diff --git a/nixos/modules/services/security/endlessh-go.nix b/nixos/modules/services/security/endlessh-go.nix index 8a22c01390a65..9cac615ac4fc1 100644 --- a/nixos/modules/services/security/endlessh-go.nix +++ b/nixos/modules/services/security/endlessh-go.nix @@ -113,7 +113,13 @@ in ); DynamicUser = true; RootDirectory = rootDirectory; - BindReadOnlyPaths = [ builtins.storeDir ]; + BindReadOnlyPaths = [ + builtins.storeDir + "-/etc/hosts" + "-/etc/localtime" + "-/etc/nsswitch.conf" + "-/etc/resolv.conf" + ]; InaccessiblePaths = [ "-+${rootDirectory}" ]; RuntimeDirectory = baseNameOf rootDirectory; RuntimeDirectoryMode = "700";