fix(virtualisation): add & extend sub{u,g}id ranges

This commit is contained in:
Felix Schröter 2023-09-18 23:39:37 +02:00
parent 7fae92e31d
commit 5ba17c8ccf
Signed by: felschr
GPG key ID: 671E39E6744C807D
3 changed files with 36 additions and 1 deletions
virtualisation

View file

@ -7,4 +7,27 @@ _:
# Create unique User Namespace for the container
containers.userns = "auto";
};
virtualisation.containers.storage.settings = {
# defaults
storage = {
driver = "overlay";
graphroot = "/var/lib/containers/storage";
runroot = "/run/containers/storage";
};
# SUB_UID_MAX: https://man7.org/linux/man-pages/man5/login.defs.5.html
storage.options.auto-userns-max-size = 600100000;
};
# Increase sub{u,g}id range
users.users."root" = {
subUidRanges = [{
startUid = 60100000;
count = 60000000;
}];
subGidRanges = [{
startGid = 60100000;
count = 60000000;
}];
};
}