Try sandboxing
parent
44a65b4f90
commit
d1c1c0693b
|
@ -1,6 +1,6 @@
|
||||||
local PROD = 'production';
|
local PROD = 'production';
|
||||||
local STAGE = 'staging';
|
local STAGE = 'staging';
|
||||||
local NIX = 'nix --extra-experimental-features nix-command --extra-experimental-features flakes ';
|
local NIX = 'nix --sandbox --extra-experimental-features nix-command --extra-experimental-features flakes ';
|
||||||
local VOLUMES = [
|
local VOLUMES = [
|
||||||
{ name: 'site', path: '/site' },
|
{ name: 'site', path: '/site' },
|
||||||
{ name: 'cache', path: '/nix/store' },
|
{ name: 'cache', path: '/nix/store' },
|
||||||
|
@ -28,6 +28,7 @@ local Step(env, name, cmds, extras={}, volumes=VOLUMES) =
|
||||||
volumes: volumes,
|
volumes: volumes,
|
||||||
commands: cmds,
|
commands: cmds,
|
||||||
when: WhenProd(prod),
|
when: WhenProd(prod),
|
||||||
|
privileged: true,
|
||||||
} + extras;
|
} + extras;
|
||||||
|
|
||||||
local BootstrapStep =
|
local BootstrapStep =
|
||||||
|
|
Loading…
Reference in New Issue