mirror of
https://github.com/ordinary-dev/nixos-config.git
synced 2024-09-20 03:40:29 +05:00
feat: harden openssh settings
This commit is contained in:
parent
042f5561cd
commit
de591bd560
|
@ -30,6 +30,7 @@
|
||||||
./services/mastodon.nix
|
./services/mastodon.nix
|
||||||
./services/microboard.nix
|
./services/microboard.nix
|
||||||
./services/nextcloud.nix
|
./services/nextcloud.nix
|
||||||
|
./services/openssh.nix
|
||||||
./services/phoenix.nix
|
./services/phoenix.nix
|
||||||
./services/prosody.nix
|
./services/prosody.nix
|
||||||
./services/ss.nix
|
./services/ss.nix
|
||||||
|
@ -80,12 +81,6 @@
|
||||||
deluged
|
deluged
|
||||||
];
|
];
|
||||||
|
|
||||||
# Enable the OpenSSH daemon.
|
|
||||||
services.openssh = {
|
|
||||||
enable = true;
|
|
||||||
settings.PasswordAuthentication = false;
|
|
||||||
};
|
|
||||||
|
|
||||||
powerManagement.powertop.enable = true;
|
powerManagement.powertop.enable = true;
|
||||||
|
|
||||||
system.stateVersion = "22.11";
|
system.stateVersion = "22.11";
|
||||||
|
|
14
nixos/services/openssh.nix
Normal file
14
nixos/services/openssh.nix
Normal file
|
@ -0,0 +1,14 @@
|
||||||
|
{ config, ... }:
|
||||||
|
{
|
||||||
|
services.openssh = {
|
||||||
|
enable = true;
|
||||||
|
settings = {
|
||||||
|
PasswordAuthentication = false;
|
||||||
|
PermitRootLogin = "no";
|
||||||
|
AllowUsers = [
|
||||||
|
"lumin"
|
||||||
|
"forgejo"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
Loading…
Reference in a new issue