diff --git a/modules/services/lib.nix b/modules/services/lib.nix index cec9166..35ff320 100644 --- a/modules/services/lib.nix +++ b/modules/services/lib.nix @@ -106,18 +106,15 @@ with lib; onFailure = [ "service-failure-notify@%n.service" ]; startLimitBurst = 5; startLimitIntervalSec = 600; - path = [ pkgs.podman pkgs.podman-compose pkgs.su pkgs.shadow pkgs.coreutils ]; + path = [ pkgs.podman pkgs.podman-compose pkgs.su pkgs.sudo pkgs.shadow pkgs.coreutils ]; serviceConfig = { - Type = "exec"; - User = "numbus-admin"; - Group = "users"; TimeoutStartSec = "1000"; ExecStartPre = [ "${pkgs.bash}/bin/bash -c 'sleep $((RANDOM % ${toString startDelay}))'" - "${pkgs.podman-compose}/bin/podman-compose -f /etc/podman/${name}/compose.yaml pull" + "${pkgs.sudo}/bin/sudo -u numbus-admin podman-compose -f /etc/podman/${name}/compose.yaml pull" ]; - ExecStart = "${pkgs.podman-compose}/bin/podman-compose ${envFileArg} --in-pod ${toString pod} -f /etc/podman/${name}/compose.yaml up --remove-orphans"; - ExecStop = "${pkgs.podman-compose}/bin/podman-compose ${envFileArg} --in-pod ${toString pod} -f /etc/podman/${name}/compose.yaml down"; + ExecStart = "${pkgs.sudo}/bin/sudo -u numbus-admin podman-compose ${envFileArg} --in-pod ${toString pod} -f /etc/podman/${name}/compose.yaml up --remove-orphans"; + ExecStop = "${pkgs.sudo}/bin/sudo -u numbus-admin podman-compose ${envFileArg} --in-pod ${toString pod} -f /etc/podman/${name}/compose.yaml down"; Restart = "on-failure"; RestartSec = "3m"; };