atlas
0e3df82504
feat(#972): tighten hive-priv systemd sandbox — ProtectSystem=strict + ReadWritePaths
Replace ProtectSystem=false with ProtectSystem=strict now that privsep
is complete (issue #702 closed) and hive-c0re runs as the non-root
hive-core user.
ReadWritePaths carves out the six paths hive-priv must write to at
runtime; everything else is read-only:
/etc/nixos-containers — writes <container>.conf (bind-mounts,
network isolation, nspawn flags)
/run/hive — fallback socket bind when LISTEN_FDS absent
/run/hive-agent — chown/chmod per-agent socket directories
/run/systemd — container@ drop-ins (resource limits) and
machinectl/systemd-machined machine state
/var/lib/nixos-containers — container rootfs (nixos-container script)
/nix — nix store + profile updates during
container create/update
PrivateTmp=true (already set) keeps /tmp private.
StateDirectory=hive-priv (already set) keeps /var/lib/hive-priv writable
for nix's fetch/eval cache (HOME points there).
nix flake check --no-build passes.
|
2026-06-03 16:57:01 +02:00 |
| .. |
|
hive-c0re.nix
|
feat(#972): tighten hive-priv systemd sandbox — ProtectSystem=strict + ReadWritePaths
|
2026-06-03 16:57:01 +02:00 |
|
hive-ci.nix
|
fix(#981): validate runner credentials on every boot, purge stale .runner
|
2026-06-02 00:27:47 +02:00 |
|
hive-forge.nix
|
fix(#981): enable Forgejo Actions so runner registration token API works
|
2026-06-01 18:38:44 +02:00 |
|
hive-gateway.nix
|
fix(#1155): enable recommendedTlsSettings + recommendedGzipSettings in gateway nginx
|
2026-06-03 16:48:33 +02:00 |
|
hive-matrix.nix
|
fix(#1061): suppress tuwunel default displayname suffix
|
2026-06-02 11:18:38 +02:00 |
|
hive-network.nix
|
fix: assert gateway.enable when isolateContainers + forge.enable
|
2026-06-03 16:33:10 +02:00 |