Files
hakurei/options.md
T

948 lines
7.9 KiB
Markdown
Raw Normal View History

2024-11-19 18:12:35 +09:00
## environment\.fortify\.enable
Whether to enable fortify\.
*Type:*
boolean
*Default:*
` false `
*Example:*
` true `
## environment\.fortify\.package
The fortify package to use\.
*Type:*
package
*Default:*
2025-05-26 02:55:19 +09:00
` <derivation fortify-static-x86_64-unknown-linux-musl-0.4.1> `
2024-11-19 18:12:35 +09:00
## environment\.fortify\.apps
2025-05-26 02:55:19 +09:00
Declaratively configured fortify apps\.
2024-11-19 18:12:35 +09:00
*Type:*
2025-05-26 02:55:19 +09:00
attribute set of (submodule)
2024-11-19 18:12:35 +09:00
*Default:*
2025-05-26 02:55:19 +09:00
` { } `
2024-11-19 18:12:35 +09:00
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.packages
2024-11-19 18:12:35 +09:00
List of extra packages to install via home-manager\.
*Type:*
list of package
*Default:*
` [ ] `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.args
2025-03-30 23:05:57 +09:00
Custom args\.
Setting this to null will default to script name\.
*Type:*
null or (list of string)
*Default:*
` null `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.capability\.dbus
2024-11-19 18:12:35 +09:00
Whether to proxy D-Bus\.
*Type:*
boolean
*Default:*
` true `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.capability\.pulse
2024-11-19 18:12:35 +09:00
Whether to share the PulseAudio socket and cookie\.
*Type:*
boolean
*Default:*
` true `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.capability\.wayland
2024-11-19 18:12:35 +09:00
Whether to share the Wayland socket\.
*Type:*
boolean
*Default:*
` true `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.capability\.x11
2024-11-19 18:12:35 +09:00
Whether to share the X11 socket and allow connection\.
*Type:*
boolean
*Default:*
` false `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.command
2024-11-19 18:12:35 +09:00
Command to run as the target user\.
Setting this to null will default command to launcher name\.
Has no effect when script is set\.
*Type:*
null or string
*Default:*
` null `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.dbus\.session
2024-11-19 18:12:35 +09:00
D-Bus session bus custom configuration\.
Setting this to null will enable built-in defaults\.
*Type:*
null or (function that evaluates to a(n) anything)
*Default:*
` null `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.dbus\.system
2024-11-19 18:12:35 +09:00
D-Bus system bus custom configuration\.
Setting this to null will disable the system bus proxy\.
*Type:*
null or anything
*Default:*
` null `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.devel
2024-11-19 18:12:35 +09:00
2025-04-13 11:10:45 +09:00
Whether to enable debugging-related kernel interfaces\.
2025-01-23 20:49:49 +09:00
*Type:*
boolean
*Default:*
` false `
*Example:*
` true `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.device
2025-01-23 20:49:49 +09:00
2025-04-13 11:10:45 +09:00
Whether to enable access to all devices\.
2024-11-19 18:12:35 +09:00
*Type:*
boolean
*Default:*
` false `
*Example:*
` true `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.env
2024-11-19 18:12:35 +09:00
Environment variables to set for the initial process in the sandbox\.
*Type:*
null or (attribute set of string)
*Default:*
` null `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.extraConfig
2024-11-19 18:12:35 +09:00
Extra home-manager configuration\.
*Type:*
anything
*Default:*
` { } `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.extraPaths
2024-11-19 18:12:35 +09:00
2025-05-26 02:55:19 +09:00
Extra paths to make available to the container\.
2024-11-19 18:12:35 +09:00
*Type:*
2025-05-26 02:55:19 +09:00
list of (submodule)
2024-11-19 18:12:35 +09:00
*Default:*
` [ ] `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.extraPaths\.\*\.dev
Whether to enable use of device files\.
*Type:*
boolean
*Default:*
` false `
*Example:*
` true `
## environment\.fortify\.apps\.\<name>\.extraPaths\.\*\.dst
Mount point in container, same as src if null\.
*Type:*
null or string
*Default:*
` null `
## environment\.fortify\.apps\.\<name>\.extraPaths\.\*\.require
Whether to enable start failure if the bind mount cannot be established for any reason\.
*Type:*
boolean
*Default:*
` false `
*Example:*
` true `
## environment\.fortify\.apps\.\<name>\.extraPaths\.\*\.src
Host filesystem path to make available to the container\.
*Type:*
string
## environment\.fortify\.apps\.\<name>\.extraPaths\.\*\.write
Whether to enable mounting path as writable\.
*Type:*
boolean
*Default:*
` false `
*Example:*
` true `
## environment\.fortify\.apps\.\<name>\.gpu
2024-11-19 18:12:35 +09:00
Target process GPU and driver access\.
Setting this to null will enable GPU whenever X or Wayland is enabled\.
*Type:*
null or boolean
*Default:*
` null `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.groups
2024-11-19 18:12:35 +09:00
List of groups to inherit from the privileged user\.
*Type:*
list of string
*Default:*
` [ ] `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.identity
2024-11-19 18:12:35 +09:00
2025-05-26 02:55:19 +09:00
Application identity\. Identity 0 is reserved for system services\.
2024-11-19 18:12:35 +09:00
*Type:*
2025-05-26 02:55:19 +09:00
integer between 1 and 9999 (both inclusive)
2024-11-19 18:12:35 +09:00
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.insecureWayland
2025-02-15 23:03:13 +09:00
Whether to enable direct access to the Wayland socket\.
*Type:*
boolean
*Default:*
` false `
*Example:*
` true `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.mapRealUid
2024-11-19 18:12:35 +09:00
2025-01-23 20:49:49 +09:00
Whether to enable mapping to priv-user uid\.
*Type:*
boolean
*Default:*
` false `
*Example:*
` true `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.multiarch
2025-01-23 20:49:49 +09:00
2025-03-26 02:18:59 +09:00
Whether to enable multiarch kernel-level support\.
2024-11-19 18:12:35 +09:00
*Type:*
boolean
*Default:*
` false `
*Example:*
` true `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.name
2024-11-19 18:12:35 +09:00
Name of the apps launcher script\.
*Type:*
string
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.net
2024-11-19 18:12:35 +09:00
2025-01-23 20:49:49 +09:00
Whether to enable network access\.
2024-11-19 18:12:35 +09:00
*Type:*
boolean
*Default:*
` true `
*Example:*
` true `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.nix
2024-11-19 18:12:35 +09:00
2025-03-26 02:18:59 +09:00
Whether to enable nix daemon access\.
2024-11-19 18:12:35 +09:00
*Type:*
boolean
*Default:*
` false `
*Example:*
` true `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.path
2025-03-30 23:05:57 +09:00
Custom executable path\.
Setting this to null will default to the start script\.
*Type:*
null or string
*Default:*
` null `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.script
2024-11-19 18:12:35 +09:00
Application launch script\.
*Type:*
null or string
*Default:*
` null `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.share
2024-11-19 18:12:35 +09:00
Package containing share files\.
Setting this to null will default package name to wrapper name\.
*Type:*
null or package
*Default:*
` null `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.shareUid
Whether to enable sharing identity with another application\.
*Type:*
boolean
*Default:*
` false `
*Example:*
` true `
## environment\.fortify\.apps\.\<name>\.tty
2024-11-28 00:19:06 +09:00
2025-01-23 20:49:49 +09:00
Whether to enable access to the controlling terminal\.
2024-11-28 00:19:06 +09:00
*Type:*
boolean
*Default:*
` false `
*Example:*
` true `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.useCommonPaths
Whether to enable common extra paths\.
*Type:*
boolean
*Default:*
` true `
*Example:*
` true `
## environment\.fortify\.apps\.\<name>\.userns
2024-11-19 18:12:35 +09:00
2025-03-26 02:18:59 +09:00
Whether to enable user namespace creation\.
2024-11-19 18:12:35 +09:00
*Type:*
boolean
*Default:*
` false `
*Example:*
` true `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.apps\.\<name>\.verbose
2025-01-23 20:49:49 +09:00
Whether to enable launchers with verbose output\.
*Type:*
boolean
*Default:*
` false `
*Example:*
` true `
2025-05-26 02:55:19 +09:00
## environment\.fortify\.commonPaths
Common extra paths to make available to the container\.
*Type:*
list of (submodule)
*Default:*
` [ ] `
## environment\.fortify\.commonPaths\.\*\.dev
Whether to enable use of device files\.
*Type:*
boolean
*Default:*
` false `
*Example:*
` true `
## environment\.fortify\.commonPaths\.\*\.dst
Mount point in container, same as src if null\.
*Type:*
null or string
*Default:*
` null `
## environment\.fortify\.commonPaths\.\*\.require
Whether to enable start failure if the bind mount cannot be established for any reason\.
*Type:*
boolean
*Default:*
` false `
*Example:*
` true `
## environment\.fortify\.commonPaths\.\*\.src
Host filesystem path to make available to the container\.
*Type:*
string
## environment\.fortify\.commonPaths\.\*\.write
Whether to enable mounting path as writable\.
*Type:*
boolean
*Default:*
` false `
*Example:*
` true `
## environment\.fortify\.extraHomeConfig
Extra home-manager configuration to merge with all target users\.
*Type:*
anything
2025-02-23 18:52:33 +09:00
## environment\.fortify\.fsuPackage
The fsu package to use\.
*Type:*
package
*Default:*
2025-05-26 02:55:19 +09:00
` <derivation fortify-fsu-0.4.1> `
2025-01-23 20:49:49 +09:00
2024-11-19 18:12:35 +09:00
## environment\.fortify\.stateDir
The state directory where app home directories are stored\.
*Type:*
string
## environment\.fortify\.users
Users allowed to spawn fortify apps and their corresponding fortify fid\.
*Type:*
attribute set of integer between 0 and 99 (both inclusive)