mirror of
https://github.com/ordinary-dev/nixos-config.git
synced 2024-09-19 19:30:28 +05:00
feat: harden openssh settings
This commit is contained in:
parent
042f5561cd
commit
de591bd560
|
@ -30,6 +30,7 @@
|
|||
./services/mastodon.nix
|
||||
./services/microboard.nix
|
||||
./services/nextcloud.nix
|
||||
./services/openssh.nix
|
||||
./services/phoenix.nix
|
||||
./services/prosody.nix
|
||||
./services/ss.nix
|
||||
|
@ -80,12 +81,6 @@
|
|||
deluged
|
||||
];
|
||||
|
||||
# Enable the OpenSSH daemon.
|
||||
services.openssh = {
|
||||
enable = true;
|
||||
settings.PasswordAuthentication = false;
|
||||
};
|
||||
|
||||
powerManagement.powertop.enable = true;
|
||||
|
||||
system.stateVersion = "22.11";
|
||||
|
|
14
nixos/services/openssh.nix
Normal file
14
nixos/services/openssh.nix
Normal file
|
@ -0,0 +1,14 @@
|
|||
{ config, ... }:
|
||||
{
|
||||
services.openssh = {
|
||||
enable = true;
|
||||
settings = {
|
||||
PasswordAuthentication = false;
|
||||
PermitRootLogin = "no";
|
||||
AllowUsers = [
|
||||
"lumin"
|
||||
"forgejo"
|
||||
];
|
||||
};
|
||||
};
|
||||
}
|
Loading…
Reference in a new issue