!VhzbGHamdfMiGxpXyg:robins.wtf

NixOS Incus and LXC

49 Members
lxc, lxd, incus discussions related to NixOS16 Servers

Load older messages


SenderMessageTime
3 Jan 2024
@hexa:lossy.networkhexaaye14:06:50
@hexa:lossy.networkhexaalthough, maybe not14:06:55
@hexa:lossy.networkhexathat only works for groups that can write to nixpkgs14:07:08
@adam:robins.wtfadamcstephensthe entire group needs write access? or just individuals in it14:07:37
@hexa:lossy.networkhexathe group needs to have nixpkgs committers as a parent14:07:49
@adam:robins.wtfadamcstephensahh14:08:01
@adam:robins.wtfadamcstephensnot all of our members are committers14:08:06
@hexa:lossy.networkhexayeah, the only team that has this relationship is the security team I think14:08:23
@adam:robins.wtfadamcstephensand maybe systemd?14:09:08
@adam:robins.wtfadamcstephensor their notifications don't work14:09:16
@hexa:lossy.networkhexayeah, possibly14:09:55
16 Jan 2024
@sysedwinistrator:matrix.orgsysedwinistrator joined the room.11:37:11
17 Jan 2024
@aanderse:nixos.devaandersedoes anyone remember why the `systemd` `LoadCredential` is disabled on LXC? i think that is an upstream thing... anyone remember why?19:30:18
@hexa:lossy.networkhexadisabled where?20:03:24
@hexa:lossy.networkhexa * aanderse: disabled where? 20:08:30
@aanderse:nixos.devaandersenixos/modules/virtualisation/lxc-container.nix20:13:26
@aanderse:nixos.devaandersedistro builder says to turn it off... but apparently only required if `security.nesting` is set to `false`20:14:13
@aanderse:nixos.devaandersewe can't detect the value of that at build time20:14:33
@aanderse:nixos.devaandersebut we could detect the value at runtime20:14:47
@aanderse:nixos.devaanderseso I'm not sure what we should do here...20:14:56
@hexa:lossy.networkhexawhat does security.nesting do?20:15:15
@aanderse:nixos.devaanderseadd a nixos option or try to do the right thing via shell scripting at runtime20:15:22
@hexa:lossy.networkhexalike how does it interfere with loadcredential?20:15:56
@hexa:lossy.networkhexanamespacing restrictions?20:16:03
@aanderse:nixos.devaandersethat sounds right20:16:12
@aanderse:nixos.devaanderseit's necessary for the nix sandbox in the container20:16:29
@aanderse:nixos.devaanderseso make sense20:16:37
@aanderse:nixos.devaandersewe're starting to play with cachix and i was surprised when it didn't work20:17:51
@aanderse:nixos.devaandersehuh?20:17:54
@aanderse:nixos.devaandersethat can't be...20:18:02

Show newer messages


Back to Room ListRoom Version: 10