24 May 2021 |
| rajivr joined the room. | 03:32:40 |
9 Apr 2025 |
ElvishJerricco | what are you actually trying to do? | 19:47:35 |
24 May 2021 |
| vika (she/her) 🏳️⚧️ joined the room. | 07:12:13 |
9 Apr 2025 |
Arian | Not true. You can do sandboxing on the slice level | 19:55:40 |
24 May 2021 |
| plabadens joined the room. | 10:19:13 |
9 Apr 2025 |
ElvishJerricco | oh? | 19:56:15 |
24 May 2021 |
| talyz joined the room. | 11:59:32 |
9 Apr 2025 |
Arian | E.g. I have IPAdddressDeny=169.254.169.254 on. -.slice to make sure no service can access the metadata server unless I explicitly allow it | 19:56:26 |
24 May 2021 |
| papojari 🏳️🌈 ☭ (we/us) (Old) left the room. | 14:53:34 |
9 Apr 2025 |
Arian | All units in a slice inherit all the sandboxing options | 19:56:40 |
25 May 2021 |
| Aluísio Augusto Silva Gonçalves joined the room. | 06:40:36 |
9 Apr 2025 |
Arian | * All units in a slice inherit all the sandboxing options of that slice | 19:56:53 |
25 May 2021 |
| amikke joined the room. | 11:39:43 |
9 Apr 2025 |
ElvishJerricco | that works because IPAddressDeny is a cgroup thing | 19:57:09 |
25 May 2021 |
| princemachiavelli joined the room. | 15:21:12 |
9 Apr 2025 |
ElvishJerricco | slices are about cgroups | 19:57:12 |
25 May 2021 |
| zopieux joined the room. | 17:30:05 |
9 Apr 2025 |
ElvishJerricco | e.g. PrivateTmp is about namespaces | 19:57:19 |
ElvishJerricco | which slices have nothing to do with | 19:57:22 |
25 May 2021 |
| mvnetbiz changed their display name from mvtva to mvnetbiz. | 23:25:42 |
9 Apr 2025 |
Arian | Aaaaaah yeh. That is in systemd.resource-control | 19:57:45 |
26 May 2021 |
| plabadens set a profile picture. | 10:05:28 |
9 Apr 2025 |
Arian | You're right. Slice units can have settings from systemd.exec | 19:57:59 |
26 May 2021 |
| justinrestivo joined the room. | 12:27:38 |
9 Apr 2025 |
Arian | * You're right. Slice units can not have settings from systemd.exec | 19:58:17 |
26 May 2021 |
hexa | https://github.com/NixOS/nixpkgs/pull/124435/files#diff-284b1cb0fc0427dcf6c404c9d67183be977048f3261d8ecd63653753a496a868R107 | 15:19:48 |
9 Apr 2025 |
| dblsaiko ⚧︎ 🔪 changed their display name from dblsaiko 🔪 to dblsaiko ⚧︎ 🔪. | 20:07:04 |
26 May 2021 |
hexa |
Note that database_path should not be set because the services reliance on systemd StateDir.
| 15:19:59 |
hexa | What would be a reasonable way to handle this? I'm thinking an mkOption with readOnly = true , but there might be a realistic wish to move the state directory to another volume | 15:21:51 |
hexa | Is ReadWritePath the way? | 15:22:32 |