Unverified Commit 22349999 authored by Adam C. Stephens's avatar Adam C. Stephens Committed by GitHub
Browse files

nixos/kanidm: add home_mount_prefix to BindPaths if set (#382915)

parents cc594f99 2f45486c
Loading
Loading
Loading
Loading
+10 −6
Original line number Diff line number Diff line
@@ -855,12 +855,16 @@ in
          User = "kanidm";
          Group = "kanidm";

          BindPaths = [
          BindPaths =
            [
              # To create the socket
              "/run/kanidmd:/run/kanidmd"
              # To store backups
              cfg.serverSettings.online_backup.path
          ];
            ]
            ++ optional (
              cfg.enablePam && cfg.unixSettings ? home_mount_prefix
            ) cfg.unixSettings.home_mount_prefix;

          AmbientCapabilities = [ "CAP_NET_BIND_SERVICE" ];
          CapabilityBoundingSet = [ "CAP_NET_BIND_SERVICE" ];