nixos/mxisd: umask to avoid accidental world-readability
This commit is contained in:
parent
81add6600c
commit
590e60d124
|
@ -130,6 +130,7 @@ in {
|
|||
EnvironmentFile = mkIf (cfg.environmentFile != null) [ cfg.environmentFile ];
|
||||
ExecStart = "${cfg.package}/bin/${executable} -c ${cfg.dataDir}/mxisd-config.yaml";
|
||||
ExecStartPre = "${pkgs.writeShellScript "mxisd-substitute-secrets" ''
|
||||
umask 0077
|
||||
${pkgs.envsubst}/bin/envsubst -o ${cfg.dataDir}/mxisd-config.yaml \
|
||||
-i ${configFile}
|
||||
''}";
|
||||
|
|
Loading…
Reference in New Issue
Block a user