diff options
Diffstat (limited to 'modules/pc/security/default.nix')
| -rw-r--r-- | modules/pc/security/default.nix | 19 |
1 files changed, 19 insertions, 0 deletions
diff --git a/modules/pc/security/default.nix b/modules/pc/security/default.nix new file mode 100644 index 0000000..c1c084c --- /dev/null +++ b/modules/pc/security/default.nix @@ -0,0 +1,19 @@ +{ config, lib, ... }: +{ + imports = [ + ./apparmor.nix + ./audit.nix + ./doas.nix + ./kernel.nix + ./pam.nix + ./polkit.nix + ./sudo.nix + ]; + + security = { + rtkit.enable = lib.modules.mkForce config.services.pipewire.enable; + virtualisation.flushL1DataCache = "always"; + }; + + programs.firejail.enable = true; +} |