nixos/netdata: change wrappers permissions

This commit is contained in:
Izorkin 2021-05-10 10:35:29 +03:00
parent 859633ee43
commit 85914bc01d
No known key found for this signature in database
GPG Key ID: 1436C1B3F3679F09

View File

@ -216,7 +216,7 @@ in {
capabilities = "cap_dac_read_search,cap_sys_ptrace+ep";
owner = cfg.user;
group = cfg.group;
permissions = "u+rx,g+rx,o-rwx";
permissions = "u+rx,g+x,o-rwx";
};
security.wrappers."cgroup-network" = {
@ -224,7 +224,7 @@ in {
capabilities = "cap_setuid+ep";
owner = cfg.user;
group = cfg.group;
permissions = "u+rx,g+rx,o-rwx";
permissions = "u+rx,g+x,o-rwx";
};
security.wrappers."freeipmi.plugin" = {
@ -232,7 +232,7 @@ in {
capabilities = "cap_dac_override,cap_fowner+ep";
owner = cfg.user;
group = cfg.group;
permissions = "u+rx,g+rx,o-rwx";
permissions = "u+rx,g+x,o-rwx";
};
security.wrappers."perf.plugin" = {
@ -240,7 +240,7 @@ in {
capabilities = "cap_sys_admin+ep";
owner = cfg.user;
group = cfg.group;
permissions = "u+rx,g+rx,o-rx";
permissions = "u+rx,g+x,o-rwx";
};
security.wrappers."slabinfo.plugin" = {
@ -248,7 +248,7 @@ in {
capabilities = "cap_dac_override+ep";
owner = cfg.user;
group = cfg.group;
permissions = "u+rx,g+rx,o-rx";
permissions = "u+rx,g+x,o-rwx";
};
security.pam.loginLimits = [