Try adding BPF capability for credential-in-container support
This commit is contained in:
parent
e50930a4dc
commit
d91c7b7c98
|
@ -25,7 +25,10 @@ let
|
||||||
];
|
];
|
||||||
ports = [ "${toString cfg.port}:80" ];
|
ports = [ "${toString cfg.port}:80" ];
|
||||||
networks = [ "external_network" ];
|
networks = [ "external_network" ];
|
||||||
capabilities.SYS_ADMIN = true;
|
capabilities = {
|
||||||
|
BPF = true;
|
||||||
|
SYS_ADMIN = true;
|
||||||
|
};
|
||||||
};
|
};
|
||||||
nixos = {
|
nixos = {
|
||||||
useSystemd = true;
|
useSystemd = true;
|
||||||
|
|
Loading…
Reference in New Issue