diff --git a/nixosConfigurations/muede-lpt2/containers.nix b/nixosConfigurations/muede-lpt2/containers.nix index ff0e4d5..8e4ae9f 100644 --- a/nixosConfigurations/muede-lpt2/containers.nix +++ b/nixosConfigurations/muede-lpt2/containers.nix @@ -1,4 +1,9 @@ -{ self, ... }: +{ + config, + lib, + ... +}: + { config = { boot.enableContainers = true; @@ -22,13 +27,25 @@ # }; # }; - # # Global DefaultTimeoutStopSec is 10s (modern-desktop.nix), which kills systemd-nspawn - # # before it finishes halting, leaving cgroups busy and breaking restarts. - # systemd.services."container@damocles".serviceConfig = { - # TimeoutStopSec = "60s"; - # # After a SIGKILL of nspawn, the kernel needs a moment to reap its cgroups. - # # Without this, the immediate restart attempt fails with "Device or resource busy". - # RestartSec = "5s"; - # }; + # Global DefaultTimeoutStopSec is 10s (modern-desktop.nix), which kills systemd-nspawn + # before it finishes halting, leaving cgroups busy and breaking restarts. + systemd.services = + let + # The imperative template plus every declarative container: nixos-containers + # generates each one as its own unit, so an override on "container@" alone + # would not reach them. + containerUnits = [ + "container@" + ] + ++ map (name: "container@${name}") (lib.attrNames config.containers); + in + lib.genAttrs containerUnits (_: { + serviceConfig = { + TimeoutStopSec = "2min"; + # After a SIGKILL of nspawn, the kernel needs a moment to reap its cgroups. + # Without this, the immediate restart attempt fails with "Device or resource busy". + RestartSec = "5s"; + }; + }); }; }