modules/ipfs: allow CAP_NET_BIND_SERVICE

This commit is contained in:
Max Headroom 2022-09-24 13:59:05 +02:00
parent 1fdc2aed10
commit efc518a97b

View file

@ -87,7 +87,10 @@ in
systemd.services.ipfs = {
environment.LIBP2P_FORCE_PNET = "1";
serviceConfig.Slice = "remotefshost.slice";
serviceConfig = {
Slice = "remotefshost.slice";
AmbientCapabilities = [ "CAP_NET_BIND_SERVICE" ];
};
postStart = "chmod 660 /run/ipfs/ipfs-api.sock";
};