diff --git a/modules/config/impermanence.nix b/modules/config/impermanence.nix index 04f0b40..11aa8cf 100644 --- a/modules/config/impermanence.nix +++ b/modules/config/impermanence.nix @@ -90,7 +90,10 @@ in { hideMounts = true; directories = [ - "/var/tmp/agenix-rekey" + { + directory = "/var/tmp/agenix-rekey"; + mode = "1777"; + } "/var/tmp/nix-import-encrypted" # Decrypted repo-secrets can be kept "/var/lib/systemd" "/var/log"