Arnold Krille
9045a8e24c
declarative containers: additional veths
...
With these changes, a container can have more then one veth-pair. This allows for example to have LAN and DMZ as bridges on the host and add dedicated containers for proxies, ipv4-firewall and ipv6-firewall. Or to have a bridge for normal WAN, one bridge for administration and one bridge for customer-internal communication. So that web-server containers can be reached from outside per http, from the management via ssh and can talk to their database via the customer network.
The scripts to set up the containers are now rendered several times instead of just one template. The scripts now contain per-container code to configure the extra veth interfaces. The default template without support for extra-veths is still rendered for the imperative containers.
Also a test is there to see if extra veths can be placed into host-bridges or can be reached via routing.
2016-07-28 23:06:41 +02:00
Franz Pletz
263fff0ab8
linux: fix build, remove upstreamed patches
2016-07-28 23:05:27 +02:00
Franz Pletz
9aee2a17af
linux: 4.6.4 -> 4.6.5
...
Removed patch was applied upstream.
2016-07-28 23:05:27 +02:00
Franz Pletz
b68fe1a572
linux: 4.5.6 -> 4.5.7
2016-07-28 23:05:27 +02:00
Joachim F
d472a823aa
Merge pull request #17348 from igsha/fix-libgxps
...
libgxps: fix building
2016-07-28 22:34:31 +02:00
Franz Pletz
8605d76f17
Revert "mariadb: 10.1.9 -> 10.1.16 (security)"
...
This reverts commit 55bd6da9fb
.
Fixes #17340 .
2016-07-28 22:31:43 +02:00
Vladimír Čunát
3a402e248f
Merge branch 'staging'
...
It includes a security update of libidn.
2016-07-28 20:36:17 +02:00
Igor Sharonov
b11b3dfa2d
libgxps: fix building
2016-07-28 21:06:39 +03:00
Eelco Dolstra
fd5bbdb436
nixos-containers: Set DevicePolicy=closed
...
This makes the container a bit more secure, by preventing root
creating device nodes to access the host file system, for
instance. (Reference: systemd-nspawn@.service in systemd.)
2016-07-28 17:58:55 +02:00
Eelco Dolstra
bf3edfbb3c
nixos-containers: Use systemd 231's --notify-ready flag
2016-07-28 17:58:52 +02:00
Eelco Dolstra
42f8df10a2
linux: 4.4.16 -> 4.4.16
2016-07-28 17:03:55 +02:00
Eelco Dolstra
51871dfb37
systemd: 230 -> 231
2016-07-28 17:03:55 +02:00
Eelco Dolstra
09115245d9
Merge pull request #17341 from mimadrid/update/nano-2.6.2
...
nano: 2.6.1 -> 2.6.2
2016-07-28 16:58:20 +02:00
Frederik Rietdijk
9a9294d0c6
Merge pull request #17332 from lancelotsix/update_sqlalchemy
...
Update sqlalchemy and related
2016-07-28 16:47:35 +02:00
mimadrid
ca780df195
nano: 2.6.1 -> 2.6.2
2016-07-28 16:46:25 +02:00
Robin Gloster
154af9e67d
Merge pull request #9499 from khumba/scilab-bin-5
...
scilab-bin: init at 5.5.2
2016-07-28 16:43:08 +02:00
Robin Gloster
bddec681fb
Merge pull request #17334 from RamKromberg/init/catclock
...
catclock: init at 2015-10-04
2016-07-28 16:31:12 +02:00
Marco Maggesi
c28eb6c2ba
Update HOL Light to version 2016-07-23.
2016-07-28 15:56:20 +02:00
Frederik Rietdijk
ace13888c7
Merge pull request #17282 from magnetophon/faust1git
...
faust1git: 2016-04-27 -> 2016-07-19
2016-07-28 15:11:07 +02:00
Frederik Rietdijk
e40f5e6658
Merge pull request #17338 from matthiasbeyer/update-rtv
...
Update rtv
2016-07-28 15:01:31 +02:00
Thomas Tuegel
399f8ab48f
Merge pull request #17336 from DamienCassou/melpa-stable-generated
...
melpa-stable-packages: 2016-07-28
2016-07-28 07:43:38 -05:00
Peter Hoeg
d0a177411d
kde5.systemsettings: include missing qtquickcontrols dependency
2016-07-28 07:38:30 -05:00
Frederik Rietdijk
00278ef685
Merge pull request #17335 from siddharthist/yapf/0.11.0
...
yapf: init at 0.11.0
2016-07-28 14:27:25 +02:00
Matthias Beyer
39cd6895c1
rtv: 1.9.0 -> 1.10.0
2016-07-28 14:00:37 +02:00
Matthias Beyer
4954ac202a
pythonPackages: praw: 3.3.0 -> 3.5.0
2016-07-28 14:00:20 +02:00
Robin Gloster
356c2fe00d
Revert "nginx: Verify that configuration is syntactically correct" ( #17337 )
2016-07-28 13:55:06 +02:00
Damien Cassou
b9f7a65179
melpa-stable-packages: 2016-07-28
2016-07-28 13:44:44 +02:00
Peter Hoeg
62f2f72e98
tmux module: do not override keys by default in VI mode ( #17330 )
...
We want to stick to upstream defaults as much as possible.
As pointed out by @8573 in #16999 , this was not the case.
2016-07-28 13:10:42 +02:00
Langston Barrett
f457c74ab3
yapf: init at 0.11.0
2016-07-28 13:00:13 +02:00
Lancelot SIX
ffbe8d13fd
Merge pull request #17333 from matthiasbeyer/update-timewarrior
...
timewarrior: 0.9.5.alpha -> 1.0.0.beta1
Built and tested.
2016-07-28 12:32:50 +02:00
Ram Kromberg
4f94e026f4
catclock: init at 2015-10-04
2016-07-28 12:09:31 +03:00
Matthias Beyer
af5e45cf2e
timewarrior: 0.9.5.alpha -> 1.0.0.beta1
2016-07-28 10:57:19 +02:00
Lancelot SIX
c6a0d680d8
pythonPackages.sqlalchemy_1_0: 1.0.12 -> 1.0.14
2016-07-28 10:08:48 +02:00
Lancelot SIX
771a0aae49
pythonPackages.geoalchemy2: 0.3.0.dev1 -> 0.3.0
2016-07-28 10:08:35 +02:00
Lancelot SIX
4a91da6321
pythonPackages.shapely: 1.5.13 -> 1.5.15
...
Fix tests
2016-07-28 10:08:13 +02:00
wmapp
62ba6b07f2
sct: Updated sha256 in default.nix ( #17163 )
2016-07-28 09:21:21 +02:00
Pascal Wittmann
cf114708fe
Merge pull request #17153 from rasendubi/rhythmbox
...
rhythmbox: init at 3.2.1
2016-07-28 08:56:07 +02:00
Peter Hoeg
65ef5d8f5b
rspam module: use mkEnableOption
...
See #17329 .
2016-07-28 07:06:35 +02:00
Franz Pletz
55bd6da9fb
mariadb: 10.1.9 -> 10.1.16 (security)
2016-07-28 06:56:14 +02:00
Franz Pletz
975d33e640
mysql51: remove, not maintained anymore
2016-07-28 06:56:13 +02:00
Bryan Gardiner
ed071594e5
scilab-bin: init at 5.5.2
...
A built-from-source Scilab 5 package looks to be a lot more work, and some
dependencies are missing from Nixpkgs, but the binary version with bundled
dependencies works.
2016-07-27 21:30:12 -07:00
Franz Pletz
8a1e7cd556
rspamd service: fix runtime directory, log to syslog
...
Fixes #17144 .
2016-07-28 06:22:29 +02:00
Franz Pletz
d23521b16c
rmilter service: use runtime dirctory for socket
2016-07-28 06:22:23 +02:00
Franz Pletz
63784b8021
php: 5.5.37 -> 5.5.38, 5.6.23 -> 5.6.24 (security)
...
https://secure.php.net/ChangeLog-5.php#5.5.38
https://secure.php.net/ChangeLog-5.php#5.6.24
2016-07-28 06:22:23 +02:00
Jun Hao
5bf4a9ff73
webkitgtk24x: fix libwebp missing library path, add libobjc as dependency on OSX ( #17198 )
2016-07-28 04:45:54 +02:00
Christine Koppelt
39da575262
add epub for NixOS manual (second try) ( #17205 )
2016-07-28 04:27:39 +02:00
Robin Lambertz
b65e9d87e2
matrix-synapse: Only run StartPre script when data folder doesn't exist ( #17216 )
2016-07-28 04:13:21 +02:00
Matthias Beyer
c31cbe8f9c
xterm: Make dec-locator support optional ( #17238 )
...
Enable it by default but allow disabling, which solves some issues one
might have with vim/nvim as reported and documented in
#17158
#17170
#17234
neovim/neovim#5015
2016-07-28 04:08:54 +02:00
leenaars
ad87385b0e
simpleTpmPk11: git-20140925 -> git-20160712 ( #17317 )
2016-07-28 04:01:08 +02:00
Michele Guerini Rocco
cf8c16e3aa
mkvtoolnix: 9.2.0 -> 9.3.1 ( #17321 )
2016-07-28 04:00:04 +02:00