diff options
| author | Fuwn <[email protected]> | 2024-09-03 01:52:03 -0700 |
|---|---|---|
| committer | Fuwn <[email protected]> | 2024-09-03 01:52:03 -0700 |
| commit | c6deea451af1af2fdf4aee7f1ed74209f312a9b3 (patch) | |
| tree | d725ce5a39939b1379f2a4141cd0ab54c1ef16cc /modules/security/default.nix | |
| parent | home (diff) | |
| download | nixos-config-c6deea451af1af2fdf4aee7f1ed74209f312a9b3.tar.xz nixos-config-c6deea451af1af2fdf4aee7f1ed74209f312a9b3.zip | |
modules
Diffstat (limited to 'modules/security/default.nix')
| -rw-r--r-- | modules/security/default.nix | 24 |
1 files changed, 24 insertions, 0 deletions
diff --git a/modules/security/default.nix b/modules/security/default.nix new file mode 100644 index 0000000..06302ea --- /dev/null +++ b/modules/security/default.nix @@ -0,0 +1,24 @@ +{ + config, + lib, + ... +}: +let + inherit (lib.modules) mkForce; +in +{ + imports = [ + ./audit.nix + ./doas.nix + ./pki.nix + ./polkit.nix + ./sudo.nix + ./tpm.nix + ]; + + security = { + auditd.enable = true; + rtkit.enable = mkForce config.services.pipewire.enable; + virtualisation.flushL1DataCache = "always"; + }; +} |