cfg/common/security.nix
2025-07-14 14:45:55 +02:00

22 lines
291 B
Nix

{
config,
lib,
pkgs,
...
}:
{
security = {
protectKernelImage = true;
sudo.enable = false;
doas = {
enable = true;
extraRules = [
{
groups = [ "wheel" ];
persist = true;
keepEnv = true;
}
];
};
};
}