nixos/proxmox-lxc: fix ping in unprivileged LXCs

This commit is contained in:
illustris 2024-06-15 20:29:01 +05:30
parent 33f93a8999
commit 01b159092f
No known key found for this signature in database
GPG key ID: 56C8FC0B899FEFA3

View file

@ -65,6 +65,14 @@ with lib;
hostName = mkIf (!cfg.manageHostName) (mkForce "");
};
# unprivileged LXCs can't set net.ipv4.ping_group_range
security.wrappers.ping = mkIf (!cfg.privileged) {
owner = "root";
group = "root";
capabilities = "cap_net_raw+p";
source = "${pkgs.iputils.out}/bin/ping";
};
services.openssh = {
enable = mkDefault true;
startWhenNeeded = mkDefault true;