Add --no-sandbox flag to nixos-rebuild command

Fixes kernel namespace sandboxing issues when running as systemd service.
The --no-sandbox flag disables Nix build sandboxing which requires
kernel namespaces not available in restricted service environments.
This commit is contained in:
Christoffer Martinsson 2025-10-25 01:37:21 +02:00
parent 2d3844b5dd
commit f5d2ebeaec

View File

@ -302,6 +302,7 @@ impl Agent {
tokio::process::Command::new("sudo")
.arg("/run/current-system/sw/bin/nixos-rebuild")
.arg("switch")
.arg("--no-sandbox")
.arg("--flake")
.arg(".")
.current_dir(working_dir)