2024-04-18 17:53:15 -04:00
|
|
|
{ lib, ... }:
|
2024-04-10 18:23:40 -04:00
|
|
|
{
|
2024-02-05 22:45:43 +01:00
|
|
|
security.auditd.enable = true;
|
2023-12-23 06:49:01 +01:00
|
|
|
|
2023-12-24 20:09:35 +01:00
|
|
|
boot = {
|
|
|
|
default = true;
|
2024-03-03 18:06:28 -05:00
|
|
|
kernel.sysctl = {
|
|
|
|
"net.ipv6.conf.ens3.accept_ra" = 1;
|
|
|
|
};
|
2023-12-24 20:09:35 +01:00
|
|
|
};
|
|
|
|
|
2023-12-27 10:03:13 +01:00
|
|
|
networking = {
|
|
|
|
firewall = {
|
|
|
|
enable = lib.mkDefault true;
|
2024-01-02 16:30:08 +01:00
|
|
|
allowedTCPPorts = [ ];
|
2023-12-27 10:03:13 +01:00
|
|
|
};
|
|
|
|
};
|
2023-12-23 06:49:01 +01:00
|
|
|
|
2024-04-18 17:53:15 -04:00
|
|
|
services.autopull = {
|
|
|
|
enable = true;
|
|
|
|
ssh-key = "/root/.ssh/id_ed25519_ghdeploy";
|
|
|
|
path = /root/dotfiles;
|
2023-12-23 06:49:01 +01:00
|
|
|
};
|
|
|
|
|
2024-04-18 17:53:15 -04:00
|
|
|
system.autoUpgrade = {
|
|
|
|
enable = true;
|
|
|
|
flags = [ "--accept-flake-config" ];
|
|
|
|
randomizedDelaySec = "1h";
|
|
|
|
persistent = true;
|
|
|
|
flake = "github:RAD-Development/nix-dotfiles";
|
2023-12-23 06:49:01 +01:00
|
|
|
};
|
2023-12-25 13:29:02 -05:00
|
|
|
}
|