summaryrefslogtreecommitdiff
path: root/modules/desktop/security/default.nix
blob: c1c084c8306ab9b8e835784d474b68a44deb88b0 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
{ config, lib, ... }:
{
  imports = [
    ./apparmor.nix
    ./audit.nix
    ./doas.nix
    ./kernel.nix
    ./pam.nix
    ./polkit.nix
    ./sudo.nix
  ];

  security = {
    rtkit.enable = lib.modules.mkForce config.services.pipewire.enable;
    virtualisation.flushL1DataCache = "always";
  };

  programs.firejail.enable = true;
}