summaryrefslogtreecommitdiffstats
path: root/nixos
diff options
context:
space:
mode:
authorIzorkin <izorkin@elven.pw>2021-05-04 23:13:51 +0300
committerIzorkin <izorkin@elven.pw>2021-05-05 20:46:07 +0300
commit53651179b922485330a96a13cacfe7d08ec0938b (patch)
tree0d7d48c4a617266b77ec865d3a02217811423ec4 /nixos
parent360ed28868f665a73f3b08801df38c6af984df74 (diff)
nixos/netdata: update capabilities
Diffstat (limited to 'nixos')
-rw-r--r--nixos/modules/services/monitoring/netdata.nix5
1 files changed, 5 insertions, 0 deletions
diff --git a/nixos/modules/services/monitoring/netdata.nix b/nixos/modules/services/monitoring/netdata.nix
index a6ecc2a566ca..c2ee1c0df7f1 100644
--- a/nixos/modules/services/monitoring/netdata.nix
+++ b/nixos/modules/services/monitoring/netdata.nix
@@ -183,6 +183,9 @@ in {
ConfigurationDirectory = "netdata";
ConfigurationDirectoryMode = "0755";
# Capabilities
+ AmbientCapabilities = [
+ "CAP_SETUID" # is required for cgroups and cgroups-network plugins
+ ];
CapabilityBoundingSet = [
"CAP_DAC_OVERRIDE" # is required for freeipmi and slabinfo plugins
"CAP_DAC_READ_SEARCH" # is required for apps plugin
@@ -192,6 +195,8 @@ in {
"CAP_SYS_PTRACE" # is required for apps plugin
"CAP_SYS_RESOURCE" # is required for ebpf plugin
"CAP_NET_RAW" # is required for fping app
+ "CAP_SYS_CHROOT" # is required for cgroups plugin
+ "CAP_SETUID" # is required for cgroups and cgroups-network plugins
];
# Sandboxing
ProtectSystem = "full";