From 47d0f8a2d637bb15e4ab60d2c276e91dde441efc Mon Sep 17 00:00:00 2001 From: "assistant-ngalaiko[bot]" <307087249+assistant-ngalaiko[bot]@users.noreply.github.com> Date: Sun, 20 Sep 2026 23:56:33 +0000 Subject: [PATCH] Fix vault sync env continuation --- hosts/exedev/users/assistant.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/hosts/exedev/users/assistant.nix b/hosts/exedev/users/assistant.nix index 5568bd6..7b31a36 100644 --- a/hosts/exedev/users/assistant.nix +++ b/hosts/exedev/users/assistant.nix @@ -206,15 +206,15 @@ in else echo "assistant-vault-sync: $envfile missing; Discogs sync skipped until DISCOGS_TOKEN is placed (see README)." >&2 fi + # Reference cacert directly instead of /etc: its symlink targets the + # image rootfs store path, which may be garbage-collected after an + # in-place deployment. exec /command/s6-setuidgid assistant \ env \ HOME=/var/lib/assistant \ USER=assistant \ SHELL=/bin/sh \ PATH=/etc/profiles/per-user/assistant/bin:/nix/var/nix/profiles/default/bin:/bin:/sbin:/usr/bin \ - # Reference cacert directly instead of /etc: its symlink targets the - # image rootfs store path, which may be garbage-collected after an - # in-place deployment. SSL_CERT_FILE=${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt \ NIX_SSL_CERT_FILE=${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt \ NODE_EXTRA_CA_CERTS=${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt \