We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
2 parents c702134 + 00ec90a commit 81c6240Copy full SHA for 81c6240
modules/containers.nix
@@ -44,11 +44,11 @@ in
44
useIPTables = !config.networking.nftables.enable;
45
in lib.mkIf cfgd.recommendedDefaults {
46
fixed-cidr-v6 = "fd00::/80"; # TODO: is this a good idea for all networks?
47
- iptables = useIPTables;
48
- ip6tables = useIPTables;
+ iptables = lib.mkIf useIPTables true;
+ ip6tables = lib.mkIf useIPTables true;
49
ipv6 = true;
50
# userland proxy is slow, does not give back ports and if iptables/nftables is available it is just worse
51
- userland-proxy = false;
+ userland-proxy = lib.mkIf useIPTables false;
52
};
53
54
autoPrune = lib.mkIf cfgd.aggressiveAutoPrune {
0 commit comments