security: start setting permissions on secrets properly

This commit is contained in:
Christoph Hollizeck 2025-12-01 23:53:27 +01:00
parent 01fb6d8ec9
commit 2adc358dec
Signed by: Daholli
GPG key ID: 249300664F2AF2C7
6 changed files with 43 additions and 34 deletions

View file

@ -40,8 +40,7 @@
"root"
username
]
++ lib.optional (builtins.hasAttr "native" config.services.gitea-actions-runner.instances) "gitea-runner"
++ lib.optional config.services.hydra.enable "hydra hydra-www hydra-evaluator hydra-queue-runner";
++ lib.optional (builtins.hasAttr "native" config.services.gitea-actions-runner.instances) "gitea-runner";
in
{
nix-path = "nixpkgs=flake:nixpkgs";