${cfg.bridgeName}:no-carrier --timeout=60"
|
||||||
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
# WireGuard interface creation (host-side oneshot)
|
# WireGuard interface creation (host-side oneshot)
|
||||||
|
|||||||
@@ -341,7 +341,8 @@
|
|||||||
enable = true;
|
enable = true;
|
||||||
settings.MEMOS_PORT = "57643";
|
settings.MEMOS_PORT = "57643";
|
||||||
};
|
};
|
||||||
systemd.services.memos.serviceConfig.PrivateUsers = lib.mkForce false;
|
# ReadWritePaths doesn't work with ProtectSystem=strict on ZFS submounts (/var/lib is a separate dataset)
|
||||||
|
systemd.services.memos.serviceConfig.ProtectSystem = lib.mkForce "full";
|
||||||
|
|
||||||
services.outline = {
|
services.outline = {
|
||||||
enable = true;
|
enable = true;
|
||||||
|
|||||||
Reference in New Issue
Block a user