diff options
Diffstat (limited to 'modules/security/default.nix')
| -rw-r--r-- | modules/security/default.nix | 24 |
1 files changed, 24 insertions, 0 deletions
diff --git a/modules/security/default.nix b/modules/security/default.nix new file mode 100644 index 0000000..06302ea --- /dev/null +++ b/modules/security/default.nix @@ -0,0 +1,24 @@ +{ + config, + lib, + ... +}: +let + inherit (lib.modules) mkForce; +in +{ + imports = [ + ./audit.nix + ./doas.nix + ./pki.nix + ./polkit.nix + ./sudo.nix + ./tpm.nix + ]; + + security = { + auditd.enable = true; + rtkit.enable = mkForce config.services.pipewire.enable; + virtualisation.flushL1DataCache = "always"; + }; +} |