nixos/hosts/lab/foundry.nix
lew 71f32ba49c fix: use podman.user for rootless instead of mkForce on serviceConfig
The oci-containers module has native rootless support via podman.user
which handles cgroup delegation, runtime dirs, and cidfile paths.
Delegate=true workaround for NixOS/nixpkgs#410857.
2026-04-04 23:36:01 +01:00

25 lines
640 B
Nix

{ ... }:
{
services.caddy.virtualHosts."foundry.ily.rs" = {
extraConfig = ''
reverse_proxy localhost:30000
encode zstd gzip
'';
};
virtualisation.oci-containers.containers.foundry = {
image = "node:22.22.2-slim";
cmd = [ "node" "main.js" "--dataPath=/data" ];
workdir = "/app";
user = "1000:1000";
podman.user = "lew";
volumes = [
"/srv/foundry/app:/app:ro"
"/srv/foundry/data:/data"
];
ports = [ "127.0.0.1:30000:30000" ];
};
# Workaround for NixOS/nixpkgs#410857 until backport of #475089 lands
systemd.services.podman-foundry.serviceConfig.Delegate = true;
}