fix: add stability fixes to installed ATM config

Same fixes as live.nix: disable SwiftShader, enforce MemoryMax=1G,
add 1GB swap file, and clean /tmp on boot. Applies to douro-installed
and tejo-installed configs used by nixos-rebuild on disk-installed ATMs.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Patrick Mulligan 2026-03-02 13:08:28 -05:00
commit fe5a3d661f

View file

@ -151,7 +151,8 @@
serviceConfig = { serviceConfig = {
EnvironmentFile = lib.mkForce "/var/lib/lamassu-atm/.env"; EnvironmentFile = lib.mkForce "/var/lib/lamassu-atm/.env";
Environment = "LD_LIBRARY_PATH=${pkgs.stdenv.cc.cc.lib}/lib"; Environment = "LD_LIBRARY_PATH=${pkgs.stdenv.cc.cc.lib}/lib";
ExecStart = lib.mkForce "${pkgs-unstable.electron}/bin/electron --no-sandbox --disable-gpu-sandbox --disable-gpu --enable-logging ${atm-app}"; ExecStart = lib.mkForce "${pkgs-unstable.electron}/bin/electron --no-sandbox --disable-gpu-sandbox --disable-gpu --disable-software-rasterizer --enable-logging ${atm-app}";
MemoryMax = lib.mkForce "1G";
NoNewPrivileges = lib.mkForce false; NoNewPrivileges = lib.mkForce false;
ProtectSystem = lib.mkForce false; ProtectSystem = lib.mkForce false;
ProtectHome = lib.mkForce false; ProtectHome = lib.mkForce false;
@ -176,6 +177,12 @@
}; };
}; };
# Swap file — ATMs have ~2GB RAM; prevents hard-freeze under memory pressure
swapDevices = [{ device = "/var/swapfile"; size = 1024; }];
# Clean /tmp on boot to prevent stale build artifacts filling disk
boot.tmp.cleanOnBoot = true;
# SSH with password for initial provisioning # SSH with password for initial provisioning
services.openssh.settings.PasswordAuthentication = lib.mkForce true; services.openssh.settings.PasswordAuthentication = lib.mkForce true;
}) })