diff --git a/nix/nixosModules.nix b/nix/nixosModules.nix index 52ba773776..328880a1e5 100644 --- a/nix/nixosModules.nix +++ b/nix/nixosModules.nix @@ -364,8 +364,9 @@ # service has no /run/user/ unless the uid lingers, and the # dispatch fails closed — without this, no cron job runs at all. # - # Needs nixpkgs >= 25.05 (users.manageLingering). - linger = lib.mkDefault true; + # Needs nixpkgs >= 25.05 (users.manageLingering). In container mode cron + # runs inside the container, so the host uid needs no user manager. + linger = lib.mkDefault (!cfg.container.enable); }; }) diff --git a/website/docs/getting-started/nix-setup.md b/website/docs/getting-started/nix-setup.md index 3041696e5d..b49616bd0d 100644 --- a/website/docs/getting-started/nix-setup.md +++ b/website/docs/getting-started/nix-setup.md @@ -223,6 +223,10 @@ To enable container mode, add one line: Container mode auto-enables `virtualisation.docker.enable` via `mkDefault`. If you use Podman instead, set `container.backend = "podman"` and `virtualisation.docker.enable = false`. ::: +:::note Cron on a native install needs a lingering service user +Scheduled cron jobs are launched in a transient `systemd-run --user --scope` so a gateway restart cannot kill a running job. That needs a systemd user manager for the service uid, which a system service only gets when the uid lingers. With `createUser = true` the module sets `users.users..linger = true` (nixpkgs ≥ 25.05), orders the gateway after `linger-users.service`, and waits briefly for `/run/user//bus` before starting. If you declare the user yourself (`createUser = false`), set `linger = true` on it or run `sudo loginctl enable-linger ` once; otherwise cron degrades to unscoped workers (or fails closed under `cron.require_restart_safe_scope: true`). +::: + --- ## Configuration