ci-deploy: grant the trigger user polkit access to nixos-upgrade #26
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/ci-deploy-polkit"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Run #316 (
ci: validate deploy key and run ssh -T before deploy) showed the deploy key itself is now fine —ssh -Tconnected and the forced command ran — but the trigger script'ssystemctl start --wait nixos-upgrade.servicewas denied:The forced command runs as the non-interactive
ci-deployuser, so polkit checks the start request and denies it without a rule. This PR adds asecurity.polkit.extraConfigrule insidemodules/ci-deploy.nixallowing exactly theci-deployuser to start exactlynixos-upgrade.service(polkit is already enabled on freun-dev for the netbird rules; this only adds the scoped rule).Verified:
nix eval+ fullnix buildofnixosConfigurations.freun-dev.config.system.build.toplevel; the mergedsecurity.polkit.extraConfigcontains both the netbird rules and the new nixos-upgrade rule; polkit.enable = true.