nixos/fail2ban: add option to enable sending mail #157364
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Motivation for this change
Addresses #156480 (cannot send mail because the systemd unit is sandboxed). This PR adds the option
fail2ban.mail.enable
. Setting this prevents addingNoNewPrivileges
andProtectSystem
in the systemd unit configuration. It also addsmta=mail
tojail.conf.local
, and adds the packagemailutils
.This PR also adds options
fail2ban.mail.destemail
andfail2ban.mail.sender
that add the corresponding entries tojail.conf.local
.Things done
sandbox = true
set innix.conf
? (See Nix manual)nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD"
. Note: all changes have to be committed, also see nixpkgs-review usage./result/bin/
)nixos/doc/manual/md-to-db.sh
to update generated release notes