Hardening

This commit is contained in:
2025-08-03 20:06:32 +03:00
parent 2e0e24b411
commit 8e8a2c9c3c

View File

@@ -26,7 +26,8 @@
];
# Allow grafana access to the sqlite db
systemd.services.eko.serviceConfig.StateDirectoryMode = lib.mkForce 0755;
users.users.eko.extraGroups = [ "grafana" ];
systemd.services.eko.serviceConfig.StateDirectoryMode = lib.mkForce 0750;
systemd.services.grafana = {
serviceConfig = {
ProtectHome = lib.mkForce false;