renge/coturn: Fix ACME copying
Sandboxing requires + instead of ! for elevating permissions of pre-start script.
This commit is contained in:
parent
90d3720a75
commit
d23c15da90
|
@ -72,7 +72,8 @@ in
|
||||||
systemd.services.coturn = {
|
systemd.services.coturn = {
|
||||||
after = [ "acme-finished-${fqdn}.target" ];
|
after = [ "acme-finished-${fqdn}.target" ];
|
||||||
serviceConfig = {
|
serviceConfig = {
|
||||||
ExecStartPre = lib.singleton "!${pkgs.writeShellScript "coturn-setup-tls" ''
|
RuntimeDirectory = "turnserver";
|
||||||
|
ExecStartPre = lib.singleton "+${pkgs.writeShellScript "coturn-setup-tls" ''
|
||||||
cp ${config.security.acme.certs."${fqdn}".directory}/{fullchain,key}.pem /run/turnserver/
|
cp ${config.security.acme.certs."${fqdn}".directory}/{fullchain,key}.pem /run/turnserver/
|
||||||
chgrp turnserver /run/turnserver/{fullchain,key}.pem
|
chgrp turnserver /run/turnserver/{fullchain,key}.pem
|
||||||
''}";
|
''}";
|
||||||
|
|
Loading…
Reference in a new issue