| 23 May 2021 |
Gytis Ivaskevicius | (and ofc make sure that files owned by that group has rw permissions) | 17:50:03 |
| 9 Apr 2025 |
ElvishJerricco | two things being in the same slice has little to do with whether they should be configured similarly | 19:41:10 |
| 23 May 2021 |
andi- | Of course that is the easy way out :-) | 17:53:01 |
| 9 Apr 2025 |
@srestegosaurio:tchncs.de | I would have doubted my hability to read if you had told me that it was indeed possible. xD
| 19:41:55 |
| 23 May 2021 |
andi- | I can solve the issue and it isn't blocking me right now but I'd like to know how I would do this properly in the upstream sense. | 17:53:28 |
| 9 Apr 2025 |
@srestegosaurio:tchncs.de | So then it is templates what I need, right?
| 19:43:36 |
| 23 May 2021 |
| kreisys joined the room. | 19:09:12 |
| 9 Apr 2025 |
@srestegosaurio:tchncs.de | Not actually intending to apply them to the whole system but I have a a lot of repeated code.
| 19:45:12 |
| 23 May 2021 |
| Room Avatar Renderer. | 20:54:58 |
| 9 Apr 2025 |
ElvishJerricco | templates are for when you want the literal same unit but with different parameters | 19:45:58 |
| 24 May 2021 |
| papojari π³οΈβπ β (we/us) (Old) changed their display name from papojari to papojari β (we/us). | 00:09:53 |
| 9 Apr 2025 |
ElvishJerricco | e.g. systemd-fsck@dev-foo.service is the fsck service for the parameter /dev/foo | 19:46:09 |
| 24 May 2021 |
| papojari π³οΈβπ β (we/us) (Old) changed their display name from papojari β (we/us) to papojari π³οΈβπ β (we/us). | 00:14:37 |
| 9 Apr 2025 |
@srestegosaurio:tchncs.de | Well, then I guess it's time to do some nix abominations.
| 19:46:48 |
| 24 May 2021 |
| papojari π³οΈβπ β (we/us) (Old) changed their display name from papojari π³οΈβπ β (we/us) to papojari π³οΈβπ β (we/us) (Old). | 00:40:08 |
| 9 Apr 2025 |
ElvishJerricco | If you just want different units to share some directives, I think you're just looking for a Nix function | 19:47:15 |
| 24 May 2021 |
| rajivr joined the room. | 03:32:40 |
| 9 Apr 2025 |
ElvishJerricco | what are you actually trying to do? | 19:47:35 |
| 24 May 2021 |
| vika (she/her) π³οΈββ§οΈ joined the room. | 07:12:13 |
| 9 Apr 2025 |
Arian | Not true. You can do sandboxing on the slice level | 19:55:40 |
| 24 May 2021 |
| plabadens joined the room. | 10:19:13 |
| 9 Apr 2025 |
ElvishJerricco | oh? | 19:56:15 |
| 24 May 2021 |
| talyz joined the room. | 11:59:32 |
| 9 Apr 2025 |
Arian | E.g. I have IPAdddressDeny=169.254.169.254 on. -.slice to make sure no service can access the metadata server unless I explicitly allow it | 19:56:26 |
| 24 May 2021 |
| papojari π³οΈβπ β (we/us) (Old) left the room. | 14:53:34 |
| 9 Apr 2025 |
Arian | All units in a slice inherit all the sandboxing options | 19:56:40 |
| 25 May 2021 |
| AluΓsio Augusto Silva GonΓ§alves joined the room. | 06:40:36 |
| 9 Apr 2025 |
Arian | * All units in a slice inherit all the sandboxing options of that slice | 19:56:53 |
| 25 May 2021 |
| amikke joined the room. | 11:39:43 |
| 9 Apr 2025 |
ElvishJerricco | that works because IPAddressDeny is a cgroup thing | 19:57:09 |