environment.etc."lxc/default.conf".text = cfg.defaultConfig;
systemd.tmpfiles.rules = [ "d /var/lib/lxc/rootfs 0755 root root -" ];
- security.apparmor = {
- profiles = {
- "bin.lxc-start" = ''
- #include ${pkgs.lxc}/etc/apparmor.d/usr.bin.lxc-start
- '';
- "lxc-containers" = ''
- #include ${pkgs.lxc}/etc/apparmor.d/lxc-containers
- '';
- };
- includes = [ (pkgs.lxc+"/etc/apparmor.d") ];
+ security.apparmor.packages = [ pkgs.lxc ];
+ security.apparmor.policies = {
+ "bin/lxc-start".profile = ''
+ #include ${pkgs.lxc}/etc/apparmor.d/usr.bin.lxc-start
+ '';
+ "lxc-containers".profile = ''
+ #include ${pkgs.lxc}/etc/apparmor.d/lxc-containers
+ '';
};
};
}