From c6deea451af1af2fdf4aee7f1ed74209f312a9b3 Mon Sep 17 00:00:00 2001 From: Fuwn Date: Tue, 3 Sep 2024 01:52:03 -0700 Subject: modules --- modules/security/default.nix | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) create mode 100644 modules/security/default.nix (limited to 'modules/security/default.nix') diff --git a/modules/security/default.nix b/modules/security/default.nix new file mode 100644 index 0000000..06302ea --- /dev/null +++ b/modules/security/default.nix @@ -0,0 +1,24 @@ +{ + config, + lib, + ... +}: +let + inherit (lib.modules) mkForce; +in +{ + imports = [ + ./audit.nix + ./doas.nix + ./pki.nix + ./polkit.nix + ./sudo.nix + ./tpm.nix + ]; + + security = { + auditd.enable = true; + rtkit.enable = mkForce config.services.pipewire.enable; + virtualisation.flushL1DataCache = "always"; + }; +} -- cgit v1.2.3