mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-07 20:47:14 +03:00
opencode fix linger
This commit is contained in:
@@ -336,7 +336,18 @@ in
|
|||||||
# Refs:
|
# Refs:
|
||||||
# https://www.freedesktop.org/software/systemd/man/systemd.resource-control.html
|
# https://www.freedesktop.org/software/systemd/man/systemd.resource-control.html
|
||||||
# https://www.freedesktop.org/software/systemd/man/systemd.exec.html#OOMScoreAdjust=
|
# https://www.freedesktop.org/software/systemd/man/systemd.exec.html#OOMScoreAdjust=
|
||||||
systemd.user.services.opencode-web.serviceConfig = {
|
# Override the [Service] section emitted by `programs.opencode.web`.
|
||||||
|
# Upstream writes its own [Service] keys (ExecStart, EnvironmentFile,
|
||||||
|
# Restart, RestartSec); merging on the same `Service` attrset unions both
|
||||||
|
# sides into the same systemd section, so cgroup limits land where systemd
|
||||||
|
# actually reads them.
|
||||||
|
#
|
||||||
|
# NOTE: do NOT use `serviceConfig = { ... }` here — it is rendered as a
|
||||||
|
# literal `[serviceConfig]` section header by home-manager, which systemd
|
||||||
|
# silently ignores (verified on sapphira, journal: "Unknown section
|
||||||
|
# 'serviceConfig'. Ignoring."). The previous version of this block was
|
||||||
|
# exactly that, so the OOM/cgroup protection above never took effect.
|
||||||
|
systemd.user.services.opencode-web.Service = {
|
||||||
MemoryHigh = "1G";
|
MemoryHigh = "1G";
|
||||||
MemoryMax = "2G";
|
MemoryMax = "2G";
|
||||||
OOMScoreAdjust = -900;
|
OOMScoreAdjust = -900;
|
||||||
|
|||||||
@@ -68,6 +68,11 @@ in
|
|||||||
hashedPasswordFile = config.sops.secrets.hashed_password.path; # hashed_password
|
hashedPasswordFile = config.sops.secrets.hashed_password.path; # hashed_password
|
||||||
homeMode = "700";
|
homeMode = "700";
|
||||||
home = "/home/${user}";
|
home = "/home/${user}";
|
||||||
|
# Linger keeps `user@<uid>.service` (the systemd user manager) alive
|
||||||
|
# across logouts, so user services like opencode-web survive when no
|
||||||
|
# SSH/login session is active. Without this the service is torn down
|
||||||
|
# together with the user manager on the last session close.
|
||||||
|
linger = true;
|
||||||
extraGroups = [
|
extraGroups = [
|
||||||
"audio"
|
"audio"
|
||||||
"disk"
|
"disk"
|
||||||
|
|||||||
Reference in New Issue
Block a user