Unverified Commit 2f45486c authored by oddlama's avatar oddlama
Browse files

nixos/kanidm: add home_mount_prefix to BindPaths if set

parent 1062db4d
Loading
Loading
Loading
Loading
+10 −6
Original line number Diff line number Diff line
@@ -855,12 +855,16 @@ in
          User = "kanidm";
          Group = "kanidm";

          BindPaths = [
          BindPaths =
            [
              # To create the socket
              "/run/kanidmd:/run/kanidmd"
              # To store backups
              cfg.serverSettings.online_backup.path
          ];
            ]
            ++ optional (
              cfg.enablePam && cfg.unixSettings ? home_mount_prefix
            ) cfg.unixSettings.home_mount_prefix;

          AmbientCapabilities = [ "CAP_NET_BIND_SERVICE" ];
          CapabilityBoundingSet = [ "CAP_NET_BIND_SERVICE" ];