diff options
| author | Maximilian Bosch <maximilian@mbosch.me> | 2024-12-11 18:51:53 +0100 |
|---|---|---|
| committer | Maximilian Bosch <maximilian@mbosch.me> | 2024-12-12 13:42:52 +0100 |
| commit | 51a6938a44eaab83af90c5b7dfb08a6a66b0ad45 (patch) | |
| tree | 941f6da075ebda1b9cf910c89e4296240f403b3a /pkgs/development/python-modules/httpserver | |
| parent | 0d2883adc2c63cc5f56eb638494274aae272aca2 (diff) | |
nixos/doc: document how to allow-list tablespaces
It was brought up that the restricted file-system access breaks
tablespaces[1]. I'd argue that this is the desired behavior, the whole
point of the hardening is the lock the service down and I don't consider
tablespaces common enough to elevate privileges again. Especially since
the workaround is trivial as shown in the diff.
For completeness sake, this adds the necessary `ReadWritePaths` change
to the postgresql section of the manual.
This also adds a small correction about the state of
`ensurePermissions`.
[1] https://github.com/NixOS/nixpkgs/pull/344925#issuecomment-2521188907
Diffstat (limited to 'pkgs/development/python-modules/httpserver')
0 files changed, 0 insertions, 0 deletions
