The agent runs as a systemd DynamicUser and was failing the nginx acquisition with "No matching files for pattern /var/log/nginx/access.log" because access.log is nginx:nginx 640 — readOnlyPaths handles sandbox visibility but not Unix perms. extraGroups = [ "nginx" ] gets it past the group bit. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| adguard.nix | ||
| arr-interconnect.nix | ||
| authelia.nix | ||
| bazarr.nix | ||
| cloudflare-ddns.md | ||
| cloudflare-ddns.nix | ||
| crowdsec.nix | ||
| fail2ban.nix | ||
| game-servers.nix | ||
| go2rtc.nix | ||
| homepage.nix | ||
| jellyfin.nix | ||
| nginx.nix | ||
| prowlarr.nix | ||
| qbittorrent-nox.nix | ||
| radarr.nix | ||
| router.nix | ||
| server-permissions.nix | ||
| sonarr.nix | ||