diff --git a/modules/security.nix b/modules/security.nix index 9d10c3b..ba2a6ef 100644 --- a/modules/security.nix +++ b/modules/security.nix @@ -2,14 +2,11 @@ { security.sudo.execWheelOnly = true; - + nix.settings.allowed-users = [ "@wheel" ]; security.apparmor.enable = true; - security.audit.enable = true; - security.auditd.enable = true; - services.fail2ban.enable = true; boot.kernel.sysctl = { diff --git a/modules/services.nix b/modules/services.nix index b4fff7f..2c7b01c 100644 --- a/modules/services.nix +++ b/modules/services.nix @@ -28,13 +28,7 @@ enable = true; autoStart = true; openFirewall = true; - }; - - security.wrappers.sunshine = { - owner = "root"; - group = "root"; - capabilities = "cap_sys_admin+p"; - source = "${pkgs.sunshine}/bin/sunshine"; + capSysAdmin = true; }; services.avahi.publish.enable = true;