diff --git a/deploy/nixos/live.nix b/deploy/nixos/live.nix index 7b9ab99..630f32d 100644 --- a/deploy/nixos/live.nix +++ b/deploy/nixos/live.nix @@ -141,7 +141,9 @@ in Environment = "LD_LIBRARY_PATH=${pkgs.stdenv.cc.cc.lib}/lib"; # Electron needs --no-sandbox in the live/testing environment # --enable-logging makes renderer console.log visible in journalctl - ExecStart = lib.mkForce "${pkgs-unstable.electron}/bin/electron --no-sandbox --disable-gpu-sandbox --disable-gpu --enable-logging ${atm-app}"; + ExecStart = lib.mkForce "${pkgs-unstable.electron}/bin/electron --no-sandbox --disable-gpu-sandbox --disable-gpu --disable-software-rasterizer --enable-logging ${atm-app}"; + # Prevent Electron from consuming all RAM on memory-constrained ATMs + MemoryMax = lib.mkForce "1G"; # Disable all security hardening that conflicts with Electron NoNewPrivileges = lib.mkForce false; ProtectSystem = lib.mkForce false; @@ -179,6 +181,16 @@ in }; }; + # Swap file — Douro/Tejo have only 2GB RAM; without swap the system + # hard-freezes under memory pressure instead of gracefully OOM-killing. + swapDevices = [{ + device = "/var/swapfile"; + size = 1024; # MB + }]; + + # Clean /tmp on boot to prevent stale Nix build artifacts from filling disk + boot.tmp.cleanOnBoot = true; + # Allow SSH with password for initial setup on the live system services.openssh.settings.PasswordAuthentication = lib.mkForce true;