summaryrefslogtreecommitdiff
path: root/parts/modules/nixos/base/security.nix
diff options
context:
space:
mode:
authorseth <[email protected]>2023-10-30 04:22:32 -0400
committerseth <[email protected]>2023-10-30 09:46:15 +0000
commit10b0df38b4286237b56ff9177f8d4c5676bfb5c1 (patch)
treeab298c74339bf9bc41571fa88746ecd9c522fbdf /parts/modules/nixos/base/security.nix
parent4c2c60a4f2b14c1e6ffaffe5e301dc31ac4fed0f (diff)
tree-wide: refactor
i went overboard on modules. this is much comfier
Diffstat (limited to 'parts/modules/nixos/base/security.nix')
-rw-r--r--parts/modules/nixos/base/security.nix27
1 files changed, 0 insertions, 27 deletions
diff --git a/parts/modules/nixos/base/security.nix b/parts/modules/nixos/base/security.nix
deleted file mode 100644
index e13d1c7..0000000
--- a/parts/modules/nixos/base/security.nix
+++ /dev/null
@@ -1,27 +0,0 @@
-{
- lib,
- pkgs,
- ...
-}: let
- inherit (lib) mkDefault;
-in {
- security = {
- apparmor.enable = mkDefault true;
- audit.enable = mkDefault true;
- auditd.enable = mkDefault true;
- polkit.enable = mkDefault true;
- rtkit.enable = mkDefault true;
- sudo.execWheelOnly = true;
- };
-
- services.dbus.apparmor = mkDefault "enabled";
-
- users = {
- defaultUserShell = pkgs.bash;
- mutableUsers = false;
- };
-
- nix.settings = {
- trusted-users = ["root" "@wheel"];
- };
-}