dotfiles/hosts/thinkpad/system/security.nix

29 lines
394 B
Nix
Raw Normal View History

2024-04-28 11:35:35 +02:00
{
2025-01-09 09:34:41 +01:00
pkgs,
config,
systemd,
user,
...
}:
{
2024-04-28 11:35:35 +02:00
# enabling firejail for sandboxing
programs.firejail = {
enable = true;
};
# enabling doas
security.doas.enable = true;
security.sudo.enable = false;
2025-01-09 09:34:41 +01:00
security.doas.extraRules = [
{
users = [ user ];
keepEnv = true;
persist = true;
}
];
2024-04-28 11:35:35 +02:00
2025-01-09 09:34:41 +01:00
# setting up a polkit
2024-04-28 11:35:35 +02:00
security.polkit.enable = true;
}