Lock down services to LAN

This commit is contained in:
2025-04-22 13:40:41 -05:00
parent 2034274ee0
commit b27d748e30
3 changed files with 22 additions and 24 deletions

View File

@ -1,13 +1,5 @@
{ config, lib, pkgs, ... }:
{
environment.etc."containers/containers.conf".text = lib.mkForce ''
[engine]
init_path = "${pkgs.catatonit}/bin/catatonit"
[network]
network_backend = "cni"
cni_plugin_dirs = ["${pkgs.cni-plugins}/bin"]
'';
virtualisation.oci-containers = {
containers = {