mirror of
https://github.com/NixOS/nixpkgs.git
synced 2025-06-12 04:35:41 +03:00
nixos/proxmox-lxc: fix ping in unprivileged LXCs
This commit is contained in:
parent
33f93a8999
commit
01b159092f
1 changed files with 8 additions and 0 deletions
|
@ -65,6 +65,14 @@ with lib;
|
|||
hostName = mkIf (!cfg.manageHostName) (mkForce "");
|
||||
};
|
||||
|
||||
# unprivileged LXCs can't set net.ipv4.ping_group_range
|
||||
security.wrappers.ping = mkIf (!cfg.privileged) {
|
||||
owner = "root";
|
||||
group = "root";
|
||||
capabilities = "cap_net_raw+p";
|
||||
source = "${pkgs.iputils.out}/bin/ping";
|
||||
};
|
||||
|
||||
services.openssh = {
|
||||
enable = mkDefault true;
|
||||
startWhenNeeded = mkDefault true;
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue