1766193006
This commit is contained in:
@@ -2,14 +2,11 @@
|
||||
|
||||
{
|
||||
security.sudo.execWheelOnly = true;
|
||||
|
||||
|
||||
nix.settings.allowed-users = [ "@wheel" ];
|
||||
|
||||
security.apparmor.enable = true;
|
||||
|
||||
security.audit.enable = true;
|
||||
security.auditd.enable = true;
|
||||
|
||||
services.fail2ban.enable = true;
|
||||
|
||||
boot.kernel.sysctl = {
|
||||
|
||||
@@ -28,13 +28,7 @@
|
||||
enable = true;
|
||||
autoStart = true;
|
||||
openFirewall = true;
|
||||
};
|
||||
|
||||
security.wrappers.sunshine = {
|
||||
owner = "root";
|
||||
group = "root";
|
||||
capabilities = "cap_sys_admin+p";
|
||||
source = "${pkgs.sunshine}/bin/sunshine";
|
||||
capSysAdmin = true;
|
||||
};
|
||||
|
||||
services.avahi.publish.enable = true;
|
||||
|
||||
Reference in New Issue
Block a user