feat!(services/self_host): now SSO is running under the authentik user
This commit is contained in:
parent
246163fde9
commit
2a36f5c9c1
1 changed files with 9 additions and 0 deletions
|
|
@ -12,6 +12,15 @@ let
|
|||
in
|
||||
{
|
||||
config = lib.mkIf cfg {
|
||||
users = {
|
||||
users.authentik = {
|
||||
isSystemUser = true;
|
||||
description = "Authentik service user";
|
||||
group = "authentik";
|
||||
home = "/var/lib/authentik";
|
||||
};
|
||||
groups.authentik = {};
|
||||
};
|
||||
systemd.tmpfiles.rules = [
|
||||
"d /run/authentik 0750 authentik authentik - -"
|
||||
];
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue