diff --git a/modules/nixos/services/homeserver/restic/backups.nix b/modules/nixos/services/homeserver/restic/backups.nix index c05cd95..ee86741 100644 --- a/modules/nixos/services/homeserver/restic/backups.nix +++ b/modules/nixos/services/homeserver/restic/backups.nix @@ -43,7 +43,7 @@ services.restic.backups = { main = { - user = "restic"; + user = "restic-backup"; package = pkgs.writeShellScriptBin "restic" '' exec /run/wrappers/bin/restic "$@" ''; diff --git a/modules/nixos/services/restic.nix b/modules/nixos/services/restic.nix index ff42627..2ef3330 100644 --- a/modules/nixos/services/restic.nix +++ b/modules/nixos/services/restic.nix @@ -3,17 +3,17 @@ { # make wrapper to run restic rootless users = { - users.restic = { - group = "restic"; + users.restic-backup = { + group = "restic-backup"; isSystemUser = true; }; - groups.restic = {}; + groups.restic-backup = {}; }; security.wrappers.restic = { source = lib.getExe pkgs.restic; - owner = "restic"; - group = "restic"; + owner = "restic-backup"; + group = "restic-backup"; permissions = "500"; capabilities = "cap_dac_read_search+ep"; };