Commit 6da0fd26 authored by erdnaxe's avatar erdnaxe 🦋
Browse files

NixOS 22.05 cleanup

parent 569c6031
......@@ -84,17 +84,6 @@
SystemCallArchitectures = "native";
};
systemd.services.wpa_supplicant.serviceConfig = {
ProtectControlGroups = true; # OpenSUSE
ProtectHome = "read-only"; # OpenSUSE
ProtectHostname = true; # OpenSUSE
ProtectKernelLogs = true; # OpenSUSE
ProtectKernelModules = true; # OpenSUSE
ProtectKernelTunables = true; # OpenSUSE
ProtectSystem = "full"; # OpenSUSE
RestrictRealtime = true; # OpenSUSE
};
systemd.services.postgresql.serviceConfig = {
NoNewPrivileges = true; # arch
PrivateDevices = true; # arch
......
......@@ -160,12 +160,6 @@
latitude = 48.85;
longitude = 2.35;
};
#services.swayidle = {
# enable = true;
# events = [
# { event = "before-sleep"; command = "swaylock"; }
# ];
#};
wayland.windowManager.sway = {
enable = true;
wrapperFeatures.gtk = true;
......
{
# To remove in NixOS 22.05
imports = [ <nixos-unstable/nixos/modules/services/misc/heisenbridge.nix> ];
services.heisenbridge = {
enable = true;
homeserver = "http://127.0.0.1:8008";
......
{
nixpkgs.config.allowUnfree = true;
services.minecraft-server = {
enable = true;
package = import ../custom_pkg/fabric-server.nix;
eula = true;
openFirewall = true;
declarative = true;
serverProperties = {
server-port = 25565;
gamemode = 1;
motd = "Fabric Creative server";
};
};
# Merged in unstable, https://github.com/NixOS/nixpkgs/pull/152455
systemd.services.minecraft-server.serviceConfig = {
# Hardening
CapabilityBoundingSet = [ "" ];
DeviceAllow = [ "" ];
LockPersonality = true;
PrivateDevices = true;
PrivateTmp = true;
PrivateUsers = true;
ProtectClock = true;
ProtectControlGroups = true;
ProtectHome = true;
ProtectHostname = true;
ProtectKernelLogs = true;
ProtectKernelModules = true;
ProtectKernelTunables = true;
ProtectProc = "invisible";
RestrictAddressFamilies = [ "AF_INET" "AF_INET6" ];
RestrictNamespaces = true;
RestrictRealtime = true;
RestrictSUIDSGID = true;
SystemCallArchitectures = "native";
UMask = "0077";
};
}
Supports Markdown
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment